Monday, 6 July 2015

GhostShell Back to Life

The hackers in the GhostShell crew have published a list of recently compromised targets. It's a list that includes websites in the government and the educational sector in the US, as well as retailers around the world.

Each entry is accompanied by links to four different public paste locations, containing a preview of the extracted data. So far, there are 548 published victims. Data includes email addresses, usernames, ZIP codes, phone numbers, names, dates of birth as well as hashed and plain text passwords.

The group has also published all of the data in one shot on Pastebin.

The team says that it has altruistic intentions: to bring to light the inherent insecurity of cloud providers and our most enshrined institutions.

`Time to bring to light the things that you`ve never been told in the media lately. How truly deplorable cybersecurity has become,` the group tweeted.

In another tweet, it added, `Reminder: These are all preview leaks. If you want to help patch them please report the vulnerabilities. Thanks. – GhostShell.`

GhostShell became notorious a couple of years ago for several hacking sprees before going underground, including one in which it dumped 1.6 million records. However, its Twitter feed sprang to life again on June 28.

Read original article

Harvard Suffers Data Breach

Harvard Suffers Data Breach Spanning Multiple Schools, Administration Networks

Investigation so far shows email and system login info may have been compromised, university says.

A data breach at Harvard University appears to have exposed system and email passwords belonging to an unspecified number of faculty, staff, and students from numerous schools and at least one major administrative network at the university.

Harvard discovered the intrusion on June 19 but publicly disclosed it only Thursday while it worked to mitigate the issue. A statement disclosing the breach said Harvard discovered an intrusion into the Faculty of Arts and Sciences (FAS) network and another one at the university Central Administration network.

The FAS is Harvard's largest division, according to the university. It encompasses several schools including Harvard College, the Graduate School of Arts and Sciences, the School of Engineering and Applied Sciences, and the Division of Continuing Education. Also part of FAS is several libraries and museums and Harvard's athletics division.

In addition to those on the FAS network, others whose data was compromised include people at Harvard Divinity School, the Radcliffe Institute for Advanced Study, and the Harvard T.H. Chan School of Public Health and other schools.

Though Harvard's statement and accompanying FAQ are sparse on the details, the university`s advice to affected parties suggests that not everyone was impacted in exactly the same manner. Those with a login to FAS, the Divinity School, Central Administration, and Radcliffe Institute for Advanced Study, for instance, were asked to change the passwords associated with both their Harvard system and their email accounts.

Meanwhile, victims from the Graduate School of Design, Harvard Graduate School of Education, Harvard John A. Paulson School of Engineering and Applied Sciences, and Harvard T.H. Chan School of Public Health, were asked only to change passwords to their Office 365 or Icemail university email service accounts.

The university also instructed those affiliated with the affected networks to update all devices synched with their Harvard account with the new password.

In the breach disclosure statement, Harvard provost Alan Garber and its executive vice president Katie Lapp said that no personal or research data appears to have been compromised. Though passwords to individual systems appear to have been compromised in some cases, there is no indication that credentials in the university's core PIN System was compromised, they said.

Those affiliated with the Harvard Business School, Harvard Kennedy School, Harvard Law School, Harvard Medical School, and Harvard School of Dental Medicine, were not impacted in the breach.

This is the second time in recent months that Harvard has had to deal with an intrusion into its networks. In April, a group of hackers claiming a pro- Palestinian agenda defaced the website of Harvard's Institute of Politics. The intrusion resulted in the hackers replacing the site's usual web page with various propaganda images and messages for a total of about 35 minutes before the site was taken offline.

Academic institutions generally have a poor reputation for information security. Security vendor BitSight Technologies, which rates different industries on their security posture, gives the education sector the lowest score based on its analysis of data gathered from sensors around the globe. The company looks at data like indicators of compromise, infected machines, and improper configuration, to calculate credit-rating-like scores for different industries. In its latest index, the median security score for Education is just 550 -- compared to 710 for the financial services industry.

Somewhat surprisingly enough, though, there haven't been too many publicly reported instances of major intrusions at universities in recent months. In fact, since the beginning of this year, there have been just 6 publicly reported breaches at academic institutions, according to the Privacy Rights Clearinghouse.

Read original article

Saturday, 4 July 2015

Pay with a selfie

Make an online payment with your credit card and you`re probably used to having to enter a password or PIN. But if a trial scheme by MasterCard takes off, this could become a thing of the past. The finance company is testing out a new payment authorization technique including fingerprint scanning and facial recognition.

MasterCard is working with Apple, BlackBerry, Google, Microsoft, and Samsung to introduce the biometric checks. The initial plan is to trial the system with 500 participants before possibly rolling it out on a larger scale. It`s something that MasterCard believes will be welcomed by millennials and should simplify the process of making payments from a smartphone.

Demonstrating the system to CNNMoney, it showed how payments could be authorized with a quick touch of a fingerprint scanner, something Apple and Samsung have already implemented. The other option is to use facial recognition. A clear security concern here is that as well as authorizing payments by pointing a cameraphone at one`s face, the system might be foiled by simply using a photograph. To get around this problem, users will be required to blink to indicate that they are a real person.

MasterCard says that privacy is maintained by not transmitting or saving images of fingers or faces. Scans are digitized and sent encoded to authorization servers. It`s not something that is going to appeal to everyone, but Ajay Bhalla from the company says: `The new generation, which is into selfies. I think they`ll find it cool. They`ll embrace it`.

Other possible authorization techniques include heartbeat pattern checking and voice recognition. But for now, it`s the trial of facial and fingerprint scanning to look out for -- you might be using your face to make your next purchase.

Read original article

Cardinals Sack Employee

The Cardinals confirmed July 2 that they had fired Chris Correa, who was the team`s scouting director - in charge of researching and recruiting new players - but declined to detail why.

Cardinals general manager John Mozeliak, who has denied having any knowledge of the alleged hack attack prior to being notified by the FBI, told the St. Louis Post Dispatch that Correa was fired on July 1. `I can confirm he was on administrative leave and subsequently was terminated,` he said. `At this time it`s still an ongoing investigation, and there`s really nothing more that I can add at this point.`

Astros attorney Jim Martin, tells Associated Press that no other employees have been fired to date, but that related investigations remain underway. `I can`t give you an end-point,` he said. `But our internal review is still ongoing.`

The Houston office of the FBI, which is leading the related investigation, did not immediately respond to a related request for comment. But the existence of the investigation was first confirmed in June by The New York Times, which reported that the FBI`s investigation centered on one or more breaches of the `Ground Control` database built by the Astros, as well as related memos, which detail private discussions about scouting reports, player trades and confidential statistics. The FBI reportedly served related subpoenas on both the Cardinals and the Major League Baseball organization, and seized some Cardinals computers in February.

Astros Data Dumped

In June 2014, 10 months of Astros` internal-trade chatter were leaked to anonymous text-sharing website Anonbin. That leak apparently alerted Astros officials to a potential breach, and sparked the FBI`s investigation.

Correa, however, has rejected allegations that he stole or leaked any Astros data. `Mr. Correa denies any illegal conduct,` Correa`s lawyer, Nicholas Williams, said in a statement. `The relevant inquiry should be what information did former St. Louis Cardinals employees steal from the St. Louis Cardinals organization prior to joining the Houston Astros, and who in the Houston Astros organization authorized, consented to, or benefited from that roguish behavior?`

According to a single, unnamed source cited by the St. Louis Post Dispatch, however, Correa admitted to Cardinals officials that he had accessed the Astros database, but only to ascertain if the team had stolen proprietary Cardinals information, and denied stealing or leaking any Astros data. The source suggested that based on the number of times that the Astros database was reportedly accessed, the leak was the result of one or more hackers who were not Correa.

The existence of the database - and its URL - was apparently public knowledge, after the Ground Control website address was reportedly visible in a photograph that accompanied a March 2014 feature story in the Houston Chronicle. In that story, Astros general manger Jeff Luhnow and the team`s `director of decision sciences` - former NASA employee and analytics expert Sig Mejdal - said Ground Control was modeled on the Cardinals` similar `Red Bird Dog` system. Luhnow joined the Astros from the Cardinals in 2011.

Password Hygiene

In an interview last month with Sports Illustrated, Luhnow denied suggestions that he had taken intellectual property from the Cardinals, or that the hack attack was facilitated by his failing to change his Cardinal-era passwords when he joined the Astros. `That`s absolutely false,` said Luhnow, who was a McKinsey consultant and later the founder and president of data analytics firm Archetype Solutions, and who has said that Ground Control was built `from scratch.`

Read original article

Bitcoin Exchange Hacked

Memo to organizations: Do not allow PCs that run software such as Skype and Microsoft Office to connect to a server that hosts your bitcoin wallet.

That`s one takeaway from a breach report apparently prepared for Bitstamp, a European bitcoin exchange - the company is officially registered in the United Kingdom - that suffered a Jan. 4 breach. The breach resulted in the theft of
18,977 bitcoins, which at the time were worth 4.4 million euros, or $5.3 million (see Bitstamp Back Online After Breach).

Bitstamp did not immediately respond to a request to verify the authenticity of the apparently leaked breach report, dated Feb. 20, which is now circulating online. The report, which is attributed to Bitstamp general counsel George Frost, says that it includes information gathered by digital forensics investigations firm Stroz Friedberg, plus information shared by the U.S. Secret Service and FBI, as well as the `U.K.`s cybercrime unit,` which likely means the National Crime Agency.

`This is an active investigation,` the February report says. `We believe we have identified at least one of the hackers and are baiting a `honey trap` to lure him into the U.K. in order to make an arrest. Moreover, we need to be very careful not to educate other criminal hackers about how we safeguard our assets and information.` To date, however, U.K. police agencies have not announced any related arrests.

A copy of the purported Bitstamp report was first posted July 1 to Reddit by a single-purpose account. It was later added to a dedicated Bitstamp Incident Report site hosted by WordPress.

The report says that Bitstamp was compromised by a phishing attack that targeted six different employees. `All of the phishing messages were highly tailored to the victim, and showed a significant degree of background knowledge on the part of the attacker,` the report says. And the attacks continued until the attacker successfully compromised a systems administrator`s PC with malware. Crucially, that sysadm had access credentials for Bitstamp`s Internet-connected bitcoin repository, or what`s known as a `hot wallet.`

Targeted Phishing Attack

The attack began with a phishing message, dated Nov. 4, which purported to offer Bitstamp CTO Damian Merlak free tickets to a punk-rock festival, the report says. `Merlak was contacted by Skype account punk.rock.holiday. ... The gambit for this phishing attack was to offer Mr. Merlak free tickets to Punk Rock Holiday 2015. (Merlak is keen on punk rock and has played in a band.)`

The attacker then sent Merlak a `participant form` named `Punk Rock Holiday 2015 TICKET Form1.doc` which included a malicious script written in the Visual Basic for Applications - or VBA - programming language, the report says. When the document was opened in Microsoft Word, the script was designed to execute, and pull a malicious file down to the PC from an external IP address. But the report says that there was no indication that this script ever executed.

The attacker, however, continued to demonstrate `persistent effort,` the report says. `Over a period of approximately five weeks, four more Bitstamp employees received similar highly targeted phishing attacks, each tailored to individual interests.` For one of those attacks, the hacker posed as a journalist, and in another, a headhunter.

Read original article

Friday, 3 July 2015

Insurer data exposure

Illinois-based Trustmark Mutual Holding Company is notifying an undisclosed number of individuals that a software error resulted in emails containing their personal information being sent to the wrong insurance carrier clients.

How many victims? Undisclosed.

What type of personal information? Names, Social Security numbers, and payroll deduction information.

What happened? A software error resulted in emails containing personal information being sent to the wrong insurance carrier clients.

What was the response? Trustmark contacted each insurance carrier recipient and requested confirmation that the emails and the attachments had been permanently deleted. The software error that caused the incident has been identified and corrected, and safeguards have been implemented to ensure a similar incident does not occur again. All potentially impacted individuals are being notified, and offered identity protection services for two years.

Details: Trustmark provides consolidated billing services for other insurance carriers, and on May 13 its automated billing email system generated and sent encrypted emails to certain insurance carrier clients. Each email should have contained a single file with information related to each carrier`s insureds, but on May 14, Trustmark discovered that a software error resulted in each carrier receiving file attachments for all of the carriers.

Quote: `We believe the risk of misuse of your information is low, but we are providing this notice to you in an abundance of caution,` a notification letter said.


Read original article

Yahoo Patches SSRF

A researcher says Yahoo has finally patched a SSRF vulnerability which affected all its services that required images to be processed.

SSRF (Server-Side Request Forgery) vulnerabilities, also known as XSPA (Cross-Site Port Attack), exist when an application that processes user supplied URLs doesn't properly verify the response from the server before sending it back to the client. An attacker can exploit such flaws to attempt to bypass access controls (e.g. firewalls), conduct port scanning by using the affected servers as a proxy, and even access data on a system.

California-based security researcher Behrouz Sadeghipour says he discovered a SSRF/XSPA vulnerability in a Yahoo image processing system back in July 2014. He immediately reported his findings, but it took the company until June 2015 to address the bug.

Yahoo services such as Flickr and Yahoo Groups allow users to utilize the IMG tag in comments and messages. When posted, the images are processed through yimg.com, Yahoo's image domain.

The researcher first discovered that he could use the request to yimg.com to execute cross-site scripting (XSS) payloads. He also found that he could launch SSRF attacks by replacing the value of the `url` parameter in the request with his own URL.

Sadeghipour told SecurityWeek that this medium severity vulnerability allowed him to internally access local networks and determine which ports are open on a specific local or remote machine.

The expert has published a blog post containing additional technical information on the bug, along with a video that shows how the vulnerability could have been exploited on Yahoo Groups.

In 2012, researchers at ERPScan published a detailed analysis on the impact of SSRF on business critical applications. Such flaws were also analyzed by Riyaz Ahemed Walikar later in 2012.

In the same year, Walikar identified a SSRF/XSPA vulnerability in the Yahoo! Developer Network. The security bug could have been exploited by an attacker to port scan Internet-facing servers using Yahoo's machines, the expert said.

Last year, security researcher Andrea Santese reported finding a SSRF/XSPA vulnerability on a domain used at the time by Yahoo for submitting websites to the Yahoo! Directory.

Read original article