New password-stealing virus targets Facebook

by Michael Smith (Veshengro)

According to Reuters Wire Services Hackers have flooded the Internet with virus-tainted spam that targets Facebook's estimated 400 million users in an effort to steal banking passwords and gather other sensitive information.

The emails tell recipients that the passwords on their Facebook accounts have been reset, urging them to click on an attachment to obtain new login credentials, according to anti-virus software maker McAfee Inc.

If the attachment is opened, it downloads several types of malicious software, including a program that steals passwords, said McAfee.

This shows yet again how careful users have to be and also that users have to, finally, understand that rarely any service, whether FB or other, will contact users in such a way.

I have personally had a “stupid”, for that is the only word that comes to mind, email telling me that my login credentials had been lost due to a fault in their system and I should click on the link given in the email to sort it out. Right, and pigs fly.

Hackers have long targeted Facebook users, sending them tainted messages via the social networking company's own internal email system. With this new attack, they are using regular Internet email to spread their malicious software.

A Facebook spokesman said the company could not comment on the specific case, but pointed to a status update the company posted on its web site earlier on Wednesday warning users about the spoofed email and advising users to delete the email and to warn their friends.

McAfee estimates that hackers sent out tens of millions of spam across Europe, the United States and Asia since the campaign began.

Dave Marcus, McAfee's director of malware research and communications, said that he expects the hackers will succeed in infecting millions of computers.

"With Facebook as your lure, you potentially have 400 million people that can click on the attachment. If you get 10 percent success, that's 40 million," he said.

The email's subject line says "Facebook password reset confirmation customer support," according to Marcus.

But the email may also have other tag-lines and everyone be best advised to ignore and – if so inclined – report such emails to the companies concerned.

Once again my advice:

  1. Have good anti-virus protection and no, you do not have to pay for it. AVG will do nicely.

  2. Do not open any links that have been given in any such emails as reputable companies do not work in such a manner.

  3. In addition to that with regards to Facebook: Do not use any applications on that social network, especially none that are third-party and most of them, in fact, are. Many a virus and Trojan is hidden in them.

Beware that there are many scams going on and try not to be the next victim.

Copyright © 2010

IT experts warn users turn off WiFi to prevent laptop theft

Credant warns users to turn off WiFi to help prevent laptop theft

Credant Technologies, the endpoint data security specialist, has warned laptop users to turn off their WiFi signals before stowing their laptop in the boot of their car or stashing their laptop in the office cupboard or desk drawer, apparently out of sight of thieves.

"BT Openzone recently announced it had passed the million WiFi access point mark in the UK (http://bit.ly/9t3ZF4) and cellular carriers are also boosting their WiFi coverage areas to take the load off their hard-pressed 3G networks, which all adds up to something of a WiFi explosion in the UK," said Sean Glynn, Credant's VP Marketing.

"This in turn has triggered the widespread availability of low-cost keyfob WiFi detectors for under a fiver, and quite sophisticated directional detectors for around the 30 pounds mark, both of which can be used by thieves to detect the presence of an out of sight laptop," he added.

Glynn's warning comes after a warning from a security analyst in Jamaica has reported that a large number of laptops are being stolen using WiFi detection techniques for later criminal use (http://bit.ly/aktKPv)

And, he says, with auction sites selling WiFi detection kit for pocket money prices, it is only a matter of time before this type of laptop detection technique finds its way to the UK.

Credant's observations, he went on to say, suggest that the real focus of identity thieves is the company laptop, which, as well as being a saleable item in its own right, can also contain valuable company data that can potentially be sold to the highest bidder online.

And as the jailing of the Darkmarket carder forum mastermind for almost five years on Friday illustrates (http://bit.ly/a2QZKs) identity theft is now big business, he noted.

Glynn went on to say that, because the latest laptops have a set time - sometimes up to 30 minutes - before they go into sleep mode when the laptop lid is shut, it doesn't take a genius to realise that shopping malls around 6pm on weekdays can be a prime source of potential notebook computers, just waiting to be stolen from cars.

"And whilst the office worker is busy inside the mall doing their shopping, no-one is going to think twice about someone in a suit waving their `car keys' around, ostensibly trying to find their car, when in fact s/he is looking for the strongest WiFi signal," he said.

"You may not be able to totally prevent your laptop being stolen, but only switching on your WiFi when you really need it, and, of course, encrypting your data on the notebook drive, will go a long way to preventing your computer becoming just another statistic," he added.

For more on Credant Technologies: www.credant.com

To be perfectly honest I cannot understand why anyone would want to leave the WiFi (Wireless LAN) on their laptop, notebook or netbook computer on when not in use, and that for simply one single and simple reason alone; namely the fact that the transceiver for the wireless uses battery power.

It is always advisable, simply for power management, to have the WiFi off when it is not being used.

Eskenzi PR with additional writing by Michael Smith

Personal data of 15,000 National Guardsmen lost

15,000 more reasons to archive data, says Origin Storage, as Arkansas National Guard archival disk goes missing

Basingstoke, March 2010: Reports that staff data spanning more than five years at the Arkansas National Guard have gone missing on a back-up drive highlights the need for encrypted backups to be taken on live data - and also strengthen the argument that live data should also be encrypted, says Origin Storage.

"The archival drive reportedly contains the names, addresses and social security number details of at least 15,000 current and former members of staff as at March 2009, and spans back to the start of 2004," said Andy Cordial, managing director of the storage system integration specialist.

"Whilst some experts claim that encrypting live data is overkill in some situations, the fact that was an archival disk, and almost certainly only accessed if the computer's primary drive went down, means that high levels of encryption should have been applied," he added.

Cordial noted that this isn't the first time a US military database has gone missing as, back in the spring of 2006, similar details of more than 2.2 million US military personnel - including nearly 80 percent of the active-duty force - were stolen (http://bit.ly/cXjE4B).

That data, including more than 430,000 National Guard members, was subsequently recovered after an in-depth investigation by the US military, indicating the potential value to fraudsters of the information that was stolen - "and that is before we start taking about US national security," he said.

According to the Origin Systems MD, the fact the US National Guard is recommending that all affected current and former members of staff contact a credit reference bureau indicates the potential fall-out from this hard dive loss, as the data lost is a identity thief's dream come true.

Social security numbers in the US, he explained, are much more powerful that national insurance IDs in the UK, as they are commonly used a means of identification online and over the phone, much as dates of birth are used in the UK.

The sheer size and history of the US, he said, means that there is a distinct possibility of several people of the same name having the same birthday but, because the social security number is unique to an individual, it is a much more useful identifier.

As a result, he added, most citizens use the number as their personal user credential when deadline with financial or government institutions.

"As a supplier we always recommend that archival data be protected by multiple layers of defence, such as encryption and password protection, as seen on our Datalocker range of secure backup systems (http://bit.ly/2vb6y9)," he said.

"And since we are dealing with a lot of staff data here it's also advisable to encrypt the current database, only decrypting data on the fly as and when it is needed. There is simply no excuse not to use password plus encryption on such valuable data," he added.

For more on the Arkansas archival drive theft: http://bit.ly/cW5sRp

For more on Origin Storage: www.originstorage.com

Source: Eskenzi PR

Industrialized cyber attacks infect educational servers worldwide

Hackers Automate in ‘Industrial Revolution’ Threat

Imperva Report Details Industrialization of Cyber Attacks and Uncovers Hacker Scheme to Infect Educational Servers Worldwide

London, March 2010 – Imperva, the data security leader, on March 1, 2010 released a new report warning that hackers have become industrialized and represent an exponentially increased threat to individuals, organizations and Government.

Imperva’s report says the emerging industrialization of hacking parallels the way in which the 19th century revolution advanced methods and accelerated assembly from single to mass production. The result is that today’s cybercrime industry has transformed and automated itself to improve efficiency, scalability and profitability.

The report, The Industrialization of Hacking, can be downloaded at: http://www.imperva.com/ld/industrialization.asp

As an example of this ‘industrial revolution’, Imperva has discovered a new hacker scheme that is infecting educational servers worldwide with Viagra ads that infect web users with malware when they visit the infected page on the legitimate education site.

According to Imperva, cyber-criminals are using industrialized methods to automate an as-yet unreported search engine manipulation scheme that has infected hundreds, possibly thousands of .edu and .ac.uk servers worldwide with Viagra ads. “This attack on academic institutions highlights how hacking has become industrialized infecting servers from major institutions including UC Berkeley, Ohio State, University of Oxford and more. Ironically, this technique is the most prevalent method used to create havoc in cyberspace, yet remains virtually unknown to the general public,” explained Imperva CTO Amichai Shulman.

The mass infection can be easily seen by searching Google US with the terms “Viagra and .edu”: http://www.google.com/searchhl=en&source=hp&q=viagra+.edu&aq=f&aqi=g10&aql=&oq=

Or Google UK with the terms “Viagra and .ac”: http://www.google.co.uk/#hl=en&source=hp&q=viagra+.ac&meta=&rlz=1R2GZAZ_enGB348&aq=f&oq=viagra+.ac&fp=a73fa2ac306dd28e

Key findings in the report include the organizational structure and technical innovations for automating attacks:

  • Organization structure – Over the years, a clear definition of roles and responsibilities within the hacking community has developed to form a supply chain that resembles a drug cartel. The division of labor in today’s industrialized hacking industry includes:

Researchers: A researcher’s sole responsibility is to hunt for vulnerabilities in applications, frameworks, and products and feed their knowledge to malicious organizations for the sake of profit.

Farmers: A farmer’s primary responsibility is to maintain and increase the presence of botnets in cyberspace through mass infection.

Dealers: Dealers are tasked with the distribution of malicious payloads.

  • Technical innovations—Hacking techniques once considered cutting-edge and executed only by savvy experts are now bundled into software tools available for download. Today, the hacking community typically deploys a two-stage process designed to proliferate botnets and perform mass attacks.

  • Search engine manipulation. This technique is the most prevalent method used to spread bots, yet remains virtually unknown to the general public. Essentially, attackers promote Web-link references to infected pages by leaving comment spam in online forums and by infecting legitimate sites with hidden references to infected pages. For example, a hacker may infect unsuspecting Web pages with invisible references to popular search terms, such as “Britney Spears” or “Tiger Woods.” Search engines then scour the websites reading the invisible references. As a result, these malicious websites now top search engine results. In turn, consumers unknowingly visit these sites and consequently infected their computers with the botnet software.

  • Executing mass attacks through automated software—To gain unauthorized access into applications, dealers input email addresses and usernames as well as upload lists of anonymous proxy addresses into specialized software, the same way consumers upload addresses to distribute holiday cards. Automated attack software then performs a password attack by entering commonly used passwords. In addition, today’s industrialized hackers can also input a range of URLs and obtain inadequately protected sensitive data.

About Imperva

Imperva, the Data Security leader, enables a complete security lifecycle for business databases and the applications that use them. More than 4,500 of the world’s leading enterprises, government organisations, and managed service providers rely on Imperva to prevent sensitive data theft, protect against data breaches, secure applications, and ensure data confidentiality. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring from the database to the accountable application user and is recognised for its overall ease of management and deployment. For more information, visit www.imperva.com.

Source: Eskenzi PR

Imperva launch new service to block automated cyber attacks

Imperva Introduces ThreatRadar To Mitigate Automated, Industrialized Cyber Attacks

First Reputation-Based Service for Web Application Security

London, March 2010 – Imperva, the data security leader, today announced the general availability of ThreatRadar, a new add-on to Imperva’s market-leading Web Application Firewall (WAF) that provides automated, reputation-based defense against large scale industrialized cyber attacks.

“ThreatRadar dramatically increases an enterprise’s ability to stop attacks by automatically adapting the defense so traffic from malicious sources can be blocked before an attack is attempted,” explained Imperva’s CTO Amichai Shulman. “By harnessing the collective insight of the security community, ThreatRadar can block traffic from malicious sources. As attackers shift locations and techniques Imperva’s ThreatRadar-powered WAF delivers the broadest arsenal of defense capabilities available today.”

Anyone using ThreatRadar with Imperva’s WAF will have an effective means to mitigate:

  • Mass SQL Injection attacks coming from botnets

  • Several types of automated attacks such as Comment SPAM campaigns, scraping attacks, web email SPAM attacks

ThreatRadar specific ally provides protection against:

  • Malicious sources: Up-to-date protection from sources that have repeatedly performed malicious activity on other web applications. Often part of the ten million plus botnet network they are executing attacks on behalf of remote hackers.

  • Anonymous Proxies: Up-to-date protection from sources that are used as anonymous proxies. By hiding the identity of traffic sources, anonymous proxies are often exploited by hackers to launch attacks.

  • The Onion Router, a.k.a., TOR IPs: Up-to-date protection from the TOR hacker network. Hackers use the TOR network to launch attacks without revealing their identity and location.

  • Phishing URLs: Real time alerting on phishing incidents against your domain.

  • In addition, ThreatRadar will provide:

  • IP Forensics Tool: A dynamic, web-based tool providing additional context on attackers, including geographic location and user profile, that takes the guesswork out of incident analysis.

  • Ongoing threat updates–Imperva’s Application Defense Center (ADC) has researched and integrated credible attack source data providers to ensure protection accuracy and effectiveness. The ADC will continually update attack sources as an ongoing service.

About Imperva

Imperva, the Data Security leader, enables a complete security lifecycle for business databases and the applications that use them. More than 4,500 of the world’s leading enterprises, government organisations, and managed service providers rely on Imperva to prevent sensitive data theft, protect against data breaches, secure applications, and ensure data confidentiality. The award-winning Imperva SecureSphere is the only solution that delivers full activity monitoring from the database to the accountable application user and is recognised for its overall ease of management and deployment. For more information, visit www.imperva.com.

Source: Eskenzi PR

Brocade welcomes Government’s IT Strategy

Smarter IT is needed not more IT

The news announced by the UK government that it expects to make savings of £3.2 billion annually from 2013/14 made through transformation in public sector information technology has been broadly welcomed by Brocade.

Paul Phillips, Regional Director UK and Ireland, Brocade, stated: “The announcement that the Government’s ICT strategy will focus on a smarter, cheaper and greener public sector ICT infrastructure should be broadly welcomed by both the industry and tax payer alike,”

“Promoting efficient and effective services for the public is a worthy objective. However schemes such as this will only be truly effective when joined together and integrated seamlessly, as opposed to ad hoc and individual approaches that often lead to IT duplication and considerable waste. It’s more than making information available, it’s about clever investments being made in networking technologies. Investments that are designed to deliver leaner, cost-effective infrastructures to complement existing business models,” added Paul Phillips.

Under the IT Strategy the government intends to create one secure, resilient and flexible network which will enable every area of government to adapt their ICT to best deliver for the public.

“Critically for the first time, the plan also intends to bring together all Government departments, local government and wider public sector organisations to remove unnecessary overlaps between departments and avoid the costly duplication of IT,” he continued.

The key provisions outlined by the Government include:

  • Launching a Government Cloud ('G-Cloud') which is intended to enable public sector bodies to select and host ICT services from one secure shared network. Multiple services will be available from multiple suppliers on the network making it quicker and cheaper to switch suppliers and ensure systems are best suited to need.

  • Cutting the of the number of data centres to approximately 10 to 12 which is expected to save £300 million, lead to 75% reduction in power and cooling requirements of the centres and ensure data storage is secure, accessible and sustainable.

  • Creating a Government Applications store designed for sharing and reusing online computer programmes (like standard Office applications such as word processing and email) on a pay by use basis. It will speed up procurement and deliver savings of approximately £500 million per year.

  • Implementing a common desktop strategy which will lead to savings of £400 million per year.

“What is clear is that as a result of the economic downturn many in the public sector are now looking at investing in networking technology to improve efficiency in their organisation to reduce the burden on the tax payer. This is about smarter IT and not just IT for IT’s sake,” added Phillips.

Source: Spreckley Partners

Mobile workforce shift will cause security headache for many companies

Infosecurity Europe says mobile workforce shift will cause security headache for many companies

London, UK – A report just recently published that highlights the rising numbers of workers are moving to a truly mobile working environment confirms what many in the IT security industry have suspected for some time, says Claire Sellick, Event Director for Infosecurity Europe.

The iPass report, which took in responses from 1,000 enterprises, found that large swathes of enterprise staffers are using their smartphones to access their email - and a whole lot more.

"What is particularly concerning is the fact that 54 per cent of Blackberry users said they would move to an Apple iPhone if they were offered one, and 63% of employees prefer their smartphone over a laptop," she said.

"The problem here is that, whilst it's relatively easy to defend a laptop against the vagaries of a mobile Internet connection, securing a smartphone is a whole new ballgame for many IT managers," she added.

And, Sellick went on to say, as iPass said in its report, there are clear resultant risks in terms of compliance and security that arise from the migration to smartphones.

Many of the exhibitors at the upcoming Infosecurity Europe event, which takes place at London's Earl's Court exhibition centre on 27th - 29th April, are showing security solutions to what many people are calling the shift to agile working.

In addition, she explained, the show's education programme - which sees a raft of industry professionals giving their advice to visitors free of charge - will help IT managers make the transition to agile working in a safe and secure manner.

What is clear from anecdotal evidence - as well as studies of the enterprise workforce such as this latest one - is that the shift to mobile working is becoming something of a revolution, rather than the progressive evolution that many have previously observed.

"It's clear that enterprises now face the issue of workers using their smartphones, as well as their laptops, whilst on the move. One of our exhibitors has report on the subject (http://www.infosec.co.uk/ExhibitorLibrary/662/Mobile_security_26.pdf) and theme will be explored in several of our keynotes and seminars at the show," she said.

"In many ways, it is security issues such as this that makes the education programme at the show so attractive to attendees, who would normally have to pay for the free advice from a variety of industry professionals if they were at a conference," she added.

For more on the mobile workforce report: http://bit.ly/9hEHvw

To register to attend or for more information please visit www.infosec.co.uk

About Infosecurity Europe

Infosecurity Europe, celebrating 15 years at the heart of the industry in 2010, is Europe’s number one Information Security event. Featuring over 300 exhibitors, the most diverse range of new products and services, an unrivalled education programme and visitors from every segment of the industry, it is the most important date in the calendar for Information Security professionals across Europe. Organised by Reed Exhibitions, the world’s largest tradeshow organiser, Infosecurity Europe is one of five Infosecurity events around the world with events also running in Belgium, Netherlands and Russia. Infosecurity Europe runs from the 27th – 29th April 2010, in Earls Court, London. For further information please visit www.infosec.co.uk

Source: Eskenzi PR