Friday Squid Blogging: The Far Side Squid Comic

The Far Side is always good for a squid reference. Here’s a recent one.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Law Enforcement Access to Chat Data and Metadata

A January 2021 FBI document outlines what types of data and metadata can be lawfully obtained by the FBI from messaging apps. Rolling Stone broke the story and it’s been written about elsewhere.

I don’t see a lot of surprises in the document. Lots of apps leak all sorts of metadata: iMessage and WhatsApp seem to be the worst. Signal protects the most metadata. End-to-end encrypted message content can be available if the user uploads it to an unencrypted backup server.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Concerned by the Security Risk Affecting Popular Services and Apps? Here’s What We Know.

Several security researchers have recently reported a powerful software bug that could potentially affect thousands of popular websites, services, hosted apps, and even game servers—thanks to an apparent flaw that could allow hackers to compromise or take control of servers that run them. 

 Just as reported by the developers of the popular Minecraft game, this flaw potentially affects servers that run Twitter, Apple’s iCloud, the Steam gaming platform, and a growing number of others that may be vulnerable. 

One research group has dubbed the vulnerability as “Log4Shell,” and the name appears to be sticking. It involves a widely used software used to log information on servers. This software is open source, meaning it is freely available to developers. As a result,  countless organizations and businesses use it on their servers.   

While details are still evolving, researchers are acting with a proper degree of caution given the potential scope of the issue. Needless to say, the immediate level of concern remains high given the potential of the flaw to impact millions of servers, devices, and the people who use them. 

What can an attacker do with this vulnerability?  

At this early stage, a few things appear to be possible: 

  • A hacker could access the logs on impacted servers, gathering the information kept there. This could include any kind of information from chats, usernames, passwords, or other information, depending on what’s being logged by the website, app, or service in question.  
  • In some instances, the vulnerability reportedly allows hackers to execute code or functions that can compromise or even take over the targeted server. For example, there have been reports of compromised servers that were converted to illicitly mine for cryptocurrencies. 
  • Likewise, there is the potential for hackers to further use the impacted servers to distribute malware to the computers, smartphones, and other devices connected to them. As of this writing, we have yet to uncover any such attacks. However, determined hackers could attempt such an attack if they believe there’s some value or return in doing so. 

What if I know someone who plays Minecraft or is running a Minecraft server? 

The developers of Minecraft have provided several steps that detail what both players and server hosts should do to protect themselves. The developers clearly recognize the potential gravity of the situation and are taking a proactive approach in saying, “This vulnerability poses a potential risk of your computer being compromised, and while this exploit has been addressed with all versions of the game client patched, you still need to take [steps] to secure your game and your servers.” We’ve provided the link to those steps here: 

 Recommended steps for Minecraft players and server hosts. 

How else you can protect yourself 

Right now, as this situation evolves, the best step is to keep your eyes open. If the app, service, site, or game you’re on performs strangely, consider signing out and closing it down. Then, perform a security scan on your device to check for viruses, malware, or other threats. Follow the guidance from your online protection software if any results come up. 

You may also consider limiting your app and service usage to the most important activities. If it’s not an urgent or important online task or activity, see about putting it off until more is known. 

Likewise, stay tuned. The details around this vulnerability continue to unfold. As they do, you’ll find further guidance that can help keep you and your family protected from this or any follow-on threats associated with this issue. 

The post Concerned by the Security Risk Affecting Popular Services and Apps? Here’s What We Know. appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Log4Shell Vulnerability is the Coal in our Stocking for 2021

Overview:

On December 9th, a vulnerability (CVE-2021-44228) was released on Twitter along with a POC on Github for the Apache Log4J logging library. The bug was originally disclosed to Apache on November 24th by Chen Zhaojun of Alibaba Cloud Security Team. The impact of this vulnerability has the potential to be massive due to its effect on any product which has integrated the log4j library into its applications. This includes products from internet giants such as Apple iCloud, Steam, Samsung Cloud storage, but thousands of additional products and services will likely be vulnerable. This is just the beginning as Java is heavily used in applications spanning nearly every industry.

What is it?

The vulnerability exists in the way the Java Naming and Directory Interface (JNDI) feature resolves variables.  When a JNDI reference is being written to a log, JNDI will fetch all requirements to resolve the variable. To complete this process, it will download and execute any remote classes required. This applies to both server-side and client-side applications since the main requirements for the vulnerability are any attacker-controlled input field and this input being passed to the log.

To orchestrate this attack, an attacker can use several different JNDI lookups. The most popular lookup currently being seen in both PoCs and active exploitation is utilizing LDAP; however, other lookups such as RMI and DNS are also viable attack vectors.  It’s worth noting that the simplistic LDAP/RMI attack vectors only work with older JDK versions. There are publications that have demonstrated methods to circumvent this limitation to achieve code execution, albeit with added complexity to the attack.

Java object deserialization vulnerabilities are not a new breed of vulnerabilities or attacks. Previous offensive research such as “marshalsec” can be applied to this vulnerability making code execution simplistic.

What can be done about this?

There is a lot of information about different ways to mitigate this vulnerability. The most important and complete mitigation is to update log4j to the stable release version 2.15.0. Some sources are reporting that Java versions 6u211, 7u201, 8u191, and 11.0.1 are not vulnerable to this attack. This is not entirely the case. These versions are more resilient to the LDAP attack vector; however, they do not completely mitigate the vulnerability and are still susceptible to attack. To determine if a Java application is running a vulnerable version, a list of the impacted JAR files can be determined based on the hashes linked here.

The McAfee Enterprise ATR (Advanced Threat Research) team has been closely tracking this vulnerability since it became known. Our initial goal was to determine the ease of exploitation using the public PoC, which we have reproduced and confirmed. This was done using the public Docker container, and a client/server architecture leveraging both LDAP and RMI, along with marshalsec to exploit log4j version 2.14.1. We will be posting a short video to demonstrate the reproduction for anyone who is struggling with this.

Going forward we plan to test variations of the exploit delivered using additional services such as DNS. We may update this document accordingly with results.

In the meantime, McAfee Enterprise has released a network signature KB95088 for customers leveraging NSP (Network Security Platform). The signature detects attempts to exploit CVE-2021-44228 over LDAP. This signature may be expanded to include other protocols or services, and additional signatures may be released to complement coverage.

Full coverage for this vulnerability can be tracked from our Security Bulletin here.

What’s out there?

Resources for the issue continue to evolve and expand rapidly. A growing list of PoCs and tools can be found here:

https://github.com/tangxiaofeng7/apache-log4j-poc

https://github.com/christophetd/log4shell-vulnerable-app

https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b

https://www.greynoise.io/viz/query/?gnql=tags%3A%22Apache%20Log4j%20RCE%20Attempt%22

https://rules.emergingthreatspro.com/open/

https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes

The post Log4Shell Vulnerability is the Coal in our Stocking for 2021 appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Verdict Reached in Josh Duggar Case

Verdict Reached in Josh Duggar Case

A political activist and former star of the reality TV show 19 Kids and Counting has been convicted of two charges relating to the sexual abuse of children.

On Thursday, after a six-day trial that featured ten witnesses, a jury found Josh Duggar guilty of one count of receiving CSAM and one count of possessing CSAM. It took the jury just under seven hours of deliberation to reach its verdict.

The 33-year-old married father of seven now faces a maximum prison sentence of 40 years and a fine of up to $500,000.

Speaking outside the federal courthouse in Fayetteville, Arkansas, after the verdict was reached, Clay Fowlkes, the acting US attorney for the Western District of Arkansas, said: “First and foremost, this shows that no person is above the law.”

Fowlkes continued: “Regardless of wealth, social status, or fame, our office will continue to seek out all individuals who seek to abuse children and victimize them through the downloading, possession, and sharing of child pornography.”

Duggar’s defense attorney, Justin Gelfand, said that his client intends to launch an appeal against his conviction.

Federal authorities began an investigation into Duggar in 2019 after a Little Rock police detective discovered CSA files were being shared by a computer linked to the former reality tv star. The content was downloaded to a device located at a car dealership owned by Duggar. 

Agents from the Department of Homeland Security executed a search warrant at Duggar’s Wholesale Motorcars and seized a computer and two other electronic devices.

The three devices were analyzed by James Fottrell, the director of the Department of Justice’s High Technology Investigative Unit. In court, Fottrell described how a Linux partition, created on Duggar’s workplace computer, circumvented software that monitors internet use for inappropriate activity.

Fottrell found evidence that images and videos of minors being sexually abused could have been accessed and then deleted from Duggar’s work computer.

Duggar was arrested on April 29, 2021, and pleaded not guilty to receiving and possessing CSAM. He was later released from police custody on May 5, 2021, to await trial. 

Judge Timothy Brooks said that sentencing will take place in roughly four months’ time.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

DARPA Announces SMOKE Program

DARPA Announces SMOKE Program

US military network-security researchers have launched a new program to discover more about the tactics of malicious hackers.

The Signature Management Using Operational Knowledge and Environments (SMOKE) program was announced on Tuesday in a broad agency statement put out by officials at the US Defense Advanced Research Projects Agency (DARPA) in Arlington, Virginia.

Signatures are patterns that describe the way in which an organization performs cyber operations.

SMOKE is asking the computer industry to develop methods to identify, model, and mitigate the typical behaviors of threat actors. The aim of the program is to develop technologies to generate evasive cyber infrastructure that accelerates red team cyber operations (CO).

The data-driven tools will achieve this goal through automated threat-informed planning, emulation, and attribution risk assessment.

DARPA stated: “In a complementary activity, SMOKE will develop data-driven tools to automate the discovery of distinguishable patterns of sophisticated cyber threat infrastructure (i.e., signatures).”

The agency outlined two key technical objectives of the project. The first is to include informing operators of adversary signatures as they prepare cyber infrastructure in real time, and the second is to find a way to provide attribution risk assessments for planning and surveillance of the cyber infrastructure that is in use. 

The program’s key research challenges include finding a way to automatically build and traverse associations in large-scale cyber datasets, expanding the use of attribution techniques to non-experts, and discovering latent associations between infrastructure elements.

Researchers will also be tasked with generating useful statistics for planners to predict how well infrastructure configurations will break from, or conform to, desired infrastructure signatures.

Possible approaches that the industry could apply to these challenges include using machine learning to model infrastructure associations through automated pattern recognition and graph-based inference.

The SMOKE program is being managed by Tejas Patel of the Information Innovation Office (I2O). It will be conducted at the unclassified level. 

The start date of the program is anticipated to be August of next year. Proposers are strongly encouraged to propose their own data sources and methods, and to offer up options for program-wide access to those sources.

The deadline to submit proposals to the program is January 31, 2022.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Most Phishing Pages are Short-lived

Most Phishing Pages are Short-lived

The lifespan of most phishing pages is as brief as that of an adult mayfly, according to new research by cybersecurity company Kaspersky.

Between July 19 and August 2, 2021, researchers analyzed 5,307 examples of phishing pages. They found that within 13 hours of monitoring commencing, a quarter of all pages had become inactive.

A sizable chunk of links (1,784) ceased functioning after the first day of monitoring, and half of the phishing pages included in the study survived no more than 94 hours. 

Researchers emphasized the importance of repelling spam attacks with fraudulent links within the first few hours, when the potency of a phishing page is at its highest. 

“It is important for users to remember that when they receive a link and have doubts about the legitimacy of the site, we recommend they wait for a few hours,” said Egor Bubnov, security researcher at Kaspersky. 

“During that time, not only will the likelihood of getting the link in the anti-phishing databases increase, but the phishing page itself can stop its activity.” 

Explaining why the lifecycle of phishing pages is so fleeting, researchers wrote: “With every hour of life of a new site, it appears in more anti-phishing databases, which means that fewer potential victims will visit it.”

What determines the lifespan of a page is how long it takes for site administrators to detect the threat and remove it. 

“Even if phishers have deployed their own server on a purchased domain, if they are suspected of fraudulent activity, the registrars may deprive the phishers of the right to host the data on it,” noted researchers.

When a phisher’s page is identified by site administrators, the cyber-criminal typically prefers to create a new page instead of modifying an existing one. 

“In addition, very rarely phishers may change the page in order to avoid being blocked,” wrote researchers. “For example, if phishers use a brand as bait, they might alter it to another one. However, most pages are simply blocked by the time phishers decide to change the form of activity.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Half of Websites Still Using Legacy Crypto Keys

Half of Websites Still Using Legacy Crypto Keys

The internet is becoming more secure overall, but slightly more than half of websites’ digital keys are still generated via legacy encryption algorithms, according to new research.

Security firm Venafi enlisted the help of noted researcher Scott Helme to analyze the world’s top one million sites over the past 18 months.

The resulting TLS Crawler Report revealed some progress in a few areas.

Nearly three-quarters (72%) of sites now actively redirect traffic to use HTTPS, an increase of 15% since March 2020. Even better, more than half of the sites studied that use HTTPS are on the latest version of TLS: TLSv1.3. It has now overtaken TLSv1.2 to become the most popular protocol version.

In addition, almost one in five of the top one million sites now use the more secure HSTS (HTTP Strict Transport Security) — a 44% increase since March 2020.

Better still, the number of top one million sites using EV certificates is at its lowest point ever in the last six years of analysis. These are noted for slow, manual approval processes which drive too much friction for end users.

Conversely, the much more user-friendly Let’s Encrypt is now the leading Certificate Authority for TLS certificates, with 28% of sites using it.

However, there is also some work to be done. The report found that nearly 51% of sites still use legacy RSA encryption algorithms to generate authentication keys.

Alongside TLS, these form the “machine identities” which help to validate and secure connections between physical, virtual and IoT devices, APIs, applications and clusters.

RSA is significantly less secure than modern alternative ECDSA, a public key cryptography encryption algorithm which boasts greater computational complexity and smaller authorization keys. The latter means they require less bandwidth to set up an SSL/TLS connection, making them ideal for mobile apps and support for IoT and embedded devices, according to Venafi.

Helme branded the RSA findings “a shame and somewhat surprising.”

“I would have expected that the rise in adoption of TLSv1.3 usage would have driving the ECDSA numbers up much more. One of the main reasons to keep RSA around for authentication is legacy clients that don’t support ECDSA yet, but that seems at odds with the huge rise in TLSv1.3 which isn’t supported by legacy clients. We also continue to see use of RSA 3072 and RSA 4096 in numbers that are concerning,” explained Helme.

“If you’re using larger RSA keys for security reasons then you should absolutely be on ECDSA already which is a stronger key algorithm and offers better performance. My gut feeling here is that there’s a lot of legacy stuff out there or site operators just haven’t realized the advantages of switching over to ECDSA.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

NVD: It’s Another Record Year for Vulnerabilities

NVD: It’s Another Record Year for Vulnerabilities

The US-CERT has recorded more vulnerabilities so far in 2021 than any year previously, the fifth year in a row this has happened.

At the time of writing, 18,376 vulnerabilities in production code were recorded in the US National Vulnerability Database (NVD), exceeding the 2020 record of 18,351.

However, there were fewer high severity bugs in the NVD than last year. In 2020 the figure reached an all-time-high of 4381, falling to 3630 so far in 2021.

Pravin Madhani, CEO of K2 Cyber Security, argued that this could be due to improved coding practices and the growing popularity of DevSecOps. However, while organizations are coding better, they’re not testing as thoroughly as they should, allowing bugs to slip through into production, he added.

“The ongoing COVID-19 pandemic has continued to push many organizations to rush getting their applications to production, as part of their digital transformation and cloud journeys,” Madhani said.

“This means the code may have been through fewer QA cycles, and there may have been more use of third party, legacy, and open source code, another risk factor for more vulnerabilities.”

Casey Ellis, CTO at Bugcrowd, argued that the record number of software flaws this year is a reflection of the pace of technological development.

“It’s a probability game, and the more software that is produced, the more vulnerabilities will exist,” he added.

Yaniv Bar-Dayan, CEO at Vulcan Cyber, claimed that more concerning than this year’s NVD list is the “security debt” that continues to pile up year after year.

“If IT security teams are leaving 2020’s vulnerabilities unaddressed, the real 2021 number is cumulative and becoming harder and harder to defend against,” he argued.

“Cybersecurity teams need to do more than just scan for vulnerabilities. We need to work together as an industry to better measure, manage and mitigate cyber risk, or we will be crushed by this growing mountain of vulnerability debt.”

The news comes after bug bounty platform HackerOne revealed its researchers found 66,000 valid vulnerabilities this year, a 20% increase on the 2020 figure.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains