by Michael Smith
British workers are the most likely to open dodgy-looking emails than any other developed nation except the Chinese, according to new research by Cisco on the habits of corporate workers.
I must say that this finding does come at no surprise to this writer as I have seen this happening but the Brits are not alone here, of that I am sure. There are also enough of them in the United States who will do that and also fall for the kind of spam like “pass this on to 100 of your friends or your PC will blow up” and stuff like that.
While only 25% of US workers, 23% of French workers and 28% of Japanese admitted opening suspicious emails, the figure in the UK rose to 45%. Only the Chinese, at 54%, showed a higher level of curiosity.
Maybe the Brits are a little more honest than the workers from other countries when they answered the questions.
But although the Brits like to see the message text, they are better disciplined when it comes to opening unsafe attachments or going to websites of dubious origin. Only 3% admitted doing so – far fewer than most other countries. In Japan, 14% opened attachments, followed by India (11%), China (8%), Germany (6%) and Australia (5%). Only 2% of US workers admitted opening attachments or suspicious URLs.
The problem is that not all URLs are suspicious looking, and that is the problem here. However, the advice should be not to open attachments or follow links unless we know who sent them and that they are safe. If need be check back with the supposed sender.
The Cisco research marks the second year the company has surveyed attitudes in 10 industrial countries, questioning 100 IT decision-makers and 100 remote workers (end-users) in each country.
The survey also found an increase in workers using their work computers for personal use, such as shopping. In the UK, 43% of respondents said their company had no objection to them doing so.
It seems also that the lines between work and home computers are blurring, with a greater proportion of remote workers using personal devices to access work files, and work devices to access personal files than they did in 2006. That trend seems to be strongest in China and the US.
Because of this blurring trend devices such as the MXI Secure Stealth MXP loaded with MojoPac Enterprise desktop environment are so important nowadays. People use their own PCs to connect to networks of their companies and organizations and could, inadvertently introduce the gods only know what into the system. A secure desktop on a USB drive is the answer here. But, I digressed.
There is some risky behaviour about. We have more remote workers, and we are blurring the lines between personal and corporate assets. And with Web 2.0, everyone has hopped on the bandwagon of socialising with people around the world.
A lot of people at work feel comfortable because they believe their PCs are locked down tightly. With the threat vectors changing, however, we need to take a look at how to tackle such threat. This means that users have to be trained properly and that proper procedures and devices must be used to make things as secure as possible.
Hackers from around the world starting to use stealth tactics to get into networks and steal intellectual property. Who wants to pay millions in research and development when they can just go and steal the information?
Often poor security procedures are allowing hackers to penetrate networks and once inside, they escalate their privileges to become basically an unpaid systems administrator. They then grab the corporate data and remove it very slowly piece by piece, so that no one even knows that they have been there.
Technology and procedures can only do so much. A cultural and behavioural change needs to imposed in the organisation so that people understand the implications as to their own vulnerabilities.
People have to be made aware of the potential repercussions of any mistake or a "moment's lack of thought".
For compliance purposes organisations also need to be able to show they provide users with adequate training and information, so that they can prove good practice in the event of a security breach.
© M Smith (Veshengro), September 2008
<>
Brits lack email security awareness – says a Cisco report
Zero day flaw in WORD allows exploits by Trojan
by Michael Smith (Veshengro)
Microsoft warned on July 10, 2008, that an unpatched security vulnerability in WORD has become the subject of targeted attacks.
Yet another security flaw in Microsoft products? You don't say... The more I see of Microsoft the more I wonder what kind of incompetence reigns there at Redmond.
The flaw – which, supposedly, is restricted, so they claim, to Microsoft Office WORD 2002 Service Pack 3 (one may wonder when they notice that it not just affects that one) – creates a mechanism for hackers to inject hostile code onto vulnerable systems. Redmond has published workarounds as a stop-gap measure while its researchers investigate the flaw in greater depth.
In the meantime, Microsoft is keen to downplay alarm. "At this time, we are aware of limited, targeted attacks attempting to use the reported vulnerability, but we will continue to track this issue," a post on its security response blog explains.
The vulnerability has appeared in a number of samples on malware. A widening number of anti-virus firms have issued signature updates to defend against the threat.
Symantec, acting on samples sent to it by handlers at the SANS Institute's Internet Storm Centre, was the first to publish an advisory.
Maybe a firewall would be advisable here as well that can prevent the injection of hostile code such as the recently tested – by me, due to my favorite Zonealarm having been disabled by the nice guys from Redmond with Microsoft Security Update for Windows KB951748 – PC Tools' free Firewall. It has an advanced facility that can prevent the injection of code. It can be annoying though when this is set as it will have the little window pop up every time that you launch a program, until it has learned which programs are allowed to do this and that.
The timing of the arrival of the exploit meant Microsoft had not enough time to respond before its regular “Patch Tuesday” update, This factor is probably no coincidence. So far the direct details of the flaw are still under investigation and it can be safely assumed that they will probably be withheld from the public and industry even until a fix is unavailable. It is also not at all clear as to who the attack is targeting and aimed at. However, historically unpatched WORD exploits are a particular favorite of Chinese hackers.
Seeing how clever Redmond was recently with Microsoft Security Update for Windows KB951748, which disabled most if not indeed all Zonealarm applications and so far we have no response from them as to that foul up, why should we trust them when they are so silent.
Many people seem to believe that the disabling of Zonealarm in the above mentioned patch was no coincidence but was in fact one of the aims.
Yet again, I cannot and will not comment further to such claims as they cannot, so far, be substantiated and proven. Let the reader, however, beware.
The best advice, I am sure, can only be here, yet again, to go Open Source, and to use and alternative to Microsoft Office. There are a number of them available and most are as good, at least, as MS Office.
As I, personally, am moving – work wise – between Linux and Windows all the time, I am using only, nowadays, Open Office 2.0 for all the work that generally would have been the domain of MS Office. This is with the exceptions as and when WORD needs to be used to work with some templates, for instance, such as Avery Dennison's ones, as they still do not have created an Open Office interoperability.
I am not saying that there may not be vulnerabilities in Open Office or the other Open Source products. The fact remains, though, that most hackers do not seem to even attempt to target such open source software and also operating systems. Or, more precisely, in the case of the operating systems, such as Linux Ubuntu, they try to get somewhere but do not succeed.
© M Smith (Veshengro), July 2008
Variant of blackmailing virus spreading on Internet
Another blackmailing virus. Oh, how lovely - NOT
by Michael Smith (Veshengro)
Security software firm Kaspersky Lab has reported a new and dangerous blackmailing virus and is alerting computer users everywhere about a new variant of Gpcode, a dangerous encryptor virus.
The Virus.Win32.Gpcode.ak malware encrypts users' files with various extensions, including .doc, .txt, .pdf, .xls, .jpg, .png, .cpp, .h and more, using an RSA encryption algorithm with a 1024-bit key, and that is a lot.
Kaspersky Lab itself added a virus signature to block Virus.Win32.Gpcode.ak in early June 2008.
Kaspersky Lab says it has succeeded in thwarting previous variants of Gpcode by cracking the private key held by the attackers.
However, the author of the new Gpcode variant has taken two years to improve the virus and previous errors have been fixed and the key has been lengthened to 1024 bits instead of the original 660, which was crackable.
So far, it would appear that Kaspersky have been unable to decrypt files encrypted by Gpcode.ak since the key is 1024 bits long and so far no errors have been found in the implementation. That means, according to Kaspersky, the only way to decrypt the encrypted files, presently, is to use the private key which, unfortunately, only the author of that virus has.
After Gpcode.ak encrypts files on the victim's machine, it changes the extension of these files to ._CRYPT, and places a text file named !_READ_ME_!.txt in the same folder.
In the text file the criminal tells the victims that the file has been encrypted and offers to sell them a decryptor: "Your files are encrypted with RSA-1024 algorithm. To recovery your files you need to buy our decryptor. To buy decrypting tool contact us at: ********@yahoo.com"
Kaspersky Lab is still working on a way to recover data that has been encrypted without having to use the criminal's decryptor. Let's hope that they will do so and in addition to that that those criminals get caught.
In addition to that, what can one do? Even the best anti-virus software is and will be always one step behind the virus writers and criminals.
While personal vigilance as to where one goes and what email one opens is important, and more often than not it is the bad email protocol of users that bring them those lovely viruses and Trojans. However, Trojans sometimes come packaged in different ways even where the user would not suspect them to be.
See my article “Viruses and Trojans in Trusted Downloads” on how easy it is to have such things reach your computer.
© M Smith (Veshengro), June 2008
Employees' USB sticks 'could risk security'
Workers who bring USB sticks and iPods into their place work and connect them to its computer system are a potential threat to their own organisations, according to information security solutions firm Kaspersky.
David Emm, senior technology consultant at the company, explains that employees are not experts in this field and as such they may not be fully aware of the risks.
Giving small business technology advice, he states that if and when workers bring USB sticks and iPods into work they should scan the peripherals before they integrate them into the computer system.
This allows a "layer of confidence" to be established in the firm, Mr Emm adds.
"It's really a question of giving sensible advice to your staff," he concludes.
Meanwhile, research by Websense suggests that 90 per cent of businesses have suffered a hacker attack in the last 12 months and 45 per cent have had their IT systems infected by a computer virus.
