Wednesday, July 2, 2008

Test Credentials? These looks a lot like yours...


At times, I realize that despite my best efforts, I still haven't gotten through to some of our developers. We do automated web application testing, and normally use test credentials created for that purposes to log in. This morning, I got a call from a developer who was working from home. "I'll just give you my username and password", said the developer.

I calmly noted that to do so was a direct violation of policy, and that I really needed alternate credentials. It looks like it is time to run the "Why you shouldn't share your credentials" class again, with an emphasis on the dismissal for cause part of the policy...

Flickr Creative Commons image credit to husin.sani.

Monday, June 30, 2008

Mobile phone security awareness: Secure wipe and IPhone 2.0

Mobile phones, particularly smartphones are becoming ubiquitous, and many users are forwarding organizational email to their private devices. With sensitive data potentially accessible on these devices, the ability to wipe them securely has become a necessity. Vendors are starting to make progress - mobile device encryption is becoming more available, and wipe utilities that securely wipe data are being announced. The most recent? Apple's Iphone 2.0 firmware.

AppleInsider reports that the Iphone 2.0 firmware will include the ability to perform a secure wipe of the device. According to AppleInsider, "Unlike today's iPhone software, however, the revised function will wipe data in similar fashion to the "Secure Empty Trash" function of Mac OS X, by which all data is deleted, unlinked, and then overwritten several times to make it irretrievable by even the savviest of recovery tools."

This is far better than the current delete function, which leaves remnant data in place.

Apple will go one step further however, as the new firmware will also include a feature allowing remote wiping of a stolen or lost phone - a feature that both end users and enterprise security staffers will be delighted to have.

Friday, June 13, 2008

Spear Phishing and Taxes

A co-worker of mine recently received the following spear phishing message. It was more sophisticated - or at least, far less crudely constructed than many, and included details appropriate to his actual employment.

The phone number was the individual's employer's main switchboard, and it was sent to a work email address that he uses for notification from the IRS. Forms are referenced, and document numbers that look like official government numbers are included. A perceptive user should notice that the URL is from a .com address, and of course, the headers clearly showed that the email was not from a government system.

As is common in such email, there is a threat included to make reply more likely - in this case, a bill will be sent by the government.

Department of the Treasury Date of this Notice: May 23 2008
Internal Revenue Service Letter Number 531(DO)
District Director Form: 1040

XXXXXXXX YYYYYYYY
EMPLOYER NAME
(999) 999-9999
-NOTICE OF DEFICIENCY-
Dear XXXXXXX YYYYYYY,
We have determined that you owe additional tax and other amounts, or both, for the tax year(s) identified above. This letter is your NOTICE OF DEFICIENCY, as required by law. The enclosed statement shows how we figured the deficiency. If you want to contest this determination in court before making any payment, you have 90 days from the date of this letter (150 days if addressed outside the United States) to file a petition with the United States Tax Court for a redetermination of the deficiency.

link to (www.tax-revenue.com) removed

If you decide not to sign and return the waiver, and you do not file a petition with the Tax Court within the time limit, the law requires us to assess and bill you for the deficiency after 90 days from the date of this letter (150 days if this letter is addressed to you outside the United States).

Thank you for your cooperation.
Sincerely yours,
Charles O. Rossotti
Commissioner by
Roger K. Burgess CR
District Director
Letter 531(DO)(Rev.9-96)

Wednesday, June 11, 2008

Tenable announces the end of the Nessus Registered Feed

Tenable has announced(PDF) that their Registered Feed for Nessus users will be discontinued. Organizations that relied on the plugin feed, despite the delay from their commercial Direct Feed will no longer receive updates for free. The Direct Feed subscription remains reasonably priced at $1200 a year, and Tenable is offering a discount during the transition.

Tenable also notes in their release that they will support teaching and training organizations, as well as charity with free Direct Feeds, which should mean that at least some of the groups that were using the registered feed will not lose their access. For most others, it means a yearly cost to continue using Nessus.

Interestingly, home users using Nessus for personal, non-commercial use will get access to a new "HomeFeed" service with no delay for plugin availability. That leaves Tenable a gateway for users to learn how to use Nessus, while forcing organizations that relied on the free feed to pay for a license.

A FAQ is available with more detail.

Monday, June 9, 2008

Here Phishy Phishy: Another Phishing Example

I've changed the original site name in this email - it is typically in capital letters, and is the domain of the user the email was sent to.

Giveaways this time? The capitalized domain, the request for password, date of birth, and country, the thank you, signature, and the warning code, as well as the headers showing a non-local email origin.

The good news is that most users won't fall for a phishing email like this - but I still see users fall for some of the more sophisticated bank and Paypal scams.

Dear YOURSITE.COM Email Account Owner,

This message is from YOURSITE.COM messaging center to all YOURSITE.COM email account
owners. We are currently upgrading our data base and e-mail account
center. We are deleting all unused YOURSITE.COM email account to create more
space for new accounts.

To prevent your account from closing, you will have to update it below so
that we will know that it's a present used account.

CONFIRM YOUR EMAIL IDENTITY BELOW

Email Username : .......... .....
EMAIL Password : ................
Date of Birth : .................
Country or Territory : ..........

Warning!!! Account owner that refuses to update his or her account within
Seven days of receiving this warning will lose his or her account
permanently.

Thank you for using YOURSITE.COM!

Warning Code:XXXXXXXXX

Thanks,
YOURSITE.COM Team
YOURSITE.COM BETA

PGP announces Mac full disk encryption

Macworld writes that PGP has announced their MacOS full disk encryption product with a July release date for PGP Whole Disk Encryption 9.9. Not quite here yet, but close!

Friday, June 6, 2008

Why My Printer Received a DMCA Takedown Notice

Michael Piatek, Tadayoshi Kohno, and Arvind Krishnamurthy of the University of Washington have released a very interesting research paper titled "Challenges and Directions for Monitoring P2P File Sharing Networks". They studied P2P clouds and monitoring methods, and succeeded in getting takedown notices sent to spoofed IPs and IPs of hosts that were not actually sharing files (but which did send in queries). The paper is well worth a read for staffers who have to deal with DMCA takedown notices, and will likely be of interest to those who are dealing with legal cases dealing with P2P based copyright infringement.

The New York Times' BITS section covered the article today as well.