The Internet is Held Together With Spit & Baling Wire

A visualization of the Internet made using network routing data. Image: Barrett Lyon, opte.org.

Imagine being able to disconnect or redirect Internet traffic destined for some of the world’s biggest companies — just by spoofing an email. This is the nature of a threat vector recently removed by a Fortune 500 firm that operates one of the largest Internet backbones.

Based in Monroe, La., Lumen Technologies Inc. [NYSE: LUMN] (formerly CenturyLink) is one of more than two dozen entities that operate what’s known as an Internet Routing Registry (IRR). These IRRs maintain routing databases used by network operators to register their assigned network resources — i.e., the Internet addresses that have been allocated to their organization.

The data maintained by the IRRs help keep track of which organizations have the right to access what Internet address space in the global routing system. Collectively, the information voluntarily submitted to the IRRs forms a distributed database of Internet routing instructions that helps connect a vast array of individual networks.

There are about 70,000 distinct networks on the Internet today, ranging from huge broadband providers like AT&T, Comcast and Verizon to many thousands of enterprises that connect to the edge of the Internet for access. Each of these so-called “Autonomous Systems” (ASes) make their own decisions about how and with whom they will connect to the larger Internet.

Regardless of how they get online, each AS uses the same language to specify which Internet IP address ranges they control: It’s called the Border Gateway Protocol, or BGP. Using BGP, an AS tells its directly connected neighbor AS(es) the addresses that it can reach. That neighbor in turn passes the information on to its neighbors, and so on, until the information has propagated everywhere [1].

A key function of the BGP data maintained by IRRs is preventing rogue network operators from claiming another network’s addresses and hijacking their traffic. In essence, an organization can use IRRs to declare to the rest of the Internet, “These specific Internet address ranges are ours, should only originate from our network, and you should ignore any other networks trying to lay claim to these address ranges.”

In the early days of the Internet, when organizations wanted to update their records with an IRR, the changes usually involved some amount of human interaction — often someone manually editing the new coordinates into an Internet backbone router. But over the years the various IRRs made it easier to automate this process via email.

For a long time, any changes to an organization’s routing information with an IRR could be processed via email as long as one of the following authentication methods was successfully used:

-CRYPT-PW: A password is added to the text of an email to the IRR containing the record they wish to add, change or delete (the IRR then compares that password to a hash of the password);

-PGPKEY: The requestor signs the email containing the update with an encryption key the IRR recognizes;

-MAIL-FROM: The requestor sends the record changes in an email to the IRR, and the authentication is based solely on the “From:” header of the email.

Of these, MAIL-FROM has long been considered insecure, for the simple reason that it’s not difficult to spoof the return address of an email. And virtually all IRRs have disallowed its use since at least 2012, said Adam Korab, a network engineer and security researcher based in Houston.

All except Level 3 Communications, a major Internet backbone provider acquired by Lumen/CenturyLink.

“LEVEL 3 is the last IRR operator which allows the use of this method, although they have discouraged its use since at least 2012,” Korab told KrebsOnSecurity. “Other IRR operators have fully deprecated MAIL-FROM.”

Importantly, the name and email address of each Autonomous System’s official contact for making updates with the IRRs is public information.

Korab filed a vulnerability report with Lumen demonstrating how a simple spoofed email could be used to disrupt Internet service for banks, telecommunications firms and even government entities.

“If such an attack were successful, it would result in customer IP address blocks being filtered and dropped, making them unreachable from some or all of the global Internet,” Korab said, noting that he found more than 2,000 Lumen customers were potentially affected. “This would effectively cut off Internet access for the impacted IP address blocks.”

The recent outage that took Facebook, Instagram and WhatsApp offline for the better part of a day was caused by an erroneous BGP update submitted by Facebook. That update took away the map telling the world’s computers how to find its various online properties.

Now consider the mayhem that would ensue if someone spoofed IRR updates to remove or alter routing entries for multiple e-commerce providers, banks and telecommunications companies at the same time.

“Depending on the scope of an attack, this could impact individual customers, geographic market areas, or potentially the [Lumen] backbone,” Korab continued. “This attack is trivial to exploit, and has a difficult recovery. Our conjecture is that any impacted Lumen or customer IP address blocks would be offline for 24-48 hours. In the worst-case scenario, this could extend much longer.”

Lumen told KrebsOnSecurity that it continued offering MAIL-FROM: authentication because many of its customers still relied on it due to legacy systems. Nevertheless, after receiving Korab’s report the company decided the wisest course of action was to disable MAIL-FROM: authentication altogether.

“We recently received notice of a known insecure configuration with our Route Registry,” reads a statement Lumen shared with KrebsOnSecurity. “We already had mitigating controls in place and to date we have not identified any additional issues. As part of our normal cybersecurity protocol, we carefully considered this notice and took steps to further mitigate any potential risks the vulnerability may have created for our customers or systems.”

Level3, now part of Lumen, has long urged customers to avoid using “Mail From” for authentication, but until very recently they still allowed it.

KC Claffy is the founder and director of the Center for Applied Internet Data Analysis (CAIDA), and a resident research scientist of the San Diego Supercomputer Center at the University of California, San Diego. Claffy said there is scant public evidence of a threat actor using the weakness now fixed by Lumen to hijack Internet routes.

“People often don’t notice, and a malicious actor certainly works to achieve this,” Claffy said in an email to KrebsOnSecurity. “But also, if a victim does notice, they generally aren’t going to release details that they’ve been hijacked. This is why we need mandatory reporting of such breaches, as Dan Geer has been saying for years.”

But there are plenty of examples of cybercriminals hijacking IP address blocks after a domain name associated with an email address in an IRR record has expired. In those cases, the thieves simply register the expired domain and then send email from it to an IRR specifying any route changes.

While it’s nice that Lumen is no longer the weakest link in the IRR chain, the remaining authentication mechanisms aren’t great. Claffy said after years of debate over approaches to improving routing security, the operator community deployed an alternative known as the Resource Public Key Infrastructure (RPKI).

“The RPKI includes cryptographic attestation of records, including expiration dates, with each Regional Internet Registry (RIR) operating as a ‘root’ of trust,” wrote Claffy and two other UC San Diego researchers in a paper that is still undergoing peer review. “Similar to the IRR, operators can use the RPKI to discard routing messages that do not pass origin validation checks.”

However, the additional integrity RPKI brings also comes with a fair amount of added complexity and cost, the researchers found.

“Operational and legal implications of potential malfunctions have limited registration in and use of the RPKI,” the study observed (link added). “In response, some networks have redoubled their efforts to improve the accuracy of IRR registration data. These two technologies are now operating in parallel, along with the option of doing nothing at all to validate routes.”

[1]: I borrowed some descriptive text in the 5th and 6th paragraphs from a CAIDA/UCSD draft paper — IRR Hygiene in the RPKI Era (PDF).

Further reading:

Trust Zones: A Path to a More Secure Internet Infrastructure (PDF).

Reviewing a historical Internet vulnerability: Why isn’t BGP more secure and what can we do about it? (PDF)

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK and German Police Take Down 21 Jihadist Websites

UK and German Police Take Down 21 Jihadist Websites

Service providers have suspended over 20 websites in Germany and the UK for disseminating online terrorist propaganda, Europol has revealed.

In the last week of October, a referral action targeted 50 sites that police flagged for promoting violent jihadist ideology in support of terrorist groups such as the Islamic State (IS) and al-Qaeda.

Police requested that service providers, including registrars, hosting firms and internet infrastructure companies, check these against their terms of service, which resulted in 21 being suspended.

“Terrorist groups traditionally relied on self-administered websites for the storage and dissemination of their propaganda,” Europol explained.

“With mainstream social media companies intensifying their efforts to suspend offending content from their platforms, terrorist groups and their online supporters increasingly use websites as a vital tool to broadcast their message and create archives for their propaganda releases. In spite of frequent suspensions, these websites continue to move their content to new domains.”

Fewer than half the number of sites originally flagged by police were taken down because law enforcers currently rely on voluntary co-operation with the service provider community. This is co-ordinated by Europol’s EU Internet Referral Unit (EU IRU), set up in 2015.

However, this is set to change with the introduction of a new EU regulation in April 2021. Once enacted, this will give EU authorities the power to demand the removal of online terrorist content via a dedicated platform dubbed “PERCI.”

In August, Europol warned that while official propaganda from IS had dwindled over the past year after disruption by allied forces, informal supporter networks continue to pose a problem.

It claimed that IS-supporting media outlets had not only upped their own output but also offered help to these supporters on how to use encrypted communications to stay hidden online.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ukrainian Cops Bust Mobile Device Hacking Group

Ukrainian Cops Bust Mobile Device Hacking Group

Ukrainian investigators are celebrating after claiming to have arrested a prolific mobile hacking gang which targeted victims via Apple and Samsung phishing sites.

Cyber-specialists arrested five alleged members of the so-called “Phoenix” group at the Security Service of Ukraine (SSU).

Users were apparently lured to their phishing sites and, after downloading an app there, would unwittingly give the hackers remote access to their devices.

“The data obtained in this way allowed the attackers to withdraw funds from citizens’ accounts and sell information about their private lives to third parties,” the SSU explained. “The average ‘cost’ for unauthorized access to a mobile phone owner’s account was $200.”

The group also made money by unlocking lost and stolen Apple gadgets which were subsequently sold through a network of stores in the cities of Kyiv and Kharkiv.

Phoenix had apparently been active for at least two years, amassing hundreds of victims over that time.

Investigators searched five addresses, including the suspected hackers’ homes and ‘telephone shops’ which were actually “underground technical centers.”

They seized stolen mobile phones and computing equipment including software and hardware designed to hijack accounts.

Interestingly, the five residents of Kyiv and Kharkiv are all said to have graduated from higher technical colleges. A lack of opportunities for the large number of science and technology graduates in the region is one explanation for the size of the Russian-speaking cybercrime underground.

Ukrainian police last month arrested a suspected botnet herder responsible for controlling an automated network of 100,000 compromised machines to launch DDoS and other attacks.

The alleged Phoenix group members are facing charges related to illegal interference in computers and networks under Article 361 of the country’s criminal code

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FBI: 2021 Holiday Season Fraud Could Exceed $53m

FBI: 2021 Holiday Season Fraud Could Exceed $53m

The $53m figure reported lost to scammers during the 2020 holiday season could be even higher this year thanks to the continued impact of the pandemic, the FBI has warned.

Public Service Announcement on the eve of the Thanksgiving holiday yesterday revealed that the Feds received over 17,000 complaints of non-delivery of goods ordered online last year.

The FBI said scammers use multiple tactics to lure victims, advertising items for sale via unsolicited emails, untrusted websites, and social media.

Sometimes the goods are never delivered, and sometimes they are counterfeit. Hard-to-source items like event tickets and gaming consoles are widespread, the FBI claimed. Rumors of shortages of certain items due to the pandemic are likely to ramp up the pressure on individuals to make poor decisions, it added.

In luring unwitting shoppers into making a purchase, the fraudsters also access the victims’ personal and financial information.

Other ways to obtain this info are via unsolicited messages that claim the user has won a prize draw or gift card and can only enter their details to claim it. Fraudulent online surveys are often used for the same purpose.

“The holidays are also a popular time for pet purchases. Criminals will use legitimate website photos to promise the non-existent pet to multiple buyers,” the notice continued.

“Red flags include added shipping/carrier fees, taxes, and or vaccination costs. If purchasing a pet online, consider meeting the animal and owner via video chat before buying to reduce the chances of being scammed.”

The FBI listed a range of steps online shoppers should be taking to protect themselves from holiday seasons scams. These include: avoiding password reuse; keeping AV up-to-date on all machines; not clicking on links in unsolicited messages; and being wary of “too-good-to-be-true” offers.

Retailers can also do their bit to protect potential customers. A study this week found that 81% of UK retailers still had not implemented the highest level of anti-phishing protocol DMARC

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

McAfee Enterprise Defender Blog | CISA Alert: MS Exchange & Fortinet Vulnerabilities

Threat Summary

On November 17, 2021, The US Cybersecurity & Infrastructure Security Agency (CISA) pushed an Alert entitled “Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activities” which you need to pay attention to if you use Microsoft Exchange or Fortinet appliances. It highlights one Microsoft Exchange CVE (Common Vulnerability & Exposure), three Fortinet CVEs and a list of malicious and legitimate tools associated with this activity.

Threat Intelligence Update from McAfee Enterprise

A few hours later our Advanced Threat Research (ATR) team published a new campaign in MVISION Insights under the name “Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities”. Immediately after, MVISION Insights started to provide near real-time statistics on the prevalence of the tools associated to this threat campaign by country and by sector.

Figure 1. MVISION Insights Global prevalence statistics for this campaign on Nov 19, 2021

In this blog I want to show you how you can operationalize the data linked to this alert in MVISION Insights together with your investigation and protection capabilities to better protect your organization against this threat.

Tracking New Campaigns and Threat Profiles, Including This Alert

MVISION Insights combines Campaigns and Threat Profiles in the same list, and you can change the order from “Last Detected” to “Last Added” as shown below.

Figure 2. List of MVISION Insights campaigns last added, with a selection of this campaign

On the left of figure 2, a color code shows you the severity assigned by the McAfee ATR team (Medium for this campaign), in the middle you can see whether we have seen detections of the analysed IOCs in your country or in your sector

If you are a McAfee Endpoint Security or IPS customer, on the right of figure 2 you can see whether you have had any detection of these IOCs by your McAfee Endpoint Security or IPS, or whether Endpoint Security has found exposed devices, or devices with insufficient Endpoint Security protection

As shown in figure 2, you can also click the campaign’s preview to read a short description, and the labels given by MVISION Insights:

  • APT
  • Ransomware
  • Tool
  • Vulnerability

In this case, you can see that CISA suspects this campaign to be associated with an APT threat group. It includes Ransomware behaviors. The labels also highlight the use of hacking tools and vulnerabilities which you can then view in the Campaign details. Last September we hosted a webinar focused on threat intelligence and protection against hacking tools.

The campaign description highlights the usual use of “devices encrypted with the Microsoft Windows BitLocker encryption feature”.

The campaign’s details also provide links to other sources, such as the CISA alert in this case.

Figure 3. Original CISA Alert used for this campaign

Evaluating the Risk and Whether you Could be Exposed

Once you have identified campaigns which could potentially hit you, you can evaluate your risk and whether you could be exposed because you could have:

        • Vulnerabilities listed
          In figure 4, you can see that in this campaign there is 1 CVE for Microsoft Exchange, and 3 CVEs for Fortinet FortiOS
        • Exposed devices
          In figure 2, there are none
        • Insufficient Endpoint Security protection
          In Figure 2, there are none

Figure 4. List of Common Vulnerabilities and Exposures (CVEs) in this campaign’s details

If you are a McAfee Enterprise customer, the MVISION Insights Endpoint Security Posture checks whether you have enabled the necessary Endpoint Security features to have the best level of protection across your estate.

In the example below:

  • 3 Endpoint Security devices have an insufficient AMcore content to detect all campaigns
  • The warning sign shows that some devices have been excluded from this assessment by the MVISION Insights administrator
  • 1 Endpoint Security device is missing Real Protect Client and Cloud
  • 1 Endpoint Security device is missing Adaptive Threat Protection (ATP)
  • 1 Endpoint Security device has an unresolved detection for a Medium Severity Campaign

As seen previously, this lab environment has sufficient protection to detect the “Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities” campaign IOCs. However, to have full Endpoint protection, GTI, On-Access scan, Exploit Prevention, Real Protect and ATP must be enabled.

Figure 5. McAfee Endpoint Security Detection across all MVISION Insights campaigns

Hunting for Detections and IOCs in Your Environment

If you are a McAfee Endpoint Security or IPS customer, the detections related to the campaign’s IOCs are automatically mapped by MVISION Insights as shown in Figure 6.

Figure 6: McAfee Endpoint Security Detection across all MVISION Insights campaigns

You can also use your Endpoint Detection and Response (EDR) or SIEM solution to search for the presence of IOCs. As you can see below in Figure 7, we have categorized the IOCs, and in this instance:

  • 4 File Hashes have been analyzed by our Threat Research experts and 3 File Hashes have NOT been fully analyzed at this time
  • 2 File Hashes are dual use, and therefore are non-Deterministic
  • 5 File Hashes are partially unique (2 Malicious and 2 Probable Malicious)

If you are an MVISION EDR customer, you can automatically search for the presence of these IOCs across your estate from MVISION insights

Otherwise, you can export the IOCs and hunt them in your EDR, and SIEM, to examine the evidence of a potential compromise and escalate the case to a level2 or level3 analyst to run a full investigation.

Additionally, you can also use the MVISION APIs with a third-party Threat Intelligence Platform such as ThreatQ, ThreatConnect or MISP to orchestrate this threat hunting capability.

Figure 7: MVISION Insights IOCs for this campaign

You can also leverage the new Campaign Connections feature (Figure 8) to check whether these IOCs are also listed in other campaigns or threat profiles. Campaign collection uses graphs to connect all the MVISION campaigns, and threat profile data such as:

  • IOCs
  • MITRE techniques
  • MITRE and McAfee Tools
  • Threat actors and groups
  • Labels
  • Prevalent countries and sectors
  • Detections

Figure 8: MVISION Insights Campaign connection using the IOCs of this campaign

Hunting TTPs in Your Environment

Beyond the IOCs, your Threat Analysts can also leverage the MITRE Techniques and Tools related to this campaign and documented in MVISION Insights.

Figure 9: MITRE Techniques and Tools observed in MVISION Insights for this campaign

For example, here you could use MVISION EDR to look for the presence of:

  • Unusual Scheduled Tasks
  • Unusual WinRAR archives
  • Unusual local and domain account usage
  • Mimikatz behavior

Then you can quarantine suspected devices before running a full remediation. You can also check that your Endpoint Security solution has credential theft protection capabilities such as ENS credential theft protection.

Vulnerability Management

If your organization hosts Microsoft Exchange or Fortinet appliances you will need to apply the recommended patching and upgrade recommendations. If you find indicators of compromise you might want to increase the priority of the tickets, asking the Fortinet and Microsoft Exchange administrators to fix these CVEs due to these suspicious activities.

Summary

To better assess your risk and exposure against this campaign you should review your current capabilities to:

  • Be informed about the latest relevant CISA alerts and other new campaigns and threat actors
  • Hunt the IOCs, Tools and Techniques associated
  • Identify Common Vulnerabilities and Exposures
  • Review your level of Endpoint Protection against these threats

McAfee Enterprise offers Threat Intelligence, and Security Operations workshops to provide customers with best practice recommendations on how to utilize their existing security controls to protect against adversarial and insider threats; please reach out if you would like to schedule a workshop with your organization.

The post McAfee Enterprise Defender Blog | CISA Alert: MS Exchange & Fortinet Vulnerabilities appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Joke Hitman Website Catches Plotting Michigander

Joke Hitman Website Catches Plotting Michigander

A website, initially set up by graduates to offer IT support, has caught a criminal after a woman used it to try to arrange the murder of her ex-husband. 

RentaHitman.com is a darkly titled domain set up by a group of friends after they graduated from a California business school with degrees in IT. 

The site’s operator, Novato resident Bob Innes, told SFGATE that ‘hit’ in the site’s title referred to website clicks and that ‘man’ represented the team of IT professionals whose services were available to hire. 

Since the domain was registered in 2005 with the tagline, “Your Point & Click Solution!” it has received hundreds of inquiries from users seeking to engage an actual hitman to murder on their behalf. 

Innes eventually fully converted the domain into a joke hitman-for-hire site. Despite the inclusion of fake details, such as the statement: “Rest assured that your information will remain private since Rent-A-Hitman is the only organization in the world that is 100% compliant with the Hitman Information Privacy & Protection Act of 1964,” some users still took the site seriously.

One such user was 52-year-old Wendy Lynn Wein of South Rockwood, Michigan. In the spring of 2020, Wein attempted to use the site to solicit the murder of her ex-husband. 

Wein filled out a ‘service request’ form on the site using a fake name. Her details were then passed onto the Michigan State Police. When an undercover detective, posing as a professional hitman, contacted Wein, she agreed to meet with them.

Wein then gave the detective her former husband’s place of employment, work schedule and home address and told him that she would pay $5,000 to have him killed. 

Later that day, Wein met up with the detective and paid what she believed was a $200 deposit to secure their services as a hitman.

On November 12, Wein pleaded guilty to using a computer to commit a crime and solicitation of murder. 

Wein will be sentenced on January 13 2022 by 38th Circuit Court judge Daniel White, who presided over the case. Under her plea agreement, Wein will serve no more than nine years in prison.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

YouTube Live Crypto Scams Made Nearly $9m in October

YouTube Live Crypto Scams Made Nearly $9m in October

Cyber-criminals are making millions of dollars by promoting fake cryptocurrency giveaways on social media, according to new research by Tenable.

The cyber exposure platform today warned social media users to be alert to scams involving Bitcoin, Ethereum, Dogecoin, Cardano, Ripple and Shiba Inu. 

To make the giveaways appear legitimate, scammers are using footage from public figures associated with cryptocurrency. Notable individuals who the scammers have exploited include Michael Saylor, chairman and CEO of MicroStrategy and a fervent supporter of Bitcoin; Vitalik Buterin, Ethereum co-founder; Charles Hoskinson, Cardano founder and Ethereum co-founder; Brad Garlinghouse, CEO of Ripple Labs; and Elon Musk, CEO of Tesla and SpaceX.

Tenable’s researchers calculated that one subset of YouTube Live crypto scams unlawfully netted at least $8.9m in October alone.

Bitcoin scams were the most profitable, generating an average amount of $1.6 million per scam and a total of $8.2m. Scams involving Ethereum were the second most profitable, receiving $413k in stolen funds with an average profit of $82,778 per scam.

Perpetrators running Shiba Inu scams earned $239k in funds, receiving on average $34,192 per scam.

“Scammers recognize that users place a lot of trust in influential voices so create fake videos featuring the founders and co-founders of cryptocurrencies as well as notable individuals associated with cryptocurrency companies or CEOs of companies who have promoted the use of and/or discussed the purchase of cryptocurrencies for their company balance sheets,” said a spokesperson for Tenable. 

The YouTube Live stream scams shared a familiar tactic: directing users to external websites that claim to double one’s cryptocurrency. 

Satnam Narang, staff research engineer at Tenable, said it was important for users to be skeptical of YouTube Live videos promising giveaways from notable figures.

“Never send cryptocurrency to participate in a giveaway, as it’s unlikely to be genuine, and you won’t be able to recover your digital money once it has been sent,” warned Narang. 

YouTube users who come across a scam can report the content by clicking on the flag icon displayed beneath the video and selecting “scams or fraud” in the dropdown menu.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains