Feb 6, 2011

A malicious addition to a Facebook link

In the last few days we have discovered that spam messages with malicious links are being sent via instant messenger services. It turns out that the mailings were carried out by the Zeroll IM worm. A bot generated various messages depending on the language of the recipient. Here are a few of them:
“Wie findest du das Foto?”
“seen this?? :D %s”
“This is the funniest photo ever!”
“bekijk deze foto :D”
“uita-te la aceasta fotografie :D”
Like lots of other similar incidents, the cybercriminals have made use of social engineering, asking users to look at pictures with alluring names. At the end of the message there is a link such ashttp://www.facebook.com/l.php?u=********.org/Jenny.jpg. As well as the link to the Jenny.jpg file the messages included similar links to Sexy.jpg.
The page that the http://www.facebook.com/l.php?u= link leads to is not actually malicious – it contains a warning from Facebook telling the user they are leaving the site.

Facebook warning
If you add a link to any random site after ‘l.php?u=’, then a window opens with a warning from Facebook. However, after the user clicks the ‘Continue’ button the link will direct the user to the corresponding site. This mechanism was used by the cybercriminals to make the link to the malicious site look more legitimate.
When the browser redirects to the page ********.org/Jenny.jpg it leads to the file PIC1274214241-JPG-www.facebook.com.exe which is then launched by unsuspecting users. Hereafter, the terms jenny.jpg and sexy.jpg refer to this executable file.
After analyzing jenny.jpg and sexy.jpg it turned out that they were typical downloaders, protected by packers and written in Visual Basic.


Fragment of the downloader code after the jenny.jpg file is unpacked in full
The downloaders’ job is typical for these types of program – download another malicious program to the infected computer. In this case, it’s the file srce.exe. So that the user doesn’t suspect anything, the downloaders also open the picture that was promised in the original spam message. The picture is downloaded from the Internet (the link can be seen in the screenshot).
So what is srce.exe? It’s a dropper + downloader whose outer shell is also written in Visual Basic. It downloads IM-Worm.Win32.XorBot.a which uses Yahoo Messenger to send out messages to users.
So what we have here is a link to a page on Facebook being used in instant messaging spam instead of a direct link to a malicious object. You could say that Facebook is being used a service along the lines of bit.ly: it allows links to be modified so that they are directed via the Facebook domain.
Zeroll is still actively sending out spam. The messages contain links to different files, but with similar names such as Girls.jpg and Marisella.jpg. And even though people already know they shouldn’t just click any old links, even if it was sent by someone on their contact list, it’s worth reminding everyone again. If nothing else, cybercriminals are creative, and the Zeroll spam once again confirms this.

A keygen with a twist

Programs for cracking commercial software are, sadly, not unpopular. They have also caught the attention of malware writers, who prepared a couple of surprises for those who don’t mind a free ride every now and then.
A short time ago, we detected a Trojan dropper which passes itself off as a key generator for Kaspersky Lab products. The file’s name is kaspersky.exe.
Once launched, the file displays a key generator window prompting the user to select a product. After one of the options is selected, the program proceeds to generate a key.


Keygen window
While the freebie lover is waiting for the result, two pieces of malware that were stealthily installed and launched by the dropper make themselves at home on the PC.
One of these is detected by Kaspersky Lab as Trojan.MSIL.Agent.aor. It steals registration data for other programs, as well as passwords, mostly for online games. It rather considerately stores all the stolen data in one file. A fragment of the file is shown on the screenshot below.


Fragment of a file that is filled in with registration data for the software listed in it
The Trojan also modifies the ‘hosts’ system file to block access to a number of websites. For example, such websites as virustotal.com and virusscan.jotti.org, which offer file scanning by solutions from many antivirus vendors, become inaccessible.
Fragment of a modified hosts file:
##Do not touch this file, changing it will cause SERIOUS damage to your computer
127.0.0.1 virustotal.com
127.0.0.1 www.virustotal.com
127.0.0.1 www.virusscan.jotti.org/
127.0.0.1 www.virusscan.jotti.org/en
127.0.0.1 www.virusscan.jotti.org/en

The second piece of malware installed by the dropper is a typical backdoor which also has keylogger functionality, collecting keystroke data. It is detected as Trojan.Win32.Liac.gfu.
Thus, running a supposed key generator for Kaspersky Internet Security will plant a couple of very real malicious programs on your computer, which KIS will then have to deal with. Provided, of course, that the keys generated by the ‘keygen’ actually work.

Securing a wireless network

       Securing a wireless network

If your wireless network is not secure, a hacker can easily intercept the data you send and receive, or access files saved on your computer – all from the comfort of their own sofa.


Why is it necessary to secure my wireless network?

These days, most computers are wireless-enabled: they let you connect to the Internet without a physical network cable. The major benefit, of course, is that you can use your computer anywhere in the house or office (as long as it’s within range of your wireless router). However, there are potential risks involved in wireless networking - unless you make your network secure:
  • A hacker could intercept any data you send and receive;
  • A hacker could get access to your wireless network;
  • Another person could hijack your Internet access.
Therefore, if your wireless network is not protected, a hacker could intercept any data you send; access your network, and therefore your shared files; use your connection to connect to the Internet - especially significant if you have a download limit on your internet package and your bandwidth is being swallowed up by a hijacker.

How do I secure my wireless network?

There are some simple steps you can take to secure your wireless network and router in order to minimise these risks:
  • Change the administrator password for your wireless router. It’s easy for a hacker to find out the manufacturer’s default password and use this to access your wireless network. And avoid using a password that can be guessed easily: follow the guidelines provided in the section below on choosing a password.
  •  Switch off SSID (Service Set Identifier) broadcasting, to prevent your wireless device announcing its presence to the world.
  • Enable encryption in your connection settings: WPA encryption is best, if your device supports it (if not, use WEP encryption).
  • Change the default SSID name of your device. Again, it’s easy for a hacker to find out the manufacturer’s default name and then use this to locate your wireless network. Avoid using a name that can be guessed easily: you should follow the guidelines provided in the 'Choosing a Password'section.

To secure your wireless network:

  • Change the administrator password;
  • Enable WAP or WEP encryption;
  • Switch off the SSID and change the default name of your wireless router;
Follow the advice above on how to protect from malicious code and hacker attacks. 

Passwords

Passwords
Choosing a good password is vital to being secure online. Just follow a few golden rules, which a surprising amount of people ignore. Three of the most common internet passwords? 'password', 'monkey' and '123456'.


Why are passwords important?

We now use the Internet for a wide range of activities, including online banking, online shopping and online research. Increasingly, we’re also using the Internet to socialise. In the last few years there's been a massive growth in the number of social networking sites such as Facebook, MySpace, etc. We share all kinds of personal details as well as music, pictures, and videos.
Unfortunately, the more personal details we make available, the more exposed we are to online identify theft. Identity theft is when a criminal steals confidential personal data that lets them fraudulently obtain goods and services in your name. A cybercriminal could, for example, open a bank account, obtain a credit card or apply for a driving licence or passport. Or they could simply steal money directly from your bank account.
Given that passwords protect such valuable data, they're clearly very important. You should protect all your online accounts with passwords - but you must be careful when choosing them.
Passwords help safeguard you against identity theft. They make it harder for cybercriminals to profile you, access your bank account (or other online accounts) and steal your money.

Choosing a good password is an important part of lowering the risk of becoming a victim of cybercrime. The following guidelines should help you when choosing passwords for your online accounts.
  • How to choose secure passwords

  • Make your passwords memorable, so that you don’t have to write them down or store them in a file on your computer (remember, this file could be stolen by cybercriminals).
  • Don’t use real words that a hacker or cybercriminal can find in a dictionary.
  • Use a mixture of uppercase and lowercase letters, numbers and non-alphanumeric characters such as punctuation marks (although the latter are not always allowed).
  • Don’t recycle passwords, e.g. don’t use 'password1', 'password2', 'password3', etc. for different accounts.
  • If possible, use a passphrase, rather than a single word.
  • Don’t use the same password for multiple accounts. If a cybercriminal finds the password to one account, they can use to access other accounts.
  • How to keep your passwords safe

  • Don’t use obvious passwords that can be easily guessed, such as your spouse’s name, your child’s name, pet's name, car registration, postcode etc.
  • Don’t tell anyone your password. If an organisation contacts you and asks for your password, even by phone, don't give them any of your personal details. Remember, you don’t know who’s at the other end of the telephone line.
  • If an online store, or any web site, sends you an email confirmation that contains a new password, login again and change your password immediately.
  • Check that your Internet security software blocks attempts by cybercriminals to intercept or steal passwords.

Feb 5, 2011

32 Ways to Secure Your Digital Life

For every freedom and convenience we enjoy in our digital lives, there are countless cyber do-badders looking for ways to exploit them. Fight back with these 32 ways to protect your digital life!
Call us cynical or hard-edged, but we frankly believe that the world is filled with hustlers, grifters, and crooks out to bamboozle us at every turn.
Those suspicions are doubled for our digital lives. For no longer do bunko artists need to trick you into buying that iPad box with a brick in it. Today, they can rip you off by auto pilot. With the deadliness and stealth of a UAV, these scumbags can steal your banking credentials, clone your debit card, or infect your computer. Don't worry about being too paranoid. There's really no such thing as being overly vigilant when it comes to your digital security.

Protect Your Desktop PC

Installing strong, up-to-date security software is a given. But it takes much more than that to defend the epicenter of your digital life.
32 Ways to Secure Your Digital Life

Keep Your OS Patched


Could real people actually be as clueless as some of those characters we see in movies? Sadly, you need no more evidence of that cliché than the average computer user. Even though he or she knows that an OS update is as critical as, say, nailing boards over your windows in a zombie apocalypse, many choose to ignore the updates until something crawls in and eats their brains.
The most basic security step PC users should take-regardless of OS-is to install the latest updates. Yes, we know, it can be teeth-gritting-especially when the updates are larger than the original OS-but it's necessary for patching holes being used by attackers to squeeze into your PC.

Lose Windows XP

Windows XP was a great operating system but it's now pushing 10 years old and it's a popular target for attacks. Why? It's not as secure as its replacements. It's also where the money is-literally-with 51 percent of computers on the planet running it. Many attacks specifically target XP and ignore Windows Vista and Windows 7 completely. Unless you like to wrench on your OS all day, we recommend that you give XP the retirement it has earned.

Keep Your Applications Patched

Even Microsoft haters have to admit the company has done an admirable job patching its operating systems in a reasonable amount of time. Because of this, many of the weak spots on a PC aren't even the OS anymore, but rather the third-party applications. While Microsoft will patch its own products in Windows Update, it doesn't do squat about anything else. With literally dozens of apps to check for updates every week, you can see where the problem lies. That's why we run Secunia's PSI Scanner (www.secunia.com). The free app runs in the background and checks your installed apps and plugins for available updates and then gives you a link of where to download the patch. The latest beta version will actually install some of the updates for you. The company also offers an online scanner but we don't recommend it because it runs in Java.
32 Ways to Secure Your Digital Life
Secunia's free PSI app will monitor the dozens of applications installed on your machine for available security patches.

Beware the Usual Suspects 

When a massive malware outbreak occurs, you can almost always expect to see these five shifty guys in the police lineup: Flash, Acrobat/Reader, QuickTime, Java, and JavaScript.
Normally we'd say just execute 'em, but it doesn't always work that way. Yes, if you can, simply uninstall these offenders (save JavaScript), but if you must have them, there is a way to at least mitigate some of the damage.
Start by disabling Acrobat/Reader in your browser. In Firefox, go to Tools, then Add-ons, then Plugins, and disable the Acrobat plugin. While you're there, you should also probably disable QuickTime, Java, and even the DivX Web Player if you want to be extra cautious.
32 Ways to Secure Your Digital Life
Disabling plugins for Acrobat, QuickTime, and other media players can mitigate some of the damage from new zero-day exploits.
To disable these plugins in Chrome, go to Options, Under the Hood, Content Settings, Plugins, and select "Disable individual plugins."
Now, go into the Acrobat app, go to Edit, Preferences, Trust Manager, and uncheck "Allow opening of non-PDF file attachments with external applications." While you're in Preferences, click the JavaScript option and uncheck "Enable Acrobat JavaScript." Also click on Internet and uncheck "Display PDF in browser." Or just dump the whole thing for Foxit Reader (www.foxitsoftware.com).
For QuickTime, start the player, dig into Edit, Preferences, QuickTime Preferences, Browser, and uncheck "Play movies automatically."
To mitigate the damages from Adobe Flash, consider running the FlashBlock extension in Firefox and Chrome. This will prevent Flash from being displayed on a page. In its place will be a place holder that, when clicked, will play the Flash content.
Disabling JavaScript unilaterally can be problematic, as it breaks many sites. Still, for the paranoid, there is a way. The NoScript extension for Firefox is the leading contender. Chrome has no such extension, but you can go to Tools, then Options, then Content Settings, then JavaScript, and select "Do not allow any site to run JavaScript." This will place a small icon in the address bar that will let only your favorite sites run JavaScript. Disabling JavaScript in Chrome can be wonky, but it's worth investigating if you want to avoid one of the primary ways crooks are targeting you.

Use a Virtualized Browser

Since the vast majority of attacks are coming from the browser, one of the safest ways to surf the web is from a virtualized browser or a virtual machine. Dell offers its free KACE browser (www.kace.com), which virtualizes Firefox 3.6 along with Adobe Reader and Flash. Malware that exploits holes in Firefox, Reader, or Flash would be contained within the virtual machine. The bad news? If you do get an infection and need to flush the virtual Firefox, you lose all of your settings. That includes the numerous updates to Firefox that come out seemingly every month and any bookmarks and plugins you installed. An alternative is to build a virtual machine using either Virtual PC 2007 (www.microsoft.com) or VM Ware Player (www.vmware.com). Both are free, and both Microsoft and VM Ware offer free images that include browsers. Microsoft offers Vista and XP with IE8 installed and VM Ware offers Ubuntu with Firefox installed. Of the three options, VM Ware's is the most solid but folks not used to Linux might be thrown for a loop. Microsoft's images time out after three months, so you'll have to download it again.

Get a Second Opinion

Do you really know if that file is truly untainted? Many malware writers are specifically crafting wares to avoid detection by antivirus suites. If you have a file that you need to run, we recommend that you incubate it for a few days or a few weeks if possible. This gives security software a chance to catch up to any new exploit. We then recommend that you get a second opinion from Virustotal.com. This website lets you upload a file to be scanned by two dozen AV engines. Just remember that malware writers are also using tools such as Virustotal.com to see if their wares can pass muster, so long incubations are key.

Unshorten Those URLs

Shortened URLs can conveniently turn unwieldy web address into bite-size morsels, but they can also disguise a link to a malware-ridden site. Though many of the URL shortening services check for malicious websites, it's usually better to verify a shortened URL's destination. For that, we use Longurlplease.com. It supports 81 shortening services. As for cryptic shortened URLs, visit Virustotal.com to have the address checked by six URL analysis engines.
32 Ways to Secure Your Digital Life
Although many URL shortening services claim to scan for malware, it's probably best to lengthen those URLs before you click on them, using Longurlplease.com.

Run in a Standard User Account

Running as an administrator in a Windows OS is a bit like giving someone the right to walk into your home and rummage through every nook and cranny. One easy way to avoid or greatly limit damage from malware is to always run with standard user rights. As with all things, this is no guarantee against harm. Some malware, even when executed in a standard user account, can grant itself administrator privileges and still run rampant through your PC, but running as a standard user minimizes risk.
32 Ways to Secure Your Digital Life
Running in standard user mode in a Windows OS has proven to be useful in beating back malware attacks.

Use a Live CD/Linux Distro to Do Banking

That Windows is the number one target for cybercrime and mischief is not news to any of us-naturally, owning 95 percent of the market makes it an obvious target. That's why we agree with security journalist Brian Krebs (http://krebsonsecurity.com) that members of the most at-risk group should do online banking with a Linux Live CD. You can do your gaming and other Windows-based computing booted from your hard drive. But once you have to go into secure mode, whip out your Live CD and boot to it. Numerous Linux builds are available, but the most popular, and among the easiest, is Ubuntu.

Restrict PC Access for Others

So, you've created this incredibly secure moat, ringed with razor wire, claymores, and mines. And then you let your 14-year-old nephew play some Flash games or "check email." Right. The best solution is to have visitors use a separate, secured guest PC. But if they must use your machine, make sure you have the guest account activated. Another option is to have them use a virtual machine. Once they're done, simply shut down the VM and erase any trace of their activities. Or have them use your HTPC, where they're working in the open instead of being left alone in your office.

PHYSICAL SECURITY: Put Your Laptop on Lockdown

32 Ways to Secure Your Digital Life
Kensington's new ClickSafe key lock makes it an easy one-step process to secure your laptop from snatch-and-grabs.
Obviously, all the same security risks and safety recommendations that apply to your desktop computer also apply to your laptop. But your laptop carries the added risk of being stolen. And let's face it: If you haven't encrypted all your sensitive data or been diligent about backups, the loss of your laptop could be mighty painful. One way to prevent the potentially dire consequences is to use a laptop lock.
The vast majority of notebooks have a slot to accommodate a physical locking mechanism-it's usually designated by a padlock icon. The lock itself is attached to a reinforced cable which cannot be easily cut without the aid of a large and very noticeable set of bolt cutters. The cable is either bolted to the floor-in your office at work, for instance-or looped around a substantial or immovable object. Kensington is one of the biggest names in cable-lock makers, and offers both combination and key locks, priced at $25 and $50, respectively.

Protect Your Network

Keep your digital bits out of the hands of baddies.
32 Ways to Secure Your Digital Life

Use Google Public DNS

If the crooks can't convince you to visit their phony-baloney banking webpage, the next step is to get you there against your will. One way to do that is to poison the DNS cache you're using. The DNS server translates URLs into IP addresses. By exploiting flaws in the DNS software, crooks are able to redirect you to any sight of their choice-even if you typed in the correct URL of your bank.
32 Ways to Secure Your Digital Life
Bypass your ISP's DNS for one that's likely faster and more secure, Google DNS.
To avoid this, we recommend switching from your ISP's DNS to Google's public DNS (http://bit.ly/7Ti5tM). It's free and the company has implemented many of the recommended safeguards against cache poisoning. To change the DNS on your client PC, go to Network Connections, right-click on your connection, and double-click Internet Protocol. Then simply enter the preferred DNS of 8.8.8.8 and alternate of 8.8.4.4 and click OK.

Conduct Personal Business at Home

You want a simple reason not to check your personal email at work? Someone in your network could be using a so-called "man in the middle" attack to spy on you. Whether by exploiting ARP cache poisoning, session hijacking, or some other technique, MITM attacks let a crook steal the credentials issued to your machine and then fool, say, Yahoo or Gmail into thinking he's you.
At work, with hundreds of computers and a network that stretches the coasts, you really wouldn't know where the MITM attack is coming from. This risk negates the possibility that your corporate network is more secure than your home network. So, assuming you have secured your home Wi-Fi (or don't use wireless) and that the other machines on your home LAN are secure, save your personal email and banking for home.

Secure Your Wireless

Quick, what's the most secure wireless available today? None. OK, we jest, but probably no wireless protocol is 100 percent secure. But just because there's a theoretical way to break the latest wireless encryptions doesn't mean you should be using the weakest form. The weakest, of course, is WEP. Easily broken in under a minute by anyone capable of reading an Internet how-to, WEP is far less secure than WPA or WPA2. If you're running WEP because some old hardware doesn't support WPA2, consider junking the old equipment or upgrading your router to one that supports guest networks. This lets you keep your internal network behind WPA2, while keeping guests roped off with the weaker WEP protocol to access the Internet. If you're running WPA2, the adage in security circles is that the longer and more randomized the key, the better.
Although not a guarantee, you can also set up your router's wireless to only accept connections from known MAC addresses. These are the unique IDs assigned to each computer's network card. The hole there is that an intruder could easily spoof a MAC address from a trusted client to still access your wireless network.

Check Each Machine's Shares and Services

You can check what files are shared on a machine by right-clicking My Computer, selecting Manage, and clicking Shared Folders. Great, now how do you do it for all of the machines on your network? One way is to use NetBrute Scanner (www.rawlogic.com). This free utility will scan your internal network and report on shared resources that are available.

Scan Your Network for Intruders and Piggybackers

If a neighbor has broken into your network so he or she could download movie torrents, how would you know? Since most home networks use DHCP, go into your browser's setup screen and check the DHCP screen to see how many IP addresses are assigned. Then, try to match those up with the systems on your network. If you have more IP addresses assigned than devices (remember that your smartphone will eat an IP address if it's using Wi-Fi), you may have an intruder. Another option is to use RogueScanner (www.paglo.com), a free tool that will query devices on your network and compare them to an online database of devices to help you identify the machines.
32 Ways to Secure Your Digital Life
Running an internal port scan may help reveal intruders freeloading on your network's bandwidth.
So what do you do if you have an intruder or suspect one? Since the person has likely infiltrated your network via wireless, you'll want to lock down your wireless by switching to WPA2 and using a very long and very random key.

Smartphone Security

It's a lot smaller than your desktop PC, but the risks are just as big.
32 Ways to Secure Your Digital Life

Hang on Tight

Currently, the number one threat to smartphone users is having the device end up in the wrong hands, through theft or loss. Your first line of defense, therefore, is constant vigilance regarding your smartphone's whereabouts.

Use a Password and Encryption

Should your phone get lost or stolen, a good first layer of protection is a password, an option many phone users neglect. Choose the strongest password option available-a passphrase, for instance, rather than a four-digit code or swipe pattern. Encryption options vary among mobile OSes, but when possible, you should encrypt your storage card as well as your device memory.

Back Up Your Data

Just as with a PC, backing up your smartphone is important. Regularly synching the device to a linked computer will do the trick. It's insurance against the loss of your phone, corruption of your OS, or any other event that jeopardizes your data.

Don't Store Sensitive Data


The surest way to guard your sensitive data is to keep it off your smartphone altogether. Minimize the number and/or days of emails you store on your phone, or better yet, save email and attachments to a server. Make it a habit to regularly move or delete anything you wouldn't want to share with strangers.

Practice App Awareness

An abundance of apps is both a blessing and a curse for smartphones-there is no way every app that makes it to market can be thoroughly vetted for 100 percent fail-safe security. By selecting reputable apps, backed by favorable user reviews, from a trusted source, you can diminish the risks. Avoid apps with scant reviews or that have only recently been uploaded. Also be cautious when granting an app permissions; consider the app's function and what it might reasonably need access to.

Keep Software/Firmware Updated

Make sure you are running the latest versions of your apps, OS, and phone manufacturer software and firmware. This will ensure that any security holes are patched and your device is less vulnerable to hacks.

Disable Bluetooth and Wi-Fi When Not in Use

Unsecured wireless networks can be used by hackers to either attack your phone or steal information from it. You can protect yourself by keeping Wi-Fi and Bluetooth off when you don't need them. When wireless is needed, stick to known Wi-Fi networks using WPA2 and beware of public networks, which are sometimes set up by crooks to snare people's data.
When using Bluetooth, make sure it's in non-discoverable mode to avoid hacks like "Bluesnarfing" (stealing data), "Bluejacking" (sending unsolicited messages), and "Bluebugging" (listening in on your calls).

Beware of Links and Attachments

You've long been warned about the risks of opening strange links and attachments-particularly those arriving in unsolicited emails or text messages. All those same warnings apply to smartphones. And those warnings also apply to calling unfamiliar phone numbers received in messages, and clicking links for app "updates." You can ensure the authenticity of an update by going to the app's website.  

SMARTPHONE AV: Add Extra Protection with a Third-Party Security App

Currently, smartphone malware infections are rare-nothing like what you see with PCs. But as proliferation of the devices grow, expect viruses, worms, and trojans to become more of an issue. To combat these threats, you need third-party software, and if you're like the majority of smartphone users, you don't have it. But even if malware isn't a pressing problem at the moment, a security app can offer other useful benefits, such as browsing protection, telephone and text-message spam blocking, and theft-protection features like locking down, wiping, or even locating a stolen phone.
You can find mobile security apps by many of the big names in PC protection. Independent security testing lab AV Comparatives (www.av-comparatives.org) recently evaluated mobile apps from ESET, F-Secure, Kaspersky, and Trend Micro and gave them all "Approved" designations. See the full report at http://bit.ly/cGRySZ.

Webmail Safety

In today's connected landscape where we enjoy Internet access not only from our desktops and notebooks, but also from our smartphones, tablets, and even our portable media players, it's easy to see why free-to-use webmail has become so popular. Most webmail accounts now offer several gigabytes of storage space, effectively turning us into digital pack rats.
Everything you choose to save-from sensitive email exchanges to confidential attachments-is not only accessible to you, but anyone who manages to figure out your password, whether by brute force dictionary attacks or by answering a series of weak security questions. And it's not just your email history that's in danger; an unsecure webmail account opens the door to other security breaches, like using your email account to send spam and spread viruses. Here are some ways you can avoid becoming just another statistic.

Create a Burly Password

Your webmail account is only as secure as your password, so use a strong one. The best way to do this is to use a combination of letters, numbers, and even symbols if your webmail provider allows. Avoid using real words at all costs, as these are easily cracked by any teenage hacker using a brute force dictionary script. For particularly sensitive accounts, use a random password generator (http://bit.ly/bf9oB2).

Use Multiple Passwords

The key to your house doesn't unlock your car door, nor does it work with your safety deposit box. If it did, you'd be three feet deep in dung if it ever fell into the wrong hands, and the same concept applies to your digital accounts. In practice, most people tend to use the same password for various accounts, and that's a rookie mistake. Use a different password for your email than you do your bank account, forum login, and whatever else you do online. If you have trouble keeping track of them all, store your passwords in a virtual safe, like KeePass (free, http://keepass.info).

Log Out/Leave No Trace

It might be slightly inconvenient to log out of your webmail and clear your browser cache, but if your notebook ends up lost or stolen, you'll be glad you did. And if there are others around, log out and close your browser before heading off for a bathroom break.

About Security Questions

Answering security questions can save your bacon if you forget your login credentials, but keep in mind that anyone who knows you well can probably guess the correct answer(s). Only rely on these if the questions are particularly personal in nature, or if you're allowed to create your own that are not easily guessable. And, for God's sake, don't publish that information in your Facebook profile. There's no point in having a security question of what city where you born in, or what your pet's name is if your public profile gives the answer away.

Feb 4, 2011

The human factor and information security

The human factor and information security

  • Computer security as a system
  • People are part of the system
  • Security vulnerabilities and some examples
  • Conclusion
This article has not been written in order to scare users, or to push them into buying security software for their computers. It's simply an attempt to share some thoughts which have come to mind in my work as a virus analyst, while analysing code, reading a range of forums and articles, and numerous daily messages from readers asking for help.

Computer security as a system

Information security cannot be thought of as a single, discrete, entity; it's a whole range of measures, and should be viewed as a system. Information security is as complex as any other system which combines a number of different aspects and approaches, none of which can be regarded as more or less important. This means that no single aspect or approach can be disregarded; if one area or part of the system is ignored, the system will not function correctly.
Information security differs very little from security in general. After all, no one would install a heavy security door with a pick-proof lock on a garden shed. Similarly, a car can have excellent tires, but if the brakes are faulty, the car will be unsafe. Protection against cyber threats works on the same principle: all possible weak points should be secured, whether on a desktop computer, an organization's server or a corporate network. Data should also be accessed via secure paths, although I'm not going to discuss how any of this should be done in this article. Those who work with information should also be viewed as a part of the system, a link in the chain which ensures both data exchange and the security of the system overall.

People are part of the system

There's a wide variety of security software available, including firewalls, intrusion detection systems, antivirus solutions etc. Each type of software is designed to perform very specific functions, and using such software will help protect a system. However, even using the very best software, which implements the most advanced technology and the most secure algorithms, cannot guarantee 100% system security. This is because people are involved in the development and implementation of software, and people make mistakes. Consequently people, who are a part of any system, are always going to be the weak point in a security system.
The human factor is the underlying reason why many attacks on computers and systems are successful. Of course, there are a great many specific examples. Let's take a look at how and why hackers, virus writers and other malicious users exploit the human factor, using people as the chosen method to penetrate systems.

Security vulnerabilities and some examples

A lot of users don't understand that using software which contains vulnerabilities poses a genuine security risk to their computer or system. The majority of users see their computer as a black box; they don't understand how it works, and in reality, they don't really want to. They want to use computers in the same way as a vacuum cleaner, a fridge, a washing machine, or any other household appliance, without having to understand how the appliance performs its function. And many users think that viruses, hackers, and other cyber threats are simply the invention of security software vendors. In some ways, who can blame them, given that some of those working in the security industry regard viruses as 'something that happen to stupid users' and antivirus software is simply a waste of money. "I'll simply install an operating system which isn't susceptible to viruses, and software without any vulnerabilities, and then I'll have nothing to worry about" so goes the theory.
Underestimating the severity of potential threats is only part of the problem, however. The human factor also comes into play in creating and implementing security policies and procedures, and many potentially exploitably loopholes appear at the drafting stage.
The security of wireless networks is in a lamentable state due to the fact that errors were made when wireless protocols were being developed. There are as much written about secure programming as there are program errors; however, I'm sure while programmers and testers will continue to identify loopholes which already exist, new ones will continue, albeit inadvertently, to be created. And even the most carefully developed software has to be implemented, which again brings humans into the equation: the best firewall in the world will not protect your system if you have a poorly trained system administrator.
While I was writing this article, a worm was gaining ground on the Internet. Lupper spreads via known vulnerabilities, and if an administrator regularly reads vulnerability alerts and installs patches promptly, the system won't be vulnerable to Lupper. This is standard for all worms. The usual scenario is that a vulnerability advisory is issued, but most people don't pay much attention to it; then proof of concept code is released showing how the vulnerability can be created, but the majority of users still don't understand the gravity of the situation and take no action. Lupper follows this pattern, and confirms the fact that security issues are not taken seriously enough at an early stage.
Another example of an irresponsible approach to security is how users treat confidential information. An analogous situation in everyday life: who would leave their keys in the outside lock, or hang them on a hook where anyone could take them? No-one, of course. But lots of systems use an empty password, or the users' name as a password, making it extremely easy to access the system. As an alternative, let's take the scenario where the administrator requires users to have passwords which are difficult to guess, and therefore better from a security point of view. This is all well and good, in theory, but I've often seen such 'secure' passwords written on a piece of paper and left lying on the user's desk, or stuck to the monitor. It's not surprising that malicious users take advantage of this situation.
Another human failing which malicious users exploit to the full is curiousity. The vast majority of us have encountered email worms at some time and know that these worms arrive as attachments to infected messages. Sending the worm out is only half the battle, however, for the virus writer or malicious user. The worm then has to be activated in order to spread further, and this is done by opening the attachment. You might thing that users have become wary of attachments to unexpected messages, and consequently don't open them. Unfortunately, the cyber criminals and vandals know how to pique users' curiosity. An intriguing message referring to the attachment will be opened by the majority of users, as the graph below shows:
Why do you open suspicious attachments?
Why do you open suspicious attachments?
Interestingly, in spite of the fact that antivirus vendors constantly stress that suspicious attachments shouldn't be opened, the number of users who open these attachments remains stable. This can be explained by the fact that virus writers are constantly finding new ways to exploit human curiosity and gullibility.
However, email worms don't only spread attached to messages. Recently, users have been receiving a ling to the body of the worm, rather than the worm file itself. The user is still part of the activation process, and has to be persuaded to click on the link in order to launch the worm. It seems that this is very simple: let's take Email-Worm.Win32.Monikey, which sends emails like the one shown below:
Email sent by Email-Worm.Win32.Monikey
Email sent by Email-Worm.Win32.Monikey
At first glance, this seems to be a perfectly normal email, telling the user that s/he has received an e-greetings card. It's logical for the user to click on the link in order to view the card, and the malicious users who have sent the email are counting on this: the unsuspecting user, in trying to view the alleged card, will launch the worm. So what is the answer? How can malicious emails be distinguished from genuine emails? The screenshot below is a legitimate email sent out by the POSTCARD.RU service:
Email sent by POSTCARD.RU
Email sent by POSTCARD.RU.
Firstly, it should be highlighted that the email shown in screenshot 1 uses HTML code - this is used to mask the URL of the address where the worm is place, making it appear to be a link to POSTCARD.RU. Screenshot 2 shows the email from POSTCARD.RU which includes a warning, stating that all emails from POSTCARD.RU are in plain text only; any message containing HTML is not legitimate, and potentially malicious. If the user wants to view their card, they should copy the link into their browser - a genuine link will then cause the e-card to be displayed. Under no circumstances should users click on HTML links; in this case, as in many others, this opens a site containing malware, which will then be activated.
A similar approach has been used recently in a spam mailing. Messages stated 'If you wish to unsubscribe from our mailing list, please click on the link below'. You might ask what the problem is - of course users don't want to receive mountains of spam, and will try and use the link to unsubscribe. When the user clicks on the link, an HTML page is opened, which alledgedly checks the subscriber database, and then displays a message saying 'Your address has been removed'. However, this is all an illusion - in actual fact, two malicious programs will be downloaded to the victim machine:Trojan-Dropper.Win32.Small.gr and Trojan-Spy.Win32.Banker.s. There's a clear lesson here - spammers are not going to worry about users wants and needs, and once they have got hold of an address, that address will receive spam regardless of any attempts to unsubscribe. In fact, attempts to unsubscribe usually result either in more spam, or in malicious code being downloaded. The best way to deal with spam is simply to delete the unwanted messages.
The summer of 2005 brought a new type of mass mailing, with cleverly designed emails which targeted a clear group. Malicious users started spamming corporate email addresses with messages appearing to come from the user's manager. This was done by spoofing the address field. However, the real return address, which couldn't be seen, was the malicious user's address. Of course, conscientious employees are highly likely to do as they are told by their manager, and would therefore open the attachment and launch the malicious program. It should be noted that such incidents don't receive much publicity; those responsible for security in organizations which are targeted usually attempt to prevent the information from reaching the wider world.
When malicious code is mass mailed, the senders often play on the popularity of antivirus solutions. This kills two birds with one stone: the user launches the malicious program, and antivirus vendors are discredited. This last point should be emphasised - if users receive enough messages appearing to be from antivirus companies, sooner or later they will start to think that the antivirus companies are sending out infected updates, and will stop updating their antivirus solutions. This, of course, makes antivirus software lose most of its efficacy. It must be stressed that no antivirus company distributes updates via mass mailing, and users should not install programs which arrive by email on their machines. Email-Worm.Win32.Swen successfully used this approach by presenting itself as a security patch issued by Microsoft. The worm managed to infect several hundred thousand computers around the world as users installed the alleged patch. The worm's authors had carefully waited for the moment when users would be most likely to install a security patch, having been frightened by the recent Lovesan incident.
This case shows how virus writers exploit events in the world at large in order to infect more machines. They do this extremely quickly and effectively - recent cases include mass mailings of Trojans following the terrorist bombings on the London underground, the power cuts in Moscow, and Hurricane Katrina in the USA in 2005. The messages sent made reference to these and other disasters in order to entice users to open attachments or click on links.
Malicious code for instant messaging programs (ICQ, Miranda etc.) takes a very similar approach.
How do computers get infected by instant messaging malware? More often than not, the malicious user sends a link to the body of the worm, which is activated once the user clicks on the link. In order to get users to click on the link, the same methods are used as with email. However, in some cases cyber criminals have gone further, as Trojan-PSW.Win32.LdPinch shows. The authors decided that having received the link, the recipient would probably want to chat, or at least say thank you. They developed a bot which would generate likely answers to be sent to the recipients' questions or phrases.
In spite of these new, more sophisticated methods, virus writers haven't forgotten about an older, tried and tested one - using links, which differ only slightly from trusted addresses and where the difference is not obvious at a first, cursory glance (e.g. changing an I to an |). This continues to be used as it is an effective way of enticing users into clicking on links. An example of this was detected in summer 2005, when we intercepted a worm which spread via MSN Messenger. The link sent by the worm, http://www.vbulettin.com/xxxxxxx, supposedly led to the site of a well regarded antivirus publication. Unsurprisingly, many users trusted this link, not realizing that Virus Bulletin is actually located at www.virusbtn.com, clicked, and activated the worm.
The user receives the malicious program in some form or another in all the cases mentioned above. Although many users do launch the programs, some heed repeated warnings, and don't click on links or open attachments. Consequently, virus writers need to find other, more effective methods, to reach these security conscious users. It would be far more effective if the user didn't receive anything directly, but simply picked up the malicious program while surfing the web. Due to this, there has been an increase in the number of sites which have been compromised and had malicious programs placed on them. Malicious users naturally choose popular sites, often those of well-known companies. Although malicious programs placed on compromised sites usually only stay there a few days before they are removed, this is long enough for thousands of machines to be infected.
One example of this is the email worm Monikey, which was mentioned above. Infected messages contain a link to the site where the body of the worm had been placed. The worm was placed on totally legal sites, and we haven't managed to establish exactly how this was done. However, we suspect that accounts which could be used to access the sites were stolen and the data used by the authors of Monikey. It's surprising that the administrators of compromised sites, although they removed the body of the worm, didn't block the accounts which had been misused. And the worm continues to appear on the same sites which often display the following announcement, assuring users that the site owners did not carry out any mass mailing, explaining that the site has been compromised, and apologizing for the inconvience.
Announcement on compromised site
Announcement on compromised site
Cyber vandals from Nizhni Novgorod came up with an even more inventive method of distributing their malicious code via the Internet. They offered webmasters, who agreed to place a Trojan on their site, 6 cents for every machine infected by the Trojan. It's a cause for some concern that a fair number of webmasters agreed to do this.
All of the above shows that users are under considerable threat in a variety of ways when surfing the Internet.
There are of course other ways of exploiting human nature, and the topic of social engineering deserves a separate article. Sometimes malicious users don't know where to start when trying to penetrate a system. One tried and tested method is to get to know someone within the target organization. This provides a foothold to conduct a range of attacks, often without resorting to technology, but simply by exploiting human fallibility. For instance, a potential hacker may call the organization being targeted, state that s/he is an employee, and be given a variety of information, ranging from telephone numbers to IP addresses. This information can then be used to attack the organization's network.

Conclusion

Computers are becoming ever more widely used in every area of life. THe potential profits to be made from cybercrime are also increasing, and techniques used by cyber criminals are consequently evolving rapidly.
Creating a reliable and effective security system in the modern world is not at all easy. There are so many potential weak points that detecting new security loopholes and patching them is an unending process. New technologies are taking the place of old ones, and are being used to solve today's problems - but these new technologies have their own drawbacks. But hackers, virus writers and malicious users are inventing new tricks in order to evade the security software currently being used. The result is a continued stand off between cyber criminals and security professionals, with only intermittent success for the security industry. However, users have the ability to swing the balance one way or the other: unfortunately the unpredictability (or predictability) of human behaviour can bring the most concerted efforts made to secure systems to nothing.
Despite this, I hope that this article may cause some readers to consider information security in more depth, and to pay more attention to security issues.

AVG Anti-Virus Free Edition for Linux


AVG ANTI-VIRUS FREE EDITION FOR LINUX

AVG Anti-Virus Free Edition for Linux
Basic antivirus protection for Linux/FreeBSD available to download for free. Free virus protection for your PC. For private and non-commercial use only.



Name
VersionType
Size
AVG Server Edition for Linux
(avg85flx-r863-a3205.i386.deb)
8.5.0863deb
88 MB
AVG Server Edition for Linux
(avg85flx-r863-a3205.i386.rpm)
8.5.0863rpm
88 MB
AVG Server Edition for Linux
(avg85flx-r863-a3205.i386.sh)
8.5.0863sh
88 MB
AVG Server Edition for Linux
(avg85flx-r863-a3205.i386.tar.gz)
8.5.0863tar.gz
88 MB
AVG Server Edition for FreeBSD
(avg85ffb-r863-a3205.i386.tar.gz)
8.5.0863tar.gz89 MB


AVG LINKSCANNER® FOR MAC


AVG LINKSCANNER® FOR MAC

Web protection for your Mac
Online criminals are getting smarter, but we're one step ahead of them. Now you can surf, search, email, shop, and social network knowing that the pages you visit are safe. AVG LinkScanner® checks each web page in real time before it opens on your Mac. If it sees trouble ahead, it stops you. It's easy to use, won't get in your way and it's FREE.

Twitter Delicious Facebook Digg Stumbleupon Favorites More