# SecurityOrb.com — Full Content > Complete content index for LLM consumption > Generated: 2026-10-02 | Posts: 200 --- ## Prepare for the “Intro to LLM Red Teaming Using Garak” Workshop URL: https://securityorb.com/prepare-for-the-intro-to-llm-red-teaming-using-garak-workshop/ Type: post Modified: 2026-09-17 Prepare for the “Intro to LLM Red Teaming Using Garak” Workshop Before attending the Intro to LLM Red Teaming Using Garak workshop, please download the student workbook and one of the preconfigured virtual-machine images listed below. The virtual machines include Garak and a local instance of Microsoft’s Phi-3 language model, allowing you to complete the hands-on activities without relying on an external AI service. Because the virtual-machine files are large, begin downloading them well before the workshop. You need only the image that matches your virtualization software—either VirtualBox or VMware. Required Course Materials1. Student Workbook Download and review the workbook before class: Download the Intro to LLM Red Teaming Student Workbook File: Intro_to_LLM_Red_Teaming_Student_Workbook.docxApproximate size: 84.92 KB The workbook contains workshop concepts, guided exercises, knowledge checks, and space for recording observations and assessment findings. 2. Preconfigured Virtual Machine or Windows Install Choose one of the following images. VirtualBox - credentials for image (secone/secone123) Download the VirtualBox Garak Image File: Garak.ovaApproximate size: 14.08 GB Import the .ova file using the appliance-import feature in Oracle VirtualBox. VMware - credentials for image (secone/secone123) Download the VMware Garak Image File: Lubuntu Garak.zipApproximate size: 15.32 GB Extract the ZIP archive before opening the virtual machine in VMware Workstation, VMware Fusion, or another compatible VMware product. or You can install directly on a Windows computers: GARAK Setup and Download:Start up PowerShell as Admin#Install python version 3.13winget install Python.Python.3.13#Create Project Foldermkdir garak-project#Go to foldercd garak-project#Create Environmentpy -m venv .venv#Allow powershell scriptsSet-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass#Activate Environment.\.venv\Scripts\Activate.ps1#Upgrades and Installs Pippy -m pip install --upgrade pip#Install Garakpy -m pip install -U garak#Ollama Windows Downloadirm https://ollama.com/install.ps1 | iex#Download Phi3 ModelOllama pull phi3#Scan Phi3 with autoDANCached Probepy -m garak --model_type ollama --model_name phi3 --probes dan.AutoDANCached Before the Workshop Please complete the following steps before class: Install or update your preferred virtualization platform.Download the student workbook.Download either the VirtualBox image or the VMware image.Import or open the virtual machine.Start the virtual machine and confirm that the Lubuntu desktop loads successfully.Verify that Garak and the local Phi-3 model are available.Bring the workstation’s administrator credentials in case a local configuration change is needed.Ensure that your computer has enough free disk space for the download, extracted image, snapshots, and workshop output files. At least 35–40 GB of available space is recommended. Depending on your virtualization software, you may be asked whether the virtual machine was moved or copied. Selecting “I copied it” is generally appropriate because it creates new identifiers for your local copy. What We Will Cover This workshop introduces the principles and practice of red teaming applications powered by large language models. We will discuss why traditional software testing is not sufficient by itself for generative AI systems and examine how adversarial testing can reveal unsafe, unreliable, biased, or policy-violating behavior. Topics will include: The purpose, value, and limitations of LLM red teamingCommon risks associated with generative AI applicationsThreat modeling and defining the scope of an assessmentUnderstanding Garak probes, generators, detectors, and reportsConfiguring Garak to test a locally hosted language modelRunning focused and grouped probe evaluationsInterpreting results without treating automated findings as definitiveRecognizing prompt-injection, jailbreak, content-safety, and misuse risksDocumenting evidence and distinguishing true findings from false positivesDeveloping practical recommendations for model and application developersApplying age-appropriate safety criteria to applications intended for childrenHands-On Activities During the workshop, you will use Garak to evaluate the local Phi-3 model. Activities will include executing selected probes, reviewing model responses, locating Garak reports, and assessing whether observed behavior represents an acceptable risk. A major exercise will place you in the role of a red-team assessor reviewing a generative-AI application designed to communicate with middle-school students. You will investigate areas such as jailbreak resistance, slur generation, bullying, sexualized content, and attempts to conceal unsafe instructions. Based on the evidence, you will decide whether the application should be approved, conditionally approved, or rejected and provide recommendations to its developers. Important Testing Guidance All workshop testing must remain inside the authorized lab environment. Do not direct probes at public systems, production applications, or third-party services without explicit written authorization. Some test prompts and model responses may contain offensive, discriminatory, sexualized, or otherwise disturbing material. These examples are included strictly for controlled security testing and educational analysis. Handle generated reports responsibly, avoid unnecessarily reproducing harmful content, and follow the instructor’s guidance throughout the exercises. Need Help Before Class? If the download, extraction, or virtual-machine import fails, record the error message and contact the instructor before the workshop. Resolving setup issues in advance will allow us to spend class time on red-teaming techniques and hands-on analysis. Please arrive with the workbook downloaded and the virtual machine successfully started. We look forward to exploring how structured adversarial testing can help make generative-AI systems safer, more reliable, and better suited to their intended audiences. --- ## Comprehensive Guide to CISSP: A Review of "CISSP All-in-One Exam Guide, Ninth Edition" by Shon Harris and Fernando Maymi URL: https://securityorb.com/comprehensive-guide-to-cissp-a-review-of-cissp-all-in-one-exam-guide-ninth-edition-by-shon-harris-and-fernando-maymi/ Type: post Modified: 2026-08-24 Rating: ★★★★★ The Certified Information Systems Security Professional (CISSP) certification is a prestigious credential sought after by professionals in the field of cybersecurity. To navigate the complexities of the CISSP exam, candidates often turn to trusted study resources. "CISSP All-in-One Exam Guide, Ninth Edition" by Shon Harris and Fernando Maymi has long been considered a go-to reference for CISSP aspirants. In this comprehensive review, we will explore the book's content chapter by chapter. Chapter 1: Introduction to the CISSP Certification The authors kick off the book by providing an overview of the CISSP certification and the domains it covers. They explain the exam format and set the stage for the journey ahead. Chapter 2: Security and Risk Management This chapter delves into fundamental concepts of security and risk management. Harris and Maymi do an excellent job explaining key principles and frameworks, such as confidentiality, integrity, availability (CIA), and risk assessment. Chapter 3: Asset Security The authors explore the protection of assets in this chapter, covering topics like data classification, ownership, and data retention policies. They also discuss physical security measures and the importance of asset management. Chapter 4: Security Architecture and Engineering This section provides insights into security architecture, system design, and secure development practices. It's a critical chapter for those wanting to understand the design principles of secure systems. Chapter 5: Communication and Network Security Communication and network security are crucial in today's interconnected world. Harris and Maymi guide readers through the essentials of network security, including protocols, devices, and best practices. Chapter 6: Identity and Access Management Access control is a fundamental aspect of cybersecurity. This chapter explores identity management, authentication, authorization, and access control models in depth. Chapter 7: Security Assessment and Testing For a secure system, continuous testing is essential. This chapter covers various assessment and testing methodologies, including vulnerability assessment and penetration testing. Chapter 8: Security Operations This section delves into security operations, incident response, disaster recovery, and business continuity planning. It provides a holistic view of how organizations should handle security incidents and maintain business continuity. Chapter 9: Software Development Security Secure software development is a key concern in the digital age. The authors discuss secure coding practices, secure development life cycles, and common software vulnerabilities. Chapter 10: Security and Risk Management The final chapter revisits the security and risk management domain, summarizing key concepts and emphasizing their importance in the CISSP exam. Appendices and Additional Resources The book also includes valuable appendices that provide supplemental information, such as a glossary, exam tips, and practice questions. It's a great resource for reinforcing your knowledge. In conclusion, "CISSP All-in-One Exam Guide, Ninth Edition" by Shon Harris and Fernando Maymi is a comprehensive and well-structured resource for CISSP aspirants. The chapter-by-chapter breakdown ensures that readers can approach each domain with clarity and depth. The authors' expertise shines through in their clear explanations and practical insights. However, it's important to note that this book is an excellent study guide but should be supplemented with real-world experience and additional practice exams. If you are serious about earning your CISSP certification, this book should be a key component of your study plan. --- ## Reflecting on National Cybersecurity Awareness Month 2023: A Call for Continued Vigilance URL: https://securityorb.com/reflecting-on-national-cybersecurity-awareness-month-2023-a-call-for-continued-vigilance/ Type: post Modified: 2026-08-24 October is recognized as Cyber Security Awareness Month and as we come to the end of the month, so does National Cybersecurity Awareness Month (NCSAM) 2023. This annual observance, dedicated to promoting cybersecurity awareness, provides a valuable opportunity to reflect on the critical issues surrounding digital safety, the history of NCSAM, and the imperative of continued vigilance in the face of evolving cyber threats. The History of National Cybersecurity Awareness Month NCSAM is celebrated every October, and it was established in 2004. This initiative originated as a joint effort between the U.S. Department of Homeland Security (DHS) and the National Cyber Security Alliance (NCSA) and has since expanded to include participation from government agencies, educational institutes, businesses, and individuals around the world. The primary objective of NCSAM is to increase awareness about the importance of cybersecurity and to promote the adoption of best practices to protect individuals, businesses, and national security interests. Over the years, the campaign has focused on themes such as "Stop. Think. Connect." and "Own IT. Secure IT. Protect IT." These themes emphasize the need for responsible online behavior and the safeguarding of personal and sensitive data. The Importance of Cybersecurity Awareness With the conclusion of NCSAM in the next few days at the end of October, it is important to remember that cybersecurity awareness is a year-round commitment. Cybersecurity touches every aspect of our digital lives, from safeguarding personal information to protecting the economy and national security. As technology advances and cyber threats become more sophisticated, our vigilance must remain constant. Here are three critical aspects of cybersecurity that deserve ongoing attention: Multifactor Authentication (MFA) One of the most effective ways to bolster online security is through the use of multifactor authentication (MFA). MFA requires users to provide two or more forms of identification before granting access to an account or system. This additional layer of security significantly reduces the risk of unauthorized access, even if a password is compromised. Individuals and organizations should embrace MFA for their online accounts, email, social media, and work-related applications. The ease of implementation and the considerable improvement in security make MFA a simple but powerful tool in the fight against cyber threats. Phishing Awareness Phishing awareness is a critical component in the defense against cyber attacks, benefiting both individual users and businesses. For individual users, understanding the tactics employed by cybercriminals in phishing attacks can make them more alert and watchful when interacting with emails, websites, and messages. By recognizing the characteristics of phishing, such as suspicious email addresses, grammar errors, and urgent requests for personal information, users can avoid falling victim to scams that can compromise their personal and financial information. This awareness allows individuals to take practical steps in protecting themselves and their families from the devastating consequences of identity theft and financial fraud. As it relate to businesses, phishing awareness is vital for safeguarding sensitive corporate data and preserving the integrity of operations. Employees who are well-informed about the dangers of phishing are less likely to click on malicious links, share sensitive data, or download harmful attachments. This not only reduces the risk of data breaches but also helps maintain the company's reputation and customer trust. Closing the Cybersecurity Workforce Gap The cybersecurity workforce gap is a growing concern globally, and the United States is no exception. The demand for skilled cybersecurity professionals far outpaces the available talent. Closing this gap is essential to protecting our digital infrastructure and national security. To address this issue, we must encourage educational programs that prepare the next generation of cybersecurity experts. Public and private sectors should work together to create incentives for individuals to pursue careers in cybersecurity. As technology continues to advance, the need for a strong cybersecurity workforce is only set to increase.   Conclusion In conclusion, as National Cybersecurity Awareness Month comes to an end in October, it is essential to recognize that our commitment to cybersecurity must persist throughout the year. Cyber threats do not adhere to a calendar; they are a constant and evolving challenge. By employing practices such as multifactor authentication, phishing awareness campaigns and addressing the cybersecurity workforce gap, we can better protect our digital lives, the economy, and national security. Let NCSAM be a reminder that cybersecurity awareness is not limited to a month but is a commitment that must remain a priority in our ever-connected world. --- ## October is Cybersecurity Awareness Month: Why Cyber Basics Still Matter URL: https://securityorb.com/october-is-cybersecurity-awareness-month-why-cyber-basics-still-matter/ Type: post Modified: 2026-08-16 As October kicks off, we are reminded of the importance of Cybersecurity Awareness Month and Cybersecurity Career Awareness Week. These initiatives serve not just to raise awareness but to equip everyone—from individuals to organizations—with the tools and knowledge to protect against the growing wave of cyber threats. Between strong passwords, 6-digit PINs, and fingerprints scanned into our devices, cybersecurity is ingrained into our daily routines. When done correctly, these small but impactful actions greatly enhance our online safety, providing peace of mind that our data, finances, and families are protected. While technological advancements like artificial intelligence (AI) have transformed the cybersecurity landscape, the basics are as essential as ever. This year’s Cybersecurity Awareness Month highlights four simple yet powerful ways to stay safe online: Use Strong Passwords and a Password Manager Turn On Multifactor Authentication (MFA) Update Your Software Recognize and Report Phishing Let’s Dive into Each Key Message Use Strong Passwords and a Password Manager The foundation of good cybersecurity starts with strong, unique passwords. Unfortunately, only 38% of people use unique passwords for all their accounts, according to the National Cybersecurity Alliance’s 2023 Oh, Behave! report. Creating complex passwords and leveraging a password manager makes it easier to maintain these standards across multiple accounts, ensuring that even if one password is compromised, others remain secure. Turn On Multi-factor Authentication (MFA) MFA adds an additional layer of protection by requiring something you know (password) and something you have (like a mobile device) to access your accounts. The report found that 79% of people are familiar with MFA, but only 70% actually know how to use it. MFA can significantly reduce the risk of unauthorized access, especially if passwords are weak or compromised. Update Your Software Whether it's your phone, laptop, or an app you use, keeping your software up to date is a simple yet often overlooked cybersecurity measure. Software updates patch security vulnerabilities, and ignoring these updates leaves systems open to exploitation. Despite this, only 36% of people install updates as soon as they are available. It’s essential to stay current with updates to protect your devices from emerging threats. Recognize and Report Phishing Phishing continues to be a prevalent threat, yet many individuals feel confident in recognizing phishing attempts, with 69% of respondents expressing confidence in this area. However, phishing attempts are becoming increasingly sophisticated. Training yourself to recognize suspicious emails and promptly reporting them can help prevent falling victim to such attacks. While 51% of Americans report cybercrimes, it’s vital that this percentage continues to rise. Why Cyber Basics Are Still the Best Defense In a world of advancing cyber threats, returning to the basics offers a robust defense. By implementing strong passwords, MFA, software updates, and learning to recognize phishing, individuals and businesses alike can drastically reduce their vulnerability to cyber attacks. The statistics in the Oh, Behave! report underscore the importance of continued awareness and education. While 84% of people see online safety as a priority, there’s a gap between understanding and action. The tools are there, but habits need to catch up. Fast Facts: Cybersecurity in 2023 84% of people consider online safety a priority. Only 38% use unique passwords across all accounts. About one-third of people started using a password manager after cyber training. 79% are familiar with MFA, and 70% know how to use it. Only 36% always install software updates when available. 69% are confident in identifying phishing attempts. 51% of Americans actively report cybercrimes. Cybersecurity Career Awareness Week: Encouraging the Next Generation During this month, it’s also crucial to recognize Cybersecurity Career Awareness Week, which aims to inspire more people to explore careers in this field. With a growing demand for skilled professionals, now is an opportune time for students and those looking to switch careers to consider joining the cybersecurity workforce. Cybersecurity offers opportunities to solve real-world problems, safeguard organizations, and be at the cutting edge of technological advancement. Final Thoughts Cybersecurity Awareness Month provides a timely reminder that cybersecurity starts with everyday habits. Whether you’re securing personal devices, protecting your family, or considering a career in cybersecurity, the basics still hold the most power. By adopting these practices and sharing the message with others, we can collectively make the digital world a safer place. As we move forward, remember: Use strong passwords, turn on MFA, update your software, and always report phishing attempts—the simple steps that can make a world of difference. --- ## AI in Cybersecurity and Cybersecurity in AI URL: https://securityorb.com/ai-in-cybersecurity-and-cybersecurity-in-ai/ Type: post Modified: 2026-08-16 The concepts of "AI in Cybersecurity" and "Cybersecurity in AI" address distinct but interrelated issues in the realm of technology and security. Here’s a breakdown of the differences: AI in Cybersecurity Definition: This refers to the application of artificial intelligence (AI) technologies to enhance and improve cybersecurity measures. Key Areas and Applications: Threat Detection and Response: AI algorithms can analyze vast amounts of data to detect anomalies and potential threats much faster than traditional methods. Machine learning models can identify patterns associated with malware, phishing, and other cyber threats. Automation: Automating repetitive tasks such as monitoring and responding to security incidents. AI-driven systems can prioritize and respond to alerts, reducing the workload on human analysts. Predictive Analytics: Predicting future attacks by analyzing historical data and identifying trends. Proactive threat hunting and vulnerability assessments. Behavioral Analysis: Monitoring user behavior to detect insider threats and compromised accounts. Continuous authentication systems that adapt based on user behavior. Adaptive Security: Systems that adapt their defense mechanisms in real-time based on the evolving threat landscape. Benefits: Enhanced detection and mitigation of threats. Improved efficiency and reduced response times. The ability to handle large-scale data and complex threat environments. Cybersecurity in AI Definition: This pertains to the measures taken to ensure the security of AI systems themselves, safeguarding them from various threats and vulnerabilities. Key Areas and Applications: Data Integrity and Privacy: Ensuring the data used to train AI models is accurate, unaltered, and free from biases or malicious tampering. Protecting sensitive information and maintaining privacy throughout the AI lifecycle. Model Security: Protecting AI models from adversarial attacks where attackers manipulate input data to deceive the model. Guarding against model theft, where proprietary models are stolen or replicated by unauthorized parties. Algorithm Robustness: Developing robust algorithms that can withstand attempts to exploit their weaknesses. Implementing techniques to detect and mitigate adversarial attacks on AI systems. Deployment Security: Securing the environment in which AI models are deployed, including cloud infrastructure and edge devices. Ensuring that AI systems are resilient against denial-of-service (DoS) attacks and other disruptions. Governance and Compliance: Establishing policies and frameworks to ensure AI systems comply with legal and regulatory requirements. Implementing ethical guidelines to prevent misuse of AI technologies. Benefits: Protects the integrity and functionality of AI systems. Ensures the trustworthiness and reliability of AI outputs. Prevents malicious exploitation of AI technologies. Summary AI in Cybersecurity focuses on leveraging AI to enhance the capabilities of cybersecurity measures, providing more effective and efficient protection against cyber threats. Cybersecurity in AI, on the other hand, involves protecting AI systems from threats, ensuring their integrity, and securing the data and models they rely on. Both are crucial in the modern technological landscape, as AI becomes more integrated into various systems and processes, and the need to protect both the technology and its applications grows. Audio Podcast - https://notebooklm.google.com/notebook/77f36366-fc94-42a3-bc7d-02ca41a8a352/audio --- ## Basic Linux Commands URL: https://securityorb.com/basic-linux-commands/ Type: post Modified: 2023-07-31 ls - List files and directories in the current directory. Example: ls Explanation: This command will display a list of files and directories in the current location. pwd - Print working directory. Example: pwd Explanation: This command shows the path of the current directory you are in. cd - Change directory. Example: cd /home/user/documents Explanation: This command changes the current directory to "/home/user/documents". mkdir - Make directory. Example: mkdir new_folder Explanation: This command creates a new directory named "new_folder" in the current directory. rmdir - Remove directory. Example: rmdir empty_folder Explanation: This command deletes an empty directory named "empty_folder" from the current directory. cp - Copy files or directories. Example: cp file.txt /path/to/destination Explanation: This command copies "file.txt" to the specified destination path. mv - Move or rename files or directories. Example 1: mv file.txt /path/to/destination Explanation 1: This command moves "file.txt" to the specified destination path. Example 2: mv old_file.txt new_file.txt Explanation 2: This command renames "old_file.txt" to "new_file.txt". rm - Remove files or directories. Example 1: rm file.txt Explanation 1: This command deletes the file named "file.txt". Example 2: rm -r folder Explanation 2: This command deletes the "folder" directory and all its contents recursively. touch - Create an empty file or update the file's timestamp. Example 1: touch new_file.txt Explanation 1: This command creates a new empty file named "new_file.txt". Example 2: touch existing_file.txt Explanation 2: This command updates the timestamp of the "existing_file.txt" without changing its content. cat - Concatenate and display the content of files. Example: cat file.txt Explanation: This command displays the content of "file.txt" on the terminal. more / less - Display the content of files page by page. Example: less large_file.txt Explanation: This command allows you to view the content of "large_file.txt" page by page, making it easier to read large files. head - Display the beginning of a file. Example: head file.txt Explanation: This command shows the first few lines of "file.txt". tail - Display the end of a file. Example: tail file.txt Explanation: This command shows the last few lines of "file.txt". grep - Search for a pattern in files. Example: grep "keyword" file.txt Explanation: This command searches for the word "keyword" in "file.txt" and displays matching lines. echo - Print a message or value to the terminal. Example: echo "Hello, World!" Explanation: This command prints the message "Hello, World!" to the terminal. chmod - Change file permissions. Example: chmod +x script.sh Explanation: This command adds the executable permission to "script.sh", allowing it to be run as a script. chown - Change file ownership. Example: chown user:group file.txt Explanation: This command changes the owner and group of "file.txt" to the specified user and group. ps - Display the currently running processes. Example: ps aux Explanation: This command shows a list of all running processes on the system along with additional details. kill - Terminate a process. Example: kill PID Explanation: This command sends a termination signal to the process with the specified PID (Process ID). top - Display dynamic real-time information about running processes. Example: top Explanation: This command provides a live view of the system's processes, updating regularly. These are just some of the most basic Linux commands. The Linux command line offers a plethora of powerful utilities and options to explore and master. --- ## Top 5 Open Source Vulnerability Security Scanning Tools URL: https://securityorb.com/top-5-open-source-vulnerability-security-scanning-tools/ Type: post Modified: 2023-04-21 Nmap: Nmap is a powerful open source network exploration and security auditing tool that can help identify vulnerabilities in a system. It is widely used for port scanning, version detection, and network mapping. Nmap can also be used for vulnerability scanning by detecting known vulnerabilities in software and services running on a system. OpenVAS: OpenVAS is an open source vulnerability scanner that can be used to scan for known vulnerabilities in software and services on a network. It is a powerful tool that can perform comprehensive scans of networks, identify vulnerabilities, and generate reports. Metasploit Framework: Metasploit is a popular open source penetration testing framework that can be used to identify and exploit vulnerabilities in systems. It can also be used for vulnerability scanning by running exploit modules that detect known vulnerabilities in software and services. Nikto: Nikto is an open source web server scanner that can be used to identify vulnerabilities in web servers and web applications. It can perform comprehensive scans of web servers, identify vulnerabilities, and generate reports. Lynis: Lynis is an open source security auditing tool that can be used to scan for security vulnerabilities in Linux and Unix systems. It can identify vulnerabilities in the system configuration, installed software, and system security settings. Lynis is lightweight and easy to use, making it a popular choice for security professionals. These tools are popular among security professionals because they are open source, free to use, and can be customized to meet specific security needs. They are also regularly updated by their communities, which ensures that they are kept up-to-date with the latest threats and vulnerabilities. Additionally, they are user-friendly and come with detailed documentation and tutorials, making them accessible even to non-experts. --- ## The Benefits of Sock Puppets in Open-Source Intelligence (OSINT) URL: https://securityorb.com/the-benefits-of-sock-puppets-in-open-source-intelligence-osint/ Type: post Modified: 2022-09-25 A Sock Puppet is fake persona, or an alternative online identity used to collect and investigate open-source information on a target.  The main goal of the Sock Puppet is to not have the profile linked back to the investigator. This is vital as to provide operational security (OPSEC) to protect the investigator from retaliation or to prevent bringing awareness to the target that they are being investigated by a specific entity. Maintaining and managing a sock puppet also requires a detailed understanding of the many different platforms the investigator will used to create accounts for the fake persona.  As these policies change, so can the information that is disclosed or shared publicly. To effectively create and use a functional sock puppet here are a few recommendations: To anonymize the account so that it does not record the original IP address or location, the use of a VPN or TOR while creating the account is highly recommended. In addition, it is recommended doing so from a public Wi-Fi connection. Certain social media platforms such as Facebook may prevent individuals from creating an account from a VPN or TOR connect. In that case, using a public Wi-Fi is recommended. When logging to the sock account, be sure to always use a VPN, TOR or public Wi-Fi, under no circumstances should the creator use a direct IP address that may link back to them. Make the account as legitimate as possible by producing daily activities, using it for a long period of time and making online connections. When creating a name for the account, it is recommended using a fake name generator. In doing so, the investigator will be provided with an identity of a person that has never existed.  The identity will have a name, address, mother’s maiden name, weight, height, date of birth, in addition to many other useful information need to create a person.  Female accounts then to have more success when creating a sock puppet. https://www.fakenamegenerator.com/ Now that an identity has been created, providing an image is highly recommended. The creator has two options, using a cartoon avatar or providing an image of a human that does not exist through the use of artificial intelligence.  Never use a real person’s face as individuals can use tools such as Google identify the photo’s original owner. https://thispersondoesnotexist.com/ When creating an email account for the sock puppet, it is recommended using any email provider such as gmail.com, mail.com or yahoo.com to name a few. As previously stated, be sure the IP address cannot be link to the creator. Obtain a burner cell phone and SIM card that can be used account verification. Be sure to not have the phone linked back to the investigator by paying with cash or a privacy-based credit card. Having more than one sock puppet is highly recommended in case something goes wrong, the investigator will have an active back-up. Sock Puppets are important for the protection of the investigator, things change fast in the online world, and it is important the investigator keep up with the changes. --- ## The Open-Source Intelligence (OSINT) Cycle URL: https://securityorb.com/the-open-source-intelligence-osint-cycle/ Type: post Modified: 2022-09-19 Open-source intelligence, or OSINT, refers to the process of collecting information from public and legal data sources to serve a specific function. Some open sources components might include social media, videos, blogs, news, and the web (surface, Deep and Dark Web). OSINT encompasses 5 phases in its process. The following diagram shows the OSINT cycle. Source Identification - It is the initial phase of the OSINT process. The OSINT investigator (Black Hat or White Hat) identifies the potential sources from which information will be gathered. Data harvesting - In this phase, the OSINT investigator collects and harvests information from the select sources and other sources that are discovered. Data processing and information- During this phase, the OSINT investigator processes the harvest information for actionable observation by searching for information that may assist in the enumeration. Data analysis - In this phase, the OSINT Investigator performs data analysis of the processed information using OSINT analysis tools and techniques. Results delivery - It is the final phase in the OSINT analysis and findings are reported to the stake holders. --- ## Benefits of STEM Summer Camps URL: https://securityorb.com/benefits-of-stem-summer-camps/ Type: post Modified: 2022-03-20 STEM summer camps can make summer learning fun and exciting by teaching kids about science, technology, engineering, and math.  The camps can give children an opportunity to continue learning more about a concept they were introduced to during the school year or event explore different STEM concepts they may not learn about in their classrooms. In just one summer, kids discover not only their passion for learning but perhaps even their future career path. Learn Basic STEM Skills Instead of forgetting the STEM concepts they’ve learned at school, kids can practice those concepts and apply them in hands-on activities and real-life scenarios.  For example, using robotics to implement a manufacturing solution, implementing code to sort through data or conducting a chemical experience to determine the acidity. In addition to the STEM activities, participant of the camo will start developing soft skills like communication, critical thinking, and problem-solving.  These skills will help them in their future careers and lives by working together, using their imagination, and enhancing their communication skills while solving multiple challenges. How to Find a STEAM Summer Camp for Kids? There are many schools and institutions offering STEM summer camps for kids and each of them may use different programs and approaches. To choose the right one, consider the following factors. Your budget How much are you willing to spend on this year’s summer camp? It’s no secret that summer camps can be pricey especially if you are enrolling more than one child and if the program requires them to live on the campus. That’s why it’s important to consider your budget for everything, including lodging, transportation, and food. Do your research first, then pick the one that suits your budget and other requirements at the same time. You and your children’s preferences Are you okay with the kids staying at the camp? Will they be able to take care of themselves if you are not around? Are they old enough to join a sleep-away camp? These are some of the questions you need to ask before enrolling them to STEM summer camp for kids. Think about these things very well while researching to select one that works for your family. Curriculum You want to know what kinds of activities, classes, workshops they are going to do during the camp. These vary from institution to institution, so compare them carefully. You also want to find out how many kids are going to be there per class. More often, small classes are better because teachers can provide individualized attention and kids get to know each other more. The camp learning environment If the camp offers open houses, grab this opportunity to take a tour. Make sure to take your child with you. Surveying the place before sending your kids is a must. It gives you an opportunity to speak with the staff, directors, and counselors and get to know more about their experience. --- ## U.S. Can Expect to see more Ransomware Attacks URL: https://securityorb.com/u-s-can-expect-to-see-more-ransomware-attacks/ Type: post Modified: 2021-06-02 In the cybersecurity space, there are many things we do not all agree on, but one thing I have noticed in the past year is that we all agree that the U.S. can expect to see more ransomware attacks as the nation recover from recent attacks which included the District of Columbia Police Department, The Colonial Pipeline and now the JBS meat plant.  These will continue to increase, especially in the state, local environment, as well as in the critical infrastructure and manufacturing space. There are two main reasons for this trend: Organizations are not implementing the basic security controls thus allowing attackers to take advantage of easy attack vectors. A major of the critical infrastructure in the U.S. are operated by private organizations with very little IT and security regulations. Many organizations are frequently deciding to pay the ransom after they have been attacked. Security researchers and law enforcement often recommend organizations not to pay the ransoms, but when stakeholders and the media are applying pressure, organizational leader must do what is best for the organization.  This validates the ransomware industry and their frequency and tactics become more sophisticated. This recent attack seems to have a Russian’s group fingerprint associated to it just like the pipeline event.  Many security researchers, law enforcement officials and politicians are recommending in conjunction to increasing regulations on U.S. based organizations, the U.S. must also impose sanctions against countries that allow these types of activities to occur inside their borders. --- ## Bad Ending for Washington, D.C.'s Metropolitan Police Department (MPD) after a Ransomware Attack URL: https://securityorb.com/bad-ending-for-washington-d-c-s-metropolitan-police-department-mpd-after-a-ransomware-attack/ Type: post Modified: 2021-05-11 A group of ransomware hackers known as “Babuk” leaked internal police files from the Washington, D.C. Metropolitan Police Department (MPD).  The information was stolen in late April.  The type of information that was released included officers' personal information including psychological evaluations, credit history and Social Security numbers.  In addition, the leaked information included polygraph tests, social media posts, employment history, financial liabilities and scanned copies of officers' driver's licenses.  The leak occurred due to a break down in negotiations between MPD and Babuk who claimed the monetary offer the department made to prevent the leak was not enough.  Babuk claimed to have stolen approximately 250 GB of information from the department which can equate to 127,000 songs or 37, 600 photos on your computer. Security experts often recommend not paying the ransom after such an attack as it would only continue to fuel the ransomware tactics.  Even the FBI has issued a statement regarding this type of cyber-attack stating: "The FBI does not support paying a ransom in response to a ransomware attack," the agency advises. "Paying a ransom doesn’t guarantee you or your organization will get any data back. It also encourages perpetrators to target more victims and offers an incentive for others to get involved in this type of illegal activity." Babuk’s tactics differ to the tactics of DarkSide in Babuk stole the data and threatened to release it unless a ransom demand was met while DarkSide encrypted files and demanded a ransom in exchange for unlocking them. --- ## Colonial Pipeline Ransomware Attack URL: https://securityorb.com/colonial-pipeline-ransomware-attack/ Type: post Modified: 2021-05-09 One of the nation's largest fuel pipelines has been forced to shut down after being affected by a ransomware cyberattack.  Ransomware is a form of malware that encrypts a victim's files. The attacker then demands a ransom from the victim to restore access to the data upon payment. Colonial Pipeline was forced to shut down its entire network as well as proactively take various systems offline to contain the threat, halting all pipeline operations.  The massive US pipeline runs 5500 miles from Houston to New Jersey and transport 45% of all fuel to the East Coast. The President has been briefed and the White House stated it is working with the organization to avoid disruption to supply and restore pipeline operations as quickly as possible, but it is still unclear to how long the pipelines will be off the grid. Experts warn a prolonged delay could eventually impact consumers. This latest attack comes amid growing concerns about the nation’s cybersecurity posture.  Last December a massive software breach at Texas based SolarWinds was identified, where hackers reportedly gained access to the emails at U.S. government agencies.  Also, in Florida, investigators stated hackers took control of the computer systems of a water treatment facility in an attempt to tamper with the water supply. It's important that organization take these attacks seriously since these attacks will continue and are not going away.  So, it's imperative that if you're an owner operator of critical infrastructure that you invest in the cybersecurity controls. Update: 5/10/21 at 7:40 am EST A Russian criminal group may be responsible for a ransomware attack that shut down a major U.S. fuel pipeline, two sources familiar with the matter said Sunday. The group, known as DarkSide, is relatively new, but it has a sophisticated approach to the business of extortion, the sources said. --- ## Ransomware attack leads to shutdown of major U.S. pipeline system URL: https://securityorb.com/ransomware-attack-leads-to-shutdown-of-major-u-s-pipeline-system/ Type: post Modified: 2021-05-08 By: David E. Sanger A cyberattack forced the shutdown of one of the largest pipelines in the United States, in what appeared to be a significant attempt to disrupt vulnerable energy infrastructure. The pipeline carries refined gasoline and jet fuel up the East Coast from Texas to New York. The operator of the system, Colonial Pipeline, said in a statement late Friday that it had shut down its 5,500 miles of pipeline, which it says carries 45 percent of the East Coast’s fuel supplies, in an effort to contain the breach on its computer networks. Earlier Friday, there were disruptions along the pipeline, but it was unclear whether that was a direct result of the attack. Read more here. --- ## The Cybersecurity Job Gap and How Getting Women in STEM can Help [Video] URL: https://securityorb.com/the-cybersecurity-job-gap-and-how-getting-women-in-stem-can-help/ Type: post Modified: 2021-05-03 As the number of cyber-attacks continues to grow each year, the importance of cybersecurity and the need for cybersecurity practitioners will also continue to increase. As previously stated, Researchers at Cybersecurity Ventures detailed in a 2019 post there would be 3.5 million unfilled cybersecurity positions globally in 2021, but with the addition of 700,000 additional skilled practitioners according to a Cybersecurity Workforce Study that entered the field this year, the projected number has dropped to approximately 3,21 million. This is encouraging data and it seems we are moving in a position direction as the numbers have actually fallen for the first time since data on this matter has been collected. To continue to effectively reduce the cybersecurity job gap, we should look towards STEM and the underrepresented group of young women and girls. Women make up only 28% of the workforce in science, technology, engineering and math (STEM), and men vastly outnumber women majoring in most STEM fields in college. Key factors perpetuating the women STEM gap: Gender Stereotypes: STEM fields are often viewed as masculine. Male-Dominated Cultures: Because fewer women study and work in STEM, these fields tend to perpetuate inflexible, exclusionary, male-dominated cultures that are not supportive of or attractive to women and minorities. Fewer Role Models: girls have fewer role models to inspire their interest in these fields, seeing limited examples of female scientists and engineers in books, media and popular culture. There are even fewer role models of Black women in math and science. Some ways of closing the STEM Gap for women are: Raise awareness that girls and women are as capable as boys — when given encouragement and educational opportunities. Promote public awareness to parents about how they can encourage daughters as much as sons in math and science Supporting learning opportunities and positive messages about their abilities. Provide professional education to teachers — addressing implicit and systemic biases. Encourage girls and women to take math and science classes — including advanced classes. Design courses and change environments and practices in STEM studies to be more welcoming for women. Prioritize diverse, inclusive and respectful environments, and strong, diverse leadership. Recruit female employees and work to retain and promote women throughout their careers with strong advancement pipelines and continued professional development and leadership training.     --- ## Social Media Safety Awareness Tips URL: https://securityorb.com/social-media-safety-awareness-tips/ Type: post Modified: 2021-05-03 Social media provides a way to stay connected and share with others, but did you know that the cyber criminals will also use social media as another technique to conduct their attacks.  It is important to protect yourself as well as know the common signs of someone trying to trick or scam you. Over social media one common method is that cyber criminals will take over someone's social media account.  Once they control the account a criminal will pretend to be the accounts owner and post an urgent message to everyone connected to that account.  This message will say they are traveling internationally, and that they were just mugged and desperately need you to send them money. If you send money, you are not helping your friend you are actually sending money to the criminal.  Another common method is similar to phishing email attacks.  Cyber criminals post messages attempting to trick you into clicking on a link that takes you to a malicious website. Watch out for messages that seem urgent suspicious or try to make you feel rushed or afraid.  If you receive an odd message from a friend and are not sure if it was really then that sent it call them on the phone to confirm. Finally, attackers may use software to try and guess your password, if they gain access, they can then use your account to launch attacks on your contacts and friends.  Always try protecting each of your social media accounts with a unique strong password and enable two factor authentication whenever possible. --- ## Internet Safety Tips for Parent and Kids [Video] URL: https://securityorb.com/internet-safety-tips-for-parent-and-kids-video/ Type: post Modified: 2021-05-03 In a recent interview on the BNC network, I provided a few tips to keep kids safe while online on the Internet.  We feel having a set of rules that guides both a child and parent on online usage and expectations makes a lot of sense.  It also allows an opportunity for both the parent and child to talk about the components that are in the contract as a way to dialog about the importance of being in the digital world. You can view a copy of our online agreement here. --- ## Supply Chain Risk Management (SCRM) Explained URL: https://securityorb.com/supply-chain-risk-management-scrm-explained/ Type: post Modified: 2021-05-03 Supply chain risk management (SCRM) is the process of identifying, assessing, and mitigating the risks associated with the distributed and interconnected nature of IT products and service supply chain. Supply chain risks may include insertions of counterfeits, unauthorized production, tampering, theft insertion of malicious software and hardware, as well as poor manufacturing and development practices in the supply chain. These may lead to loss of sensitive information or cause unsafe situations that could compromise an organization’s mission, personnel or reputation. The Supply Chain Risk Management Life Cycle Risk Identification The only way to address risk is to make sure you’re identifying it in the first place. The first phase of the risk management lifecycle is to establish a risk profile and then enact active monitoring to keep it up to date. Risk Assessment Understand what impact a risk event could have on your business. Be aware of those partners who have a significant impact on sales, margins or profit. Risk Mitigation Define both preventive action plans and reactive action plans. These are what provide the basis for addressing risk using appropriate measures to secure supply and protect brand. Types of Supply Chain Risk Management Cyber Risk The possibility that your business is harmed by your suppliers’ use of technology. Financial Risk The possibility that suppliers will encounter a business scenario that threatens their financial health. Reputational Risk The possibility that a supplier will engage in activity that negatively affects your brand perception. Natural Disaster Risk The possibility that your supply chain is disrupted by a hurricane, earthquake or other natural hazard. Man-Made Risk Man-made risk is the possibility that your supply chain is disrupted by events like fires or explosions. While there are many SCRM sources of best practices, the NIST makes many publications freely available. --- ## Non-sensitive PII + Sensitive PII = Sensitive PII URL: https://securityorb.com/non-sensitive-pii-sensitive-pii-sensitive-pii/ Type: post Modified: 2021-04-30 Non-sensitive PII refers to any information that is publicly available.  If any of the information is combined with sensitive PII, then it would become sensitive PII.  Some Examples of Non-sensitive PII are: Work phone # Work fax # Work email address Work location Sensitive PII is personally identifiable information, which if lost, compromised, or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.  A person’s name in combination with any one of the following: Email Address Home telephone number Place of birth Date of birth Driver’s license number Mother’s maiden name Passport number Financial, medical, or criminal records Biometrics (such as DNA, iris scan, fingerprints) Financial/bank account numbers Personal or government account credit or debit card number Employment information to include ratings, disciplinary actions, performance elements and standards. Non-Sensitive PII together combined with Sensitive PII = Sensitive PII Tips for handling PII: Protect: Everyone has the responsibility to protect "PII in any form (physical or electronic, sensitive or non-sensitive) from unauthorized disclosure, modification, or destruction in order to ensure its confidentiality, integrity, and availability." Destroy: PII that is no longer needed should be destroyed in order to reduce risk to your organization (follow record retention schedules). Disclosure: You should only share sensitive personal information to authorized individuals. If you have doubts about sharing sensitive data, consult with your supervisor or Privacy Manager. --- ## The Civilian Cybersecurity Reserve: A National Guard-like program to address growing cybersecurity vulnerabilities faced by the U.S. government URL: https://securityorb.com/the-civilian-cybersecurity-reserve-a-national-guard-like-program-to-address-growing-cybersecurity-vulnerabilities-faced-by-the-u-s-government/ Type: post Modified: 2021-04-30 The SolarWinds cyberattack as well as other recent cyber breaches targeted at the United States has demonstrate the risks of the cyber workforce shortage.  Researchers at Cybersecurity Ventures a trusted source for cybersecurity facts, figures, and statistics stated there is currently 3.5 million unfilled cybersecurity jobs globally, which is enough to fill 50 NFL stadiums.  In the US alone according to cybersecurity research groups, there are an estimated 315,000 unfilled cybersecurity positions. As cybersecurity threats and attacks continue to grow in scale, occurrence, and complexity, it’s critical that a solution to address the deficiency is put in place.  Unfortunately, the pipeline of security talent isn’t where it needs to be to help curb the widespread of cyber-crimes we are facing.  Until we can rectify the quality of education and training of new cyber practitioners and pursue inclusion using STEM programs to include underrepresented groups, the problem will persist. In fact, in the past few years there has been a zero-percent unemployment rate in cybersecurity and the opportunities in this field are vast. To help combat this problem, lawmakers want to create a National Guard-like program to address growing cybersecurity vulnerabilities faced by the U.S. government.  This would be like a Civilian Cybersecurity Reserve and it would be voluntary and by invitation only.  This would allow our national security agencies to have access to the qualified, capable, and service-oriented American talent necessary to respond when an attack occurs. What are your thoughts in this program?  Do you think it is a good idea and it can help with the overall issue?  Please share your opinion. --- ## Parent/Child Agreement Contract URL: https://securityorb.com/parent-child-agreement-contract/ Type: post Modified: 2021-04-05 Nowadays having an online agreement or a set of rules that guides both a child and parent on online usage and expectations makes a lot of sense.  It also allows an opportunity for both the parent and child to talk about the components that are in the contract as a way to dialog about the importance of being in the digital world. Once the agreement is signed, it is still important for parents to stay engaged in the child’s usage. Below is a parent/child agreement you can use.  Feel free to add or remove items as needed. SecurityOrb - Parent Child Online Agreement --- ## Internet Safety Tips for Seniors and Scams to Watch Out for URL: https://securityorb.com/internet-safety-tips-for-seniors-and-scams-to-watch-out-for/ Type: post Modified: 2021-03-30 According to a Pew Research Center survey, about 66% of Americans over the age of 65 are online.  They are keeping up to date with the latest news stories, staying in touch with family, getting medical information, managing appointments, renewing prescriptions, and accessing medical records.  In addition, seniors are using the Internet as a way to stay in the workforce and even launch a new career or business as well as a way to make new friends and to find romantic partners through online dating. All of these attributes are great, but there are always dangers to be aware of from malicious individuals and fraudsters.  They use the Internet to scam unsuspecting users.  A rule of thumb is if an offer, email, or message sound too good to be true or just seems suspicious, it probably is. In conjunction with the normal found here, seniors should be aware of: Personal emergency scam: Scammers email or post social media messages that appear to be from someone you know saying they are in distress, such as having their wallet stolen or having been arrested. If you get such a message, find another way to verify if it’s true, such as reaching out directly to the person. If you get such a message from a friend, there is a good chance that their account was hacked and that it’s a criminal who is out to steal your money. You owe money scam: Be wary of emails that claim you owe money. If you hear from a bill collector or a government agency about money “owed” by you or a family member, don’t respond unless you are certain it’s legitimate. It’s pretty common for scammers to send “bills” to people who don’t actually owe them money. Online dating scam: Many people have found love via dating websites, but others have been scammed out of money by online con artists. For tips on safe online dating and a list of red flags, see “Meeting new friends and romantic partners.” Infected computer scam: You might get a call from “Microsoft,” saying your computer is infected or vulnerable to hacking, with an offer to fix it for you. Hang up. Microsoft and other reputable companies never make these calls. These are criminals trying to steal your money and plant viruses on your machine. Also be suspicious of any messages in email or that pop-up on your computer, in your Web browser, or on a mobile app warning you of a virus or a security risk. If you have reason to suspect that your device is at risk, consult a trusted expert but never download software or apps that you aren’t certain to come from legitimate sources. The bottom line is to speak out and don’t be ashamed if you do get scammed and become a victim of fraudulent activities.  Criminals are very good at what they do and there have been lots of very smart people who have been victimized online. If it happens to you, report it to a trusted person and, if appropriate, law enforcement. Even if you let your guard down, it’s not your fault if something bad happened to you. --- ## 5 Teen Internet Safety Tips URL: https://securityorb.com/5-teen-internet-safety-tips/ Type: post Modified: 2021-03-29 How could our teens live without their smartphones, laptops, and other devices that allow them to go online, communicate and have fun with their friends in a safe manner?  We have provided five (5) tips they should remember. 1.     Keep Your Online Identity Private We all understand on the Internet, you really never know who is at the other end.  Therefore, a good rule is to not tell anyone your real name and address or schedule such as practice locations and etc. 2.     Your Password Belongs to You … And Only You Don’t ever give your password to anyone (except your parents). It's just that simple because someone can post information that gets you expelled from school, in trouble with your parents, 3.     What You Post Can Live Forever Watch what you post about yourself or others and watch what your friends post about you because you may have to live with it for a long, long time. 4.     Be a Good Digital Citizen Watch what you write and post while online somebody is or will be reading what you write. Also, illegally downloading music or movies and making online threats are just as illegal on the Internet as they are in the real world. You cannot hide behind a screen name and get away with it. 5.     Be Careful and Smart about Meeting Someone in Person The FBI presents a strict warning: “Never meet anyone in person that you meet online.” That said, many teens do make good friends online. You just have to be careful and smart as well as make sure other people you know, and trust also know this “new” online person. --- ## Update Greenbone Vulnerability Management Plugins on Kali (NVT, Cert Data & SCAP Data) Automatically URL: https://securityorb.com/update-greenbone-vulnerability-management-plugins-nvt-cert-data-scap-data-automatically/ Type: post Modified: 2021-03-18 Once you have installed or configured the Greenbone Vulnerability Management system it is a good idea to ensure it is kept up to date and running the latest security scripts to find the latest vulnerabilities as well as sync to the most updated nvt, scap and cert data.  The best way to do this is to create a script that sync’s the necessary data for you automatically each day. Create a script under /usr/local/bin called update-gvm vi /usr/local/bin/update-gvm add the following contents to the file sudo runuser -u _gvm -- greenbone-nvt-sync sudo runuser -u _gvm -- greenbone-scapdata-sync sudo runuser -u _gvm -- greenbone-certdata-sync save the file and make it executable chmod a+x /usr/local/bin/update-gvm run the script to make sure it works and that there are no errors /usr/local/bin/update-gvm add the script to cron to run daily crontab -e add the following contents 1 1 * * * /usr/local/bin/update-gvm 1>/dev/null 2>/dev/null the above cronjob will be run at 1-minute past 1 every day --- ## SA.3.169 Community-based Threat Sharing (CMMC Level 3) URL: https://securityorb.com/sa-3-169-community-based-threat-sharing-cmmc-level-3/ Type: post Modified: 2021-03-18 Receive and respond to cyber threat intelligence from information sharing forums and sources and communicate to stakeholders. Source Discussion Establish relationships with external organizations to gather cyber threat intelligence. Periodically review the sources of intelligence to ensure they are up-to-date and relevant [a]. Cyber threat intelligence from external sources should inform situational awareness activities within the organization. Relevant external threat intelligence is reviewed and communicated to stakeholders within the organization for appropriate action if needed [c]. To enhance situational awareness activities, leverage external sources for cybersecurity threat intelligence. Establish a relationship with external organizations, or periodically survey relevant sources, to ensure you are receiving up-to-date threat intelligence information pertinent to your organization. CMMC Clarification To enhance situational awareness activities within the organization, leverage external sources for cybersecurity threat information. Establish a relationship with external organizations, or periodically survey relevant sources, to ensure you are receiving up-to-date threat intelligence information pertinent to your organization. Examples of sources include US-CERT, various critical infrastructure sector ISACs, ICS-CERT, industry associations, vendors, and federal briefings. Threat information is reviewed and, if applicable to your organization, communicated to the appropriate stakeholders for action. CMMC GUIDE FURTHER DISCUSSION Cyber threat intelligence may include: attacker methodologies, tools, and tactics; indicators of specific malware; details of specific attacks; and high-level information on changing threats [a]. Examples of cyber threat intelligence sources include: Department of Homeland Security (ICS-CERT, US-CERT); Information Sharing and Analysis Centers (ISACs); DoD Defense Industrial Base (DIB) Collaborative Information Sharing Environment (DCISE); vendors’ notifications; industry groups (e.g., Internet Storm Center, Nextgov, ThreatWatch); and law enforcement (e.g., FBI, InfraGard, IC3) [a]. Examples of procedures the organization may implement to effectively receive, respond to, and communicate cyber threat intelligence may include: source identification, monitoring frequency, threat identification, threat validation and analysis, threat communication, procedures for the identification of stakeholders, stakeholder communication requirements, and tools and techniques for communication [b,c]. An organization may respond to threat intelligence with actions like updating firewall rules, issuing advisories to users, or providing new indicators of compromise to incident response personnel. This practice, SA.3.169, which ensures receiving and responding to cyber threat intelligence, is a baseline practice for the following practices: IR.2.096, RM.2.141, and RM.3.144. These practices benefit from the use of cyber threat intelligence. Examples You are in charge of IT operations for your company. Part of your role is to ensure you are aware of up-to-date cyber threat intelligence information so you can properly perform risk assessments and vulnerability analyses. To do this, you join a defense sector ISAC, and sign- up for alerts from US-CERT. You use information you receive from these external entities to update your threat profiles, vulnerability scans, and risk assessments. Also, you use these sources to gather best practices for informing your employees of potential threats and disseminate the information throughout your organization to the appropriate stakeholders. References CMMC NIST CSF v1.1 ID.RA-2 NIST SP 800-53 Rev 4 PM-16 --- ## IR.2.092 Incident Preparation (CMMC Level 2) URL: https://securityorb.com/ir-2-092-incident-preparation-cmmc-level-2/ Type: post Modified: 2021-03-16 Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities. Source Discussion Organizations recognize that incident handling capability is dependent on the capabilities of organizational systems and the mission/business processes being supported by those systems. Organizations consider incident handling as part of the definition, design, and development of mission/business processes and systems. Incident-related information can be obtained from a variety of sources including audit monitoring, network monitoring, physical access monitoring, user and administrator reports, and reported supply chain events. Effective incident handling capability includes coordination among many organizational entities including mission/business owners, system owners, authorizing officials, human resources offices, physical and personnel security offices, legal departments, operations personnel, procurement offices, and the risk executive. As part of user response activities, incident response training is provided by organizations and is linked directly to the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail is included in such training. For example, regular users may only need to know who to call or how to recognize an incident on the system; system administrators may require additional training on how to handle or remediate incidents; and incident responders may receive more specific training on forensics, reporting, system recovery, and restoration. Incident response training includes user training in the identification/reporting of suspicious activities from external and internal sources. User response activities also include incident response assistance which may consist of help desk support, assistance groups, and access to forensics services or consumer redress services, when required. NIST SP 800-61 provides guidance on incident handling. SP 800-86 and SP 800-101 provide guidance on integrating forensic techniques into incident response. SP 800-161 provides guidance on supply chain risk management. CMMC Clarification Incident handling should include activities that prepare your organization to respond to incidents. These activities may include the following: identify people inside and outside your organization you may need to contact during an incident; establish a way to report incidents, such as an email address or a phone number; establish a system for tracking incidents; and determine a place and a way to store evidence of an incident. You may need software and hardware to analyze incidents when they occur. You should also consider incident prevention activities as part of your incident-handling capability. The incident handling team provides input for such things as risk assessments and training. Your organization should detect incidents in different ways. Use indicators to detect incidents. Indicators are things that don’t look like what you expect. Examples include: alerts from your sensors or antivirus software; a filename that looks unusual; and a log entry that raises concern. After you detect an incident, you should analyze it to decide what to do. To analyze an incident, you need to know what should be occurring on your network and what should not. This will help you determine when an incident may have occurred. It may also help you decide what to do about it. You should also document what you know about the incident. Include all the log entries associated with the incident in your documentation. Containment of the incident is important. This stops the damage the incident is causing to your network. You should base the containment activities you do on your incident analysis. These activities can include: disconnecting a system from the internet; and changing firewall settings to stop an attack. Recovery activities are things to fix that caused the incident. This will help prevent the incident from happening again. Recovery activities also include things that fix the affected systems, including: restoring backup data; and reinstalling software. User response activities include: performing a lessons-learned analysis; deciding if you should contact the police; and updating any policy or plans as a result of after incident analysis. CMMC GUIDE FURTHER DISCUSSION Incident handling capabilities prepare your organization to respond to incidents and may: identify people inside and outside your organization you may need to contact during an incident; establish a way to report incidents, such as an email address or a phone number; establish a system for tracking incidents; and determine a place and a way to store evidence of an incident [b]. This practice may be thought of as an umbrella practice supported by IR.2.093, IR.2.094, and IR.2.096. Further detail on these objectives are provided in the practices on detection and reporting of events (IR.2.093), the analysis and correlation of events that result in a declaration that an event is actually an incident (IR.2.094), and responding to declared incidents with predefined procedures (IR.2.096). Software and hardware may be required to analyze incidents when they occur. Incident prevention activities are also part of an incident-handling capability. The incident-handling team provides input for such things as risk assessments and training. Contractors detect incidents using different indicators. Indicators may include: alerts from sensors or antivirus software, a filename that looks unusual, and log entries that raise concern. After detecting an incident, an incident response team performs analysis [c,d]. This requires some knowledge of normal network operations. The incident should be documented including all the log entries associated with the incident. Containment of the incident is a critical step to stop the damage the incident is causing to your network. Containment activities should be based on previously defined organizational priorities and assessment of risk. Recovery activities restore systems to pre-incident functionality and address its underlying causes. Organizations should use recovery activities as a means of improving their overall resilience to future attacks. Examples Example 1 Your manager asks you to set up your organization’s incident response capability. First, you create an email address to collect information on possible incidents. Next, you draft a contact list of all the people in the organization who need to know when an incident occurs. Then, you write down a procedure for how to submit incidents. This includes what everyone should do when a potential incident is detected or reported. The procedure also explains how to track incidents, from initial creation to closure. Example 2 You receive an email alert about a possible incident. An employee identified a suspicious email message as a phishing attempt. First, you document the incident in your incident tracking system. Then, you immediately reference your defined procedures for handling incidents. For example, you send an email to your employees alerting them not to open a similar email. You also start collecting information around the reported incident. Example 3 In response to the suspicious email, you perform a set of actions. You reinstall the software on the machine of the user involved. This means that the individual no longer has an infected machine. You update your phishing protection software. This ensures that it can block the latest phishing attacks. You update your training material to emphasize the threat of phishing emails. References NIST SP 800-171 Rev 1 3.6.1 NIST CSF v1.1. RS.RP-1 CERT RMM v1.2 IMC:SG1.SP1 NIST SP 800-53 Rev 4 IR-2, IR-4 --- ## SI.1.210 System Integrity/Patching (CMMC Level 1) URL: https://securityorb.com/si-1-210-system-integrity-patching-cmmc-level-1/ Type: post Modified: 2021-03-15 Identify, report, and correct information and information system flaws in a timely manner. Source Discussion Organizations identify systems that are affected by announced software and firmware flaws including potential vulnerabilities resulting from those flaws and report this information to designated personnel with information security responsibilities. Security-relevant updates include patches, service packs, hotfixes, and anti-virus signatures. Organizations address flaws discovered during security assessments, continuous monitoring, incident response activities, and system error handling. Organizations can take advantage of available resources such as the Common Weakness Enumeration (CWE) database or Common Vulnerabilities and Exposures (CVE) database in remediating flaws discovered in organizational systems. Organization-defined time periods for updating security-relevant software and firmware may vary based on a variety of factors including the criticality of the update (i.e., the severity of the vulnerability related to the discovered flaw). Some types of flaw remediation may require more testing than other types of remediation. NIST SP 800-40 provides guidance on patch management technologies. CMMC Clarification All software and firmware have potential flaws. Many vendors work to reduce those flaws by releasing vulnerability information and updates to their software and firmware. Organizations should have a process to review relevant vendor newsletters with updates about common problems or weaknesses. After reviewing the information the organization should execute a process called patch management that allows for systems to be updated without adversely affecting the organization. Organizations should also purchase support from their vendors to ensure timely access to updates. CMMC GUIDE FURTHER DISCUSSION All software and firmware have potential flaws. Many vendors work to remedy those flaws by releasing vulnerability information and updates to their software and firmware. Contractors must have a process to review relevant vendor notifications and updates about problems or weaknesses [a]. After reviewing the information, the contractor must implement a patch management process that allows for software and firmware flaws to be fixed without adversely affecting the system functionality [e,f]. Contractors must define the time frames within which flaws are identified, reported, and corrected for all systems. Contractors should consider purchasing support from their vendors to ensure timely access to updates [a]. Examples You have many responsibilities at your company, including IT. You know that malware, ransomware, and viruses can be big problems for companies. You make sure to enable all security updates for your software, including the operating system and applications, and purchase the maintenance packages for new hardware and operating systems. References FAR Clause 52.204-21 b.1.xii NIST SP 800-171 Rev 1 3.14.1 NIST CSF v1.1 RS.CO-2, RS.MI-3 CERT RMM v1.2 VAR:SG2.SP2 NIST SP 800-53 Rev 4 SI-2 UK NCSC Cyber Essentials AU ACSC Essential Eight --- ## CA.2.158 Ongoing Security Assessment (CMMC Level 2) URL: https://securityorb.com/ca-2-158-ongoing-security-assessment-cmmc-level-2/ Type: post Modified: 2021-03-11 Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. Source Discussion Organizations assess security controls in organizational systems and the environments in which those systems operate as part of the system development life cycle. Security controls are the safeguards or countermeasures organizations implement to satisfy security requirements. By assessing the implemented security controls, organizations determine if the security safeguards or countermeasures are in place and operating as intended. Security control assessments ensure that information security is built into organizational systems; identify weaknesses and deficiencies early in the development process; provide essential information needed to make risk-based decisions; and ensure compliance to vulnerability mitigation procedures. Assessments are conducted on the implemented security controls as documented in system security plans. Security assessment reports document assessment results in sufficient detail as deemed necessary by organizations, to determine the accuracy and completeness of the reports and whether the security controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting security requirements. Security assessment results are provided to the individuals or roles appropriate for the types of assessments being conducted. Organizations ensure that security assessment results are current, relevant to the determination of security control effectiveness, and obtained with the appropriate level of assessor independence. Organizations can choose to use other types of assessment activities such as vulnerability scanning and system monitoring to maintain the security posture of systems during the system life cycle. NIST SP 800-53 provides guidance on security and privacy controls for systems and organizations. SP 800-53A provides guidance on developing security assessment plans and conducting assessments. CMMC Clarification As organizations implement security controls, they should avoid a “set it and forget it” mentality. The security landscape is constantly changing. Reassess existing controls at periodic intervals in order to validate their usefulness in organizational systems. This will let you determine if the control is still meeting the needs of the organization. Set the assessment schedule according to organizational needs. Consider regulatory obligations and internal policies when assessing the controls. Typical outputs of the practice include: documented assessment results; proposed new controls, or updates to existing controls; remediation plans; and newly identified risks. CMMC GUIDE FURTHER DISCUSSION Avoid a “set it and forget it” mentality when implementing security controls. The security landscape is constantly changing. Reassess existing controls at periodic intervals in order to validate their effectiveness in your environment. Set the assessment schedule according to organizational needs. Consider regulatory obligations and internal policies when assessing the controls. Outputs from security control assessments typically include: documented assessment results; proposed new controls, or updates to existing controls; remediation plans; and newly identified risks. This practice, CA.2.158, which ensures determining security controls are implemented properly, promotes effective security assessments for organizational systems required by CA.3.161. Examples You are in charge of IT operations in your company. You ensure that security controls are achieving their objectives. After you implement the controls, you monitor their performance. You should perform this review as often as necessary to meet: your organization’s risk planning needs; and any regulations or policies you must follow. When you assess the controls, document what you find. When you find your controls are not meeting your requirements, you should act and make changes. You can: propose updated or new controls; develop a plan to improve the control; and document new risks that you find. You should also document these actions. References NIST SP 800-171 Rev 1 3.12.1 NIST CSF v1.1 DE.DP-3 NIST SP 800-53 Rev 4 CA-2 --- ## AC.1.004 Publicly Posted Information (CMMC Level 1) URL: https://securityorb.com/ac-1-004-publicly-posted-information-cmmc-level-1/ Type: post Modified: 2021-03-10 Control information posted or processed on publicly accessible information systems. Source Discussion In accordance with laws, Executive Orders, directives, policies, regulations, or standards, the public is not authorized to access nonpublic information (e.g., information protected under the Privacy Act, FCI, and proprietary information). This requirement addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication. Individuals authorized to post FCI onto publicly accessible systems are designated. The content of information is reviewed prior to posting onto publicly accessible systems to ensure that nonpublic information is not included. CMMC Clarification Do not allow sensitive information, including Federal Contract Information (FCI), which may include CUI, to become public. It is important to know which users/employees are allowed to publish information on publicly accessible systems, like your company website. Limit and control information that is posted on your company’s website(s) that can be accessed by the public. CMMC GUIDE FURTHER DISCUSSION Do not allow FCI to become public – always safeguard the confidentiality of FCI by controlling the posting of FCI on company-controlled websites or public forums, and the exposure of FCI in public presentations or on public displays [d]. It is important to know which users are allowed to publish information on publicly accessible systems, like your company website, and implement a review process before posting such information [a,c]. If FCI is discovered on a publicly accessible system, procedures should be in place to remove that information and alert the appropriate parties [e]. Example You are head of marketing for your company and want to become better known by your customers. So, you decide to start issuing press releases about your company projects. Your company gets FCI from doing work for the Federal government. FCI is information that is not shared publicly. Because you recognize the need to control sensitive information, including FCI, you carefully review all information before posting it on the company website or releasing it to the public. You allow only certain employees to post to the website. References FAR Clause 52.204-21 b.1.iv NIST SP 800-171 Rev 1 3.1.22 NIST SP 800-53 Rev 4 AC-22 --- ## MP.1.118 Media Destruction - Sanitation (CMMC Level 1) URL: https://securityorb.com/mp-1-118-media-destruction-sanitation-cmmc-level-1/ Type: post Modified: 2021-03-10 Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse. Source Discussion This requirement applies to all system media, digital and non-digital, subject to disposal or reuse. Examples include digital media found in workstations, network components, scanners, copiers, printers, notebook computers, and mobile devices; and non-digital media such as paper and microfilm. The sanitization process removes information from the media such that the information cannot be retrieved or reconstructed. Sanitization techniques, including clearing, purging, cryptographic erase, and destruction, prevent the disclosure of information to unauthorized individuals when such media is released for reuse or disposal. Organizations determine the appropriate sanitization methods, recognizing that destruction may be necessary when other methods cannot be applied to the media requiring sanitization. Organizations use discretion on the employment of sanitization techniques and procedures for media containing information that is in the public domain or publicly releasable or deemed to have no adverse impact on organizations or individuals if released for reuse or disposal. Sanitization of non-digital media includes destruction, removing FCI from documents, or redacting selected sections or words from a document by obscuring the redacted sections or words in a manner equivalent in effectiveness to removing the words or sections from the document. NARA policy and guidance control sanitization processes for federal contract information. NIST SP 800-88 provides guidance on media sanitization. CMMC Clarification In this case, “media” can mean something as simple as paper, or storage devices like diskettes, disks, tapes, microfiche, thumb drives, CDs and DVDs, and even mobile phones. It is important to see what information is on these types of media. If there is Federal contract information (FCI)—information you or your company got doing work for the Federal government that is not shared publicly)—you or someone in your company should do one of two things before throwing the media away: clean or purge the information, if you want to reuse the device; or shred or destroy the device so it cannot be read. See NIST Special Publication 800-88 Revision 1, Guidelines for Media Sanitization for more information. CMMC GUIDE FURTHER DISCUSSION “Media” refers to a broad range of items that store information, including paper documents, disks, tapes, digital photography, USB drives, CDs, DVDs, and mobile phones. It is important to know what information is on media so that you handle it properly. If there is FCI, you or someone in your company should either: shred or destroy the device before disposal so it cannot be read [a] or clean or purge the information, if you want to reuse the device [b]. See NIST Special Publication 800-88, Revision 1, Guidelines for Media Sanitization, for more information. Example You are moving into a new office. As you pack for the move, you find some of your old CDs in a file cabinet. When you load the CDs into your computer drive, you see that one has information about an old project your company did for the Department of Defense (DoD). Rather than throw the CD in the trash, you make sure that it is shredded.   References FAR Clause 52.204-21 b.1.vii NIST SP 800-171 Rev 1 3.8.3 NIST CSF v1.1 PR.DS-3 CERT RMM v1.2 KIM:SG4.SP3 NIST SP 800-53 Rev 4 MP-6   --- ## AC.1.003 External/Remote Connections (CMMC Level 1) URL: https://securityorb.com/ac-1-003-external-remote-connections-cmmc-level-1/ Type: post Modified: 2021-03-09 Verify and control/limit connections to and use of external information systems. Sources Discussion External systems are systems or components of systems for which organizations typically have no direct supervision and authority over the application of security requirements and controls or the determination of the effectiveness of implemented controls on those systems. External systems include personally owned systems, components, or devices and privately-owned computing and communications devices resident in commercial or public facilities. This requirement also addresses the use of external systems for the processing, storage, or transmission of FCI, including accessing cloud services (e.g., infrastructure as a service, platform as a service, or software as a service) from organizational systems. Organizations establish terms and conditions for the use of external systems in accordance with organizational security policies and procedures. Terms and conditions address as a minimum, the types of applications that can be accessed on organizational systems from external systems. If terms and conditions with the owners of external systems cannot be established, organizations may impose restrictions on organizational personnel using those external systems. This requirement recognizes that there are circumstances where individuals using external systems (e.g., contractors, coalition partners) need to access organizational systems. In those situations, organizations need confidence that the external systems contain the necessary controls so as not to compromise, damage, or otherwise harm organizational systems. Verification that the required controls have been effectively implemented can be achieved by third-party, independent assessments, attestations, or other means, depending on the assurance or confidence level required by organizations. Note that while “external” typically refers to outside of the organization’s direct supervision and authority, that is not always the case. Regarding the protection of FCI across an organization, the organization may have systems that process FCI and others that do not. And among the systems that process FCI, there are likely access restrictions for FCI that apply between systems. Therefore, from the perspective of a given system, other systems within the organization may be considered “external to that system. CMMC Clarification Make sure to control and manage connections between your company network and outside networks, such as the public internet or a network that does not belong to your company. Be aware of applications that can be run by outside systems. Control and limit personal devices like laptops, tablets, and phones from accessing the company networks and information. You can also choose to limit how and when your network is connected to outside systems and/or decide that only certain employees can connect to outside systems from network resources. CMMC GUIDE FURTHER DISCUSSION Control and manage connections between your company network and outside networks. Outside networks could include the public internet, one of your own company’s networks that fall outside of your assessment boundary (e.g., an isolated lab), or a network that does not belong to your company [c,e]. Tools to accomplish include firewalls and connection allow/deny lists. External systems not controlled by your company could be running applications that are prohibited or blocked. Control and limit access to corporate networks from personally owned devices such as laptops, tablets, and phones [b,d,f]. You may choose to limit how and when your network is connected to outside systems or only allow certain employees to connect to outside systems from network resources [e]. Example You help manage IT for your employer. You and your coworkers are working on a big proposal, and all of you will put in extra hours over the weekend to get it done. Part of the proposal includes Federal Contract Information or FCI. FCI is information that you or your company get from doing work for the Federal government. Because FCI is not shared publicly, you remind your coworkers to use their company laptops, not personal laptops or tablets, when working on the proposal over the weekend. References FAR Clause 52.204-21 b.1.iii NIST SP 800-171 Rev 1 3.1.20 CIS Controls v7.1 12.1, 12.4 NIST CSF v1.1 ID.AM-4, PR.AC-3 CERT RMM v1.2 EXD:SG3.SP1 NIST SP 800-53 Rev 4 AC-20, AC- 20(1) --- ## AC.1.002 User Access Restrictions (CMMC Level 1) URL: https://securityorb.com/ac-1-002-user-access-restrictions-cmmc-level-1/ Type: post Modified: 2021-03-08 Limit information system access to the types of transactions and functions that authorized users are permitted to execute. Source Discussion Organizations may choose to define access privileges or other attributes by account, by type of account, or a combination of both. System account types include individual, shared, group, system, anonymous, guest, emergency, developer, manufacturer, vendor, and temporary. Other attributes required for authorizing access include restrictions on time-of-day, day-of-week, and point-of-origin. In defining other account attributes, organizations consider system-related requirements (e.g., system upgrades scheduled maintenance,) and mission or business requirements, (e.g., time zone differences, customer requirements, remote access to support travel requirements).   CMMC Clarification Make sure to limit users/employees to only the information systems, roles, or applications they are permitted to use and that are needed for their jobs. CMMC GUIDE FURTHER DISCUSSION Limit users to only the information systems, roles, or applications they are permitted to use and are needed for their roles and responsibilities [a]. Limit access to applications and data based on the authorized users’ role and responsibilities [b]. Common types of functions a user can be assigned are creating, read, update, and delete. Examples You are in charge of payroll for the company and need access to certain company financial information and systems. You work with IT to set up the system so that when users log onto the company’s network, only those employees you allow can use the payroll applications and access payroll data. Because of this good access control, your coworkers in the Shipping Department cannot access information about payroll or paychecks.   References FAR Clause 52.204-21 b.1.ii NIST SP 800-171 Rev 1 3.1.2 CIS Controls v7.1 1.4, 1.6, 5.1, 8.5, 14.6, 15.10, 16.8, 16.9, 16.11 NIST CSF v1.1 PR.AC-1, PR.AC-3, PR.AC-4, PR.AC-6, PR.PT-3, PR.PT-4 CERT RMM v1.2 TM:SG4.SP1 NIST SP 800-53 Rev 4 AC-2, AC- 3, AC-17 --- ## AC.1.001 Basic Security Requirements (CMMC Level 1) URL: https://securityorb.com/ac-1-001-basic-security-requirements-cmmc-level-1/ Type: post Modified: 2021-03-06 Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems). Source Discussion Access control policies (e.g., identity- or role-based policies, control matrices, and cryptography) control access between active entities or subjects (i.e., users or processes acting on behalf of users) and passive entities or objects (e.g., devices, files, records, and domains) in systems. Access enforcement mechanisms can be employed at the application and service level to provide increased information security. Other systems include systems internal and external to the organization. This requirement focuses on account management for systems and applications. The definition of and enforcement of access authorizations, other than those determined by account type (e.g., privileged verses [sic] non-privileged) are addressed in requirement 3.1.2 (AC.1.002). CMMC Clarification Control who can use company computers and who can log on to the company network. Limit the services and devices, like printers, that can be accessed by company computers. Set up your system so that unauthorized users and devices cannot get on the company network. CMMC GUIDE FURTHER DISCUSSION Identify users, processes, and devices that are allowed to use company computers and can log on to the company network [a]. Automated updates and other automatic processes should be associated with the user who initiated (authorized) the process [b]. Limit the devices (e.g., printers) that can be accessed by company computers [c]. Set up your system so that only authorized users, processes, and devices can access the company network [d,e,f]. This practice, AC.1.001, controls system access based on user, process or device identity. AC.1.001 leverages IA.1.076, which provides a vetted and trusted identity for access control required by AC.1.001. Examples Example 1 You are in charge of IT for your company. You give a username and password to every employee who uses a company computer for their job. No one can use a company computer without a username and a password. You give a username and password only to those employees you know have permission to be on the system. When an employee leaves the company, you disable their username and password immediately. Example 2 A coworker from the marketing department tells you their boss wants to buy a new multi- function printer/scanner/fax device and make it available on the company network. You explain that the company controls system and device access to the network, and will stop non-company systems and devices unless they already have permission to access the network. You work with the marketing department to grant permission to the new printer/scanner/fax device to connect to the network, then install it. References FAR Clause 52.204-21 b.1.i NIST SP 800-171 Rev 1 3.1.1 CIS Controls v7.1 1.4, 1.6, 5.1, 14.6, 15.10, 16.8, 16.9, 16.11 NIST CSF v1.1 PR.AC-1, PR.AC-3, PR.AC-4, PR.AC-6, PR.PT-3, PR.PT-4 CERT RMM v1.2 TM:SG4.SP1 NIST SP 800-53 Rev 4 AC-2, AC- 3, AC-17 AU ACSC Essential Eight --- ## Internet Safety Day 2021 URL: https://securityorb.com/internet-safety-day-2021/ Type: post Modified: 2021-02-09 Today, Tuesday, 9 February 2021, we celebrate the 18th edition of Safer Internet Day with actions taking place right across the globe. With a theme once again of "Together for a better internet", this day calls upon all stakeholders to join together to make the internet a safer and better place for all, and especially for children and young people. securityorb.com/ would like to share a few links to some useful content that can help you, your family, and your business. Internet Safety 101 The Ultimate Guide for Parents This is the ultimate, easy-to-digest guide to keeping your family safe online. Let’s get straight to the point: As parents, we worry about our kids and the internet. We want to keep them safe but aren’t always sure how. Where do we start? Right here. This Internet Safety 101 guide issimple to follow and very practical. If you want to be clued-up and confident but are short on time, we made this for you. You’re going to see the issues and risks and be given actionable tips for protecting your family. Let’s dive right in. Retrieve from - https://wetheparents.org/internet-safety-for-parents Safer Internet Day 2021: History, Theme And Tips For Personal Online Security The safer internet day is celebrated in February each year and this year, Feb. 9 marks the day. The day was launched in the U.K. to raise awareness about correct internet practices and reflect on the concerns around the online world such as cyberbullying and other forms of online harassment. The day focuses on a range of topics, including consent, ownership, and data privacy, and also aims to rid the online world of malevolence of any sort and ensure the security of children and adults alike. Retrieved from - https://www.ibtimes.com/safer-internet-day-2021-history-theme-tips-personal-online-security-3141176 --- ## CMMC Level 3 Control - Email Sandboxing (SI.3.220) URL: https://securityorb.com/cmmc-level-3-control-email-sandboxing-si-3-220/ Type: post Modified: 2020-09-18 In the CMMC process, one of the controls that many organizations may have some issues understanding or implementing is Email Sandboxing or SI.3.220.  An overview for this control states an organization should utilize sandboxing to detect or block potentially malicious email.  The action can prevent malicious files from entering the network and should be document in the Configuration Management Policy. An email sandbox provides an isolated environment to execute an attached file or linked URL.  Before allowing attachments or links to be opened on the production network, they are executed within the sandbox and their behavior is observed. By opening these files or links in a protected environment, the system detects malicious activity before it is introduced into the network. Office365 and its Advance Threat Protection can provide these services with their URL Detonation and Dynamic Delivery.  The Dynamic Delivery feature allows recipients to read and respond to emails while the attachment is being scanned. Dynamic Delivery delivers emails to the recipient’s inbox along with a “placeholder” attachment notifying the user that the real attachment is being scanned—all with minimal lag time.  If a user clicks the placeholder attachment, they see a message showing the progress of the scan. If the attachment is harmless, it seamlessly re-attaches to the email so the user can access it. If it is malicious, Office 365 Advanced Threat Protection will filter out the attachment. URL Detonation can be enabled through the policy controls in the Safe Links admin window under settings. To enable URL Detonation, select the “On” radio button and then select the Use Safe Attachments to scan downloadable content checkbox. Dynamic Delivery can be activated through the policy controls from the Safe Attachments admin control window under Settings. Simply select the Dynamic Delivery radio button. Other email services also provide the sandboxing service as well.  For example, this feature is available with G Suite Enterprise and G Suite Enterprise for Education.  So, contact your email provider if you are not sure. --- ## Password Security Question Recommendations URL: https://securityorb.com/password-security-question-recommendations/ Type: post Modified: 2020-04-06 Can these answers be found on your Facebook account, or other social media accounts?  Things like, what city did you grow up in?  What is your dog’s name? What is your favorite book? What was your first job? What is your mother’s maiden name? It is risky to post this information on social media because of security questions.  Security questions exist on pretty much every website that requires a username and password.  So for instance, does something like this look familiar?  It asks you first to enter in your birthday, then it asks you for your security questions, such as those just mentioned. These are things that friends know, that family members know and that anyone who is a social media connection can likely find out.  Typically, users are very honest when it comes to security questions.  Whenever they ask for their pet’s name, they enter their pet’s name.  Malicious parties can utilize your social media account to find the answers to these questions, which then allows then to reset your password. This is especially a concern when people’s Facebook, Twitter or other accounts are public.  Anyone can search the Internet, find your account, and then view the information on that account.  The best practice is not not be honest when filling out these questions.  Just threat the security questions as another password field.  If it asks you for your pet’s name.  Enter something completely unrelated.  If it asks for your mother’s maiden name, do the same thing, enter something completed unrelated. Now you do not have that security concern of giving strangers answers to these questions.  Also check out our best practices to creating passwords. Let me know if you agree with this recommendation. --- ## Zoom enacts security and privacy control to prevent Zoombombing URL: https://securityorb.com/zoom-enacts-security-and-privacy-control-to-prevent-zoombombing/ Type: post Modified: 2020-04-06 Zoom enacts security and privacy control to prevent Zoonbombing In our recent article, “What is Zoombombing and how to defend against it” we explained Zoombombing is when an unauthorized person or stranger joins a Zoom meeting/chat session and causes disorder by saying offensive things and even photobombing your meeting by sharing pornographic and hate images. This has been occurring because most Zoom meetings have a public link that, if a person were to click it, it will allow them to join that meeting even though they are not a participant.  Zoombombers have been collecting these links and sharing them in private chat groups, and conducting disruptions. Fortunately, on April 5th, Zoom turned on the passwords and waiting room features for meetings by default aimed at users of their free version and those with a single license version to help prevent “Zoombombing”. These changes came right on time as Trent Lo, a cybersecurity researcher and members of a Kansas City-based security meetup group, SecKC, developed a program that can automatically scan for Zoom meeting IDs on the Internet.  The program titled “zWarDial” is able to identify approximately 100 Zoom meeting IDs in an hour and collect nearly 2,400 Zoom meetings IDs in a single day. Another added benefit from the April 5th change is previously scheduled Zoom meetings will also have Zoom passwords automatically enabled.  Some experts have gone as far to categorize Zoom as malicious software or Malware as described in a recent article by The Guardian titled, “‘Zoom is malware’: why experts worry about the video conferencing platform”.  I personally would not take it that far to describe it as malware, but do fault Zoom for not following adequate SecSDLC procedures.  In additional, as in many applications, there are always deficiencies and bugs that will need to be remediated. Hopefully these changes will provide the privacy protection needed to keep our events private and safe. Please share your thoughts below. --- ## WordPress 5.4 “Adderley” Released URL: https://securityorb.com/wordpress-5-4-adderley-released/ Type: post Modified: 2020-04-01 WordPress 5.4 “Adderley” Released WordPress 5.4 “Adderley” was released to the public on March 31, 2020. Check WordPress 5.4 announcement blogpost for more information on this release. For Version 5.4, the database version (db_version in wp_options) updated to 47018, and the Trac revision was 47541. You can find the full list of tickets included in 5.4 on Trac. The WordPress 5.4 Field Guide has pertinent, in-depth information on the major technical changes for this release. --- ## What is Zoombombing and how to defend against it URL: https://securityorb.com/what-is-zoombombing-and-how-to-defend-against-it/ Type: post Modified: 2020-04-01 Before I define Zoombombing let me explain what Zoom is.  Zoom is a very popular video conference service that has a free option that allows many users to have meetings and chat sessions with each other.  It has been on the rise as more people are using it to stay in touch during the coronavirus restrictions. Zoombombing is when an unauthorized person or stranger joins a Zoom meeting/chat session and cause disorder by saying offensive things and even photobombing your meeting by sharing pornographic and hate images.  Imagine if your young kids are participating in an online school meeting and suddenly it is interrupted in that manner.  Well unfortunately is has happened numerous times. Most Zoom meetings have a public link that, if a person were to click it, it will allow them to join.  Malicious individuals or Zoombombers have been collecting these links and sharing them in private chat groups, then signing on to other people’s conferences to cause disruption. On Monday the FBI warned users of a nationwide rise on this issue, as more people have turned to the Zoom video-teleconferencing service.  Zoom the company encouraged users hosting public group meetings to review settings for their safety as well as report incidents to its support team so it could “take appropriate action.” When using Zoom for online classrooms, meetings or events, the host is advised to making meetings private and require a password or use the waiting room feature to control the admittance of additional people.  The links to a teleconference or classroom should be sent directly to the individual participants and never be publicly available on a social media post.  Finally, those managing a conference in Zoom should change the screen sharing option to “Host-Only.” Experts in the field of information security and privacy have provided numerous suggestions when hosting a Zoom event.  Compiled below is a list of recommendations.  I have provided a few of the implementation process to apply these security and privacy features.  For items not covered in this post, please check on the Zoom web page for additional instructions. Zoom Safety Checklist Before Meeting: Disable autosaving chats Disable file transfer Disable screen sharing for non-hosts Disable remote control Disable annotations Use per-meeting ID, not personal ID Disable “Join Before Host” Enable “Waiting Room” During Meeting: Assign at least two co-hosts Mute all participants Lock the meeting, if all attendees are present If you are Zoombombed: Remove problematic users and disable their ability to rejoin when asked Lock the meeting to prevent additional Zoombombers If you schedule a meeting from the web interface, you won’t see the option to disable screen sharing. Instead: Click on “Settings” in the left-hand menu Scroll down to “Screen sharing” and under “Who can share?” click “Host-Only” Click on “Save” On the Zoom Settings page, turn off participant controls: Sign in to Zoom Click on the Settings link on the upper right (it looks like a gear). On the right side of the page, turn off: Autosaving chats, file transfer, screen sharing, and remote control. Assign a Co-Host For larger meetings, identify a co-host or two ahead of time whose role is to be a virtual room monitor and manage order during the meeting by managing the participants. Co-hosts are assigned during a meeting and cannot start a meeting. Sign into Zoom.us. Click on the Settings link on the left of the screen. Scroll down to the Co-host option on the Meeting tab and verify that the setting is enabled. Turn on Co-Host. If a verification dialog displays, choose Turn On to verify the change. Prevent Screen Sharing by non-hosts To prevent participants from screen sharing during a call, use the host controls at the bottom of the window, click the arrow next to Share Screen and then choose Advanced Sharing Options. Under “Who can share?” choose “Only Host” and close the window. You can also lock the Screen Share by default for all of your meetings in your web settings. Enable the Waiting Room Before you start your meeting, enable the Waiting Room for your meeting. You and your co-host will then play an active role in choosing who to allow into the room through the participants' list. Meeting hosts can customize Waiting Room settings for additional control, and can even personalize the message that people see when they enter the Waiting Room so they know they’re in the right spot. This is a great way to post rules and guidelines for your event, like your screen-sharing or muting policy. Locking the Meeting to Prevent Re-Joining of Removed Participants During the meeting, a host or co-host can click on the More and Mute All Controls at the bottom of the Participants List. When viewing the Participants List, click Lock Meeting (under More) to prevent other participants from joining the meeting in progress. Muting All Participants During the meeting, a host or co-host can click on the More and Mute All Controls at the bottom of the Participants list. On the Participants List, click Mute All to mute all meeting attendees.   I hope this information was helpful, more importantly, I hope this information lets you know you do not have to sit back and be a victim and that you have options that can protect your events.  Please share this information with your peers and colleagues.   Good luck and be safe during these trying times… --- ## The CMMC Accreditation Body signs MOU with the U.S. Department of Defense URL: https://securityorb.com/the-cmmc-accreditation-body-signs-mou-with-the-u-s-department-of-defense/ Type: post Modified: 2020-03-25 The CMMC-AB is pleased to announce that it has mutually signed the Memorandum of Understanding (MOU) with the Department of Defense.  We are working to make additional information available to the public in conjunction with our DoD partners, who are necessarily focused on the COVID-19 public crisis. The CMMC-AB continues its collaboration with DoD and industry across multiple lines of effort related to implementing CMMC in support of current milestones. We are grateful for the opportunity to establish and implement CMMC assessment, certification, training, and accreditation processes to help the Department achieve the goals of improving cybersecurity in the Defense Supply Chain. -The Cybersecurity Maturity Model Certification Body --- ## Microsoft Windows SMB Server Could Allow for Remote Code Execution (CVE-2020-0796) - Security Advisory URL: https://securityorb.com/microsoft-windows-smb-server-could-allow-for-remote-code-execution-cve-2020-0796-security-advisory/ Type: post Modified: 2020-03-12 SUBJECT: A Vulnerability in Microsoft Windows SMB Server Could Allow for Remote Code Execution (CVE-2020-0796)   OVERVIEW: A vulnerability has been discovered in Microsoft Windows SMB Server that could allow for remote code execution. Microsoft Server Message Block (SMB) is a network file sharing protocol that allows users or applications to request files and services over the network. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the account running the SMB server and client processes. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.   THREAT INTELLIGENCE: There are no reports of this vulnerability being exploited in the wild.   SYSTEMS AFFECTED: Windows 10 Version 1903 for 32-bit Systems Windows 10 Version 1903 for ARM64-based Systems Windows 10 Version 1903 for x64-based Systems Windows 10 Version 1909 for 32-bit Systems Windows 10 Version 1909 for ARM64-based Systems Windows 10 Version 1909 for x64-based Systems Windows Server, version 1903 (Server Core installation) Windows Server, version 1909 (Server Core installation)   RISK: Government: Large and medium government entities: High Small government entities: Medium Businesses: Large and medium business entities: High Small business entities: Medium Home users: Low   TECHNICAL SUMMARY: A vulnerability has been discovered in Microsoft Windows SMB Server that could allow for remote code execution. This vulnerability is due to an error in handling maliciously crafted compressed data packets within version 3.1.1 of Server Message Blocks. To exploit this vulnerability, an attacker can send specially crafted compressed data packets to a target Microsoft Server Message Block 3.0 (SMBv3) server. Clients who connects to the malicious SMB server would then also be impacted. Microsoft Server Message Block (SMB) is a network file sharing protocol that allows users or applications to request files and services over the network. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the account running the SMB server and client processes. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.     RECOMMENDATIONS: We recommend the following actions be taken: Consider applying the workarounds provided by Microsoft until patches are released; The workaround does not mitigate attacks targetting SMB clients. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. Remind users not to visit websites or follow links provided by unknown or untrusted sources. Inform and educate users regarding the threats posed by hypertext links contained in emails or attachments especially from un-trusted sources. Apply the Principle of Least Privilege to all systems and services.   REFERENCES: Microsoft: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv200005   Tenable: https://www.tenable.com/blog/cve-2020-0796-wormable-remote-code-execution-vulnerability-in-microsoft-server-message-block   CVE: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0796 --- ## Setting up the root account on Kali 2020 URL: https://securityorb.com/setting-up-the-root-account-on-kali-2020/ Type: post Modified: 2020-02-14 Starting with Kali 2020.1, there is no longer a superuser account and the default user is now a standard, non-privileged user.  In Kali Linux 2020.1, both the default username and password are “kali”   If you would like to use root instead of the none superuser account kali, here are the instructions to do so: Issue command "sudo su" Issue command "passwd root" At this point you can log-off and re log-in or you can just switch the user and log in as root.   Let me know if this helped you.   --- ## Kali 2020.1 Default Username & Password - kali kali URL: https://securityorb.com/kali-2020-1-default-username-password-kali-kali/ Type: post Modified: 2020-02-01 Starting with Kali 2020.1, there is no longer a superuser account and the default user is now a standard, non-privileged user. Until now, users have logged on to the system with the user “root” and the password “toor”. In Kali Linux 2020.1, both the default user and password will be “kali”   username: kali password: kali kali linux invalid password root toor for version 2020.1   If you would like to use root instead here are the instructions to do so: Issue command "sudo su" Issue command "passwd root" At this point you can log-off and re log-in or you can just switch the user and log in as root.   Let me know if this helped you.     --- ## Intel Active Management Technology Multiple Vulnerabilities (INTEL-SA-00241) URL: https://securityorb.com/intel-active-management-technology-multiple-vulnerabilities-intel-sa-00241/ Type: post Modified: 2020-01-13 Vulnerability: Intel Active Management Technology Multiple Vulnerabilities (INTEL-SA-00241) Severity: High Location: 623/TCP & 16992/TCP Summary: Multiple potential security vulnerabilities in Intel Active Management Technology (Intel AMT) may allow escalation of privilege, information disclosure, and/or denial of service. Vulnerability Detection Result Installed version: 11.8.55.3510 Fixed version: 11.8.70 Installation path / port:      / Solution type: VendorFix  - Upgrade to version 11.8.70, 11.11.70, 11.22.70, 12.0.45 or later. Affected Software/OS: Intel Active Management Technology 11.0 to 11.8.65, 11.10 to 11.11.65, 11.20 to 11.22.65 and 12.0 to 12.0.35. Vulnerability Insight: Intel Active Management Technology is prone to multiple vulnerabilities: - Cross site scripting may allow a privileged user to potentially enable escalation of privilege via network access (CVE-2019-11132) - Insufficient input validation may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access (CVE-2019-11088) - Logic issue may allow an unauthenticated user to potentially enable escalation of privilege via network access (CVE-2019-11131) - Insufficient input validation may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access (CVE-2019-0131) - Insufficient input validation may allow an unauthenticated user to potentially enable information disclosure via network access (CVE-2019-0166) - Insufficient input validation may allow an unauthenticated user to potentially enable information disclosure via physical access (CVE-2019-11100) Vulnerability Detection Method: Checks if a vulnerable version is present on the target host. Details: Intel Active Management Technology Multiple Vulnerabilities (INTEL-SA-00241) (OID: 1.3.6.1.4.1.25623.1.0.143286) Version used: 2020-01-07T08:25:23+0000 References CVE: CVE-2019-11132, CVE-2019-11088, CVE-2019-11131, CVE-2019-0131, CVE-2019-0166, CVE-2019-11100 CERT: CB-K19/0978, DFN-CERT-2019-2375 Other: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00241.html --- ## Cybersecurity Maturity Model Certification (CMMC) Levels URL: https://securityorb.com/cybersecurity-maturity-model-certification-cmmc-levels/ Type: post Modified: 2020-01-10 The CMMC model has five defined levels, each with a set of supporting practices and processes, illustrated in Figure 2.  Practices range from Level 1 (basic cyber hygiene) and to Level 5 (advance/progressive).  In parallel, processes range from being performed at Level 1, to being documented at Level 2, to being optimized across the organization at Level 5.  To meet a specific CMMC level, an organization must meet the practices and processes within that level and below. Each of the levels is described in more detail below. Level 1 CMMC Level 1 focuses on basic cyber hygiene and consists of the safeguarding requirements specified in 48 CFR 52.204-21.  The Level 1 practices establish a foundation for the higher levels of the model and must be completed by all certified organizations. Not every domain within CMMC has Level 1 practices. At both this level and Level 2, organizations may be provided with FCI. FCI is information not intended for public release. It is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. FCI does not include information provided by the Government to the public. While practices are expected to be performed, process maturity is not addressed at CMMC Level 1, and therefore, a CMMC Level 1 organization may have limited or inconsistent cybersecurity maturity processes. Level 2 CMMC Level 2 focuses on intermediate cyber hygiene, creating a maturity-based progression for organizations to step from Level 1 to 3.  This more advanced set of practices gives the organization greater ability to both protect and sustain their assets against more cyber threats compared to Level 1.  CMMC Level 2 also introduces the process maturity dimension of the model. At CMMC Level 2, an organization is expected to establish and document standard operating procedures, policies, and strategic plans to guide the implementation of their cybersecurity program. Level 3  An organization assessed at CMMC Level 3 will have demonstrated good cyber hygiene and effective implementation of controls that meet the security requirements of NIST SP 800-171 Rev 1. Organizations that require access to CUI and/or generate CUI should achieve CMMC Level 3.  CMMC Level 3 indicates a basic ability to protect and sustain an organization’s assets and CUI; however, at CMMC Level 3, organizations will have challenges defending against advanced persistent threats (APTs).  Note that organizations subject to DFARS clause 252.204-7012 will have to meet additional requirements such as incident reporting.  For process maturity, a CMMC Level 3 organization is expected to adequately resource activities and review adherence to policy and procedures, demonstrating management of practice implementation. Level 4 At CMMC Level 4, an organization has a substantial and proactive cybersecurity program.  The organization has the capability to adapt their protection and sustainment activities to address the changing tactics, techniques, and procedures (TTPs) in use by APTs. For process maturity, a CMMC Level 4 organization is expected to review and document activities for effectiveness and inform high-level management of any issues. Level 5 At CMMC Level 5, an organization has an advanced or progressive cybersecurity program with a demonstrated ability to optimize their cybersecurity capabilities.  The organization has the capability to optimize their cybersecurity capabilities in an effort to repel APTs. For process maturity, a CMMC Level 5 organization is expected to ensure that process implementation has been standardized across the organization. --- ## Understanding Cybersecurity Maturity Model Certification (CMMC) URL: https://securityorb.com/understanding-cybersecurity-maturity-model-certification-cmmc/ Type: post Modified: 2020-01-03 By: Kellep Charles and Adrian Williams So, if you haven’t heard or if you are not familiar with the cybersecurity maturity model certification (CMMC), don’t worry about it, we are here to explain it all to you. The CMMC is a certification procedure developed by the Department of Defense (DoD) to certify contractors have the controls to protect sensitive data including Federal Contract Information and Controlled Unclassified Information (CUI).  The CMMC Model is based on the best-practices of different cybersecurity standards including NIST SP 800-171, NIST SP 800-53, ISO 27001, ISO 27032, AIA NAS9933 and others into one cohesive standard for cybersecurity.  The Domains have seventeen (17) sections listed below: Access Control Asset Management Audit and Accountability Awareness and Training Configuration Management Identification and Authentication Incident Response Maintenance Media Protection Personnel Security Physical Security Recovery Risk Management Security Assessment Situational Awareness Systems and Communications Protection System and Information Integrity The CMMC contains five levels ranging from basic hygiene controls to state-of-the-art controls, but unlike NIST 800-171, the CMMC will not contain a self-assessment component. Every organization that plans to conduct business with the Department of Defense will be required to undergo an audit by an authorized auditing entity before bidding on a contract or subcontracting to a prime. The CMMC is intended to serve as a verification mechanism to ensure appropriate levels of cybersecurity practices and processes are in place to ensure basic cyber hygiene as well as protect controlled unclassified information (CUI) that resides in the Department’s industry partners’ networks.  CUI is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. Version 1.0 of the CMMC framework will be available in January 2020 to support training requirements. In June 2020, the industry should begin to see the CMMC requirements as part of Requests for Information.  The initial implementation of the CMMC will only be within the DoD, but we predict this will be expanded to the Federal sector at some point as well. So, how can we obtain the CMMC for our organization? As stated, there is no self-certification.  Your organization will coordinate directly with an accredited and independent third-party commercial certification organization to request and schedule a CMMC assessment. Your company will specify the level of the certification requested based on your company’s specific business requirements. Your company will be awarded certification at the appropriate CMMC level upon demonstrating the appropriate maturity in capabilities and organizational maturity to the satisfaction of the assessor and certifier.  Once your certification has been obtained, the level will be made public, however, details regarding specific findings will not be publically available. The DoD will only see your certification level. Why is it important? Existing measures have failed the U.S., just take a look at the Chinese J-31 aircraft as a prime example, which is very similar to the American F-35 Joint Strike Fighter.  The question is not whether U.S. adversaries have become better innovators, as compared to becoming better thieves.  The NIST 800-171 relies on organizations to self-assess their posture and then report their compliance.  Self-assessments cannot be truly trusted, thus a new approach is needed. In addition, compliance does not mean you are secure and will never equal that.  Compliance requires only achieving a level of implementation and making sure items are in place.  For example, putting a lock on a door may satisfy a compliance requirement, but the type of lock and the type of door that affects how safe and secure the item being protected can actually be safeguarded.  To address these shortcomings, as well as protect the information, CUI and national security the CMMC is a welcome and needed mechanism. --- ## September Is Insider Threat Awareness Month URL: https://securityorb.com/september-is-insider-threat-awareness-month/ Type: post Modified: 2019-08-26 “Detect, Deter, Mitigate.” That’s the theme of a new government program designating September as Insider Threat Awareness month. With it, securityorb.com/ joins our colleagues in government, industry, and education to promote awareness of this critical threat to the nation and your organization.  Beginning next week, we will be making weekly posts on our social media pages on this topic to help us all stay vigilant in our security awareness and in protecting the data entrusted to us. Anyone can wittingly or unwittingly become an insider threat, and all organizations are vulnerable. Insider incidents damage national security, risk lives and cause the loss of classified information and profit.  They can also result in trade secret theft, fraud, and sabotage that can significantly damage an organization’s business and reputation. Look for the first of our weekly messages this September. --- ## Cyber Safety for Students: The Back to School Edition URL: https://securityorb.com/cyber-safety-for-students-the-back-to-school-edition/ Type: post Modified: 2019-08-25 As the summer break comes to an end, many students will be returning to school with mobile devices, such as smart phones/watches, tablets, and laptops. Although these devices are a great aid in helping students complete school assignments, projects as well as stay in touch with family and friends, there are numerous risks associated with using them. The goal is to help our students manage their digital lives responsibly.  Here are a few simple steps parents and students may use to help keep them safe while using their devices. Kellep Charles, Digital Protection Expert, Researcher and Educator at securityorb.com/ recommends: For the student: No matter what social media platform you are using, consider the type of information you are sharing with others and ensure you are limiting it to prevent your identity from being compromised. Here are the common cyber risks you may face when using social media: Sharing sensitive information - Sensitive information includes anything that can help a person steal your identity or find you, such as your full name, Social Security number, address, birthdate, phone number, or where you were born. Posting questionable content - Remember when applying for school or future employment, they may look at your social media accounts before bringing you on board. Questionable content can include pictures, videos, or opinions that may be offensive, rude, vile, seem unprofessional or mean and can damage your reputation or future opportunities. Tracking your location - Many social media platforms allow you to check in and broadcast your location, or automatically adds your location to photos and posts. Think twice before allowing that to happen.   SIMPLE TIPS Remember, there is no ‘Delete’ button on the Internet. Think before you post, because even if you delete a post or picture from your profile only seconds after posting it, there is a good chance someone still saw it and may have obtained a copy. Don’t broadcast your location. Location or geo-tagging features on social networks is not the safest feature to activate. You could be telling a stalker exactly where to find you or telling a thief that you are not home. Connect only with people you trust. While some social networks might seem safer for connecting because of the limited personal information shared through them, keep your connections to people you know and trust. Keep certain things private from everyone. Certain information should be kept completely off your social networks to begin with. While it’s fun to have everyone wish you a happy birthday, or for long-lost friends to reconnect with you online, listing your date of birth with your full name and address gives potential identity thieves pertinent information. Other things to keep private includes sensitive pictures or information about friends and family. Just because you think something is amusing does not mean you should share it with the world. Speak up if you’re uncomfortable. If a friend posts something about you that makes you uncomfortable or you think is inappropriate, let them know. Likewise, stay open-minded if a friend approaches you because something you’ve posted makes them feel uncomfortable. People have different tolerances for how much the world knows about them, and it is important to respect those differences. Also report any instances of cyber bullying you see.   For the Parents: BE AWARE OF WHAT YOUR KIDS POST ONLINE. Understand the cyber risks kids face when using social media. Talk to your kids about the following risks: What they are posting - Talk to your kids about the information they post online. Many of them don’t understand the damage they could do to their reputation or future prospects with unkind or angry posts and compromising photos or videos. Ensure your kids are not sharing or posting sensitive information - Sensitive information includes anything that can help a person steal your child’s identity or find them, such as their/your full name, Social Security number, address, birthdate, phone number, or place of birth. Compromising content - This includes photos or status updates that may damage your child’s reputation or future prospects. Unkind or angry content - This includes anything malicious directed at themselves or another person, as well as opinions that are probably better left unshared. Who they are connecting with - Social media allows kids to connect with their friends, but there is also a risk of connecting with someone they do not know or who is only pretending to be a kid. What level of privacy they are using - Many social media platforms have privacy settings that allow users to limit who sees their content. There are also settings for location tracking and geo-tagging of photos or statuses.   SIMPLE TIPS FOR PARENTS Talk to your kids. Help them understand the importance of owning their digital lives and only sharing things that will not put them in danger, negatively affect their future, or harm others. Emphasize the concept of credibility to teens: not everything they see on the Internet is true and people on the Internet may not be who they appear to be. Watch for changes in their behavior. If your child suddenly avoids the computer, it may be a sign they are being bullied or stalked online. Review security settings and privacy policies for the social media sites kids frequent. These settings are frequently updated so check back regularly. Periodically review social media accounts to ensure no questionable content or inappropriate connections are established.   The bottom-line mobile devices and the Internet are wonderful things and every step should be taken to be a good digital citizen.  Unfortunately, even when you follow the proper steps, bad things can occur.  Understanding what to do and where to go can be the difference maker. --- ## EC Council Coming to Capitol Technology University URL: https://securityorb.com/ec-council-coming-to-capitol-technology-university/ Type: post Modified: 2019-08-19 November 14 and 15 Capitol Technology University is hosting a cybersecurity conference. Day 1 will be EC Council Advanced workshops. You may sign up here https://iclass.eccouncil.org/capitol-technology/.  Day two will be presentations of accepted research papers. All papers must be submitted by October 15 and accepted papers will be published in a special edition of the American Journal of Science and Engineering ( you can get their template here:http://ajse.us/instruction-for-authors/ ) Send submissions to:wceasttom@captechu.edu --- ## The Capital One Data Breach and What Can You Do to Protect Yourself URL: https://securityorb.com/the-capital-one-data-breach-and-what-can-you-do-to-protect-yourself/ Type: post Modified: 2019-07-30 In one of the biggest data breaches, a hacker by the name Paige Thompson gained access to more than 140,000 Social Security numbers, 1 million Canadian Social Insurance numbers and 80,000 bank account numbers, in addition to an undisclosed number of people's names, addresses, credit scores, credit limits, balances, and other information.  However, the company stated no credit card account numbers or log-in credentials were compromised in the breach. Capital One first heard about the hack on July 19th, but waited until July 29th to inform customers as they worked with law enforcement to investigate the breach. Paige who is 33-year-old, and lives in Seattle, had previously worked as a software engineer for Amazon Web Services, the cloud hosting company that Capital One was using. She was able to gain access on March 22 and 23 by exploiting a misconfigured web application firewall. Thompson posted the information on GitHub, a site where developers store their projects and network with like-minded people, using her full name and also boasted on social media that she had Capital One information and the method she used to obtain the data. What will Capital One do for you? The breach affected around 100 million people in the United States and about 6 million people in Canada, according to Capital One.  Consumers and small businesses who applied for Capital One credit cards from 2005 through early 2019 are most at risk at this time.  Capital One will offer $125 to anyone whose data was hacked or free credit monitoring for 10 years. What should you do to protect yourself? securityorb.com/ recommends the following steps to protecting yourself after a possible data breach: Change your passwords immediately and when creating the new password use a combination of upper and lower case letters, numbers and symbols, and that each website you visit should have a unique password.   You should consider using multifactor authentication instead of passwords.   You should never give out personal details over the telephone, even if the caller seems to represent Capital One or the email appears to be from a Capital One address.   You need to be careful whenever you are contacted by an unsolicited caller. Hang up and call the number on your card.   You should immediately freeze your credit reports at the three major firms: Equifax, Experian and TransUnion.   You should check your credit card statement to make sure there are no unauthorized charges.   You should file your taxes as early as possible.   This is the latest in a long line of data breaches, privacy violations and hacks affecting hundreds of millions of Americans. Two years after Equifax revealed that hackers accessed the personal information of up to 147 million people.   Last year, Facebook announced that U.K.-based Cambridge Analytica improperly accessed 87 million Facebook users’ data.   WhatsApp, the messaging and audio app owned by Facebook, announced last May that hackers were able to install spyware on Android smartphones and Apple Capital One says it will notify affected individuals via a variety of channels, and make free credit monitoring and identity protection available to everyone affected. --- ## CentOS Update for bpftool CESA-2018:3651 centos7 URL: https://securityorb.com/centos-update-for-bpftool-cesa-20183651-centos7/ Type: post Modified: 2019-03-01 CentOS Update for bpftool CESA-2018:3651 centos7 (OID: 1.3.6.1.4.1.25623.1.0.882981) SummaryThe remote host is missing an update for the 'bpftool' package(s) announced via the CESA-2018:3651 advisory. Vulnerability Detection Result Package kernel version kernel-3.10.0-862.el7 is installed which is known to be vulnerable. SolutionSolution type: VendorFix Please install the updated package(s). Affected Software/OSbpftool on CentOS 7. Vulnerability InsightThe kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: stack-based buffer overflow in chap_server_compute_md5() in iscsi target (CVE-2018-14633) * kernel: NULL pointer dereference in af_netlink.c:__netlink_ns_capable() allows for denial of service (CVE-2018-14646) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. Red Hat would like to thank Vincent Pelletier for reporting CVE-2018-14633 and Christian Brauner for reporting CVE-2018-14646. Bug Fix(es): These updated kernel packages include also numerous bug fixes. Space precludes documenting all of the bug fixes in this advisory. Vulnerability Detection MethodChecks if a vulnerable package version is present on the target host. Details: CentOS Update for bpftool CESA-2018:3651 centos7 (OID: 1.3.6.1.4.1.25623.1.0.882981) Version used: $Revision: 12880 $ References CVE: CVE-2018-14633, CVE-2018-14646 CERT: CB-K18/1124, CB-K18/0942, DFN-CERT-2019-0115, DFN-CERT-2018-2579, DFN-CERT-2018-2458, DFN-CERT-2018-2421, DFN-CERT-2018-2398, DFN-CERT-2018-2366, DFN-CERT-2018-2318, DFN-CERT-2018-2304, DFN-CERT-2018-2280, DFN-CERT-2018-2252, DFN-CERT-2018-2129, DFN-CERT-2018-2099, DFN-CERT-2018-2039, DFN-CERT-2018-2029, DFN-CERT-2018-1995, DFN-CERT-2018-1990, DFN-CERT-2018-1963 Other: CESA:2018:3651 http://lists.centos.org/pipermail/centos-announce/2018-December/023132.html --- ## MyFitnessPal Data Breach URL: https://securityorb.com/myfitnesspal-data-breach/ Type: post Modified: 2019-02-21 Breach: MyFitnessPal Date of breach: 1 Feb 2018 Number of accounts: 143,606,147 Compromised data: Email addresses, IP addresses, Passwords, Usernames Description: In February 2018, the diet and exercise service MyFitnessPal suffered a data breach. The incident exposed 144 million unique email addresses alongside usernames, IP addresses and passwords stored as SHA-1 and bcrypt hashes (the former for earlier accounts, the latter for newer accounts). In 2019, the data appeared listed for sale on a dark web marketplace (along with several other large breaches) and subsequently began circulating more broadly. The data was provided to HIBP by a source who requested it to be attributed to "BenjaminBlue@exploit.im". --- ## I’ve Been Hacked – What To Do After You’ve Been Hacked URL: https://securityorb.com/ive-been-hacked-what-to-do-after-youve-been-hacked/ Type: post Modified: 2018-12-07 By Carter Graydon at Hacked.com There’s nothing quite like that feeling of dread that slowly envelops you when you realize you’ve been backed. Regardless if it’s just your social media account or something as serious as your bank account or credit card, you can’t escape those first few moments of confusion, anger, and the overwhelming sense of fear. You don’t know how they got your information, what other accounts they’ve had access to, how long they’ve had access, and it’s terrifying. So I’ve come up with a checklist to help you protect yourself from further damage and begin the repairing process. Do Not Panic First off, breath. It might sound silly, but you need a clear head to proceed. Panic and fear will only lead to confusion. You can easily forget crucial steps you need to take or repeat ones and waste time. Change your Passwords Change your passwords, especially if you use the same password for multiple accounts. You should change your passwords once every 3-6 months. Consider using a password management software like LastPass or KeePass. In the future, set up two-factor authentication when possible. Identity Theft? Notify Credit Agencies If your personal information (such as social security number) has been compromised, notify the credit agencies (Equifax, Experian and TransUnion) and request a 90-day credit alert. Activating this tells businesses to contact you before any new account can be opened in your name. This alert can be renewed every 90 days. It can also stay in effect for seven years – so long as your identity has been stolen, and you’ve filed a report with the police. The Federal Trade Commission also offers some excellent advice and includes details on how to get your life back after your identity has been stolen. Monitor your Credit Card Bills Monitor your credit card bills and double check any charges you don’t recognize. Criminals are known to make small charges to begin with, hoping they’ll go unnoticed, before running your card for something really big. If you see a charge you didn’t make, call the credit card company and alert them right away. Close Accounts If someone has already stolen your identity and opened an account, immediately contact the credit issuer and have the account closed. Dispute any charges that were made. Request your credit report from one of the three credit agencies and ask for any unauthorized accounts or incorrect information be removed from your record. This will help preserve your credit score. Record Calls Submit your report through the FTC website and keep copies of all your reports and correspondences with these agencies. Record everything, use certified mail and get delivery receipts. Most of the places you’ll need to call will have a notice, “This call may be recorded for quality assurance purposes”, but don’t rely on them for recording the conversation. Record the call yourself, but be sure to inform the person on the other end of the line that you are recording the call. Check your state for telephone recordings laws. Check the Sent Folder in your Email Check your sent folder of your email and look for any messages that may have gone out that you didn’t send. Hackers might request personal information from banks or send viruses to your friends. If you see anything suspicious, contact the recipients and let them know. If the hacker has gained access to your account and locked you out by changing the password, you’ll need to contact the email provider and prove you’re the rightful account holder. And remember, if you’ve used your email address and the same password for other websites, those are all compromised as well. Change those as fast as you can to beat them to the draw. Even if you don’t use the same password for those accounts, the hacker can still use the “forget my password” feature and have a new one email to them. If you’re concerned, your computer may have a virus, avoid making online purchases until you have run comprehensive anti-virus and malware software. Some virus installs keyloggers on your computer, letting the hacker see every keystroke. Typing in your credit card information is all they would need. --- ## First it was Marriott, now Quora has been Hacked… URL: https://securityorb.com/first-it-was-marriot-now-quora-has-been-hacked/ Type: post Modified: 2018-12-06 100 million Quora users may have had their data accessed by an unauthorized third party. Quora is actively investigating the incident, and has already taken steps to improve its security. What happened On Friday we discovered that some user data was compromised by a third party who gained unauthorized access to one of our systems. We're still investigating the precise causes and in addition to the work being conducted by our internal security teams, we have retained a leading digital forensics and security firm to assist us. We have also notified law enforcement officials. While the investigation is still ongoing, we have already taken steps to contain the incident, and our efforts to protect our users and prevent this type of incident from happening in the future are our top priority as a company. Read more on their blog here.   --- ## Marriott Data Breach and What You Need to Know URL: https://securityorb.com/marriott-data-breach-and-what-you-need-to-know/ Type: post Modified: 2018-12-05 Marriott just announced a data breach that’s exposed sensitive customer info Here’s what you need to know about the Marriott breach ·       Marriott International said its Starwood guest reservation database was breached, exposing the personal info of about 500 million customers. ·       Compromised data includes: Name, address, phone number, email address, passport number, Starwood Preferred Guest ("SPG") account info, date of birth and more. ·       Some customers’ info also includes payment card numbers and expiration dates, but the payment card numbers were encrypted. How to protect your info after this breach To support you during this time, we've put together some guidelines to help you protect yourself: ·       Stay alert for new info. If you have been part of a data breach, the breached company may send you a notice. Retain all documents and consider any suggestions they may have. Also, pay attention to and retain any mail you receive that is unfamiliar to you, such as notices from the IRS regarding your taxes or any bills from unknown lenders. ·       Change your passwords on any accounts that may have been breached and remember to use unique passwords across different accounts. ·       Keep an eye on your financial accounts online and set up any alert features they may have. This could help save time and keep you notified of any unusual events if they occur. ·       Monitor your credit and identity by checking your credit reports at each of the 3 credit bureaus for free once every 12 months. Look for unusual activity, such as new accounts, personal info or inquiries. --- ## The SecurityOrb Show – An Interview with Dr. Elizabeth Milovidov, Esq. founder of DigitalParentingCoach.com. – 11/27/2018 URL: https://securityorb.com/the-securityorb-show-an-interview-with-dr-elizabeth-milovidov-esq-founder-of-digitalparentingcoach-com-11-27-2018/ Type: post Modified: 2018-11-29 I had the opportunity to speak with Dr. Elizabeth Milovidov, Esq. founder of DigitalParentingCoach.com about Internet Safety. Listen to what Dr. Milovidov has to say here:   /Podcast/Elizabeth.wav Elizabeth Milovidov is an American lawyer, a French law professor and a European eSafety consultant. She founded Digital Parenting Coach and provides support to governments and associations. From 2014-2016, she consulted for European Schoolnet, a European consortium of 30 Education Ministries on several internet-related projects, including the ENABLE (the European Network Against Bullying in Learning and Leisure Environments) project and 2017-2018 she helped create the e-Salama national child online protection plan in Morocco. Currently, she is consulting for the Digital Society division of the Ministry of Transport and Communication, Qatar. She provides support to EU Kids Online, Internet Matters, UK Safer Internet Centre, Family Online Safety institute, DigiLitEY and many other key actors in online child protection. She is a frequent guest on France 24 where she shares digital parenting tips and strategies. She regularly intervenes as an independent expert on Children’s Rights and the Internet and Digital Parenting for the Council of Europe and is currently an Expert Working Group member on Digital Citizenship Education as well as a member of the Drafting Group of Specialists on Children and the Digital Environment. She has several publications on parenting in the digital age available on Amazon and co-wrote the Internet Literacy Handbook for the Council of Europe. She is an international speaker on Internet safety issues, leads parental workshops, writes on digital parenting, and coaches parents on best practices in the digital age through her website www.digitalparentingcoach.com and Facebook Group, The Digital Parenting Community. A graduate of UCLA and UC Davis, she practiced as a litigator in California for four years before moving to France to work as General Counsel in two Internet Technology companies. She earned a Ph.D. in International Relations and Diplomacy from the American Graduate School (AGS) in Paris (dissertation: international adoption via Internet and photo listings). She is an Assistant Professor at AGS and a lecturer at several universities in France and Geneva and specializes in Law and Technology (ISCOM, Paris), Intellectual Property and Internet Law (INSEEC, Paris) and Children’s Rights and the Internet (University of Geneva, Geneva).   --- ## CVE-2018-15454 (Cisco SIP) Exploit Information URL: https://securityorb.com/cve-2018-15454-cisco-sip-exploit-information/ Type: post Modified: 2018-11-19 IB-18-20248-CVE-2018-15454 Exploit Attempts Against Government Facilities Sector TLP: AMBER Department of Homeland Security NCCIC US-CERT Reference Number: IB-18-20248 Report Date: 2018-11-15T22:19:01+00:00   Notification:   DISCLAIMER: This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. The DHS does not endorse any commercial product or service, referenced in this bulletin or otherwise. This document is distributed as TLP:AMBER: Limited disclosure, restricted to participants' organizations. Recipients may only use TLP:AMBER information with members of their own organization, and with clients or customers who need to know the information to protect themselves or prevent further harm. For more information on the Traffic Light Protocol, see http://www.us-cert.gov/tlp.   Summary:   From October 2018, NCCIC analysts have observed network traffic indicating attempts, by unknown actors against multiple government agencies, to exploit a vulnerability [CVE-2018-15454] in the Session Initiation Protocol (SIP) inspection engine of Cisco ASA Software and Cisco FTD Software. This vulnerability could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU usage, resulting in a DoS condition.   The vulnerability is due to improper handling of SIP traffic and affects Cisco ASA Software Release 9.4 and later and Cisco FTD Software Release 6.0 and later if SIP inspection is enabled (ENABLED BY DEFAULT). An attacker could exploit this vulnerability by sending SIP requests designed to specifically trigger this issue at a high rate on any of the following Cisco products:   - 3000 Series Industrial Security Appliance (ISA) - ASA 5500-X Series Next-Generation Firewalls - ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers - Adaptive Security Virtual Appliance (ASAv) - Firepower 2100 Series Security Appliance - Firepower 4100 Series Security Appliance - Firepower 9300 ASA Security Module - FTD Virtual (FTDv)   This activity was observed in the Government Facilities Sector.   Analysis:   Host IPv4: 46.249.59.196 Sighted: 2018-10-19 [only single sightings used] Killchain Phase: Exploitation Characterization: IP Watchlist Notes: NCCIC analysts have observed network traffic from this IP address, related to attempts by unknown actors against multiple government agencies, to exploit a vulnerability [CVE-2018-15454] in the Session Initiation Protocol (SIP) inspection engine of Cisco ASA Software and Cisco FTD Software. This vulnerability could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU usage, resulting in a DoS condition.   Attempted scanning/exploit activity will be over port 5060 and will show a large number of incomplete SIP connections while the vulnerability is actively being exploited.   Open source research indicates this IP is geolocated in the Netherlands [ASN: AS50673]. Reporting by security vendors indicate this IP has been involved in scanning, brute force attempts, and other malicious network activity.   Host IPv4: 5.62.63.223 Sighted: 2018-10-19 [only single sightings used] Killchain Phase: Exploitation Characterization: IP Watchlist Notes: NCCIC analysts have observed network traffic from this IP address, related to attempts by unknown actors against multiple government agencies, to exploit a vulnerability [CVE-2018-15454] in the Session Initiation Protocol (SIP) inspection engine of Cisco ASA Software and Cisco FTD Software. This vulnerability could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU usage, resulting in a DoS condition.   Attempted scanning/exploit activity will be over port 5060 and will show a large number of incomplete SIP connections while the vulnerability is actively being exploited.   Open source research indicates this IP has a point-of-presence (PoP) in the United Kingdom [ASN: AS198605] and virtual PoP in the United States. Reporting by security vendors indicate this IP has been involved in scanning, brute force attempts, and other malicious network activity.   Host IPv4: 212.129.19.40 Sighted: 2018-10-19 [only single sightings used] Killchain Phase: Exploitation Characterization: IP Watchlist Notes: NCCIC analysts have observed network traffic from this IP address, related to attempts by unknown actors against multiple government agencies, to exploit a vulnerability [CVE-2018-15454] in the Session Initiation Protocol (SIP) inspection engine of Cisco ASA Software and Cisco FTD Software. This vulnerability could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU usage, resulting in a DoS condition.   Attempted scanning or exploit activity can be observed over port 5060 and shows a large number of incomplete SIP connections while the vulnerability is actively being exploited.   Open source research indicates this IP is geolocated in France [ASN: AS12876]. Reporting by security vendors indicate this IP has been involved in scanning, brute force attempts, and other malicious network activity. --- ## Amazon AWS GuardDuty URL: https://securityorb.com/amazon-guardduty/ Type: post Modified: 2018-11-16 What Is Amazon GuardDuty? Amazon GuardDuty is a continuous security monitoring service that analyzes and processes the following data sources: VPC Flow Logs, AWS CloudTrail event logs, and DNS logs. It uses threat intelligence feeds, such as lists of malicious IPs and domains, and machine learning to identify unexpected and potentially unauthorized and malicious activity within your AWS environment. This can include issues like escalations of privileges, uses of exposed credentials, or communication with malicious IPs, URLs, or domains. For example, GuardDuty can detect compromised EC2 instances serving malware or mining bitcoin. It also monitors AWS account access behavior for signs of compromise, such as unauthorized infrastructure deployments, like instances deployed in a region that has never been used, or unusual API calls, like a password policy change to reduce password strength. GuardDuty informs you of the status of your AWS environment by producing security findings that you can view in the GuardDuty console or through Amazon CloudWatch events. How Amazon GuardDuty Uses Its Data Sources To detect unauthorized and unexpected activity in your AWS environment, GuardDuty analyzes and processes data from AWS CloudTrail event logs, VPC Flow Logs, and DNS logs. The logs from these data sources are stored in the Amazon S3 buckets. GuardDuty accesses them there using the HTTPS protocol. While in transit from these data sources to GuardDuty, all of the log data is encrypted. GuardDuty extracts various fields from these logs for profiling and anomaly detection, and then discards the logs. The following sections describe the details of how GuardDuty uses each supported data source. Topics AWS CloudTrail event logs VPC Flow Logs DNS logs AWS CloudTrail event logs AWS CloudTrail provides you with a history of AWS API calls for your account, including API calls made using the AWS Management Console, the AWS SDKs, the command line tools, and higher-level AWS services. CloudTrail also allows you to identify which users and accounts called AWS APIs for services that support CloudTrail, the source IP address that the calls were made from, and when the calls occurred. For more information, see What is AWS CloudTrail? You can configure CloudTrail trails to log management events and/or data events. Management events provide insight into management operations that are performed on resources in your AWS account. For example, configuring security (IAM AttachRolePolicy API operations), registering devices (Amazon EC2 CreateDefaultVpc API operations), configuring rules for routing data (Amazon EC2 CreateSubnet API operations), or setting up logging (AWS CloudTrail CreateTrail API operations). Data events provide insight into the resource operations performed on or within a resource. For example, Amazon S3 object-level API activity (GetObject, DeleteObject, and PutObject API operations) or AWS Lambda function execution activity (the Invoke API). For more information, see Logging Data and Management Events for Trails. Currently, GuardDuty only analyzes CloudTrail management events. If you have CloudTrail configured to log data events, there will be a difference between GuardDuty analysis based on CloudTrail data and the logs that CloudTrail itself is delivering. Another important detail about GuardDuty's usage of CloudTrail as a data source is the handling and processing of CloudTrail's global events. For most services, events are recorded in the region where the action occurred. For global services such as AWS IAM, AWS STS, Amazon CloudFront, and Route 53, events are delivered to any trail that includes global services, and are logged as occurring in US East (N. Virginia) Region. For more information, see About Global Service Events. GuardDuty processes all events that come into a region, including global events that CloudTrail sends to all regions. This allows GuardDuty to maintain user and role profiles in each region and enables it to accurately detect credentials that are being maliciously used across regions. Important It is highly recommended that you enable GuardDuty in all supported AWS regions. This allows GuardDuty to generate findings about unauthorized or unusual activity even in regions that you are not actively using. This also allows GuardDuty to monitor AWS CloudTrail events for global AWS services. If GuardDuty is not enabled in all supported regions, its ability to detect activity that involves global services is reduced. VPC Flow Logs VPC Flow Logs capture information about the IP traffic going to and from Amazon EC2 network interfaces in your VPC. For more information, see VPC Flow Logs. Important When you enable GuardDuty, it immediately starts analyzing your VPC Flow Logs data. It consumes VPC Flow Log events directly from the VPC Flow Logs feature through an independent and duplicative stream of flow logs. This process does not affect any existing flow log configurations that you might have. GuardDuty doesn't manage your flow logs or make them accessible in your account. To manage access and retention of your flow logs, you must configure the VPC Flow Logs feature. There is no additional charge for GuardDuty access to flow logs. However, enabling flow logs for retention or use in your account falls under existing pricing. For more information, see Working With Flow Logs. DNS logs If you use AWS DNS resolvers for your EC2 instances (the default setting), then GuardDuty can access and process your request and response DNS logs through the internal AWS DNS resolvers. If you are using a 3rd party DNS resolver, for example, OpenDNS or GoogleDNS, or if you set up your own DNS resolvers, then GuardDuty cannot access and process data from this data source. Pricing for GuardDuty For information about GuardDuty pricing, see Amazon GuardDuty Pricing. Accessing GuardDuty You can work with GuardDuty in any of the following ways: GuardDuty Console https://console.aws.amazon.com/guardduty The console is a browser-based interface to access and use GuardDuty. AWS SDKs AWS provides software development kits (SDKs) that consist of libraries and sample code for various programming languages and platforms (Java, Python, Ruby, .NET, iOS, Android, and more). The SDKs provide a convenient way to create programmatic access to GuardDuty. For information about the AWS SDKs, including how to download and install them, see Tools for Amazon Web Services. GuardDuty HTTPS API You can access GuardDuty and AWS programmatically by using the GuardDuty HTTPS API, which lets you issue HTTPS requests directly to the service. For more information, see the Amazon GuardDuty API Reference. --- ## Amazon AWS Inspector URL: https://securityorb.com/amazon-aws-inspector/ Type: post Modified: 2018-11-15 What is Amazon Inspector? Amazon Inspector is an automated security assessment service that helps you test the network accessibility of your Amazon EC2 instances and the security state of your applications running on those instances. Amazon Inspector allows you to automate security vulnerability assessments throughout your development and deployment pipeline or against static production systems. This allows you to make security testing a more regular occurrence as part of development and IT operations. Amazon Inspector is an API-driven service that uses an optional agent, making it easy to deploy, manage, and automate. Amazon Inspector assessments are offered to you as pre-defined rules packages mapped to common security best practices and vulnerability definitions. Amazon Inspector consists of a technology that analyzes your network configurations, an Amazon-developed agent that is installed in the operating system of your EC2 instances, and a security assessment service that uses telemetry from the agent and AWS configurations to assess instances for security exposures and vulnerabilities. Important AWS does not guarantee that following the provided recommendations will resolve every potential security issue. The findings generated by Amazon Inspector depend on your choice of rules packages included in each assessment template, the presence of non-AWS components in your system, and other factors. You are responsible for the security of applications, processes, and tools that run on AWS services. For more information, see the AWS Shared Responsibility Model for security. Note AWS is responsible for protecting the global infrastructure that runs all the services offered in the AWS cloud. This infrastructure comprises the hardware, software, networking, and facilities that run AWS services. AWS provides several reports from third-party auditors who have verified our compliance with a variety of computer security standards and regulations. For more information, see AWS Cloud Compliance. For more information, see Amazon Inspector Terminology and Concepts. Benefits of Amazon Inspector Amazon Inspector enables you to quickly and easily assess the security of your AWS resources for forensics, troubleshooting, or active auditing purposes at your own pace, either as you progress through the development of your infrastructures or on a regular basis in a stable production environment. Amazon Inspector enables you to focus on more complex security problems by offloading the overall security assessment of your infrastructure to this automated service. By using Amazon Inspector, you can gain deeper understanding of your AWS resources because Amazon Inspector findings are produced through the analysis of the real activity and configuration data of your AWS resources. Features of Amazon Inspector Configuration Scanning and Activity Monitoring Engine - Amazon Inspector provides an engine that analyzes system and resource configuration and monitors activity to determine what an assessment target looks like, how it behaves, and its dependent components. The combination of this telemetry provides a complete picture of the assessment target and its potential security or compliance issues. Built-in Content Library - Amazon Inspector incorporates a built-in library of rules and reports. These include checks against best practices, common compliance standards and vulnerabilities. These checks include detailed recommended steps for resolving potential security issues. Automatable via API - Amazon Inspector is fully automatable via an API. This allows organizations to incorporate security testing into the development and design process, including selecting, executing, and reporting the results of those tests. Amazon Inspector Pricing Amazon Inspector pricing is based on the number of Amazon EC2 instances included in each assessment and the rules packages used in those assessments. For detailed information about Amazon Inspector pricing, see Amazon Inspector Pricing. Accessing Amazon Inspector You can work with the Amazon Inspector service in any of the following ways. Amazon Inspector Console Sign in to the AWS Management Console and open the Amazon Inspector console at https://console.aws.amazon.com/inspector/. The console is a browser-based interface to access and use the Amazon Inspector service. AWS SDKs AWS provides software development kits (SDKs) that consist of libraries and sample code for various programming languages and platforms (Java, Python, Ruby, .NET, iOS, Android, and more). The SDKs provide a convenient way to create programmatic access to the Amazon Inspector service. For information about the AWS SDKs, including how to download and install them, see Tools for Amazon Web Services. Amazon Inspector HTTPS API You can access Amazon Inspector and AWS programmatically by using the Amazon Inspector HTTPS API, which lets you issue HTTPS requests directly to the service. For more information, see the Amazon Inspector API Reference. AWS Command Line Tools You can use the AWS command line tools to issue commands at your system's command line to perform Amazon Inspector tasks; this can be faster and more convenient than using the console. The command line tools are also useful if you want to build scripts that perform AWS tasks. For more information, see the Amazon Inspector's AWS Command Line Interface. --- ## Using Docker To Install OpenVAS On CentOS URL: https://securityorb.com/using-docker-to-install-openvas-on-centos/ Type: post Modified: 2018-11-14 An interesting post from Gerry Williams at gerrywilliams.net Description: Saw a post on r/sysadmin the other day with a walkthrough on using Docker for the first time. Thought I would take some notes: To Resolve: 1. On the host computer, open up Hyper V and create a new Virtual Machine. Download the Centos7 iso if you don’t already have it. 2. Before starting the virtual machine, we need to edit its properties: 2a. Change UEFI option to UEFI Authority 2b. Change Network Adapter to Enable MAC Address spoofing 2c. Enable Nested Virtualization. On the host machine, open Powershell as admin and type: Set-Vmprocessor -Vmname Docker -Enablevirtualizationextensions $True 1 Set-Vmprocessor -Vmname Docker -Enablevirtualizationextensions $True 3. Install Centos7 minimal on a Virtual Machine. 4. Update it and give it a static IP, and install Docker stuff: # Update:
sudo yum update

# Set a static ip = https://www.gerrywilliams.net/2016/10/setting-a-static-ip-in-centos/

# Install docker
yum install -y yum-utils device-mapper-persistent-data lvm2
yum-config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo
yum-config-manager --enable docker--ce-edge
yum-config-manager --enable docker--ce-test
yum install docker-ce

# Start and enable docker
systemctl start docker
systemctl enable docker 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 # Update: sudo yum update # Set a static ip = https://www.gerrywilliams.net/2016/10/setting-a-static-ip-in-centos/ # Install docker yum install -y yum-utils device-mapper-persistent-data lvm2 yum-config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo yum-config-manager --enable docker--ce-edge yum-config-manager --enable docker--ce-test yum install docker-ce # Start and enable docker systemctl start docker systemctl enable docker 5. Now that docker is installed, we can search for images to run. For example, let’s install OpenVAS: # Search docker images:
docker search openvas

# Download an image
docker pull mikesplain/openvas

# See images
docker images 1 2 3 4 5 6 7 8 # Search docker images: docker search openvas # Download an image docker pull mikesplain/openvas # See images docker images 6. Now lets start and run it: # To run: The command breakdown is: -d is background (detach), -p is ports, --name is just a name, and last is the image file.
docker run -d -p 443:443 -p 9390:9390 --name openvas mikesplain/openvas

# To see running docker images:
docker ps

# To see installation logs
docker logs -ft mikesplain/openvas

# Add firewall exceptions:
firewall-cmd --zone=public --add-port=443/tcp --permanent
firewall-cmd --zone=public --add-port=9390/tcp --permanent
firewall-cmd --reload

# To see all containers created, but some may be offline
docker ps -a 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 # To run: The command breakdown is: -d is background (detach), -p is ports, --name is just a name, and last is the image file. docker run -d -p 443:443 -p 9390:9390 --name openvas mikesplain/openvas # To see running docker images: docker ps # To see installation logs docker logs -ft mikesplain/openvas # Add firewall exceptions: firewall-cmd --zone=public --add-port=443/tcp --permanent firewall-cmd --zone=public --add-port=9390/tcp --permanent firewall-cmd --reload # To see all containers created, but some may be offline docker ps -a 7. That is it, if you want to see the OpenVAS web GUI, just go to https://10.10.10.23 (if the Centos VM static IP is 10.10.10.23) in a browser on CentOS. It should bring up OpenVAS login! Creds are ‘admin/admin’   Video: --- ## OpenVAS image for Docker on Ubuntu URL: https://securityorb.com/openvas-image-for-docker-on-ubuntu/ Type: post Modified: 2018-11-14 A Docker container for OpenVAS on Ubuntu. By default, the latest images includes the OpenVAS Base as well as the NVTs and Certs required to run OpenVAS. We made the decision to move to 9 as the default branch since 8 seems to have many issues in docker. We suggest you use 9 as it is much more stable. Our Openvas9 build was designed to be a smaller image with fewer extras built in. Please note, OpenVAS 8 is no longer being built as OpenVAS 9 is now standard. The image is can still be pulled from the Docker hub, however the source has been removed in this github as is standard with deprecated Docker Images. Openvas Version Tag Web UI Port 9 latest/9 443 Usage Simply run: # latest (9) docker run -d -p 443:443 --name openvas mikesplain/openvas # 9 docker run -d -p 443:443 --name openvas mikesplain/openvas:9 This will grab the container from the docker registry and start it up. Openvas startup can take some time (4-5 minutes while NVT's are scanned and databases rebuilt), so be patient. Once you see a It seems like your OpenVAS-9 installation is OK. process in the logs, the web ui is good to go. Goto https:// Username: admin Password: admin To check the status of the process, run: docker top openvas In the output, look for the process scanning cert data. It contains a percentage. To run bash inside the container run: docker exec -it openvas bash Specify DNS Hostname By default, the system only allows connections for the hostname "openvas". To allow access using a custom DNS name, you must use this command: docker run -d -p 443:443 -e PUBLIC_HOSTNAME=myopenvas.example.org --name openvas mikesplain/openvas OpenVAS Manager To use OpenVAS Manager, add port 9390 to you docker run command: docker run -d -p 443:443 -p 9390:9390 --name openvas mikesplain/openvas Volume Support We now support volumes. Simply mount your data directory to /var/lib/openvas/mgr/: mkdir data docker run -d -p 443:443 -v $(pwd)/data:/var/lib/openvas/mgr/ --name openvas mikesplain/openvas Note, your local directory must exist prior to running. Set Admin Password The admin password can be changed by specifying a password at runtime using the env variable OV_PASSWORD: docker run -d -p 443:443 -e OV_PASSWORD=securepassword41 --name openvas mikesplain/openvas Update NVTs Occasionally you'll need to update NVTs. We update the container about once a week but you can update your container by execing into the container and running a few commands: docker exec -it openvas bash ## inside container greenbone-nvt-sync openvasmd --rebuild --progress greenbone-certdata-sync greenbone-scapdata-sync openvasmd --update --verbose --progress /etc/init.d/openvas-manager restart /etc/init.d/openvas-scanner restart Docker compose (experimental) For simplicity a docker-compose.yml file is provided, as well as configuration for Nginx as a reverse proxy, with the following features: Nginx as a reverse proxy Redirect from port 80 (http) to port 433 (https) Automatic SSL certificates from Let's Encrypt A cron that updates daily the NVTs To run: Change "example.com" in the following files: docker-compose.yml conf/nginx.conf conf/nginx_ssl.conf Change the "OV_PASSWORD" enviromental variable in docker-compose.yml Install the latest docker-compose run docker-compose up -d LDAP Support (experimental) Openvas do not support full ldap integration but only per-user authentication. A workaround is in place here by syncing ldap admin user(defined by LDAP_ADMIN_FILTER) with openvas admin users everytime the app start up. To use this, just need to specify the required ldap env variables: docker run -d -p 443:443 -p 9390:9390 --name openvas -e LDAP_HOST=your.ldap.host -e LDAP_BIND_DN=uid=binduid,dc=company,dc=com -e LDAP_BASE_DN=cn=accounts,dc=company,dc=com -e LDAP_AUTH_DN=uid=%s,cn=users,cn=accounts,dc=company,dc=com -e LDAP_ADMIN_FILTER=memberOf=cn=admins,cn=groups,cn=accounts,dc=company,dc=com -e LDAP_PASSWORD=password -e OV_PASSWORD=admin mikesplain/openvas Refrenced from - https://hub.docker.com/r/mikesplain/openvas/ --- ## WP GDPR Compliance WordPress Plug-in Exploited URL: https://securityorb.com/wp-gdpr-compliance-wordpress-plug-in-exploited/ Type: post Modified: 2018-11-13 A WordPress plug-in that's supposed to help with GDPR compliance contains a dangerous privilege escalation vulnerability that attackers have been actively exploiting to compromise websites. A WordPress plug-in known as the WP GDPR Compliance plug-in contains a dangerous privilege escalation vulnerability that attackers have been actively exploiting to compromise websites.  The bug was discovered by the WordPress.org Plugin Directory Team on November 6 and patched the next day in version 1.4.3. But despite the fixes, attacks on sites still running versions 1.4.2 and older are still going on, according to security experts from Defiant, a company that runs the Wordfence firewall plugin for WordPress sites. WP GDPR ensure compliance with Europe’s General Data Protection Regulation by providing tools through which site visitors can permit use of their personal data or request data stored by the website’s database. More information can be located below: ZDNet - https://www.zdnet.com/article/zero-day-in-popular-wordpress-plugin-exploited-in-the-wild-to-take-over-sites/   --- ## Video: General Data Protection Regulation (GDRP) - The law that lets Europeans take back their data from big tech companies URL: https://securityorb.com/general-data-protection-regulation-gdrp-the-law-that-lets-europeans-take-back-their-data-from-big-tech-companies/ Type: post Modified: 2018-11-12 Tech companies' reign over users' personal data has run largely unchecked in the age of the internet. Europe is seeking to end that with a new law --- ## Mitigating Buffer Overflow Attacks in Linux/Unix URL: https://securityorb.com/mitigating-buffer-overflow-attacks-in-linux-unix/ Type: post Modified: 2018-11-07 A buffer overflow is the most common and the most serious threat to Linux/Unix operating systems. Buffer overflows occur when code running in unprotected memory in a buffer overwrites memory in an adjacent location. For example, a string of information, say 20 bytes, is sent to a 16-byte buffer, which can't accommodate that string. Linux/Unix is written in C and there are memory-safety issues to consider, it could occur as a result of programming errors if memory boundary checking is inefficient or if boundary checking in a process isn't present. Buffer overflow becomes a security issue when an attacker manages to maliciously insert code into the memory of a running process, the attacker may then be able to acquire the privileges of that process. Generally buffer overflow is stack based where malicious code placed on a stack changes the return pointer and consequentially program flow, and heap based where overflowing buffers on lower parts of the heap result in unpredictable effects on the rest of the heap. When trying to prevent buffer overflow, there are few preventative measures you can take. Of course, careful programming should ensure that attackers aren't made aware of where privilege processes are running from. So analysis of source code for potential vulnerabilities is highly recommended. However, given that programmers are human, buffer overflows are always going to be a problem. It's important to disable stack execution and randomize stack location because this will make it more difficult for attackers to locate overflows and inject malicious code. When possible, if you are writing programs, use languages that have memory protection features, for example, Java or C#. In C and C++, there are no automatic bounds checking on the buffer, which means a user can write past a buffer. For example:                       int main () {                      int buffer[10];                     buffer[20] = 10;                      } The above C program is a valid program, and every compiler can compile it without any errors. However, the program attempts to write beyond the allocated memory for the buffer, which might result in unexpected behavior. It's always a good idea to perform runtime checking to ensure that buffer overflow isn't occurring. In certain operating systems, you can enforce stack protection. With stack protection, you can modify your kernel to ensure that code only executes from areas of memory that you have cordoned off and locked. If a malicious user attempts to insert code into the stack-protected memory of a running process, the process will abort. Service will be denied, but the system won't be compromised. The methods vary depending on the distribution of Linux/Unix or Linux that you are using. --- ## Mac OS X Security Keychain URL: https://securityorb.com/mac-os-x-security-keychain/ Type: post Modified: 2018-11-07 The keychain is a secure database store for passwords and certificates and is created for each user account on Mac OS X.  The system software itself uses keychains for secure storage.  The “login” keychain is the default location for user credentials and should be protected, while the keychain is unlocked all passwords in the keychain can be exported.  The login keychain should be locked when the system sleeps or after long periods of inactivity. Changing your keychain password When a keychain mismatch occurs, the user must change their keychain password to match the password used to log on to the machine.  To correctly change your keychain password, the user will use the application Keychain Access.  Keychain Access is located in Applications\Utilities. Change your keychain password: Select "login" under the list of keychains. From the menu at the top of the screen, click Edit. Select Change Password for Keychain "login"... Enter the current keychain password.  Remember that the "current" keychain password is the password previously used to log into the machine, before your most recent password change. Enter your new password and verify.  The new password you enter should match the password you used to log into the machine. --- ## SSD Encryption from Crucial and Samsung is not secure Exposes Data URL: https://securityorb.com/ssd-encryption-from-crucial-and-samsung-is-not-secure-exposes-data/ Type: post Modified: 2018-11-06 Carlo Meijer and Bernard van Gastel, two researchers at Radboud University in the Netherlands issued a warning that hardware encryption in various models of Solid State Drives (SSDs) are not secure.  The vulnerabilities only affected "ATA security" and "TCG Opal hardware-based encryption on SEDs.  Furthermore, it affected the hardware-based encrypted SSD models with a local built-in chip, separate from the main CPU. The researchers examined multiple SSDs, including Crucial and Samsung, some of which they found could be unlocked with any password if the password validation routine in RAM was modified through a standard JTAG debugging interface. The two stated that the SEDs they've analyzed, allowed users to set a password that decrypted their data, but also came with support for a so-called "master password" that was set by the SED vendor. They stated, “Any attacker who read an SED's manual can use this master password to gain access to the user's encrypted password, effectively bypassing the user's custom password”. Other issues are detailed in the researchers' paper, titled "Self-encrypting deception: weaknesses in the encryption of solid state drives (SSDs)," which can be downloaded in PDF format from here. Due to limited access to SSDs, Meijer and van Gastel said they've only tested their findings on a small number of devices, listed in the table below, but found that all were vulnerable. Both Crucial and Samsung whose products they've tested have released firmware updates to address the reported flaws. --- ## Information Commissioner Calls for Regulation of Social Media Following Cambridge Analytica scandal URL: https://securityorb.com/information-commissioner-calls-for-regulation-of-social-media-following-cambridge-analytica-scandal/ Type: post Modified: 2018-11-06 An interesting article by Tom Reeve on scmagazineuk.com: The Information Commissioner Elizabeth Denham has published a report into the the use of data analytics for political purposes at the same time as appearing before the Parliamentary DCMS committee today. Appearing alongside her deputy commissioner James Dipple-Johnstone, Denham was testifying on "Disinformation and 'fake news'" before the Digital, Culture, Media and Sport Committee (DCMS), chaired by the MP Damian Collins. The report into data analytics and political campaigning, which runs to 113 pages, is the culmination of "the largest investigation of its type by any Data Protection Authority," the report says. It involved social media platforms, data brokers, analytics firms, academic institutions, political parties and campaign groups. The report is a summary of its findings – more details will emerge in any regulatory notices which are issued by the Information Commissioner's Office (ICO). Read the rest here. --- ## Ruby2.3 Security Update - CVE-2018-16395 CVE-2018-16396 URL: https://securityorb.com/ruby2-3-security-update-cve-2018-16395-cve-2018-16396/ Type: post Modified: 2018-11-06 Security fix in Ruby on Rails Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2018-16395     Tyler Eckstein reported that the equality check of    OpenSSL::X509::Name could return true for non-equal objects. If a    malicious X.509 certificate is passed to compare with an existing    certificate, there is a possibility to be judged incorrectly that    they are equal. CVE-2018-16396     Chris Seaton discovered that tainted flags are not propagated in    Array#pack and String#unpack with some directives. For the stable distribution (stretch), these problems have been fixed inversion 2.3.3-1+deb9u4. We recommend that you upgrade your ruby2.3 packages. For the detailed security status of ruby2.3 please refer to its security tracker page at:https://security-tracker.debian.org/tracker/ruby2.3 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ --- ## UK's Information Commissioner’s Office (ICO) Slap Fines on Facebook and Equifax URL: https://securityorb.com/uks-information-commissioners-office-ico-slap-fines-on-facebook-and-equifax/ Type: post Modified: 2018-11-05 UK fines Facebook £500,000 for failing to protect user data Facebook was fined £500,000 by the UK's Information Commissioner’s Office (ICO) for its role in the Cambridge Analytica data scandal which allowed unauthorized access of 87 million user information without sufficient consent. The fine forced by the ICO was calculated using the UK's old Data Protection Act 1998 which can impose a maximum penalty of £500,000 which represents a small fee for a company that brought in $40.7bn (£31.5bn) in global revenue in 2017.  The penalty could have been much larger had it fallen under EU's General Data Protection Regulation (GDPR), where a company could face a maximum fine of 20 million euros or 4% of its annual global revenue, whichever is higher, for such a privacy breach. The investigation found that Facebook failed to keep the personal information of its users secure by failing to make suitable checks on developers using its platform. Equifax recently faced a similar fine of £500,000 from its massive data breach that exposed personal and financial data of hundreds of millions of its customers. --- ## Cisco WebEx Meetings Server XML External Entity (CVE-2018-18895) URL: https://securityorb.com/cisco-webex-meetings-server-xml-external-entity-cve-2018-18895/ Type: post Modified: 2018-11-05 DESCRIPTION Cisco Webex Meetings Server includes a version of Castor XML that is affected by XXE. Because of that Cisco WebEx Meetings Server prior to versions 2.8MR3 and 3.0MR2 patch 1 are affected from XXE vulnerability. A remote unauthenticated attacker may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts by using this vulnerability. Vulnerable path: /WBXServixe/XMLService Vulnerable parametre: siteName SOLUTION Update current Cisco WebEx Meetings Server to 2.8MR3, 3.0MR2 patch 1, or the upcoming 4.0 release. REFERENCES You can find Cisco’s announcement from the link below:https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvm56811 You can find more information about XXE from the link below:https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing Castor XML fixed this issue with CVE-2014-3004. CREDIT Alphan Yavas from Biznet Bilisim A.S.   --- ## U-Boot verified boot bypass vulnerabilities (CVE-2018-18439, CVE-2018-18440) URL: https://securityorb.com/u-boot-verified-boot-bypass-vulnerabilities-cve-2018-18439-cve-2018-18440/ Type: post Modified: 2018-11-04 Security advisory: U-Boot verified boot bypass ============================================== The Universal Boot Loader - U-Boot [1] verified boot feature allows cryptographic authentication of signed kernel images, before their execution. This feature is essential in maintaining a full chain of trust on systems which are secure booted by means of an hardware anchor. Multiple techniques have been identified that allow to execute arbitrary code, within a running U-Boot instance, by means of externally provided unauthenticated data. All such techniques spawn from the lack of memory allocation protection within the U-Boot architecture, which results in several means of providing excessively large images during the boot process. Some implementers might find the following issues as an intrinsic characteristic of the U-Boot memory model, and consequently a mere aspect of correct U-Boot configuration and command restrictions. However in our opinion the inability of U-Boot to protect itself when loading binaries is an unexpected result of non trivial understanding, particularly important to emphasize in trusted boot scenarios. This advisory details two specific techniques that allow to exploit U-Boot lack of memory allocation restrictions, with the most severe case also detailing a workaround to mitigate the issue. It must be emphasized that cases detailed in the next sections only represent two possible occurrences of such architectural limitation, other U-Boot image loading functions are extremely likely to suffer from the same validation issues. To a certain extent the identified issues are similar to one of the findings reported as CVE-2018-1000205 [2], however they concern different functions which in some cases are at a lower level, therefore earlier in the boot image loading stage. Again all such issues are a symptom of the same core architectural limitation, being the lack of memory allocation constraints for received images. It is highly recommended, for implementers of trusted boot schemes, to review use of all U-Boot booting/loading commands, and not merely the two specific ones involved in the findings below, to apply limitations (where applicable/possible) to the size of loaded images in relation to the available RAM. It should also be emphasized that any trusted boot scheme must also rely on an appropriate lockdown of all possibilities for interactive consoles, by boot process interruption or failure, to ever be prompted. U-Boot insufficient boundary checks in filesystem image load ------------------------------------------------------------ The U-Boot bootloader supports kernel loading from a variety of filesystem formats, through the `load` command or its filesystem specific equivalents (e.g. `ext2load`, `ext4load`, `fatload`, etc.) These commands do not protect system memory from being overwritten when loading files of a length that exceeds the boundaries of the relocated U-Boot memory region, filled with the loaded file starting from the passed `addr` variable. Therefore an excessively large boot image, saved on the filesystem, can be crafted to overwrite all U-Boot static and runtime memory segments, and in general all device addressable memory starting from the `addr` load address argument. The memory overwrite can directly lead to arbitrary code execution, fully controlled by the contents of the loaded image. When verified boot is implemented, the issue allows to bypass its intended validation as the memory overwrite happens before any validation can take place. The following example illustrates the issue, triggered with a 129MB file on a machine with 128MB or RAM: ``` U-Boot 2018.09-rc1 (Oct 10 2018 - 10:52:54 +0200) DRAM: 128 MiB Flash: 128 MiB MMC: MMC: 0 # print memory information => bdinfo arch_number = 0x000008E0 boot_params = 0x60002000 DRAM bank = 0x00000000 -> start = 0x60000000 -> size = 0x08000000 DRAM bank = 0x00000001 -> start = 0x80000000 -> size = 0x00000004 eth0name = smc911x-0 ethaddr = 52:54:00:12:34:56 current eth = smc911x-0 ip_addr = baudrate = 38400 bps TLB addr = 0x67FF0000 relocaddr = 0x67F96000 reloc off = 0x07796000 irq_sp = 0x67EF5EE0 sp start = 0x67EF5ED0 # load large file => ext2load mmc 0 0x60000000 fitimage.itb # In this specific example U-Boot falls in an infinite loop, results vary # depending on the test case and filesystem/device driver used. A debugging # session demonstrates memory being overwritten: (gdb) p gd $28 = (volatile gd_t *) 0x67ef5ef8 (gdb) p *gd $27 = {bd = 0x7f7f7f7f, flags = 2139062143, baudrate = 2139062143, ... } (gdb) x/300x 0x67ef5ef8 0x67ef5ef8: 0x7f7f7f7f 0x7f7f7f7f 0x7f7f7f7f 0x7f7f7f7f ``` It can be seen that memory address belonging to U-Boot data segments, in this specific case the global data structure `gd`, is overwritten with payload originating from `fitimage.itb` (filled with `0x7f7f7f7f`). ### Impact Arbitrary code execution can be achieved within a U-Boot instance by means of unauthenticated binary images, loaded through the `load` command or its filesystem specific equivalents. It should be emphasized that all load commands are likely to be affected by the same underlying root cause of this vulnerability. ### Workaround The optional `bytes` argument can be passed to all load commands to restrict the maximum size of the retrieved data. The issue can be therefore mitigated by passing a `bytes` argument with a value consistent with the U-Boot memory regions mapping and size. U-Boot insufficient boundary checks in network image boot --------------------------------------------------------- The U-Boot bootloader supports kernel loading from a variety of network sources, such as TFTP via the `tftpboot` command. This command does not protect system memory from being overwritten when loading files of a length that exceeds the boundaries of the relocated U-Boot memory region, filled with the loaded file starting from the passed `loadAddr` variable. Therefore an excessively large boot image, served over TFTP, can be crafted to overwrite all U-Boot static and runtime memory segments, and in general all device addressable memory starting from the `loadAddr` load address argument. The memory overwrite can directly lead to arbitrary code execution, fully controlled by the contents of the loaded image. When verified boot is implemented, the issue allows to bypass its intended validation as the memory overwrite happens before any validation can take place. The issue can be exploited by several means: - An excessively large crafted boot image file is parsed by the `tftp_handler` function which lacks any size checks, allowing the memory overwrite. - A malicious server can manipulate TFTP packet sequence numbers to store downloaded file chunks at arbitrary memory locations, given that the sequence number is directly used by the `tftp_handler` function to calculate the destination address for downloaded file chunks. Additionally the `store_block` function, used to store downloaded file chunks in memory, when invoked by `tftp_handler` with a `tftp_cur_block` value of 0, triggers an unchecked integer underflow. This allows to potentially erase memory located before the `loadAddr` when a packet is sent with a null, following at least one valid packet. The following example illustrates the issue, triggered with a 129MB file on a machine with 128MB or RAM: ``` U-Boot 2018.09-rc1 (Oct 10 2018 - 10:52:54 +0200) DRAM: 128 MiB Flash: 128 MiB MMC: MMC: 0 # print memory information => bdinfo arch_number = 0x000008E0 boot_params = 0x60002000 DRAM bank = 0x00000000 -> start = 0x60000000 -> size = 0x08000000 DRAM bank = 0x00000001 -> start = 0x80000000 -> size = 0x00000004 eth0name = smc911x-0 ethaddr = 52:54:00:12:34:56 current eth = smc911x-0 ip_addr = baudrate = 38400 bps TLB addr = 0x67FF0000 relocaddr = 0x67F96000 reloc off = 0x07796000 irq_sp = 0x67EF5EE0 sp start = 0x67EF5ED0 # configure environment => setenv loadaddr 0x60000000 => dhcp smc911x: MAC 52:54:00:12:34:56 smc911x: detected LAN9118 controller smc911x: phy initialized smc911x: MAC 52:54:00:12:34:56 BOOTP broadcast 1 DHCP client bound to address 10.0.0.20 (1022 ms) Using smc911x-0 device TFTP from server 10.0.0.1; our IP address is 10.0.0.20 Filename 'fitimage.bin'. Load address: 0x60000000 Loading: ################################################################# ... #################################### R00=7f7f7f7f R01=67fedf6e R02=00000000 R03=7f7f7f7f R04=7f7f7f7f R05=7f7f7f7f R06=7f7f7f7f R07=7f7f7f7f R08=7f7f7f7f R09=7f7f7f7f R10=0000d677 R11=67fef670 R12=00000000 R13=67ef5cd0 R14=02427f7f R15=7f7f7f7e PSR=400001f3 -Z-- T S svc32 ``` It can be seen that the program counter (PC, r15) is set to an address originating from `fitimage.itb` (filled with `0x7f7f7f7f`), as the result of the U-Boot memory overwrite. ### Impact Arbitrary code execution can be achieved within a U-Boot instance by means of unauthenticated binary images, passed through TFTP and loaded through the `tftpboot` command, or by a malicious TFTP server capable of sending arbitrary response packets. It should be emphasized that all network boot commands are likely to be affected by the same underlying root cause of this vulnerability. ### Workaround The `tftpboot` command lacks any optional argument to restrict the maximum size of downloaded images, therefore the only workaround at this time is to avoid using this command on environments that require trusted boot. Affected version ---------------- All released U-Boot versions, at the time of this advisory release, are believed to be vulnerable. All tests have been performed against U-Boot version 2018.09-rc1. Credit ------ Vulnerabilities discovered and reported by the Inverse Path team at F-Secure, in collaboration with Quarkslab. CVE --- CVE-2018-18440: U-Boot insufficient boundary checks in filesystem image load CVE-2018-18439: U-Boot insufficient boundary checks in network image boot Timeline -------- 2018-10-05: network boot finding identified during internal security audit by Inverse Path team at F-Secure in collaboration with Quarkslab. 2018-10-10: filesystem load finding identified during internal security audit by Inverse Path team at F-Secure. 2018-10-12: vulnerability reported by Inverse Path team at F-Secure to U-Boot core maintainer and Google security, embargo set to 2018-11-02. 2018-10-16: Google closes ticket reporting that ChromeOS is not affected due to their specific environment customizations. 2018-10-17: CVE IDs requested to MITRE and assigned. 2018-11-02: advisory release. References ---------- [1] https://www.denx.de/wiki/U-Boot [2] https://lists.denx.de/pipermail/u-boot/2018-June/330487.html Permalink --------- https://github.com/inversepath/usbarmory/blob/master/software/secure_boot/Security_Advisory-Ref_IPVR2018-0001.txt --- ## New PortSmash Side-Channel Vulnerability (CVE-2018-5407) URL: https://securityorb.com/new-portsmash-side-channel-vulnerability-cve-2018-5407/ Type: post Modified: 2018-11-04 A new vulnerability being called PortSmash, (CVE-2018-5407) has been discovered impacting all CPUs that use a Simultaneous Multithreading (SMT) architecture.  SMT is a technology that allows multiple computing threads to be executed simultaneously on a CPU core. PortSmash is being classified as a  side-channel attack which is technique used for leaking encrypted data from a computer's memory or CPU, that will also record and analyze discrepancies in operation times, power consumption, electromagnetic leaks, or even sound to gain additional info that may help break encryption algorithms and recovering the CPU's processed data. An example on how the attack may work: A malicious process next to legitimate processes using SMT's parallel thread running capabilities. The malicious PortSmash process than leaks small amounts of data from the legitimate process, helping an attacker reconstruct the encrypted data processed inside the legitimate process. The team that discovered the vulnerability published a proof-of-concept (PoC) code on GitHub that demonstrates a PortSmash attack on Intel Skylake and Kaby Lake CPUs. To rectify the issue, organizations are urged to install an Intel provided patch that has been released prior to the PortSmash proof-of-concept being released or to disable SMT/Hyper-Threading in the CPU chip's BIOS until you are able to install the security patches. PortSmash has joined the list of newly discovered side-channel vulnerabilities such as TLBleed, Meltdown, Foreshadow and Spectre. --- ## Eurostar Customers Reset Passwords After Security Breach URL: https://securityorb.com/eurostar-customers-reset-passwords-after-breach/ Type: post Modified: 2018-11-03 Eurostar forced all of its customers to reset their passwords after indications of a possible security breach by hackers attempted to access user accounts.  In an email, customers were notified that a threat actor may have used automated attempts to login with stolen user email and passwords that were obtained in an unknown method.  The email also stated, "We’ve since carried out an investigation which shows that your account was logged into between the 15 and 19 October, If you didn’t log in during this period, there’s a possibility your account was accessed by this unauthorized attempt." The email instructed customers to reset their passwords and check their accounts for unusual activity while ensuring them their payment card information hadn’t been compromised. Please review our Best Practices for Creating a Password post when creating a new password. --- ## Continuous Monitoring : Academic Paper URL: https://securityorb.com/continuous-monitoring-academic-paper/ Type: post Modified: 2018-11-03 INTRODUCTION The Federal Information Security Act (FISMA) of 2002 requires that government agencies report on their Information Technology Security Status annually to the Office of Management and Budget (OMB).   Under current FISMA guidelines, any system owner within a government agency is required to complete the certification and accreditation (C&A) process.  The process requires that  security controls and policies for all subsystems within the environment be implemented including: host based hardening, Host Based Security Systems (HBSS), installing firewalls, Intrusion Protections Systems (IPS).   Once the security systems are deployed and technical security controls are in place,  typically an outside independent organization will validate the security controls, through a risk assessment process.  Once the process is complete the information is reviewed and the agency will decide to grant the system an Authorization to Operate (ATO).   Under new guidelines all systems are required to monitor the baselines security controls and document any changes to the system by implementing a continuous monitoring program.  A continuous monitoring plan should be implemented to assess the risk to the environment based on changes to the system.    Currently, there are a  number of organizations that make recommendations for implementing a continuous monitoring program but differ on the definition and implementation.  The implementation of a continuous monitoring program can be made if an organization uses common sense in conjunction with the recommendations contained in current National Institute of Standards and Technology, SANs and Department of Home Land Security. Continuous Monitoring Defined Continuous Monitoring is the on-going assessment of change and related risk to the baseline configuration of security authorized operational IT systems within the enterprise.  The goal of a Continuous Monitoring program is to determine if built in system security controls continue to be effective over time.  The proper balance of policy, context, processes and technology application dictates the overall effectiveness of the program.  A number of government organizations have developed standards and recommendations for developing a continuous monitoring strategy.   The National Institute of Standards and Technology (NIST) Special Publication 800-137 rev 1 " Information  Security Continuous Monitoring for Federal Information Systems and Organizations" presents guidelines for applying NIST's Risk Management Framework (RMF) to Federal Systems.  In NIST's Special Publication NIST defines continuous monitoring as: " Information security continuous monitoring (ISCM) is defined as maintaining ongoing awareness of the information security, vulnerabilities and threats to support organizational risk management". NIST in conjunction with the Department of Home Land Security (DHS) developed NIST Interagency Report 7756 “CAESARS Framework Extension: An Enterprise Continuous Monitoring Technical Reference Model (Second Draft) “which extends the original CAEARS Reference Architecture that describes standard protocols and systems to produce an automated continuous monitoring system.  Currently, hardware and software tools using a standard set a protocols to monitor all assets within the enterprise have not been currently developed.   DHS plans to award contacts totaling more than 6 billion to a number of companies to develop and implement continuous diagnostic and mitigation tools.   In addition, the SANs Institute working with the Department of Defense (DOD) published " Twenty Critical Security Controls for Effective Cyber Defense" which makes a number of recommendations on the implementation of continuous monitoring.   Even though complete monitoring tools sets have not been fully develop, organizations can use SAN's recommend controls to begin to implementing a continuous monitoring program to provide situational awareness of the enterprise. Within the recommended 20 controls, three controls, Critical Control, 4, 14, and 16 make recommendations to implement continuous monitoring capabilities across an enterprise networks.  Critical Control 4  provides recommendations on vulnerability scanning and remediation.  Critical Control 14 discusses the importance of auditing within the enterprise. Lastly, Critical Control 16 discusses account monitoring and control. 2.0 Vulnerability Scanning Unfortunately, many organizations fail to monitor the security controls for changes that may affect the security posture of the system.  Once security configuration baselines are applied to systems,  little is done to update the controls based on system changes.  Implementing vulnerability scanning and compliance tools is an easy way protect the enterprise against known threats. Vulnerability scanning tools incorporate two different scanning mechanisms, compliance scans and vulnerability scans to protect the enterprise.  Compliance scans checks the systems against a known set of configuration security  baselines or set of policies used for system hardening, such as those published by Defense Information Systems Agency (DISA) and the Center for Internet Security (CIS).    The compliance scans should run against all system on the network to maintain ATO compliance and detect if any unauthorized changes were made to circumvent security.  On the other hand, vulnerability scans checks the system against known set of threat signatures.   The vulnerability scans will list known threats based on Common Vulnerability Alerts (CVE), vendor patch updates on common operating systems and application software.    In addition, vulnerability scanning tools can provide network discovery scans to check for unauthorized devices that may be connected to the network.  The discovery scans can be used to maintain the organization Configuration Management policies.  SANs Critical Control 4 states " run automated vulnerability scanning tools against all systems on the network on a weekly or more frequent basis and deliver prioritized lists of the most critical vulnerabilities to each responsible system administrator along with risk scores that compare the effectiveness of system administrators and departments in reducing risk. Where feasible, vulnerability scanning should occur on a daily basis using an up-to-date vulnerability-scanning tool. Any vulnerability identified should be remediated in a timely manner, with critical vulnerabilities fixed within 48 hours". Vulnerability scanning should be incorporated into any organization's security plan and should be the first step in the implementation of a continuous monitoring program.   Many scanning tools are available in the commercial market, such as Tenable's NESSUS vulnerability scanner and eEye Digital's Retina vulnerability scanner. 3.0 Audit Logging Audit logs are one of the most important security controls to implement when developing security policies within the enterprise.   Audit logs provide a wealth of information on the daily activities of authorized system users and some cases unauthorized users as well.   Almost every piece of equipment incorporated in building a IT infrastructure provides audit logging capability.  Unfortunately,   many organizations do not correctly implement audit logging policies when developing a System Security Plan.  An organization's audit policy may include the requirement to enable audit logging, but does not specify which logs are enabled, time period for review, retention time or how the logs will be consolidated offline for protection.   SANs Critical Control 14 states  " Deficiencies in security logging and analysis allow attackers to hide their location, malicious software used for remote control, and activities on victim machines. Even if the victims know that their systems have been compromised, without protected and complete logging records they are blind to the details of the attack and to subsequent actions taken by the attackers. Without solid audit logs, an attack may go unnoticed indefinitely and the particular damages done may be irreversible". Information Systems are under constant threats and attacks occurring from outside or inside the organization.  Incorporating a strong audit logging capability and policies will help to detect unauthorized users, configuration changes, information for forensic investigations and system performance monitoring.  Organizations should have audit logging enabled on network equipment for successful and failed logons, logoffs, account lockout, user account and password management, policy changes, object access and installed/un-installed applications at a minimum.  Audit logs should be reviewed daily for any suspicious activity and retained off line for a minimum of 1 year.    Reviewing audit logs can be very difficult, if not impossible to access each device on the network to review logs individually.    Organizations should incorporate tools to consolidate all device logs into a single location for review.  This prevents internal threats and outside attackers from deleting audit logs to cover their tracks from malicious activity.   The system should have the capability to send alerts to security personnel for certain events in real time,  either by email or Short Message Service (SMS). Audit log consolidation should be considered the second step in the implementation of a continuous monitoring program.  The enabling of audit logs on devices and consolidating the logs to central device is one of the best ways to detect threats and provide situational awareness of the enterprise.  The audit logs can provide insight to what is considered normal activity and what is not.   Many tools for audit consolidation are available from companies like, GFI Software's, GFI Events Manager, and Splunk that can ingest any type of ANSI based text file and then search for any data tag associated with a source event. 4.0 Account Monitoring One of the most frequently targets of hackers are user accounts, default accounts, service accounts and inactive accounts.   Hackers will target default accounts that have not been disabled with dictionary attacks and when exploited are difficult to detect.   Even though most organizations have security policies on managing account access, poor oversight by management fails to strictly enforce policy.   The uses of service accounts to access systems are all too common which makes correlating specific users with access very difficult.  If an attacker just discovers a valid User ID than they have half of the puzzle to hack the account.  If an attacker gains access to a system with an active user account they usually can find a way to gain access to an administrator level and exploit the entire system.   Therefore, account monitoring policies should be reviewed on a regular basis and incorporated into the organization's continuous monitoring program. The implementation of regular monitoring of account access is one of the easiest ways to mitigate risk to the entire system.    Account management should be incorporated into the daily operations of every System Administrator that has account creating authority.   First, password requirements should be enabled on all systems, require passwords with 14 characters in length and include upper, lower and special characters.   Account passwords must be changed after 60 days and inactive account disabled after 30 days.    In addition, default system accounts should be disabled and renamed including the default administrator account.   Accounts for terminated employees should be disabled immediately, all too often those accounts are left active making exploit by a disgruntled employee effortless.    Moreover, System Administrators that leave and/or terminated should have their account disabled before leaving the building and the system closely monitored for any unauthorized activity.   Lastly, all active accounts should be fully reviewed on a regular basis for employees that were transferred to new positions outside the division. Incorporating account monitoring into a continuous monitoring program is a quick and effective means to mitigate risk to the system.  In addition,   the cost associated with implementing account monitoring is minimal, since it mostly entails an increase in security awareness and policy enforcement. Conclusion The number of attacks increase daily and the job of defending the system becomes more difficult especially when defending against zero day vulnerabilities.  Organizations tend to apply system security with the least amount of cost as possible.  However, with the ever increasing regulatory requirements organizations must find cost effective ways to protect and increase the situational awareness of their networks.     In order to meet mandated requirements, organizations can implement a cost effective continuous monitoring program by conducting regular compliance and vulnerability scans, consolidate audit reporting and maintain a comprehensive account management policy to maintain the security posture of their enterprise. --- ## Armis Discovers "BLEEDINGBIT," Two Critical Chip-Level Vulnerabilities URL: https://securityorb.com/armis-discovers-bleedingbit-two-critical-chip-level-vulnerabilities/ Type: post Modified: 2018-11-03 Armis, the enterprise IoT security company, today announced the discovery of two critical vulnerabilities related to the use of Bluetooth Low Energy (BLE) chips made by Texas Instruments (TI), and used in Cisco, Meraki and Aruba wireless access points, called "BLEEDINGBIT." If exploited, they allow an unauthenticated attacker to break into enterprise networks undetected, take over access points, spread malware, and move laterally across network segments. Neither of the vulnerabilities can be detected or stopped by traditional network and endpoint security solutions. Enterprise Networks Impacted The first BLEEDINGBIT vulnerability impacts the TI BLE chips (cc2640, cc2650) embedded in Cisco and Meraki Wi-Fi access points. If exploited, the proximity-based vulnerability triggers a memory corruption in the BLE stack, which could allow attackers to compromise the main system of the access point – thereby gaining full control over it. The second issue impacts the Aruba Wi-Fi access point Series 300 with TI BLE chip (cc2540) and specifically its use of TI's over-the-air firmware download (OAD) feature. This issue is technically a backdoor in BLE chips that was designed to allow firmware updates. The OAD feature is often used as a development tool, but is active in some production access points. It can allow a nearby attacker to access and install a completely new and different version of the firmware -- effectively rewriting the operating system of the BLE chip, if not implemented correctly by the manufacturer. In default configurations, the OAD feature doesn't automatically offer a security mechanism that differentiates a "good" or trusted firmware update from a potentially malicious update. By abusing this feature, an attacker can gain a foothold on an access point through which he can penetrate secure networks. TI has already released software updates that address the first vulnerability. Cisco, Meraki, and Aruba are expected to have patches available by November 1. Armis is still in the process of assessing the full reach of the BLEEDINGBIT vulnerabilities -- beyond the threat they pose on network infrastructure devices -- and is working with CERT Coordination Center (CERT/CC) and various vendors to validate that appropriate patches are provided to every affected product. "BLEEDINGBIT is a wakeup call to enterprise security for two reasons," said Armis CEO Yevgeny Dibrov. "First, the fact that an attacker can enter the network without any indication or warning raises serious security concerns. Second, these vulnerabilities can break network segmentation -- the primary security strategy that most enterprises use to protect themselves from unknown or dangerous unmanaged and IoT devices. And here, the access point is the unmanaged device." More Industries and Devices May Be Affected While Armis found the vulnerabilities in Wi-Fi access points, they may manifest in in other types of devices and equipment used in a variety of industries as well. "In this instance, we have clearly identified how BLEEDINGBIT impacts network devices," said Ben Seri, VP of Research at Armis. "But this exposure potentially goes beyond access points, as these chips are used in many other types of devices and equipment. They are used in a variety of industries such as healthcare, industrial, automotive, retail, and more. As we add more connected devices taking advantage of new protocols like BLE, we see the risk landscape grow with it." How to Protect Yourself To protect themselves, organizations with Cisco, Meraki, and Aruba access points should check for the latest updates. Manufacturers using these chips should upgrade to the latest BLE-STACK from TI. Impacted Chips and Remediation The first security vulnerability is present in these TI chips when scanning is used (e.g. observer role or central role that performs scanning) in the following device/software combinations and can be remediated as follows: For CC2640 (non-R2) and CC2650 with BLE-STACK version 2.2.1 or an earlier version are impacted, customers can update to version 2.2.2. For CC2640R2F, version 1.00.00.22 (BLE-STACK 3.0.0) is impacted, customers can update to SimpleLink CC2640R2F SDK version 1.30.00.25 (BLE-STACK 3.0.1) or later. For CC1350, version 2.20.00.38 (BLE-STACK 2.3.3) or earlier is impacted, customers can update to SimpleLink CC13x0 SDK version 2.30.00.20 (BLE-STACK 2.3.4) or later. Additional updates on proper use of the OAD feature can be found here. The BLEEDINGBIT vulnerabilities are the latest issues that illustrate new attack vectors targeting unmanaged and unprotected devices. Last year, Armis discovered BlueBorne, a set of nine zero-day Bluetooth-related vulnerabilities in Android, Windows, Linux and iOS that affected billions of devices, including smartphones, TVs, laptops, watches and automobile audio systems. For a full report on BLEEDINGBIT, please visit https://armis.com/bleedingbit. --- ## UK needs to talk to China to ensure cybersecurity URL: https://securityorb.com/uk-needs-to-talk-to-china-to-ensure-cybersecurity/ Type: post Modified: 2018-11-03 As the UK’s cybersecurity situation becomes more uncertain and vulnerable day by day, top cyber intelligence officers have spoken out about seeking alternative arrangements to ensure a more protected digital environment across the country. Specifically, technical director of GCHQ’s National Cyber Security Centre, Ian Levy, has declared that the UK ought to forge a cyber relationship with China – a softer stance to the earlier warnings and red flags that were raised against Chinese companies – due to its rapid technological advance, great online influence, and its ability to provide support on a cybersecurity front. During a speech at the Atlantic Future Forum in New York, delivered to a crowd of cyber professionals and military and intelligence executives, Levy said: “Like it or not, we are going to have to talk to China. The reality is they will own a huge chunk of internet structure going forward. “Like it or not like it, they have 1.4 billion people who are going to be cybercrime victims. Like it or not like it, we are going to have to talk to them because we are going to get all the collateral damage from those attacks.” Read more here. --- ## Cybersecurity Career Pathway URL: https://securityorb.com/cybersecurity-career-pathway/ Type: post Modified: 2018-11-02 There are many opportunities for workers to start and advance their careers within cybersecurity. This interactive career pathway shows key jobs within cybersecurity, common transition opportunities between them, and detailed information about the salaries, credentials, and skillsets associated with each role. --- ## National Cybersecurity Career Awareness Week URL: https://securityorb.com/national-cybersecurity-career-awareness-week/ Type: post Modified: 2018-11-02 The National Cybersecurity Career Awareness Week (NCCAW), brought to you by the National Initiative for Cybersecurity (NICE), is a week-long campaign focused on increasing awareness about careers in cybersecurity and building a national cybersecurity workforce to enhance America’s national security and promote economic prosperity. NICE brings to the forefront information of local, regional, and national interest to inspire, educate, and engage citizens to pique their interest in cybersecurity careers. National Cybersecurity Career Awareness Week takes place during November’s National Career Development Month, and each day of the week-long campaign provides an opportunity to learn about the contributions, innovations, and opportunities that can be found by choosing a career in cybersecurity. Key Messages Use these key messages to craft your own communications to your contacts. National Cybersecurity Career Awareness Week: creates excitement and increases public awareness and engagement in building a strong cybersecurity workforce emphasizes the demand and opportunities in the field of cybersecurity increases awareness around the multiple career options within the field of cybersecurity highlights the numerous pathways to enter the cybersecurity career field advances the NICE Strategic Plan objective to inspire cybersecurity career awareness with students showcases efforts to increase participation of women, minorities, veterans, persons with disabilities, and other underrepresented populations in the cybersecurity workforce Help make this National Cybersecurity Career Awareness Week campaign a success. Visit the NCCAW website to see what tools and resources you can use to help promote the week-long effort to your connections. --- ## CVE-2018-17914 URL: https://securityorb.com/cve-2018-17914/ Type: post Modified: 2018-11-02 Description InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine Edition) runtime. Source:  MITRE Description Last Modified:  11/02/2018 References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov. Hyperlink Resource https://ics-cert.us-cert.gov/advisories/ICSA-18-305-01 --- ## Complementing a Security Management Model with the 20 Critical Security Controls: Academic Paper URL: https://securityorb.com/complementing-a-security-management-model-with-the-20-critical-security-controls-academic-paper/ Type: post Modified: 2018-11-02 The complexity and velocity of the threats organizations are facing are only escalating and there is a definite need for careful analysis of the attack trends to determine effective mitigations.  According to a study by Verizon, 92% of data breaches in 2012 were perpetrated by outsiders and one-fifth of all data breaches were connected with state affiliated actors, which highlights that the sophistication and resources available to conduct attacks is growing.   Furthermore, 69% of breaches were discovered by an external party and often went months before they were detected, offering a glimpse into the how little visibility organizations have into active attacks (Verizon, 2013, pp. 5-6).  Of the top threat actions identified in 2012, which were tampering, spyware, backdoor, export data, use of stolen credentials, capture stored data, phishing, command and control, downloader, and brute force, there were seven threat actions related to malware.  The analysis and recommendations by Verizon stated the Critical Security Controls, if implemented, could have directly limited the success of the top threat actions, leading to their recommendation that most organizations could benefit from implementing all of the Critical Security Controls to some level (Verizon, 2013, p. 58). Of the organizations affected by data breaches in 2012, they are a cross section of small to large organizations, geographically spanning 27 countries and representing a diverse assortment of industries (Verizon, 2013, pp. 4-5).  These organizations probably had reasonable security controls in place, such as firewalls, antivirus, and security policies, and given the widespread reference and adoption of various security management models, such as ISO 27000, COBIT, NIST, and other compliance frameworks, such as PCI DSS, these organizations undoubtedly had access to industry best practices and recommendations.  However, even with all these good resources, organizations are increasingly finding themselves reacting to security breaches, often as a result of notification by outside parties, which have caused damage to the organizations reputation and actual economic losses of information and intellectual property. John Pescatore, a seasoned security analyst formerly with Gartner and now with the SANS Institute noted, “Most of the Compliance regimes are invariably rigid, top-down structures, whereas the CSC effort is purposely bottomup” (Pescatore, 2013, p. 20).  This characterization could point to the reason there is an apparent disconnect between many organizations attempts to maintain compliance with various security management models and the fact that they are not effectively stopping attacks.  A recent report by the Center for Strategic and International Studies makes an interesting point about compliance frameworks: “The older compliance and audit-based approach found in legislative mandates like the Health Information Portability and Accountability Act (HIPAA), the Federal Information Security Management Act (FISMA), and the Financial Services Modernization Act (also known as Graham-Leach-Blilely, GLB) is both resource intensive and ineffective. Compliance is usually a good thing, but in cybersecurity it came to stand for a static, paper-driven method that was expensive without providing equivalent benefits” (Lewis, 2013, p. 7). The new approach to cyber security is based on evaluation of attack data and what measures have effectively prevented attacks.  The resulting analysis and recommendations are offering organizations a change to assess their security environment with a clear goal in mind. The stated goal of the Critical Security Controls is to, “…protect critical assets, infrastructure, and information by strengthening your organization’s defensive posture through continuous, automated protection and monitoring of your sensitive information technology infrastructure to reduce compromises, minimize the need for recovery efforts, and lower associated costs.”  The controls were developed by experts from various government agencies including the NSA, FBI, US Department of Defense, US Department of Homeland Security, the UK government’s Centre for the Protection of Critical Infrastructure, and the Australian Defence Signals Directorate, with the assistance of various other industry recognized professionals.  Five principles of an effective cyber security defense are reflected in the Critical Security Controls: “Offense informs defense: Use knowledge of actual attacks that have compromised systems to provide the foundation to build effective, practical defenses. Include only those controls that can be shown to stop known real-world attacks. Prioritization: Invest first in controls that will provide the greatest risk reduction and protection against the most dangerous threat actors, and that can be feasibly implemented in your computing environment. Metrics: Establish common metrics to provide a shared language for executives, IT specialists, auditors, and security officials to measure the effectiveness of security measures within an organization so that required adjustments can be identified and implemented quickly. Continuous monitoring: Carry out continuous monitoring to test and validate the effectiveness of current security measures. Automation: Automate defenses so that organizations can achieve reliable, scalable, and continuous measurements of their adherence to the controls and related metrics professionals” (Council on CyberSecurity, 2013, pp. 2-3). The Critical Security Controls represent controls that are already found in many of the security management models in use today and are not meant to replace these models, but to focus and prioritize the controls that are implemented to achieve significant reductions in attack success.  Simply put, the Critical Security Controls represent the controls most likely to enhance an organization’s security posture, and provide a guide to management to know where to focus their attention and resources first.  One reason that makes the Critical Security Controls so valuable to smaller organizations, is they allow an organization to leverage the expertise of government, industry, and academia in determining what threats and vulnerabilities they are likely to face and should therefore allocate their resources to defend (Sager, 2013, p. 1). The consensus based risk assessment approach essentially allows for a risk assessment based on what the community of experts are seeing, rather than only relying on the expertise internal to one organization to determine the right responses.  Tony Sager, the former chief of the information assurance directorate at the NSA, asserts the Critical Security Controls are a “foundational risk assessment” that allows an organization to use it to determine where to start taking action.  The case for why the Critical Security Controls are relevant is simply that organizations today use common technologies and face common threats in an increasingly interconnected environment where organizations are linked to each other, so a common baseline of Critical Security Controls is applicable to many organizations.  Additionally, organizations may not have access to the resources and expertise to produce the results of the Critical Security Controls, so by leveraging the power of the community, they are in a better position to quickly assess and implement a baseline of defenses to thwart most attacks and then can concentrate their focus on specific threats to their business to further enhance their security posture (Sager, 2013, pp. 1-2). Expanding on the concept of using the Critical Security Controls as a foundational risk assessment is the goal of implementing continuous monitoring.  Given the dynamic nature of risks organizations face, there is an incentive to consider the move to continuous monitoring as a way to ensure risks are being managed effectively.  Risk assessment should not be a periodic activity, but should be integrated with the continuous monitoring approach used to manage risks based on the constant stream of new information available.   The Critical Security Controls offer another key advantage in this space as they provide an organization with a prioritized list of the most important elements to target for continuous monitoring (Sager, 2013, p. 3). Automation of the continuous monitoring process is also key in leveraging the ability of the controls to quickly provide value to an organization.  A central philosophy in the design of the Critical Security Controls is that, “…any defenses that can be automated, should be automated,” enabling rapid detection and mitigation of attacks to an organization’s network, with the goal of minimizing the damage (Tarala, 2012, p. 1).  Today’s organizations are up against some very sophisticated attacks, including malware that have the potential to avoid signature-based detection and also have the ability to disable antivirus and other security tools.  This stresses the importance of having automated controls such as application whitelisting, intrusion detection systems, and asset tracking systems that run and report automatically (Tarala, 2012, p. 5).  The principle way to accomplish automation and continuous monitoring is by deploying sensors to collect threat data from inbound and outbound network traffic and report it for correlation and further analysis.  The Critical Security Controls outline 45 different sensors that can be put into use by organizations.  These include asset tracking, vulnerability management systems, patch management systems, intrusion detection systems, authentication systems, and file integrity systems (Tarala, 2012, pp. 6-7).  Automation does not eliminate the need for intelligent people to analyze the information and determine how to respond, though it does maximize their efficiency and effectiveness by knowing when and where attacks are happening so they can focus their time remediating any issues that arise. Conclusion The Critical Security Controls offer a compelling incentive to organizations to align their security environment with these effective mitigations and reduce their potential for successful attacks.  As organizations implement these controls, it is likely they will realize cost savings through automation, increased visibility into the actual threats they face through continuous monitoring, and an overall lower risk of cyber attack, espionage, and theft, which can be a competitive advantage for any organization in today’s increasingly connected world. References Council on CyberSecurity. (2013, March). Critical Controls for Effective Cyber Defense - Version 4.1. Retrieved from Council on CyberSecurity: http://www.counciloncybersecurity.org/images/downloads/Critical%20Controls%20v4.1.pdf Lewis, J. A. (2013, February). Raising the Bar for Cybersecurity. Retrieved from Center for Strategic and International Studies: http://csis.org/files/publication/130212_Lewis_RaisingBarCybersecurity.pdf Pescatore, J. (2013, June). SANS 2013 Critical Security Controls Survey: Moving From Awareness to Action. Retrieved from SANS: http://www.sans.org/critical-security-controls/CSC_Survey_2013.pdf Sager, T. (2013, March). The Critical Security Controls: The Foundation For An Enterprise Risk Management Framework. Retrieved from NIST: http://csrc.nist.gov/cyberframework/rfi_comments/040813_sans_sager_controls_part2.pdf Tarala, J. (2012, June). Streamline Risk Management by Automating the SANS 20 Critical Security Controls. Retrieved from SANS: http://www.sans.org/reading-room/analysts-program/streamline-risk Verizon. (2013). 2013 Data Breach Investigation Report. Retrieved from Verizon: http://www.verizonenterprise.com/resources/reports/rp_data-breach-investigations-report-2013_en_xg.pdf --- ## Attack Overview - Video URL: https://securityorb.com/attack-overview-video/ Type: post Modified: 2018-10-30 There are generally two reasons an individual or an organization is attacked.  One, you are specifically targeted or two, you are a target of opportunity. Any good hacker will take a few common steps to attack a site these can generally be ordered from 1-4. Reconnaissance Scanning Research Vulnerabilities Performing the attack   Often you are going to be attacked by “script-kiddies” the easiest way to protect against them is simply make their job hard and they’ll move on somewhere else. Make sure OS and Apps are up to date with patches Turn off and remove un-necessary services and software Run a host-based firewall Don’t display information in service banners Don’t provide any information about your network/systems publicly --- ## The SecurityOrb Show - An Interview with Haiti CyberCon Co-Founder Michel Arbrouet URL: https://securityorb.com/the-securityorb-show-an-interview-with-haiti-cybercon-co-founder-michel-arbrouet/ Type: post Modified: 2018-10-30 HaitiCyberCon is an InfoSec/Hacker conference for professionals and enthusiasts alike located in Haiti, offering training as well interesting and inventive talks and workshops.  We had the opportunity to speak with MICHEL ARBROUET, the co-founder of the conference about the event, the goal of the event and some other interesting topics.   You can obtain more information about Haiti CyberCon below and see how you can get involved: https://www.haiticybercon.com/ https://www.facebook.com/haiticybercon/ 8662398227 @HaitiCyberCon --- ## A Book Review of “Pentesting Azure Applications” by Matt Burrough URL: https://securityorb.com/a-book-review-of-pentesting-azure-applications-by-matt-burrough/ Type: post Modified: 2018-10-28 In this book review, I looked at the topic of pentesting cloud-based applications, specifically Microsoft’s Azure.  While the focus of the book was for Azure, a lot of the information will be beneficial no matter the cloud environment.  Even thought Cloud hosting has been around for several years, it is still a new technology and many senior security professionals are learning the do and don’ts of how to secure the infrastructure. Matt Burrough I found “Pentesting Azure Applications” to be informative and Matt does a great job of sharing links to additional information on topics that can help secure your Azure deployment(s).  In this aspect, while this book is meant to be used for pentesting Azure, it is also a great resource in securing and locking down your subscription.   Just by looking at and using the “Defender’s Tips” that Matt includes, you will definitely make your network and systems more secure. The text consists of 8 chapters, each chapter stands by itself and there is no need to read chapters 1 thru 7, if you are looking to understand logging and alerting in chapter 8.  Below is a breakdown of each chapter and what can be found in each.  Since the book can be used for all levels of security testers, you may find that some chapters are more useful than others.  A lot of large pentesting firms have a team that handles the preparation and legal aspects for multiple teams, and you may want to jump straight to reconnaissance or network investigations chapters. Chapter 1 – Preparation In this chapter, Matt Burrough covers what to me is the most important part of any type of pentesting, the scope and legal issues.  Scope is an essential part of setting up the engagement rules, identifying the assets to be targeted and what, if anything, is out of bounds.  When compared to normal assessments, it is even more important to firmly define the scope in any cloud environment.  Matt makes sure to point out that assessments of this type involve three parties, the testing company, the tested organization and Microsoft, in the case of Azure.  All legal aspects should be reviewed by the pentesting companies’ lawyers to ensure compliance with all local and national regulations.  As with most endeavors, preparation is the framework for a successful, safe and legal penetration exercise. Chapter 2 – Access Methods Matt starts out by describing the two basic deployment models Azure Service Management (ASM - Legacy) and Azure Resource Manager (newer role-based system).  He spends time going over the advantages and disadvantages of both models as well as defining the weaknesses that can be targeted.  He details how certificate-based authentication works with in ASM and the difficulties of managing certificates.  He points out that the limit of certificate and owner tracking can be a problem, as well as name reuse, certificate revocation lists, storage, and nonrepudiation.  Matt recommends, as good security practice in Azure, that any legacy ASM model deployed should be migrated to ARM. Matt details several tools that can be used at each phase, listing where to find them and how to use them to get the most out of each.  Even though I have used Mimikatz in the past, I found that I picked up a new trick or two that I will definitely be using in the future.  He covers some basic information gathering techniques, like looking for credentials in unencrypted documents or saved tokens.  Additionally, he covers what to do if you run into systems that are using 2 Factor Authentication. Chapter 3 – Reconnaissance If you have done any work as pentester or defender, you will be familiar with the reconnaissance phase of pentesting, the knocks on the doors and the taps on the windows.  Most are familiar with basic port scanning looking for open ports and services, but with cloud environments such as Azure you have additional web services that are now susceptible to reconnaissance and attack.  As in chapter 2, Matt goes over several tools that will help in evaluating what services and networks are available for exploitation. As with other Microsoft products, PowerShell is a key tool in managing your Azure deployment and as such is also a tool that can be used to perform reconnaissance.  Keeping with providing Defender’s tips, Matt provides some great information on securing PowerShell.  The step by step directions that are provided are really good to be able to just jump in and start mapping out the services. Matt provides numerous basic commands that will get you started, including gathering information that will be essential as you move on from the reconnaissance phase.  One key aspect that he points out about VM pricing tiers that can help in identifying what might be running on that system.  Other information that can be found during this portion of the assessment, such as, IP addresses, Firewall rules, possible services will be of great benefit when you get to chapter 5. Matt has links to a couple very useful PowerShell scripts, one for each access model that automates the manual command line processes that he discusses.  This allows you to quickly gather the information and then review it at a later time. Chapter 4 – Examining Storage Here Matt describes Azure cloud storage and how there are two keys that grant full control to the data contained within the storage.  He starts off with some best practices, which also, if not implemented, points to some weaknesses that can be targeted.  There are three types of access to storage accounts, account keys, user credentials and Share Access Signature (SAS) tokens.  He goes into each of these types and details how they work and where they can be used.  Next, he spends some time discussing where to find these keys, such as built in to source code, configuration files and storage utilities.   If these methods don’t bare fruit, he covers several tools that can aid in getting access.  Once you have access to a storage account, Matt lists the steps of identifying the storage types and provides a script that can automate the process. Chapter 5 –Targeting Virtual Machines Here the author spends a great deal of time explaining various techniques and methods that are used in generic pentesting activities of more traditional infrastructures.  If you are able to obtain storage access as identified in chapter 4, Matt shows you how to take a snapshot of running VMs and then download them to work on them on your own hardware.  Another useful tool, autopsy, a disk forensic tool, is discussed and shown how it can have advantages over other tools used to explore the virtual hard drive (VHD).  Matt includes directions and several screenshots that allow even a novice to quickly start exploring the disk image.  A review of how best to start working with a Windows or Linux system, including various ways to crack password for both.  I have to admit it brought back some old memories when he was discussing Cain & Abel for password cracking. Chapter 6 – Investigating Networks This chapter starts with the available network options offered by Azure.  On top of basic network configurations, there are system level firewalls that are included by Azure for their SQL servers and application services.  Additionally, for web applications there is a paid Web Application Firewall (WAF) offering.  Azure does also allow Next-Generation firewalls as a service to be offered to their clients, which can add another level of difficulty in your pentesting attempts.  By understanding what is offered by Azure, a pentester can know what to expect and have the right tools and methods will work best. Matt points out that there are several VPN connection options available for connecting corporate network to cloud networks.  He provides a PowerShell scripts to export the details of VPN connections that are discovered, including ExpressRoute.  ExpressRoute is a custom Microsoft offering that offers dedicated connections between your local and cloud networks. Next, Matt covers the Service Bus, and how to gain details and how to look at messages for sensitive PII, code executions or SQL interactions.  Lastly in this chapter, Matt discusses two ways of connecting non-Azure services to Azure. Chapter 7 – Other Azure Services In previous chapters, the focus was on Azure core offerings, in chapter 7, some of the newer or lesser known services are discussed.  Matt takes a look at Azure Key Vault, Web Apps, and Automation and discusses the functionality, capabilities and vulnerable aspects of each.  He points out that like most tools, these services if configured incorrectly can be both the issue and the solution. Chapter 8 –Monitoring, Logs and Alerts In the final chapter, Matt detours from the attacking nature of pentesting and shift his focus to how Azure can be useful in monitoring your cloud environment.  Here he shows how system events and logs can be used to generated alerts that could help defect or at least detect the things he was teaching in chapters 2-7. He covers the Azure Security Center (ASC), the Operations Management Suite (OMS) and the Secure DevOps Kit.  ASC (paid subscription) has both detection and prevention components, it can alert on potentially malicious activity and also look at service configurations and make suggestions on increasing security of those services.  In chapter 2, Matt discussed using the tool MimiKatz, well here in chapter 8 he shows how just using that program can generate an alert for that activity.  If you don’t have a robust logging and monitoring platform, such as Splunk, the OMS offering can provide the same services for cloud and on-premise systems. Lastly, Matt covers the Secure DevOps Kit, a collection of scripts, that when used will review your Azure subscription and test for numerous configuration issues and produce a report with results. Conclusion While this book serves those interested in pentesting Azure, it is also a good guide for pentesting in general and additionally offers a lot of information on securing your infrastructure.  Being more of a defender, myself, I found useful advice throughout the book, but was particularly interested in chapter 8.  The book is available online and can be purchased at the No Starch Press website here, as well as a link to scripts that were discussed in the book. --- ## How-to Display a Warning Banner Before the Login Prompt URL: https://securityorb.com/how-to-display-a-warning-banner-before-the-login-prompt/ Type: post Modified: 2018-10-04 It is best to have a warning banner displayed before a user is logged in.  Below is how you will implement this task. 1) By default sshd server turns off this feature. 2) Login as the root user; create your login banner file: # vi /etc/ssh/sshd-banner Append text: * * * * * * * * * * W A R N I N G * * * * * * * * * * This computer system is the property of XYZ. It is for authorized use only.  By using this system, all users acknowledge notice of, and agree to comply with XYZ’s Acceptable Use of Information Technology Resources Policy (“AUP”).  Unauthorized or improper use of this system may result in administrative disciplinary action, civil charges/criminal penalties, and/or other sanctions as set forth in XYZ’s AUP. By continuing to use this system you indicate your awareness of and consent to these terms and conditions of use. If you are physically located in the European Union, you may have additional rights per the GDPR. Visit the web site dataprivacy.utk.edu for more information. LOG OFF IMMEDIATELY if you do not agree to the conditions stated in this warning. * * * * * * * * * * * * * * * * * * * * * * * * 3) Open sshd configuration file /etc/sshd/sshd_config using a text editor: # vi /etc/sshd/sshd_config 4) Add/edit the following line: Banner /etc/ssh/sshd-banner 5) Save file and restart the sshd server: # /etc/init.d/sshd restart 6) Test your new banner (from Linux or UNIX workstation or use any other ssh client): $ ssh user@host   Output: * * * * * * * * * * W A R N I N G * * * * * * * * * * This computer system is the property of XYZ. It is for authorized use only.  By using this system, all users acknowledge notice of, and agree to comply with XYZ’s Acceptable Use of Information Technology Resources Policy (“AUP”).  Unauthorized or improper use of this system may result in administrative disciplinary action, civil charges/criminal penalties, and/or other sanctions as set forth in XYZ’s AUP. By continuing to use this system you indicate your awareness of and consent to these terms and conditions of use. If you are physically located in the European Union, you may have additional rights per the GDPR. Visit the web site dataprivacy.utk.edu for more information. LOG OFF IMMEDIATELY if you do not agree to the conditions stated in this warning. * * * * * * * * * * * * * * * * * * * * * * * * --- ## Is Digital Privacy A Right Or A Privilege? URL: https://securityorb.com/is-digital-privacy-a-right-or-a-privilege/ Type: post Modified: 2018-10-03 By Steve Andriolea Contributor at Forbes.com There are many dimensions to our digital worlds. We buy everything online. We entertain ourselves with endless piles of digital content. We communicate and socialize with friends and colleagues. We’re all digital, all the time. But what we do, what we buy, who we visit and what we think is now on sale. Have we thought carefully enough about this? Is everyone OK with selling browsing histories? I’d sure like to know which sites my friends, colleagues and enemies visit. Wouldn’t you? I’m sure that retailers would love to know what I do online. Many of them already do, of course, but we’re about to tell them more about me – and you – than anyone – except them – really wants to know. Several recent events should make us re-think our digital rights and privileges. The debate about net neutrality, which I’ve discussed before, is important here, especially given the recent decision by the United States Congress to allow Internet Service Providers to collect and sell browser data. When I asked my students if they were aware of the proposed changes to the law, they were surprised to learn that their surfing habits could now be collected and sold, though they all already know about cyber stalking when they search for Spring break deals. They immediately started to hypothesize where browsing histories could be exposed with varying results, such as what might happen if their parents knew everything they did online, or if the sites that politicians or their staffs visited were posted on social media. Or how insurance companies might leverage browsing histories to set rates. It didn’t take them long to identify lots of weird scenarios. While most of these scenarios are unrealistic, some may well occur if the new regulations are sloppily interpreted. The proponents of net neutrality rollbacks argue that tiered rate schedules will fund infrastructure innovation. The supporters of anti-privacy legislation argue that there’s little distinction between media companies (like Facebook) and ISPs, and both should have the right to collect and sell data that reflects the behavior of their customers. These are the business arguments. Are there other arguments we might want to consider? Read more at Forbes here. --- ## National Cyber Security Awareness Month - Week 1: Make Your Home a Haven for Online Security URL: https://securityorb.com/national-cyber-security-awareness-month-week-1-make-your-home-a-haven-for-online-security/ Type: post Modified: 2018-10-01 National Cyber Security Awareness Month Week 1: Make Your Home a Haven for Online Security October 1, 2018 We’re excited to kick off the first week of National Cyber Security Awareness Month. This week, we’ll focus on how you can secure yourself at home. We have several resources available to help you, including: Four simple steps for protecting you and your family in your daily lives The top three online threats to your children and what you can do about them The methods criminals use for gaining information about you and your family If you’re interested in participating in this week’s activities, visit the NCSAM Activity Page, where you can also find online safety tips, interesting trends, and blog posts. Remember: security depends on you – Know it. Own it. Protect it. --- ## A Book Review of “Learning Malware Analysis” by Monnappa KA URL: https://securityorb.com/a-book-review-of-learning-malware-analysis-by-monnappa-ka/ Type: post Modified: 2018-10-01 Monnappa KA In my latest book review, I took on the topic of malware analysis which is not often covered in security books or training centers.  In 2018, Packt Publishing released “Learning Malware Analysis” by Monnappa KA.  Monnappa works for Cisco Systems as an information security investigator focusing on threat intelligence and the investigation of advanced cyber-attacks, he is also a member of the Black Hat review board. I found “Learning Malware Analysis” to be very informative, easy to read as well as follow, moreover I found the examples in the book easy to replicate which was priceless.  Many times in the examples associated with books, the labs never quit work out as stated and you are left trying to figure out that went wrong.  When Monnappa introduced a concept, he would define it and follow it up with an example or analogy to help the reader obtain a stronger comprehension.  If fact, throughout the whole book, he would end a paragraph, concept or idea with the term “for example” or “for instance”.  This was something I appreciated very much as some of the concepts can be uncharted territory even for the seasoned security practitioner. Monnappa went through great length as he explained why it was important to use a testing environment, how to create a testing the environment, how to obtain the necessary tools and lastly how to obtain the malware to analyze.  Another important aspect I would like to share is the diversity in the techniques he presented for analysis.  Monnappa discussed a technique using Linux command line, followed by using a software tool then he also showed how to replicate an analysis using python code in multiple operating environments.  This can be very valuable to the reader depending on their skill level, experience and comfort level on different platforms.  In my opinion, to be successful in malware analysis, I would recommend being proficient in the Linux operating system as well as having some programming knowledge as the later chapters drew from it and proved to be more challenging.  As Monnappa stated, “To gain a deeper understanding of a malware's inner workings and to understand the critical aspects of a malicious binary, code analysis needs to be performed.” This book is definitely geared towards those in the incident response, cybersecurity investigation, malware analysis, forensic practitioner sector, but as an academic, this text can also serve well in academia as a lab resource to compliment lectures in the program.  I also see this text as an excellent recourse for security practitioners looking to take a new direction in their career to learn or enhance their malware analysis skills. The text consists of 11 chapters, the first 3 chapter provided an abundance of fundamental information and examples to get the reader started, while the remaining chapter are draws from a basic understanding of programming and took the topic into greater depths.  Below is a breakdown of each chapter. Chapter 1 - Introduction to Malware Analysis: In this chapter, Monnappa introduced the readers to the concept of malware analysis as he discussed the different types that exist.  He then discussed the various types of malware analysis such as static and dynamic, followed by a comprehensive set of instructions to setting up an isolated malware analysis lab environment. Chapter 2 - Static Analysis: In this chapter, Monnappa explained and demonstrated the tools and techniques necessary to extract information from malicious binary. In doing so the reader would be able to compare and classify malware samples as well as learn how to determine various aspects of the binary without executing it. Chapter 3 - Dynamic Analysis: in this chapter, he showed the reader the tools and techniques needed to determine the behavior of the malware and its interaction with the system. Chapter 4 - Assembly Language and Disassembly Primer: in this chapter, the author went into the basics of computer programing, the assembly language and basic computer architecture.  These would be the necessary skills required to perform code analysis in the later chapters. Chapter 5 - Disassembly Using IDA: In this chapter, Monnappa covered the features of IDA Pro Disassembler, and examined how to use IDA Pro to perform static code analysis (Disassembly). Chapter 6 - Debugging Malicious Binaries: In this chapter, Monnappa explained the technique of debugging a binary using x64dbg and IDA Pro debugger. He also demonstrated how to use a debugger to control the execution of a program and to manipulate a program's behavior. Chapter 7 - Malware Functionalities and Persistence: In this chapter, Monnappa described various functionalities of malware using reverse engineering. He also covered the various persistence methods used by the malicious programs. Chapter 8 - Code Injection and Hooking: In this chapter, Monnappa discussed and demonstrated common code injection techniques used by the malicious programs to execute malicious code within the context of a legitimate process. He also described the hooking techniques used by the malware to redirect control to the malicious code to monitor, block, or filter an API's output. The reader had the opportunity to analyze malicious programs that use code injection and hooking techniques. Chapter 9 - Malware Obfuscation Techniques: In this chapter, the author discussed encoding, encryption, and packing techniques used by the malicious programs to conceal and hide information. The reader will learn different strategies to decode/decrypt the data and unpack the malicious binary. Chapter 10 - Hunting Malware Using Memory Forensics: In this chapter, the author demonstrated techniques to detect malicious components using memory forensics. The reader will learn various Volatility plugins to detect and identify forensic artifacts in memory. Chapter 11 - Detecting Advanced Malware Using Memory Forensics: In this chapter, Monnappa demonstrated the stealth techniques used by advanced malware to hide from forensic tools. You will have the opportunity to learn how to investigate and detect user mode and kernel mode rootkit components. Monnappa’s approach to “Learning Malware Analysis” was comprehensive, useful and timely, especially with the increase of malware entering out operational environment.  Organizations are in need of specialized practitioners who understand the threat and can analyze them to aid in the defense of critical assets. This book does serve those interested in venturing to malware analysis but as stated, it is recommended, those venturing into the field have an understanding of computer architecture and computer programming concepts. In academia, this book can be useful in the information security and/or computer science programs. Monnappa’s book makes a valuable contribution to the information security community by provided information security practitioners with the knowledge and capability to obtain the rare ability to conduct malware analysis.  I personally enjoyed chapters 1 – 6, because of the information and examples were easy to comprehend and perform.  While chapter 7 – 11 were more advanced and difficult, I never felt lost when following the examples and reading the text.  I personally would recommend this book for those looking to enter the malware analysis field or even enhancing their current skills in this topic.  From reading the text, I can deduce Monnappa is very proficient in the topic and he does an excellent job in conveying his knowledge to text. The book is available online and can be purchased at the Packt Publishing website here or at Amazon here. --- ## Cyberwar Season 1 – Episode 3: Cyber Mercenaries URL: https://securityorb.com/cyberwar-season-1-episode-3-cyber-mercenaries/ Type: post Modified: 2018-09-10 Authoritarian regimes are using spyware tools bought from private companies in the West. Hacker PhineasFisher targeted these companies to reveal their deals to suppress dissent. Hey everyone I am on the third episode of “Cyberwar” hosted by Ben Makuch (@BMakuch) a national security reporter that travels the world to meet with hackers, government officials, and dissidents to investigate the ecosystem of cyberwarfare. They have been really entertaining and educational about the events and issues in information security and digital privacy on a global level. Episode 1 looked at Anonymous Episode 2 looked at The Sony Hack In episode 3, Ben explored the world of commercial spyware tools. In his report, he discovered many governments using spyware tools on criminals but alarming he discovered repressive regimes using it to spy on their opposition. One such example stemmed from an incident that occurred to Mesay Mekonnen, an exiled Ethiopian Journalist from ESAT living in the America. Mekonnen received a skype friend request with the ESAT logo, once he accepted the friend request, it soon followed with a PDF file. Mokonnen then attempted to open the PDF file and systems reacted unfavorably and infected his computer. Upon investigation, the internet address pointed to a company called “Hacking Team” as well as an internet address in Ethiopia. Ron Deibert, Director of Citizen Lab stated, “Surveillance in of itself is not a bad thing, the question is what is that surveillance for and are there proper checks and balances around it?”. Ben spoke to Eric Rabe of “Hacking Team” about the incident and their practices where he discussed there is a use for their tool to aid law enforcement and that Hack Team is not responsible for human right abuses that occur from using their tool. A hacker named PhineasFisher did not agree with Hacking Team’s practice and hacked their servers showing client lists and many information which showed some bad business judgment. Interesting enough it was also discovered a number of companies supplying Hacking Team with 0-days to hack companies. Overall, this was another great episode into the world of commercial spyware and the push to get it regulated. You can view the episode here or at the full link provided: https://www.viceland.com/en_us/video/cyber-mercenaries/57717831a83ff7132d3e8d22 Also, on YouTube: How do you feel about this episode and the topic? Please share your thoughts. --- ## Ex-Facebook security boss: U.S. elections risk becoming 'World Cup of information warfare' URL: https://securityorb.com/ex-facebook-security-boss-u-s-elections-risk-becoming-world-cup-of-information-warfare/ Type: post Modified: 2018-09-04 Ex-Facebook security boss: U.S. elections risk becoming 'World Cup of information warfare' After three years in the trenches of Facebook's war against disinformation, Alex Stamos brings bad news from the front: US elections are at risk of becoming the "World Cup of information warfare." "That campaign to drive wedges into American society has not stopped. If anything, it has intensified," Stamos told CNN recently. Stamos is not an alarmist. He has spent the better part of the past two decades in the digital security business, most recently as the head of information security at Facebook. Before that, he spent a few years at Yahoo — where, among other things, he warned US lawmakers about the impact of online advertising on data security and privacy. He has over the years earned a reputation for speaking his mind, and at one point challenged Michael Rogers, head of the National Security Agency at the time, on the finer points of data encryption. His warning comes as Facebook COO Sheryl Sandberg and other tech leaders are set to appear before the Senate Intelligence Committee. The panel, led by Republican Richard Burr and Democrat Mark Warner, wants to know just what Facebook, Twitter, Google, and others are doing to safeguard November's midterm elections against the sort of disinformation campaigns that peppered their platforms in 2016. Read more here. --- ## Book Review of “Practical Cyber Intelligence” by Wilson Bautista Jr URL: https://securityorb.com/book-review-of-practical-cyber-intelligence-by-wilson-bautista-jr/ Type: post Modified: 2018-08-31 Packt Publishing, in 2018 released “Practical Cyber Intelligence” by Wilson Bautista Jr. a retired military officer who holds the position of Director of IT and InfoSec at i3 Microsystems. Author: Wilson Bautista Jr. I found this book to be very informative, easy to read as well as easy to follow once I engaged it.  One of the key aspects that captured my attention pertained to the vital information and moreover the perspective into information security that is rarely discussed or examined in recent offerings.  As a practitioner in the information security field, this book can serve as a handbook for team leads, managers, directors and CISOs responsible for securing organizational assets. As an educator of information security, this book can serve as a key role in courses dealing with in the management of information security as a possible text, but definitely as supplemental reading text. The author asks a lot of questions to help the reader think of the problems organizations have to face when tasked to protect their assets, but he also answered a great deal of questions to aid the reader in understanding solutions to those very problems.  One such example that hit home with me existed in chapter 1 in the section titled “Intelligence drives operations”.  Here Bautista explained the concept of “Priority Information Requirements (PIRs)” in military use and used a commercial, non-military example of the concept to illustrate how it fits in the information security arena.  These are the real world examples that it a joy to read and increased my over knowledge in the field. The table of content represented an orderly and organized method to following the text.  The first few chapters provided information and historical references to build a foundational concepts of the overall topic.  Each chapter literally builds on top of the next chapter while reinforcing information from the previous chapter in conjunction to building new knowledge and concepts the further you read. The body of the book consist of fifteen (15) well-written chapters with the last chapter being more of a conclusion/wrap-up chapter. Below is a summary of each chapter: Chapter 1, The Need for Cyber Intelligence – Bautista does an excellent job explaining to the reader the reason why organizations need to incorporate a cyber intelligence component into their organization’s cyber security posture.  He then provided a brief history of how intelligence have been used in the military drawing from stories pertaining to the American Revolutionary War and Napoleon’s use of intelligence.  Bautista did an excellent job in explaining the different type if intelligence gathering and what information would fall under those categories.  This chapter was gratifying and informative as it laid a strong foundation cyber intelligence. Chapter 2, Intelligence Development - Bautista introduced a useful concept in information hierarchy known as “DIKW” which stands for Data, Information, Knowledge and Wisdom.  This concept discussed the techniques that would be used to sort through massive data to turn in into actionable intelligence.  I found this chapter to be very useful as he provided processes such as “The Intelligence Cycle Steps” that can be mapped to current security data collection procedures in an organization. Chapter 3, Integrating Cyber Intel, Security, and Operations – In this chapter, Bautista introduced and explains the concept of operation security (OPSEC), as well as discussed the concept of developing a strategic cyber intelligence capability by adding the Capability Maturity Model (CMM) into the discussion.  Once again, he took the time to explain the OPSEC process, by breaking it down into five (5) steps and examined the model of the cyber intelligence program roles into three (3) sections. Chapter 4, Using Cyber Intelligence to Enable Active Defense – In the chapter, Bautista reintroduced the concept of CMM as well as the Cyber Kill Chain which aids in identifying the actions needed by an adversary to exploit a target.  Once again, he provided a detail breakdown of active defense topics which covered a wide range of concepts. Chapter 5, F3EAD For You and For Me – In this chapter, the author introduced the Find, Fix, Finish, Exploit, Analyze, and Disseminate process that is deployed for high value targets and it's applicability to the Cyber Kill Chain.  Bautista begins by defining the concept of targeting, then provides a practical scenario where the intelligence cycle and F3EAD were integrated.  He also examines many concepts previously discussed as it relates to F3EAD and Cyber Kill Chain. Chapter 6, Integrating Threat Intelligence and Operations – In this chapter, Bautista examines in detail how cyber intelligence can be incorporated in a security program.  I enjoyed this chapter due to my familiarity with many of the processes, actions and concepts as an InfoSec practitioner.  He discussed the concept of evidence-base knowledge and the tools associated with them.  Many topics once again were re-introduced such as CMM and how information gather can be implemented with some popular and commonly used tools. Chapter 7, Creating the Collaboration Capability – In this chapter, the main goal was to explain the process and importance of creating a collaboration capability to support a cyber intelligence program throughout the organization.  Some key thoughts discussed were the formal communication such as policies and reports, and informal communications such as working groups and influence.  He also explained how communication fits into cyber intelligence and what tools can aid in the process. Chapter 8, The Security Stack – The author provided a view on how information captured from different security capabilities can be developed into cyber intelligence to support decision making.  Once again CMM is reintroduced for information security in great detail.  This chapter was very informative for the security practitioner. Chapter 9, Driving Cyber Intel – In this chapter, Bautista shared an interesting topic of leveraging the user community as a source of information gathering and reporting.  The chapter looks into the importance and usefulness of security awareness and examining the CMM process in detail to drive the security awareness process. Chapter 10, Baselines and Anomalies – In this chapter, Bautista discussed the difficulty of reporting and metrics in operations and continuous monitoring is examined under the CMM concept in great detail. Chapter 11, Putting out the Fires – Bautista introduced the concept of handling anomalies, by discussing ways to improve incident response through developing good intelligence communication channels.  The incident response process is explained in detail and once again incorporated into the CMM. Chapter 12, Vulnerability Management – In this chapter, Bautista discussed how an organization can reduce weaknesses through the concept of vulnerability management.  He explained in detail once again the under the CMM concept the process of scanning, reporting and managing in conjunction to the scoring systems. Chapter 13, Risky Business and Chapter 14, Assigning – These chapters are closely related as Bautista introduced a broad overview of risk, data classification, risk metrics and key risk indicators under the CMM concept.  Some interesting governance, risk management and compliance (GRC) tools are provided to aid with the process. Chapter 15, Wrapping Up – Bautista provided an overall summary of the book and concepts covered within.  He described a scenario of an established cyber intelligence program the their operational practices.  It is worth reading and it is relatively short. Bautista’s approach in his book “Practical Cyber Intelligence” was comprehensive for both the beginner and seasoned security practitioner regardless of their role.  I do think a seasoned professional in leadership will find more value in the text as compared to a Jr. Security Analyst.  In addition, as an educator, this text definitely has a role in the academic realm especially in the graduate level. This book is a contribution to the information security community and will surely aid in producing knowledgeable information security leaders and managers in the future.  I personally enjoyed chapter 6, Integrating Threat Intelligence and Operations, chapter 11, putting out the Fires and chapter 12, Vulnerability Management the most as I was able to relate from my professional experience. I do recommend that if you are interested in expanding your knowledge in information security or if you are in a leadership role and would like to know more about topic of protecting your organization beyond the traditional manner, this book would be a great source. The book is available online and can be purchased at the Packt Publishing website here or at Amazon here. Reference: Bautista Jr., Wilson (2018). Practical Cyber Intelligence. Packt Publishing Packt is searching for authors like you If you're interested in becoming an author for Packt, please visit authors.packtpub.com and apply today. They have worked with thousands of developers and tech professionals, just like you, to help them share their insight with the global tech community. You can make a general application, apply for a specific hot topic that they are recruiting an author for, or submit your own idea. --- ## Cyberwar Season 1 – Episode 2: The Sony Hack URL: https://securityorb.com/cyberwar-season-1-episode-2-the-sony-hack/ Type: post Modified: 2018-08-01 So, I am on my second episode of “Cyberwar” hosted by Ben Makuch (@BMakuch) a national security reporter. Cyberwar is a show where Ben travels the world to meet with hackers, government officials, and dissidents to investigate the ecosystem of cyberwarfare. The first episode looked into the decentralized group of international activist hackers known as “Anonymous” while episode 2 explores The Sony Hack.  At that time (2014) the Sony Hack was one of the worst attacks against a corporation.  Not only were embarrassing emails released, personal health records of employees and their family and social security numbers to name a few were dumped.  North Korea was named the culprit and many people assumed it was due to an upcoming release of a movie titled ‘The Interview” about the assassination of the North Korea leader. Ben was able to get an interview with a former Sony employee (Celina Chavanette), this was the first time someone from the inside spoke about the matter on camera and it was interesting to hear about the incident from her point of view. Other compelling interviews were conducted which contradicted the government’s assertion North Korea was behind the hack Overall, this was another great episode into the back story behind why Sony was a target by many entities and not just North Korea. You can view the episode here or at the full link provided: https://www.viceland.com/en_us/video/the-sony-hack/577177f4db3251f521db358f Also, on YouTube:   How do you feel about this episode and the topic?  Please share your thoughts. --- ## Cyberwar Season 1 – Episode 1 Recap: Who is Anonymous? URL: https://securityorb.com/cyberwar-season-1-episode-1-recap-who-is-anonymous/ Type: post Modified: 2018-07-31 I started watching a very interesting program titled “Cyberwar” hosted by Ben Makuch (@BMakuch) who is a national security reporter. The show is described as: Ben Makuch travels the world to meet with hackers, government officials, and dissidents to investigate the ecosystem of cyberwarfare. The first episode looked into the decentralized group of international activist hackers known as “Anonymous” which has been linked to numerous high-profile incidents over the years, including Internet attacks on governments, major corporations, financial institutions and religious groups.  A trademark for the online hacktivist group is a person wearing a Guy Fawkes mask. I found this episode to be very nostalgic as Ben chronicled the start of Anonymous with its start on 4chan to LulzSec and affiliation with WikiLeaks.  Also, being able to see him interview former as well as current Anonymous members brings an authentic piece that is rarely seen when discussing this subject matter. The segment about Hector Xavier Monsegur aka Sabu as well as other hackers being arrested was especially intriguing since I followed that story closely and covered it on securityorb.com/ on numerous occasions as listed below: LulzSec & Anonymous Hackers Arrested - https://securityorb.com/general-security/lulzsec-anonymous-hackers-arrested/   LulzSec Sabu was working for the FBI - https://securityorb.com/general-security/lulzsec-sabu-working-fbi-trace-lulzsec-hackers/   Sabu speaks about his early days of hacking - https://securityorb.com/interview/cnet-news-hector-monsegur-interview-sabu-speaks-early-days-hacking/ Ben was also able to score an interview with legendary hacktivist and former Anonymous member Jeremy Hammand aka sup_g while he is still serving time for the Stratfor Global Intelligence firm hack. Overall, this was a great episode, especially for those of us that followed these hacking groups.  Being able to hear their thoughts and motives is something that is priceless.   You can view the episode here or at the full link provided: https://www.viceland.com/en_us/video/who-is-anonymous/5771776a4939b9e7078f1f55 What is your feeling about this episode and the topic?  Please share your thoughts. --- ## LifeLock’s Customer emails made Vulnerable URL: https://securityorb.com/lifelocks-customer-emails-made-vulnerable/ Type: post Modified: 2018-07-26 Per Krebs, “Identity theft protection firm LifeLock — a company that’s built a name for itself based on the promise of helping consumers protect their identities online — may have actually exposed customers to additional attacks from ID thieves and phishers”. Here’s what we know so far: LifeLock, an identity protection company, has put millions of customer emails at risk for phishing and identity theft attacks, thanks to a bug on its website.   The bug enabled customer email addresses to be harvested by simply changing one number in the URL of a web page used by customers to unsubscribe from LifeLock communications.   It’s important to note that this is not a breach, but it is a vulnerability to pay attention to, since ID thieves can use email addresses to steal other personal info. How to protect your info: Here are some tips to help you protect yourself:   Be skeptical of email communications urging you to take immediate action or claiming that they are privacy policy updates.   Do not click on any suspicious-looking links in those messages and instead forward any suspicious email to the company itself. Call the company directly to confirm whether any such messaging is actually from them.   Do not enter any personal info or credentials via links in emails. If you need to make updates, go directly to the company’s website to do so.   Check your credit report regularly to keep an eye on any unauthorized activity.   Consider locking your credit file to help prevent potentially fraudulent access.   Reference: LifeLock Bug Exposed Millions of Customer Email Addresses - https://krebsonsecurity.com/tag/lifelock/   --- ## OWASP Mutillidae II URL: https://securityorb.com/owasp-mutillidae-ii/ Type: post Modified: 2018-07-26 OWASP Mutillidae II Web Pen-Test Practice Application OWASP Mutillidae II is a free, open source, deliberately vulnerable web-application providing a target for web-security enthusiast. Mutillidae can be installed on Linux and Windows using LAMP, WAMP, and XAMMP. It is pre-installed on SamuraiWTF and OWASP BWA. The existing version can be updated on these platforms. With dozens of vulnerabilities and hints to help the user; this is an easy-to-use web hacking environment designed for labs, security enthusiast, classrooms, CTF, and vulnerability assessment tool targets. Mutillidae has been used in graduate security courses, corporate web sec training courses, and as an "assess the assessor" target for vulnerability assessment software.   Features Has over 40 vulnerabilities and challenges. Contains at least one vulnerability for each of the OWASP Top Ten 2007, 2010, 2013 and 2017 Actually Vulnerable (User not asked to enter “magic” statement) Mutillidae can be installed on Linux, Windows XP, and Windows 7 using XAMMP making it easy for users who do not want to install or administrate their own webserver. Mutillidae is confirmed to work on XAMPP, WAMP, and LAMP. Installs easily by dropping project files into the "htdocs" folder of XAMPP. Will attempt to detect if the MySQL database is available for the user Preinstalled on Rapid7 Metasploitable 2, Samurai Web Testing Framework (WTF), and OWASP Broken Web Apps (BWA) Contains 2 levels of hints to help users get started Includes bubble-hints to help point out vulnerable locations Bubble-hints automatically give more information as hint level incremented System can be restored to default with single-click of "Setup" button User can switch between secure and insecure modes Secure and insecure source code for each page stored in the same PHP file for easy comparison Provides data capture page and stores captured data in database and file Allows SSL to be enforced in order to practice SSL stripping Used in graduate security courses, in corporate web sec training courses, and as an "assess the assessor" target for vulnerability software Mutillidae has been tested/attacked with Cenzic Hailstorm ARC, W3AF, SQLMAP, Samurai WTF, Backtrack, HP Web Inspect, Burp-Suite, NetSparker Community Edition, and other tools Instructional Videos: http://www.youtube.com/user/webpwnized Updates tweeted to @webpwnized Updated frequently Project Whitepaper: http://www.giac.org/paper/gwapt/3387/introduction-owasp-mutillidae-ii-web-pen-test-training-environment/126917 Download it here or https://sourceforge.net/projects/mutillidae/   --- ## Warning Banner Sample for Systems and Network Devices URL: https://securityorb.com/warning-banner-sample-for-systems-and-network-devices/ Type: post Modified: 2018-07-21 System/Network Login Banners Login banners provide a definitive warning to any possible intruders that may want to access your system that certain types of activity are illegal, but at the same time, it also advises the authorized and legitimate users of their obligations relating to acceptable use of the computerized or networked environment(s). A requirement for successfully prosecuting unauthorized users who improperly use an organization’s computer is that the computer must have a warning banner displayed at all access points. The banner must warn authorized and unauthorized users: what is considered proper use of the system; that the system is being monitored to detect improper use and other illicit activity; that there is no expectation of privacy while using this system. The technical details for implementing banners is dependent on the particular operating system and access point. Below are long- and short-form login banners that are acceptable to use on any organization’s system. Long-Form Banner: * * * * * * * * * * W A R N I N G * * * * * * * * * * This computer system is the property of [Organization Name]. It is for authorized use only. By using this system, all users acknowledge notice of, and agree to comply with, the [Organization Name] Acceptable Use of Information Technology Resources Policy (“AUP”).  Click here to read the policy. Users have no personal privacy rights in any materials they place, view, access, or transmit on this system. The [Organization Name] complies with state and federal law regarding certain legally protected confidential information, but makes no representation that any uses of this system will be private or confidential. Any or all uses of this system and all files on this system may be intercepted, monitored, recorded, copied, audited, inspected, and disclosed to authorized [Organization Name] and law enforcement personnel, as well as authorized individuals of other organizations. By using this system, the user consents to such interception, monitoring, recording, copying, auditing, inspection, and disclosure at the discretion of authorized [Organization Name] personnel. Unauthorized or improper use of this system may result in administrative disciplinary action, civil charges/criminal penalties, and/or other sanctions as set forth in the University’s AUP. By continuing to use this system you indicate your awareness of and consent to these terms and conditions of use. If you are physically located in the European Union, you may have additional rights per the GDPR. Visit the web site dataprivacy.utk.edu for more information.117-120217-18 ALL USERS SHALL LOG OFF [Organization Name] OWNED SYSTEM IMMEDIATELY IF SAID USER DOES NOT AGREE TO THE CONDITIONS STATED ABOVE. * * * * * [Organization Name Department]* * * * *  Short-Form Banner: * * * * * * * * * * W A R N I N G * * * * * * * * * * This computer system is the property of the [Organization Name]. It is for authorized use only.  By using this system, all users acknowledge notice of, and agree to comply with, the [Organization Name] Acceptable Use of Information Technology Resources Policy (“AUP”).  Click here to read the policy.  Unauthorized or improper use of this system may result in administrative disciplinary action, civil charges/criminal penalties, and/or other sanctions as set forth in the [Organization Name] AUP. By continuing to use this system you indicate your awareness of and consent to these terms and conditions of use. If you are physically located in the European Union, you may have additional rights per the GDPR. Visit the web site dataprivacy.utk.edu for more information. LOG OFF IMMEDIATELY if you do not agree to the conditions stated in this warning. * * * * * * * * * * * * * * * * * * * * * * * * --- ## Mile2® Certification Updates URL: https://securityorb.com/mile2-certification-updates/ Type: post Modified: 2018-07-17 C)PTE Version 5.0 is Finally Here! Mile2® is proud to announce our newly updated Certified Penetration Testing Engineer Certification! New topics include the Internet of Things (IoT), as well as the most up to date penetration testing methodologies. Learn More About C)PTE V.5 Hot New Cybersecurity Courses! CPSH - Certified Powershell Hacker: Learn how to hack with Microsoft PowerShell and get certified with one of the leading Cyber Security PowerShell courses. Download Course Outline Red Team vs Blue Team:  Mile2® offers ½, 1 day and 2-day Red Team vs. Blue Team courses. Experience a real live attack and defense session. Learn More C)SA2 - Certified Security Awareness 2:  This course teaches general security awareness as well as how to develop a strong security culture within your company’s community. Learn More About C)SA2 Ultimate C)ISSO Bootcamp Begins August 17th! Don't Miss Out! Become a Certified Information Systems Security Officer and Command a Six-Figure Salary! Our Ultimate Bootcamp will get you C)ISSO and C)ISSM Certified in just 6 days. Register For Bootcamp --- ## Cyber Security Job Posting URL: https://securityorb.com/cyber-security-job-posting/ Type: post Modified: 2018-07-17 Title: Cyber Security Location: Patuxent River, MD 20670 Duration; Full Time Security Clearance: Active Secret Certification: DoD 8570 IAT Level II (Security+CE, CCNA-Security, GSEC, SSCP) or IAM Level II Certification (CAP, CASP CE, GSLC, CISM, CISSP). Job Description: ·         Demonstrate subject matter expertise in DoD Information Assurance Certification and Accreditation Process (DIACAP) and / or Risk Management Framework (RMF). ·         Ensure information systems security and application security policies and procedures (Security Technical Implementation Guides [STIG], Information Assurance Vulnerability Management [IAVM], and Federal Information, Security Management Act (FISMA)) are followed. ·         Develop/implement system security plans, control implementation, system requirements, test procedures, etc. ·         Conduct information system (IS) security assessments and validations. ·         Provide security recommendations/remedial actions to the client to ensure IS compliance is met and plan of actions and milestones are define accordingly. Please provide the following information Rate Expectation: Full Name: Contact No: Alternate contact (if any): Email address: Current Location: Relocation: Availability: Visa status Kindly share your detailed resume at sandeepk@etalentnetwork.com --- ## Using Login Banner on a Mac OS X system URL: https://securityorb.com/using-login-banner-on-a-mac-os-x-system/ Type: post Modified: 2018-07-17 What is a login Banner? A login banner is a statement made by the system owner that asserts their rights and informs the users of the system what expectation of privacy they should have. Login banners are a critical aspect of IT system security as they allow IT systems administrators and IT Security staff to monitor the system for intrusion and abuse. Why do we need login banners? In any modern IT system log monitoring, network monitoring, and security monitoring take place at regular intervals. It is theoretically possible that, while performing their work related duties, an IT systems administrator will come across user information (such as a file stored on the system). The purpose of the login banner is to inform any user of the system that they may be monitored and that unauthorized or malicious access may be prosecuted. Administrators should use login banners on any system that supports their use. Sample Login Banner As a login banner is a form of legal assertion, please consult your General Counsel and Information Services before using the following login banner for use on any systems: Access to electronic resources at [Organization] is restricted to employees, students, or individuals authorized by the [Organization] or its affiliates. Use of this system is subject to all policies and procedures set forth by the [Organization] located at www.xyz.com. Unauthorized use is prohibited and may result in administrative or legal action. [Organization] may monitor the use of this system for purposes related to security management, system operations, and intellectual property compliance. Command to issues warning banner on Mac OS X sudo defaults write /Library/Preferences/com.apple.loginwindow LoginwindowText "Your Warning Message Here" You will be prompted for your password. Once that is complete, you can log out to see the warning banner (requires you todisable automatic login). --- ## FTC Issues Alert on Tech Support Scams URL: https://securityorb.com/ftc-issues-alert-on-tech-support-scams/ Type: post Modified: 2018-07-16 The Federal Trade Commission has released an alert on tech support scams. Scammers use pop-up messages, websites, emails, and phone calls to entice users to pay for fraudulent tech support services to repair problems that don’t exist. Users should not pay or give control of their devices to any stranger offering to fix problems. NCCIC encourages users and administrators to refer to the FTC Alert and the NCCIC Tip on Avoiding Social Engineering and Phishing Attacks for more information. If you believe you are a victim of a tech support scam, file a complaint at www.FTC.gov/complaint. --- ## Ubuntu Firewall: Basic Introduction URL: https://securityorb.com/ubuntu-firewall-basic-introduction/ Type: post Modified: 2018-07-16 This is a basic introduction to Ubuntu firewall using the terminal commands.  This tutorial requires you have administrative access to your Ubuntu system.  If you installed Ubuntu the first account created by default has administrative access via sudo.  You will need to type sudo for each command illustrated below.  The system will ask for your login password the first time (it will remember that password for about 15 minutes).  Follow the steps below to check and modify the firewall. Open a terminal window (ctrl t).  In the terminal window enter: you@ursystem:~$ sudo ufw status [sudo] password for you: Status: inactive ufw stands for uncomplicated[1] firewall.  It is a very simple interface to get you started.  All modern Linux firewalls are based on the packet filtering framework developed and maintained by the folks at netfilter.org. In the above example the firewall is not running to enable the firewall enter the command: you@ursystem:~$ sudo ufw enable Command may disrupt existing ssh connections. Proceed with operation (y|n)? y Firewall is active and enabled on system startup You have enabled your firewall try the status command again to see the results.  It reports active.  The firewall is active but you have not set any rules.  To allow ssh connections to your system enter the command: you@yoursystem:~$ sudo ufw allow ssh Rule added Rule added (v6) (note this is displayed if you are also using IP v6) You have just added ssh however you have allowed connection to port 22 from any location on the internet (using both UDP and TCP).  You have also allowed connection using IPv6.  If you are only using IPv4 delete the rule for IPv6 and harden the remaining rule to only allow tcp.  To verify the above rules created enter the status command again.  Look at the “From” column. you@yoursystem:~$ sudo ufw status Status: active To                    Action     From --                    ------     ---- 22                    ALLOW      Anywhere 22 (v6)               ALLOW      Anywhere (v6)   Notice the one command generated 2 rules.  It is best to be very specific and allow only the ip addresses you expect to connect from and the protocol to use.  In this case we want to only allow TCP and from one IP address, using IPv4.  I will delete the above rules, using the reset option. You can reset the firewall by using the reset options as follows: sudo ufw --force reset   Notice the “--force” option, this issues the command without asking for permission.  The firewall is back to defaults.  Issue “sudo ufw status” to verify. Let’s enable the firewall again only this time to one specific IP address and using the TCP protocol version 4.  To do so gather the IP address you want to ssh from and enter that IP in the command: sudo ufw allow from {your ip address in here} to any port 22 proto tcp   Enter the command for status “sudo ufw status”.  What do you see?  Even though you created a firewall rule the firewall is still disabled from the previous reset command.  Enable the firewall “sudo ufw enable” and run the status command again.  You should see the new rule you just created. This rule allows only the IP address entered in the brackets to connect to your system, via ssh. In order to modify the rules you need to list them with numbers so enter the command:   you@yoursystem:~$ sudo ufw status Status: active To                         Action      From --                         ------      ---- 22/tcp                     ALLOW       10.0.0.20   Let’s add another rule to allow connections to your systems web server.   you@yoursystem:~$ sudo ufw allow from 10.0.0.20 to any port 80 proto tcp Rule added you@yoursystem:~$ sudo ufw status Status: active To                         Action      From --                         ------      ---- 22/tcp                     ALLOW       10.0.0.20 80/tcp                     ALLOW       10.0.0.20 Now you have 2 rules.  Let’s list the rules with the associated number.  Listing rules with numbers is needed when deleting rules.   you@yoursystem:~$ sudo ufw status numbered Status: active      To                         Action      From      --                         ------      ---- [ 1] 22/tcp                     ALLOW IN    10.0.0.20 [ 2] 80/tcp                     ALLOW IN    10.0.0.20 Notice the numbers 1 and 2 in brackets, on the left before the rule.  That represents the number for that rule.   To delete the second rule enter the command: you@yoursystem:~$ sudo ufw delete 2 Deleting: allow from 10.0.0.20 to any port 80 proto tcp Proceed with operation (y|n)? y Rule deleted   UFW verified you wanted to delete rule 2 and it requested you answer yes with a y.  If you do not want to be prompted use the “--force” options as illustrated earlier.  Below is a list of other commands you can issue (copied from the man page).   ufw [--dry-run] enable|disable|reload ufw [--dry-run] default allow|deny|reject [incoming|outgoing|routed] ufw [--dry-run] logging on|off|LEVEL ufw [--dry-run] reset ufw [--dry-run] status [verbose|numbered] ufw [--dry-run] show REPORT ufw [--dry-run] [delete] [insert NUM] allow|deny|reject|limit [in|out] [log|log-all] [  PORT[/PROTOCOL] | APPNAME ] [comment COMMENT] ufw   [--dry-run]   [rule]  [delete]  [insert  NUM]  allow|deny|reject|limit  [in|out  [on  INTERFACE]] [log|log-all] [proto PROTOCOL] [from ADDRESS [port PORT | app APPNAME ]] [to ADDRESS [port PORT  |  app APPNAME ]] [comment COMMENT] ufw [--dry-run] route [delete] [insert NUM] allow|deny|reject|limit [in|out on INTERFACE] [log|log-all] [proto PROTOCOL] [from ADDRESS [port PORT | app APPNAME]] [to ADDRESS [port PORT | app APPNAME]]  [com‐ ment COMMENT] ufw [--dry-run] delete NUM ufw [--dry-run] app list|info|default|update   As you can see ufw provides a plethora of commands and options.  Let’s take the commands apart. Above you see [--dry-run] which is the option to test the command without enabling it.  The firewall can be enabled, disabled or the rules reloaded.  The default behavior of the firewall can be se with the default option.  You can set the log level to (low, medium, high or full) or turn it on of off.  Reset, resets the firewall as illustrated above.  The status command has the option numbered (illustrated above) or verbose which gives you additional information as to the behavior.  You can add comments to the rules and even specify application names.  The applications are stored in /etc/ufw/applications.d.   The show REPORT option gives you details about what the firewall is doing for example try this command: you@yoursystem:~$ sudo ufw show listening tcp: 139 * (smbd) 22 * (sshd) [ 1] allow from 10.0.0.20 to any port 22 proto tcp   445 * (smbd) tcp6: 139 * (smbd) 22 * (sshd) 445 * (smbd) udp: 137 10.0.0.255 (nmbd) 137 10.0.0.80 (nmbd) 137 * (nmbd) 138 10.0.0.255 (nmbd) 138 10.0.0.80 (nmbd) 138 * (nmbd) 37937 * (dnsmasq) 49595 * (avahi-daemon) 5353 * (avahi-daemon) 631 * (cups-browsed) udp6: 46295 * (avahi-daemon) 5353 * (avahi-daemon)   Notice the firewall is listening on so many ports can you tell if this is a server or desktop os?  It’s most likely a desktop OS since it is listening on the Windows ports.   In conclusion ufw has many options and supports a simple and full syntax.  I recommend using the full syntax and be very specific to open the specific port, protocol and ip addresses that need access. [1] https://help.ubuntu.com/lts/serverguide/firewall.html.en --- ## Macy’s and Bloomingdale’s just announced a data breach that’s exposed sensitive customer info URL: https://securityorb.com/macys-and-bloomingdales-just-announced-a-data-breach-thats-exposed-sensitive-customer-info/ Type: post Modified: 2018-07-13 Here’s what you need to know about the Macy’s and Bloomingdale’s breach Macy’s and Bloomingdale’s (both owned by parent company Macy’s, Inc.) recently sent letters to some of their online customers confirming the retailer had discovered a cybersecurity threat to its systems on June 11, 2018. According to the letters, “an unauthorized third party, from April 26, 2018, through June 12, 2018, used valid customer usernames and passwords to log in to customer online profiles.” Hackers were able to access users' first and last names, addresses, phone numbers, email addresses, birth dates, and debit and credit card numbers with expiration dates, Macy's said. See this article for more information. How to protect your info after this breach To support you during this time, we've put together some guidelines to help you protect yourself: Change your Macys.com or Bloomingdales.com password(s). Monitor your credit/debit card accounts for any suspicious activity. Update any debit/credit cards you’ve used on Macys.com or Bloomingdales.com. Check your credit report regularly to keep an eye on any unauthorized activity. --- ## SplunkLive! DC - 7/19 @ The Convention Center URL: https://securityorb.com/splunklive-dc-7-19-the-convention-center/ Type: post Modified: 2018-07-12 Our friends at Splunk are pleased to announce that Registration is Now Open for SplunkLive! Washington, D.C. on July 19.    SpunkLive! Washington D.C Date: July 19, 2018 Time: 8:00 am – 4:00 pm Location: Walter E Washington Convention Center  801 Mount Vernon Place NW Washington, DC 20001 Registration page: http://live.splunk.com/splunkliveDC-07192018 Keynote Speaker: Declan Morris, Splunk CIO Public Sector Luncheon: Special luncheon, including a panel discussion exclusively for Public Sector (government, Aerospace & Defense, Higher Education) participants Breakout Sessions & SE Presenters: The final agenda including the breakout sessions is listed below.    Agenda: Time Description 8:00am Breakfast and Registration 9:00am Turn Data into Answers with Splunk Declan Morris, CIO, Splunk Overview Track IT Ops Track Security Track Industry Track 10:45am Improve Your Velocity With Splunk Cloud Gain Real Time Insights from Your Data Using Splunk and AWS Cloud Solve Your Security Challenges with Splunk Leveraging Continuous Monitoring with Splunk to Support Compliance Requirements 11:45am Lunch 12:45pm Get More from Your Machine Data with Splunk AI Analytics Through DevOps Lifecycle Intro to Security Analytics Methods Enabling Efficient Government with Splunk 2:00pm Getting Data In Predictive, Proactive and Collaborative ML with Splunk ITSI Accelerate Incident Response Using Automation and Orchestration Keeping Agency Operations Humming with Event Analytics 3:00pm Reception — PartnerZone   --- ## Installing ClamAV on CentOS 7 URL: https://securityorb.com/installing-clamav-on-centos-7/ Type: post Modified: 2018-07-12 Referenced from Linux-Audit: To get ClamAV on CentOS installed, we have to use the EPEL repository (Extra Packages for Enterprise Linux). Fortunately, the Fedora project provides this with an easy installation. Unfortunately the default configuration is not properly working. In this post we collect some of the issues and required changes. Let’s start with installing the EPEL support. yum install epel-release Next step is installing all ClamAV components. yum install clamav-server clamav-data clamav-update clamav-filesystem clamav clamav-scanner-systemd clamav-devel clamav-lib clamav-server-systemd   Installing ClamAV with help of EPEL repository Configure SELinux for ClamAV If you are using ClamAV on CentOS, together with SELinux, we should configure it a little bit. This way ClamAV can access all files on disk, and update its data definition files. Enable antivirus_can_scan_system: setsebool -P antivirus_can_scan_system 1   Configuration of Clam daemon Copy a the clamd.conf template, in case you don’t have a configuration file yet. cp /usr/share/clamav/template/clamd.conf /etc/clamd.d/clamd.conf sed -i ‘/^Example/d’ /etc/clamd.d/clamd.conf Change /etc/clamd.d/clamd.conf file and define if you want to run the scanner as root, or a specific user. Check your /etc/passwd file for the related Clam user. Change the following two options: User clamscan LocalSocket /var/run/clamd./clamd.sock Enable Freshclam Freshclam helps with keeping the database of ClamAV up-to-date. First delete the related “Example” line from /etc/freshclam.conf. cp /etc/freshclam.conf /etc/freshclam.conf.bak sed -i ‘/^Example/d’ /etc/freshclam.conf Check the other options in the file, and change it to your preferred settings. Missing systemd service file We didn’t get a systemd service file, so creating a quick file here. The process should be forking itself and start freshclam in daemon mode. In this case we configure it to check 4 times a day for new files. Create a new file /usr/lib/systemd/system/clam-freshclam.service # Run the freshclam as daemon [Unit] Description = freshclam scanner After = network.target   [Service] Type = forking ExecStart = /usr/bin/freshclam -d -c 4 Restart = on-failure PrivateTmp = true   [Install] WantedBy=multi-user.target Now enable and start the service. systemctl enable clam-freshclam.service   systemctl start clam-freshclam.service Check the status. [root@centos7 system]# systemctl status clam-freshclam.service clam-freshclam.service - freshclam scanner Loaded: loaded (/usr/lib/systemd/system/clam-freshclam.service; enabled) Active: active (running) since Thu 2015-06-11 11:09:24 CEST; 1s ago Process: 3158 ExecStart=/usr/bin/freshclam -d -c 4 (code=exited, status=0/SUCCESS) Main PID: 3159 (freshclam) CGroup: /system.slice/clam-freshclam.service └─3159 /usr/bin/freshclam -d -c 4 Change service files By default, the service files seem to be messy and not working. These are the files bundled: [root@centos7 system]# ls -l /usr/lib/systemd/system/clam* -rw-r--r--. 1 root root 136 Apr 29 20:38 /usr/lib/systemd/system/clamd@scan.service -rw-r--r--. 1 root root 231 Apr 29 20:38 /usr/lib/systemd/system/clamd@.service When enabling the clamd service, we would see something like this: [root@centos7 system]# systemctl enable /usr/lib/systemd/system/clamd@.service Failed to issue method call: Unit /usr/lib/systemd/system/clamd@.service does not exist. So let’s fix it. First rename the /usr/lib/systemd/system/clamd@.service file. Rename the clamd@ file. mv /usr/lib/systemd/system/clamd@.service /usr/lib/systemd/system/clamd.service Now we have to change the clamd@scan service as well, as it refers to a non-existing file now. Change this line in /usr/lib/systemd/system/clamd@scan.service and remove the @ sign. .include /lib/systemd/system/clamd@.service Next step is changing the clamd service file /usr/lib/systemd/system/clamd.service [Unit] Description = clamd scanner daemon After = syslog.target nss-lookup.target network.target   [Service] Type = simple ExecStart = /usr/sbin/clamd -c /etc/clamd.d/clamd.conf --foreground=yes Restart = on-failure PrivateTmp = true   [Install] WantedBy=multi-user.target Move into the directory. cd /usr/lib/systemd/system Start all services. [root@centos7 system]# systemctl enable clamd.service [root@centos7 system]# systemctl enable clamd@scan.service [root@centos7 system]# systemctl start clamd.service [root@centos7 system]# systemctl start clamd@scan.service Checking the status With all these changes, ClamAV on CentOS 7 should be running now. The easiest way to check, is using the ps command and see if freshclam and clamd are running. Useful resources for debugging are the systemctl status command, followed by the service. Then there is logging in /var/log/messages, which usually will reveal when and why something is (not) running.   --- ## Burp to Brute Force a Login Page URL: https://securityorb.com/burp-to-brute-force-a-login-page/ Type: post Modified: 2018-07-12 Using Burp to Brute Force a Login Page Authentication lies at the heart of an application’s protection against unauthorized access. If an attacker is able to break an application's authentication function then they may be able to own the entire application. The following tutorial demonstrates a technique to bypass authentication using a simulated login page from the “Mutillidae” training tool. The version of “Mutillidae” we are using is taken from OWASP’s Broken Web Application Project. Find out how to download, install and use this project. First, ensure that Burp is correctly configured with your browser. In the Burp Proxy tab, ensure "Intercept is off" and visit the login page of the application you are testing in your browser. Return to Burp. In the Proxy "Intercept" tab, ensure "Intercept is on". In your browser enter some arbitrary details in to the login page and submit the request. The captured request can be viewed in the Proxy "Intercept" tab. Right click on the request to bring up the context menu. Then click "Send to Intruder". Note: You can also send requests to the Intruder via the context menu in any location where HTTP requests are shown, such as the site map or Proxy history. Go to the Intruder "Positions" tab. Clear the pre-set payload positions by using the "Clear" button on the right of the request editor. Add the "username" and "password" parameter values as positions by highlighting them and using the "Add" button. Change the attack to "Cluster bomb" using the "Attack type" drop down menu. Go to the "Payloads" tab. In the "Payload sets" settings, ensure "Payload set" is "1" and "Payload type" is set to "Simple list". In the "Payload options" settings enter some possible usernames. You can do this manually or use a custom or pre-set payload list. Next, in the "Payload Sets" options, change "Payload" set to "2". In the "Payload options" settings enter some possible passwords. You can do this manually or using a custom or pre-set list. Click the "Start attack" button. In the "Intruder attack" window you can sort the results using the column headers. In this example sort by "Length" and by "Status". The table now provides us with some interesting results for further investigation. By viewing the response in the attack window we can see that request 118 is logged in as "admin". To confirm that the brute force attack has been successful, use the gathered information (username and password) on the web application's login page. Account Lock Out In some instances, brute forcing a login page may result in an application locking out the user account. This could be the due to a lock out policy based on a certain number of bad login attempts etc. Although designed to protect the account, such policies can often give rise to further vulnerabilities. A malicious user may be able to lock out multiple accounts, denying access to a system. In addition, a locked out account may cause variances in the behavior of the application, this behavior should be explored and potentially exploited. Verbose Failure Messages Where a login requires a username and password, as above, an application might respond to a failed login attempt by indicating whether the reason for the failure was an unrecognized username or incorrect password. In this instance, you can use an automated attack to iterate through a large list of common usernames to enumerate which ones are valid. A list of enumerated usernames can be used as the basis for various subsequent attacks, including password guessing, attacks on user data or sessions, or social engineering. Scanning a login page In addition to manual testing techniques, Burp Scanner can be used to find a variety of authentication and session management vulnerabilities. In this example, the Scanner was able to enumerate a variety of issues that could help an attacker break the authentication and session management of the web application. Refernced from - https://support.portswigger.net/customer/portal/articles/1964020-using-burp-to-brute-force-a-login-page       --- ## Accessing and Installing GSM Community Edition - OpenVAS URL: https://securityorb.com/accessing-and-installing-gsm-community-edition-openvas/ Type: post Modified: 2018-07-12 Version: 4.2.17 (includes OpenVAS-9) Download: https://dl.greenbone.net/download/VM/gsm_ce_4.2.17.iso (350 MByte) sha256sum: a4490e1c1d5b93c52b67eb533da8aa0ebe435551f89c8cea1619e6a772733a97 Compatibility: VirtualBox, ESXi, Hyper-V Minimum requirements: 2 CPU Cores, 2 GByte RAM The GSM Community Edition is a derivate of the GSM ONE and allows a quick and easy option on Windows, Linux or Mac to give the solution a trial. No particular know-how is needed. In contrast to the commercial solution the Community Feed instead of the Greenbone Security Feed is used. Also some management functions like for TLS certificates are not included. Feed updates happen on a regular basis, but the system itself can not be updated. The commercial version can be updated seamless and also includes access to the Greenbone Support. The Community Edition as well as the GSM ONE are designed for use with a laptop. The full feature set for a vulnerability management process (schedules, alarms, sensors) are only available with the bigger GSM models (see here for an overview) and can be obtained from Greenbone as an evaluation unit. Startup Community Edition: Create a virtual image: VirtualBox by hand via "New": Type: Linux Version: Other Linux (64bit) Memory: 2048M Harddisk: 9G CPUs: 2 Create a new hard disk for the virtual machine. Take care that the network connection works inside-out and outside-in: The system needs access to the internet for the setup. For using the systems' web interface you need to access the system from where your web browser runs. Audio, USB and Floppy should be disabled. Now choose the downloaded ISO image as medium for the CD drive and start the virtual machine. Hyper-V by hand via "New - Virtual Computer": Generation: Generation 1 Startup memory: 2048MB Use Dynamic Memory: deactivate Network: Select a connection that has access to the Internet. The system needs access to the internet for the setup. For using the systems' web interface you need to access the system from where your web browser runs. Virtual hard disk: create an new, with an minimum of 9GB Installation Options: Now choose the downloaded iso image as medium. After saving, change the number of processors to 2 ESXi / VMWare: Basically follow the hints as in "VirtualBox by hand". In the menu choose the option "Setup" and confirm that the hard disk can be overwritten. The installation process will now run for a while. You will be asked for a username and password for the administrative account. Notice this account because there will be no other way to administrate the system. Follow the instructions up to the reboot. The system will automatically reboot a second time. As soon as the login prompt "Welcome to Greenbone OS" appears, log in with the previously created administration account. You now enter the setup wizard which guides you through the final steps: Web-User: Creation of an administration account for the web interface. There, you can later create more account as needed. Greenbone Subscription Key: In case you have a received an evaluation key from Greenbone, you can now upload it. If you don't have one, the system will use the Greenbone Community Feed instead of the Greenbone Security Feed. It is possible to upload a evaluation key any time later and change the feed. Download Feed: Without a feed you can not do any scans and the SecInfo section remains empty. So the download is highly recommended, but requires internet access. The feed update now runs in the background and you are on the main menu of the administration. Via "About" you can have a look at the key properties of your setup, especially the address of the web interface and whether there still runs the Feed update as a system operation. Log in to the web interface with the web administrator account. During the installation a self-signed TLS certificate was created. Your browser will regard it insecure and you need to tell your browser to accept it as an exception. Only after the feed update completed there will be all information in the SecInfo area and first scans possible. This could take half an hour or even longer. Documentation and guides are available at the Greenbone TechDoc Portal. However, the user interface is self-explaining. Just give it a start. The wizard will help you to create and run your first scan task. Please note: Shutting down the virtual machine should only be done via the menu Maintenance->Power to ensure that important system processes like the Feed update are not interrupted. Copyright, licenses and sources: The Feed and Greenbone OS consists of various components with various Copyrights and (Open Source) Licenses. In essence the product can be used for any purpose but for re-distribution the conditions of the licenses have to be considered. Details are summarized in the License Information. There, you will also find the offer for source code access according to GNU GPL. --- ## Reset the admin password in OpenVAS URL: https://securityorb.com/reset-the-admin-password-in-openvas/ Type: post Modified: 2018-07-12 Try this: openvasmd --user=admin --new-password=new_password Or you can create a new administrative account with : openvasad -c add_user -u your_new_login_here -r Admin Then use this account to change the default admin’s password. --- ## 5 pen testing rules of engagement: What to consider while performing Penetration testing URL: https://securityorb.com/5-pen-testing-rules-of-engagement-what-to-consider-while-performing-penetration-testing/ Type: post Modified: 2018-07-11 By Fatema Patrawala of Packt Publishing - https://hub.packtpub.com/author/fatemap/ Penetration testing and ethical hacking are proactive ways of testing web applications by performing attacks that are similar to a real attack that could occur on any given day. They are executed in a controlled way with the objective of finding as many security flaws as possible and to provide feedback on how to mitigate the risks posed by such flaws. Security-conscious corporations have implemented integrated penetration testing, vulnerability assessments, and source code reviews in their software development cycle. Thus, when they release a new application, it has already been through various stages of testing and remediation. When planning to execute a penetration testing project, be it for a client as a professional penetration tester or as part of a company’s internal security team, there are aspects that always need to be considered before starting the engagement. This article is an excerpt from the book Web Penetration testing with Kali Linux – Third Edition, written by Gilberto Najera-Gutierrez, Juned Ahmed Ansari. Rules of Engagement for Pen testing Rules of Engagement (RoE) is a document that deals with the manner in which the penetration test is to be conducted. Some of the directives that should be clearly spelled out in RoE before you start the penetration test are as follows: The type and scope of testing Client contact details Client IT team notifications Sensitive data handling Status meeting and reports Type and scope of Penetration testing The type of testing can be black box, white box, or an intermediate gray box, depending on how the engagement is performed and the amount of information shared with the testing team. There are things that can and cannot be done in each type of testing. With black box testing, the testing team works from the view of an attacker who is external to the organization, as the penetration tester starts from scratch and tries to identify the network map, the defense mechanisms implemented, the internet-facing websites and services, and so on. Even though this approach may be more realistic in simulating an external attacker, you need to consider that such information may be easily gathered from public sources or that the attacker may be a disgruntled employee or ex-employee who already possess it. Thus, it may be a waste of time and money to take a black box approach if, for example, the target is an internal application meant to be used by employees only. White box testing is where the testing team is provided with all of the available information about the targets, sometimes even including the source code of the applications, so that little or no time is spent on reconnaissance and scanning. A gray box test then would be when partial information, such as URLs of applications, user-level documentation, and/or user accounts are provided to the testing team. Gray box testing is especially useful when testing web applications, as the main objective is to find vulnerabilities within the application itself, not in the hosting server or network. Penetration testers can work with user accounts to adopt the point of view of a malicious user or an attacker that gained access through social engineering. When deciding on the scope of testing, the client along with the testing team need to evaluate what information is valuable and necessary to be protected, and based on that, determine which applications/networks need to be tested and with what degree of access to the information. Client contact details We can agree that even when we take all of the necessary precautions when conducting tests, at times the testing can go wrong because it involves making computers do nasty stuff. Having the right contact information on the client-side really helps. A penetration test is often seen turning into a Denial-of-Service (DoS) attack. The technical team on the client side should be available 24/7 in case a computer goes down and a hard reset is needed to bring it back online. Penetration testing web applications has the advantage that it can be done in an environment that has been specially built for that purpose, allowing the testers to reduce the risk of negatively affecting the client’s productive assets. Client IT team notifications Penetration tests are also used as a means to check the readiness of the support staff in responding to incidents and intrusion attempts. You should discuss this with the client whether it is an announced or unannounced test. If it’s an announced test, make sure that you inform the client of the time and date, as well as the source IP addresses from where the testing (attack) will be done, in order to avoid any real intrusion attempts being missed by their IT security team. If it’s an unannounced test, discuss with the client what will happen if the test is blocked by an automated system or network administrator. Does the test end there, or do you continue testing? It all depends on the aim of the test, whether it’s conducted to test the security of the infrastructure or to check the response of the network security and incident handling team. Even if you are conducting an unannounced test, make sure that someone in the escalation matrix knows about the time and date of the test. Web application penetration tests are usually announced. Sensitive data handling During test preparation and execution, the testing team will be provided with and may also find sensitive information about the company, the system, and/or its users. Sensitive data handling needs special attention in the RoE and proper storage and communication measures should be taken (for example, full disk encryption on the testers’ computers, encrypting reports if they are sent by email, and so on). If your client is covered under the various regulatory laws such as the Health Insurance Portability and Accountability Act (HIPAA), the Gramm-Leach-Bliley Act (GLBA), or the European data privacy laws, only authorized personnel should be able to view personal user data. Status meeting and reports Communication is key for a successful penetration test. Regular meetings should be scheduled between the testing team and the client organization and routine status reports issued by the testing team. The testing team should present how far they have reached and what vulnerabilities have been found up to that point. The client organization should also confirm whether their detection systems have triggered any alerts resulting from the penetration attempt. If a web server is being tested and a WAF was deployed, it should have logged and blocked attack attempts. As a best practice, the testing team should also document the time when the test was conducted. This will help the security team in correlating the logs with the penetration tests. --- ## OWASP Top 10 Application Security Risks URL: https://securityorb.com/owasp-top-10-application-security-risks/ Type: post Modified: 2018-07-06 The OWASP Top 10 focuses on identifying the most serious risks for a broad array of organizations. For each of these risks, we provide generic information about likelihood and technical impact using the following simple ratings scheme, which is based on the OWASP Risk Rating Methodology.   A1:2017 Injection Injection flaws, such as SQL, OS, and LDAP injection occur when untrusted data is sent to an interpreter as part of a command or query. The attacker’s hostile data can trick the interpreter into executing unintended commands or accessing data without proper authorization. A2:2017 Broken Authentication Application functions related to authentication and session management are often implemented incorrectly, allowing attackers to compromise passwords, keys, or session tokens, or to exploit other implementation flaws to assume other users’ identities (temporarily or permanently). A3:2017 Sensitive Data Exposure Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data deserves extra protection such as encryption at rest or in transit, as well as special precautions when exchanged with the browser. A4:2017 XML External Entity (XXE) Many older or poorly configured XML processors evaluate external entity references within XML documents. External entities can be used to disclose internal files using the file URI handler, internal SMB file shares on unpatched Windows servers, internal port scanning, remote code execution, and denial of service attacks, such as the Billion Laughs attack. A5:2017 Broken Access Control Restrictions on what authenticated users are allowed to do are not properly enforced. Attackers can exploit these flaws to access unauthorized functionality and/or data, such as access other users' accounts, view sensitive files, modify other users’ data, change access rights, etc. A6:2017 Security Misconfiguration Security misconfiguration is the most common issue in the data, which is due in part to manual or ad hoc configuration (or not configuring at all), insecure default configurations, open S3 buckets, misconfigured HTTP headers, error messages containing sensitive information, not patching or upgrading systems, frameworks, dependencies, and components in a timely fashion (or at all). A7:2017 Cross-Site Scripting (XSS) XSS flaws occur whenever an application includes untrusted data in a new web page without proper validation or escaping, or updates an existing web page with user supplied data using a browser API that can create JavaScript. XSS allows attackers to execute scripts in the victim’s browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites. A8:2017 Insecure Deserialization Insecure deserialization flaws occur when an application receives hostile serialized objects. Insecure deserialization leads to remote code execution. Even if deserialization flaws do not result in remote code execution, serialized objects can be replayed, tampered or deleted to spoof users, conduct injection attacks, and elevate privileges. A9:2017 Using Components with Known Vulnerabilities Components, such as libraries, frameworks, and other software modules, run with the same privileges as the application. If a vulnerable component is exploited, such an attack can facilitate serious data loss or server takeover. Applications and APIs using components with known vulnerabilities may undermine application defenses and enable various attacks and impacts. A10:2017 Insufficient Logging & Monitoring Insufficient logging and monitoring, coupled with missing or ineffective integration with incident response allows attackers to further attack systems, maintain persistence, pivot to more systems, and tamper, extract or destroy data. Most breach studies show time to detect a breach is over 200 days, typically detected by external parties rather than internal processes or monitoring. --- ## OpenVAS & Metasploit Integration - How to Use OpenVAS in Metasploit URL: https://securityorb.com/openvas-metasploit-integration-how-to-use-openvas-in-metasploit/ Type: post Modified: 2018-07-06 Recently during an engagement, I was able to use OpenVAS in Metasploit to scan a host and conduct a test to see if the system was indeed exploitable.  Here is how it was done below: Issue command msfconsole to open Metasploit console. msfconsole To use the OpenVAS integration you need to load the OpenVAS module within msfconsole. Do this by running the command load openvas. Start by connecting to the server using the command openvas_connect. openvas_connect username password 127.0.0.1 9390 To create a target to scan use the command openvas_target_create. If you want spaces in the name or comment then make sure you place quotations around them. openvas_target_create "Local Machine" 192.168.70.128 "My Local Machine"  Create a task by specifying a target and a configuration. Use the command openvas_config_list to get a list of configurations and the command openvas_target_list to get a list of targets. openvas_config_list openvas_task_create "Local Scan" "Scan My Local Machine" 0 1  Start the task with openvas_task_start and watch the progress using openvas_task_list. openvas_task_start 0 openvas_task_list openvas_task_list  Once the scan is finished, the progress is -1, list the available reports using openvas_report_list. openvas_report_list   If this was helpful please let me know. --- ## WordPress 4.9.7 Security and Maintenance Release URL: https://securityorb.com/wordpress-4-9-7-security-and-maintenance-release/ Type: post Modified: 2018-07-05 WordPress 4.9.7 is now available. This is a security and maintenance release for all versions since WordPress 3.7. We strongly encourage you to update your sites immediately. WordPress versions 4.9.6 and earlier are affected by a media issue that could potentially allow a user with certain capabilities to attempt to delete files outside the uploads directory. Thank you to Slavco for reporting the original issue and Matt Barry for reporting related issues. Seventeen other bugs were fixed in WordPress 4.9.7. Particularly of note were: Taxonomy: Improve cache handling for term queries. Posts, Post Types: Clear post password cookie when logging out. Widgets: Allow basic HTML tags in sidebar descriptions on Widgets admin screen. Community Events Dashboard: Always show the nearest WordCamp if one is coming up, even if there are multiple Meetups happening first. Privacy: Make sure default privacy policy content does not cause a fatal error when flushing rewrite rules outside of the admin context. Download WordPress 4.9.7 or venture over to Dashboard → Updates and click “Update Now.” Sites that support automatic background updates are already beginning to update automatically. The previously scheduled 4.9.7 is now referred to as 4.9.8, and will follow the release schedule posted yesterday. Thank you to everyone who contributed to WordPress 4.9.7: --- ## SummerCon 2018 URL: https://securityorb.com/summercon-2018/ Type: post Modified: 2018-07-02 Summercon is one of the oldest hacker conventions, and the longest running such conference in America. It helped set a precedent for more modern "cons" such as H.O.P.E. and DEF CON, although it has remained smaller and more personal. SummerCon has been hosted in cities such as Pittsburgh, St. Louis, Atlanta, New York, Washington, D.C., Austin, Las Vegas, and Amsterdam. [maxgallery id="9655"]   --- ## SummerCon 2018 Recap URL: https://securityorb.com/summercon-2018-recap/ Type: post Modified: 2018-06-30 SummerCon 2018 was another success this year in New York.  Being one of the oldest hacking conventions in America we always like the opportunity to attend and enjoy the vibe. Armed with some great speaker and topic below, this event kept the attention of the attendees. https://securityorb.com/Videos/summercon2018.mov This Year in Crypto Nick Sullivan Sometime in the last year, the word “crypto” became a dirty word. While linguists have been focused on debating abbreviation cannibalism in adjacent tech circles, it has also been a quietly interesting year for cryptography. From new theoretical advances in post-quantum cryptography and zero-knowledge proofs, to the discovery of efficient trilinear maps, to the rise of secure transport protocols like TLS 1.3 and secure group messaging proposals like MLS, cryptography nerds have a lot to talk about. This year has also been a challenging year for cryptographic technologies. Vulnerabilities in the software that supports cryptography in the Desktop version of Signal and GPG Tools and the surprising ROBOT vulnerability continued to highlight the fact that "secure" protocols are not secure without secure implementations. In the geopolitical realm, encryption issues have flared up, culminating with Russia’s attempts to block Telegram and major cloud companies deciding to disable domain fronting. This talk will attempt to distill the last year in crypto down to a short talk. Who X-Rays the X-Rays – A deeper dive into Medical Device Security Richard Oak The healthcare industry has (finally) woken up to cyber-security. Hospitals are starting to demand cyber-security in new devices and manufacturers are delivering. This is great news for the future – but what about the past and the present? In this talk we examine the current state of cyber security in healthcare. We look at the protocols that are used to transfer information round the networks, and the devices themselves to see how well they would stand up to a modern cyber-attack. Hack you a Koober Netty for Great Good! Dino Dai Zovi Do you want a koober netty? Or do you already have one? You may even already have many koober netties (pronounced: "kubernetes"). Either way, it turns out that they can be used for more things than just running your Linux containers in the cloud. They can also be used to give attackers access to thousands more computers than just the one running the container that the attacker got a shell in. How cool is that? In this talk, we'll discuss all of the magical ways that Kubernetes can give attackers access to your entire cluster and cloud environments. We'll also discuss some ways that it can be made to not do this if making attackers sad is your thing. Blackhat Ethereum Ryan Stortz and Jay Little In the blockchain, there are no secrets. Every transaction is logged and everyone has a copy of all of the code. Nearly all of this code can only be analyzed through reverse engineering. Over the past year, we've seen enterprising hackers use flaws in smart contracts to whisk away millions. This was made possible thanks to Ethereum, the technology that powers cryptocats, and Solidity, a high level language that describes Ethereum's Turing complete smart contracts. This talk will introduce smart contract security, present common vulnerability classes, and demonstrate how to reverse engineer EVM code to identify these vulnerabilities. The talk will also present tools to support vulnerability discovery in EVM code and Solidity. Exploiting the Exploiters: Hunting Fraud in Telecom Networks Vlad Wolstencroft Lurking underneath our increasingly mobile-connected world is a growing fraud problem -- one which exposes user data to security and privacy risks. Interconnect bypass fraud has been an issue within telecom networks ever since mobile phones were allowed to roam between countries. GSM Gateways, also known as "simboxes," are one of the primary keys for criminals to unlock the ability to conduct fraud on these networks. In this talk, we'll explore how carriers and aggregators globally send your SMS and voice traffic through these IoT-based devices, which are not subject to any of the security or privacy requirements of critical infrastructure. However, these devices still handle our critical data -- both offering a profit opportunity for fraudsters as well as creating a privacy nightmare for mobile subscribers. Then, we'll delve into the defensive devices dedicated to heuristic measurements, detection, and destruction of GSM gateways, and the retaliatory countermeasures employed to avoid detection, simulate real subscriber behavior, and outsmart the mobile network operators. Next, we'll explore multiple GSM Gateway vendors and the equipment they provide for legitimate -- sometimes less-than-legitimate -- purposes. We'll examine how these systems operate and what actual security controls they provide for our voice and signaling data. While we expect stringent controls when data flows through network operators, can we hold the same expectation for these network elements operated in someone's basement? Finally, I will propose new techniques to detect, map, and disable these devices remotely, as well as track the operators of these systems -- without the pitfalls of relying on heuristic measurements. With these methods, we can begin disrupting the $6b in fraudulent revenue running on the backs of flawed and vulnerable devices. The New Hotness – Hunting for Code Similarity at Scale Juan Andres Guerrero-Saade Researching digital espionage involves a steep and unforgiving learning curve. Techniques come in waves, some more promising than others. Be it proprietary sandboxes, YARA retrohunting, passiveDNS analysis, or malware investigation platforms. Entire companies and niche industries have spawned to help researchers further their hunting at scale. The new hotness is code similarity analysis. By honing in on the particularities of the malware developer's coding conventions and setup, and their lazy reuse of code, researchers can identify clusters of shared activity. At scale, this technique yields fascinating results in otherwise unattributable cases. However, it has also proven a treacherous and uncertain technique, as fringe cases require manual analysis to avoid silly mistakes. And don't forget, threat hunting involves a puzzle that fights back. Just as we are testing and building up this new technique, adversaries have already begun to subvert its promise and turn it against us. Let's discuss the secrets and intricacies of this New Hotness. REVERSE ENGINEERING WINDOWS DEFENDER ANTIVIRUS Alexei Bulazel Windows Defender Antivirus' MpEngine.dll implements the core of Defender's functionality in an enormous ~11 MB, 30,000+ function DLL. Based on months of personal research time spent reverse engineering Defender, I'll cover my findings on Defender's dynamic analysis systems, custom tooling that I built to enable my analysis, and various ways that malicious code can give Defender trouble. Leave your comments if you attended the event.   --- ## Web Applications and the Need to Test Them URL: https://securityorb.com/web-applications-and-the-need-to-test-them/ Type: post Modified: 2018-06-29 Web application or often referred to as web app is a program that performs a specific task by using a web browser as the interface or client in a server-client environment.  Some common type of web applications you may be already familiar with can be as simple as a chat board, word processor or an online spreadsheet to as advanced as a project management tool or a point-of-sale program to name a few. What make using web applications so desirable to many organizations is that it lightens the developer of the responsibility of building a client for a specific type of computer or a specific operating system.  Prior to web applications, organizations would have to create a client that would operate on a Windows-Based system, Mac-Based system as well as a Linux-based system.  At times different operating systems with in the same family would require a different client implementation for example a Windows 7 version and a Windows XP version. Since web apps operates using a web browser such as Firefox, Safari or Internet Explorer anyone can access the application as long as they have internet access.  For the most part any Internet connected device should be able to access the intended web app though some applications require a specific Web browser to operate correctly at times. I was asked once during a class I was teaching, “Prof. Charles, what is the difference between a website and a web app?”  My response mainly stated, a website’s main purpose and function is to provide information to the end user such as http://foxnews.com and http://cnn.com while web apps primary function or purpose is to allow the end user to perform actions such as webmail and online timesheets. The security issues associated with web apps are that they are connected via the web and anyone can potentially access them.  So testing them during the development stage, before they are deployed as well as when they are in production is paramount to the security of the application, users and the organization. From all indications the trend of increasing use of web applications will continue, creating a bigger landscape for potential application security problems.  In fact, data from a  web application vulnerability report from 2017 found vulnerabilities in every web application that was analyzed, furthermore, 58% of the web apps that were analyzed had at least one high-severity vulnerability. The Equifax incident that compromised the personal data of over 143 million Americans is a prime example of what can go wrong when web application security is not continually tested and fails. There are three main types of application security testing (AST) that are performed against web apps.  Each tool tackle the issue of securing web apps from a different perspectives.  These three approaches are: Static Application Security Testing (SAST) searches for known patterns of vulnerabilities and defects in the source code. Dynamic Application Security Testing (DAST) use known types of attacks against a running instance of the software in production to determine if the software is vulnerable. Interactive Application Security Testing (IAST) is an emerging approach that combines static and dynamic techniques to improve testing. In my next posting, I will discuss SAST, DAST and IAST in detail. --- ## WebGoat 8: An intentionally Insecure Web Application for WebApp Testing URL: https://securityorb.com/webgoat-8-an-intentionally-insecure-web-application-for-webapp-testing/ Type: post Modified: 2018-06-26 As an instructor, from time to time to teach a concept, I need to perform an actual test to get my point across to the students.  Testing or hacking a live site may have some repercussions that I rather not have to deal with, so using an insecure application locally works great for me.  I recently using OWASP’s WebGoat to show a bunch of students how to test and location security issues in Web Applications. WebGoat is a deliberately insecure web application maintained by OWASP designed to teach web application security lessons. This program is a demonstration of common server-side application flaws. The exercises are intended to be used by people to learn about application security and penetration testing techniques. WARNING 1: While running this program your machine will be extremely vulnerable to attack. You should disconnect from the Internet while using this program. WebGoat's default configuration binds to localhost to minimize the exposure. WARNING 2: This program is for educational purposes only. If you attempt these techniques without authorization, you are very likely to get caught. If you are caught engaging in unauthorized hacking, most companies will fire you. Claiming that you were doing security research will not work as that is the first thing that all hackers claim. Instructions: Download Download the latest WebGoat release from: https://github.com/WebGoat/WebGoat/releases Install java -jar webgoat-server-<>.jar [--server.port=8080] [--server.address=localhost] By default WebGoat starts on port 8080 with --server.port you can specify a different port. With address you can bind it to a different address (default localhost) Access http://localhost:8080/WebGoat Let me know your experience with WebGoat. --- ## OpenVAS Terms to Know URL: https://securityorb.com/openvas-term-to-know/ Type: post Modified: 2018-06-25 OpenVAS Terms to Know Host A Host is a single system that is connected to a computer network and that may be scanned. One or many hosts form the basis of a scan target. A host is also an asset type. Any scanned or discovered host can be recorded in the asset database. Hosts in scan targets and in scan reports are identified by their network address, either an IP address or a hostname. Quality of Detection (QoD) The Quality of Detection (QoD) is a value between 0% and 100% describing the reliability of the executed vulnerability detection or product detection. This concept also solves the challenge of potential vulnerabilities. Such are always recorded and kept in the results database but are only visible on demand. While the QoD range allows to express the quality quite fine-grained, in fact most of the test routines use a standard methodology. Therefore QoD Types are associate with a QoD value. The current list of types might be extended over time. QoD QoD Type Description 100% exploit The detection happened via an exploit and therefore is fully verified. 99% remote_vul Remote active checks (code execution, traversal attack, sql injection etc.) where the response clearly shows the presence of the vulnerability. 98% remote_app Remote active checks (code execution, traversal attack, sql injection etc.) where the response clearly shows the presence of the vulnerable application. 97% package Authenticated package-based checks for Linux(oid) systems. 97% registry Authenticated registry-based checks for Windows systems. 95% remote_active Remote active checks (code execution, traversal attack, sql injection etc.) where the response shows the likely presence of the vulnerable application or of the vulnerability. “Likely” means that only rare circumstances are possible where the detection would be wrong. 80% remote_banner Remote banner check of applications that offer patch level in version. Many proprietary products do so. 80% executable_version Authenticated executable version checks for Linux(oid) or Windows systems where applications offer patch level in version. 75% This value was assigned to any pre-qod results during system migration. However, some NVTs eventually might own this value for some reason. 70% remote_analysis Remote checks that do some analysis but which are not always fully reliable. 50% remote_probe Remote checks where intermediate systems such as firewalls might pretend correct detection so that it is actually not clear whether the application itself answered. This can happen for example for non-TLS connections. 30% remote_banner_unreliable Remote banner checks of applications that don’t offer patch level in version identification. For example, this is the case for many Open Source products due to backport patches. 30% executable_version_unreliable Authenticated executable version checks for Linux(oid) systems where applications don’t offer patch level in version identification. 1% general_note General note on potential vulnerability without finding any present application. The value of 70% is the default minimum used for the default filtering to display the results in the reports. Severity The Severity is a value between 0.0 (no severity) and 10.0 (highest severity) and expresses also a Severity Class (None, Low, Medium or High). This concept is based on CVSS but is applied also where no full CVSS Base Vector is available. For example, arbitrary values in that range are applied for Overrides and used by OSP scanners even without a vector definition. Comparison, weighting, prioritisation is possible of any scan results or NVTs because the severity concept is strictly applied across the entire system. Not a single severity is just expressed as “High” for example. Any new NVT is assigned with a full CVSS vector even if CVE does not offer one and any results of OSP scanners is assigned a adequate severity value even if the respective scanner uses a different severity scheme. The severity classes None, Low, Medium and High are defined by sub-ranges of the main range 0.0-10.0. Users can select to use different classifications. The default is the NVD classification which is the most commonly used one. Scan results are assigned a severity while achieved. The severity of the related NVT may change over time though. Users can select Dynamic Severity to let the system always use the most current severity of NVTs for the results. Solution Type This information shows possible solutions for the remediation of the vulnerability. Currently three different variants are available: Workaround: Information is available about a configuration or specific deployment scenario that can be used to avoid exposure to the vulnerability. There may be none, one, or more workarounds available. This is typically the “first line of defense” against a new vulnerability before a mitigation or vendor fix has been issued or even discovered. Mitigation: Information is available about a configuration or deployment scenario that helps to reduce the risk of the vulnerability but that does not resolve the vulnerability on the affected product. Mitigations may include using devices or access controls external to the affected product. Mitigations may or may not be issued by the original author of the affected product, and they may or may not be officially sanctioned by the document producer. Vendor-Fix: Information is available about an official fix that is issued by the original author of the affected product. Unless otherwise noted, it is assumed that this fix fully resolves the vulnerability. None-Available: Currently there is no fix available. Information should contain details about why there is no fix. WillNotFix: There is no fix for the vulnerability and there never will be one. This is often the case when a product has been orphaned, end-of-life, or otherwise deprecated. Information should contain details about why there will be no fix issued. --- ## OpenVAS Authenticated Scan using Local Security Checks URL: https://securityorb.com/openvas-authenticated-scan-using-local-security-checks/ Type: post Modified: 2018-06-23 An authenticated scan may provide more vulnerability details on the scanned system. During an authenticated scan the target is both scanned from the outside via the network and from the inside via a valid user login. During an authenticated scan OpenVAS logs in to the target system in order to run local security checks (LSC). The scan therefore requires prior setup of user credentials. These credentials are used to authenticate to different services on the target system. In some circumstances the results could be limited by the permissions of the user account. The NVTs in the corresponding NVT families (local security checks) will only be executed if the OpenVAS was able to log in to the target system. The local security check NVTs in the resulting scan are minimally invasive. OpenVAS only determines the risk level but does not introduce any changes on the target system. However the login by OpenVAS is probably being logged by the target system. OpenVAS can use different credentials based on the nature of the target. However, the most important ones are: SMB On Windows systems OpenVAS can check the patch level and locally installed software such as Adobe Acrobat Reader or the Java suite. SSH This access is used to check the patch level on UNIX and Linux systems. ESXi This access is used for testing of VMWare ESXi servers locally. SNMP Network components like routers and switches may be tested via SNMP.   Pros and Cons of Authenticated Scans The extent and success of the testing routines for authenticated scans depend heavily on the permissions of the account used. On Linux systems an unprivileged user is sufficient and may access most interesting information while especially on Windows systems unprivileged users are very restricted and administrative users provide more results. An unprivileged user does not have access to the Windows registry, the Windows system folder \windows, which contains the information on updates and patchlevels, etc. Local security checks are the most gentle method to scan for vulnerability details. While remote security checks try to be least invasive as well, they might have some impact. Simply stated an authenticated scan is similar to a Whitebox approach. The OpenVAS has access to prior information and may access the target from within. Especially the registry, software versions and patchlevel are accessible. A remote scan is similar to a Blackbox approach. Here the OpenVAS uses the same techniques and protocols as a potential attacker to access the target from the outside. The only information available was collected by the OpenVAS itself. During the test the OpenVAS may provoke malfunctions to extract any available information on the used software. The scanner might for example send a malformed request to a service to trigger a response containing further information on the deployed product. During a remote scan using the scan configuration Full and Fast all remote checks are safe. The used NVTs might have some invasive components but none of the used NVTs try to trigger a defect of malfunction in the target (see example below). This is ensured by the scan preference safe_checks=yes in the scan configuration. All NVTs with very invasive components or which might trigger a denial of service (DoS) are automatically excluded from the test. Referenced from http://docs.greenbone.net --- ## Using Metasploit to Conduct NMAP Scans URL: https://securityorb.com/using-metasploit-to-conduct-nmap-scans/ Type: post Modified: 2018-06-20 Using Metasploit and nmap together as been a useful technique for me during some of my engagements.  Below are the steps I take to implement that task. Start metasploit by issuing the following command: msfconsole Verify the status of the database by issuing the following command: db_status Run NMAP from inside msfconsole and save the output into the MetaSploit database. db_nmap -v -sV host_or_network_to_scan db_nmap -v -sV 192.168.1.1 (Single Host) db_nmap -v -sV 192.168.1.0/24 (Network Range) To list all the remote hosts discovered during your nmap scan issue command: Hosts To add the hosts to the list of remote targets issue command: hosts –R To list all of the available targets issue command: show targets You can search for exploits using the “search” keywords below: search type:exploit search CVE-XXXX-XXXX search cve:2014 search name:wordpress If you found this to be useful, please leave a comment. --- ## Metaspolit – msfconsole help command output URL: https://securityorb.com/metaspolit-msfconsole-help-command-output/ Type: post Modified: 2018-06-19 msf > help Core Commands ============= Command Description ------- ----------- ? Help menu banner Display an awesome metasploit banner cd Change the current working directory color Toggle color connect Communicate with a host exit Exit the console get Gets the value of a context-specific variable getg Gets the value of a global variable grep Grep the output of another command help Help menu history Show command history irb Drop into irb scripting mode load Load a framework plugin quit Exit the console route Route traffic through a session save Saves the active datastores sessions Dump session listings and display information about sessions set Sets a context-specific variable to a value setg Sets a global variable to a value sleep Do nothing for the specified number of seconds spool Write console output into a file as well the screen threads View and manipulate background threads unload Unload a framework plugin unset Unsets one or more context-specific variables unsetg Unsets one or more global variables version Show the framework and console library version numbers Module Commands =============== Command Description ------- ----------- advanced Displays advanced options for one or more modules back Move back from the current context edit Edit the current module or a file with the preferred editor info Displays information about one or more modules loadpath Searches for and loads modules from a path options Displays global options or for one or more modules popm Pops the latest module off the stack and makes it active previous Sets the previously loaded module as the current module pushm Pushes the active or list of modules onto the module stack reload_all Reloads all modules from all defined module paths reload_lib Reload one or more library files from specified paths search Searches module names and descriptions show Displays modules of a given type, or all modules use Selects a module by name Job Commands ============ Command Description ------- ----------- handler Start a payload handler as job jobs Displays and manages jobs kill Kill a job rename_job Rename a job Resource Script Commands ======================== Command Description ------- ----------- makerc Save commands entered since start to a file resource Run the commands stored in a file Database Backend Commands ========================= Command Description ------- ----------- db_connect Connect to an existing database db_disconnect Disconnect from the current database instance db_export Export a file containing the contents of the database db_import Import a scan result file (filetype will be auto-detected) db_nmap Executes nmap and records the output automatically db_rebuild_cache Rebuilds the database-stored module cache db_status Show the current database status hosts List all hosts in the database loot List all loot in the database notes List all notes in the database services List all services in the database vulns List all vulnerabilities in the database workspace Switch between database workspaces Credentials Backend Commands ============================ Command Description ------- ----------- creds List all credentials in the database msf > help | more Credentials Backend Commands ============================ Command Description ------- ----------- creds List all credentials in the database Database Backend Commands ========================= Command Description ------- ----------- db_connect Connect to an existing database db_disconnect Disconnect from the current database instance db_export Export a file containing the contents of the database db_import Import a scan result file (filetype will be auto-detected) db_nmap Executes nmap and records the output automatically db_rebuild_cache Rebuilds the database-stored module cache db_status Show the current database status hosts List all hosts in the database loot List all loot in the database notes List all notes in the database services List all services in the database vulns List all vulnerabilities in the database workspace Switch between database workspaces Resource Script Commands ======================== Command Description ------- ----------- makerc Save commands entered since start to a file resource Run the commands stored in a file Job Commands ============ Command Description ------- ----------- handler Start a payload handler as job jobs Displays and manages jobs kill Kill a job rename_job Rename a job Module Commands =============== Command Description ------- ----------- advanced Displays advanced options for one or more modules back Move back from the current context edit Edit the current module or a file with the preferred editor info Displays information about one or more modules loadpath Searches for and loads modules from a path options Displays global options or for one or more modules popm Pops the latest module off the stack and makes it active previous Sets the previously loaded module as the current module pushm Pushes the active or list of modules onto the module stack reload_all Reloads all modules from all defined module paths reload_lib Reload one or more library files from specified paths search Searches module names and descriptions show Displays modules of a given type, or all modules use Selects a module by name Core Commands ============= Command Description ------- ----------- ? Help menu banner Display an awesome metasploit banner cd Change the current working directory color Toggle color connect Communicate with a host exit Exit the console get Gets the value of a context-specific variable getg Gets the value of a global variable grep Grep the output of another command help Help menu history Show command history irb Drop into irb scripting mode load Load a framework plugin quit Exit the console route Route traffic through a session save Saves the active datastores sessions Dump session listings and display information about sessions set Sets a context-specific variable to a value setg Sets a global variable to a value sleep Do nothing for the specified number of seconds spool Write console output into a file as well the screen threads View and manipulate background threads unload Unload a framework plugin unset Unsets one or more context-specific variables unsetg Unsets one or more global variables version Show the framework and console library version numbers msf > --- ## Wireshark Security Advisory URL: https://securityorb.com/wireshark-security-advisory/ Type: post Modified: 2018-06-08 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4217-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 03, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : wireshark CVE ID : CVE-2018-9273 CVE-2018-7320 CVE-2018-7334 CVE-2018-7335 CVE-2018-7419 CVE-2018-9261 CVE-2018-9264 CVE-2018-11358 CVE-2018-11360 CVE-2018-11362 It was discovered that Wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for PCP, ADB, NBAP, UMTS MAC, IEEE 802.11, SIGCOMP, LDSS, GSM A DTAP and Q.931, which result in denial of service or the execution of arbitrary code. For the oldstable distribution (jessie), these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u14. For the stable distribution (stretch), these problems have been fixed in version 2.2.6+g32dac6a-2+deb9u3. We recommend that you upgrade your wireshark packages. For the detailed security status of wireshark please refer to its security tracker page at: Information on source package wireshark http://security-tracker.debian.org Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org --- ## Linux Commands - Run .bin file in Linux / UNIX URL: https://securityorb.com/linux-commands-run-bin-file-in-linux-unix/ Type: post Modified: 2018-06-07 Run .bin file in Linux / UNIX Change the permission of the file you downloaded to be executable by typing the following command: $ chmod +x file.bin Start the installation process or run .bin file by typing the following command: $ sudo ./file.bin For example if .bin file name is program.bin. Then type the following commands: $ chmod +x program.bin $ sudo ./program.bin     --- ## The Security Assessment Process & Best Practices Presentation URL: https://securityorb.com/the-security-assessment-process-best-practices-presentation/ Type: post Modified: 2018-05-17 --- ## Internet Safety Tips for Kids & Teens URL: https://securityorb.com/internet-safety-tips-for-kids-teens/ Type: post Modified: 2018-05-09 Internet Safety Tips for Kids & Teens Personal Information. Don’t give out personal information without your parents’ permission. This means you should not share your last name, home address, school name, or telephone number. Remember, just because someone asks for information about you does not mean you have to tell them anything about yourself! Screen Name. When creating your screen name, do not include personal information like your last name or date of birth. Passwords. Don’t share your password with anyone but your parents. When you use a public computer make sure you logout of the accounts you’ve accessed before leaving the terminal. Photos. Don’t post photos or videos online without getting your parents’ permission. Online Friends. Don’t agree to meet an online friend unless you have your parents’ permission. Unfortunately, sometimes people pretend to be people they aren't. Remember that not everything you read online is true. Online Ads. Don’t buy anything online without talking to your parents first. Some ads may try to trick you by offering free things or telling you that you have won something as a way of collecting your personal information. Downloading. Talk to your parents before you open an email attachment or download software. Attachments sometimes contain viruses. Never open an attachment from someone you don’t know. Bullying. Don’t send or respond to mean or insulting messages. Tell your parents if you receive one. If something happens online that makes you feel uncomfortable, talk to your parents or to a teacher at school. Social Networking. Many social networking websites (e.g., Facebook, Twitter, Second Life and MySpace) and blog hosting websites have minimum age requirements to signup. These requirements are there to protect you! Research. Talk to your librarian, teacher or parent about safe and accurate websites for research. The public library offers lots of resources. If you use online information in a school project make sure you explain where you got the information. For more tips, please see the following: https://securityorb.com/is4k/ --- ## Openvas 9 on Ubuntu Setup URL: https://securityorb.com/openvas-9-on-ubuntu-setup/ Type: post Modified: 2018-05-03 Sysadmin Ramblings Basic Installation  Install Ubuntu 16.04LTS Make sure you update your newly installed system with the latest patches - security updates. sudo apt-get update sudo apt-get upgrade sudo apt-get dist-upgrade Openvas9 is available as a package for Ubuntu 14.04 and Ubuntu 16.04. sudo add-apt-repository ppa:mrazavi/openvas sudo apt-get update sudo apt-get install openvas9 Follow the prompts and answer yes for redis-server install. Once installed,  run updates on the NVT to ensure you have the latest vulnerability tests. sudo greenbone-nvt-sync sudo greenbone-scapdata-sync sudo greenbone-certdata-sync The commands above may take a few minutes to run.  Once complete restart the openvas services to ensure they use the updated tests. sudo /etc/init.d/openvas-manager restart sudo /etc/init.d/openvas-scanner restart There are additional components required to fully utilise openvas,  the best way to find out what is required is to download and use the openvas check tool.  It can be downloaded here.  Once downloaded run the application ./openvas-check-setup --v9 Once everything has been setup and you now have a fully functioning setup ,you can access the openvas server from your preferred brower @    https://host-ip-address:4000 The default username/password is admin / admin however if the password is somehow set or you need to change the admin password to something more secure (preferable),  use the following command to do so. sudo openvasmd --new-password=my_secure_password --user=admin In order to run scans and properly identify vulnerabilities on your hosts / networks ,  its best to first setup the necessary credentials.  Go to configuration -> credentails. Click on the star in the top left hand corner to create a new credential.  You will need to setup Windows/SMB as well as Linux credentials for the different hosts within your organization.  Regarding SMB users ive had success with and without the domain name in the username field. Openvas - SSH Strong Ciphers  Its best practice to harden your ssh servers and this includes using strong ciphers.  The documentation regarding openvas and strong ciphers or lack thereof threw me for a bit. I couldnt find anything that clearly identified the problem or assisted me in being able to run authenticated tests,  so hopefully this will help you. Whenever my authenticated checks failed,  I noticed the following errors in my openvassd.messages file. "Failed to set SSH key type 'ssh-ed25519'". If you view /var/lib/openvas/plugins/ssh_fund.inc it indicates that for ed25519 you need to upgrade to libssh greater than 0.7. Ubuntu 16.04 uses libssh0.6.3 , to successfully logon to ssh servers using secure ciphers it requires libssh0.7 and greater.  There is a ppa available that upgrades to a later version of libssh, but unfortunately this didnt work for me.  I needed to manually upgrade libssh,  below is the steps i followed. You need to ensure your system has git,cmake and a few other packages installed. sudo apt-get install git sudo apt-get install build-essential sudo apt-get install cmake sudo apt-get install zlib1g-dev sudo apt-get install libssl-dev Next install libssh git clone git://git.libssh.org/projects/libssh.git libssh cd libssh mkdir build cd build cmake -DCMAKE_INSTALL_PREFIX=/usr .. make sudo make install Link the default installed libssh binaries  to the new installed ones cd  /usr/lib/x86_64-linux-gnu rm libssh.so.4 rm libssh_threads.so.4 ln -s /usr/lib/libssh.so.4 libssh.so.4 ln -s /usr/lib/libssh_threads.so.4 libssh_threads.so.4 Restart openvas scanner to ensure it uses the new binaries /etc/init.d/openvas-scanner restart --- ## Update OpenVAS Plugins (NVT, Cert Data & SCAP Data) Automatically URL: https://securityorb.com/update-openvas-plugins-nvt-cert-data-scap-data-automatically/ Type: post Modified: 2018-05-03 Once you have install OpenVAS it is a good idea to ensure it is kept up to date and running the latest security scripts to find the latest vulnerabilities as well as sync to the most updated nvt, scap and cert data.  The best way to do this is to create a script that sync's the necessary data for you automatically each day. Create a script under /usr/local/bin called update-openvas vi /usr/local/bin/update-openvas add the following contents to the file /usr/sbin/greenbone-nvt-sync /usr/sbin/greenbone-certdata-sync /usr/sbin/greenbone-scapdata-sync /usr/sbin/openvasmd --update --verbose --progress /etc/init.d/openvas-manager restart /etc/init.d/openvas-scanner restart save the file and make it executeable chmod a+x /usr/local/bin/update-openvas run the script to make sure it works and that there are no errors /usr/local/bin/update-openvas add the script to cron to run daily crontab -e add the following contents 1 1 * * * /usr/local/bin/update-openvas 1>/dev/null 2>/dev/null the above cronjob will be run at 1 minute past 1 every day --- ## 10 Year Old Talks about Cyber Bullying URL: https://securityorb.com/10-year-old-cyberbully/ Type: post Modified: 2018-04-13 10-year-old Cassidy Warner says she has been bullied since the first grade and made a public plea on Facebook to put an end to it. In an interview with CNN's Chris Cuomo, she said that she is still being bullied. --- ## How to Reset or Create a Password for OpenVas URL: https://securityorb.com/how-to-reset-or-create-a-password-for-openvas/ Type: post Modified: 2018-04-11 The password to access OpenVas vulnerability scanner with username ‘admin’ is created during the initial setup.  At times you forget the password or want to reset it.  This can be accomplished by resetting the password using the following command: To change admin password: sudo openvasmd -- --user=admin -- --new-password=letmein Then logon using admin for the username and letmein as the password   If you would like to create additional user accounts for user accountability, you can create additional usernames by using the following commands: sudo openvasmd -- --create-user [my-new-user] and it would create the user with a generated password. --- ## Did Cambridge Analytica access your Facebook information? How to check and protect yourself URL: https://securityorb.com/did-cambridge-analytica-access-your-facebook-information-how-to-check-and-protect-yourself/ Type: post Modified: 2018-04-10 Starting this past Monday, Facebook started to inform users if their data may have been shared with Cambridge Analytica. The social media company is informing affected users at the top of “News Feeds.” The alert, titled “Protecting Your Information,” will be visible to users whose information was accessed by a third-party website and potentially shared with Cambridge Analytica. Facebook will direct those users to a “See How You’re Affected” tool. Facebook will provide other users with a different link that identifies which apps are connected to their accounts. Users have the option of prohibiting apps from accessing their data. --- ## Important Message Regarding MyFitnessPal Account Security URL: https://securityorb.com/important-message-regarding-myfitnesspal-account-security/ Type: post Modified: 2018-04-02 NOTICE OF DATA BREACH To the MyFitnessPal Community: We are writing to notify you about an issue that may involve your MyFitnessPal account information. We understand that you value your privacy and we take the protection of your information seriously. What Happened? On March 25, 2018, we became aware that during February of this year an unauthorized party acquired data associated with MyFitnessPal user accounts. What Information Was Involved? The affected information included usernames, email addresses, and hashed passwords - the majority with the hashing function called bcrypt used to secure passwords. What We Are Doing Once we became aware, we quickly took steps to determine the nature and scope of the issue. We are working with leading data security firms to assist in our investigation. We have also notified and are coordinating with law enforcement authorities. We are taking steps to protect our community, including the following: We are notifying MyFitnessPal users to provide information on how they can protect their data. We will be requiring MyFitnessPal users to change their passwords and urge users to do so immediately. We continue to monitor for suspicious activity and to coordinate with law enforcement authorities. We continue to make enhancements to our systems to detect and prevent unauthorized access to user information. What You Can Do We take our obligation to safeguard your personal data very seriously and are alerting you about this issue so you can take steps to help protect your information. We recommend you: Change your password for any other account on which you used the same or similar information used for your MyFitnessPal account. Review your accounts for suspicious activity. Be cautious of any unsolicited communications that ask for your personal data or refer you to a web page asking for personal data. Avoid clicking on links or downloading attachments from suspicious emails. For More Information For more information, please go to https://content.myfitnesspal.com/security-information/FAQ.html. Sincerely, Paul Fipps Chief Digital Officer --- ## Baltimore becomes the third U.S. city in a week to be hacked URL: https://securityorb.com/baltimore-becomes-the-third-u-s-city-in-a-week-to-be-hacked/ Type: post Modified: 2018-04-01 An article by Julius White at WEAA.org: Ransomware. Privacy. User Data. Facebook. Hacked. Those words and phrases have been all over the news in the past couple of weeks. Just last week, the City of Atlanta’s computer network was hacked and those responsible demanded $58,000 in ransomware to allow the city to regain its systems. Computer repair expert William Allen, talks with WEAA's Julius White about how not only to protect your computers, but your privacy on social media as well. The City of Leeds, Alabama, a small community just outside of Birmingham, was hacked and the hackers demanded and were paid $12,000. In Baltimore, city officials say the 911 dispatch system was hacked over the weekend, prompting a temporary shutdown of automated dispatching. In a statement released Wednesday, Frank Johnson, Baltimore Chief Information Officer, issued a statement about the weekend hack that prompted a temporary shutdown of the automated 911 dispatch system. “ [We] identified a limited breach of the Computer Aided Dispatch (CAD) Network over the weekend that supports the 911 and 311 Public Safety Emergency Communications Services due to “ransomware” perpetrators,” said Johnson. “We were able to successfully isolate the threat and ensure that no harm was done to other servers or systems across the City’s network. Once all systems were properly vetted, CAD was brought back online. No personal data of any citizen was compromised in this attack. The City continues to work with its federal partners to determine the source of the intrusion.” Johnson went on to assure all Baltimore city residents that [the City is] fully committed to safeguarding the integrity of the City’s IT infrastructure and assets. So, how can you protect your home computers—your laptops, etc., from being hacked? What about safeguarding your privacy while social media, i.e., Facebook, Instagram, etc.? Computer repair expert William Allen has information for your social media peace of mind. Read and Listen to more here. --- ## Under Armour MyFitnessPal hack affects 150 million user accounts URL: https://securityorb.com/under-armour-myfitnesspal-hack-affects-150-million-user-accounts/ Type: post Modified: 2018-03-30 The accounts of about 150 million users of nutrition-tracking app MyFitnessPal were breached last month, Under Armour (UAA) said Thursday, adding its name to the list of corporations targeted by hackers. Hackers gained access to personal data included user names, emails and encrypted passwords, the sportswear apparel maker said in a news release. The affected data did not include Social Security numbers and driver's license numbers. Under Armour is investigating the data breach. The company on Tuesday learned that an unauthorized party had acquired data associated with MyFitnessPal user accounts in late February. Under Armour said it would notify anyone whose information was exposed in the cybertheft. Read more here. --- ## Open Vulnerability Assessment System release 9 (OpenVAS-9) URL: https://securityorb.com/open-vulnerability-assessment-system-release-9-openvas-9/ Type: post Modified: 2018-03-14 The OpenVAS developers are happy to announce a round of maintenance releases for the Open Vulnerability Assessment System release 9 (OpenVAS-9). This round includes the following releases: - OpenVAS Libraries 9.0.2 - OpenVAS Scanner 5.1.2 Many thanks to everyone who has contributed to the releases. For a detailed list of the changes in the individual modules, please refer to the "CHANGES" file which is included in every release file or to the release notes under the corresponding repositories of each module at the GitHub project page. https://github.com/greenbone/gvm-libs/releases and https://github.com/greenbone/openvas-scanner/releases This page contains signatures for every release file as well. You can find links to the latest source tarballs for all currently maintained releases here: ? http://openvas.org/install-source.html Releases of other Openvas-9 modules are expected to follow soon, as well as binary packages for major GNU/Linux distributions by third parties. --- ## p-smash DoS (ICMP 9 flood) URL: https://securityorb.com/p-smash-dos/ Type: post Modified: 2018-02-19 p-smash DoS (ICMP 9 flood) Vulnerability Severity p-smash DoS (ICMP 9 flood) 7.8 (High) Summary - It was possible to crash the remote machine by flooding it with ICMP type 9 packets. Vulnerability Detection Result - Vulnerability was detected according to the Vulnerability Detection Method. Impact - A cracker may use this attack to make this host crash continuously, preventing you from working properly. Solution - Upgrade your Windows 9x operating system or change it. Vulnerability Detection Method - Details: p-smash DoS (ICMP 9 flood) (OID: 1.3.6.1.4.1.25623.1.0.11024) Version used: $Revision: 8144 $ References: Other: http://support.microsoft.com/default.aspx?scid=KB;en-us;q216141 --- ## Information Assurance Scholarship Program: Capitol Technology University URL: https://securityorb.com/information-assurance-scholarship-program-capitol-technology-university/ Type: post Modified: 2018-01-31 Picture this: a full scholarship package enabling you to complete your cybersecurity education without being hampered by financial burdens. In addition, a generous stipend covering room and board. And the assurance of federal government employment after graduation. All this is possible through the Information Assurance Scholarship Program (IASP), which is available to students at DHS and NSA-designated Centers of Excellence in cybersecurity education, including Capitol. But don't let time slip by: the application deadline is coming soon. Here's how the IASP works. Students chosen for this prestigious opportunity receive full scholarship packages including undergraduate or graduation tuition as well as a stipend ($25,000 undergraduate and $30,000 graduate) for room and board. In exchange, for each year that they receive the scholarship recipients agree to provide one year of paid cybersecurity work for the federal government after graduation. You must apply through the university. The deadline for completed IASP applications is Monday, February 5, 2018. Completed applications must be submitted with unofficial transcripts and 2 letters of reference from faculty or employers. The application includes a competency statement related to six areas of cybersecurity competency. Official transcripts must be submitted by Friday, February 16, 2018 for submission to the funder. All applicants will present on their knowledge and ability in the six competency areas via Adobe Connect. The selection panel representatives will interview all applicants immediately following their presentation. Presentation/Interview sessions will occur between February 6, 2018 and February 16, 2018. Notification of selection for nomination will be made to students by February 28, 2018. The nominated student list will be forwarded to NSA by the deadline of February 28, 2018. NSA will make the final selections by August 1, 2018. Completed applications should be received by midnight 5 February 2018. Email address: iasp@captechu.edu Assistance for Students The Career Services department can assist you and provide guidance in completing the IASP application process. For more information, e-mail Careers@captechu.edu or phone 240-965-2494. Make sure to leave a message. View this video for information about completing the application. The segment related to your responses for the six competencies gives concrete examples of how to represent your knowledge and ability in these areas. An Adobe Connect information session will be held on Thursday 25 January 2018 @ 7 PM EST: http://capitol.adobeconnect.com/iasp/ --- ## 2018 Security Concerns to Look Out For URL: https://securityorb.com/2018-security-concerns-look/ Type: post Modified: 2018-01-12 2017 was a tough year for cyber security companies and professional as phishing attacks, ransomware and state-sponsored attacks took front stage.  So what should we expect for 2018?  I say bigger breaches and new types of attacks if the current trend continues.  With that being said, her are a few of my ideas on the types of attacks that will cover our headlines in 2018:   State-sponsored Attacks will Increase – The regular actors such as North Korea, China, Russia and Iran will continue with their cyber-attacks to extort, steal and disrupt information systems. I also see new actors including our so called allies jumping into the pot to obtain economic and technological advantages.   Internet of Things (IoT) attacks will increase – As more Internet connected devices enter the market from what I have been able to ascertain from this year’s CES, I could not help but think about how minimal security controls are implemented to defend against cyber-attacks.   Ransomware Attacks will Increase – The increase of ransomware attacks are no surprise to me since their presence have increased from 2016 to 2017 exponentially and I see no change in 2018. What I am most concerned with in the idea many of the new attacks will be targeted.  For example, there are concerns, hackers will focus their efforts towards the health-care sector and target devices such as pacemakers.  So instead of paying to get you information back, a person will have to pay to keep their life.   These are just a few of the concerns I predict will have security practitioners up at night, the good news, our awareness of this threats have increased and security tools are being implemented to assist in defending our information systems and data.  What do you think? --- ## SecurityOrb.com’s Top 3 Security Hacks of 2017 URL: https://securityorb.com/securityorb-coms-top-3-security-hacks-2017/ Type: post Modified: 2018-01-07 In recent years security breaches have been a big topic as it has impacted many of our lives and 2017 is not different.  securityorb.com/ recently reviewed some of the most notable hacks of 2017 and compiled a list of the top 3 security breaches.    Equifax – In July of 2017, Equifax one of the largest credit bureaus was hacked as the personal information of 145 million people were taken by cybercriminals. It was considered among the worst breaches of all time because of the amount of sensitive information exposed, including Social Security numbers, addresses and the maiden names of your mother.   Leaked NSA Hacking Tools – In April of 2017, a hacking group called the Shadow Brokers leaked a bunch of hacking tools that belonged to the National Security Agency aimed at exploiting Windows-based systems. One to the tools leaked by the Shadow Brokers was used in the year's biggest global cyberattack known as the WannaCry exploit.   WannaCry – In May of 2017 the ransomware known as “WannaCry” targeted more than 150 countries and many of the businesses within those countries that were running outdated Windows software. The hackers behind WannaCry demanded money to unlock the files and more than 300,000 machines were effected across several industries, including health care, universities and car companies.   Let us know what you think of the list, what else should have been on the list in your opinion? --- ## The Software Engineering Institute (SEI) Issues Advice on Ransomware URL: https://securityorb.com/software-engineering-institute-sei-issues-advice-ransomware/ Type: post Modified: 2017-06-03 The Software Engineering Institute (SEI) of Carnegie Mellon University has released a blog post on best practices for preventing and responding to ransomware. This common malware captures, encrypts, and holds your data to extort a ransom. SEI’s top recommendation to thwart ransomware attacks is to back up your important files regularly. US-CERT recommends that users and administrators review SEI's blog post (link is external) and US-CERT's Security Publication on Ransomware for more information. --- ## Suspicious Activities on Hotels.com User Accounts URL: https://securityorb.com/suspicious-activities-hotels-com-user-accounts/ Type: post Modified: 2017-06-01 I recently received an email from Hotels.com stating an unauthorized user may have accessed user’s accounts and are urging customers to change their password.  Read the actual email below. “We are writing to make you aware of recent activity involving Hotels.com accounts that leads us to believe that some of your personal information, including your reward nights, may have been accessed by an unauthorized user. However, rest assured that your full credit card information was not compromised on our website. On May 22-29, 2017, we detected unusual user activity with a number of accounts, including yours, which we believe resulted from an unauthorized user accessing the accounts using customers’ usernames and passwords. The accessed data could have included your name, address, e-mail address, hotel booking history, reward nights, and the last four digits of your stored credit card—but only if a user selected the option to save credit card numbers. If we’re able to verify that free nights were recently removed from your account without your authorization, we will quickly restore those nights. We are taking steps to ensure the continued security of your data, including resetting all compromised passwords. When you attempt to log in to your account, you will receive a message that will provide you with instructions on how to change your password. The following are tips on how better to protect your account: To reset your password, click the "forgot your password" link and follow the instructions on the screen. Because an unauthorized user accessed your account using your username and password, we recommend that you create an entirely different password and one that is not shared with any other online service. Strong passwords are at least eight characters long, and contain upper and lowercase letters, plus numbers and symbols. Verify your account details are correct by validating your e-mail address, and other account information. If you notice anything unusual with your account details, please contact us. The security of our customers’ account information is of the utmost importance to us, and we apologize for any inconvenience this issue may cause you.  If you have questions, please feel free to contact Hotels.com at 800-246-8357. Please note that our Customer Service agents will not be able to assist you with changing your password—only you can change your password online. Sincerely, Hotels.com Customer Support” --- ## Kmart Stores Battling Malware-Based Security Breach of its Store Credit Card Processing Systems. Again... URL: https://securityorb.com/kmart-stores-battling-malware-based-security-breach-store-credit-card-processing-systems/ Type: post Modified: 2017-06-01 An article by Brian Krebs from KrebsonSecurity.com: For the second time in less than three years, Kmart Stores is battling a malware-based security breach of its store credit card processing systems. Last week I began hearing from smaller banks and credit unions who said they strongly suspected another card breach at Kmart. Some of those institutions received alerts from the credit card companies about batches of stolen cards that all had one thing in common: They were all used at Kmart locations. Asked to respond to rumors about a card breach, Kmart’s parent company Sears Holdings said some of its payment systems were infected with malicious software: “We recently became aware that Sears Holdings was a victim of a security incident involving unauthorized credit card activity following certain customer purchases at some of our Kmart stores. We immediately launched a thorough investigation and engaged leading third party forensic experts to review our systems and secure the affected part of our network.” “Our Kmart store payment data systems were infected with a form of malicious code that was undetectable by current anti-virus systems and application controls. Once aware of the new malicious code, we quickly removed it and contained the event. We are confident that our customers can safely use their credit and debit cards in our retail stores.” Based on the forensic investigation, NO PERSONAL identifying information (including names, addresses, social security numbers, and email addresses) was obtained by those criminally responsible. However, we believe certain credit card numbers have been compromised. Nevertheless, in light of our EMV compliant point of sale systems, which rolled out last year, we believe the exposure to cardholder data that can be used to create counterfeit cards is limited. There is also no evidence that kmart.com or Sears customers were impacted.” Sears spokesman Chris Brathwaite said the company is not commenting on how many of Kmart’s 735 locations nationwide may have been impacted or how long the breach is believed to have persisted, saying the investigation is ongoing. Read the rest here.   --- ## Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure URL: https://securityorb.com/presidential-executive-order-strengthening-cybersecurity-federal-networks-critical-infrastructure/ Type: post Modified: 2017-05-11 The White House Office of the Press Secretary For Immediate Release May 11, 2017 Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure EXECUTIVE ORDER - - - - - - - STRENGTHENING THE CYBERSECURITY OF FEDERAL NETWORKS AND CRITICAL INFRASTRUCTURE By the authority vested in me as President by the Constitution and the laws of the United States of America, and to protect American innovation and values, it is hereby ordered as follows: Section 1.  Cybersecurity of Federal Networks. (a)  Policy.  The executive branch operates its information technology (IT) on behalf of the American people.  Its IT and data should be secured responsibly using all United States Government capabilities.  The President will hold heads of executive departments and agencies (agency heads) accountable for managing cybersecurity risk to their enterprises.  In addition, because risk management decisions made by agency heads can affect the risk to the executive branch as a whole, and to national security, it is also the policy of the United States to manage cybersecurity risk as an executive branch enterprise. (b)  Findings. (i)    Cybersecurity risk management comprises the full range of activities undertaken to protect IT and data from unauthorized access and other cyber threats, to maintain awareness of cyber threats, to detect anomalies and incidents adversely affecting IT and data, and to mitigate the impact of, respond to, and recover from incidents.  Information sharing facilitates and supports all of these activities. (ii)   The executive branch has for too long accepted antiquated and difficult–to-defend IT. (iii)  Effective risk management involves more than just protecting IT and data currently in place.  It also requires planning so that maintenance, improvements, and modernization occur in a coordinated way and with appropriate regularity. (iv)   Known but unmitigated vulnerabilities are among the highest cybersecurity risks faced by executive departments and agencies (agencies).  Known vulnerabilities include using operating systems or hardware beyond the vendor's support lifecycle, declining to implement a vendor's security patch, or failing to execute security-specific configuration guidance. (v)    Effective risk management requires agency heads to lead integrated teams of senior executives with expertise in IT, security, budgeting, acquisition, law, privacy, and human resources. (c)  Risk Management. (i)    Agency heads will be held accountable by the President for implementing risk management measures commensurate with the risk and magnitude of the harm that would result from unauthorized access, use, disclosure, disruption, modification, or destruction of IT and data.  They will also be held accountable by the President for ensuring that cybersecurity risk management processes are aligned with strategic, operational, and budgetary planning processes, in accordance with chapter 35, subchapter II of title 44, United States Code. (ii)   Effective immediately, each agency head shall use The Framework for Improving Critical Infrastructure Cybersecurity (the Framework) developed by the National Institute of Standards and Technology, or any successor document, to manage the agency's cybersecurity risk.  Each agency head shall provide a risk management report to the Secretary of Homeland Security and the Director of the Office of Management and Budget (OMB) within 90 days of the date of this order.  The risk management report shall: (A)  document the risk mitigation and acceptance choices made by each agency head as of the date of this order, including: (1)  the strategic, operational, and budgetary considerations that informed those choices; and (2)  any accepted risk, including from unmitigated vulnerabilities; and (B)  describe the agency's action plan to implement the Framework. (iii)  The Secretary of Homeland Security and the Director of OMB, consistent with chapter 35, subchapter II of title 44, United States Code, shall jointly assess each agency's risk management report to determine whether the risk mitigation and acceptance choices set forth in the reports are appropriate and sufficient to manage the cybersecurity risk to the executive branch enterprise in the aggregate (the determination). (iv)   The Director of OMB, in coordination with the Secretary of Homeland Security, with appropriate support from the Secretary of Commerce and the Administrator of General Services, and within 60 days of receipt of the agency risk management reports outlined in subsection (c)(ii) of this section, shall submit to the President, through the Assistant to the President for Homeland Security and Counterterrorism, the following: (A)  the determination; and (B)  a plan to: (1)  adequately protect the executive branch enterprise, should the determination identify insufficiencies; (2)  address immediate unmet budgetary needs necessary to manage risk to the executive branch enterprise; (3)  establish a regular process for reassessing and, if appropriate, reissuing the determination, and addressing future, recurring unmet budgetary needs necessary to manage risk to the executive branch enterprise; (4)  clarify, reconcile, and reissue, as necessary and to the extent permitted by law, all policies, standards, and guidelines issued by any agency in furtherance of chapter 35, subchapter II of title 44, United States Code, and, as necessary and to the extent permitted by law, issue policies, standards, and guidelines in furtherance of this order; and (5)  align these policies, standards, and guidelines with the Framework. (v)    The agency risk management reports described in subsection (c)(ii) of this section and the determination and plan described in subsections (c)(iii) and (iv) of this section may be classified in full or in part, as appropriate. (vi)   Effective immediately, it is the policy of the executive branch to build and maintain a modern, secure, and more resilient executive branch IT architecture. (A)  Agency heads shall show preference in their procurement for shared IT services, to the extent permitted by law, including email, cloud, and cybersecurity services. (B)  The Director of the American Technology Council shall coordinate a report to the President from the Secretary of Homeland Security, the Director of OMB, and the Administrator of General Services, in consultation with the Secretary of Commerce, as appropriate, regarding modernization of Federal IT.  The report shall: (1)  be completed within 90 days of the date of this order; and (2)  describe the legal, policy, and budgetary considerations relevant to -- as well as the technical feasibility and cost effectiveness, including timelines and milestones, of -- transitioning all agencies, or a subset of agencies, to: (aa)  one or more consolidated network architectures; and (bb)  shared IT services, including email, cloud, and cybersecurity services. (C)  The report described in subsection (c)(vi)(B) of this section shall assess the effects of transitioning all agencies, or a subset of agencies, to shared IT services with respect to cybersecurity, including by making recommendations to ensure consistency with section 227 of the Homeland Security Act (6 U.S.C. 148) and compliance with policies and practices issued in accordance with section 3553 of title 44, United States Code.  All agency heads shall supply such information concerning their current IT architectures and plans as is necessary to complete this report on time. (vii)  For any National Security System, as defined in section 3552(b)(6) of title 44, United States Code, the Secretary of Defense and the Director of National Intelligence, rather than the Secretary of Homeland Security and the Director of OMB, shall implement this order to the maximum extent feasible and appropriate.  The Secretary of Defense and the Director of National Intelligence shall provide a report to the Assistant to the President for National Security Affairs and the Assistant to the President for Homeland Security and Counterterrorism describing their implementation of subsection (c) of this section within 150 days of the date of this order.  The report described in this subsection shall include a justification for any deviation from the requirements of subsection (c), and may be classified in full or in part, as appropriate. Sec. 2.  Cybersecurity of Critical Infrastructure. (a)  Policy.  It is the policy of the executive branch to use its authorities and capabilities to support the cybersecurity risk management efforts of the owners and operators of the Nation's critical infrastructure (as defined in section 5195c(e) of title 42, United States Code) (critical infrastructure entities), as appropriate. (b)  Support to Critical Infrastructure at Greatest Risk.  The Secretary of Homeland Security, in coordination with the Secretary of Defense, the Attorney General, the Director of National Intelligence, the Director of the Federal Bureau of Investigation, the heads of appropriate sector-specific agencies, as defined in Presidential Policy Directive 21 of February 12, 2013 (Critical Infrastructure Security and Resilience) (sector-specific agencies), and all other appropriate agency heads, as identified by the Secretary of Homeland Security, shall: (i)    identify authorities and capabilities that agencies could employ to support the cybersecurity efforts of critical infrastructure entities identified pursuant to section 9 of Executive Order 13636 of February 12, 2013 (Improving Critical Infrastructure Cybersecurity), to be at greatest risk of attacks that could reasonably result in catastrophic regional or national effects on public health or safety, economic security, or national security (section 9 entities); (ii)   engage section 9 entities and solicit input as appropriate to evaluate whether and how the authorities and capabilities identified pursuant to subsection (b)(i) of this section might be employed to support cybersecurity risk management efforts and any obstacles to doing so; (iii)  provide a report to the President, which may be classified in full or in part, as appropriate, through the Assistant to the President for Homeland Security and Counterterrorism, within 180 days of the date of this order, that includes the following: (A)  the authorities and capabilities identified pursuant to subsection (b)(i) of this section; (B)  the results of the engagement and determination required pursuant to subsection (b)(ii) of this section; and (C)  findings and recommendations for better supporting the cybersecurity risk management efforts of section 9 entities; and (iv)   provide an updated report to the President on an annual basis thereafter. (c)  Supporting Transparency in the Marketplace.  The Secretary of Homeland Security, in coordination with the Secretary of Commerce, shall provide a report to the President, through the Assistant to the President for Homeland Security and Counterterrorism, that examines the sufficiency of existing Federal policies and practices to promote appropriate market transparency of cybersecurity risk management practices by critical infrastructure entities, with a focus on publicly traded critical infrastructure entities, within 90 days of the date of this order. (d)  Resilience Against Botnets and Other Automated, Distributed Threats.  The Secretary of Commerce and the Secretary of Homeland Security shall jointly lead an open and transparent process to identify and promote action by appropriate stakeholders to improve the resilience of the internet and communications ecosystem and to encourage collaboration with the goal of dramatically reducing threats perpetrated by automated and distributed attacks (e.g., botnets).  The Secretary of Commerce and the Secretary of Homeland Security shall consult with the Secretary of Defense, the Attorney General, the Director of the Federal Bureau of Investigation, the heads of sector-specific agencies, the Chairs of the Federal Communications Commission and Federal Trade Commission, other interested agency heads, and appropriate stakeholders in carrying out this subsection.  Within 240 days of the date of this order, the Secretary of Commerce and the Secretary of Homeland Security shall make publicly available a preliminary report on this effort.  Within 1 year of the date of this order, the Secretaries shall submit a final version of this report to the President. (e)  Assessment of Electricity Disruption Incident Response Capabilities.  The Secretary of Energy and the Secretary of Homeland Security, in consultation with the Director of National Intelligence, with State, local, tribal, and territorial governments, and with others as appropriate, shall jointly assess: (i)    the potential scope and duration of a prolonged power outage associated with a significant cyber incident, as defined in Presidential Policy Directive 41 of July 26, 2016 (United States Cyber Incident Coordination), against the United States electric subsector; (ii)   the readiness of the United States to manage the consequences of such an incident; and (iii)  any gaps or shortcomings in assets or capabilities required to mitigate the consequences of such an incident. The assessment shall be provided to the President, through the Assistant to the President for Homeland Security and Counterterrorism, within 90 days of the date of this order, and may be classified in full or in part, as appropriate. (f)  Department of Defense Warfighting Capabilities and Industrial Base.  Within 90 days of the date of this order, the Secretary of Defense, the Secretary of Homeland Security, and the Director of the Federal Bureau of Investigation, in coordination with the Director of National Intelligence, shall provide a report to the President, through the Assistant to the President for National Security Affairs and the Assistant to the President for Homeland Security and Counterterrorism, on cybersecurity risks facing the defense industrial base, including its supply chain, and United States military platforms, systems, networks, and capabilities, and recommendations for mitigating these risks.  The report may be classified in full or in part, as appropriate. Sec. 3.  Cybersecurity for the Nation. (a)  Policy.  To ensure that the internet remains valuable for future generations, it is the policy of the executive branch to promote an open, interoperable, reliable, and secure internet that fosters efficiency, innovation, communication, and economic prosperity, while respecting privacy and guarding against disruption, fraud, and theft.  Further, the United States seeks to support the growth and sustainment of a workforce that is skilled in cybersecurity and related fields as the foundation for achieving our objectives in cyberspace. (b)  Deterrence and Protection.  Within 90 days of the date of this order, the Secretary of State, the Secretary of the Treasury, the Secretary of Defense, the Attorney General, the Secretary of Commerce, the Secretary of Homeland Security, and the United States Trade Representative, in coordination with the Director of National Intelligence, shall jointly submit a report to the President, through the Assistant to the President for National Security Affairs and the Assistant to the President for Homeland Security and Counterterrorism, on the Nation's strategic options for deterring adversaries and better protecting the American people from cyber threats. (c)  International Cooperation.  As a highly connected nation, the United States is especially dependent on a globally secure and resilient internet and must work with allies and other partners toward maintaining the policy set forth in this section.  Within 45 days of the date of this order, the Secretary of State, the Secretary of the Treasury, the Secretary of Defense, the Secretary of Commerce, and the Secretary of Homeland Security, in coordination with the Attorney General and the Director of the Federal Bureau of Investigation, shall submit reports to the President on their international cybersecurity priorities, including those concerning investigation, attribution, cyber threat information sharing, response, capacity building, and cooperation.  Within 90 days of the submission of the reports, and in coordination with the agency heads listed in this subsection, and any other agency heads as appropriate, the Secretary of State shall provide a report to the President, through the Assistant to the President for Homeland Security and Counterterrorism, documenting an engagement strategy for international cooperation in cybersecurity. (d)  Workforce Development.  In order to ensure that the United States maintains a long-term cybersecurity advantage: (i)    The Secretary of Commerce and the Secretary of Homeland Security, in consultation with the Secretary of Defense, the Secretary of Labor, the Secretary of Education, the Director of the Office of Personnel Management, and other agencies identified jointly by the Secretary of Commerce and the Secretary of Homeland Security, shall: (A)  jointly assess the scope and sufficiency of efforts to educate and train the American cybersecurity workforce of the future, including cybersecurity-related education curricula, training, and apprenticeship programs, from primary through higher education; and (B)  within 120 days of the date of this order, provide a report to the President, through the Assistant to the President for Homeland Security and Counterterrorism, with findings and recommendations regarding how to support the growth and sustainment of the Nation's cybersecurity workforce in both the public and private sectors. (ii)   The Director of National Intelligence, in consultation with the heads of other agencies identified by the Director of National Intelligence, shall: (A)  review the workforce development efforts of potential foreign cyber peers in order to help identify foreign workforce development practices likely to affect long-term United States cybersecurity competitiveness; and (B)  within 60 days of the date of this order, provide a report to the President through the Assistant to the President for Homeland Security and Counterterrorism on the findings of the review carried out pursuant to subsection (d)(ii)(A) of this section. (iii)  The Secretary of Defense, in coordination with the Secretary of Commerce, the Secretary of Homeland Security, and the Director of National Intelligence, shall: (A)  assess the scope and sufficiency of United States efforts to ensure that the United States maintains or increases its advantage in national-security-related cyber capabilities; and (B)  within 150 days of the date of this order, provide a report to the President, through the Assistant to the President for Homeland Security and Counterterrorism, with findings and recommendations on the assessment carried out pursuant to subsection (d)(iii)(A) of this section. (iv)   The reports described in this subsection may be classified in full or in part, as appropriate. Sec. 4.  Definitions.  For the purposes of this order: (a)  The term "appropriate stakeholders" means any non-executive-branch person or entity that elects to participate in an open and transparent process established by the Secretary of Commerce and the Secretary of Homeland Security under section 2(d) of this order. (b)  The term "information technology" (IT) has the meaning given to that term in section 11101(6) of title 40, United States Code, and further includes hardware and software systems of agencies that monitor and control physical equipment and processes. (c)  The term "IT architecture" refers to the integration and implementation of IT within an agency. (d)  The term "network architecture" refers to the elements of IT architecture that enable or facilitate communications between two or more IT assets. Sec. 5.  General Provisions.  (a)  Nothing in this order shall be construed to impair or otherwise affect: (i)   the authority granted by law to an executive department or agency, or the head thereof; or (ii)  the functions of the Director of OMB relating to budgetary, administrative, or legislative proposals. (b)  This order shall be implemented consistent with applicable law and subject to the availability of appropriations. (c)  All actions taken pursuant to this order shall be consistent with requirements and authorities to protect intelligence and law enforcement sources and methods.  Nothing in this order shall be construed to supersede measures established under authority of law to protect the security and integrity of specific activities and associations that are in direct support of intelligence or law enforcement operations. (d)  This order is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person. DONALD J. TRUMP THE WHITE HOUSE, May 11, 2017. --- ## Congresswoman Clarke Acts to Protect Americans from Cyber-Terrorists and Hackers URL: https://securityorb.com/congresswoman-clarke-acts-protect-americans-cyber-terrorists-hackers/ Type: post Modified: 2017-03-02 Brooklyn, N.Y. – Congresswoman Yvette D. Clarke introduced, the “Cybersecurity Responsibility Act,” a bill directing the Federal Communications Commission (FCC) to establish regulations protecting communications networks from cyberattacks, which in recent years have disclosed without authorization the private information of more than one hundred millions Americans, and could have influenced the 2016 Presidential Election. Hackers have illegally launched attacked on such companies as Target and J.P. Morgan Chase, as well as the Democratic National Committee. In each instance, existing cybersecurity programs were insufficient to protect highly-sensitive information.   House Energy and Commerce Committee Ranking Member, Congressman Frank Pallone, Jr. (D-NJ) and Congresswoman Yvette D. Clarke released the following statements:   Congresswoman Clarke: “Every few weeks we hear the same story: cyberattacks by hackers – some of whom are affiliated with foreign governments that are hostile to the United States – compromise sensitive information that should have remained private. As a result, Americans are concerned about the safety of the bank accounts and the contents of their emails and text messages. In addition, recent disclosures about Russian hacking of the Democratic National Committee in 2016 to benefit Donald Trump raise serious concerns that the results of the election were compromised.”   “It has become clear that we need to have a comprehensive policy on cybersecurity that protects personal information, from the pin number for your debit card to your email password to your medical records. With the authority to regulate international and interstate communications in the interest of the public, the Federal Communications Commission should collaborate with experts in cybersecurity to develop best practices that will allow internet providers and other companies to protect themselves and their customers from the threat of hacking. We have to fight any attack on our personal privacy – as well as the institutions of our democracy – from cyberterrorists.”   Congressman Pallone: “Our networks and devices are the hub of our digital lives.  They can make our lives better and our economy stronger, but only when they are secure,” said Rep. Frank Pallone, Jr. (D-NJ) “I commend Congresswoman Clarke for proposing a new approach to protecting consumers from the growing barrage of cyber-attacks, especially from state-funded actors.  This bill would ensure that Americans do not have to choose between innovation and security.”   The bill requires the FCC to issue the new cybersecurity regulations within 180 days of its enactment.   ###   Christine L. Bennett Press Secretary Office of Congresswoman Yvette D. Clarke (NY-09) 2058 Rayburn House Office Building T: 202.225.6231 | C: 202.306.0906 | E: Christine.Bennett@mail.house.gov --- ## SHA-1 (Secure Hash Algorithm 1) Hash Function Broken Again by Researchers URL: https://securityorb.com/sha-1-secure-hash-algorithm-1-hash-function-broken-researchers/ Type: post Modified: 2017-02-23 SHA-1 (Secure Hash Algorithm 1) Hash Function Broken Again by Researchers Researchers from Google and the CWI Institute revealed that they had found a consistent way to break the cryptographic hash function SHA-1 (Secure Hash Algorithm 1) during a recent demonstration. The Secure Hash Algorithm is a family of cryptographic hash functions published by the National Institute of Standards and Technology (NIST) as a U.S. Federal Information Processing Standard (FIPS) which includes: SHA-1: A 160-bit hash function which resembles the earlier MD5 algorithm. This was designed by the National Security Agency (NSA) to be part of the Digital Signature Algorithm. Cryptographic weaknesses were discovered in SHA-1, and the standard was no longer approved for most cryptographic uses after 2010. SHA-2: A family of two similar hash functions, with different block sizes, known as SHA-256 and SHA-512. They differ in the word size; SHA-256 uses 32 byte words where SHA-512 uses 64 byte words. There are also truncated versions of each standard, known as SHA-224, SHA-384, SHA-512/224 and SHA-512/256. These were also designed by the NSA. SHA-3: A hash function formerly called Keccak, chosen in 2012 after a public competition among non-NSA designers. It supports the same hash lengths as SHA-2, and its internal structure differs significantly from the rest of the SHA family. Even though SHA-1 has been considered out-of-date for a while now, and many browser vendors had planned on suspending SHA-1 based certificates this year due to its weaker crypto structure than the newer SHA-2 and SHA-3 standards.  This recent news should enforce the need to not use SHA-1 as part of security operations. Google and CWI engineered a collision attack against SHA-1, demonstrating two PDF files with the same SHA-1 hash and different content as a proof-of-concept of their findings. --- ## Cyber Security Predictions for 2017 URL: https://securityorb.com/cyber-security-predictions-2017/ Type: post Modified: 2017-01-05 Whether it was a billion compromised Yahoo accounts or state-sponsored Russian hackers muscling in on the US election, this past year saw hacks of unprecedented scale and temerity. And if history is any guide, next year should yield more of the same. It’s hard to know for certain what lies ahead, but some themes began to present themselves toward the end of 2016 that will almost certainly continue well into next year. And the more we can anticipate them, the better we can prepare. Here’s what we think 2017 will hold. Consumer Drones Get Weaponized Given how frequently the US has used massive flying robots to kill people, perhaps it’s no surprise that smaller drones are now turning deadly, too—this time in the hands of America’s enemies. In October the New York Times reported that in the first known case, US-allied Kurdish soldiers were killed by a small drone the size of a model airplane, rigged with explosives. As drones become smaller, cheaper, and more powerful, the next year will see that experiment widened into a full-blown tactic for guerrilla warfare and terrorism. What better way to deliver deadly ordnance across enemy lines or into secure zones of cities than with remote-controlled accuracy and off-the-shelf hardware that offers no easy way to trace the perpetrator? The US government is already buying drone-jamming hardware. But as with all IEDs, the arms race between flying consumer grade bombs and the defenses against them will likely be a violent game of cat-and-mouse. Another iPhone Encryption Clash When the FBI earlier this year demanded that Apple write new software to help crack its own device—the iPhone 5c of dead San Bernadino terrorist Rizwan Farook—it fired the first shots in a new chapter of the decades-long war between law enforcement and encryption. And when it backed off that request, saying it had found its own technique to crack the phone, it only delayed any resolution. It’s only a matter of time until the FBI or other cops make another legal demand that an encryption-maker assist in cracking its protections for users, setting the conflict in motion again. In fact, in October the FBI revealed in October that another ISIS-linked terrorist, the man who stabbed ten people in a Minnesota mall, used an iPhone. Depending on what model iPhone it is, that locked device could spark Apple vs. FBI, round two, if the bureau is determined enough to access the terrorist’s data. (It took three months after the San Bernadino attack for the FBI’s conflict with Apple to become public, and that window hasn’t passed in the Minnesota case.) Sooner or later, expect another crypto clash. Russian Hackers Run Amok Two months have passed since the Office of the Director of National Intelligence and the Department of Homeland Security stated what most of the private sector cybersecurity world already believed: That the Kremlin hacked the American election, breaching the Democratic National Committee and Democratic Congressional Campaign Committee and spilling their guts to WikiLeaks. Since then, the White House has promised a response to put Russia back in check, but none has surfaced. And with less than a month until the inauguration of Putin’s preferred candidate—one who has buddied up to the Russian government at every opportunity and promised to weaken America’s NATO commitments—any deterrent effect of a retaliation would be temporary at best. In fact, the apparent success of Russia’s efforts—if, as CIA and FBI officials have now both told the Washington Post, Trump’s election was the hackers’ goal—will only embolden Russia’s digital intruders to try new targets and techniques. Expect them to replicate their influence operations ahead of elections next year in Germany, the Netherlands, and France, and potentially to even try new tricks like data sabotage or attacks on physical infrastructure. A Growing Rift Between the President and the Intelligence Community Though the US intelligence community—including the FBI, NSA, and CIA—has unanimously attributed multiple incidents of political hacking to Russian government-sponsored attackers, President-elect Donald Trump has remained skeptical. Furthermore, he has repeatedly cast doubt on digital forensics as an intelligence discipline, saying things like, “Once they hack, if you don’t catch them in the act you’re not going to catch them. They have no idea if it’s Russia or China or somebody.” Trump has also caused a stir by declining daily intelligence briefings. Beyond just the current situation with Russia, Trump’s casual dismissal of intelligence agency findings is creating an unprecedented dissonance between the Office of the President and the groups that bring it vital information about the world. Current and former members of the intelligence community told WIRED in mid-December that they find Trump’s attitude disturbing and deeply concerning. If the President-elect permanently adopts this posture, it could irrevocably hinder the role of intelligence agencies in government. President Obama, for one, says he is hopeful that the situation is temporary, since Trump has not yet felt the full responsibility of the presidency. “I think there is a sobering process when you walk into the Oval Office,” Obama said recently in a press conference. “There is just a whole different attitude and vibe when you’re not in power as when you are in power.” If Trump does eventually embrace the intelligence community more fully, the next question will be whether it can move on from what has already transpired. Read More Here... --- ## The Top 5 Free Network Security Vulnerability Security Scanners URL: https://securityorb.com/top-5-free-network-security-vulnerability-security-scanners/ Type: post Modified: 2016-11-01 A vulnerability scanner is software application that assesses security vulnerabilities in networks or host systems and produces a set of scan results. However, because both administrators and attackers can use the same tool for fixing or exploiting a system, administrators need to conduct a scan and fix problems before an attacker can do the same scan and exploit any vulnerabilities found. This article provides a general overview of vulnerability scanners There are a number of free products available to conduct the task, securityorb.com/ has provided our top 5 free network vulnerability security scanners for your review.   [pjc_slideshow slide_type="the-top-5-free-network-vulnerability-security-scanners"] --- ## American vigilante hacker sends Russia a warning URL: https://securityorb.com/american-vigilante-hacker-sends-russia-warning/ Type: post Modified: 2016-10-24 By Jose Pagliery at cnn.com An American vigilante hacker -- who calls himself "The Jester" -- has defaced the website of the Russian Ministry of Foreign Affairs in retaliation for attacks on American targets. On Friday night, the Jester gained access to the Russian government ministry's website. And he left a message: Stop attacking Americans. "Comrades! We interrupt regular scheduled Russian Foreign Affairs Website programming to bring you the following important message," he wrote. "Knock it off. You may be able to push around nations around you, but this is America. Nobody is impressed." MID.ru is the official website of the Russian agency that is in charge of maintaining that country's international diplomacy -- equivalent to the U.S. Department of State. His hacking of the website included this gag: Visitors are subjected to the ear-piercing sound of an American civil alert message -- that shrieking dial tone that accompanies emergency weather broadcasts. Read more here.   --- ## Internet of Things comes back to bite us as hackers spread botnet code URL: https://securityorb.com/internet-things-comes-back-bite-us-hackers-spread-botnet-code/ Type: post Modified: 2016-10-04 An article by Elizabeth Weise , USATODAY 8:02 p.m. EDT October 3, 2016 SAN FRANCISCO – Consumers around the world could see their home Internet speeds slow in the coming weeks due to a recent release of software that allows hackers to use Internet-connected devices to attack websites. The source code for Mirai, a tool that creates what are known as botnets, has been released on the so-called dark web, sites that require specific software or authorization to access and that operate as a sort of online underground for hackers. The release was announced Friday on Hackforums, a hacker discussion board. Two security experts contact by USA TODAY looked at the source code and confirmed it was this botnet tool. Mirai is an easy-to-use program that allows even unskilled hackers to take over online devices and use them to launch distributed denial of service, or DDoS attacks. The software spreads via the Internet, taking over DVRs, cable set-top boxes, routers and even Internet-connected cameras used by stores and businesses for surveillance. Once a device is hijacked, so much of its bandwidth goes towards doing the botnet's work that it can run slowly or suffer intermittent failures, and it's very difficult for the consumer to know the cause. The code is “a gift to cyber criminals,” said Thomas Pore, director of IT and services for Plixer International, a Kennebunk, Maine-based malware incidence response company. Mirai was used to knock computer security writer Brian Krebs offline on September 13. Expect more and more such attacks in the future, says Roland Dobbins, a DDoS expert with Arbor Networks. “We’re seeing more attackers becoming aware that embedded devices are an easy way to launch these attacks,” he said. DDos attacks from the Internet of Things DDos attacks have existed since at least 1999. They involve using a network of computers to bombard a website with millions of messages, so many that the system cannot cope and shuts down. Read more here. --- ## Clinton, Trump Debate 'Twenty-First Century War' Of Cyberattacks URL: https://securityorb.com/clinton-trump-debate-twenty-first-century-war-cyberattacks/ Type: post Modified: 2016-09-28 An interesting article by Kelly Jackson Higgins of DarkReading.com: A long-standing inside joke in the security community is to tweet "drink" when the word "cybersecurity" is uttered by the President at the State of the Union Address or by candidates during a Presidential debate. During Monday's televised debate between Presidential candidates Hillary Clinton and Donald Trump, there were plenty of opportunities to imbibe (um, tweet). The very first question about the nation's security was about hacking. Debate moderator and NBC news anchorman Lester Holt posed the question to the candidates at the top of the third and final section of the debate, Securing America: "We want to start with a twenty-first century war happening every day in this country. Our institutions are under cyberattack, and our secrets are being stolen. So my question is, who's behind it? And how do we fight it?" Holt asked. Both Clinton and Trump stressed the importance of cybersecurity for the next administration. "Well I think cybersecurity … cyberwarfare, will be one of the biggest challenges to the next President because clearly we're facing at this point two different kinds of adversaries," nation-state actors and cybercriminals, Clinton said. Clinton also called out Russia's recent hacking activity. "There's no doubt now that Russia has used cyberattacks against all kinds of organizations in our country and I am deeply concerned about this." The US needs to "make it very clear" to nations who engage in cyberattacks against the US that "the US has much greater capacity and we are not going to sit idly by and permit state actors to go after our information: our private-sector information or our public sector information," she said. "And we're going to have to make it clear that we don't want to use the kinds of tools that we have. We don't want to engage in a different kind of warfare. But we will defend the citizens of this country, and the Russians need to understand that." Read More Here. --- ## RESILIA – Spearheading the Best Practice crusade for Cyber Resilience URL: https://securityorb.com/resilia-spearheading-best-practice-crusade-cyber-resilience/ Type: post Modified: 2016-09-01 Organizations are spending vast sums protecting their digital assets, still hardly a week goes by without news of a major security breach. Attacks are larger, more complex and targeted. Sought-after digital assets include intellectual property (IP), and customer and financial data. The average financial impact of each breach is increasing and it’s becoming harder to keep these attacks out of the news. The bottom line is the consequences for organizations can be devastating in terms of loss of revenue and reputation. --- ## NSA Cyber Hacking Tools Hacked and Released to the Public URL: https://securityorb.com/nsa-cyber-hacking-tools-hacked-released-public/ Type: post Modified: 2016-08-22 Last week on my radio show, I discussed how some of the most powerful hacking tools created by the NSA’s elite hacking group known as the "Equation Group" have been released in the public by a hacking group calling themselves "The Shadow Brokers”. Many experts in the InfoSec arena including the security firm Kaspersky stated, “The files posted by The Shadow Brokers and tools used by the Equation group, “share specific and rare characteristics”, so the probability of falsification is “highly unlikely.” The tools that were release are much more sophisticated than many of the open source and freely available hacking tools that are available on the internet.  These tools can easily circumvent the security of many of the major government and corporate networks both in the US and abroad.  These tools can also be used to take over firewalls that are used in the largest and most critical environments around the world. The Shadow Brokers are asking for 1 Million in Bitcoins (around $568 Million Dollars) in an auction to release more hacking tools in the public. How can this happen you ask? The main suspect is Russia, and it's not clear if the hackers broke into the secure NSA computer network or, more likely, an NSA employee left the hacking tools on an unsecured intermediate server during a hacking operation. In a tweet about the event, Edward Snowden, former NSA employee and whistle blower stated, "NSA's hackers are told not to leave their hack tools ('binaries') on the server after an op," but later stated, "But people get lazy." If Russia is indeed responsible as many security researchers believe, it seems they have taken their cyber-attacks to a new level with the recent occurrence pertaining to the hacked emails and stolen documents from the Democratic Party. How should the US respond? --- ## Trump invites Russia to meddle in the U.S. presidential race with Clinton’s emails URL: https://securityorb.com/trump-invites-russia-meddle-u-s-presidential-race-clintons-emails/ Type: post Modified: 2016-07-28 Trump invites Russia to meddle in the U.S. presidential race with Clinton’s emails Republican nominee Donald Trump pleaded directly Wednesday with the Russian government to meddle in the U.S. presidential election by finding and releasing tens of thousands of private emails from his Democratic opponent, Hillary Clinton — an extraordinary and perhaps unprecedented maneuver in American politics. “Russia, if you’re listening, I hope you’re able to find the 30,000 emails that are missing,” Trump said during a news conference at one of his South Florida resorts. He added later, “They probably have them. I’d like to have them released.” Asked whether Russian espionage into the former secretary of state’s correspondence would concern him, Trump said, “No, it gives me no pause. If they have them, they have them.” The emails cited by Trump are from Clinton’s time at the State Department, where her use of a private server prompted a federal investigation. The FBI concluded that no prosecution was necessary. Read More Here Here’s What We Know About Russia and the DNC Hack As the Democratic National Convention continues its week-long stay in Philadelphia, accusations of Russian hacking continue to cloud the proceedings. At this point, it seems likely that Russia is responsible. What’s less clear is what that will mean going forward. It’s been a bad stretch for the Democratic National Committee. Hackers broke into its servers months ago, stealing private emails, opposition research, and campaign correspondence. Last Friday, Wikileaks made nearly 20,000 of those private emails public, revealing embarrassing details of the political machine’s inner workings. DNC official allege that the Russian government is behind the breach. The New York Times reports that US intelligence agencies increasingly share that opinion. According to a number of top cybersecurity researchers, they’re probably right. Read more Here   Did Russian government hackers leak the DNC emails? By now, it’s pretty clear that Russian hackers are responsible for breaches of the Democratic National Committee networks that occurred last summer and in April of this year — several forensic security firms have found evidence that traces the breach back to Russia. Now that DNC emails harvested during the breaches are starting to appear on Wikileaks, pundits are speculating that Russia leaked the emails in a bid to land Donald Trump in the Oval Office. But is the email leak also attributable to hackers on Russia’s government payroll? A new analysis released by security consulting firm ThreatConnect has marshaled more evidence to prove that hackers linked to the Russian government communicated with journalists about the leaked documents. A hacker set up a website and Twitter account to take credit for the DNC breach soon after it was initially reported, calling himself Guccifer 2.0 (a moniker modeled after a Romanian hacker who is recently pleaded guilty to hacking American political operatives). That claim shed doubt on initial reports from The Washington Post and others that laid the responsibility for the breach squarely at the feet of organizations with ties to the Russian government and its president, Vladimir Putin. But ThreatConnect’s research suggests that Guccifer 2.0 is simply an invention of the Russian government to deflect attention from its involvement in the breach. Read More Here --- ## 7 Steps to a Cyber-Resilient Business URL: https://securityorb.com/7-steps-to-a-cyber-resilient-business/ Type: post Modified: 2016-07-12 Cyber security is the most prominent risk issue facing company Boards of Directors and executives worldwide. We are inundated almost daily with accounts of major corporate data breaches and compromised networks. Recent high-profile attacks such as the targeting of point-of-sale terminals at Target, Home Depot and Staples, server software at JP Morgan, and employee databases at Sony, demonstrate how vulnerable even the largest and most sophisticated companies can be. In this highly challenging environment, board members and executives are, not surprisingly, unsure of how best to protect themselves. Proactive prevention with a focus on cyber resilience: A “how to” guide The first and most important step is to take measures to prevent intrusions from occurring in the first place. Just as a proper diet, exercise, hand-washing and regular flu shots are important to minimizing your odds of developing the flu, maintaining standard systems hygiene is critical to protecting your organization from being infiltrated by hackers. In fact, the Center for Internet Security claims that up to 80% of cyber attacks can be prevented by: Maintaining an inventory of authorized and unauthorized devices Maintaining an inventory of authorized and unauthorized software Developing and managing secure configurations for all devices Conducting continuous (automated) vulnerability assessment and remediation Actively managing and controlling the use of administrative privileges Unfortunately, blocking four out of five attacks still leaves open the possibility that a substantial number of attacks might succeed. And today, it’s more a matter of when rather than if you will, eventually, be successfully attacked. What happens then? Even well prepared companies may not know immediately that they have been breached. But those that have prepared for such an event will be much better off than those that have not. Just as conducting fire drills can save lives in the event of a real fire, preparing for the aftermath of a cyber attack can make an enormous difference in how quickly your company gets back on its feet and how well officers and board members do in the limelight after a major breach becomes public. steps-to-cyber-resilience-final The good news is that building a cyber-resilience action plan is a step-by-step process that any company willing to commit the time and resources can accomplish. And, after ensuring you have good system hygiene, the next step is to put the right group together to work out the details. This working group should include a cross-functional collection of senior managers (Sales & Marketing, IT, Finance, Legal, Risk, HR, etc.) each of whom is willing to meet regularly to discuss cyber security, monitor evolving threats (as seen from his or her unique perspective in the company), and participate in modeling and analyzing hypothetical attacks. Once formed, the group can begin to map out the plan by, first, assessing the company’s cyber risk profile. A recent study from Verizon has concluded that 95% of all cyber attacks can be analyzed in terms of nine basic patterns.2 A thorough study of the patterns, facilitated perhaps by the help of an external cyber security expert, can help the group determine the types of attacks their company is most vulnerable to; preventive measures can then be tailored to these patterns. To go deeper, the team should then develop hypothetical scenarios, based on the most relevant patterns identified above, to help identify in detail possible attack modes, targets, vulnerabilities and impacts. There is no need for, and it is in fact a detriment to require, great precision in this exercise. No one can know for certain, ahead of the event, how much damage a successful data breach will cause in terms of lost revenue, reputational harm, or stock price declines. All that is needed are rough estimates that give enough sense of scale and types of potential harm to enable the team to put together a risk mitigation strategy. Such a strategy will involve steps to mitigate the damage to the most relevant targets in an attack. For example, if a company determines that its greatest threat is malware installations in point-of-sale software systems, directed by domestic operatives, via vendor access rights, then it might consider investments in end-to-end encryption, Application White Listing (AWL), File Integrity Monitoring (FIM), system access software, vendor access controls and regular reviews of all vendor access logs. It is important to realize that cyber-attacks cannot be fully mitigated. In these instances, having the right cyber insurance coverage in place can make all the difference in how your company performs in the days, weeks and months following a successful attack. Cyber insurance can provide critical capital and expert assistance when a cyber-security event occurs. Companies may also want to acquire Directors and Officers (D&O) liability insurance to protect board members company officers against claims of negligence following a breach. In addition, they may want to review their property, casualty and business interruption coverage to ensure that sufficient protection exists in the event of a successful cyber-attack on the company’s infrastructure. Fortunately this type of attack has, to date, been rare. But such attacks are not unheard of, and the potential for them is growing more likely given current geopolitical instabilities, especially for multinationals with exposure in more sensitive countries around the globe. By taking the steps outlined above, a company can increase its cyber resiliency and be much better positioned to quickly recover from a successful cyber-attack. Source : https://www.aig.com/knowledge-and-insights/building-a-cyber-resilient-business --- ## Connected Cars: Strategies For Reducing The Ever-Expanding Risk URL: https://securityorb.com/connected-cars-strategies-for-reducing-the-ever-expanding-risk/ Type: post Modified: 2016-05-12 The best way automakers can keep customers safe and mitigate threats to their own enterprise is to first hack themselves. As automakers improve the driving experience with digital technology, they also open up new avenues for attack. The good news is that these avenues are too advanced for the average “script kiddie." They are, however, by no means beyond the abilities of well-funded experts, as many hackers are these days. In fact, one automaker contracted my firm well before the headline-grabbing Jeep Cherokee hack last summer to conduct an advanced attack on their entire enterprise. Within four weeks, our ten-person team of ethical hackers was able to gain access that would have allowed us to interfere with both corporate and manufacturing networks as well as conduct unauthorized interactions with the vehicles. This ever-expanding attack surface of connected cars exposes significant risk to drivers’ safety, but it is also a serious threat to private customer and enterprise data. To maintain the public’s confidence, automotive manufacturers must develop proactive solutions that address major issues beyond the vehicle itself.   Read more here. --- ## Cyber Security Agenda for the Next President URL: https://securityorb.com/cyber-security-agenda-for-the-next-president/ Type: post Modified: 2016-05-12 The Obama administration has implemented a number of cybersecurity and privacy initiatives aimed at making IT more secure for the federal government and the private sector. Those include the cybersecurity framework, National Strategy for Trusted Identities in Cyberspace, employing encryption and sharing cyberthreat information. Will the next president carry on the Obama cybersecurity policies or decide to take a different approach? That's a question to be debated by a panel of experts at Information Security Media Group's Fraud and Breach Prevention Summit in the Washington area May 17 and 18. Read more here. --- ## WordPress 4.5.2 Security Release URL: https://securityorb.com/wordpress-4-5-2-security-release/ Type: post Modified: 2016-05-09 WordPress 4.5.2 Security Release Posted May 6, 2016 by Helen Hou-Sandi on the WordPress Blog Site. WordPress 4.5.2 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. WordPress versions 4.5.1 and earlier are affected by a SOME vulnerability through Plupload, the third-party library WordPress uses for uploading files. WordPress versions 4.2 through 4.5.1 are vulnerable to reflected XSS using specially crafted URIs through MediaElement.js, the third-party library used for media players. MediaElement.js and Plupload have also released updates fixing these issues. Both issues were analyzed and reported by Mario Heiderich, Masato Kinugawa, and Filedescriptor from Cure53. Thanks to the team for practicing responsible disclosure, and to the Plupload and MediaElement.js teams for working closely with us to coördinate and fix these issues. Download WordPress 4.5.2 or venture over to Dashboard → Updates and simply click “Update Now.” Sites that support automatic background updates are already beginning to update to WordPress 4.5.2. Additionally, there are multiple widely publicized vulnerabilities in the ImageMagick image processing library, which is used by a number of hosts and is supported in WordPress. For our current response to these issues, see this post on the core development blog. --- ## WordPress Redirect Hack via Test0.com/Default7.com URL: https://securityorb.com/wordpress-redirect-hack-via-test0-comdefault7-com/ Type: post Modified: 2016-05-06 WordPress Redirect Hack via Test0.com/Default7.com An article written by Denis Sinegubko: We’ve been working on a few WordPress sites with the same infection that randomly redirects visitors to malicious sites via the default7 .com / test0 .com / test246 .com domains. In this post, we’ll provide you with a review of this attack, investigated by our malware analyst, John Castro. Header.php Injection In all cases, the malware injects 10-12 lines of code at the top of the header.php file of the current WordPress theme: Malicious injection in header.php When decoded, you see this main part of the malware: Decoded malware The logic is simple. It redirects visitors to default7. com if it’s their first visit to this site after the infection, then it sets the 896diC9OFnqeAcKGN7fW cookie for one year to track returning visitors. If they are not search engine crawlers, it checks the user agent header. For more information, read more here. --- ## The Johns Hopkins Foreign Affairs Symposium Presents: The Price of Privacy: Re-Evaluating the NSA URL: https://securityorb.com/johns-hopkins-foreign-affairs-symposium-presents-price-privacy-re-evaluating-nsa/ Type: post Modified: 2016-04-23 The Johns Hopkins Foreign Affairs Symposium Presents: The Price of Privacy: Re-Evaluating the NSA --- ## Encryption Technology and Law Enforcement Technology Testified URL: https://securityorb.com/7742-2/ Type: post Modified: 2016-04-23 Encryption Technology and Law Enforcement Technology and law enforcement officials testified at a hearing on the use of encryption technology. In the law enforcement, witness Amy Hess argued that without access to encrypted data on smartphones and other devices, the FBI cannot investigate crimes to the best of their ability. Technology industry experts explained in the second panel that encryption is critical to U.S. national security, and there is no way to provide a back door to encrypted data without risking the privacy and security of everyone. Bruce Sewell, Apple’s senior vice president of legal and global security, denied claims that Apple supplied its source code to China, saying the company was asked but refused. --- ## Should CIOs worry about the Internet of Hackable Things? URL: https://securityorb.com/cios-worry-internet-hackable-things/ Type: post Modified: 2016-03-04 An interesting article by Jen A. Miller from CIO.com: If 2015 was the year of the Internet of Things, 2016 could be the year of the hacked Internet of Things. That could mean a lot of headaches for CIOs, whether they're fans of these new devices themselves or will be dealing with employees connecting them at work and managing the potential security exposure that brings. "The issue to date is that devices are vulnerable just by the fact that they exist and can connect to the Internet," says Jerry Irvine, member of the U.S. Chamber of Commerce’s Cybersecurity Leadership Council and CIO of Prescient Solutions. "Anybody can get to a device if you don't secure them properly." One of the reasons why it's a big hacker target: It's, well, big. Gartner estimates that 6.4 billion connected things will be in use by 2016, up 30 percent from last year. They also predict that 5.5 million new things will get connected every day. That's a lot of possible portals for bad players to get in. Read the rest here. --- ## IRS Issues Alert for Tax Phishing Scheme URL: https://securityorb.com/irs-issues-alert-tax-phishing-scheme/ Type: post Modified: 2016-03-02 The Internal Revenue Service (IRS) has issued a news release addressing a new spear phishing scheme targeting payroll and human resource professionals.  In this scheme, cybercriminals pose as company executives requesting personal information on employees. US-CERT encourages users and administrators to review the IRS news release for details and refer to US-CERT Security Tip ST15-001 for information on tax-themed phishing attacks. --- ## Content Filtering Software List URL: https://securityorb.com/content-filtering-software-list/ Type: post Modified: 2016-02-23 What is Internet Content Filtering? What if you could block Internet content for your children based on their maturity level? What if you could block porn completely without being forced to use a filter that treats you like a kid? Internet content filters looks at all websites visited in real time and rates them based on age-appropriateness.  Parents can easily adjust the Filter’s sensitivity as their kids grow older, meaning the Filter grows with them. Commercial Software for Content Filtering: Cyber Patrol: http://www.cyberpatrol.com CyberSitter: http://www.cybersitter.com InternetSafety: http://www.internetsafety.com/safe-eyes-parental-control-software.php ContentWatch: http://www.contentwatch.com NetNanny: http://www.netnanny.com (powered by ContentWatch - also works on mobile devices) Panda Internet Security: http://www.pandasecurity.com/security-promotion/usa/panda-internet-security PC TattleTale Parental Control: http://www.pctattletale.com Aobo Porn Filter - Website Blocker: http://aobo.cc/aobo-porn-filter.html Sentry Parental Controls: http://www.sentryparentalcontrols.com   Free Software for Content Filtering OpenDNS - FamilyShield: http://www.opendns.com/familyshield Parental Filter: http://www.softpedia.com/get/Security/Lockdown/Parental-Filter.shtml K9 Web Protection: http://www1.k9webprotection.com ProCon Latte: http://procon.mozdev.org (read interesting related article)   Content Filtering for Firefox KidZui - a safe browser and online playground for kids 3-12 FoxFilter Add-on for Firefox Interesting article on using manual proxy configurations   Filtering Content with IE's Content Advisor --- ## InfoSec Jobs - Security Operations Specialist URL: https://securityorb.com/infosec-jobs-security-operations-specialist/ Type: post Modified: 2016-02-01 Contact Information: Srikanth K SYSTEL INC | Atlanta, GA Phone:  678 250 9874 T: 888 8SYSTEL Ext:263 mailto: srikanthk@systelinc.com www.systelinc.com If you are available & interested in below opportunity contact Srikanth with word version of your resume, best time & number to contact you. Please feel free to contact him to discuss more about this opportunity.   To know more about us, please visit www.systelinc.com Position: 2 Security Operations Specialist Location: Foster City, CA Duration: 6+ Months   Se. Operation Specialist - The Security Operations Specialist is a key member of the Information Security and Privacy team and works to ensure our SIEM and Vulnerability Scanning solutions are maintained and updated as appropriate. The candidate will assist with identifying and driving necessary configuration changes and enhancements. The role will work collaboratively with the Security Engineering teams to ensure these solutions are up to date and optimized.   ESSENTIAL JOB FUNCTIONS: Vulnerability Scanning * Customize vulnerability scan reports as needed. * Ensure that vulnerability scans are occurring at regular intervals. * Ensure that vulnerability scans are updated regularly as new networks and sites are spun up. * Regularly test solution upgrades in a test environment and follow change control to implement upgrades in production. * Creating and tuning vulnerability scan groups and configurations.   SIEM * Install and configure new data / log collectors. * Create new SIEM content and rules to help identify important security events. * Work closely with our Security Operation Center to gather their requirements and build content that meets those requirement * Regularly test solution upgrades in a test environment and follow change control to implement upgrades in production.   REQUIRED SKILLS & JOB QUALIFICATIONS: * Minimum 3-4 years of progressively responsible IT experience with at least 2 years of security/infrastructure protection experience. * Familiar with general change management procedures and systems. * Experience performing security operations tasks and working with Engineering teams to implement necessary changed * Strong verbal and written communication skills with the ability to adapt information delivery based on the target audience. * Ability to work in a fast paced, highly visible, changing environment. * Proven ability at building working relationships with partners, peers, and senior Management. * Excellent analytical and problem solving skills. * Ability to multitask and manage multiple topics and demands concurrently. * Familiar with SIEM solutions like Splunk, ArcSight, LogRhythm, QRadar * Familiar with vulnerability scanning solutions like Qualys, Foundstone, Nexpose * Prior working experience in a pharmaceutical company is preferred. * Highly organized, results-oriented and attentive to details. * Self-motivated, proactive, independent and responsive – requires little supervisory attention. * Excellent presentation, facilitation and diplomacy skills. * Able to perform other duties as assigned. * Ability to document technical changes (i.e. change control documents). --- ## InfoSec Jobs - Vulnerability Management Consultant URL: https://securityorb.com/infosec-jobs-vulnerability-management-consultant/ Type: post Modified: 2016-02-01 Contact Information: Srikanth K SYSTEL INC | Atlanta, GA Phone:  678 250 9874 T: 888 8SYSTEL Ext:263 mailto: srikanthk@systelinc.com www.systelinc.com   If you are available & interested in below opportunity contact Srikanth with word version of your resume, best time & number to contact you. Please feel free to contact him to discuss more about this opportunity. To know more about us, please visit www.systelinc.com   Position: 1 Vulnerability Management Consultant Location: Foster City, CA Duration: 6+ Months   Vulnerability Management role - The Security Engineer is a key member of the Information Security and Privacy team and works closely with Infrastructure and Application services teams to ensure that software vulnerabilities are patched according to Gilead standards so that related risk can be managed appropriately. The candidate will assist with defining and enhancing patching processes and the supporting technologies such as patch management and vulnerability scanning and testing. The role will also help to collaboratively design and implement the business processes to allow system managers and system administrators to drive towards compliance with internal vulnerability remediation standards.   ESSENTIAL JOB FUNCTIONS: * Responsible for implementing and tuning the technical solution used to identify and manage the versions of Java used in the environment. * Customize as needed the vulnerability reports that will be used by system managers, system administrators and management. * Liaise with system, database and application administrators to assist with implementation and rollout of a vulnerability management process. * Research emerging technologies in support of IT security enhancement and development efforts. * Assist in formalizing and updating security policies, procedures and technical standards; auditing/monitoring compliance with those standards; developing technical checks to verify compliance with technical controls. * Creating and tuning vulnerability scan groups and configurations.   REQUIRED SKILLS & JOB QUALIFICATIONS: * Minimum 5 years of progressively responsible IT experience with at least 3 years of security/infrastructure protection experience. * Experience performing project focused information security work with cross-functional teams in an enterprise setting. * Must have a good understanding of the following security domains: Audit and Monitoring, Risk Response & Recovery, Cryptography, Data Communications, Computer Operations Security, Telecommunications & Network Security, Security Architecture & Models. * Strong verbal and written communication skills with the ability to adapt information delivery based on the target audience. * Ability to work in a fast paced, highly visible, changing environment. * Proven ability at building working relationships with partners, peers, and senior Management. * Excellent analytical and problem solving skills. * Ability to multitask and manage multiple topics and demands concurrently. * Working knowledge of IT processes (i.e., ITIL) including incident, problem, defect, change and release management. * Familiar with patch management solutions like Satellite, SCCM, WSUS, Shavlik, Secunia, LANDesk. * Familiar with vulnerability scanning solutions like Qualys, Foundstone, Nexpose * Prior working experience in a pharmaceutical company is preferred. * Highly organized, results-oriented and attentive to details. * Self-motivated, proactive, independent and responsive – requires little supervisory attention. * Excellent presentation, facilitation and diplomacy skills. * Able to perform other duties as assigned. * Ability to document technical solutions with excellent grammar. --- ## IT, Cybersecurity Salaries on the Rise URL: https://securityorb.com/it-cybersecurity-salaries-on-the-rise/ Type: post Modified: 2016-01-19 In-demand IT professionals like Jonathan Villa, a senior cloud security architect for an IT security firm in the Midwest, gets unsolicited job offers all the time. “I received a LinkedIn message this morning for an opportunity paying up to $200K plus bonus,” he told SHRM Online via LinkedIn. He said the job description read “any skills/experience with cybersecurity is a plus.” A lot of other IT professionals who have profiles on LinkedIn are similarly bombarded by recruiters with lucrative salary and bonus offers for jobs in the technology field. And those offers aren’t likely to stop coming anytime soon. Studies show that tech workers are in demand. Very in demand. So much so that some can command $300,000 annual salaries. Plus bonuses. “I am contacted at least four to six times a week and have seen [stints] where I am contacted every day,” Villa said. “I've been contacted by recruiting firms as well as directly by company recruiters for large companies (Target, Netflix, Chase, Wells Fargo, Sony, and more).” IT and cybersecurity salaries are on the rise, according to recent studies by Menlo Park, Calif.-based HR consultancy Robert Half and Manchester, Conn.-based cybersecurity recruiting firm SilverBull. At the high end of the scale, Robert Half lists the average salary for chief information officer (CIO) at $268,250—a nearly 5 percent increase from 2015. Mobile app developers can earn up to an average of $175,750 annually, an 8.2 percent increase from 2015. At the low end, technical writers can earn up to an average of $87,250, a nearly 2 percent increase from 2015. SilverBull lists its salary information by region. For example, it states that a chief information security officer (CISO) living in San Francisco can earn up to an average of $380,000 annually. That same CISO can earn up to an average of $334,000 in Washington, D.C., or an average of up to $328,000 in Chicago. In the year ahead, Robert Half’s 2016 Salary Guide for Technology Professionals states, those in the financial services, managed services, telecommunications, health care and hospitality sectors will be most in demand. The positions these individuals will hold? Business analysts, quality assurance professionals, systems engineers and systems administrators, help desk and desktop support staff, and database administrators and business intelligence analysts. Recruiting those people can be hard. “So many IT-related positions are being created that employers throughout North America and across industries often must wait months to staff key roles,” Robert Half states in its report. “Competition among businesses for top IT talent today makes it critical for managers to rethink their recruitment and retention methods,” according to the report. “Speeding up hiring times, training from within, filling skills gaps with project professionals and offering attractive compensation can help you hire—and keep—the best and brightest for your organization.” As Forbes reported earlier this year, “Research firm IDC predicts that by 2018, fully 75 percent of chief security officers and chief information security officers will report directly to the CEO, not the CIO. “When CISO positions elevate to the C-Suite alongside chief financial officers and chief operating officers, it will arguably move the salary needle into the half-million dollar range for some,” Forbes stated. Robert Half also points out that the high salaries may hinder some companies from getting the senior-level technology talent they need. So, many companies are training existing employees to fill those roles. But why so much money? “The technology landscape has widened, and the IT professionals that command the higher salaries have a skill set that spans the expanded horizon,” Villa said. “I would compare it to features in a vehicle. If you want to be able to heat and cool your seats, you're definitely going to pay for it.” He added that many IT professionals are considering more than just salary when it comes to accepting a job offer. “For example, I've considered work-from-home policies, the culture of the company in regard to whether or not they work on newer technologies, the title of the position, and even their use of Apple or Microsoft products.” Having cybersecurity or cloud experience makes potential candidates even more valuable, Villa said. IT Recruitment Strategies “One of the best ways to approach the shortage of highly skilled talent is to build a reputation as an employer of choice,” Robert Half states in its report. It said companies can do that by: Paying at or above market salaries for top talent. Providing exciting and challenging assignments. Fostering a corporate culture where innovation is crucial and business and technology are intertwined. Making sure technology professionals have the latest tools. Promoting flexible schedules and remote working arrangements. Offering professional development opportunities Showing a clear path for growth and promotion. Listening to employees and taking action on their requests, as appropriate. Establishing a strong employee referral program. Aliah D. Wright is an online editor and manager for SHRM. You can reach her via Twitter @1SHRMScribe and on Facebook at aliahwrites. --- ## The SecurityOrb Show – An Interview with Marcus J. Carey Founder of vThreat: A Cyber-Attack Simulation Company URL: https://securityorb.com/vthreat-a-cyber-attack-simulation-service/ Type: post Modified: 2016-01-11 Listen to what Marcus has to say here: /Podcast/SecurityOrbShow_20160108_MarcusJCarey_vThreat.mp3 Cyber-attack simulation is the practice of testing an organization’s network security and incident response preparedness on-demand and without exploits to determine an organization’s security posture. Cyber-attack simulation differs from many of the current and already practiced security controls such as Penetration Testing (pentesting), security assessment and table-top exercises. For example, pentesting makes use of exploitation code whereas cyber-attack simulation does not. In addition, cyber-attack simulation differs from a security assessments since the breach method used may not be from an actual vulnerability, it maybe in policy deficiencies or human-error. While in a table-top exercise a rehearsal of what your organization will do in the case of an emergency is conducted, but in a cyber-attack simulation it replicates the actions of an attacker. securityorb.com/ had the opportunity to interview Marcus j. Carey, the founder of vThreat, a cyberattack simulation start-up that offers its cyberattack simulation as a software-as-a service (SaaS) application. Carey stated, “Vthreat offers its service on-demand, you can conduct an attack simulation anytime. You do not have to wait annually or quarterly as with some of the other services.” vThreat has a free tier as well as paid tier delivery for its cyber-attack simulation service. One key attribute of vThreat’s cyber-attack simulation offering pertains to the non-use of software agents on organizational assets, instead they make use of the cloud or java-script snippets. Listen to the full interview with vThreat Founder, Marcus J. Carey here. If you will like to meet Marcus to obtain more information about his Cyber-Attack Simulation service, he will be attending the upcoming ShmooCon 2016 on Jan. 15 to 17 at the Washington Hilton Hotel in Washington, DC.   --- ## My Security Thoughts – Your Cell Phone URL: https://securityorb.com/my-security-thoughts-your-cell-phone/ Type: post Modified: 2016-01-04 Melvin: I know that I am old. I remember when you had to be at home for someone to reach you by phone. I remember when you paid for everything with either cash or check, well you had credit cards but it was mostly cash or checks. Oh yeah airline tickets were paper. For that matter all of your documents were paper. Now thanks to advances in technology we can put all of that on your cell phone. Yes every piece of identifying documentation can go on your phone. All of your financial transactions can be done via your phone within the next 5 years. Think of it the police pull you over for speeding you bring up your license and registration on the phone and hand it to them to scan into the system. They may even be able to bill you right there on the spot and you pay with a tap on the screen. You can even unlock your doors at home with your phone. Soon all cars will be able to be unlocked and started via your phone. I am sure that I have left things out that can be done with your phone besides make calls, search the web, and post selfies. Which leads to why am I discussing cell phones on this forum. I feel that these phones are one of the greatest threats to personal security. The phones are growing to be the center of our lives. They will soon contain every aspect of our digital lives. It is a wave that will turn into a tsunami of unstoppable ingress into everyone’s lives. Now there are some that might say that the average wallet of an American contained their lives. Not only might there be a driver’s license but you could also find a social security card, health insurance card, credit cards, ATM cards, and possibly phone numbers. As a side note, are there any out there like me that cannot remember phone numbers now that we have the contact lists on our phones. I search by name and never see the phone number. Does that mean that the smart phone is making me dumber? Probably. Okay back to the discussion, even with the wallet and lets not discuss a woman’s purse, I still feel that there is more stored on a smart phone then can ever be placed into a similar physical space carried on one’s person. Thoughts?   Brian: You are correct on a number of issues – first, I can’t remember anyone’s phone number, or birthday, or E-mail – all of that is in the phone – heck, it’s to the point that I don’t recognize the number unless the phone tells me who it is that is calling – I have better things to dedicate those neurons to. I figure whomever is calling will leave a message, and I’ll listen in – if I can… And answer if it’s someone I want to talk to. One of the advantages of the old answering machines on an old land-line, well that and the fact that they worked without electricity (they used something like 6 volts over the old copper wire) – now that everything is a packet – my land line sends via Ethernet – so if power is out, the hub is down, or overloaded. Phone is useless when power is out today… Remember 9/11 and all of the busy-signals? Expect that to be the norm in any emergency these days… Unless you have a satellite phone – then you may be able to reach someone that is outside of the area affected… But your cell will be as useful as a rock. I remember being in a cave (Carlsbad) and some idiot in the group pulled out his cell phone to call his wife… Are people really that dumb? Um, you’re underground, I think the area was like 164 feet underground, your cell phone can barely go through the walls of your house, and you want to call your wife? Although these days they probably have an access point that goes over the wire up to the surface – but they didn’t back then… Of course, I was the guy on the tour that wore a glow in the dark tee-shirt, so when they tried to show was “real darkness” looks like, I could see people and they were all looking at ME… Then I looked down and saw my little bats glowing on my shirt… D’uh… Anyway, as far as security – encrypt, encrypt, encrypt… (And I mean that literally, if you can – multiple encryption methods.) I’ve taken to running hashes on passphrases so if someone tries to force me to reveal the password, I can honestly say that I don’t know the password. True – I know what will yield a hash. And while the law can force you to yield a password, they cannot force you to take an action, or reveal a procedure. (That’s to protect you from being forced to commit a crime, then be charged for it, so if you have to call a program to generate a hash from the passphrase – that you then cut and paste the 128 character string generated to decrypt your drive, you cannot be forced to tell them that process – and if your hash is then simply ROT-64 encoded, hey – it’s not your fault they can’t get that pass-phrase to work.) Anyway… My passphrases all a miss-spelled phrase, including numbers, and keyboard positions so I may know the pattern, but not the keys. So I literally cannot “write down” the pass-phrase doesn’t matter how much I want to I can’t do it. Now that’s a bit much for a cell phone – but we’re getting close to needing something like that… Scan your fingerprint, scan your IRIS, and it’s in standby so you have to enter a swipe-pattern… Anyway – treat your phone like you do your IRS software – I’m assuming that you have all of that data multiply encrypted as well. And if you have a phone for your family, you should be establishing encrypted communication tunnels. If it’s good for the military – it’s good for you… I’ve always lived by the phrase, “just because you’re paranoid, doesn’t mean someone isn’t out to get you”… Heck, I have Tor on my phone, and recently added a VPN… Yes, it’s slow – so I’ll use the VPN most of the time, but some searches, I want to keep to myself – that is what Tor is for.. That’s why I have USB sticks that boot up computer systems at home – no traces… Yeah, you can do forensics all you want – good luck with that… The only down side to all of the above is I had a drive die that wasn’t being backed up – couldn’t even get one of the latest forensic tools to see the partition on the drive… Can’t read something that you can’t see… I’ve been looking for tools like peer-block for my phone – the CPU is fast enough to monitor comms, so there should be tools to do it…   Melvin: I agree with you that encryption is the key. You have no other option to protect your data on your electronic device. I just assume that if they want to get into my gear then they probably can with enough time and effort. I also assume that strong encryption will protect my data. Now I don’t believe that they can force you to reveal your password. I believe that you cannot self incriminate. You can be forced to use your finger to unlock your phone if you enable that feature. I, myself, do not have that feature enabled. I know that I am not as hardcore as Brian but I have started using a VPN application even when at home. It also gives me a certain level of comfort to use my laptop at Starbucks. Though I still will not do any online shopping or banking. This conversation has made me think of other things that people are using their phones to accomplish. One of those is the use of the phone as a key. Drone Mobile and Viper are two vendors that have products that will allow you to unlock, start, and track your vehicle. Tesla has an app for iPhone that allows remote start. It just seems to me that if you lose your phone or it is stolen your car, data, and electronic wallet could be lost to you. Sad part is how many people know their master passwords so that they can start to get back to normal. How many people backup their phones so that they can restore to a new phone? I am seeing an avoidable trend of using the smart phone to control or store every aspect of a person’s life. What will be the outcome when people ‘s phones are compromised? I don’t even want to guess.   Tony: Hmm, I would separate personal security into two categories - 1) physical security and 2) information security. Arguably, phones do not do hurt are physical security in any way. My wallet is still more important than my phone to the average criminal. In fact, I would be safer if the criminal knew I only had a phone and no wallet; that way the reward or payoff would be much less certain for the criminal…no immediate cash or credit card payoff. The phone provides a much greater physical barrier to information than my wallet…access barriers are a big deterrent to the criminal element. +1 phones Information security is a much bigger issue and certainly not limited to phones, but I agree, it is hard to argue against the information security risk presented by phones, they contain a lot of information. Basically, it is the price you pay for having all your data at your finger-tips…there is no *free* lunch. However, I think the risk is greatly mitigated by biometric access, lock screens and other mechanisms like that. I mean, who does not password protect their phone these days? What phone OS does not provide a remote security-wipe feature? This is common stuff and it will probably get better with features that track your location or your biometrics (i.e., how far is the phone from your Fitbit?) I envision lots of cool stuff in the future with respect to securing access to the phone. Bottomline, it is pretty good now and going to get much better in the future. +1 phones Ok, I cannot help but laugh a little about smartphones making people dumber. Well, if access to information makes you dumber than…yeah I guess it does. The whole notion of attaching a number to a person is a bit wonky anyway. The goal is to communicate with the other person…not to remember numbers? The phone just provides access to a variety of mechanisms to communicate with the other person. The “number” is a detail that should not be so prominent/important. Plus, numbers just do not scale well and is definitely a very limited abstraction for “communication”. I mean c’mon…Captain Kirk probably does not know Spock’s or Scotty’s number…oh…wait…1-ENT-ERP-RISE! Comments? --- ## Security vs Privacy: Encryption Technology After the Paris Attack URL: https://securityorb.com/7662-2/ Type: post Modified: 2015-11-21 Security vs Privacy: Encryption Technology After the Paris Attack In the wake of the Paris attack, a healthy discussion about security and privacy has been revisited and the discussion is centered on encryption technology. So what is “Encryption”? Encryption is the process of encoding a message so that only the sender and the intended recipient or recipients can read it. Law enforcement and Intelligence officials claim, terrorist are taking advantage of the “end-to-end” encryption communication technology on iPhones and Android-based phones as well as apps like WhatsApp and iMessage to name a few. Now they are asking Silicon Valley to weaken its encryption or provide a backdoor so they can better monitor malicious activities. The problem is, let’s say law enforcement were to provide a search warrant to Apple so they can access your email. Apple would reply stating, “Sorry, we can’t help you, we do not have access to the data, you will have to get the key from the person of interest. They are the only one that can access the information”. They push for this level of privacy started in 2013 due to Edward Snowden revelations on how the National Security Agency (NSA) were spying and collection our information. Since then the newer operating systems on phones made by Apple and Google can’t be unlocked without the user passcode, not even by the companies themselves. Law enforcement see this as a potential danger and are looking for legislation to change the current practices, but security and privacy professional state, even if Apple and Google could be convinced to cooperate, tech executives say there are dozens of other encrypted communication systems. Most encryption techniques are publicly known and terror organizations could build their own alternatives. Furthermore, many privacy advocates fear backdoors and encryption escrow keys can allow other countries and hackers with a vector to crack the code if it is not totally secure. Before the Paris attack, it was nearly impossible for law enforcement and intelligence officials to talk about weaken decryption for surveillance matter due to Snowden revelations, but since then, there is a serious and open dialog about this matter. ISIS ranking of encryption apps.             What is your opinion? Should we give up some of our privacy in hope for better security or should we keep our privacy and maybe compromise our security?  Let me know. --- ## The Heartbleed Bug URL: https://securityorb.com/the-heartbleed-bug/ Type: post Modified: 2015-11-01   The Heartbleed Bug The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs). The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users. What leaks in practice? We have tested some of our own services from attacker’s perspective. We attacked ourselves from outside, without leaving a trace. Without using any privileged information or credentials we were able steal from ourselves the secret keys used for our X.509 certificates, user names and passwords, instant messages, emails and business critical documents and communication. How to stop the leak? As long as the vulnerable version of OpenSSL is in use it can be abused. Fixed OpenSSL has been released and now it has to be deployed. Operating system vendors and distribution, appliance vendors, independent software vendors have to adopt the fix and notify their users. Service providers and users have to install the fix as it becomes available for the operating systems, networked appliances and software they use. Source: HeartBleed --- ## The SecurityOrb Show - An Interview with ISSA-LA President Richard Greenberg URL: https://securityorb.com/the-securityorb-show-an-interview-with-issa-la-president-richard-greenberg/ Type: post Modified: 2015-10-25 The SecurityOrb Show - An Interview with ISSA-LA President Richard Greenberg /Podcast/ISSA_LA_Richard_Greenberg.mp3   I had an opportunity the current ISSA-LA President Richard Greenberg. Richard holds the CISSP certification and was the the Security Summit 2015 Co-Chair and an ISSA Fellow. He is the Information Security Officer for the Los Angeles County Department of Public Health. Previous positions include Director of Surveillance and Information Systems, Chief of Security Operations, Director of IT, and Project Manager for various companies/agencies. --- ## National Cyber Security Awareness Month Kicks Off URL: https://securityorb.com/national-cyber-security-awareness-month-kicks-off/ Type: post Modified: 2015-10-01 National Cyber Security Awareness Month Kicks Off As Growing Global Coalition Urges Internet Users Everywhere To STOP. THINK. CONNECT. Coordinated Message to Get #CyberAware Impacts Millions as Individuals, Groups and Businesses Unite to Better Protect the Internet; Organization of American States Hosts Launch Event in Washington, D.C. WASHINGTON, D.C., Oct. 1, 2015 – The 2015 National Cyber Security Awareness Month (NCSAM) kicks off emphasizing “Our Shared Responsibility,” the month’s official theme and call to action for all global citizens to take basic steps to make the Internet – a vital resource for our personal, public and professional lives – safer and more secure. Led by the National Cyber Security Alliance (NCSA), the nation's leading nonprofit, public-private partnership promoting online safety, and the U.S. Department of Homeland Security (DHS), NCSAM marks its 12thanniversary this October. Launching the month with the recognition that securing the Internet is a global imperative, the General Secretariat of the Organization of American States (OAS) will also host an international event in Washington, D.C. promoting a culture of cybersecurity among its member states’ 250 million Internet users in Latin America and the Caribbean as well as other countries around the globe. OAS is a long-time STOP. THINK. CONNECT. partner and has championed participation in education and awareness by a diverse group of stakeholders in Latin America. The theme of the month resonates with young people internationally. According to the recently released Cyber Safety for the Digital Generation survey by the Raytheon Company, 82 percent of young adults globally believe that keeping the Internet safe and secure is our shared responsibility. They are clear on the roles everyone should play in keeping them safe and secure online: 75 percent think they themselves should be significantly involved; 69 percent think the commercial websites they visit and use should be significantly involved; 51 percent think the government should be significantly involved; 47 percent think the people they interact with on social networks should be significantly involved. “We live in a global, digital age where people, networks and devices are increasingly interconnected, and everyone needs to be taking steps to use the Internet safely and more securely,” said Michael Kaiser, NCSA’s executive director. “Practicing good cybersecurity empowers Internet users to reap the benefits of connectivity with greater confidence. National Cyber Security Awareness Month succeeds when we work together to build a safer, more secure and trusted Internet. Awareness month is a must.” NCSAM 2015 also marks the fifth anniversary of STOP. THINK. CONNECT., the preeminent global cybersecurity education and awareness campaign. Driven by NCSA, the Anti-Phishing Working Group (APWG) and DHS, which leads the federal government’s campaign, STOP. THINK. CONNECT. continues to extend its international impact with a simple but increasingly important message to stay safer and more secure online. The campaign’s partners include 271 large companies, small- and medium-sized businesses, colleges and universities, regional banks and a collection of other organizations as official partners. Currently, STOP. THINK. CONNECT. has official partnerships in Canada, Australia, Panama, the European Union, India, Japan, Mexico and other countries and regions, with its materials translated into five languages — Spanish, French (Canadian), Portuguese (Brazilian), Japanese and Russian — and several more translations on the way. Check out NCSA’s new infographic, “5 Years of STC” and learn more about how to get involved: http://ncsam.info/1JCDXlT “While NCSA and its many partners work year round to create awareness around the safe and secure use of the Internet, National Cyber Security Awareness Month unites everyone in a concentrated effort to promote a culture of cybersecurity in everything we do,” said Jacqueline Beauchere, Chief Online Safety Officer of Microsoft and Chair of NCSA’s Board of Directors. “We are thrilled to see the adoption of Cybersecurity Awareness Month and STOP. THINK. CONNECT. across the globe. When industry, government and civil society work together, we can help every digital citizen access and act on the information they need to be safer and more secure online.” Ready, Set, Get #CyberAware Under the umbrella theme of “Our Shared Responsibility,” NCSAM 2015 will explore five weekly themes addressing a cross section of cybersecurity issues. They include STOP. THINK. CONNECT., cybersecurity in the workplace, connected communities and families, our evolving digital lives/the Internet of Things and building the next generation of cyber professionals. Individuals and companies and organizations of all sizes can show their support for NCSAM by becoming a Champion. Currently there are more than 475 NCSAM Champions who will play an active role in sharing important cybersecurity messages with their local communities, corporations, governments and individuals internationally. For more information on how to become a champion, visit https://www.staysafeonline.org/ncsam/champions. Using the new hashtag, #CyberAware, NCSAM’s Champions and supporters are also encouraged to join the conversation by posting tips, advice and information and participating in weekly Twitter chats occurring every Thursday at 3:00p.m. EDT and keeping up on the latest updates on http://www.facebook.com/staysafeonline. To stay safer online everyone should implement these simple, actionable steps: Keep a clean machine: Keeping all web-connected devices ‒ including PCs, mobile phones, smartphones, and tablets ‒ free from malware and infections makes the Internet safer for you and more secure for everyone. Get two steps ahead: Turn on two-step authentication ‒ also known as two-step verification or multi-factor authentication ‒ on accounts where available. When in doubt, throw it out: Links in email, posts and texts are often the ways cybercriminals try to steal your information or infect your devices. Share with care: Before posting something online, think about how it could be perceived now and in the future. Check out NCSA’s tips infographic: http://ncsam.info/1VoT4X7. A snapshot of some early NCSAM events include: #ChatSTC Twitter Chat: STOP. THINK. CONNECT. Around The Digital World (Twitter chat), October 1, 3-4 p.m. EDT/12-1 p.m. PDT.  Learn more at: https://www.staysafeonline.org/about-us/events/#sthash.jinX5kVD.dpuf OAS Cyber Security Workshop, October 2: The OAS Cyber Security Program will hold a plenary session along with SEGURINFO to launch the Cybersecurity Awareness Month. The event will focus on a discussion on the role of industries, nonprofits, and academia in raising awareness about cyber security matters among society and fostering a cybersecurity culture. Click here to register:https://www.sites.oas.org/cyber/EN/Pages/Events/eventsdet.aspx?docid=72 U.S. Chamber’s Fourth Annual Cybersecurity Summit, October 6, 8:30a.m. - 4:00p.m. EDT, Washington, D.C.: The U.S. Chamber of Commerce is pleased to host the Fourth Annual Cybersecurity Summit to explore the latest threat landscape, market-based and public-private solutions and the new framework. The summit will feature speakers from the business community, international experts, the administration and Congress. Additional information and registration here EDUCAUSE Live! Creating a Culture of Cybersecurity and Safety on Your Campus and in Your Community (webinar), October 6, 1-2 p.m. EDT/10-11 a.m. PDT. Awareness and education are key elements of creating a culture of safety on campus. Campuses have also participated in NCSAM activities over the past decade, including Texas A&M University. Learn more about their most recent security awareness campaigns, Fight Back and What's Your Status, and how they educate students, faculty and staff in October and year round. Presenters: Michael Kaiser, Executive Director, NCSA; Suzanne Traxler, Chief Information Officer, University of Wisconsin-Platteville; Allison Oslund, IT Product Strategy and Communication, Texas A&M University. Additional information and registration here Visit NCSAM’s Media Resource Hub for more information on activities and events throughout the month. Additional resources (infographics, tip sheets, media kit and more) and information on getting involved are also available at https://www.staysafeonline.org/ncsam/ No matter what audiences you are trying to reach ‒ young people, seniors, businesses or families ‒ there are resources available to help you. Visit any of these sites to get started: NCSA: https://www.staysafeonline.org DHS: http://www.dhs.gov/topic/cybersecurity FTC: https://www.ftc.gov/tips-advice/business-center/privacy-and-security/data-security BBB: http://www.bbb.org/council/for-businesses/toolkits/ About National Cyber Security Awareness Month National Cyber Security Awareness Month (NCSAM) was created as a collaborative effort between government and industry to ensure every American has the resources they need to stay safer and more secure online. Now in its 12th year, NCSAM is co-led by the Department of Homeland Security and the National Cyber Security Alliance, the nation's leading nonprofit public-private partnership promoting the safe and secure use of the Internet and digital privacy. Recognized annually in October, NCSAM involves the participation of a multitude of industry leaders ‒ mobilizing individuals, small- and medium-sized businesses, non-profits, academia, multinational corporations and governments. Encouraging digital citizen around the globe to STOP. THINK. CONNECT., NCSAM is harnessing the collective impact of its programs and resources to increase awareness about today’s ever-evolving cybersecurity landscape. Visit the NCSAM media room: https://www.staysafeonline.org/about-us/news/media-room/ About The National Cyber Security Alliance The National Cyber Security Alliance (NCSA) is the nation's leading nonprofit public-private partnership promoting the safe and secure use of the Internet and digital privacy. Working with the Department of Homeland Security (DHS), private sector sponsors and nonprofit collaborators to promote cybersecurity awareness, NCSA board members include representatives from ADP, AT&T, Bank of America, BlackBerry, Comcast Corporation, EMC Corporation, ESET, Facebook, Google, Intel, Logical Operations, Microsoft, PayPal, PKWARE, Raytheon, Symantec, Verizon and Visa. Through collaboration with the government, corporate, nonprofit and academic sectors, NCSA's mission is to educate and empower digital citizens to use the Internet securely and safely, protect themselves and the technology they use, and safeguard the digital assets we all share. NCSA leads initiatives for STOP. THINK. CONNECT., a global cybersecurity awareness campaign to help all digital citizens stay safer and more secure online; Data Privacy Day, celebrated annually on January 28 and National Cyber Security Awareness Month, launched every October. For more information on NCSA, please visit staysafeonline.org/about-us/overview/. About STOP. THINK. CONNECT.
 STOP. THINK. CONNECT. is the national cybersecurity education and awareness campaign. The campaign was created by an unprecedented coalition of private companies, non-profits and government organizations with leadership provided by the National Cyber Security Alliance (NCSA) and the Anti-Phishing Working Group (APWG).  The Department of Homeland Security leads the federal engagement in the campaign. Learn how to get involved at STOPTHINKCONNECT.org. Media Contact Tola St. Matthew-Daniel Thatcher+Co. 917-818-6196 ncsa@thatcherandco.com --- ## Obama, Xi vow cooperation on cybersecurity URL: https://securityorb.com/obama-xi-vow-cooperation-on-cybersecurity/ Type: post Modified: 2015-09-25   WASHINGTON — President Obama and Chinese counterpart Xi Jinping vowed Friday not to engage in economic cyber espionage, to cooperate more on climate change, and to work out disputes in the South China Sea region while indicating that differences remain in what has become a tense relationship between key global powers. Obama said he told Xi about the "serious concerns" that U.S. officials and businesses have over cyberspying by China, and "I indicated that it has to stop." He said the two nations have reached "a common understanding" against certain cyber activities, but "I have to insist that our work is not yet done" and "the question now is are words followed by actions." The United States and China have also struck a renewed deal to battle climate change, and to open "new channels of communications" designed to avoid confrontations between American and Chinese surveillance flights over the South China Sea, Obama said. "The United States welcomes the rise of a China that is peaceful, stable, prosperous and a responsible player in global affairs," the president said during Xi's state visit. "And I'm committed to expanding our cooperation even as we address disagreements candidly and constructively." Xi, speaking with an interpreter, described his talks with Obama as "constructive and productive," deigned to avoid "conflict" and "confrontation." He also praised the planned cooperation on climate change. Urging "dialogue" on the question of cybersecurity, Xi said that "confrontation and friction are the not the right course." As for the South China Sea, Xi said China would respect lawful surveillance flights but would also protect "territorial sovereignty" as U.S. allies protest the apparent development of Chinese military bases in the region. Read more here. --- ## DerbyCon 2015 Keynote/Track 2 Live Stream URL: https://securityorb.com/derbycon-2015-keynote-live-stream/ Type: post Modified: 2015-09-25 --- ## Cyberattack 101: Why Hackers Are Going After Universities URL: https://securityorb.com/cyberattack-101-why-hackers-are-going-after-universities/ Type: post Modified: 2015-09-21 Cyberattack 101: Why Hackers Are Going After Universities   With their vast stores of personal data and expensive research, universities are prime targets for hackers looking to graduate from swiping credit card numbers. Read more here. --- ## Glossary of Computer and Security Terms URL: https://securityorb.com/glossary-of-security-terms/ Type: post Modified: 2015-09-18 Glossary of Computer and Security Terms Avatar—a personalized graphic file or rendering that represents a computer user or user’s alter ego, often used on Web exchange boards and in online gaming; can be a real-life digital photo, but is more often a graphical representation. App—a web application, accessed over the Internet, for a mobile device (e.g., smartphone, tablet) that works much like user-installed software on a computer allowing the device to perform specific tasks. Bandwidth –also called “data transfer rate,” the amount of data that can be carried online from one point to another in a given time period, usually expressed in bits (of data) per second (bps) or bytes per second (Bps). Dial-up Internet accounts, which use a standard telephone line to connect to an Internet Service Provider (ISP), have a very narrow bandwidth (about 50 Kbps or 50,000 bits per second) and take a long time to download data. A broadband Internet account can move data at anywhere from 128 Kbps to 2,000 Kbps or more and can download large files, such as video files, much faster. Blog—from “web log,” a regularly updated personal journal, conversation, commentary, or news forum on virtually any topic that is published on the Web and may include text, hypertext, images, and links; typically displayed in reverse chronological order, blog posts invite comments from readers creating online communities of individuals with shared interests over time; updating a blog is “blogging,” someone who keeps a blog is a “blogger,” and blog entries are called “posts.” Botnet—a network of private computers, each of which is called a “bot,” infected with malicious software (malware) and controlled as a group without the owners' knowledge for nefarious and, often, criminal purposes; computers are typically infected when users open up an infected attachment or visit an infected website. Browser—short for Web browser, a software application that locates, retrieves, and displays information resources on the World Wide Web. An information resource is identified by a URL (Uniform Resource Locator), and may be a web page, image, video, or other piece of content. Popular browsers include Microsoft Internet Explorer, Firefox, Google Chrome, and Apple Safari. Byte—a unit of digital information commonly consisting of eight “bits” (a binary unit and the smallest increment of computer data) used as a measurement of computer memory size and storage capacity (usually in terms of MBs or “megabytes,” and GBs or “gigabytes”). Bits and bit rates (bits over time, as in bits per second [bps]) are also commonly used to describe connection speeds. (See bandwidth.) Cloud computing—a technology that uses the Internet and remote servers to maintain data and applications, allowing users to access applications without installation and access to their personal files from any computer with Internet access; centralizes storage, memory, processing, and bandwidth; examples include Yahoo email or Gmail with the software managed by the cloud service providers Yahoo and Google. Computer virus—a software program that is designed to replicate itself, spread from one computer to another, and interfere with computer operation; a computer virus may corrupt or delete data on a user’s computer, use an email program to spread itself to other computers, or even erase everything on a user’s hard disk. Computer viruses can be spread by attachments in email messages or instant messaging messages; disguised as attachments of images, greeting cards, or audio and video files, and hidden in illicit software or programs that are downloaded to a computer. Cookie—also referred to as an “HTTP cookie,” is a small text file that contains a unique ID tag placed on the user’s computer by a Web site to track pages visited on the site and other information; “tracking cookies” and “third-party tracking cookies” are used to compile long-term records of individuals’ browsing histories. CPU—the central processing unit, the “brain” of the computer, is the hardware within a computer system that carries out the instructions of a computer program by performing the basic arithmetic, logic, and other operations of the system; on personal computers, the CPU is housed in a single chip called a “microprocessor.” Cyberbullying—bullying that takes place using electronic technology, including the Internet, and related technologies to harm other people, in a deliberate, repeated, and hostile manner; may involve text messages or emails, rumors sent by email or posted on social networking sites, and embarrassing pictures, videos, Web sites, or fake profiles. Cyberstalking—a criminal offense that involves using the Internet or other technology to stalk or harass an individual, a group of individuals, or an organization; it may include false accusations, monitoring, making threats, identity theft, damage to data or equipment, or harassment. Cyberspace—the global network of interdependent information technology infrastructures, telecommunications networks, and computer processing systems; a metaphor for describing the non-physical terrain created by computer systems, it has come to mean anything associated with the Internet and the diverse Internet culture. Content management system—a software system that allows website publishing, editing, content storage and modification, database management, and site maintenance from a central Web page; allows multiple users with little knowledge of web programming or markup languages may collaborate to create and manage website content with relative ease. Computer actions: Clicking—to tap on a mouse button, press it down, and immediate releasing it; to click on means to select a computer screen object by moving the mouse pointer to the object’s position and clicking a mouse button; some operations require a double click, clicking a mouse button twice in rapid succession. Downloading—the transmission of a file from one computer system to another; to download a file is to request it from one computer (or from a Web page) and to receive it on another computer. Uploading is the transmission of a file in the other direction, from one computer to another. Posting—to publish a message in an online forum, such as a blog, or newsgroup; a post is a message published in an online forum or newsgroup. Logon—also called logging in or on, the process used to get access to an operating system or application; most logon procedures require a user to have a user ID and a password. Denial of Service Attack—type of online computer attack designed to deprive user or groups of users normally accessible online services; generally involves effort by hackers to temporarily or indefinitely interrupt or suspend services of a host connected to the Internet. Digital—term commonly used in computing and electronics, describes any system in which data is converted to binary numeric form as in digital audio and digital photography; computers are digital machines because at their most basic level they can distinguish between just two values, 0 and 1, or off and on. All data that a computer processes must be encoded digitally as a series of zeroes and ones. The opposite of digital is analog; a typical analog device is a clock in which the hands move continuously around the face. Digital Signature—an electronic signature that can be used to authenticate the identity of the sender of a message or the signer of a document; can also be used to ensure that the original content of the message or document that has been sent is unchanged; often used for software distribution, financial transactions, and in other cases where it is important to detect forgery or tampering. Domain Name System (DNS)—a database system that translates Internet domain and host names to IP addresses; DNS automatically converts the name typed into a Web browser address bar to the IP addresses of Web servers hosting those sites. E-book reader—a portable electronic device that is designed primarily for the purpose of reading digital books and periodicals. Email—short for electronic mail, the transmission of digital messages over communications networks, including the Internet; consists of three components: the message envelope, the message header, and the message body. Encryption—the conversion of digital information into a format unreadable to anyone except those possessing a “key” through which the encrypted information is converted back into its original form (decryption), making it readable again. Firewall—software or hardware that, after checking information coming into a computer from the Internet or an external network, either blocks the transmission or allows it to pass through, depending on the pre-set firewall settings, preventing access by hackers and malicious software ; often offered through computer operating systems. Geotagging—the process of adding geographical location, or label, to photographs, videos, website, SMS messages, QR Codes, or RSS feeds; a geotag usually consists of latitude and longitude coordinates, altitude, distance, place names, and other details about the origin of the media being tagged helping users find a variety of online location-specific information. Global Positioning System (GPS)—space-based satellite navigation system that provides positioning, navigation, and timing/distance information; maintained by the United States government and freely accessible to anyone with a GPS receiver. Hardware—specifically, computer hardware, is the collection of physical elements that comprise a computer system, including a CPU, monitor, keyboard, hard disk, and printer. In contrast, software (specifically, computer software) is a collection of computer programs, procedures, algorithms, and its documentation that provides instructions for telling a computer what to do and how to do it. Hashtag—words or phrases prefixed with the symbol # (the pound sign); used to mark keywords or topics in a Tweet or social networking service. Hyperlink—an element in an electronic document that links to another place in the same document or to an entirely different document; typically, you click on the hyperlink to follow the link. Hypertext is text with hyperlinks. HTML—HyperText Markup Language is the main markup language for displaying web pages and other information that can be displayed in a web browser; HTML elements, which form the building blocks of all Web sites, consist of tags enclosed in angle brackets (e.g.,); browsers do not display the HTML tags, which provide instructions about the appearance and content of the page, but use the tags to interpret the content of the page. HTTP—Hypertext Transfer Protocol, the foundation of data communication for the World Wide Web, defines how messages are formatted and transmitted, and what actions Web servers and browsers should take in response to various commands. For example, when an URL is entered into a browser, an HTTP command is sent to the Web server directing it to retrieve and transmit the requested Web page. HTTPS—Hypertext Transfer Protocol Secure, provides secure communication over a network, such as the Internet; basically layers additional security measures over HTTP; used by financial and online commerce Web sites to ensure the security of private information. IP Address—a unique identifier in the form of a numerical label assigned to each device, such as a personal computer or server, participating in a network, such as the Internet. Intellectual property—usually governed by patent, trademark, and copyright law, a set of rights that are recognized for owners of various property (e.g., machines, musical, literary and artistic works, discoveries and inventions, and applications); applicability to digital realm is hotly contested area of the law. Internet—a worldwide collection of computer networks that use the standard Internet Protocol Suite to serve billions of users interconnected by a broad array of electronic, wireless, and optical networking technologies; the Internet carries an extensive range of information resources and services, including inter-linked hypertext documents of the World Wide Web and the infrastructure to support email. Internet Service Provider (ISP)—an organization, usually a private business, that provides personal and business computers access to the Internet; users usually pay a monthly fee to an ISP for this service. Keylogger—also called keylogging and keystroke logging, is the action of tracking (or logging) the keys struck on a computer keyboard; usually runs hidden in the background and automatically records all keystrokes so that users are unaware of its presence and that their actions are being monitored. Keyword—in computer programming, a word or identifier that has a particular meaning to the programming language; also a term that captures the essence of the topic of a document used by a search engine to retrieve online documents related to that term or terms. JPEG—a standard method of compressing photographic images for storing and transmitting on the World Wide Web; JPEG is also the file format which employs this compression (with the following file extensions: .JPEG, .JFIF, .JPE, .JPG); the term is an acronym for Joint Photographic Experts Group, which created the standard. Laptop –a personal computer for mobile use that integrates most of the typical components of a desktop computer (i.e., display, keyboard, touchpad); sometimes called notebook computers, notebooks, or netbooks. Malware—short for malicious software, software that disrupts or damages a computer’s operation, gathers sensitive or private information, or gains access to private computer systems; may include botnets, viruses, worms, Trojans, keyloggers, spyware, adware, and rootkits. Botnet—a network of private computers, each of which is called a “bot,” infected with malicious software (malware) and controlled as a group without the owners' knowledge for nefarious and, often, criminal purposes. Virus—type of malware that has a reproductive capacity to transfer itself from one computer to another spreading infections between online devices. Worm—type of malware that replicates itself over and over within a computer. Trojan—type of malware that gives an unauthorized user access to a computer. Spyware—type of malware that quietly sends information about a user’s browsing and computing habits back to a server that gathers and saves data. Adware—type of malware that allows popup ads on a computer system, ultimately taking over a user’s Internet browsing. Rootkit—a type of malware that opens a permanent “back door” into a computer system; once installed, a rootkit will allow more and more viruses to infect a computer as various hackers find the vulnerable computer exposed and attack. Mobile device—also called a handheld, handheld device, or handheld computer, a pint-sized computer device, typically having a display screen with touch input or a miniature keyboard; most common types are smartphones, PDA, pagers, and personal navigation devices. Modem—an electronic device that converts a computer’s digital signals into specific frequencies to travel over telephone or cable television lines; computers use modems to communicate with one another over a network; often used to link home computers to the Internet through an Internet Service Provider. Network—also called a computer network, is a collection of computers interconnected by communication channels that allow sharing of resources (hardware, data, and software) and information; most common is the local area network or LAN, anywhere from a few computers in a small office to several thousand computer spread through dozens of buildings; a wide area network or WAN connects computers across multiple geographic locations, even on different continents. Online gaming—any type of game played through the Internet, over a computer network, or on a video game console (e.g., Xbox 360 and Playstation 3); usually refers to video games played over the Internet, where multiple players are in different geographic locations. Open source software—software often developed and distributed to users at no cost in a public, collaborative manner; permits users to study, change, improve, and at times also distribute the software. Operating system—a set of software or software platform on top of which other programs, called application programs, can run. PDF—developed by Adobe Systems, a portable document format file that is a self-contained cross-platform document so that files will look the same on the screen and in print, regardless of the computer or printer being used or software used to originally create the file. Personal computer (PC)—any general-purpose computer whose size, capabilities, and cost make it useful for individuals; PC software applications include, but are not limited to, word processing, spreadsheets, databases, databases, Web browsers, email, and games; may be a desktop computer, laptop, table, or a handheld PC. The term PC has been traditionally used to describe an “IBM-compatible” personal computer, in contrast to an Apple Macintosh computer. Phishing—sending emails that attempt to fraudulently acquire personal information, such as usernames, passwords, social security numbers, and credit card numbers, by masquerading as a trustworthy entity, such as a popular social website, financial site, or online payment processor; often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Plug-ins—sometimes called add-ons, are software modules that add functionality to an application; commonly used in web browsers to play video, scan for viruses, and display new file types; well-known plug-in examples include Adobe Flash Player, QuickTime, and Microsoft Silverlight. Podcast—an audio digital file that is received from the Internet and then downloaded and synced to a portable media player or computer; files are received by subscribing to a podcast feed (sometimes called an RSS feed); the term combines “broadcast” and “pod” from the success of the iPod, although podcasts can be listened to on any portable media player. Pop-ups—or pop-up ads, are a form of online advertising on the World Wide Web intended to attract web traffic or capture email addresses; created by advertisers, pop-ups generally appear unexpectedly in a small web browser window when a user is linking to a new Web site. Pop-up blockers—a web browser feature, software, or application that allows users to limit or block pop-up ads; users may often set the preferred level of blocking, from total blocking to minimal blocking. RSS—Really Simple Syndication is a family of web feed formats used to publish frequently updated works, such as blog entries, news headlines, audio, and video—in a standardized format; users subscribe to RSS feeds, which automatically send favorite content to users who have signed up for the feeds. Search engine—program that searches documents for specified keywords and returns a list of the documents where the keywords were found; often used to describe systems, including Google, Bing, and Yahoo! Search that enable users to search for documents on the World Wide Web. Security software—a generic term referring to any computer program that secures a computer system or computer network; the two main types of security software are virus protection software and software that removes adware and spyware (both require regular updating to remain effective). Server—a computer program or physical computer that services other computers over a local network or the Internet; network servers typically are configured with additional processing, memory, and storage capacity; specific to the Web, a Web server is a computer program (housed in a computer) that serves requested HTML pages or files. SMTP—Simple Mail Transfer Protocol is a protocol for sending e-email messages between servers. Smart phone—handheld device built on a mobile computing platform that features, typically, a digital camera, video camera, Global Positioning System (GPS), e-mail, and all the features of a standard cell phone; usually equipped with a high-definition, touch pad screen and miniature keyboard, smartphone allows downloading of apps for a wide range of uses. Social networking—using Internet-based tools that allow people to listen, interact, engage, and collaborate with each other; popular social networking platforms include Facebook, MySpace, YouTube, LinkedIn, and Twitter. Software—specifically, computer software, is a collection of computer programs, procedures, algorithms, and its documentation that provides instructions for telling a computer what to do and how to do it. In contrast, hardware (specifically, computer hardware) is the collection of physical elements that comprise a computer system, including a CPU, monitor, keyboard, hard disk, and printer. Spam—the use of electronic messaging systems to send unsolicited bulk messages (usually advertising or other irrelevant posts) to large lists of email addresses indiscriminately. Spyware—a type of malware (malicious software) installed on computers that collects information about users without their knowledge; can collect Internet surfing habits, user logins and passwords, bank or credit account information, and other data entered into a computer; often difficult to remove, it can also change a computer’s configuration resulting in slow Internet connection speeds, a surge in pop-up advertisements, and un-authorized changes in browser settings or functionality of other software. SQL—structured query language, a special-purpose programming language designed for managing data in relational database management systems. TLS—transport layer security (and its predecessor, secure sockets layer/SSL), are cryptographic protocols that provides communication security over the Internet. Sexting—the act of sending sexually explicit messages or photographs primarily between mobile phones. Syncing—the process of copying all electronic files and folders from one device to another (e.g., from a smartphone to a personal computer) through an Internet connection. Tablet Computer—a kind of mobile computer, larger than a mobile phone or personal digital assistant, usually having a flat touchscreen or pen-enabled interface. Twitter—an online social networking service that enables users to send and read text-based posts of up to 140 characters, known as “tweets.” URL—the Uniform Resource Locator is the global address of documents and other resources on the World Wide Web; a URL contains the name of the protocol to be used to access the file resource, a domain name that identifies a specific computer or server on the Internet, and a pathname, a hierarchical description that specifies the location of a file on that computer or server. USB Flash Drive—also called a jump drive or thumb drive, is a data storage device that is typically removable (plugged into a USB/Universal Serial Bus port on a personal computer) and rewritable, and physically much smaller than a floppy disk. USB Port—Universal Serial Bus port, a single, standardized way to connect devices (modems, printers, scanners, digital cameras, etc.) to a personal computer. Virtual reality—an artificial environment created with computer software that can simulate physical presence in places in the real world, as well as in imaginary worlds, primarily through sight and sound experiences; may range from a three-dimensional image that can be explored interactively at a personal computer to more sophisticated approaches involving wrap-around display screens, rooms with wearable computers, and devices that let you feel the display images. Voice chat—a modern form of communication using the Internet through services such as Skype, Yahoo! Messenger, AOL Instant Messenger, or Windows Live Messenger. VoIP—Voice over Internet Protocol, a technology that allows voice calls using a broadband Internet connection instead of a regular (or analog) phone line. Wi-Fi—a technology that allows an electronic device (personal computer, video game console, smartphone, tablet, digital audio player) to exchange data wirelessly (using radio waves) over a computer network. Wi-Fi Hotspot—a wireless access point to the Internet or other computer network over a wireless local area network through the use of a router connected to a link to an Internet service provider; frequently found in coffee shops and other public establishments, a hotspot usually offers Internet access within a range of about 65 feet (20 meters) indoors and a greater range outdoors; many smartphones provide built-in ability to establish a Wi-Fi hotspot. Webcam—a video camera that feeds images in real time to a computer or computer network; can be used to establish video links permitting computers to act as videophones or videoconference stations; also used for security surveillance, video broadcasting, and social videos (such as many viewed on YouTube). WWW—the World Wide Web (commonly known as “the Web” or the “Information Superhighway”), a vast collection of linked files accessed over the Internet using a protocol called HTTP (Hypertext Transfer Protocol); the system supports documents specially formatted in a markup language called HTML (Hyper Text Markup Language) that supports links to other documents, as well as graphics, audio, and video files. With an Internet “web browser,” one can view “web pages” that may contain text, images, video, and other multimedia, and “navigate” between them via “hyperlinks.” World Wide Web is not synonymous with the Internet. The WWW is just one of many applications of the Internet and computer networks. Web server—computer hardware and software that runs a website and is always connected to the Internet; using HTTP (Hypertext Transfer Protocol), a Web server delivers Web pages to browsers and other data files to Web-based applications; every Web server has an IP address and often a domain name. Website—a collection of specially formatted, related Web files (or pages) on a particular subject or organization that are stored on a computer known as a web server and accessible through a network such as the Internet; include a beginning file called a home page; a web page can contain any type of content, including text, color, graphics, animation, and sound. ZIP—a file format used for data compression and archiving; a zip file contains one or more files that have been compressed to make file size considerably smaller than the original file; the zipped version of files have a .zip file extension; can significantly reduce e-mail transmission time and save on storage space. --- ## Creating a username and password to access OpenVAS URL: https://securityorb.com/creating-a-username-and-password-to-access-openvas/ Type: post Modified: 2015-09-10 Creating a username and password to access OpenVAS 1. Open a terminal 2. Issue command → sudo openvasmd --create-user admin 3. Issue command → sudo openvasmd --user=admin --new-password=letmein 4. Issue command → sudo openvassd stop 5. Issue command → sudo openvasmd stop 6. Issue command → sudo gsad stop 7. Issue command → sudo openvassd 8. Issue command → sudo openvasmd 9. Issue command → sudo gsad 10. call up the URL on your browser Issue command → https://localhost:9392/ 11. log-in using the new username and password you created --- ## CSI: Cyber Season 1 Episode 2 Recap: CMND:CRASH URL: https://securityorb.com/csi-cyber-season-1-episode-2-recap-cmndcrash/ Type: post Modified: 2015-08-31 CSI: Cyber Season 1 Episode 2 Recap: CMND:CRASH Episode Info Air Date: Mar 11, 2015 A roller coaster crash is investigated and the probe reveals it was caused by someone who hacked into the ride's internal computer. --- ## My Security Thoughts – A Panel Discussion URL: https://securityorb.com/my-security-thoughts-a-panel-discussion/ Type: post Modified: 2015-08-31 My Security Thoughts – A Panel Discussion Melvin: Tony/Brian, you both have read my thoughts on automation and that it will have a negative impact on civilization. The paper is located here: https://securityorb.com/security-thoughts-mhbjr/. To add into this we have seen the uprising in France from cab drivers against Uber. This has resulted in France ruling that the uberPOP app is illegal though Uber is appealing the ruling it is another hurdle for the service. Now to me the French are known to protest against things that go against their comfort but are they onto something. Uber maybe the first step on a path to where not only are the cab drivers out of business but Uber drivers become extinct as well with driverless cars. What will automation do to our world? Will there be no need for the average human? Will life end for those that are not super rich? Where will it end? We have seen the increase use of drones by the military. They have said that using drones will save lives. That is obviously true but if you eliminate the horror of war for one side then what is the incentive to stop fighting? Thoughts? Tony: Rise of the SLUHs, eh? Hmmm, I don’t think so! I have had several conversations this last week about technology destroying the human condition. In fact, so much so…that it has led me to coin the term “Stupid, Low Energy, Under-employed Humans”…SLUH. One would use it in a sentence like “Hey Sluh, what you doin’?” Ok, seriously thought, I mean that’s basically the argument I hear over and over…so let me define the acronym and then get on with it. Stupid - Technology is making us/humans stupid, calculators, the internet…omg! Low Energy - Technology is making us lazy…just get up and change the channel you lazy human! Under-employed - Technology like drones, driverless cars, robots are taking our well paying jobs! Human - Technology is antithetical to humans…so take off that damn prothesis and deal with life, you whiner! If you want to get at my thoughts in detail about SLUHs go ahead, but for the moment I will address your position, Mel. Your position speaks to Stupid (“Will there be no need for the average human?”) and Under-employed (“Will life end for those that are not super rich?”). In short, tomorrow’s average human will be less average than today’s average human. Those average workers displaced by technology will become adept in using and maintaining the technology that replaced them. They will have to adapt to the new workplace that has less labor and more thinking. The good news is that technology is making humans better thinkers and collaborators anyway. Data visualization tools expand our understanding and imagination, the internet and social tools enable collective thought worldwide…this is unimaginably awesome “force multiplying stuff”. The world is full of innovation and opportunity, automation frees up humans to do more of this. We are centuries away from automation leaving no jobs for humans. Hell, we will be off the planet by then! Hmm, I really don’t have to heart to talk about the efficiency of drones/killing. I have to believe human nature (e.g., compassion et al) is the balancing force against the overall efficiency of war & killing people. And if it’s not then…perhaps we should not live amongst the stars anyway! Brian: To a certain extent you can see what is happening with the demand for increased wages, and the cost of automation - when you are forced pay $15-20/hour for someone to punch a picture, you start looking for ways to cut costs. You can see it happening, putting kiosks that let the person ordering push the button and get rid of the cashier. With the advent of the government forcing more and more businesses out of taking paper money - you have a perfect storm, where you place your order, swipe your credit card - or cell phone - and you get your burger all by machine - no humans are needed anymore and only screw things up, and more and more places are having the outside order go to India and be sent electronically back to that McDonald's since that is cheaper than having someone inside take the customer's order. That is what is happening now - right now they still have humans in the back frying things at some locations, but they are getting rid of the humans in CA where the costs make it prohibitive to have a human due to all of the associated fees that the government is slathering on top of things. Basically, entry level positions are becoming a thing of the past - McDonald's is seeing it's profits disappear so it is looking to cut corners as much as possible. So that is one side of the coin, and I see that growing in the future. Most of what used to be "entry" level positions will disappear over the next 5-10 years. 

The other side of the above trend is that humans are "freed" to do more of what they want when they want - if they can get that nasty how to live day-to-day out of the way. To a certain extent people are working less - since you can't be taxed on your personal time, so giving less of your money to the government and only working for what they need in increasing and is a trend I see as growing in the future. Look at the people who drive for Uber - they work when they need money, and only when they need money, and a lot of it is "off the books". I see that trend increasing in the years to come. Now this has other ramifications in that there is less money for infrastructure, and so forth, but when people are earning just enough to "live" how do you "encourage" them to do more, when the taxes make it so that doing more results in less? You see this a LOT in today's young men - who are on average working less than ever before, and not marrying or taking on any responsibilities. A man can live on little and doesn't mind living without a shower and so forth - or showing in the gym- so I see more of this "free-range men" syndrome. Sure there will be people that buck that trend, but it certainly seems to be growing. Men living on the beach in San Francisco are exploding - this is a trend that I think will increase. Sure there will be people who still go the traditional school, and 9-5 but I think they will start looking for less money and more perks - free car, free housing, child-care, etc. - things that can be "written" off or now taxed. Also, with cars driving themselves we will see more "robots" doing more things that used to be exclusively reserved for humans - I saw a drone fire a gun earlier this week. What will happen when someone uses one to rob a bank? (I expect it in the next few years.) Kill someone? (That will probably be sooner rather than later.) How to you get "forensics" when the criminal is a machine? The government pioneered the use of "drones" and people will run with it - they are already being used for anything and everything. Humans are innovative in ways that you may not want them to be. Of course the government will try to do what they always do - make things illegal, and everyone will ignore it. When everything is illegal - everyone is a criminal. Heck, I saw a thing a few years ago where the average person commits 1-2 felonies every day - yes, felonies. Most of that is due to the stupidity of what is now a crime - I see this continuing...  One area that will explode is the area of 3D printing - they are still doing plastics, but I saw a company experimenting with a type of "liquid-metal" - that will be a game changer. Think about when you can print what you need - need valve? Or something you don't know what the name is? Print it and use it. They are doing that in a number of places already - auto manufacturing - and that will spread. Melvin: Let me address Tony’s response first. I was not going down the SLUH road. I don’t feel that people cannot compete or be of use. My reasoning is that automation cost less than paying a human to do the same job. As automation becomes more efficient and cost to automate decrease than more people will be out of work. I am looking at the future where unemployment is increasing not because we cannot teach people or that they cannot do the work it is just that profit will win in any business so they will let people go. Brian talked about Uber. What happens when Uber uses self-driving cars? Those people that were working when they needed money are now not needed. I look again at China where there are over a billion people in China. They have an urban unemployment rate between 4 – 4.5%. They do not take into account the 300 million migrant farm workers and there are a number of groups in China that are also not accounted for in their published numbers. Even so we can just look at a company like Foxcom that makes products for Apple and other companies. It employs tens of thousands and is just one of the mega manufacturing companies. As they are able to increase the amount of automation in their factories they will do so. Where will those workers go? No nation on Earth can count on colonization to alleviate overcrowding and to find another source of trade, new trade that will bring new profit and expansion. Automation can lead to a collapse of the economy. If people cannot work because they are not needed then they will not have any money to buy things to keep the economy moving. Tony: Hmm, this sounds a bit like the Industrial Revolution argument back in the day. Ok well I guess it all depends on your timeframe, Automation will definitely displace workers but my bottomline is that humans will adapt and move on. I mean this timeframe seems soooo far out...farther out then the industrial revolution. Additionally, we have so much technology that makes the world a smaller community, a community that can better absorb displaced workers. Automation takes time and repeatability, so every industry will not become automated overnight. I just do not see enough automation that will make a dent even close to the industrial revolution. I do like Brian’s “free range men” though...the graphic alone is pretty funny. Dudes grazing and grifting the country-side. Man, you all are making me think Automation equals the Apocalyse...pretty bleak stuff. I just don’t like the math though; there are so many problems to be solved that need labor and new problems are coming along every day. Automation is a very manufactured thing that takes significant time and planning to move across numerous industries; and we are on the cusp of so many technologies that can change the landscape and job prospects. The automation argument feels like shadow boxing to me...no opponents...the real world will feint, jab and right hook Brian: Melvin you are correct - Uber is purely a temporary solution - very much like contracting back in the 90’s was - when you could contract to provide something that did X for $Y - the company paying you didn’t pay for your time, but your skills. So if you could do it in an hour, great - otherwise they didn’t care - you had control again and that business model thrived for a while - I made lot as a grad-student during that time. But that situation didn’t last long - quickly the government got involved - too much cash changing hands, and various legalities were put in place to stop it, so that today that type of piece-meal contract work is for all intents illegal, at least in the US although thriving in other countries. It is THE business model in India and places in China for the moment. But in the US you MUST work for a company - even if you are the company - 1099's are increasingly difficult and becoming a thing of the past. It's just a way to up the cost so that fewer people can stay in the game. This country always tries to figure out how to make money off something - because a growing number of bureaucrats are supported by that money. I saw that the US took in more money than ever in taxes this year - think about that for a minute, yet fewer people than ever are working - that is unsustainable, and we are well beyond what the Laffer curve predicted for the point where you discourage people from working (https://en.wikipedia.org/wiki/Laffer_curve) Look at how many older companies are now leasing cars for their workers, and I saw one in CA is providing housing if you work for them since they can write it off as a "tax" expense. That is where more opportunities are. I think that is what Uber, and Airbnb are all about - staying ahead of the taxman. Of course, this is a dangerous area as most bureaucrats are - shall we say, less than intelligent when it comes to technology? Or more importantly seeing the obvious ramifications of their laws. Since I mentioned it, let's look at AirBnB - that is in direct answer to the high taxes many cities layer on normal hotels, and AirBnb knows it and refuses to release names of the people who are participating in their business model. Why? Because today’s “business” environment for many cities (New York, San Francisco, etc) are unsustainable - it's obvious, so technology is coming up with ways to dodge the laws and make money while they can - I saw a statistic where more companies are going out of business each year than are being started - which is a first for the US. And it's been going on for a while. But that only works for so long. There is an interesting article about China - they replaced 90% of their workforce in a plant and achieved an increase in efficiency of 90% (http://www.techrepublic.com/article/chinese-factory-replaces-90-of-humans-with-robots-production-soars/) That is the way of the future - but where do those 90% who were displaced go for a job? That is the question for the next decade… --- ## Cheating website subscribers included WH, Congress workers URL: https://securityorb.com/cheating-website-subscribers-included-wh-congress-workers/ Type: post Modified: 2015-08-24 By JACK GILLUM and TED BRIDIS Published: Aug 20, 2015 WASHINGTON (AP) - Hundreds of U.S. government employees - including some with sensitive jobs in the White House, Congress and law enforcement agencies - used Internet connections in their federal offices to access and pay membership fees to the cheating website Ashley Madison, The Associated Press has learned. The AP traced many of the accounts exposed by hackers back to federal workers. They included at least two assistant U.S. attorneys; an information technology administrator in the Executive Office of the President; a division chief, an investigator and a trial attorney in the Justice Department; a government hacker at the Homeland Security Department and another DHS employee who indicated he worked on a U.S. counterterrorism response team. Few actually paid for their services with their government email accounts. But AP traced their government Internet connections - logged by the website over five years - and reviewed their credit-card transactions to identify them. They included workers at more than two dozen Obama administration agencies, including the departments of State, Defense, Justice, Energy, Treasury, Transportation and Homeland Security. Others came from House or Senate computer networks. The AP is not naming the government subscribers it found because they are not elected officials or accused of a crime. Hackers this week released detailed records on millions of people registered with the website one month after the break-in at Ashley Madison's parent company, Toronto-based Avid Life Media Inc. The website - whose slogan is, "Life is short. Have an affair" - is marketed to facilitate extramarital affairs. Many federal customers appeared to use non-government email addresses with handles such as "sexlessmarriage," ''soontobesingle" or "latinlovers." Some Justice Department employees appeared to use pre-paid credit cards to help preserve their anonymity but connected to the service from their office computers. "I was doing some things I shouldn't have been doing," a Justice Department investigator told the AP. Asked about the threat of blackmail, the investigator said if prompted he would reveal his actions to his family and employer to prevent it. "I've worked too hard all my life to be a victim of blackmail. That wouldn't happen," he said. He spoke on condition of anonymity because he was deeply embarrassed and not authorized by the government to speak to reporters using his name. The AP's analysis also found hundreds of transactions associated with Department of Defense networks, either at the Pentagon or from armed services connections elsewhere. Defense Secretary Ash Carter confirmed the Pentagon was looking into the list of people who used military email addresses. Adultery can be a criminal offense under the Uniform Code of Military Justice. "I'm aware it," Carter said. "Of course it's an issue because conduct is very important. And we expect good conduct on the part of our people. ... The services are looking into it and as well they should be. Absolutely." The AP's review was the first to reveal that federal workers used their office systems to access the site, based on their Internet Protocol addresses associated with credit card transactions. It focused on searching for government employees in especially sensitive positions who could perhaps become blackmail targets. The government hacker at the Homeland Security Department, who did not respond to phone or email messages, included photographs of his wife and infant son on his Facebook page. One assistant U.S. attorney declined through a spokesman to speak to the AP, and another did not return phone or email messages. A White House spokesman said Thursday he could not immediately comment on the matter. The IT administrator in the White House did not return email messages. Federal policies vary for employees by agency as to whether they would be permitted during work hours to use websites like Ashley Madison, which could fall under the same category as dating websites. But it raises questions about what personal business is acceptable - and what websites are OK to visit - for government workers on taxpayer time, especially employees who could face blackmail. The Homeland Security Department rules for use of work computers say the devices should be used for only for official purposes, though "limited personal use is authorized as long as this use does not interfere with official duties or cause degradation of network services." Employees are barred from using government computers to access "inappropriate sites" including those that are "obscene, hateful, harmful, malicious, hostile, threatening, abusive, vulgar, defamatory, profane, or racially, sexually, or ethnically objectionable." The hackers who took credit for the break-in had accused the website's owners of deceit and incompetence, and said the company refused to bow to their demands to close the site. Avid Life released a statement calling the hackers criminals. It added that law enforcement in both the U.S. and Canada is investigating and declined comment beyond its statement Tuesday that it was investigating the hackers' claims. ___ Associated Press writers Alicia Caldwell and Lolita C. Baldor in Washington and Raphael Satter in London contributed to this report. ___ Follow Jack Gillum on Twitter at https://twitter.com/jackgillum and Ted Bridis at https://twitter.com/tbridis © 2015 The Associated Press. All Rights Reserved. --- ## Hackers Dump Ashley Madison User Database... Where Most People Won't Find It URL: https://securityorb.com/hackers-dump-ashley-madison-user-database-where-most-people-wont-find-it/ Type: post Modified: 2015-08-19 Hackers Dump Ashley Madison User Database... Where Most People Won't Find It Attackers make good on doxing threat, but post database to dark web. The attackers who compromised Ashley Madison -- an online hook-up site for people looking for extra-marital affairs -- have made good on their threats to unmask the site's users if the site was not taken down. However, unlike the attackers who doxed Sony and Hacking Team, who uploaded all the stolen data to Pastebin, the Ashley Madison hackers dropped the 9.7 G data dump where most users will not go looking: the "dark web," only accessible through the Tor network. The data includes email addresses, credit card transaction data, and profile information on the 37 million customers of Avid Life Media, which includes Ashley Madison and its sister sites, Cougar Life and Established Men. The attackers, who call themselves Impact Team, said "We have explained the fraud, deceit, and stupidity of ALM and their members. Now everyone gets to see their data. ... Find yourself in here? It is ALM that failed you and lied to you. Prosecute them and claim damages. Then move on with your life. Learn your lesson and make amends." Read more here. --- ## Cracked Uber accounts tumble to 40 cents on the dark web URL: https://securityorb.com/cracked-uber-accounts-tumble-to-40-cents-on-the-dark-web/ Type: post Modified: 2015-08-17 A posting from naked security titled " Cracked Uber accounts tumble to 40 cents on the dark web"  by Lisa Vaas emember those cracked Uber accounts that were selling for as little as $1 on the dark web a few months ago? Well, welcome to the Midsummer Madness Sale: prices have been slashed, and now, they're going for the low, low price of only 40 cents! I know what you're thinking: With these prices, the dark-web markets selling other people's accounts must be CRAZY! (Actually, so are you if you actually buy these things. It's illegal, and your purchase could buy you a world of trouble.) Motherboard, which first picked up on the Uber account sale in March, now reports that the accounts are not only still being sold; now, valid email/password logins for Uber are selling for less than half of what they had been. To read more click here: --- ## Using ambient sound as a two-factor authentication system URL: https://securityorb.com/using-ambient-sound-as-a-two-factor-authentication-system/ Type: post Modified: 2015-08-17 A posting from naked security titled  " Using ambient sound as a two-factor authentication system" by Lee Munson We know that many of us are no good at choosing our own passwords. That's why companies are increasingly looking to bolster their own website security through additional authentication methods. To that end, we've seen many different forms of two-factor authentication (2FA) employed - John Shier wrote an excellently detailed article on the topic last year in which he noted that each of the common 2FA optionshave their disadvantages. His conclusion was that "true" 2FA, using a separate token, was probably the best way forward - but that such a system would likely not be free and would leave people with an annoyingly large amount of tokens to manage. While it's better for your security to take advantage of 2FA everywhere it is available, some people see it as an inconvenience nonetheless - either because they need to lug tokens around or because of the few seconds it takes to generate a code or type in a password received by SMS. To read more click here: --- ## Why AT&T's 'Willingness' To Help NSA Is Alarming URL: https://securityorb.com/why-atts-willingness-to-help-nsa-is-alarming/ Type: post Modified: 2015-08-17 A posting from Dark reading  titled " Why AT&T's 'Willingness' To Help NSA Is Alarming" by Eric Zeman The NSA would have had a much more difficult time spying on Americans were it not for the comfortable, chummy partnership the government forged with AT&T, say new documents released by Edward Snowden. AT&T worked closely with the government and ensured the agency had access to emails and call records for a period spanning decades. Snowden's bombshell revelations exploded two years ago. The shock and awe campaign is over. Since then, a trickle of information continues to flow like lava -- slowly, but still searingly hot -- with new and unsettling revelations. The latest comes from the New York Times, which was privy to more documents shared by Snowden. This time, Snowden detailed the nature of the relationship between the NSA and one of its top partners: AT&T. To read more click here:      --- ## Richard Bejtlich Talks Business Security Strategy, US Security Policy URL: https://securityorb.com/richard-bejtlich-talks-business-security-strategy-us-security-policy/ Type: post Modified: 2015-08-17 A video posting form Dark reading titled "Richard Bejtlich Talks Business Security Strategy, US Security Policy"  by Richard Bejtlich Chief security strategist of FireEye talks at the Dark Reading News Desk at Black Hat about what should really be driving your security department's strategy. Plus he discusses law enforcement agencies' efforts to put backdoors in encryption solutions and how the government is responding to technology's improved abilities to provide attribution for cybercrime. to see the video click here: --- ## My Security Thoughts: Anonymity and Privacy, There is None Nor Should We Expect It URL: https://securityorb.com/my-security-thoughts-anonymity-and-privacy-there-is-none-nor-should-we-expect-it/ Type: post Modified: 2015-08-16 My Security Thoughts: Anonymity and Privacy, There is None Nor Should We Expect It We all know that Al Gore invented the Internet in his spare time as an environmentalist (just joking). The Internet as we know it is the successor to the Department of Defense’s ARPANET. Thus in 1969 the first host computer was connected. The initial purpose of the ARPANET was to communicate with and share computer resources among mainly scientific users at the connected institutions.[1] The key words here are communicate and share. This is the heart of the Internet. It is sharing information and communicating with others. The definition of anonymity from TheFreeDictionary.com (http://www.thefreedictionary.com/anonymity) is: The quality or state of being unknown or unacknowledged. One that is unknown or unacknowledged.   The definition of privacy from TheFreeDictionary.com (http://www.thefreedictionary.com/privacy) is: the condition of being private or withdrawn; seclusion the condition of being secret; secrecy   You have more rights to privacy using snail mail than you do using email. When using email, it traverses the Internet in plain text (i.e., not encrypted). Your Internet Service Provider (ISP) can view your email at any time. There are strict rules on how and when the government can intercept and read your mail when going through the U.S. Postal System. Google’s Gmail, Yahoo’s mail service, and Microsoft’s free offering provides a web-based email service but your email is not private. They do scan your email to provide targeted advertising. This could be done for other reasons as well. Let me be clear—I want anonymity and privacy when I transverse the web. That is, for the most part, I want it but I don’t want criminals or terrorists to have the same. It could be said that I want my cake and to eat it as well. Getting back on track, if something is built with a set of goals then you cannot expect that thing to operate in a manner that is at odds with the initial set of goals. You need to start from scratch. Build an Internet with anonymity and privacy as the prime goals. The problem is that building a new Internet from scratch is practically impossible. There is no incentive for anyone to fund a project of this magnitude. I cannot fathom any government wanting to have a network that allows anonymity. The FBI has been saying that their greatest fear is an Internet that is dark. The prospect of encryption in every device that is unbreakable is feasible. The likelihood is low due to the current level of user sophistication that would be required. Additionally, the companies that provide all of the free services to users would balk at an Internet that offered true privacy and anonymity. Tracking algorithms would become useless. Another aspect is do we truly want an Internet that allows true anonymity. Cyber stalkers, terrorists, criminals, pedophiles, etc. could troll along the Internet behind cover identities that could not be ascertained. Try as we might, most people are conflicted when it comes to privacy and anonymity. They want it for themselves but not the bad guy. The problem is that you can’t have it both ways. Some may say that the constitution guarantees us a right to privacy. That is true but we need to look again at the Internet and that it was never envisioned to be used as it is being used. I do not believe that those designers would have thought that Twitter would be in existence among other things that exist on the web. Even if we say that the Internet needs to insure privacy, then the question becomes privacy for whom. Once again, do we want the bad guys to have privacy? Thoughts? Twitter: @mhbjr LinkedIn: Melvin Barnes, Jr. Google+: Melvin Barnes, Jr. [1] http://searchnetworking.techtarget.com/definition/ARPANET --- ## NICE (National Initiative for Cybersecurity Education) Conference 2015 URL: https://securityorb.com/nice-national-initiative-for-cybersecurity-education-conference-2015/ Type: post Modified: 2015-08-15 NICE (National Initiative for Cybersecurity Education) Conference 2015 November 3-4, 2015 San Diego, CA Ready to Work:  Equipping Our Cybersecurity Workers With The Skills to Compete NICE 2015 San Diego in a 21st-Century Economy    NICE 2015 is being designed to be a rallying point around cybersecurity education and workforce development. It provides: A face-to-face convening of public-private partners; An opportunity to signal NICE strategic directions and priorities; and A forum to showcase best practices. Join thought leaders from education, government, industry and non-profits as we address the future cybersecurity education needs of the nation. The event will take place over two days in San Diego, CA.  All companies with supporting programs, technology or with a voice in the cyber education marketplace are invited to exhibit their latest technologies and services at this event. Learn more Sponsorships are also available for additional exposure. Educational Tracks include:  Track 1: Accelerate Learning and Skills Development Explore programs and techniques that can more rapidly increase the supply of cybersecurity workers Reduce the time and cost for obtaining necessary knowledge, skills, and abilities Target displaced workers or underemployed individuals who are available and motivated Track 2: Establish a Diverse Learning Community Seek creative and effective efforts to increase the number of underrepresented populations Drive cybersecurity career awareness, exploration, and preparedness into schools and younger populations Strengthen formal education programs, technical training and certifications, and co-curricular experiences Track 3: Workforce Development and Career Planning Analyze data sources that project present and future workforce demand and supply of qualified workers Explore tools and techniques that effectively measure and validate knowledge, skills, and abilities Identify effective practices and solutions that enhance recruitment, hiring, promotion, and retention Cybersecurity has emerged as one of the leading creators of jobs and opportunity for all economic sectors. An ecosystem of technology providers, policy makers, legal expertise, banking, insurance, devices, educational programs and devices have emerged to deal with the cyber security issues that have become commonplace. In turn, the marketplace has responded by demanding a new workforce capable of taking on this challenge. For more information on the NICE initiative and the 2015 Conference, please visit https://www.fbcinc.com/nice. Questions? Please contact your FBC Account Manager directly, or FBC's Customer Outreach at 800-878-2940 x283 / katie@fbcinc.com. --- ## SecurityBSides DC 1st Round Ticket Sales Open Now URL: https://securityorb.com/securitybsides-dc-1st-round-ticket-sales-open-now/ Type: post Modified: 2015-08-15 Get them while they are hot. SecurityBSides DC registration will be opening for FIRST round ticket sales tonight at just past midnight, EDT! The event is in October, and you can find more details on the Web site at bsidesdc.org. The registration page will open automatically at the appointed hour. https://bsidesdc2015.busyconf.com/bookings/new --- ## Black Hat USA 2015 Wraps Up Record-Breaking Week in Las Vegas URL: https://securityorb.com/black-hat-usa-2015-wraps-up-record-breaking-week-in-las-vegas/ Type: post Modified: 2015-08-10 SAN FRANCISCO, Aug. 10, 2015 /PRNewswire/ -- Black Hat, the world's leading family of information security events, today highlights some of the special events and initiatives that helped make Black Hat USA 2015 a record-breaking show. In its 18th year, the event welcomed more than 11,000 of the most security-savvy professionals across the InfoSec spectrum – spanning academia, world-class researchers, and leaders in the public and private sectors. Boasting more than 110 innovative research-based Briefings presented by more than 190 researchers and speakers, as well as 70 in-depth Trainings, attendees of Black Hat USA 2015 experienced the most intensive schedule to date. For more information about the event and to download available whitepapers and presentations, visit: blackhat.com/us-15/. The Black Hat Review Board, comprised of 24 of the world's foremost security experts, evaluated more submissions this year than ever before – resulting in the most robust schedule in Black Hat history. Show Highlights Keynote Jennifer Granick, Director of Civil Liberties at the Stanford Center for Internet and Society and one of the most respected legal minds in the industry, presented "The Lifecycle of a Revolution." Granick delivered her dynamic presentation about the dying dream of Internet freedom to a packed keynote room, filled with more than 6,000 attendees. Black Hat Arsenal returned for its sixth year, offering researchers and the open source community a venue to demonstrate tools they develop and use in their daily professions – from visualization and phishing to collaborative analysis and pentesting. This year's event featured 58 tools, the largest Arsenal event to date. Black Hat's "Beyond the Gender Gap: Empowering Women in Security" panel and luncheon featured some of the top women in the security field sharing their paths to success, as well as insight on recruiting, retaining and the professional advancement of women in the security industry. Black Hat Business Hall was action-packed, as more than 200 of the industry's top companies showcased their latest technologies and solutions alongside the newly launched International Pavilion and Career Zone, as well as the Innovation City for impressive startups. Giving Back Black Hat is driven by the needs of the security community. Giving back and helping to foster the next generation of security professionals is a top priority and we are proud to highlight some of our most recent initiatives: Electronic Frontier Foundation Support: for the second year in a row, Black Hat is proudly donating $50,000 to the EFF to continue supporting their important work in protecting civil liberties within the digital world. Black Hat has a strong partnership with the EFF to provide pro-bono legal consultations to security researchers on the legality of any research or data they plan to present at the annual shows. Academic Scholarships: From a combination of speaker nominations and direct applications, Black Hat USA 2015 provided 153 students with complimentary full Briefings passes. Future Female Leaders Scholarship Program: brand new this year, Black Hat and the Executive Women's Forum (EWF) teamed up to award 27 full scholarships to female students in the Information Security, IT Risk Management and Privacy industries. Youth for Technology Foundation Support: in support of the Youth for Technology Foundation (YTF), this year Black Hat developed an exclusive Black Hat USA 2015 t-shirt for the show with all proceeds being directly donated to help bring technology and education to low-income communities in the U.S. and rural communities in developing nations. Top sponsors of Black Hat USA 2015 include: Diamond Sponsors: FireEye, Lieberman Software, Qualys, RSA, and Tenable Network Security; Platinum Plus Sponsors: AlienVault, Cisco, Digital Guardian, Fidelis Cybersecurity, HP, Lockheed Martin Corporation, LogRhythm, Palo Alto Networks, Inc., Raytheon | Websense, and Webroot; Platinum Sponsors: Bromium, Core Security Technologies, Fortinet, IBM, Optiv Security, Proofpoint, Inc., Tripwire, and ZeroFOX Inc. What's Next: Black Hat Europe 2015 Following a blockbuster week in Las Vegas, Black Hat is busy preparing for Black Hat Europe 2015, a four-day event taking place November 10-13, 2015 at the Amsterdam RAI Exhibition and Convention Centre in Amsterdam, Netherlands. The event will bring together an international security audience for two days of intense classroom-style Trainings followed by two days of the infamous Black Hat Briefings presented by some of the most renowned experts in the industry. For more information and to register, please visit: blackhat.com/eu-15/. Future Black Hat Dates and Events Black Hat Europe 2015, Amsterdam RAI, Amsterdam, NL, November 10-13, 2015 Black Hat Executive Summit 2015, Omni Montelucia Resort, Scottsdale, AZ, December 8-10, 2015 Black Hat Asia 2016, Marina Bay Sands, Singapore, March 29 – April 1, 2016 Black Hat USA 2016, Mandalay Bay, Las Vegas, Nevada, July 30 – August 4, 2016 About Black Hat For more than 17 years, Black Hat has provided attendees with the very latest in information security research, development, and trends. These high-profile global events and trainings are driven by the needs of the security community, striving to bring together the best minds in the industry. Black Hat inspires professionals at all career levels, encouraging growth and collaboration among academia, world-class researchers, and leaders in the public and private sectors. Black Hat Briefings and Trainings are held annually in the United States, Europe and Asia, and are produced by UBM Tech. More information is available at: blackhat.com. About UBM Tech UBM Tech engages technology professionals live and online through its world-class brands, including Black Hat, InformationWeek, Enterprise Connect, Game Developers Conference (GDC), Dark Reading, HDI, GTEC, Network Computing and Interop. We're dedicated to fostering real engagement by creating environments where the technology industry can make connections, share insights, and network effectively. UBM Tech is the only media company that delivers large-scale industry events, leading online brands and content marketing services serving the Enterprise IT, Information Security, Game Development, Enterprise Communications and Technical Services and Support communities. UBM Tech is a part of UBM (UBM.L), a global provider of media and information services with a market capitalization of more than $2.5 billion. For more information, go to http://tech.ubm.com. Logo - http://photos.prnewswire.com/prnh/20150810/257119LOGO   SOURCE Black Hat RELATED LINKS http://www.blackhat.com --- ## NSA sets date for purge of surveillance phone records URL: https://securityorb.com/nsa-sets-date-for-purge-of-surveillance-phone-records/ Type: post Modified: 2015-07-29 A posting from NakedSecurity titled "NSA sets date for purge of surveillance phone records " by  Lisa Vaas  The National Security Agency (NSA) has set a date to purge phone records collected during its bulk surveillance program. "Analytic access" to the five years worth of records will end on 29 November, and they'll be destroyed three months later, it said in a statement released on Monday. There are two reasons for the three-month lag: The bulk telephony metadata has to be preserved until civil litigation regarding the program is resolved or until courts relieve NSA of such obligations. From the statement: As soon as possible, NSA will destroy the Section 215 bulk telephony metadata upon expiration of its litigation preservation obligations. Also, "solely for data integrity purposes" to verify the records produced under the new, targeted production authorized by the USA Freedom Act, the NSA will allow technical personnel to access the historical metadata for those additional three months. For a while there, it didn't look like the NSA would ever let go of its death grip on the records. "Plus ça change, plus c'est la même chose, well, at least for 180 days," US Foreign Intelligence Surveillance Court (FISC) Judge Michael W. Mosman wrote last month, as he jauntily granted a six-month extension to the agency's bulk collection of phone metadata. To read more click here. --- ## Code Theft: Protecting IP At The Source URL: https://securityorb.com/code-theft-protecting-ip-at-the-source/ Type: post Modified: 2015-07-29 An interesting article from DarkReading titled "Code Theft: Protecting IP At The Source" by Anna Chiang.   Your corporate assets are at risk and every day that you avoid taking action shortens the time until your IP will be leaked. Here are six steps toward better data security. The security world is awash with various malware-centric cyber kill chain models and advanced styles of threat defense that focus on network traffic, payload, and endpoint analyses. But if you step back and look at what most security tools and frameworks are trying to accomplish at a very high level, it boils down to: Detecting and/or blocking adversaries as they try to get inside your organization to steal your valuable data and intellectual property (IP) Detecting and/or blocking adversaries as they try to exfiltrate that IP and data to use for their own purposes   To read more click here: --- ## Online Security: How The Experts Keep Safe URL: https://securityorb.com/online-security-how-the-experts-keep-safe/ Type: post Modified: 2015-07-27 An interning article titled "Online Security: How The Experts Keep Safe" from information week by Thomas Claburn. In the 1976 thriller Marathon Man, Nazi war criminal Dr. Christian Szell tortures runner "Babe" Levy to find out whether it's safe for him to retrieve diamonds stored in a bank deposit box. "Is it safe?" Szell asks repeatedly. Levy, who doesn't know, can't provide a satisfactory answer. It isn't safe online, but many people try to achieve some measure of security by keeping their passwords safe in their heads. "No one can hack my mind," explained one person responding to Google researchers about security practices. Someone could beat you about the head, a technique euphemistically known as "rubber-hose cryptanalysis," to obtain your secrets. It didn't work inMarathon Man, but it can. Fortunately, that's not a scenario likely to concern most Internet users. But it demonstrates one of several vulnerabilities that come with trying to remember passwords. There's another issue that may be more relevant: Memory doesn't scale. Trying to remember multiple passwords, if they're as complex as they should be, is a recipe for failure. Google software engineer Iulia Ion, research scientist Rob Reeder, and user experience researcher Sunny Consolvo set out to explore the difference between security experts and the rest of us. They detailed their findings in the paper "Comparing Expert and Non-Expert Security Practices," which they presented at last week's Symposium on Usable Privacy and Security.   To read more click here:  --- ## iPhone Kill Switch: How Effective Is It? URL: https://securityorb.com/iphone-kill-switch-how-effective-is-it/ Type: post Modified: 2015-07-27 An interesting article from Darkreading by Eric Zeman  titled " iPhone Kill Switch: How Effective Is It?" My iPhone 6 Plus was picked from my pocket in Barcelona in March as I walked home from dinner one evening. After speaking to local police for a few moments, I ran back to my hotel to locate the phone through Apple's Find My iPhone tool. Too late. The thieves had already turned it off. I always protect my phones, tablets, and computers with a password, so I was not worried about the thieves cracking into my handset and rooting through my personal information. Similarly, I backed the device up regularly, so there was nothing vital on the phone that I didn't have stored elsewhere. Last, I took advantage of the remote erase and lock functions so when the thieves turned the phone back on the first thing it would do was delete all my data and then turn into a useless brick. to read more click here: --- ## Converge 2015 - Hacking To Get Caught - Keynote URL: https://securityorb.com/converge-2015-hacking-to-get-caught-keynote/ Type: post Modified: 2015-07-24 Description: Raphael Mudge, the creator of Armitage and Cobalt Strike, will talk about something awesome. Raphael Mudge is the founder of Strategic Cyber LLC, a Washington, DC based company that creates software for red teams. Raphael's work Armitage pioneered ideas to allow red teams to collaborate and scale their efforts. He also worked on red team automation through DARPA's Cyber Fast Track program. Besides Armitage, Raphael is the creator of the threat emulation software Cobalt Strike and the inventor of the grammar checker on WordPress.com. His work has appeared on the cover of the Linux Journal, the Fox sitcom Breaking In, and other publications. Raphael regularly speaks on security topics and provides red team support to many cyber defense exercises. For More Information Please Visit: - http://www.convergeconference.org/ --- ## Bug exposes OpenSSH servers to brute-force password guessing attacks URL: https://securityorb.com/bug-exposes-openssh-servers-to-brute-force-password-guessing-attacks/ Type: post Modified: 2015-07-23 Bug exposes OpenSSH servers to brute-force password guessing attacks A bug in OpenSSH, the most popular software for secure remote access to UNIX-based systems, could allow attackers to bypass authentication retry restrictions and execute many password guesses. A security researcher who uses the online alias Kingcope disclosed the issue on his blog last week, but he only requested a public vulnerability ID to be assigned Tuesday. By default, OpenSSH servers allow... READ MORE --- ## Researchers Enlist Machine Learning In Malware Detection URL: https://securityorb.com/researchers-enlist-machine-learning-in-malware-detection/ Type: post Modified: 2015-07-22 A posting from dark reading by Kelly Jackson Higgins titled "Researchers Enlist Machine Learning In Malware Detection " No sandbox required for schooling software to speedily spot malware, researchers will demonstrate at Black Hat USA. In 100 milliseconds or less, researchers are now able to determine whether a piece of code is malware or not -- and without the need to isolate it in a sandbox for analysis. Welcome to the age of machine learning as a tool for more efficiently detecting malware, via so-called "deep learning" techniques. Researchers have built a special machine learning tool module that employs static analysis of a piece of code to quickly spot -- and ultimately, stop -- malware infections. A pair of researchers plans to demonstrate live at Black Hat USA next month just how this approach can spot malware from live malware feeds. Matt Wolff, chief data scientist at Cylance, says his team is applying deep learning--a more granular subset of machine learning--to malware detection by training the software via legitimate files and malicious ones, and teaching the application/algorithm which is which. The application then can take files it's never seen before and spot malware, he says. To read more click here:   --- ## Windows 10 Will Use Virtualization For Extra Security URL: https://securityorb.com/windows-10-will-use-virtualization-for-extra-security/ Type: post Modified: 2015-07-22 An interesting article from informationweek by Kelly Sheridan titled "  Windows 10 Will Use Virtualization For Extra Security"   When we're talking about Windows 10features, security upgrades are often edged out of the spotlight by flashy additions like Cortana for desktop, Microsoft Edge, and Universal Apps. Perhaps this is because Microsoft is targeting a broad consumer audience with its new operating system, and many people don't care quite as much about nitty-gritty security details as they do about the return of the Start menu. Increased security is not an attention-grabber for everyone. That said, there are still plenty of consumers and enterprise customers who want to know how their devices and data will be protected on Windows 10. We're living and working in an age of heightened security risk. The question is not whether an attack will happen, but when. [CIOs Aren't Getting What They Need From CRM] "The threats that we're seeing are dramatically different from what we saw four years ago," Chris Hallum, senior product manager for Windows business security, said in an interview with InformationWeek. "Organizations are still getting breached, even when they have the very best security solutions." Today's attacks are more aggressive and targeted. Detection-based models for pinpointing malware are no longer enough. Most hackers use one of two avenues in a security breach: identity theft and increasingly advanced malware. To read more click here: --- ## Ashley Madison Exposed: Affair Hookup Site Hacked, Member Data Posted Online URL: https://securityorb.com/ashley-madison-exposed-affair-hookup-site-hacked-member-data-posted-online/ Type: post Modified: 2015-07-20 A posting from Dark Reading by Quick Hits titled " Ashley Madison Exposed: Affair Hookup Site Hacked, Member Data Posted Online"   Member data pilfered, posted in apparent hacktivist-style doxing attack. Call it hacktivism with a spin: a controversial website for people seeking others who want to have an affair was hacked and personal details of its members leaked online. The CEO of Ashley Madison, a controversial website that facilitates adulterous affairs and hookups, confirmed to Krebs On Security that it was hacked and possibly by or with the help of an insider who is not an employee. The attacker or attackers claiming responsibility call themselves The Impact Team, and said in an online statement that it grabbed data on all of the 37 million users of Ashley Madison and its sister sites Couger Life and Established Men. All three sites are owned by Avid Life Media (ALM).   To read more click here:  --- ## Why Did A Security Firm Mysteriously Ditch a 'Privacy' Product? URL: https://securityorb.com/why-did-a-security-firm-mysteriously-ditch-a-privacy-product/ Type: post Modified: 2015-07-20 A posting from Forbes by Yael Grauer titled "Why Did A Security Firm Mysteriously Ditch a 'Privacy' Product?" :   Two weeks after Ben Caudill announced that he’d built a $200 hardware proxy which allows Internet users to mask their location, the Rhino Labs owner shut down his project. His much anticipated August appearance at DEF CON, the annual hacker convention in Las Vegas where he planned on selling the device at cost, was cancelled as well. “People are always going to speculate despite what I say and don’t say,” Caudill told me when I asked him about the theory that he cancelled the project and talk for media attention. Although he repeatedly declined to offer details on the circumstances surrounding the cancellation, he pointed out that not all press is good press, and that the company had invested time and resources into the project. “The actual result of cancelling was for more negative than going through with it would have been,” he added, pointing out that a lot of time and energy and material costs were put into the project, which he worked on with a small team for about a year.   to read more click here: --- ## Did Firefox listen to Facebook and just kill Flash? (No, but there's another patch!) URL: https://securityorb.com/did-firefox-listen-to-facebook-and-just-kill-flash-no-but-theres-another-patch/ Type: post Modified: 2015-07-14 A posting from NakedSecurity by Paul Ducklin titled "Did Firefox listen to Facebook and just kill Flash? (No, but there's another patch!)" it seems that Flash exploit stories come along in bunches, too, like those pesky buses you wait for. No sooner had we written about Facebook's new CSO's weekend "Death to Flash" tweet... ...than an eagle-eyed Naked Security reader pointed us at a tweet from someone going by @MarkSchimdty, who seems to be something of a anti-Flash hacktivist, considering the photo accompanying his tweet: BIG NEWS!! All versions of Flash are blocked by default in Firefox as of now. Not in my Flash in my Firefox, as it happens – with Flash set to "Always ask," Firefox asked and then used Flash if I agreed. But the facts behind the histrionics seemed to sort themselves out when I tried Abobe's own Flash Tester (yes, I used click-to-play): to read more click here: --- ## Dark Reading Radio: Firewall Smackdown URL: https://securityorb.com/dark-reading-radio-firewall-smackdown/ Type: post Modified: 2015-07-14 A posting from dark reading by  Marilyn Cohodas  titled firwall smackdown:   Is there a future for the venerable firewall? Join us for a debate between security CEOs Asaf Cidon of Sookasa and Jody Brazil of FireMon. Show time is Wednesday, July 15, 1:00 PM New York/10:00 AM San Francisco. In today’s  BYOD world there is probably no question that sparks greater controversy than what to do about the increasingly obscure network  perimeter -- and what that means for the ubiquitous firewall. Some experts argue that the perimeter is dead, and along with it, the stalwart firewall. Others contend that the firewall will continue to play a role in the command center of enterprise defense for a long time to come. To read more click here: --- ## Flash zero-day leaks out from "Hacking Team" hack, patch expected Real Soon Now URL: https://securityorb.com/flash-zero-day-leaks-out-from-hacking-team-hack-patch-expected-real-soon-now/ Type: post Modified: 2015-07-08 An informative article by paul duckin titled  " flash zero-day leak out from hacking team  hack, patch expected real soon" Wouldn't you just know it! Last night we wrote about how Flash troubles come in threes, like those proverbial buses: An emergency update against targeted attacks, followed by... A concerted effort to milk that exploit by Crimeware-as-a-Service crooks, followed by... Kovter, the malware that deliberately patches you against the exploit (but for all the wrong reasons). Stop the presses! Make that four buses that just arrived at once. Earlier this week, a Italian company with the unequivocal name of Hacking Team... ...got hacked, to put not too fine a point on it. Hacking Team is, indeed, into hacking – controversially, as it happens, because its main line of business is selling hacking and interception capabilities at a country level. You might therefore expect a company of that sort to have had some vulnerabilities and exploits up its sleeve. Apparently, that turns out to have been correct, though we say "to have had" because they're no longer "up its sleeve." Thanks to a giant data dump published by the hackers who hacked the hackers, the zero-day cat is out of the bag. Adobe emergency bulletin to read more click here: --- ## Cybercriminal Group Spying On US, European Businesses For Profit URL: https://securityorb.com/cybercriminal-group-spying-on-us-european-businesses-for-profit/ Type: post Modified: 2015-07-08 An informative article by  kelly jackson higgins  at dark reading   titled "Cybercriminal Group Spying On US, European Businesses For Profit" Symantec, Kaspersky Lab spot Morpho' hacking team that hit Apple, Microsoft, Facebook and Twitter expanding its targets to lucrative industries for possible illegal trading purposes. A team of attackers tied to previous hacks of Apple, Facebook, Microsoft, and Twitter, has quietly expanded its cyber espionage operation to snooping on and stealing intellectual property from multi-billion dollar firms in the pharmaceutical, software, Internet, oil and metal mining commodities sectors in the US, Europe, and Canada. But unlike most cyber espionage groups, this is no nation state-sponsored hacking operation. According to researchers at Symantec who have been investigating the so-called Morpho organization for the past two years, this cyberspying operation appears to be run by an organized crime ring with possible US ties. Some 49 different organizations across 20 nations, most in the US, have been hit by the Morpho group, which mainly has set its sights on the victim organizations' Microsoft Exchange and Lotus Domino email servers to spy on corporate correspondence or possibly insert phony emails. to read more click here: --- ## Leaked Emails: How Hacking Team And US Government Want To Break Web Encryption Together URL: https://securityorb.com/leaked-emails-how-hacking-team-and-us-government-want-to-break-web-encryption-together/ Type: post Modified: 2015-07-07 An informative article by Thomas fox-brewster  about “Why China Wants Your Sensitive Data”: Get ready America: one of the most notorious surveillance providers on the planet, Hacking Team TISI NaN%, is expanding in earnest on US shores. And, if it hasn’t collapsed as a result of a hugely embarrassing attack on its servers, the likes of the FBI, Drug Enforcement Agency and a slew of other US government departments will welcome the controversial company with open arms as they seek to break common encryption across mobiles and desktops. In response to the demand, Hacking Team is promising capabilities to crack Apple AAPL -1.08%iPhones, Google GOOGL -0.91% Android devices, and the encrypted anonymising network Tor, whilst poking at the security of mobile apps such as Wickr. This is all according to leaked emails seen by FORBES today, the result of a hack on Hacking Team, a Milan-based outfit that has been criticised for selling to regimes with questionable human rights records, from Sudan to Bahrain to Egypt and beyond. The messages came from the email account of Eric Rabe, Hacking Team’s communications chief, who was unavailable for comment at the time of publication. Rabe details a close working relationship between Hacking Team and the US government in his emails, talking up its previously-reported work with the DEA. An email from 20 May indicated that the formation of Hacking Team USA, likely to arrive this summer if the hack hasn’t derailed the plans, would not change the working relationship with the DEA, which includes intensive training operations in Bogota, Columbia. to read more click here: ---