When waging our battles on the security front, most organizations just put all the big guns on the front line. We buy expensive load balancers to prevent D.O.S attacks, state of the art firewalls to prevent penetration, VPN products to secure our backdoors etc. Whenever some major threat comes along, everybody jumps out of bed, and rushes over to plug the hole, but at time like that, we often forget one of the oldest tricks in the burglars book - the diversion (a.k.a "Steaks for the dogs").
Unlike the movies, hacking into a network is not a wham-bam, thank you, ma'am deal. A hacker spends a long time conducting surveillance and gathering intelligence, and when he does move in, it will hardly seem like a commando attack. There won't be alarms ringing or security-doors closing and sealing people off in safe rooms, and no SWAT teams will show up with mega-phones yelling. More often than not, some minor file will be found to be missing or altered several days, weeks or months later, and that will lead to investigation that will show the break in. If you get that dreadful 4 AM phone call, telling you that the Firewall's alerts are all over the place, or that your security center detects multiple attacks, that doesn't mean that someone is actually attacking your firewall.
Just like a commando unit trying to break into an army base will distract the guards with some explosions at the front gate, while trying to sneak in through the back, a computer attacker will most likely try to get the entire security team to focus everything on the very visual notification mechanisms. He will use multiple mechanisms to trigger every possible alert on your security devices, and he will do it at past-midnight so that you and your security team will be tired, angry and less-effective. He will try to get you guys to spend as much time as possible blocking the DOS attack and plugging the holes, while he quietly sneaks in through some back door that's less obvious and less protected. You will find yourself running from server to server, trying to find your hands and feet in gigabytes of logs, and chances are you'll spend days on it. When things quiet down, you might find the actual leak or penetration, but by that time, the attacker will be long-gone.
If this has happened to you, don't be surprised. After all, most information security people are technology gurus, not military-trained commanders, and it's only normal to focus our attention on the most visible threat, just like a driver would focus his attention on the tree he's about to crash into rather than another car that's about to crash into him (that is referred to often as "Tunnel Vision"). However, there is a way to handle this, and that is by preparing properly. Your organizations security policy should have this scenario specifically laid out, and the team needs to be trained not to treat any alert as an alarm. One way is to assign responsibilities to people, and sticking to them. If there is a virus rampant on the network, the backup administrator shouldn't be told to forget about the backups "for now" and help clean up machines. On the contrary! He should continue his work and keep an eye out for anything suspicious or wrong with the procedure. If the firewall appears to be breached, the PC-Technician crew shouldn't be assigned to reviewing logs, but should continue to monitor the user-request queue. Maybe an innocent account lockout request could reveal an account breach that is masked by the pointless firewall attack? Perhaps the virus was unleashed intentionally on the network so that the attacker could have uninterrupted access to the data on the backup server?
Another technique that has worked well for the physical security industry is the emergency level system. A company could create an emergency level scale, and assign specific duties to each. If a file was found to be altered, that would raise the threat level, which would have people deflect some duties and investigate, but wouldn't throw the entire IT group into chaos and mayhem.
Monday, May 4, 2009
Friday, March 6, 2009
Do you trust me?
For most of us, the System Administrators, a.k.a Sysadmins, are life-savers. They reset our passwords when we forget them, recover our files when we delete them and sometimes give us a hard time about it. For corporate management, however, this kind of power can be frightening. An administrator would usually have access to every bit of information in the company, including every employees employment and HR data, personal email, and usually customer data as well. This kind of power, if abused, can cause irreparable damage to a company, but despite that, most companies interview and screen their sysadmin just like any other employee. If, for some reason, this employee becomes bitter or estranged, there's no telling what could happen, and there have been documented cases where entire companies have been complete destroyed intentionally by their admins.
Can this happen to your company too? Possibly. CEOs and CIOs have been looking for ways to counteract this sort of threat for a while now. There is a logical problem here - if you don't trust your admin, and appoint someone to watch over him, then how do you trust that someone to not break bad? After all, even CEOs have been known to go astray and stick their hands into inappropriate pockets. Who shaves the barber?
There is no simple answer here, but generally, the answer has two parts. The logical solution is separation of powers. You appoint at least 2 or 3 administrators, and try to make sure they don't become too friendly with each other so there's less chance of collusion. One way to go about this is appointing people who are a world apart - big age difference, for example. Then, add to that job or responsibility rotation. For example, one can be appointed to manage the finance department servers, while the other owns the engineering servers, and then rotate those roles every 3-6 months. This way, if one used abuses these resources, it will most likely be revealed upon the next rotation. Another good practice is the force the administrators to go on vacation on a regular basis (and YES, it's totally worth to give them an extra few annual vacation days just for that). When the admin goes on vacation, someone else has to take over, and that would usually expose any foul play.
The 2nd part is technological - Use some system to track and log activity. This serves two purposes - people tend to mess around a lot less when they know they are being watched, and that will affect not only administrators, but also regular users. Secondly, if someone does go to the dark side, at least there will be a way to check what's been going on, and have evidence in case a law suit or criminal charges need to be filed. One such software solution is Intellinx, and another is InFlight. These solutions can record user activity directly from the network, including keystrokes and screen output from every station in the company.
Is any of that foolproof? Of course not. A smart crook can always find some way to scam his way around, and the only answer to this is to carefully build a security policy that tries to address each and every possible threat - external or internal. Another important lesson to be learned here is that the system administrator is a very sensitive position, and should be screened appropriately. The screening process should include not only technical evaluation, but also personality and psychological testing, and it wouldn't hurt to have this monitored on a regular basis too, especially if a big change has happened in the company. If you had your sysadmin fire half his technicians because the company is tight on money, you can bet he's preparing for the possibility of him being next on the chopping board, and his preparation might include stashing sensitive data or implanting backdoors into servers. Also, keep in mind that even a small-time technician that you are hiring today to haul some printers around might end up being the sysadmin in 10 years. That means that those guys should also be chosen carefully, and reviewed once again upon getting promoted. And speaking of Admins, a fun thing to read is the old classic BOFM, which tells some tails of a particularly nasty sysadmin.
Can this happen to your company too? Possibly. CEOs and CIOs have been looking for ways to counteract this sort of threat for a while now. There is a logical problem here - if you don't trust your admin, and appoint someone to watch over him, then how do you trust that someone to not break bad? After all, even CEOs have been known to go astray and stick their hands into inappropriate pockets. Who shaves the barber?
There is no simple answer here, but generally, the answer has two parts. The logical solution is separation of powers. You appoint at least 2 or 3 administrators, and try to make sure they don't become too friendly with each other so there's less chance of collusion. One way to go about this is appointing people who are a world apart - big age difference, for example. Then, add to that job or responsibility rotation. For example, one can be appointed to manage the finance department servers, while the other owns the engineering servers, and then rotate those roles every 3-6 months. This way, if one used abuses these resources, it will most likely be revealed upon the next rotation. Another good practice is the force the administrators to go on vacation on a regular basis (and YES, it's totally worth to give them an extra few annual vacation days just for that). When the admin goes on vacation, someone else has to take over, and that would usually expose any foul play.
The 2nd part is technological - Use some system to track and log activity. This serves two purposes - people tend to mess around a lot less when they know they are being watched, and that will affect not only administrators, but also regular users. Secondly, if someone does go to the dark side, at least there will be a way to check what's been going on, and have evidence in case a law suit or criminal charges need to be filed. One such software solution is Intellinx, and another is InFlight. These solutions can record user activity directly from the network, including keystrokes and screen output from every station in the company.
Is any of that foolproof? Of course not. A smart crook can always find some way to scam his way around, and the only answer to this is to carefully build a security policy that tries to address each and every possible threat - external or internal. Another important lesson to be learned here is that the system administrator is a very sensitive position, and should be screened appropriately. The screening process should include not only technical evaluation, but also personality and psychological testing, and it wouldn't hurt to have this monitored on a regular basis too, especially if a big change has happened in the company. If you had your sysadmin fire half his technicians because the company is tight on money, you can bet he's preparing for the possibility of him being next on the chopping board, and his preparation might include stashing sensitive data or implanting backdoors into servers. Also, keep in mind that even a small-time technician that you are hiring today to haul some printers around might end up being the sysadmin in 10 years. That means that those guys should also be chosen carefully, and reviewed once again upon getting promoted. And speaking of Admins, a fun thing to read is the old classic BOFM, which tells some tails of a particularly nasty sysadmin.
Thursday, February 12, 2009
Why does it keep coming back?
Conficker (a.k.a Downadup) is a nasty worm, no doubt about it, but even though it's been out for ages, it would seem there's just no way to get rid of it...or is there?
A lot of our customers seem to be getting this feeling. "We've installed patch MS08-067, and removed the worm using our anti-virus or the MSRT, but we keep getting re-infected, " they say. Some even reached the (false) conclusion that 08-067 doesn't work. Well, I can assure you that the patch works, but the worm has several clever secondary infection schemes that make it very slippery.
1. If even a single machine on the network is still infected, it will attack all other machines on the subnet consistently and try to infect them, so until every machine has been cleaned, this problem won't be over.
2. The worm penetrates target machines by using accounts with weak passwords. Resetting all domain passwords and local accounts is a good step. If that's not possible, then the SERVER and TASK SCHEDULER service should also be stopped. This is drastic, but only temporary, while the machines are being cleaned up. Once there are no longer infected machines, these services can be brought back.
This sort of step is a big problem for Server Machines, which needs the Server service to do their job, but sometimes this is what needs to be done. Think of it as quarantining a sick patient until his medicine kicks in.
3. The worm infects removable drives, like USB disks, so if an admin uses a USB disk to copy a removal tool to infected machines, he may be, in fact, contributing to the spread of the worm. This can be averted by setting the removable drives to read-only, if the drive supports it. If your drive doesn't, consider getting an SD with a USB SD Reader, as SD cards all have a read-only physical switch. Another option is to burn a CD with the tools and use it instead of a removable drive.
I've heard from several IT administrators that forcing users to use strong passwords is a problem. In certain environments, where the users are very non-technical or lazy, and have a hard time remembering passwords, this is indeed hard. However, even though resetting passwords for users is an annoying chore, the solution is not to let everybody off with empty or suitcase passwords (1111, 1234 etc), as this worm is specifically designed to take advantage of such environments. An alternative is to use a self-service password reset tool. With this type of thing, a user who forgot his/her password would use another employee's computer, or a designated Kiosk computer to reset his password. Here are several products of this type:
Finally, here's a step by step, for an IT administrator in a large organization:
1) Use a Startup script (http://technet.microsoft.com/en-us/library/cc179134.aspx) to stop the SERVER and TASK SCHEDULER on all domain machines:
Net Stop Server
Net Stop Schedule
Or better yet: Set these services to Disabled:
SC CONFIG SERVER start= "disabled"
SC CONFIG SCHEDULE start= "disabled"
2) Use the startup script to deploy the 08-067 patch to all machines
3) Use the startup script to deploy the MSRT in QUIET mode to all machines (http://support.microsoft.com/kb/891716/)
4) Reboot all domain machines to make sure that the patch and MSRT run on all machines (can be automated using the SHUTDOWN command)
5) Inspect your AD security log using Event Viewer, and filter for event ID 539 - this will tell you which machines are infected and need cleaning up.
6) Once all machines are clean, and 539 events do not appear anymore, re-enable the services and open the champagne bottles!
A lot of our customers seem to be getting this feeling. "We've installed patch MS08-067, and removed the worm using our anti-virus or the MSRT, but we keep getting re-infected, " they say. Some even reached the (false) conclusion that 08-067 doesn't work. Well, I can assure you that the patch works, but the worm has several clever secondary infection schemes that make it very slippery.
1. If even a single machine on the network is still infected, it will attack all other machines on the subnet consistently and try to infect them, so until every machine has been cleaned, this problem won't be over.
2. The worm penetrates target machines by using accounts with weak passwords. Resetting all domain passwords and local accounts is a good step. If that's not possible, then the SERVER and TASK SCHEDULER service should also be stopped. This is drastic, but only temporary, while the machines are being cleaned up. Once there are no longer infected machines, these services can be brought back.
This sort of step is a big problem for Server Machines, which needs the Server service to do their job, but sometimes this is what needs to be done. Think of it as quarantining a sick patient until his medicine kicks in.
3. The worm infects removable drives, like USB disks, so if an admin uses a USB disk to copy a removal tool to infected machines, he may be, in fact, contributing to the spread of the worm. This can be averted by setting the removable drives to read-only, if the drive supports it. If your drive doesn't, consider getting an SD with a USB SD Reader, as SD cards all have a read-only physical switch. Another option is to burn a CD with the tools and use it instead of a removable drive.
I've heard from several IT administrators that forcing users to use strong passwords is a problem. In certain environments, where the users are very non-technical or lazy, and have a hard time remembering passwords, this is indeed hard. However, even though resetting passwords for users is an annoying chore, the solution is not to let everybody off with empty or suitcase passwords (1111, 1234 etc), as this worm is specifically designed to take advantage of such environments. An alternative is to use a self-service password reset tool. With this type of thing, a user who forgot his/her password would use another employee's computer, or a designated Kiosk computer to reset his password. Here are several products of this type:
- ADSelfService Plus by ManageEngine (http://manageengine.adventnet.com/products/self-service-password/index.html)
- Desktop Authority® Password Self-Service by ScriptLogic (http://www.scriptlogic.com/Products/password-self-service/)
- SSRPM by Advanced Toolware (http://www.advtoolware.com/software/ss-reset-password/self-service-reset-password-management.asp)
- Self Service Password Reset by JiJi (http://www.jijitechnologies.com/product/self-service-reset-password-management/)
- Quite a few more: http://www.softplatz.com/software/active-directory-password-reset/
Finally, here's a step by step, for an IT administrator in a large organization:
1) Use a Startup script (http://technet.microsoft.com/en-us/library/cc179134.aspx) to stop the SERVER and TASK SCHEDULER on all domain machines:
Net Stop Server
Net Stop Schedule
Or better yet: Set these services to Disabled:
SC CONFIG SERVER start= "disabled"
SC CONFIG SCHEDULE start= "disabled"
2) Use the startup script to deploy the 08-067 patch to all machines
3) Use the startup script to deploy the MSRT in QUIET mode to all machines (http://support.microsoft.com/kb/891716/)
4) Reboot all domain machines to make sure that the patch and MSRT run on all machines (can be automated using the SHUTDOWN command)
5) Inspect your AD security log using Event Viewer, and filter for event ID 539 - this will tell you which machines are infected and need cleaning up.
6) Once all machines are clean, and 539 events do not appear anymore, re-enable the services and open the champagne bottles!
Wednesday, January 28, 2009
Bring in the troops
In recent weeks, the Conficker virus has been causing a lot of havoc everywhere – account lockouts, network congestion and a lot of headaches. People running Symantec anti-virus software know the same virus as “Downadup”, and that’s not the 1st time a Virus gets labeled differently by different companies. After all, there’s no single authority that investigates viruses, but that got me thinking – maybe it’s time we had one.
With things as they are now, it takes the anti-virus market some time to react to new viruses. Each AV vendor gets samples from its customers, analyzes them and issues signature updates to its product. Each vendor uses its own methodology to assign a priority, and as a result, some vendors take longer to react. In the Conficker case, for example, Symantec’s product is still unable to remove the infection today, almost 3 months since the virus’s first appearance. Even when an update is issued, it’s usually available only for customers of AV vendors, while users with AV software are stranded (We’ll discuss the stupidity of not having AV software on your computer another time).
When a new type of virus or disease appears in the real world, no one waits for Pfizer or Bayer to classify it and inform the public. In the USA, we have the Department of Health and Human Services and the CDC (Center for Disease Control), as well as other federal agencies like FEMA to help manage outbreaks. Since computer worms and viruses do have an economic impact, which could easily reach disastrous proportions (like in the case of worms such as MS Blaster, Code-Red and Sasser), I feel that this sort of thing should definitely be at-least shared by the governments of the world. A Federal Malware Research Center could bring some order to this wild field, and have the necessary resources to inform the public of new threats and how to manage them.
And another thing, while we're at it...we should stop giving worms "cool" and distinctive names. Maybe if the latest virus was called "The Dumbass 1", virus writers were a little less proud of themselves. Now seriously, a malware's name is not a big deal, but it's sad to say that the press today is still glorifying viruses, thereby encouraging low-self-esteemed jerks to write them. Writing a virus is stupid and detestable, and this message should be delivered clearly whenever the issue is discussed in the media - no discounts or exceptions.
With things as they are now, it takes the anti-virus market some time to react to new viruses. Each AV vendor gets samples from its customers, analyzes them and issues signature updates to its product. Each vendor uses its own methodology to assign a priority, and as a result, some vendors take longer to react. In the Conficker case, for example, Symantec’s product is still unable to remove the infection today, almost 3 months since the virus’s first appearance. Even when an update is issued, it’s usually available only for customers of AV vendors, while users with AV software are stranded (We’ll discuss the stupidity of not having AV software on your computer another time).
When a new type of virus or disease appears in the real world, no one waits for Pfizer or Bayer to classify it and inform the public. In the USA, we have the Department of Health and Human Services and the CDC (Center for Disease Control), as well as other federal agencies like FEMA to help manage outbreaks. Since computer worms and viruses do have an economic impact, which could easily reach disastrous proportions (like in the case of worms such as MS Blaster, Code-Red and Sasser), I feel that this sort of thing should definitely be at-least shared by the governments of the world. A Federal Malware Research Center could bring some order to this wild field, and have the necessary resources to inform the public of new threats and how to manage them.
And another thing, while we're at it...we should stop giving worms "cool" and distinctive names. Maybe if the latest virus was called "The Dumbass 1", virus writers were a little less proud of themselves. Now seriously, a malware's name is not a big deal, but it's sad to say that the press today is still glorifying viruses, thereby encouraging low-self-esteemed jerks to write them. Writing a virus is stupid and detestable, and this message should be delivered clearly whenever the issue is discussed in the media - no discounts or exceptions.
Monday, January 19, 2009
Never take candy from strangers
Yesterday, my darling wife told me that she got a weird SMS about 9.99$ and she's not sure what it is. Turned out it was from some IQ-Test she took online on FaceBook. When she completed the test, she was asked for her phone, to which her score was sent, along with the message that she just subscribed to a 9.99$ a month service. Clearly, this is a scam, but my sweetheart never thought that something from such a reputable source like FaceBook could be harmful.
"This is exactly how the 1st nasty Viruses/worms started to spread", I told her. A worm would harvest his victims address book, and send itself to all of his recipients. The guy's poor friends and family members would think that this, coming from a friend or family member, must be legit, but of course, it wasn't. Later on, some worms got even cleverer, and spoofed the source address to be someone else from the list, so that the victims could not know who of their close-ones is really the source of the infection.
Luckily, some people have learned to beware of wolves in sheep's clothing, and others are protected by more secure software that wouldn't let them open attachments, but the success of that "service" and others like it shows that apparently, many people still fall for that old trick. Well, if you, or your close ones think that since FaceBook is a legitimate site, then everything on it is too, think again. Pretty much anybody can upload data to FaceBook or write an app for it, and although the site has a lot of security features, it's far from secure. This specific application gives you an IQ test comprised of 10 questions (I won't waste your time with explaining why such a test is closer to guessing your IQ that actually measuring it) and asks for your phone number. To that phone, it sends a confirmation code that you need to punch in to the website, which then sends you an SMS with your so-called IQ. By entering the code, you are actually agreeing to be subscribed to a service that charges 10$ a month. Although this is written both on the website and on the SMS message, some people might miss that, or misunderstand it. Many wouldn't notice another 10$ charge on their cell service bill, and some people are making millions on those people's back.
This type of story shows why information security is more about security than information. Although this is propagated by computers, it could just as easily be done via just the phone, through an interactive TV channel, and many others. Even if you don't like computers, or maybe ESPECIALLY if you don't like computers, this poses a real risk. Not only can you be billed, you can never know for sure where your info will end up in. Maybe tomorrow you'll be flooded with 20 SMSs a day, advertizing the current Viagra or Rolex, or maybe be part of an identity theft operation. The most important lesson here is this: FaceBook is NOT your friend, and neither are MySpace or any other web service. Always assume the worst about an information source, even if you've used it for years and it was great otherwise. The bad guys, or "evil doers" as W likes to call them, are all around, and they will keep on finding new ways to separate us and our money. Just make sure it's not you, and I might also suggest educating your friends and loved ones too.
"This is exactly how the 1st nasty Viruses/worms started to spread", I told her. A worm would harvest his victims address book, and send itself to all of his recipients. The guy's poor friends and family members would think that this, coming from a friend or family member, must be legit, but of course, it wasn't. Later on, some worms got even cleverer, and spoofed the source address to be someone else from the list, so that the victims could not know who of their close-ones is really the source of the infection.
Luckily, some people have learned to beware of wolves in sheep's clothing, and others are protected by more secure software that wouldn't let them open attachments, but the success of that "service" and others like it shows that apparently, many people still fall for that old trick. Well, if you, or your close ones think that since FaceBook is a legitimate site, then everything on it is too, think again. Pretty much anybody can upload data to FaceBook or write an app for it, and although the site has a lot of security features, it's far from secure. This specific application gives you an IQ test comprised of 10 questions (I won't waste your time with explaining why such a test is closer to guessing your IQ that actually measuring it) and asks for your phone number. To that phone, it sends a confirmation code that you need to punch in to the website, which then sends you an SMS with your so-called IQ. By entering the code, you are actually agreeing to be subscribed to a service that charges 10$ a month. Although this is written both on the website and on the SMS message, some people might miss that, or misunderstand it. Many wouldn't notice another 10$ charge on their cell service bill, and some people are making millions on those people's back.
This type of story shows why information security is more about security than information. Although this is propagated by computers, it could just as easily be done via just the phone, through an interactive TV channel, and many others. Even if you don't like computers, or maybe ESPECIALLY if you don't like computers, this poses a real risk. Not only can you be billed, you can never know for sure where your info will end up in. Maybe tomorrow you'll be flooded with 20 SMSs a day, advertizing the current Viagra or Rolex, or maybe be part of an identity theft operation. The most important lesson here is this: FaceBook is NOT your friend, and neither are MySpace or any other web service. Always assume the worst about an information source, even if you've used it for years and it was great otherwise. The bad guys, or "evil doers" as W likes to call them, are all around, and they will keep on finding new ways to separate us and our money. Just make sure it's not you, and I might also suggest educating your friends and loved ones too.
Monday, January 12, 2009
The human factor
Many companies base a significant part of their manpower on outsourced workers, and this is an effective way to conveniently manage human resources that enabled financial efficiency in most cases. An aspect that many managers tend to forget is the issue of security. Are outsourced workers a source of danger to the company?
This post will anger many readers, I’m sure. After all, millions of people make an honest living as outsourced workers and many companies depend on them. However, the truth must be told, even if unpleasant. Outsourced workers could be a major security threat for the organization in many cases, and history records quite a few cases of serious damage suffered by companies that didn’t take the appropriate measures. No, I’m not saying outsourced workers are treacherous, bad or dangerous. In many cases this is exactly the opposite, because employees whose position is not secured as full-time employees will often outperform others to demonstrate their worthiness. However, the outsourcing model causes workers, esp. in the maintenance field, to be exposed to certain risks.
One problem stems from the fact that outsourced workers usually make a lot less money than FTEs. The economic pressure causes these employees to be an easy target for industrial espionage. For example, a known case involved a cleaner who was offered a significant amount in return for a daily visit to the floor-printers of his organization, and collecting the printed matter that was left there by other employees. These print-outs are of random content, but frequently include sensitive material, such as email correspondence, financial reports, future-product info etc. Such a random collection could be extremely valuable for hostile parties, both for industrial espionage and infrastructure penetration. The sum that was offered to that employee was larger than his monthly salary, and you’d be hard-pressed to find people who make 2000$ a month and can resist such a temptation. For some of them, this is a unique opportunity to finally get out of debt.
Another problem is that managers often ignore outsourced workers when thinking about their employees, and these workers are often excluded from routine activities. Often they don’t receive email that is sent to other employees (if they even have an account) or invited to events and lectures with the rest of the company. These employees might miss the companies’ procedures about information security, simply because these were never given to them in an orderly fashion. This is less obvious for technical staff, but in case of the cleaning crew, administration etc – these people are usually with the company for short periods and often do not receive thorough guidance about the procedures and guidelines. An FTE, for example, is often assigned a mentor or “buddy” for a while, who helps him get acquainted and learn what is permissible and what is not. A cleaner or security guard, on the other hand, often finds himself alone, trying to distinguish right from wrong by randomly asking co-workers or guessing. Such an employee might think that using another’s computer for surfing the web is a reasonable thing to do, just like making a phone call from someone’s phone is legitimate and common. In most companies, a phone call costs money, but is not dangerous. Web surfing, on the other hand, could introduce spyware or a virus to the computer, and that is less pleasant.
It’s important to stress once again that the purpose of this is not to impeach all outsourced workers, but to stress the great importance of them to the “system”. This requires that they be treated as equals. Even a temporary and low-ranking worker must receive a detailed guide, including the nuances of working at the company, and stressing the aspects of information security and security policies. Besides clarifying the importance of protecting the company values, such sharing of information could strengthen the bond between the employee and the employer, and reduce the temptation to cross the lines. Let’s not forget, by the way, the full timers could cross the same lines and there are many recorded incidents where even high-ranking officials succumbed to external pressure, or simply prepared a nest for a rainy day. This leads to one conclusion – there is no alternative to professional risk management procedures, which include identifying risk sources and plugging holes on a personal and systematic level.
This post will anger many readers, I’m sure. After all, millions of people make an honest living as outsourced workers and many companies depend on them. However, the truth must be told, even if unpleasant. Outsourced workers could be a major security threat for the organization in many cases, and history records quite a few cases of serious damage suffered by companies that didn’t take the appropriate measures. No, I’m not saying outsourced workers are treacherous, bad or dangerous. In many cases this is exactly the opposite, because employees whose position is not secured as full-time employees will often outperform others to demonstrate their worthiness. However, the outsourcing model causes workers, esp. in the maintenance field, to be exposed to certain risks.
One problem stems from the fact that outsourced workers usually make a lot less money than FTEs. The economic pressure causes these employees to be an easy target for industrial espionage. For example, a known case involved a cleaner who was offered a significant amount in return for a daily visit to the floor-printers of his organization, and collecting the printed matter that was left there by other employees. These print-outs are of random content, but frequently include sensitive material, such as email correspondence, financial reports, future-product info etc. Such a random collection could be extremely valuable for hostile parties, both for industrial espionage and infrastructure penetration. The sum that was offered to that employee was larger than his monthly salary, and you’d be hard-pressed to find people who make 2000$ a month and can resist such a temptation. For some of them, this is a unique opportunity to finally get out of debt.
Another problem is that managers often ignore outsourced workers when thinking about their employees, and these workers are often excluded from routine activities. Often they don’t receive email that is sent to other employees (if they even have an account) or invited to events and lectures with the rest of the company. These employees might miss the companies’ procedures about information security, simply because these were never given to them in an orderly fashion. This is less obvious for technical staff, but in case of the cleaning crew, administration etc – these people are usually with the company for short periods and often do not receive thorough guidance about the procedures and guidelines. An FTE, for example, is often assigned a mentor or “buddy” for a while, who helps him get acquainted and learn what is permissible and what is not. A cleaner or security guard, on the other hand, often finds himself alone, trying to distinguish right from wrong by randomly asking co-workers or guessing. Such an employee might think that using another’s computer for surfing the web is a reasonable thing to do, just like making a phone call from someone’s phone is legitimate and common. In most companies, a phone call costs money, but is not dangerous. Web surfing, on the other hand, could introduce spyware or a virus to the computer, and that is less pleasant.
It’s important to stress once again that the purpose of this is not to impeach all outsourced workers, but to stress the great importance of them to the “system”. This requires that they be treated as equals. Even a temporary and low-ranking worker must receive a detailed guide, including the nuances of working at the company, and stressing the aspects of information security and security policies. Besides clarifying the importance of protecting the company values, such sharing of information could strengthen the bond between the employee and the employer, and reduce the temptation to cross the lines. Let’s not forget, by the way, the full timers could cross the same lines and there are many recorded incidents where even high-ranking officials succumbed to external pressure, or simply prepared a nest for a rainy day. This leads to one conclusion – there is no alternative to professional risk management procedures, which include identifying risk sources and plugging holes on a personal and systematic level.
Friday, January 2, 2009
Is it safe? Not if you're Jewish!
The fighting in Israel in the past days is having an impact on the cyber world as well. This time, two major Israeli sites - Ynet and Discount Bank have been defaced.
When the fighting between Israel and this-or-that Arab faction breaks out, as happens once every few months, national hackers from around the globe have an excuse to waging some cyber war. This time, a group of Morrocan hackers called "Team Evil" has mounted a successful attack against two major Israeli sites. The two sites are the site belonging to Discount Bank, one of Israel's largest banks, and the other is the English version of YNet, Israel's 2nd largest web portal, operated by Yedioth Aharonot, Israel's largest daily newspaper.
The defacement shows some graphic images of dead terrorists, accompanied by anti-Israeli text. At 1st, this was thought to be a simple deface, but turns out the hackers actually brute-forced the passwords to the accounts of the sites on the Israeli hosting provider and domain registrar DomainTheNet. this allowed the hackers to impersonate the account holders and modify the DNS records to point to another website, without ever actually penetrating the original website.
This sort of attack is much easier than cracking the original websites, which are very secure, but ironically, harder to resolve. DNS modifications take time to propagate throughout the world - as long as 48 hours, so it took quite a while until the hack got noticed. When it was fixed, again, it takes a while to propagate so currently, quite a lot of users will still get the defaced page and might continue to be affected for over a day.
This breach illustrates the importance of creating a complete security policy. A company can invest millions in securing it's web farm, but a minor overlooked password could lead to an effective attack. The lesson is simple - when securing a resource, we must take into consideration every aspect of its security. In this case, the person who created the domain account with DomainTheNet simply chose an insecure password (which is a secondary lesson in this case) but there are other, simpler ways to bypass security. For example, making changes to a domain directly with ISOC, Israel's Internet Society and main registrar involves submitting a request via a web form, and then completing the request by sending a fax. The web form has virtually no security, and forging a fax of this nature is also pretty easy. Another example: Many companies rely on Email a primary, or even the only way to communicate with customers. Hacking a user's mail account is usually pretty easy, either by using brute force or calling the ISP and resetting the password, and once you have someone's email, you can use that to reset passwords of most other accounts that the user has. In short, there's an old expression to keep in mind: The chain is only as strong as its weakest link!
When the fighting between Israel and this-or-that Arab faction breaks out, as happens once every few months, national hackers from around the globe have an excuse to waging some cyber war. This time, a group of Morrocan hackers called "Team Evil" has mounted a successful attack against two major Israeli sites. The two sites are the site belonging to Discount Bank, one of Israel's largest banks, and the other is the English version of YNet, Israel's 2nd largest web portal, operated by Yedioth Aharonot, Israel's largest daily newspaper.
The defacement shows some graphic images of dead terrorists, accompanied by anti-Israeli text. At 1st, this was thought to be a simple deface, but turns out the hackers actually brute-forced the passwords to the accounts of the sites on the Israeli hosting provider and domain registrar DomainTheNet. this allowed the hackers to impersonate the account holders and modify the DNS records to point to another website, without ever actually penetrating the original website.
This sort of attack is much easier than cracking the original websites, which are very secure, but ironically, harder to resolve. DNS modifications take time to propagate throughout the world - as long as 48 hours, so it took quite a while until the hack got noticed. When it was fixed, again, it takes a while to propagate so currently, quite a lot of users will still get the defaced page and might continue to be affected for over a day.
This breach illustrates the importance of creating a complete security policy. A company can invest millions in securing it's web farm, but a minor overlooked password could lead to an effective attack. The lesson is simple - when securing a resource, we must take into consideration every aspect of its security. In this case, the person who created the domain account with DomainTheNet simply chose an insecure password (which is a secondary lesson in this case) but there are other, simpler ways to bypass security. For example, making changes to a domain directly with ISOC, Israel's Internet Society and main registrar involves submitting a request via a web form, and then completing the request by sending a fax. The web form has virtually no security, and forging a fax of this nature is also pretty easy. Another example: Many companies rely on Email a primary, or even the only way to communicate with customers. Hacking a user's mail account is usually pretty easy, either by using brute force or calling the ISP and resetting the password, and once you have someone's email, you can use that to reset passwords of most other accounts that the user has. In short, there's an old expression to keep in mind: The chain is only as strong as its weakest link!
Subscribe to:
Posts (Atom)
