Wednesday, May 28, 2014

Be careful with cybercafé computers

Cybercafé’s offer a convenient way to use a networked computer when you are away from home or office. But be careful. It's impossible for an ordinary user to tell what the state of their security might be. Since anyone can use them for anything, they have probably been exposed to viruses, worms, Trojans, keyloggers, and other nasty malware. Should you use them at all? They're okay for casual web browsing, but they're NOT okay for connecting to your email, which may contain personal information; to any secure system, like the network or server at your office, bank or credit union; or for shopping online.

A perfect example is a current co-worker who went to the local Starbucks for his morning coffee. He opened up his mobile device and connected to the free Wi-Fi. Now this in itself was not a bad thing but what happens next is the issue. He logged onto his Wells Fargo account. Made a few inquiries and transactions and logged out of his session. A couple of days later he was notified of a compromise on his Wells Fargo account. Alas, he was the victim of cyber theft.
This co-worker has now spent the last two weeks working with the fraud group to get his account moved over to a new account. I don’t feel bad for the co-worker only because he is blaming Wells Fargo for all the complications in getting his account back up and running.  Wells needs to follow protocol. Being a large bank different departments are scattered across multiple call centers throughout the country. Yes it is frustrating for the consumer but the bigger issue here is that the co-worker decided to connect to a public Wi-Fi and conduct personal business.

The moral of this story is, you never know who is watching. Hackers are everywhere. It’s ok to connect to the free Wi-Fi at a hotel, coffee shop etc but please do not conduct any personal or confidential business. You never know who will be watching.

Have a safe day.

JMS

Monday, May 5, 2014

Windows XP based ATMs could be hacker’s paradise

Windows XP based ATMs could be hacker’s paradise

A recent study shows that 90% of American banks ATMs still run Windows XP or even worse Windows CE. Microsoft has discontinued support of XP as of April 8, 2014. What could this mean for the banking and finance industry? The main concern across the board is security, as hackers could soon have an unmonitored forum, putting data and end users at risk.

Some major banks are cutting deals with Microsoft to extend life support for their Windows XP machines while they replace their fleet of ATMs, according to CNN, but replacing ATM operating systems is a major undertaking. There are over 200 thousand ATMs in the United States, according to Retail Banking Research in London. The labor required to upgrade software, or even replace the entire system inside an ATM, could cost anywhere between $1000 and $3500 apiece.

After April 8, bank customers might be less concerned to use nondescript ATM found in malls, bars and small convenience stores. These 190,000 independently run kiosks make up the other half of the nation’s ATMs, and nearly all of them run and even older, simpler operating system which Microsoft still supports.

As a consumer you will not know what the operating system behind the scenes is. Ask questions of your bank to see what their plans are for upgrading. I have read where Dibold is working with financial institutions on upgrading systems. My one take away from this is, we all knew XP was going away. Microsoft provided us 18 months to prepare. Why didn’t these banks begin the process. Was it money or man power? Whatever the reason, for the next few months you will see more issues centered around ATMs and it will truly be a hacker’s paradise.

Be safe.

                

Sunday, April 27, 2014

Heartbleed follow-up

Overview of events
On Monday April 7th, a serious vulnerability was identified in one of the most popular implementations of the SSL protocol, called OpenSSL.  SSL is a very important security protocol used throughout the Internet. Not only does SSL encrypt your online communications, but it helps ensure you are connecting to legitimate websites when you do things like shop or bank online


What it does
The Heartbleed vulnerability allows a hacker to connect to a webserver and harvest sensitive information, which may include your login and password. If an attacker were able to harvest such information, they could use that information to log into any of your accounts using the same username and password. Most sites including Facebook, Yahoo, CNN were affected.


Steps you should take
There are several steps you can take to protect yourself. Not only will these steps help protect you against the Heartbleed vulnerability, but they will help protect you against many other attacks in the future

·         First, change your passwords on websites that you know were vulnerable and have patched the vulnerability, starting with your most important accounts first. If you do not know if a website was vulnerable, go ahead and change your password anyway. This is a great time to update your passwords and improve your online security.
·         Make sure you update your passwords you use strong, hard-to-guess passwords. In addition, if the website supports something called two-step verification, enable it. This is an additional step that helps make your online account more secure. Finally, if your password has personal questions, we recommend changing the answers.
·         Make sure you are using a separate, unique password for each of your online accounts. That way, even if one website is compromised, all of your other accounts will still be safe. Can’t remember all of your passwords? Congratulations, that means you are using strong passwords. We highly recommend you use this opportunity to start using a password manager that stores all of your passwords securely. These are great tools that can not only simplify your online activities, but help make them far more secure.
·         Do not forget your email clients. If your email client, such as Outlook or Apple Mail, is using SSL to connect to your mail server, you may need to change those passwords as well.

Have a safe day


Wednesday, April 16, 2014

Heartbleed bug leaves everyone heartbroken


We all thought that April 8, 2014, will go down in computer history as the day when one of Microsoft's most beloved products reached the end of support.

As it turns out, we were wrong, as that expected occasion was overshadowed by an unexpected event: the public revelation of a bug that affects OpenSSL, one of the most widely used implementations of the SSL and TLS protocols and, thus, a wide array of operating systems and applications, computers and Internet-of-Things devices, smartphones and tablets.

OpenSSL, an open-source cryptographic library that is the default encryption engine for popular Web server software and is used in many popular operating system and apps, sports a critical vulnerability that can easily be misused by attackers to impersonate online services and steal information users believe to be protected by SSL/TLS.

What's even worse is that such an attack leaves no physical trace in the logs, so it's impossible to tell whether the vulnerability - dubbed the "Heartbleed Bug" by the Codenomicon and Google researchers who identified it - has been exploited in the wild since it was first introduced in December 2011.

Find out:

More details about the vulnerability



 


Monday, April 14, 2014

So I am getting bombarded with calls, emails and text messages with the following topics.

XP is no more. What do I do? 
Simple answer. Buy a new computer, laptop, tablet with Windows 7 or 8.1. XP is 12 years old and you most likely have an old computer that is at least 7 years old. Windows 7 will not run on that hardware. I could recommend you look at Tiger Direct or Dell for the best deals. 

Heartbleed... What  do I do?
At this point in time most sites have updated their sites and re mediated their vulnerabilities. This would be a good time to change your passwords on all the sites you have an account with. Also,  you may want to look at a password manager and keep a record of all your username/passwords. Yes, you should not be using the same account credentials for all your sites. Just think about it... If you use the same account for your email as you do for your banking site then a hacker could easily access all your accounts and god knows what happens from there.
Best free password program I could recommend is keepass. 
As always, feel free to contact me with any questions or comments.

Thanks
Joe


Wednesday, March 26, 2014

I thought you might find this interesting:

Trustwave is facing a lawsuit in relation to (and along with) Target because they allegedly failed to identify critical vulnerabilities that were leveraged by hackers during the Target breach (link provided below).  This is just another clear cut example as to why its so important to put your energy into selecting a genuine penetration testing vendor.


http://www.cnet.com/news/security-firm-trustwave-sued-in-connection-with-target-breach-report/

My two cents. I have used Trustwave for PCI services for 5 years now. They are the largest QSA organization out there and do complete the most assessments. This does not make them the best. The level of consultants who come onsite have little to no knowledge of systems or how an organization operates. I think there needs to be a more comprehensive testing program for both companies and individual QSA's to ensure companies are properly being audited. 

Send me your thoughts at jncsousa@outlook.com

Friday, March 21, 2014

YOUR BIGGEST THREATS ARE COMING FROM INSIDE

While rogue employees, such as the infamous Edward Snowden, can be a corporation’s greatest fear, the reality is your employees are probably unknowingly your greatest threat. Better than 60 percent of security events are the result of an inside attack.

Of that group, about 80 percent are from inside people unintentionally compromising your company’s security. They don’t mean to, it’s just that the nature of their job gives them direct access to highly sensitive data. They may not be taking their own security as seriously as you’re taking corporate security.
It’s frightening how careless many users are about corporate security. For example, 40% of all users who have access to a corporate infrastructure use the same login credentials on other non-corporate sites such as Facebook, Twitter, and LinkedIn, said Schoenberg. That’s just one very common example, another is someone with authorized, but unapproved access. It could be an employee that’s authorized to have access to the network from 9am to 5pm, but then you see a single access at 2am. What exactly happened there is not clear, but it definitely would require further investigation.

To combat the unintentional insider threat, all organizations should conduct an audit of your internal team. Where could people be making the biggest impact? A smaller organization could begin a manual audit process, while a larger organization will want to use audit log management tool.

Thursday, March 6, 2014

The end of Windows XP

Windows XP has proven to be one of the most popular operating systems in computing history, at one point
 it was used on most of the computers around the  world. However Windows XP is old, and all support  for it from Microsoft will be ending in April of this year.  This  means Microsoft will no longer release any end-user updates or security patches. With approximately 25% of  the world’s desktop computers still running Windows XP (only Windows 7 is more popular), millions of people  will be at greater risk once this happens. Keep in mind, home users are not the only ones who will be impacted  as XP is still widely used in offices, industrial control systems, ATM machines, medical systems, point-of-sale  terminals, and other devices. Below we describe what the risks are once Windows XP is no longer supported .and steps you can take to protect your

You may not know it, but your computer’s operating system has a limited lifespan. The vendor who created the operating system will provide updates and patches that add new features, improve the stability and performance  and keep your system secure. The problem is that eventually the vendor will no longer support your operating system, at some point they have to focus their resources on their latest and greatest technologies. This means that once an operating system is no longer supported, the vendor will no longer release patches or updates even when they know your computer is vulnerable and cyber criminals can hack into it. This is what is going to happen with Windows XP after April. 

To protect yourself and you can afford it I highly recommend you purchase a new computer. Many computers running Windows XP cannot support today’s  newer operating systems. If you cannot afford a new computer then ensure you have the latest AV and see if upgrading is an option.

12 years is a long time to hold onto an operating system. Good bye XP. Hello 21st century computing.

Have a safe day

Monday, March 3, 2014

Security Tips - Social Media


These days nearly everyone uses at least one social networking site. Social networking sites potentially expose users to a myriad of security risks including social engineering and malicious code attacks.
So what can you do to try to protect yourself? Here are some tips from the United States Computer Emergency Readiness Team (US-CERT):

Limit the amount of personal information you post - Do not post information that would make you vulnerable, such as your address or information about your schedule or routine. If your connections post information about you, make sure the combined information is not more than you would be comfortable with strangers knowing. Also be considerate when posting information, including photos, about your connections.
Remember that the internet is a public resource - Only post information you are comfortable with anyone seeing. This includes information and photos in your profile and in blogs and other forums. Also, once you post information online, you can't retract it. Even if you remove the information from a site, saved or cached versions may still exist on other people's machines.
Be wary of strangers - The internet makes it easy for people to misrepresent their identities and motives. Consider limiting the people who are allowed to contact you on these sites. If you interact with people you do not know, be cautious about the amount of information you reveal or agreeing to meet them in person.
Be skeptical - Don't believe everything you read online. People may post false or misleading information about various topics, including their own identities. This is not necessarily done with malicious intent; it could be unintentional, an exaggeration, or a joke. Take appropriate precautions, though, and try to verify the authenticity of any information before taking any action.
Evaluate your settings - Take advantage of a site's privacy settings. The default settings for some sites may allow anyone to see your profile. You can customize your settings to restrict access to only certain people. However, there is risk that even this private information could be exposed, so don't post anything that you wouldn't want the public to see. Also, be cautious when deciding which applications to enable, and check your settings to see what information the applications will be able to access.
Use strong passwords - Protect your account with passwords that cannot easily be guessed. If your password is compromised, someone else may be able to access your account and pretend to be you.
Check privacy policies - Some sites may share information such as email addresses or user preferences with other companies. This may lead to an increase in spam. Also, try to locate the policy for handling referrals to make sure that you do not unintentionally sign your friends up for spam. Some sites will continue to send email messages to anyone you refer until they join.
Use and maintain anti-virus software - Anti-virus software recognizes most known viruses and protects your computer against them, so you may be able to detect and remove the virus before it can do any damage. Because attackers are continually writing new viruses, it is important to keep your definitions up to date.


Introduction – Social Networking and Security Risks
With any new tool or application, it is always important to keep a close watch on its security implications. Facebook comes with its own set of security concerns which can put your information systems and/or personal data at risk. This article will look at some of these risks and identify possible solutions to help protect you, your personal information and your company data.

Facebook - Three of the most popular features of Facebook are the ability to add Friends, update your status and run applications such as games and quizzes. A “Friend” is anyone on the Facebook network whom you allow to see various levels of personal information, such as job, birth date, photos, group membership, comments and list of other Friends. You can even play online games and keep others updated on your daily life. Friends can also see Friends of Friends, meaning individuals, whom you have officially befriended and may never have met, may have visibility into your personal information and whereabouts.

Updates - At the top of the user’s Facebook profile is the Update field, which allows the user to post a sentence or paragraph regarding any topic at any time. Here are some examples of updates that my Facebook friends have recently posted. These are very typical:
»» “Just received a job offer. Hooray!”
»» “I’m tired of all the rain.”
»» “Looking forward to the family vacation next week at Disney World.”

Although these might seem relatively harmless, the third bullet point could raise some concern. You have just told all your friends, as well as all their friends, that you will be away from home for a full week. This is comparable to putting a sign on the main road that shouts “Empty House” for passers-by to see. Even if you have a burglar alarm or neighbors keeping an occasional eye on the home, you still don’t want to create the temptation for strangers (Friends of Friends) to consider helping them to that wonderful, new 52” flat screen TV you just purchased.



Wednesday, February 26, 2014

New variant of Zeus banking Trojan concealed in JPG images 

Researchers identified a new variant of the Zeus banking trojan, ZeusVM, that is concealed in a JPG image file to avoid detection by security software. The JPG image files contain the malware configuration files that are needed to launch man-in-the-middle and man-in-the-brrowser attacks and allow attackers to collect personal information and perform online transactions. 

Full Story: http://www.scmagazine.com/new-variant-of-zeus-banking-trojan-concealed-in-jpg-images/article/334477/ 

External reviews

Our company has multiple external exams, reviews and tests throughout the year.
PCI, OCC, SSAE16 Internal and External penetration tests. Are these all necessary? Do these really help the overall security posture of an organization. The short answer is, it depends. If management buys into the overall security program then it will certainly benefit and correlate what these exams find. If management does not have a vision and sees these audits as just something that needs to be done then you turn into what Target and Neiman Marcus currently are. Companies in trouble.

I want to get your take on this. Drop me a comment, email and lets see how people think about this subject.

Protecting Your Business From Your Remote Employees

A significant portion of your workforce is currently moving to perform full- or part-time remote work as a result of COVID-19.  As you modif...