Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Tuesday, December 12, 2017

Ho-Ho-Holiday Spams and Scams

   It's that time of year again folks.  And whatever holiday you may, or may not, celebrate... there's something we're all likely to see.  It's not presents, though maybe there are some for you.  It's not snow, though we're already seeing that here in the upper midwest US.

   It's malware and holiday scams!

   Unfortunately, it happens every year.  Sometimes it's malicious attachments.  Sometimes it's links to malware to download or phishing sites with forms ready to collect your personal and financial information.

   Here is my 2017 edition of my Top 10 Tips To Avoid Holiday Spams and Scams...

Tuesday, July 4, 2017

All Your Bitcoin Are Belong To Us

   If you're old enough... and geeky enough, you may remember this:


   All Your Base Are Belong To Us was one of the famous early internet memes.  You can take a break and read more about it here and here.

   Memes are fun!  But ransomware isn't.  We've talked about ransomware many times in the past.  It's a kind of virus or malware (malicious software).  It's been in the news quite a bit and the healthcare industry has had particular ransomware problems.  And the news will continue after May's "WannaCry" and June's Petya/GoldenEye global attacks.

   Basically, in a ransomware attack, infected computers cause data to be encrypted.  Normally encryption is a good thing, but only when you can also decrypt your data.  In this attack, only the attacker can restore your access to the information, and will do so for a "small consulting fee".

   Payment is typically made using Bitcoin.  Bitcoin has also been in the news.  It is what is called a "crypto-currency".  It's basically an online way to pay for things, kind of like an online debit card where you already have the funds in your account.  The main reason Bitcoin is used for ransomware is that it is fairly anonymous, particularly when compared with traditional credit cards or banking.  It's not completely anonymous - it does protect identity during transactions, but eventually someone may have to turn that bitcoin into other traditional currency.

   With all the ransomware attacks, some organizations are getting bitcoins so that they are ready in case they need to pay ransom!

Tuesday, May 9, 2017

Google Docs and the Mailinator

   You're minding your own business, just checking email, when you get an email from a "friend" inviting you to get a shared Google Doc file.

   You're a student of security, or at least a fan, so you're always skeptical when you receive an email with a link or attachment.  This one appears to come from someone you know.  The subject and body of the message seem consistent with a Google doc sharing message.

   Problem clue #1 - look at the "To:" line.  Clearly, this message wasn't sent to you.

   Problem clue #2 - were you expecting this email and file?  Has this sender sent you Google docs in the past?  Did this email arrive at work or home - and do you normally use Google docs there?

   But, you are rushed and don't have time to send your friend a message to see if this email is legit.  So you click.  If you're not already logged in to your Google account, you're asked to log in.  What you see next is...

Tuesday, January 17, 2017

(Browser) Caching Fire

   Someone recently asked me a question about the safety of allowing your web browser to save, and then auto-fill, passwords.  That's a very timely question because that issue has been in the news lately.

   Web browsers have all kinds of built-in capabilities.  One "feature" that is only a few years old is the ability to save information you might put into forms such as: your name and address, phone number and other contact info, credit card information.  Browsers can also save your userids and passwords for sites, then automatically fill in that info when you visit the site.

   I've always said that security-minded people should not allow web browsers to save this kind of personal and security info.  This is primarily because all browsers have a track record of having many vulnerabilities.  I've always "said" this but, as it turns out, I've never written about it!  It's about time! [Note... or so I thought! While looking for some other info, I found that I did talk about this issue back in 2013!]

   There are two primary reasons why allowing the browser to save sensitive information is a bad idea:
  1. Copycat and phishing websites can grab information directly your browser has stored without your knowledge.  This is the problem that was recently announced.
  2. As I just mentioned, browsers have many vulnerabilities and exploits. At this year's Pwn2Own contest (a 2-day event at which teams compete to exploit software vulnerabilities for cash prizes), all of the major browser fell victim!
   The latest issue that was discovered occurs when you are lured to a specially crafted website.  That happens more often than you might think

Tuesday, January 3, 2017

New Year, Don't Click!

   Well, it's a new year and, as we've discussed in the past, the more things change the more they stay the same.

   My advice for 2017... Don't Click!

   Of course, that's easier said than done.  We've discussed phishing and malicious email here, here and here.

   But on a more practical note, and because I like things that come in 3's, here's some info from the way-back machine... it's advice from Brian Krebs from 2011.  It is his 3 basic rules for online safety.  They are every bit as relevant now as when this was first published.  And it was relevant for years before that.

   The 3 rules are:
  1. If you didn’t go looking for it, don’t install it - this means when you get a pop-up asking you to install some software... don't click!  Only install software that you look for and intend to use.  And, wherever possible, install from reputable websites.  Do your research.
  2. If you installed it, update it - After you install the software you want, you need to keep it up to date.  This is not trivial, but I like using Secunia PSI (Personal Software Inspector) on my home systems for keeping software up to date.
  3. If you no longer need it, remove it - software will have vulnerabilities.  The less software you have, the fewer opportunities there are for vulnerabilities and malware.  This is especially true on your smartphone and tablet, where excess software really slows the performance of the device.
   Here's to a safe and secure 2017!

Tuesday, September 20, 2016

It's Microsoft Calling (Not!)

   The amount of automation and detection in our world today can be scary but it can also be useful.  You can set your lights to come on as you approach your home.  You can have your phone switch to wifi when you get to the office.  And Microsoft will even call you when they detect a problem with your PC!

   OK, maybe not that last one!  As we've discussed before, this is a common scam that has now been around for a few years.

   It works like this... There are 2 basic scenarios:
  1. you get a popup on your computer telling you that "Microsoft" has detected that there is a problem with your PC, and you should call the phone number they provide, or;
  2. you get a phone call directly from "Microsoft" telling you that they have detected a problem on your PC.
   Of course, neither of these are legitimate.  Microsoft will not call you.

   This article has a recording of what one of these calls sounds like.  Here's another.

   I said PC above, but people with Macs have received these as well!

   Here's the thing about these scammer orgs...  they provide very good customer support!  That, of course, is good for them but bad for us.  It's one of the reasons that these scams work.  People are very happy to receive great customer support - it's unfortunately too rare.   So when a friendly, attentive "customer service" rep is telling someone that their computer is infected, it can be convincing.

   Typically the "customer service" rep will ask the victim to pop a web browser and type in what they tell them.  The victim's web browser is directed to a malware site that will give the attacker control of that PC.

   Why do they do this?

Tuesday, July 26, 2016

Gotta Catch Some of 'Em

   Because you just can't catch 'em all!

   I guess I can't get around having to comment on Pokemon Go.

   If you have children, or if you were, born in the 90's through the 00's then you know all about Pokemon.  It used to be about the cards, action figures and, of course, the video games.  Remember the Game Boys, game cartridges and all the sounds and music?!

   With Pokemon Go, the game has gone from sometimes mobile to really mobile.  And from sometimes social to a social phenomenon.

   It's not farfetch'd!
   For some reason, many adults seem to dislike this game, siting issues like inattention to surroundings, time spent playing, etc.  I think the game is great!  Here are my top reasons why (major caveat... I have not actually played the game!  These are my observations as a technology and security professional and as a parent):
  • It gets kids out of the house - many people need a little Vitamin D.  One of the biggest complaints about gaming and computers for kids is that they don't get outside enough.
  • It gets kids moving - #exercise.  While there have been some attempts at game-ifying exercise, such as Wii Fit, it never really caught on.  Pokemon Go gets people outdoors and moving around.  In fact, part of the game is logging lots of steps.
  • It's for "kids" of all ages - parents can play along with their kids!  You don't have to play, but at the very least it's a great opportunity to be involved.
  • It's really social - you may remember that, back in the day, players could connect two Gameboys so two people could battle.  Now people are connecting IRL (In Real Life) as they hike trails, walk through cities or congregate at parks or other PokeStops.
  • It's another step toward acceptance of Augmented Reality.  Unlike Virtual Reality, in which one is entirely immersed in a manufactured visual scene, Augmented Reality overlays images, text or other information on top of what you are actually looking at.

Tuesday, July 12, 2016

Brexit Protection - click here

   Brexit Protection... or should we call it Brexitection? :-)

   How does Brexit affect your finances?  Do you care?  Plenty of people do.

   And that creates an opportunity for scammers.

   Any time there are major news events, particularly disasters or anything economic, people get worried. and the scammers are right there to play on those fears.

   According to the Telegraph, they have seen emails with subjects such as "Brexit causes historic market drop". These emails have links that supposedly connect to pages with information on how to protect your investments.  Of course, they actually download malware to the victims computer.

   This is a common problem... common because it works.

   We've covered this topic before... and the advice remains the same.  In fact, here are my top 10 email scam tips from a 2013 post!  These are just as relevant today as then.  And they will be relevant years from now:

Tuesday, June 28, 2016

We're Going About It All Wrong

   Phishing, scam, spam and malicious emails are an ongoing problem.  A recent study found that rates of these malicious emails are worst in months that have an "a", "u" or "r" in the name, with highest delivery volumes on days ending in a "y".

   Seriously though, while the worldwide spam volume seems to be trending down since a peak over 70% in 2014, rates were trending up in the first quarter of 2016 and the percentage of email that is spam or malicious is well over 50%.

   Email, along with malicious files on websites (whose links are usually delivered through email!), continue to be the top malware vectors.

   In fact, attackers don't even need to use their best, or most complex, attack methods.  It's far more cost-effective to send out random or targeted email, or to place random malicious files on websites and email out the links.  Remember, most cybercrime is economically motivated.  It's a business and the goal is ROI (return on investment).  And business is good.

   It's a big problem because we are fundamentally trusting beings.  I've always believed that people want to do the right thing.  When it comes to people, we should assume positive intent.

   However, email is not a person.

Tuesday, April 19, 2016

Ad Where?

   The first website debuted on Dec. 20, 1990 at CERN in Switzerland.  And less than four years later, the first banner ad.  The idea was simple... if people are reading information on a website, why not hit them with an ad?  Media has traditionally been either for-pay or ad-supported and the model for the web included that.  Of course, back then people had no idea the extent to which other screens like laptops, tablets and smartphones, and binge-watching would displace traditional TV watching.

   And shortly after website ads arrived, so did the malware. Ad-ware, also called "malvertising", was born.

   There are a few different ways website ads can cause problems:
  • virus code in the ad itself - so clicking on the ad downloads or executes the malware
  • malicious code that executes based on a mouse action - such as clicking on a flash animation or even just moving your mouse over an ad (called a "drive-by download")
  • a link in the ad brings you to a different page that can have malware, asks for personal information or exploits your browser to grab information from another tab (kind of like phishing)
   You may ask... why would someone allow a virus in an ad on their site?  That's a great question.   The issue is that most sites don't have a direct relationship with the people creating the ads.  The way it typically works is that sites sell space on their pages to ad brokers, who resell that space either to someone wanting to place an ad, or even to other ad brokers.  And often the ads rotate.  It becomes pretty easy for crooks to insert malware into these ad spaces without detection.

   This led to the creation of ad blockers.  These are programs that work in your browser to block content from the 3rd party ad brokers.  There was a big controversy about this in 2015.  On one hand, websites that offer free content need to have a way to monetize.  On the other hand, web and banner ads are annoying, collect our information, and can contain malware.  Some businesses block ads on corporate systems as a way to cut down on malware... and it works.

   To fight back, some sites block people who block ads!

   And that's where things get interesting.

    Let's look at Forbes.com for example.  Many websites simply show their ads along with each page.  If the ads are blocked, then those parts of the pages just don't load, or show a broken image icon.  But when you go to the Forbes website, you first see a welcome page that counts down until you can click to the main page.  While that is happening, the page loads hundreds of those 3rd party ad sites.

   And earlier this year, the Forbes site was serving malware through ads!

   So there's the bind... allow sites to display their ads, including those full sites that only display if ads are allowed; or open the enterprise to malware!

   But shouldn't the responsibility for this malware be with the website that displays the ads?  Shouldn't they test to make sure there isn't executable code in those ads?  I think so.

   I also understand that sites display content that is worth something and they deserve to be compensated.

   There are some compromises.  Some sites ask you to register to see additional content.  You are "paying" by providing information about yourself that they can sell.  Some sites charge nominal subscription fees (some sites charge high subscription fees!).

   There is perhaps some middle ground with Google Contributor.  With this consumer service you pay a nominal monthly fee.  Then google distributes that to sites based upon your usage patterns.

   What are your thoughts?  Is there a middle ground?  Should consumers have to pay for content?  Do we need to be bombarded with ads?  And who should be responsible when sites serve up malware or malicious links?

Tuesday, April 5, 2016

It's Not If, but When

   Have you heard???  2015 was the "Year of the Breach".  Of course, 2014 was the year of the breach.  And, 2013 was the year of the breach.

   2016 is shaping up to be quite a year as well.

   Of course, when we talk about breaches, we're usually talking about someone "stealing" data.  It's not actually "stolen" because you still have it.  It's more accurate to say that in a breach the data is exfiltrated.  This is also called an attack on the confidentiality of the data.

   In security, we talk about the C-I-A triangle, Confidentiality, Integrity and Availability.  Confidentiality is about the secrecy of data.  Integrity is about the accuracy of data.  Availability is about being able to properly access data when it's needed.  A well-rounded security program needs to consider all these aspects.

   What is somewhat different this year is the crypto-/ransom-ware attacks.  In these cases, the attack is a virus that typically gets in as an email attachment.  Someone opens the attachment and the virus executes.  It finds files in network shared directories and encrypts them.  Now, encryption is often a good thing, but that's when you (or your organization) has the decryption key.  In a crypto-ware attack, only the attacker has the key.  That's a problem.  It becomes ransom-ware when the attacker offers to provide the key for a "small" consulting fee, usually paid via the anonymous crypto-currency, bitcoin.
   These are basically attacks to the availability of data.  We've seen instances of hospitals or other organizations temporarily shutting down as a result.  These could also be considered attacks to the integrity of the data - though I think we have not yet seen the real integrity attacks... and they are coming.

Tuesday, February 23, 2016

Hospital Held Hostage, FBiOS and CEO Phishing

   I usually don't do "news of the week" commentary posts, but too much has happened this past week and we need to discuss it!

Hospital Held Hostage.

   I'm sure by now you've seen some info on what happened at Hollywood Presbyterian Medical Center in California.  Just in case you were on a desert island... on Feb. 5 HPMC experienced a cryptoware attack.  We've talked about those before... it's malicious software that encrypts files so that only the attacker can read them... the people who need to can't.  The story broke about 10 days later.

   Cryptoware becomes ransomware when the attackers offer to fix the problem - decrypt the files - for a "small consulting fee", usually not small and paid in bitcoin, an untraceable online currency.

   The situation itself is, unfortunately, not unique.  These kinds of attacks have been happening everywhere for years.  But there are two things that happened in this case that are unique.  First, the cryptoware completely shut down all the computerized systems in the hospital.  That means no electronic medical records, radiology, anesthesiology... just about any -ology and most hospital functions are computerized.  The hospital reverted to paper and had to turn away surgery patients or those needing more complex diagnosis, tests or procedures.  

   Second, the hospital paid the ransom.  This is the first publicized case of both a hospital shut down in this way and paying the ransom to restore their files.

   Most hospitals have procedures, called "down time procedures" for operating without some computerized resources.  And there is an incident handling process called HICS - Hospital Incident Command System - based on US FEMA (Federal Emergency Management Agency) NIMS (National Incident Management System).  But there are still medical procedures that can't be done with out access to the electronic data or computer-controlled systems.

   This attack is not OK.  Stealing people's data is bad enough.  But this affects lives.

FAQ:
   Can this happen here (wherever "here" is)?  It can, it has, it does and it will.  All industries and even home systems have been hit.  It's not "if", but "when".

   Can't we prevent it?  Yes!

   Wait.  What?  There's more to that story.  An attack like this can be prevented, but systems would have to be locked down so tight that they might not be usable.  And that's not a solution.  But there are some proactive things that can be done:
  • Don't click!  Most of these kinds of attacks start with the click of a link on a website or in an email, or opening an email attachment.  We've discussed this many times before... if you're not expecting it, if it doesn't look right, if it's not consistent... don't click!
  • Endpoint controls.  These are controls on your desktop or laptop computer including old-school anti-virus, application whitelisting, and execution controls; operational procedures like having a standard workstation configuration and regular patching.
  • Network/System controls.  Like monitoring and keeping all applications up to date with the latest versions and patches, and reliable and tested offline backups.
  • Internet controls.  Like web site filtering and email controls.
   So why did they pay?  Isn't that bad?  In some cases, if the cryptoware infection gets so bad that the organization cannot recover, there may be no other choice then to pay.  And even that's no guarantee that the attackers will or can give you the key to decrypt the files.  In some attacks, if the victim doesn't pay in time, the key is deleted and the files could be unrecoverable.  It's obviously better not to pay (or not to have to pay!), but the organization might not have a choice.

   CSI:Cyber did an episode on a hospital malware attack in Nov. 2015.  I wrote about that here.

   Just a quick commentary on the other two issues.

CEO Phishing.

   Or perhaps more correctly... phishing from your CEO!  In this phishing attack variant, an email comes from "the CEO" (or other highly placed official) demanding some kind of immediate action, typically involving wiring money.  All too often, the recipient does what they're told and sends the funds.

   Recent issues in the US and in France have kept this in the news.  Now Microsoft is getting in on the act, trying to make improvements to Outlook to help with this problem.

   As we've discussed in the past, if something on a web page or email doesn't look right, it probably isn't.  Don't click; Report it!  And even if you did click, report it!

FBiOS.

   After the San Bernadino, California terrorist shooting last December, Federal authorities captured one of the attacker's cell phone.  It is an Apple 5C.  Because of the way Apple encrypts its phones, law enforcement has been unable to view the contents of the phone.

   This week a federal judge ordered Apple to help unlock the phone.  The order is based upon the 1789 law called the All Writs Act.  Apple has chosen not to comply and that has led to plenty of discussion on both sides of the issue.  Apple says helping would set a bad precedent and weaken their phones' protections.  The FBI says it's Apple's duty to help with this criminal investigation.

   As is so often the case, there is no perfect answer.

   As Benjamin Franklin famously did not say, "Those who give up liberty for security deserve neither".  The reality for encryption is, if we make technology that law enforcement can crack, then anyone can crack it.  This is true because of the law no one can break - the law of mathematics!

   However, the Apple 5C uses an older encryption method than their newer phone.  So in this case, Apple could help without compromising everyone else's security and privacy.

   There's some great in-depth discussion of this issue on the TWIT podcast this week.

   Here are some good articles with more details.  We'll watch to see how this plays out.

Tuesday, January 12, 2016

New Year = Same Stuff

   It's a new year, but the same kind of online problems we've seen over the past few years are still here and are more prevalent than ever.

   Here's a great video about this issue by Media Pro:
Don't Let Malware Spoil the Fun from MediaPro on Vimeo. (I can't embed the video here, but do click on the link to view it.)

   The video reminds us that malware can, unfortunately, be found in many places including:
  • insecure websites
  • email attachments
  • browser add-ons
  • USB sticks
  • PDF files
   In additional to slowing down your system and causing it to not operate correctly, many kinds of malware try to grab your personal or work information.

   As we discussed here recently, your home computer defense toolkit should include:
  • anti-malware software
  • automatic updates
   But software tools are not enough.  You need to take action to protect your data and your computer:  Remember:
  1. You didn't win!...If it's too good to be true, it probably isn't true.
  2. Be careful with attachments, unknown programs, or files from USB sticks.
  3. Keep your software up to date.
   Let's do what we can to keep ourselves, our data (and our patients', customers' and clients' data) and our computers safe in 2016!

Tuesday, December 22, 2015

What's in Your Home Computer Security Toolkit?

   It's always great to get questions and comments from readers.  I received this question recently:
My home recipe is Windows Defender, Malwarebytes and KeePass. Is that a good approach or should I be thinking about adding something to my security toolkit in 2016?
   Thanks for the great question!  You’ve got some good bases covered:
  • Anti-malware (I also use defender)
  • Malware removal (I also use malwarebytes), and
  • A password vault (I use LastPass)
   That’s a great start. To round out the core toolkit, I’d add 2 things:
  1. Backups – you’ve got irreplacable pictures, tax returns, music and info of all sorts. There are many of good online products available that encrypt your data before cloud storage. I use CrashPlan, but there are many others.  For extra bonus points, you can both backup one computer to another computer and to the cloud.  That way you have more than one way to recover.

  2. Next, 2-factor authentication should be added for any sites and accounts where available.  This nicely complements your password vault so that even if an attacker stole individual or multiple passwords, they still couldn't log in to your accounts without your phone or other second authentication device.  I wrote about this recently.
   There are also a few things to do:

Tuesday, August 18, 2015

Crypto Where?

   It's that scary moment...  You're getting some work done on your computer when you see a dreaded pop-up message:

   CryptoLocker, CryptoWall and other crypto-/ransom-ware has been in the news again (or still?).  This kind of malware attack was first identified in 2013.  Rather than trying to steal information, the malware encrypts your files.  But you don't have the key to decrypt.  The attacker offers, through a pop-up message, to "sell" you the "service" to unlock your files.  To make things worse, the attacker threatens to delete the keys after a set amount of time, typically 72 hours, which could prevent you from recovering the files.

   These ransom-ware viruses are usually sent to your computer as an email attachment.  The attachment can be an office file, pdf, zip file or other file.  The malware can also come from an infected web link.

   When your computer is infected, the virus operates quietly in the background, encrypting files.  You usually won't know there's a problem until the files are encrypted, and then you're in trouble.

   So if you are infected and encrypted... then what?  Well, there's bad news, good news, more bad news and some more potentially good news!

Tuesday, July 21, 2015

Must Click Immediately!

I received this email recently.  Looks legit and serious! :-)  I better open that attachment...


   While many people would recognize this as a problem, many others would click to see what info is in the attachment.

   We regularly read about advanced and targeted attacks.  While there is plenty of nasty malware out there, most attacks start with a click.  Make sure it's not yours!

   Here are some tips to help you recognize a phishing email.

Tuesday, March 24, 2015

GOOD DAY

   I received the following email recently.  Looks too good to be true!  $1.5Million united state dollars!  Maybe I should reply? :-)

   The only thing missing is a link or attachment.

   Of course, there are tons of emails like this around.  And people do respond.

   Would you respond?  How many people at your workplace would respond?  How would you help people recognize this kind of email and not respond?

--------------
From: Dr. Xxxxx Xxxxx
Reply-To: "Dr.Xxxxx Xxxxx"
To:
Date: Fri, Mar 20, 2015 at 6:58 AM
Subject: GOOD DAY

Good day,

How are you doing hoping all is well with you and your family? We know you might have forgotten about this your outstanding compensation payment due to delay on the delivery up till now. We are here by writing to inform you that your payment file was found in our Office and we discovered that your Compensation payment of $1.5Million united state dollars have not been sent to you as it was instructed by The Economic Community of West African States (ECO-WAS)We are here to inform you that your payment has been converted into ATM Visa/Master Card to free it from Expiring, and all the necessary Arrangement for your

ATM VISA CARD Payment worth of $1.5Million United State Dollars has been granted for your payment through Our ATM Card Department Center.Now Your ATM Visa/Master Card is well packaged with every legal documents to convey it having any problem with any Authorities or with your Federal Government therefore we are here by inviting you to our office here in Republic of Benin, Office Address, UNITED BANK OF AFRICA BENIN, Xxx Xxx n,Xxxx Xxxx 2000, to enable us complete the normal formalities and activation process of your ATM Visa Card and issue the Secret PIN CODE/NUMBER to enable

you start using it at any ATM MACHINE worldwide of your choice nearest to you, as soon as it is activated, But if you are unable to come down here in our office in person you will be required to update our ATM Department Center with your contact delivery details as stated below so that they will proceed with

the necessary arrangement for the delivery of your ATM VISA/MASTER CARD.

1. Your Full name, ________________
2. Your home Address, _____________
3. Your telephone number, _________
4. A copy of your ID, _____________
5. Your age/sex, __________________
6. Your occupation, _______________
7. Your country, __________________

Therefore you should contact OUR ATM CARD PAYMENT DEPARTMENT CENTER immediately on their below;

E-mail :( dr.xxxxx.243@gmail.com )
Contact Person;
Dr. Xxxxx Xxxxx
Director Of UNITED BANK OF AFRICA BENIN,
Telephone Number; +229 nnn-nnn-nn
Try to call him immediately to know when your ATM VISA CARD will be delivered to you. I am waiting for you to update us as soon as you have received your

Visa/Master ATM Card.
Thanks and God Bless You.
Yours sincerely

Dr. Xxxxx Xxxxx

Tuesday, February 24, 2015

It Wasn't Englebart's Fault! (part 1)

   Douglas Englebart was an engineer, inventor and pioneer of the early internet.  He died in 2013.  He was known for a number of key ideas and inventions.  In 1967, he invented a very useful computer device that is a key component in propagating malware and facilitating phishing attacks... the Mouse!

   Of course, Englebart didn't invent email, email attachments, phishing emails or malicious links.

   The media is always buzzing with information about the latest breach or computer break-in.  We hear about advanced attacks, nation-states and possibility of cyber-war.  Many of these major attacks start with a simple click (or many clicks).

   Two of the main ways that malware is distributed or information is stolen is via:

  • malicious attachments sent in an email, and;
  • phishing emails with malicious links.
   For either of these methods to work, the recipient of the email needs to click... with a mouse! (well, you could also use a track-pad or track-ball).  The attachment needs to be opened.  If it's a zip file, it needs to be unzip'd.  If it's a link, clicking the link might either download malware or lead to a form asking for personal information.  Any of these actions could cause major problems.

   Let's discuss two issues:
  • what do these viruses do?
  • why can't my organization stop these? (or why can't I stop them at home?)
   This is, unfortunately, pretty complex and we'll probably handle these in two separate posts.

Why Viruses?

   As I've discussed in the past, this is really an economics issue.  There's illicit money to be made and there are smart people out there coming up with new ways to attack and take over systems.

   A typical computer virus does 1 of 3 things (I'm using the term virus generically - a virus is actually just one of a number of different types of malware (malicious software)).  It can even do more than one of these:
  1. connect "home" and download more viruses;
        This is an optional step.  The real goals are items #2 and #3.
  2. take over a computer so it can be remotely controlled, or;
        An attacker can take over a bunch of computers and use them to attack other computers or sell that capability to others. The computers taken over are called robots or bots.  They can be used to spread spam and more malware; to send a lot of traffic at target computers so they won't work properly or at all (this is called Denial of Service or DoS), or; might use other attack methods.
  3. steal information (the techy word for this is exfiltration).
        The stolen personal or corporate information can be sold or used to steal money from existing or newly created accounts.
  4. (bonus item) threaten to do the above (blackmail).
        An attacker might threaten to crash computers if not paid.  One kind of malware called "ransomware" encrypts your files so that only the attacker can decrypt them and charges you a fee to get your access back.
What can we do?

   This is a complex issue and we'll talk about protection methods next time.  For now, the best advice is to take measures we've often discussed here:
  • use anti-malware software
  • use care when opening attachments
  • use care when clicking on links
  • know who sent you that email, message, tweet, social network message, etc.
   I discussed these and other steps you can take in a post last year.

Tuesday, October 7, 2014

Celebrate Cyber-Style!

   It's time again to celebrate that wonderful US event... Happy Cyber Security Awareness month!  This event started in 2003 as a way to build awareness for online security and privacy and to encourage individuals, business and government.

   Over the past couple of posts I've focused on Identity Fraud (here and here).  We'll pause on that topic until next time.

   Today I give you...  The Top 10 Ways to Celebrate Cyber Security Month 2014!
  1. Change your password
  2. Yes, I know... I said in the past that just changing your password is not the effective measure.  That's true but with the frequency with which online sites get compromised, it's not a bad idea.  Even better - use really long passwords.  Remember, when it comes to passwords... size matters!

  3. Use a password vault
  4. A password vault is a program that encrypts and holds all your passwords.  I explain these in detail, and list some good products, in this post.

  5. Look before you click
  6. With most links to can "mouse over" the link.  That means you just move your mouse so it's on the link, but don't click yet!  Your browser will display the address to which the link will lead.  This displays at the bottom of the browser.  The actual link in the display should make sense and be the location you're expecting.  If not then... don't click!

Tuesday, August 26, 2014

When USBs Attack!

   Sometimes it seems that the more things change, the more they stay the same.  In information security, we've known for a long time that if someone can get physical access to your system, there's a chance they can get into your system.  Once an attacker has possession of your computer, laptop, tablet or smartphone, they can take their time and try multiple attacks.  We can take some preventative measures like encryption, but it needs to be implemented well.

   Of course, it's best to keep your portable devices in your possession!  But they do get lost or stolen.

   Unfortunately, there's more than one way for an attacker to physically get to your system.  If you've ever been to a conference, or a state fair, or just about any kind of gathering with give-aways, you've probably seen free USB sticks (also called thumb drives).  These supposedly have programs, games or advertising files.  And they usually do.  But they can also contain viruses or other malware.  To make matters worse, USB systems have an auto-run feature to make (legitimately) running these files "easier".