Happy New Year
securityorb.com/ would like to wish the InfoSec community a wonderful and safe Happy 2012 New Year!
securityorb.com/ would like to wish the InfoSec community a wonderful and safe Happy 2012 New Year!
The Stop Online Piracy Act (SOPA) introduced in October has been delayed until sometime in 2012. SOPA’s goal is to aid with the ongoing dilemma of copyright infringement, pirating, and/or the counterfeiting of intellectual property many US based media companies are facing by foreign and some domestic websites.
The scheme behind SOPA is to disable or withhold services from infringing sites by requiring Internet search providers, payment processors and other Internet related entities to deny services.
Support for the legislation is coming from media organizations such as the Motion Picture Association of America (MPAA) and the Recording Industry Association of America (RIAA) while tech industry giants such as Google, Yahoo, and Facebook to name a few are opposed to the bill.
The tech industry feels protecting content is a worthy goal and should be pursued, but fears the content within the bill can lead to unintended consequences. For example, copyright holders would be able to find fault on a website, contact law enforcement officials, and get websites shut down or denied services. Furthermore, tech companies such as Google could face punishment if a pirated TV show is uploaded to YouTube.
SOPA is a change from the current process based on the 1998 Digital Millennium Copyright Act, which expect companies to “act in good faith” when a copyright holder asks them to remove pirated content. However, under SOPA, sites could be punished first place and Internet companies are worried that they could be held liable for users’ actions.
While the media industry states online piracy websites such as The Pirate Bay which operates outside of the U.S. allows illegal downloads of movies, music and other digital content leads to U.S. job losses by depriving content creators income.
A similar bill to SOPA titled the Protect IP Act, was approved by a Senate committee in May of 2011, and is now pending before the full Senate. In addition, a bipartisan group of House members has proposed an alternative bill titled the Online Protection and Enforcement of Digital Trade Act (OPEN).
Even though both the media organizations and tech companies have suitable reasoning for supporting and opposing the bill, I think the tech industry and small bloggers and media organizations are at the most risk if this bill where to past. If a media organization accuses them of using their content in an inappropriate manner, request for that site to be denied of service, many of them do not have the resources for legal services to rectify the matter, thus allowing the media industry full power.
EARLY REGISTRATION ENDS DEC. 31
11th Annual DoD Cyber Crime Conference 2012
Hyatt Regency Atlanta, Atlanta, GA
Pre-Con Training: Jan. 20-23 | Conference: Jan. 23-27 | Exposition: Jan. 24-26
www.DoDCyberCrime.com
REGISTER TODAY to learn from the experts about revolutionary technologies and techniques for exposing and preventing cyber crime. Hotel space is filling up quickly, so make your reservations now.
This the only program that brings together legal, information technology, investigative, and digital forensic communities for an open and interactive forum to facilitate information sharing, hands-on digital forensics training, and team building on issues facing the DoD, as well as Federal, State and Local governments and their industry partners within the cyber crime arena.
CONFERENCE FEATURES
• Pre-Conference Hands-on Digital Forensics Training Courses (attorneys can earn CLEs), including
SANS Lethal Digital Forensic Techniques and Memory Analysis
• Classified Cyber Threat Session
• 21 Concurrent Breakout Sessions
• Forensic Tool Expo
• 80+ Exhibitors
• DC3 Digital Crime Scene Challenge (new to the 2012 Conference!)
• 6th Annual DC3 Digital Forensic Challenge Awards Presentations (challenge occurs prior to
conference: www.dc3.mil/challenge)
BREAKOUT TRACKS
The conference team has developed targeted breakout tracks focusing on Digital Forensics, Defense Industrial Base, Information Assurance, Law Enforcement/Counterintelligence, Legal, and Research and Development.The tracks include almost 200 sessions and provide attendees with a forum to discuss issues and solutions, learn new tools of the trade, get an overview of the new technologies driving the industry, and more. Attendees are encouraged to attend sessions from all tracks.
CONFERENCE AGENDA
CONFERENCE SPEAKERS BLOG
CONFERENCE REGISTRATION
Online Conference Registration Deadline: January 13, 2012 REGISTER NOW
ACCOMMODATIONS
Visit the TRAVEL page of the Web site for details about accommodations and travel.
EXHIBITING & SPONSORSHIP OPPORTUNITIES
Exhibit space and sponsorships are selling out very quickly. For vendor opportunities at this event view the EXHIBITOR PROSPECTUS.
Visit the event Web site for detailed event information: www.DoDCyberCrime.com
CONTACTS
Attendance: Sharla Warren, (703) 740-1950, SWarren@GovernmentMeetings.com
Speaker Services: Marnie Herren, (703) 740-1933, MHerren@GovernmentMeetings.com
As the holiday season steadily approaches, many individuals are planning to upgrade their current technology devices with the latest and greatest on the market. For example, individuals who currently possess an older iPhone such as the 3gs or iPhone 4 are eyeing the new iPhone 4s with the Siri feature. While android-based users have a tons of options to be excited about with the resent releases of the Nexus, RAZR and Galaxy smart phones totting the new Android 4.0 operating system titled Ice Cream sandwich. Then you have to take into consideration other tech gadgets and devices such as tablets, e-readers, netbooks, laptops and computers.
A recent survey conducted by the Public Broadcasting System (PBS) stated 49% of parents plan to give their kids a technology device this upcoming Christmas and many of these devices will be their old hand me downs.
With that said, securityorb.com/, an information security and privacy awareness site recommends that before you give away or throw away any of your electronic devices, make sure you wipe them clean. A disk/memory wipe is a secure manner to remove all existing data on a hard drive and memory card so the data cannot be retrieved.
This is important when you take into consideration the types of information we store on our smart phones these days such as pictures, account information, contacts etc.
Giving a device to a kid without properly wiping it clean can lead to issues to put your personal information at risk such as theft or lost of the device. Furthermore, it may also be costly experience if your credit information is tied into the manufacture’s app market space. Numerous apps maybe downloaded on your dime.
The same consideration should also take place if you plan to get rid of other technology such as an old computer. You want to wipe the hard drive before deposing of the system. Identity theft scammers know this is a great source to obtain information to fuel their malicious activity. Using software such as Disk Wipe can erase all disk data and prevent recovery of that data and it is free too. The EPA also has a list of recommended locations to dispose of your electronic devices in a safe and environmentally friendly manner.
Please remember, before wiping your data on an old device be sure to conduct a backup or transfer all information to the new device. Some services allow you to backup the contents of your mobile device to a cloud for safekeeping.
Below are some tips on how to conduct a hard reset or total disk wipe on some of the more popular devices. I urge you to review your manual or check on the manufacture’s website for a more detailed procedure.
Android phones: Steps to implementing a factory data reset can be done by going to:
Menu -> Settings -> Privacy -> Factory data reset.
BlackBerry phones: Steps to implementing a factory data reset can be done by going to:
Options -> Security Options -> General Settings -> Menu -> Wipe Handheld.
iPhones: Steps to implementing a factory data reset can be done by going to:
Settings -> General category -> Reset
Phishing is defined as the practice of using fraudulent e-mails and fake duplications of legitimate websites to extract financial data from computer users for purposes of identity theft.
Imagine one morning waking up and doing your daily routines, you check your email and see that an email from your bank, EBay, Amazons etc. stating your accounts have a zero balance, then it gave you a link to click. You enter your username/password and all of you’re the information looks correct and logout to continue your day. Later that day you attempt to purchase an item using your debit card and the transaction is decline. You log into your online account to verify the information displayed earlier that day and now your account is cleaned out. You go back to that email click on the link, the site is no longer accessible, and there is no way to track them.
The Phishing fraud operated by the “Phisherman” creating a false duplicate websites of a legitimate financial organization that is well known. It may look like the real thing but it is a clone. They follow up the process by send out a mass email to hundreds of users stating there is a problem with their account. The unsuspected user enters all of the vital information; the site collects the information as well as passes it on to the real server for access. The fictitious site never stays up for long just for a few hours so the “Phisherman” can hook as many phish as they can, then they’re gone like it was never there, that’s why there so hard to track.
There many ways to avoid this:
1. Do not access your account through the email or pop-up.
2. View all email in plain text if possible.
3. Contact the organization using a telephone number.
4. Report the email to your financial institute.
5. Type the web address or use a bookmark for your online banking.
6. Avoid visiting site with expire certificates.
7. Delete the phishing email.
For more information on Phishing, visit these sites below:
What is Carrier IQ?
Carrier IQ is diagnostic software that comes pre-installed on some mobile devices. Mobile network operators use information gathered on your location and call activity to improve network coverage and reduce instances of dropped calls. Recently there has been a large amount of press coverage over the perceived privacy and security violations posed by Carrier IQ software. At Lookout, it is our belief that much of this coverage has been overstated. While there are a number of real privacy issues at play, based on our understanding Carrier IQ is not malware nor has malicious intent. We do believe that companies big and small should always take a transparent approach when it comes to data they are collecting from people.
To find out whether you have Carrier IQ installed on your Android device, download our free Carrier IQ Detector App from the Android Market.
What information is or isn’t collected?
Based on credible reports, it appears that Carrier IQ has the ability to report the following information:
From our current understanding, CarrierIQ does not appear to have the ability to record SMS messages, email content, or the contents of web pages you’ve visited. In addition, Carrier IQ cannot record arbitrary keystrokes (or buttons you press) from your mobile device.
Why is Carrier IQ getting so much attention?
The biggest issue for most users is that they do not know whether they have Carrier IQ on their mobile device. In addition, there is no clear opt-out path available for those users who do have Carrier IQ installed and would prefer not to have it on their device. To find out if you have Carrier IQ on your Android device, download the Carrier IQ Detector app.
Can I remove Carrier IQ from my phone?
Because Carrier IQ software is deeply integrated with the built-in firmware on the mobile device, users would have to get special device privileges (also known as ‘root’ privileges) in order to remove it. Side effects of this process have the potential to put users at further risk of malware infection, while making devices ineligible to receive firmware updates in the future. If you are sure you know what you are doing and would like to remove Carrier IQ software from your phone, there are a number of guides available online.
How do I know if I have Carrier IQ on my phone?
Lookout has recently released Carrier IQ Detector, a free Android application that can quickly determine whether or not you have Carrier IQ software on your mobile device. Download it Now.
Source: Lookout Mobile Security Blog
Threats are constant and evolving. In this security landscape, organizations need to be proficient in both defense AND offense in order to protect themselves. Often we may understand the techniques that our adversaries are using, but somehow still fail to prepare our organizations and people for the attacks. As such, it is time for defenders to become persistent and proactive in trying to exploit their organizational assets, rather than simply waiting until their next audit.
In this Webcast Marcus Carey will discuss various techniques deployed by the current adversaries, and how to simulate those activities with Metasploit. He will also explore the countermeasures available to deterring, detecting, and responding to attacks on your network.
Date: December 7, 2011
Time: 2pm EST
Speaker:
Marcus J. Carey – Security Researcher & Community Manager
Marcus has over 17 years experience in information assurance experience working in the DoD as well as Federal and State Government organizations. Marcus has been a avid user of the Metasploit Framework for over five years. One of his focuses at Rapid7 is to show people that Metasploit is not just for penetration testers.
SANS comes to New Orleans, January 17-26. Start the year off right with our top-rated instructors and outstanding course offerings.
SANS Security East 2012 includes two brand new courses:
Security 524: Cloud Security Fundamentals
Two day course uses a variety of vendor and cloud services in the class, and exposes students to everything from architecture considerations to policy and contract review. SEC524 prepares people for the CCSK (Certificate of Cloud Security Knowledge) and covers a lot of ground including hands-on exercises working with virtual machines.
Link to SEC524 at SANS Security East 2012: http://www.sans.org/info/92934
Security 579: Virtualization and Private Cloud Security
Six day course that takes on the security challenges faced with the rapid movement towards implementing virtualized servers. SEC579 covers architecture and security design, how to design a foundational risk assessment program, and how things change when we move to a cloud environment.
Link to SEC579 at SANS Security East 2012: http://www.sans.org/info/92939
If you have any questions about these courses, feel free to contact Dave Shackleford, SEC524 & SEC579 author and instructor, dshackleford@sans.org.
***** Save $150 off your course by using discount code: Refer_SecOrb *****
Another new course offering will be taught at SANS Security East 2012.
Security 571: Mobile Device Security – Kevin Johnson, SANS Senior Instructor
This course is designed to teach students about the threats organizations are exposed to via the mobile devices on which they depend. This two-day hands-on class uses lecture, labs and real world experiences to educate the students about mobile security within the enterprise.
Link to SEC571 at SANS Security East 2012:
http://www.sans.org/info/92944
For complete details regarding SANS Security East 2012:
http://www.sans.org/info/92949
***** Save $150 off your course by using discount code: Refer_SecOrb *****
SANS is the most trusted and by far the largest source for information security training in the world. They offer training through several delivery methods – live & virtual conferences, mentors, online, and onsite.
Join SANS in 2012 for your training and save $150.00 with the use of our discount code Refer_SecOrb
SANS Security East 2012, New Orleans, LA, will kick off the new year for live training.
SANS Security East 2012 includes two brand new courses:
Security 524: Cloud Security Fundamentals
Two day course uses a variety of vendor and cloud services in the class, and exposes students to everything from architecture considerations to policy and contract review. SEC524 prepares people for the CCSK(Certificate of Cloud Security Knowledge) and covers a lot of ground including hands-on exercises working with virtual machines.
Link to SEC524 at SANS Security East 2012:
http://www.sans.org/security-east-2012/description.php?tid=4996
Security 579: Virtualization and Private Cloud Security
Six day course that takes on the security challenges faced with the rapid movement towards implementing virtualized servers. SEC579 covers architecture and security design, how to design a foundational risk assessment program, and how do things change when we move to a cloud environment.
Link to SEC579 at SANS Security East 2012:
http://www.sans.org/security-east-2012/description.php?tid=5041
SANS Security East 2012 (New Orleans) – January 17-26
http://www.sans.org/security-east-2012
Other upcoming live training events in early 2012:
SANS Monterey 2012 – January 30-February 4
http://www.sans.org/monterey-2012
SANS Phoenix 2012 – February 13-18
http://www.sans.org/phoenix-2012
SANS 2012 (Orlando) – March 23-30
http://www.sans.org/sans-2012
Free wireless hotspots is a huge security and privacy threat since hackers have the tools to really make life difficult. Check out the video below.
Connecting to a random WiFi hotspot is much like strolling into a bar in a strange part of town. Most likely you’ll have a good time, but it could ruin your day. It’s wise to assume that all hotspots harbor predators, and take appropriate precautions.
Source: http://cybercoyote.org/classes/wifi/hotspots.shtml
Laptop road warriors beware: Wi-Fi hot spots that let you hop onto the Internet anywhere you travel leave you wide open to hackers.
Source: http://www.usatoday.com/tech/wireless/2007-08-06-wifi-hot-spots_N.htm
