Atlassian password breach due to forgotten database

The recent database breach that exposed passwords that hit software development tool maker Atlassian was, due, in their words to an old database table that “was not taken offline or deleted, and it is this database table that we believe could have been exposed during the breach.”

Amichai Shulman, Imperva’s CTO explains, “This is an example of a database that was forgotten and left unprotected—something that happens more frequently that most would prefer to admit. In this case, the database contained sensitive information, but once it wasn’t used as a production system it was forgotten. Unmanaged systems put sensitive data residing on them at a high risk - unmanaged systems are the top targeted systems.”

“In order to protect sensitive data, organizations must ensure that ALL their databases are managed and under control,” recommended Shulman. “It is imperative that organizations scan their networks to discover databases, including unmanaged databases, and follow with data discovery and classification which provides the needed awareness. Access to databases hosting sensitive data should be tightly controlled and the data must be protected from both external threats (hackers) and malicious insiders.”

Imperva, the Data Security leader, enables a complete security lifecycle for business databases and the applications that use them. Over 4,500 of the world’s leading enterprises, government organizations, and managed service providers rely on Imperva to prevent sensitive data theft, protect against data breaches, secure applications, and ensure data confidentiality. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring from the database to the accountable application user and is recognized for its overall ease of management and deployment. For more information, visit www.imperva.com.

Source: Eskenzi PR

Are we facing yet another banking crisis?

How cybercriminals’ are stealing corporate funds, and putting pressure on the global banking system

The last eighteen months have delivered some of the most testing challenges to the global banking system. Whilst financial institution and businesses alike both struggle to emerge from a brutal recession, they’re now having to face up to a new threat which can potentially steal away their funds and corporate reputation with the simple click of a mouse.

In this article Dave Tripier, CMO of IronKey, explains how organised cyber crime rings have begun to target corporate banking transactions - and offers valuable advice to help banks and businesses to deal with this new threat.

For many years, global cyber crime organisations have been successfully stealing millions from personal customer bank accounts, through large scale phishing attacks. However these hi-tech criminal gangs have shifted focus to instead target the more lucrative corporate bank accounts of both public and private sector organisations.

Reiterating the seriousness of this new cyber threat, Ponemon’s 2010 Business Banking Trust survey recently revealed that 80% of banks had failed to catch fraud before funds were transferred out of their institution. More worryingly still, 57% of the businesses that have experienced a fraud attack were not fully compensated by their banks. So, businesses are naturally waiting for guidance on protecting their accounts from crime – and insuring their funds are returned if they are hit by an attack. And as analyst firm Gartner warns that the increasing attacks on online banking transactions is merely the tip of the cyber crime iceberg, the banking industry is faced with a threat that could cripple confidence in the corporate online banking system.

Why the threat landscape has changed

Global cyber crime rings have changed their tact, in recognition that it’s far more profitable to make numerous large transfers from a single corporate bank account than to try to hijack thousands of consumer-based accounts and make small money transfers.

The cyber criminals are using commercial online banking malware which comprises of a number of new families of Trojans that use live authenticated sessions to defeat traditional security defenses. The new Trojans are even able to beat multi-factor authentication that banks have employed to protect consumers against phishing fraud. They are not only capable of stealing corporate authentication credentials, but can also perform fraudulent transactions from a victim’s own computer.

These “man-in-the-browser” Trojans also rewrite the Web browser pages that a victim sees and often request secondary authentication credentials such as secret questions and answers that can be used later to change the victim’s login credentials.

Can the banks afford to take another reputational hit?

It’s natural that the threat of criminal activity will mean that companies’ confidence in their banks will drop. The Ponemon study revealed that 40% of businesses have moved their banking activities elsewhere after a fraud incident. 11% of firms that have experienced fraud claimed they have terminated their banking relationship following the attacks, and an additional 29% said they did not fully terminate their relationship, but moved their primary cash management services to another institution.

While consumer confidence is clearly a big priority for banks, reassuring corporate customers is even more pressing – with the large amounts of money changing hands. Where banks may be able to deal with the loss of ten individual customers that have experienced fraud, the financial and reputational damage of losing a big corporate customer is significantly more difficult to recover from. It’s clear that after the global banking crisis of 2009, financial institutions cannot afford any further damage to their status.

Dealing with the threats

This undoubtedly a global threat, as yet, the only authority to issue advice to banks and businesses to date has been the US Electronics Payment Association, NACHA. NACHA has advised that any business uses separate computers for banking transactions – which are not enabled for web browsing or email services. This means that while the computer is only used for banking transactions, it is not open to email nor Web based cyber attacks.

The security industry welcomes NACHA’s advice; the reality for organisations is that each member of a company’s finance team will need two computers - one for web browsing and email – and one for its banking transactions. This adds pressure time and complexity to the employee – and can prove costly for an organisation. Add to the cost of infrastructure, the associated security protocols for setting up new computers, and the need to renew the systems every three years, and this is an increasingly costly exercise.

A possible alternative?

However, it seems that just as cybercriminals are using technology to commit fraud, the banking industry can make use of advances in technology to fight back.

One approach is by IronKey who has developed a unique integration of custom silicon, security firmware, security software, and online security services into one cost-effective safe oasis for online banking.

Following NACHA’s guidance and best practices IronKey has created an integrated solution into one easy to use package which includes:

  1. A virtualised environment that operates in a read-only mode, so that malware cannot tamper with the stored image on the IronKey device. The virtualised environment can be written to only when a digitally signed update is delivered from the IronKey security management service and verified locally on the IronKey device.

  1. A secure browser runs inside a virtualised environment, it is isolated from the host’s PC malicious software providing a safe transactional environment to corporate customers.

  1. Two-factor authentication with RSA SecurID for a defense in depth approach.

  1. Anti-malware to scan of the user’s computer before running the secure environment

  1. A online service to manage the devices and provide security updates - no management infrastructure required

In summary the IronKey multifunction security device, combined with IronKey security services, gives financial institutions a cost-effective way to protect their commercial banking customers from the next generation of banking malware.

References:

Ponemon’s 2010 Business Banking Trust survey

FS-ISAC Account Hijacking of Corporate Customers. Recommendations for Customer Education.

August 24, 2009. A joint effort between the Federal Bureau of Investigation (FBI), the Financial

Services Information Sharing and Analysis Center (FS-ISAC), NACHA - the Electronic Payments

Association, and other Federal government agencies.

http://www.fsisac.com/

FFIEC Guidance–Authentication in an Internet Banking Environment

http://www.ffiec.gov/pdf/authentication_guidance.pdf

Newly discovered flaw affects all recent Java versions in Windows

Just when you thought it was safe to go back into the water along comes yet another problem

by Michael Smith (Veshengro)

Two researchers released information on a vulnerability in Sun's Java Runtime Environment that could give attackers a new point of attack to perform drive-by-downloads and compromise targeted clients on all current versions of Windows operating systems and several popular browsers. The vulnerability has been rated 'extremely critical' by the experts of security software, G Data. The company expects large attacks, targeting computers with Windows operating systems.

With Java being installed on many computers, this flaw will undoubtedly catch the eye of cyber criminals, who will be quick to find a way to exploit this vulnerability. As this leak can be exploited in most popular browsers, and is not slowed down by the security features of Windows Vista and Windows 7, this could bring serious damage to a large number of computers.

Protect yourself against this

Disabling Java-script does not protect against exploits of this vulnerability. Because it is not yet clear when this leak will be patched by Sun, users need to manually change their settings. For the two most popular browsers there are details below of how to rectify this problem:
- For Microsoft Internet Explorer, it is necessary to set a killbit for the ActiveX class ID CAFEEFAC-DEC7-0000-0000-ABCDEFFEDCBA. The manual on how to do this can be found through the following link: http://support.microsoft.com/kb/240797.

- For Mozilla Firefox, you need to go to the 'Tools' menu and click on 'Add-Ons'. Under the header 'Plugins', you will find the Java Deployment Toolkit, that can be disabled by clicking 'Deactivate'. N.B. Recent updates to the latest versions of Firefox have disabled this Java Deployment Toolkit automatically now.
Background

Security researcher Tavis Ormandy released the information about this vulnerability on seclist.org. The vulnerability originates in the browser plug-in Java Deployment Toolkit, which is installed automatically alongside Java Runtime Environment since version 6 update 10 into browsers like Microsoft Internet Explorer, Mozilla Firefox or Google Chrome. The method launch in the toolkit enables an attacker to execute Java's Web Start Launcher with arbitrary parameters. Ormandy provided a proof-of-concept web page that starts the calculator in Microsoft Windows products.

Only a few hours later, researcher Rubén Santamarta released information on how to load an arbitrary remote DLL. According to Santamarta he was able to bypass security measures DEP and ASLR given that the DLL is directly loaded into the process memory of Web Start Launcher.

While this exploit, as indicated, can also be used in Google Chrome we have not, as yet, found a way to disable, if it is attached, the Java Deployment Toolkit in Chrome. It might be therefore advisable for Chrome users to drive Firefox instead of Chrome for a while, until the problem is overcome.

© 2010

Cloud computing and social networking leave UK businesses exposed to cyber attacks - survey

Cloud computing and social networking leave UK businesses exposed to cyber attacks according to 2010 Information Security Breaches Survey

Business use of technology is evolving faster now than at any point in the last decade. Internet use has moved way beyond email and websites and into the realms of social networks and externally-hosted software services accessed across the Internet (often referred to as cloud computing).

These changes have increased the vulnerability of UK companies and public sector organisations to new cyber attacks. Hacking and denial of service attacks have doubled in the last two years. As a result, security remains high on management’s list of priorities.

These are among the preliminary findings of the 2010 Information Security Breaches Survey (ISBS) commissioned by Infosecurity Europe and written by PricewaterhouseCoopers LLP. The full results of the survey including details of the number and cost of security breaches in the UK, have be revealed at Infosecurity Europe in London on 28 April.

The rate of adoption of newer technologies has accelerated over the last two years and most respondents now say they use wireless networking, remote access and VoIP. Some 85% of smaller organisations said they were using wireless, almost double the use in 2008. The number of organisations allowing staff to have remote access to their systems has also increase with nine tenths of large companies now doing this.

As organisations have looked to cut their IT costs, they have increasingly turned to external providers who host applications on their behalf. These services, including Software as a Service (SaaS) and cloud computing, are now used by over three-quarters of the organisations polled and of these, 44% said they were entrusting critical services to third parties. All sectors are making use of the services, but government is least likely to release control of critical services.

At the same time that companies are increasing their dependence on other organisations for their IT services, there has been an explosion of new cyber attacks. 61% of large organisations have detected a significant attempt to break into their network in the last year, twice as many as two years ago.

Some 15% of large organisations have detected actual penetration by an unauthorised outsider into their network in the last year, and it is likely that many more were undetected. 25% of large organisations have suffered a denial of service attack in the last year, also more than double the proportion in 2008. Outsourcing IT services does not make the security risk go away, but few companies are taking enough steps to ensure their outsourced services are not vulnerable to attack.

Chris Potter, partner, OneSecurity, PricewaterhouseCoopers LLP, said: “Very few organisations are encrypting data held on virtual storage, including the ‘cloud’. Worryingly, only 17% of those with highly confidential data at external providers ensure that it is encrypted. Virtualisation and cloud computing seem to be set to follow the trend, established over the last decade, of controls lagging behind adoption of new technologies. Given the increased criticality and confidentiality of information held on virtual storage, organisations need to respond quickly to close this control gap.”

Responding to the data leakage threat

The increasingly inter-connected business environment and prevalence of externally provided services is reflected by a growing data leakage threat. That threat is driving an increased demand for assurance over third parties. ISO 27001 is becoming a common standard for compliance; 40% of large organisations are being asked to demonstrate compliance with the standard.

ISO 27001 and PCI (Payment Card Industry) standards are also driving adoption of some specific security mechanisms. PCI, in particular, is driving more encryption of website transactions and sensitive data fields in databases. However, organisations that need to meet government requirements are more likely to encrypt data transfers and removable media.

Andrew Beard, director, OneSecurity, PricewaterhouseCoopers LLP, said: “It seems that organisations will respond to specific requirements mandated by government or other authorities, but when the requirements are less explicit, adoption of good practice is lower. Assurance reporting appears to increase organisations level of comfort. However, as adoption of the assurance reporting standards remains low, it seems likely that some organisations have a false sense of security.”

Staff postings to social networking sites pose a new data leakage risk. Yet, at the same time, social networking is increasingly important to businesses. Organisations are reassessing their approach to controlling staff access to the Internet. The trend, established between 2006 and 2008, of allowing more staff to access the Internet has been reversed. Nearly half of large organisations now restrict which staff can access the Internet; less than a third did so in 2008.

Organisations want to allow effective use of the Internet, but reduce inappropriate use. Use of software to block access to inappropriate websites is slightly up on two years ago. Web access logging and monitoring is relatively static. However, more sophisticated use is being made of these tools than in the past. Organisations are one and a half times as likely to monitor postings to social networking sites if social networking is considered very important to their business.

Source: Eskenzi PR Ltd.

Network performance at risk as bandwidth demand outpaces capacity across UK businesses

Demand for bandwidth on computer networks is rapidly outstripping capacity in over one third of UK businesses, leading to major concerns over application delivery, security and business continuity, according to new research from Brocade.

A recent study of over 100 senior UK IT decision makers found that 39 percent felt that they would need to increase network capacity by up to 50 percent over the next year just to keep pace with user demand. The underlying capacity concern is over network and application performance, with 39 percent of those questioned stating that it (performance) was of paramount importance to the success of the business. Enforcing this, two thirds of respondents stated that their existing network could only be described at best as ‘relatively quick’, and a further 18 percent describing it as ‘slow’ showing that work still needs to be done to maintain the status quo.

Paul Phillips, Regional Director - UK & Ireland, Brocade, stated: “CIOs expect tomorrow's corporate networks to fulfil a wide range of sometimes-conflicting demands. They want unprecedented scalability, but reduced management complexity. They want seamless mobility, but tight orchestration, and they want emerging networking technologies to complement the investments they are making today, instead of forcing them to refresh the entire environment in a wholesale 'rip-and-replace' exercise.

“This research has highlighted what many in the industry had suspected; network performance, scalability, availability and security is uppermost in the minds of network managers, struggling to meet end user expectations of an ‘always-on, always-available’ network,” he added.

Key findings include:

Over the next year, 15 percent of businesses are predicting they will need to increase network capacity by 20-30 percent; 13 percent expect to have to increase capacity by 30-40 percent and a further 11 percent by anywhere between 40-50 percent Network availability is the greatest concern of 18 percent of the sample, consolidation was cited by 39 percent and security by 15 percent.

Source: Spreckley Partners

Trusteer Warns of Impending Wave of PDF malware attacks

A structural flaw in the Adobe PDF format - which is widely used to distribute documents across multiple computing platforms - can be exploited to install almost any malware on a user's computer.

And says Trusteer, the browser security and fraud prevention specialist, security researcher Didier Stevens' demonstration (http://bit.ly/bDVf7W) of a multi-stage misuse of Adobe `/Launch' function - which is part of the PDF feature set - poses a potentially serious threat to organisations and individuals.

The demonstrated attack allows criminals to embed a malicious executable file inside a simple PDF file. When the user opens the PDF the malicious executable runs.

"Whilst Acrobat Reader normally display a warning that an executable inside a PDF file is being launched, Stevens appears to have found a way to modify the alert and fool users into approving the action," said Mickey Boodaei, Trusteer's CEO.

"Our research team were quickly able to replicate Didier's findings and there is every reason to believe this exploit will be added to the multi-exploit Adobe hacker toolkits in use by cybercriminals," he added.

As a result of this potentially very serious attack vector on Acrobat and Reader, Trusteer is advising all users disable the function of running PDF-embedded attachments within Adobe's software. This, he notes, can be achieved quite easily from the settings option within the software or, as Adobe has advised in a security blog, by a direct Registry setting change (http://bit.ly/b29yXB)

Boodaei says he anticipates that cybercriminals and hackers will try to exploit this structural Adobe issue using social engineering techniques, which lure Internet users into a false sense of feeling safe. Social engineering, he explained, is becoming an increasingly important tool used by criminals.

“Many security solutions such as antivirus and personal firewalls rely on Internet users to make the right choice,” he said. “They present technical messages that are hard to understand and expect users to decide what to do with them. Acrobat Reader works similarly by expecting Internet users to understand the security implications of running an embedded file. Stevens' attack makes it harder for users to make the right choice as it allows criminals to tamper with the message that Acrobat presents and use social engineering techniques to convince users to take the wrong choice.”

"Over the last year we've seen criminals effectively using social engineering attacks to by-pass various security systems such as two-factor authentication, transaction verification, and desktop security," he said.

For example, he says, with transaction verification criminals are now using man-in-the-middle and man-in-the-browser attacks to change messages on banks' Web site and convince customers to approve fraudulent transactions. Instead of presenting the normal instructions for approving a transaction criminals change the webpage to include instructions on how to approve a fraudulent transaction. Most users just follow instructions and look for the easiest and quickest way of getting something done. They don’t stop to think if every step they make is a reasonable behavior.

Going forward Boodaei says that financial institutions and enterprises should evaluate the vulnerability of their security systems to social engineering attacks and consider measures to protect against it.

"Internet users can do their part by installing a browser security layer such as Trusteer's Rapport software (http://bit.ly/aRw8sj), which is offered as a free download by banks such as HSBC, RBS/NatWest and the Santander Group. This will help to protect their online banking account sessions."

Trusteer enables online businesses to secure communications with their customers over the Internet and protect personally identifiable information (PII) from a user's keyboard into the company's Web site. Trusteer's flagship product, Rapport, allows online banks, brokerages, healthcare providers, and retailers to protect their customers from identity theft and financial fraud. Unlike conventional approaches to Web security, Rapport protects customers’ PII from malware including Trojans, keyloggers, and pharming and phishing attacks. Trusteer is a privately held corporation led by former executives from Cyota/RSA Security, Imperva, and NetScreen/Juniper. For more information visit www.trusteer.com.

Source: Eskenzi PR

iStorage diskGenie – Product Review

Review by Michael Smith (Veshengro)

diskGenie - Portable Encrypted Hard Drive with Secure PIN code access

The diskGenie from iStorage offers powerful hardware encryption in a compact, portable device with a totally unique difference. With an easy-to-use keypad design and software free setup, the iStorage diskGenie is only accessible using a PIN code similar to using an ATM.

With its automatic AES 256 bit real time hardware encryption, it protects the data on the drive keeping it safe even if the hard drive is removed from its enclosure. Quite simply, the iStorage diskGenie is the ultimate portable hard drive and secure storage system.

With no software to install, easy setup and real-time encryption, the diskGenie is the best way to protect your data, customers and your business. The conveniently integrated USB cable eliminates the need to carry around cables, so is perfect for using with notebooks and taking your data on the road.

Its low powered, compact, robust design features a 16-point omni-directional shock mounting system, protecting the drive from drops and knocks. With storage capacities of now up to 640GB it is perfect for safely transporting data between office and home as well as storing photos, music and video files.

The iStorage diskGenie is the only hardware encrypted drive, whether USB stick kind or other, that I have so far encountered and been able to review that works with all versions of Linux straight out of the box, needing no command line or anything of that nature.

This is due to the fact, that unlike the USB drives that we encounter most of the time, and other hard drives, that are hardware encrypted the iStorage diskGenie does not use any software that has to be installed on the computer, thus working with all operating systems. A definite plus.

Its use is easy and straightforward and I did not even need to consult the guide or manual with the exception of the change of the pin code. That too, following the instructions, is a doddle and the code can be from a minimum of 6 number to 16, thus making it very secure. The drive is a total plug and play that works with any system of Windows XP and above, Mac OS 10.2 or greater, and all Linux distributions, as far as I can tell.

Key benefits of the iStorage diskGenie drive are:

  • Complete security with Real Time 256-bit AES Hardware Encryption and Pin Code Access

  • Easy to install and set up as no software needed andn thus working with all operating systems

  • Convenience via integrated USB2 so no extra cables or AC power needed

  • Robust, portable compact design with shock mounting to protect from knocks

  • Administration feature allowing up to 10 passkeys and passkey management

  • Compatibility with any operating system incl. Windows, Mac, Linux

  • Guaranteed with 3 year warranty

The iStorage diskGenie drive is available in capacities of 250GB, 320GB, 500GB, and 640GB, as real hard drives. SDD are also becoming available, so I understand.

As far as I am concerned this drive must get at least a 9 our of 10 if not even 10 out of 10. The reason I am sold on this drive is that it works, unlike so many others that claim it, with Linux straight out of the box without the need for any command line and all that jazz.

A great little drive and one that also looks good and feels good.

© 2010