#DEFCON: Exploiting Vulnerabilities in the Global Food Supply Chain

#DEFCON: Exploiting Vulnerabilities in the Global Food Supply Chain

Autonomous farming equipment that can be controlled remotely now helps to feed humanity. But what if that farming equipment were hacked?

On August 8, at the DEF CON 29 conference, an Australian researcher known only as ‘Sick Codes‘ detailed what he referred to as a “tractor load of vulnerabilities” that, if exploited by an attacker, would have dire consequences for the global food supply chain. The researcher explained that modern farming equipment is increasingly being automated, with the equipment being controlled from a centralized console that could have access to many different farms.

The researcher detailed a litany of disastrous potential things that can happen if an attacker were able to gain access to the connected farms. For example, a hacker could direct chemical treatments to be over-sprayed, turning fertile land into infertile land that can’t be used for generations. With a denial of service attack, the ability for a farmer to plant seeds at a critical time can be impacted, preventing the farmer from growing crops. Another large risk would come from the fact that an attacker could gain control of a farming device like a tractor and send it to the wrong location or even drive it off the farm onto a highway.

“What we consider downtime in a website for five minutes, might be the difference between a tractor driving auto track going offline, while the tractor keeps driving, hits a tree, or injures someone,” Sick Codes said.

The Vulnerabilities of the Connected Farm

The researcher noted that nearly every single farm today is connected with a variety of different technologies, including cellular with 4G and 5G, as well as Wi-Fi and GPS. Farming equipment also now increasingly makes use of the LoRa protocol, as well as NTRIP, which helps to provide accurate positioning.

In the case of farming equipment vendor John Deere, Sick Codes noted that information and control can be handled remotely via the John Deere Operations Center, which he and his colleagues were able to hack into.

There were multiple vulnerabilities that the researcher was able to discover, including what he referred to as a basic username enumeration issue. With that vulnerability, he was easily able to identify user names of equipment owners. There was also a Cross Site Scripting (XSS) vulnerability that enabled the researcher to get even more information.

“Obviously XSS is a really basic vulnerability, but what it does show you is that they’re not taking into consideration basic vulnerabilities,” the researcher said.

As it turns out, the XSS was only the least of the problems. Sick Codes detailed how he was able get access to a remote system that essentially gave him control of some connected farming devices that the John Deere Operations Center had access to.

“We could literally do whatever the heck we wanted with anything we wanted on the John Deere Operations Center, period,” he said.

The researcher noted that all the vulnerability information was disclosed to John Deere, which wasn’t immediately responsive. The researcher then also got the U.S government’s Cybersecurity and Infrastructure Security Agency (CISA) involved, which helped to get the issues remediated.

John Deere wasn’t the only farming equipment vendor where the researcher found issues. Case IH was also found to be lacking by Sick Codes. The researcher was able to learn that Case IH was using a publicly accessible Java Melody server, which provided visibility and control into equipment actions.

“We could just browse the Java Melody server for your sessions and it was all publicly accessible, which is ridiculous,” the researcher said.

The researcher noted that though it took some time, eventually he was able to get in contact with Case IH, and the vendor fixed the reported issues.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DEFCON: Exploiting Physical Shopping Carts for Denial of Shopping

#DEFCON: Exploiting Physical Shopping Carts for Denial of Shopping

DoS usually is an acronym that refers to Denial of Service, but according to researcher Joseph Gaby, it can also stand for Denial of Shopping.

On August 8, at the DEF CON 29 conference, Gabay outlined his research into how physical shopping cart immobilization systems work, and how they can potentially be abused by hackers. He noted that there is some pretty cool technology that most people take for granted every time they go shopping that is embedded in physical shopping carts.

Gabay explained that what physical shopping cart immobilization systems provide is a way for a retailer to prevent the theft of the shopping cart. The way it typically works is when the shopping cart is taken outside of an approved boundary, usually a parking lot, one of the wheels will lock itself using an internal mechanism, restricting the ability to take the cart any farther.

“A bunch of very smart people spent a lot of time and money designing a system to prevent people from doing something that they didn’t want them to do,” Gabay said. “This is a technical challenge, and for me, I was curious to see whether or not I could overcome it and dissect it.”

Discovering How Shopping Cart Immobilization Works

The technology that Gabay looked at comes from Gatekeeper Systems and involves several components.

There is a buried wire around the perimeter of the parking lot that sends out a signal. When the cart crosses over this signal, it senses it and uses an internal mechanism to lock up the wheel. Gabay said that store employees have a remote so that they can unlock it and bring it back into service.

Gabay noted that in the U.S. any consumer product that is going out into public that has radio frequency (RF) systems has to be approved by the Federal Communications Commission (FCC). As it turns out, as part of the approval process there is testing and report data that needs to be submitted, which are then searchable in a public database. Using that publicly available information, Gabay was able to learn what frequencies the shopping cart security system was using, which included both the 2.4 GhZ and 7.8 KHz ranges.

Gabay detailed how he built a small antenna and then took it to a parking lot where he knew the system was in place to capture some signals. The Gatekeeper system also has a device known as a CartKey, which a retail store employee can use to unlock a shopping cart that has gone outside the store perimeter. Gabay said he simply went onto eBay and bought a CartKey and then scanned the signals coming from it that were used to unlock a shopping cart.

How to Unlock a Physical Shopping Cart

By comparing the lock and unlock signals and decoding them, Gabay discovered that the unlock signal is just the inverse of the lock signal.

In order to unlock or lock a cart, all he had to do was execute what is known as a replay attack. Gabay explained that a replay attack is when a hacker captures a signal and replays it back, trying to mimic the original device.

“There’s lots of ways to protect against this with various authentication schemes or incrementing a number for the signal sent to the shopping cart wheels,” Gabay said. “They don’t implement any of this; it’s the same signal all the time, which is very good for us.”

Replaying the captured signals could be executed with a phone’s speaker, though that works only at a very short range. Gabay noted that it would be difficult to expand the range for the replay, given the frequencies that the system uses.

“It’s likely that Gatekeeper Systems did this on purpose, so you either don’t accidentally lock a whole bunch of carts or have people like us go out there and lock a whole bunch of carts all at once with nobody knowing what’s going on,” Gabay said.

Practically, Gabay doesn’t suspect that there is all that much risk to his physical shopping cart attack research. He noted that it’s possible to lock or unlock carts within a few feet, but that’s about it. He concluded by suggesting that hackers don’t actually use his research to go disrupt shopping carts by locking them.

“The only person whose day you’ll make worse is the random grocery store employee who has to go around unlocking carts, and that’s just not cool,” he said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DEFCON: Why Social Media Security is Election Security

#DEFCON: Why Social Media Security is Election Security

There may be little if any argument about the vast impact that social media platforms have on the lives of hundreds of millions of people around the world. Social media has also had a profound influence on elections.

In a session at the DEF CON 29 conference on August 7, Sebastian Bay, a researcher at the Swedish Defence Research Agency (FOI), outlined how social media platforms are failing at limiting the risk of false information dissemination, via inadequate security policies that aim to remove fake accounts. In Bay’s view, the failure to block some of the false information should be considered as a critical component of election security.

Bay explained that there are basically two related types of issue that could lead to false information. There is the issue of content itself, and then the issue of inauthentic behavior, which is about bots and other automated mechanisms designed to appear as real human activity.

In Bay’s view, the major social media platforms have made concerted efforts in recent years regarding election-related content. That said, he noted that it is tricky to develop clear policies for inauthentic behavior and other forms of social media manipulation. To be clear, Bay emphasized that inauthentic behavior is not permitted by the social media companies, though it continues to occur.

“The European Union has long underscored the need for social media companies to intensify and demonstrate effective methods to close fake accounts,” Bay said.

The social media companies do in fact report to the European Commission about the number of fake accounts that have been closed, and it’s a huge problem that Bay said is measured in the billions.

For 300 Euros Anyone Can Buy Influence

Underlying the continued challenge of fake accounts is a whole industry that provides

manipulation services for hire, including the infrastructure needed for manipulation services to work.

Bay noted that the infrastructure ranges from fake SIM cards to services used to generate and maintain fake accounts. While Bay’s agency initially referred to the market for fake accounts as a ‘black market,’ the reality is that much of the activity is happening in the open.

“It’s extremely easy to find, and the openness of this industry is still today quite striking,” he said. “We see that the larger social media manipulation service providers fearlessly promote their services on their own websites, mobile app stores and on the social media platforms themselves.”

Bay’s agency has conducted multiple experiments to see how easy it is to buy fake accounts and influence. In both 2019 and 2020, for the small sum of 300 euros, he was able to buy up to 335,000 fake engagements, across different social media providers. The activity was all also reported afterward to the social media companies, with little impact.

“Our conclusion last year was that Facebook, Instagram, Twitter, YouTube and TikTok are still failing to sufficiently combat inauthentic behavior on their platforms, enabling the widespread false information dissemination on their platforms,” Bay stated pointedly.

The same type of research is currently being conducted by Bay and his team in 2021, and he sees little change. Overall, he noted that Twitter is still the industry leader when it comes to countering abuse of their system. Facebook is making progress but still has work to do, and TikTok doesn’t seem to be moving forward much.

“Social media cyber-security equals election security, because we’re seeing that the spread of misinformation undermines the will and ability of voters to vote on Election Day,” Bay said. “We’re seeing that the intentional manipulation of political conversations on social media platforms is happening online, and some of it also happens using technical manipulation, and that can be prevented with additional cybersecurity from the social media companies.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DEFCON: Hacking RFID Attendance Systems with a Time Turner

#DEFCON: Hacking RFID Attendance Systems with a Time Turner

If a computer science student has a scheduling conflict and wants to attend two different classes that occur at the same time, what should that student do?

In a session at the DEF CON 29 conference on August 7, Ph.D. student Vivek Nair outlined a scenario where a hack of the attendance system could, in fact, enable him, or anyone else, to be in two places at the same time. Nair explained that many schools use an RFID-based attendance system known as an iClicker to track whether or not a student is present. The system includes a base station for each classroom or lecture hall, and then each student is required to carry a device, which can also be used to answer multiple-choice questions.

Nair noted that in the popular Harry Potter fiction series there is a magical device known as a Time Turner, which is used to help enable a student to be in two classes at the same time, via time travel.

“Without the luxury of magic, what is the next best thing?” Nair asked. “It is, of course, hacking.”

Building a Time Turner to Exploit a Modern University

In his talk, Nair outlined how the RFID-based system was reverse engineered so he could learn how it works. With that knowledge, he realized that there was no encryption on the device transmissions and it could be possible to mimic a real device.

“It is hard to overstate how vulnerable the system is, and it’s even more shocking that this exact model is currently used at over 1,100 universities, and in nearly 100,000 classrooms,” Nair said.

Nair said that a clone device could be built using a low-cost Arduino electronics platform. He noted that the Arduino is a low-power technology that could be powered with a small battery.

By placing the custom Arduino-based Time Turner in a classroom, it could potentially mimic the actions of a legitimate device. That means it could enable a student to claim to be physically in a class that they aren’t actually in.

Going a step further, Nair demonstrated how the custom Time Turner could also respond to polling quiz questions that a teacher might ask. The system is aware of all the other answers coming into the main base station in the classroom and can be set to automatically select the most common answer to submit, on behalf of the absent student.

“If I were more nefarious, what I could do is try to change the votes of my classmates,” Nair said. “A vulnerability that allows me to change someone else’s answer on the polling system is a major oversight.”

Going a step further, he noted that if he were even more nefarious still, the Time Turner could be used to launch a denial of service attack, flooding the classroom’s base station with hundreds of votes per second. That would quickly overwhelm the host device, eventually causing it to crash and making it impossible for legitimate students to submit answers.

Lack of Authentication

The big problem with the attendance system has to do with authentication.

Nair explained that the way the attendance system works is the student’s device is just broadcasting its presence over a radio signal without any real authentication. He emphasized that the system lacked confidentially, integrity, and availability.

“With regards to confidentiality, there was none to speak of, as I demonstrated when we were able to listen to other students’ answers,” Nair said.

Nair suggested that vendors should implement the use of encryption in transit to help provide some confidentiality. He also recommends the use of a Physically Unclonable Function (PUF) for the student device, which would restrict the ability of an attacker to build their own device with an Arduino.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DEFCON: Ransomware Moves from Nuisance to Scourge

#DEFCON: Ransomware Moves from Nuisance to Scourge

No attack type has been as impactful as ransomware in 2021.

According to a panel of experts at the DEF CON 29 conference, the rising notoriety and impact of ransomware in 2021 has accelerated the need for both government and the private sector to act—though there was no clear consensus on the panel on exactly what actions should be taken.

Chris Painter, co-chair of the Ransomware Task Force, commented that after the ransomware attack against the city of Atlanta in 2018, more awareness could or should have been raised to help limit future impact. That didn’t quite happen, and in 2021, the Colonial Pipeline, Kaseya and JBS meat-processing attacks, among so many others, have further raised the profile of ransomware in the public consciousness. Painter suggested that organizations need to further harden their own defenses to limit potential attackers.

Security researcher Robert Graham, however, doesn’t necessarily think that hardening defenses is the best approach.

“The way you secure a bank is not by locking the front door; the bank has to be open for business and you have to have people come in,” Graham said. “It’s the same thing with networks.”

Graham argued that it is unrealistic for organizations to always patch everything. In his view, if they did that, the network will be down basically all the time. The same is true about email phishing, where users are told not to click on things, which Graham argued is counter-intuitive as users are always clicking on things, and it’s hard for a regular user to distinguish between a legitimate email and one that is not.

Cyber Insurance is Not the Answer Either

The panel also debated the role of insurance in ransomware. While having the financial ability to recover from an attack is good, it’s not a solution.

Lawyer Elizabeth Wharton commented that insurance is just money and doesn’t actually fix the ransomware problem. Wharton was a senior assistant city attorney for Atlanta when that city faced its ransomware incident.

“I think building in resiliency so that when your system starts burning, you can kick right into the playbook, have a plan and know who to call—that’s important,” she said.

To Pay, or Not to Pay

A primary question with ransomware is whether or not victims should pay the ransom.

Painter noted that the Ransomware Task Force did look at the issue of ransom payment but couldn’t agree on a formal recommendation. For some organizations, paying might well be the fastest way to recover, especially when they don’t have enough staff. Though ideally, in his view, the best approach is to provide better tools to organizations of all sizes to better protect themselves and limit risk.

Wharton commented that she has seen smaller counties in economically depressed areas get hit by ransomware. Those smaller local governments typically have small budgets and maybe one person responsible for keeping IT systems online. The choice for those types of group is to pay the ransom, or to not be able to provide services to their constituents. She noted that of course they should have planned better, but reality is that they just need to get back online.

Awareness is Not Enough

A key topic of discussion on the panel was how the awareness of ransomware is a good thing that should help drive better security.

Graham argued that awareness of ransomware is not the problem. Graham noted that lots of organizations have backups of their data, which is often cited as a best practice for ransomware recovery. The problem is that organizations have not looked at how the ransomware got into their systems in the first place and what they were able to do. So for example, if ransomware infected an organization and got control of a Windows domain controller that was connected to the backup server, the backups would also be encrypted by the ransomware.

“So the approach to ransomware is that we’re aware, but we’re not actually aware of the details,” Graham said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DEFCON: A Bad eBook Can Take Over Your Kindle (or Worse)

#DEFCON: A Bad eBook Can Take Over Your Kindle (or Worse)

Amazon’s Kindle e-reader is a popular device that has been on the market since 2007, with approximately 100 million Kindles in use around the world today.

The primary purpose of the Kindle is to enable users to read books. Slava Makkaveev, security researcher at Check Point Software Technologies, had another idea, though; he wanted to see if he could load a book that would exploit the Kindle. At the DEF CON 29 conference, Makkaveev outlined the process by which he was able to exploit a Kindle with a malicious eBook that he was able to create.

“Personally, I use Kindle a lot, but I’ve never heard about a malicious eBook,” Makkaveev said. “That was the reason for me to research how to create such a book that could be used to gain root access remotely and take full control of a Kindle device.”

Makkaveev noted that typically users connect their Kindle devices to a Wi-Fi network. While Wi-Fi could have potentially been used as an entry point to attack the Kindle, in his view using an eBook to reach the device is much easier and will also enable mass attacks.

There are multiple ways that Kindle users can get books, including directly via Amazon, transferred via USB, or via an email. There are also free online libraries that are open, where it’s easy for anyone to upload and download eBooks.

“An attacker can easily upload a malicious book for free access, because no one expects to see malware targeting the Kindle,” Makkaveev said. “Most libraries only care about the correctness of the metadata in the uploaded the book, so when downloading an eBook from an online library you can never be sure of its content.”

Inside the Kindle

Makkaveev explained that basically the Kindle operating system is the Linux kernel

with a set of native programs, mainly provided by the BusyBox open source framework.

The way that many eBooks are read by the Kindle operating system is as a PDF file. There are many different things that can be embedded within a PDF file, so Makkaveev focused his research on learning how the Kindle actually parses the data to show users. During his research he discovered a pair of vulnerabilities.

The first vulnerability is identified as CVE-2021-30354 and is an integer overflow in the Kindle’s JBIG2 decoding algorithm for rendering the words from a PDF file. The overflow could enable an attacker to potentially overwrite specific bits of memory on a Kindle device.

“Now we have remote code execution vulnerability in the context of the PDF reader process,” Makkaveev said.

With the first vulnerability it’s possible to access special internal files on a Kindle, but an attacker would still be somewhat limited. What Makkaveev wanted was to be able to gain remote root access on a Kindle, free of any restrictions. That’s where the second vulnerability comes in, providing a local privilege escalation exploit identified as CVE-2021-30355.

In a brief demo, Makkaveev showed how the whole attack works, where he was able to load a malicious eBook on a Kindle and then take over the device remotely. Once the users click on the book, the malicious payload hidden in the book connects to a remote server, providing the reverse shell that locks the user screen with a window.

“As you can see, we gain the root permissions, so we can do whatever we want,” he said.

An attacker could potentially steal a victim’s Amazon account, delete books, convert the Kindle into a bot to attack other devices, or simply just brick the device, rendering it useless.

Makkaveev concluded his presentation by noting that he reported the issues to Amazon in February 2021 and they have now been fixed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Disney Employees Among Those Arrested in Child Abuse Sting

Disney Employees Among Those Arrested in Child Abuse Sting

Three Disney theme park employees have been arrested in Florida as part of an undercover sting operation to catch sexual predators who target children via the internet.

The suspects are among 17 individuals arrested by the Polk County Sheriff’s Office (PCSO) under the Operation Child Protector initiative. The initiative was a joint effort involving detectives from the Auburndale Police Department, Orlando Police Department, Winter Haven Police Department, and Orange County Sheriff’s Office.

From July 27 to August 1, detectives posed as juveniles on social media platforms, mobile apps, and online dating sites to investigate those seeking to lure children into meeting them for unlawful sexual activity. 

Most of the suspects were arrested when they turned up to what they allegedly believed was going to be a meeting with a minor that would have a sexual outcome. 

One of the suspects, 26-year-old Kenneth Javier Aquino of Orlando, who told deputies he is a lifeguard at Walt Disney World’s Animal Kingdom Lodge, turned up to meet a minor for sex wearing his Disney polo shirt, swimming trunks, and a pair of Crocs. 

In a statement, the PCSO said: “The suspects communicated with and solicited who they thought were children between the ages of 13 and 14 for sex acts. The suspects showed up to an undercover location in Polk County at separate times to meet who they thought were children, to sexually batter them.”

The PCSO alleges that some of the suspects arrested during the sting transmitted pornographic images while grooming and soliciting children online.

The group of suspects, who range in age from 26 to 47 years old, face a total of 49 felony and two misdemeanor charges. All but one of the suspects is from the central Florida area.

Within the group are couple 34-year-old Jonathan McGrew and 29-year-old Savannah Lawrence of Kissimmee, who are accused of soliciting a 13-year-old to come to their apartment and have sex with them. 

McGrew and Lawrence, who are further accused of sending a video of themselves having sex to a minor, told deputies that they are custodians at Walt Disney World Hollywood Studios.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Imprisons Drone Whistleblower

US Imprisons Drone Whistleblower

An intelligence analyst who illegally obtained classified US government documents on drone warfare and leaked them to a journalist has been sentenced to prison.

Daniel Everette Hale met the reporter in April 2013 while attending an event in a bookstore in Washington DC. 

In 2014, while working as a cleared defense contractor at the National Geospatial-Intelligence Agency (NGA), Hale printed six classified documents, all of which were later published by a news outlet.

Hale later printed 36 documents from his Top Secret-clearance computer, including 23 documents unrelated to his work at the NGA, and gave 17 of them to the journalist to publish. Among the 17 were 11 documents marked as Secret or Top Secret.

In 2019, 33-year-old Nashville resident Hale was indicted on five charges relating to the data leak. The news outlet was not identified by prosecutors, but the leaked files described in court records appear to match documents published by the Intercept.

The leaked information exposed the civilian costs of the US military’s drone program, which was ramped up to new heights under President Barack Obama. During his presidency, Obama authorized 542 drone strikes that killed an estimated 3,797 people, including 324 civilians.

Hale pleaded guilty on March 31 to retention and transmission of national defense information. He admitted to communicating with the reporter via phone, text message, email and encrypted messaging platform Jabber, and to meeting with the reporter in person on multiple occasions.

Hale served as an enlisted airman in the US Air Force from 2009 to 2013 before receiving language and intelligence training and being assigned to work at the National Security Agency and deployed to Afghanistan as an intelligence analyst.

At his sentencing on July 27, Hale said it “was necessary to dispel the lie that drone warfare keeps us safe, that our lives are worth more than theirs.”

Before sentencing Hale to serve 45 months in prison, US District Judge Liam O’Grady told the analyst that he “could have been a whistleblower … without taking any of these documents.”

The Reporters Committee for Freedom of the Press said: “Using the Espionage Act in this way to prosecute journalists’ sources as spies chills newsgathering and discourages sources from coming forward with information in the public interest.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Data Breach at University of Kentucky

Data Breach at University of Kentucky

A data breach at the University of Kentucky has exposed the personal information of hundreds of thousands of students and staff.

An annual cybersecurity inspection uncovered the breach, which was caused by a vulnerability in a server associated with the university’s College of Education database. 

News source WDRB reported that more than 355,000 email addresses were exposed in the security incident, with victims located across the world. 

“The database is part of a free resource program known as the Digital Driver’s License for training and test-taking used by K-12 schools and colleges in Kentucky and other states,” said the University of Kentucky’s chief information officer, Brian Nichols, in a statement.

The academic institution said that the names and email addresses included in the database were not limited to students and teachers based in Kentucky. The university revealed that the database also included personal information belonging to students and teachers “in all 50 states and 22 foreign countries.”

The university stated: “The database did not contain financial, health or Social Security information, limiting the potential of identity theft of any kind.”

University officials said that they have notified the school districts impacted by the data breach and informed the appropriate legal and regulatory authorities. 

The university said that it has invested $13m in cybersecurity over the past five years. To prevent a similar incident from occurring, the University of Kentucky’s Information Technology Services will be investing an additional $1.5m to fund cybersecurity measures. 

Among the measures announced by the university are the addition of multi-factor authentication for all critical systems, including email and VPN, and the creation of a new enterprise chief information security officer (CISO) position.

The university said it will also be “implementing next-generation firewalls at the edge of UK’s systems to mitigate potential security events” and taking steps to ensure that critical severity vulnerabilities affecting internet-facing mission-critical systems are patched rapidly. 

A further safety measure that will be rolled out is the automated deprovisioning of accounts for students and employees who have left the university.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk