Thursday, 23 July 2015

MongoDB Instances issues

Nearly 30,000 MongoDB instances are accessible over the Internet without any authorization enabled, an expert has warned.

With more than 10 million downloads, 2,000 customers and 1,000 partners, MongoDB is the most popular NoSQL database system. MongoDB is used by organizations such as eBay, LinkedIn, SAP and Sourceforge.

According to John Matherly, founder of the computer search engine Shodan, roughly 30,000 MongoDB instances containing nearly 600TB of data are exposed on the Internet.

The expert said he was surprised by the results of the Shodan search considering that the `mongodb.conf` configuration file available on GitHub since 2013 specified that MongoDB listens on localhost by default.

The issue was reported in early 2012 by Roman Shtylman (SERVER-4216), but it took MongoDB developers more than two years to actually address it.

`The default install of mongodb ... does not have a 'bind_ip 127.0.0.1' option set in the mongodb.conf,` Shtylman warned in 2012. `This leaves a user's server vulnerable if they are not aware of this setting. The default should be to lockdown as much as possible and only expose if the user requests it.`

Matherly says MongoDB 2.4.14, a maintenance release from April 28, 2015, is the last version that still listens to 0.0.0.0 by default, which means listening is enabled on all interfaces. The expert believes early versions of MongoDB 2.6 might also lack binding to localhost.

Matherly also noticed that a majority of the publicly accessible MongoDB instances are hosted in the cloud, particularly DigitalOcean, Amazon, Linode and OVH.

`I`ve actually observed this trend across the board: cloud instances tend to be more vulnerable than the traditional datacenter hosting. My guess is that cloud images don`t get updated as often, which translates into people deploying old and insecure versions of software,` the expert said in a blog post.

These poorly configured instances expose a total of 595.2TB of data. The ten most common database names identified as a result of the Shodan search are local, admin, db, test, config, mydb, video, hackedDB, storage, and trash.

`Faceting on the database name reveals widespread installations that might`ve been misconfigured or otherwise exposed. There are a lot of instances that have some sort of administrative database, so the app that uses MongoDB probably has authentication but the database itself doesn`t,` said Matherly.

This isn't the first time researchers report finding MongoDB databases exposed on the Web. In February, students from the Saarland University in Germany revealed finding nearly 40,000 exposed instances.

The experts noted at the time that many precompiled MongoDB packages are shipped with a default configuration that binds the service to the localhost (bind_ip is set to 127.0.0.1). However, since in many cases the database and the service using the database are running on different machines, developers remove the `bind_ip` flag to allow all network connections to the database.

This allows access from outside the trusted network and if transfer encryption and proper access control are not set up, the database becomes exposed, researchers said.

MongoDB is encouraging users to follow best security practices to ensure their instances are protected against potential attacks.

`Recently a blog post was published that claimed some users had not properly secured their instances of MongoDB and were therefore at risk. As the article explains, the potential issue is a result of how a user might configure their deployment without security enabled. There is no security issue with MongoDB - extensive security capabilities are included with MongoDB,` Kelly Stirman, VP of Strategy at MongoDB, told SecurityWeek.

`We encourage all users to follow the guidelines we prescribe for security. Security best practices are summarised here, or customers can contact MongoDB support. This is an important opportunity for everyone to ensure they are following security best practices.`

Read original article

Wednesday, 22 July 2015

Facebook Vs Belgium

In privacy cases, European internet companies may not be subject to just their home regulator, explains Sam Pfeifle

Being the world's biggest social media platform has its advantages: the pick of the world's top talent, a voice on the national policy stage, and a growing revenue stream among them.

But it has its drawbacks, too. Facebook currently finds itself in the unenviable spot of being part of a test case in similar fashion to Google, just a few years back. Just as Spain used Google to show that it, indeed, had jurisdiction to bring an enforcement action, regardless of where Google is headquartered, so, too, is Belgium (alongside Spain, Germany, and the Netherlands) using Facebook to show that it has the right to regulate a company, even if the company's EU headquarters reside inside a different set of borders.

Ostensibly, Belgium and its partners are looking at how the Facebook Like button sets a cookie and how the site tracks users who don't have accounts or aren't logged in, but the privacy industry doesn't much care about all that, truth be told. Facebook has shown itself, through its response to FTC enforcement action for example, to be a good corporate privacy citizen. If a regulator tells finds it to be violating privacy law, it takes the required corrective action and figure it out.

The company's momentum is not likely to be derailed by having to tweak cookie policy at Belgium's behest.

Rather, what industry observers care about is whether, under the current European Data Privacy Directive, and, going forward under the proposed European General Data Privacy Regulation, companies in the EU are going to find themselves under the jurisdiction of 28 separate regulators all interpreting the law in their own separate way, or whether they can expect to be under the auspices of a single privacy regulator.

Large companies are in the business of predicting risk. How will markets change, consumers' desires change, world environmental conditions change in ways that will affect their ability to turn a profit? All of those, of course, are difficult to pin down. Generally, however, the law is a fairly slow-moving target. Companies peg their risk against operating in a jurisdiction with a certain law and lay plans accordingly.

If a bill is introduced that would change that risk assessment, they monitor it and adjust if necessary.

However, these risk managers wonder, how is a company to lay plans and operate in a world where there is a single law, but 28 potential interpretations?

In the case of Facebook, the company's cookie practices have been audited by their regulator in Ireland and deemed up to snuff. And thus they went forward. Now, however, they are told by another country, operating under the same directive, that they are not up to snuff.

You can see why they sound like a child arguing with her mother: `But dad said it was okay!`

`If there is really to be such thing as an EU Digital Single Market, where companies can operate in the EU with the freedom that the internet provides, how can they be asked to abide by 28 different sets of privacy law?`

You might also see why there is momentum in the European policy community for the so-called 'one-stop shop' in the proposed Data Privacy Regulation. If there is really to be such thing as an EU Digital Single Market, where companies can operate in the EU with the freedom that the internet provides, how can they be asked to abide by 28 different sets of privacy law?

However, there is of course the opposite argument: If privacy is actually a human right, and someone feels that human right has been violated, how is that they don't have redress against the company who committed that violation just because a regulator in some other country decided it wasn't really a violation?

These countries in Europe have long and storied histories and it's understandable that they would have differing cultural opinions about what constitutes something like a legitimate interest to process data.

Thus, all eyes are on this Facebook case. Given the proposed Regulation has already been three years in development, we may find ourselves under the current Directive for some time yet. Is it now open season on internet companies? Or can companies be reasonably confident that their home regulator is all they need to worry about?

And as the Regulation comes into focus, will this case swing public opinion toward the one-stop shop or away from it?

It is not an exaggeration to say just about every company collecting personal data puts itself in Facebook's shoes and awaits the answer just as expectantly.

Read original article

Fiat Chrysler bug

A pair of computer security researchers based in St. Louis demonstrated weaknesses in an automobile system with cellular connectivity installed in as many as 471,000 vehicles in the US. Charlie Miller and Chris Valasek highlighted the vulnerability of the system by attacking a Jeep Cherokee equipped with the Uconnect system remotely while Wired`s Andy Greenberg was driving it.

Uconnect, a `connected car` system sold in a number of vehicles produced by Fiat Chrysler for the US market, uses the Sprint cellular network to connect to the Internet and allows owners to interact with their vehicle over their smartphone—performing tasks like remote engine start, obtaining the location of the vehicle via GPS, and activating anti-theft features. But vulnerabilities in Uconnect, which Fiat Chrysler has issued a patch for, made it possible for an attacker to scan Sprint`s cellular network for Uconnect-equipped vehicles, obtaining their location and vehicle identification information. Miller and Valasek demonstrated that they could then attack the systems within the car via the IP address of the vehicle, allowing them to turn the engine of the car off, turn the brakes on or off, remotely activate the windshield wipers, and take control of the vehicle`s information display and entertainment system.

Miller and Valasek also found that they could take remote control of the steering of their test vehicle, the aforementioned Jeep Cherokee—but only while it was in reverse.

In 2013, the two researchers conducted DARPA-funded research into vehicle security, demonstrating vulnerabilities that could be exploited in vehicles from a wide range of automakers. But these attacks required a direct connection to the vehicle. The Uconnect vulnerabilities are unique in that they can be launched against a vehicle from practically anywhere via a connection to Sprint`s cellular network.

Fiat Chrysler alerted customers to the vulnerability in its vehicles on July 16 with a notice on its website, but the patch the company has released must be manually installed from a USB drive by the owners or a dealer.

Read original article

OpenSSH Bug

A recently disclosed bug in OpenSSH software used to remotely access Internet-facing computers and servers allows attackers to make thousands of password guesses in a short period of time, a defect that could open systems to password cracking, a security researcher has warned.

Under normal circumstances, OpenSSH will allow just three or six login attempts before closing a connection, the researcher who goes by the moniker KingCope wrote in a blog post published last week. The recently discovered vulnerability, however, allows attackers to perform thousands of authentication requests during an open login window, which by default lasts two minutes. As a result, attackers who cycle through the most commonly used passwords face much better odds of finding the right one, since the vulnerability allows them to try many more candidates than they otherwise would.

The post includes exploit code that works with the latest release of OpenSSH, which is version 6.9. In a separate post, KingCope said his exploit worked against a version of OpenSSH included in a 2007 release of the FreeBSD operating system. OpenSSH developers didn`t respond to an e-mail seeking comment for this article.

In some respects, the severity of vulnerability can be viewed as mild. But that assumes OpenSSH users are using a cryptographic key for authentication. Under such an arrangement, only computers with the private key are able to access the Internet-facing server. On top of that, servers themselves should be configured to limit the number of login attempts, and that measure should also go a long way toward making exploitation impractical.

In other respects, the vulnerability has the potential to create serious problems. Brute-force password attacks against SSH-enabled machines are a regular event, suggesting that enough servers remain vulnerable to password guessing to make it worth attackers` time.

Sadly, SSH brute-force attacks are still a credible threat on the Internet, so this vulnerability will make those attacks easier and more efficient,` Jon Oberheide, CTO of two-factor authentication provider Duo Security, told Ars. `It`s one of those bugs where the well-configured servers won`t be affected at all, but the poorly configured servers that were already at risk due to low-throughput brute-force attacks are now at even greater risk.`

People who rely on OpenSSH should take the time to ensure that they`re using a cryptographic key pair that`s at least 2,048 bits in length. They should also make sure the private key is protected by a strong password. And again, users should ensure servers are configured to use rate limiting. Still, assuming OpenSSH developers fix the bug, users should install the patch out of an abundance of caution.

Read original article

Tuesday, 21 July 2015

37 Million Cheaters exposed

Hackers have stolen 37 million records for customers of Ashley Madison, the online `dating` website for married people looking to have an affair. The information includes `all the customers` secret sexual fantasies and matching credit card transactions,` the perpetrators said.

`The secretive nature of Ashley Madison and its especially intimate customer information means that this breach is particularly worrying to the site's subscribers,` John Smith, principal solution architect at Veracode, said via email.

The hackers, who call themselves The Impact Team, said they plan to release real names, profiles, nude photos, credit card details and `secret sexual fantasies` unless their demands were met, according to independent researcher Brian Krebs.

Apparently, those demands are motivated by morality. Ashley Madison, which carries the tagline, `Life is short. Have an affair` is only one of a few `niche` offerings from Canada-based Avid Media. It also runs sugar-daddy site Established Men, and CougarLife, which caters for women looking for `a young stud` and younger men who would like to play that part. The hackers apparently have no issue with the latter…but said that they also want Established Men shut down.

It's unlikely that the site will bow to the demands easily. Cheating is big business, and Ashley Madison has been prepping for an IPO with an eye to raising $200 million on the London Stock Exchange.

`Shutting down AM (Ashley Madison) and EM (Established Men) will cost you, but non-compliance will cost you more,` the hackers said.

Avid said that the incursion has been stopped and the site secured. It also characterized the attack as `cyber–terrorism,` and lumped itself in with the other companies that have seen data breaches of late, saying that despite `stringent security,` it was not enough, `as other companies have experienced.`

`We apologize for this unprovoked and criminal intrusion into our customers` information,` the company said in a statement. `The current business world has proven to be one in which no company`s online assets are safe from cyber-vandalism, with Avid Life Media being only the latest among many companies to have been attacked, despite investing in the latest privacy and security technologies.`

Smith noted that this is a lackluster take on the situation and signals a lack of responsibility. `Whilst Ashley Madison sold a service to its users which promised secure deletion of their personal data, it seems in reality that it did not completely purge all of that data from all systems,` he said. `As businesses collect and hold personal data they have a duty of care to protect that information against a wide range of threats, whether it is a malicious insider (as may be the case here), an external attacker or accidental release.`

And indeed, these hackers themselves said that users who had paid a fee to Avid Life to have their personal data permanently deleted had been duped—the company had actually retained records, including credit card information.

Read original article

More Retailers Hit

CVS, Rite-Aid, Sam`s Club, Walmart Canada and other large retail chains have suspended their online photo services following a suspected hack attack against a third-party service provider that may, in some cases, have resulted in the compromise of payment card data.

The suspected breach centers on PNI Digital Media Inc., a Vancouver-based firm that manages and hosts online photo services for numerous retailers. The incident serves as a reminder of the security challenges that organizations face when it comes to managing their third-party vendors and entrusting them with sensitive customer information.

Numerous chains have confirmed that they are investigating potential breaches - some involving payment card data - after being warned by PNI Digital Media that it may have suffered a hack attack that resulted in the compromise of retailers` customers` names, addresses, phone numbers, email addresses, photo account passwords and credit card information. But none of the retailers involved have so far reported that they believe the breach would affect any of their in-store customers, including anyone who used in-store photo services.

PNI Digital Media did not immediately respond to a request for comment on its reported breach investigation. Until July 17, the company`s investors page reported that it worked with numerous retailers, and while that page is now blank, a recent version cached by Google`s search engine reads: `PNI Digital Media provides a proprietary transactional software platform that is used by leading retailers such as Costco, Walmart Canada, and CVS/pharmacy to sell millions of personalized products every year. Last year, the PNI Digital Media platform worked with over 19,000 retail locations and 8,000 kiosks to generate more than 18M transactions for personalized products.`

CVS Confirms Investigation

On July 17, CVS spokesman Mike DeAngelis confirmed that CVSPhoto.com may have been affected by the suspected PNI Digital Media breach. `We disabled the site as a matter of precaution while this matter is being investigated,` DeAngelis tells Information Security Media Group.

The cvsphoto.com site now reads in part: `We have been made aware that customer credit card information collected by the independent vendor who manages and hosts CVSPhoto.com may have been compromised. As a precaution, as our investigation is underway we are temporarily shutting down access to online and related mobile photo services. We apologize for the inconvenience.`

CVS says PNI Digital Media collects credit and debit information for customers who purchase online photo services through CVSPhoto.com. Accordingly, CVS recommends that all customers of its online photo service review their credit card statements `for any fraudulent or suspicious activity` and notify their bank or card issuer if anything appears to be amiss. `Nothing is more central to us than protecting the privacy and security of our customer information, including financial information,` CVS says. `We are working closely with the vendor and our financial partners and will share updates as we know more.`

Rite Aid: No Suspected Card Theft

Drugstore chain Rite Aid has also taken its online and mobile photo services offline. `We recently were advised by PNI Digital Media, the third party that manages and hosts mywayphotos.riteaid.com, that it is investigating a possible compromise of certain online and mobile photo account customer data,` Rite Aid`s site reads. `The data that may have been affected is name, address, phone number, email address, photo account password and credit card information.`

Unlike CVS, however, Rite Aid reports that it does not believe that its customers` payment-card data is at risk. `Unlike for other PNI customers, PNI does not process credit card information on Rite Aid`s behalf and PNI has limited access to this information,` it says, adding that it has received no related fraud reports from its customers.

Sam`s Club has also taken its online photo service offline, `in an abundance of caution and as a result of recent reports suggesting a potential security compromise of the third-party vendor that hosts Sam`s Photo website.` As with Rite Aid, however, Sam`s Club reports that `at this time, we do not believe customer credit card data has been put at risk.`

Costco and Tesco Photo have also suspended their online photo services.

Walmart Canada, which also outsources online photo services to PNI, also may have been affected by the possible breach, according to the The Toronto Star, and the retailer has since suspended its online photo services website. `We were recently informed of a potential compromise of customer credit card data involving Walmart Canada`s Photocentre website, www.walmartphotocentre.ca,` Walmart states. `We immediately launched an investigation and will be contacting customers who may be impacted. At this time, we have no reason to believe that Walmart.ca, Walmart.com or in-store transactions are affected.

Walmart did not respond to Information Security Media Group`s request for comment. ISMG also reached out to office supplier Staples, which owns PNI, but did not get a response.

`PNI is investigating a potential credit card data security issue,` a Staples spokesperson told The Toronto Star.

Growing Third-Party Breach Concerns

PNI`s potential breach comes just a week after Denver-based managed services provider Service Systems Associates announced that a breach linked to a malware attack against its network had likely affected about 12 of the payments systems it operates for gifts shops at retail locations, which include zoos, museums and parks, across the country (see Denver POS Service Provider Breached).

Service Systems Associates says debit and credit purchases made between March 23 and June 25 may have been compromised.

On July 7, the Financial Services Information Sharing and Analysis Center, along with Visa, the U.S. Secret Service and The Retail Cyber Intelligence Sharing Center, which provides threat intelligence for retailers, issued a cybersecurity alert about risks merchants face when dealing with third parties.

The alert lists a number of security recommendations for managing third-party risks, including using multifactor authentication for remote-access login to point-of-sale systems and including specific policies related to outdated operating systems and software in contracts with vendors.

Earlier this month, Chris Bretz, director of payment risk at the FS-ISAC, warned that managed service providers that offer outsourced services to numerous merchants are increasingly being targeted by cybercriminals.

`Criminals continue to find success by targeting smaller retailers that use common IT and payments systems,` Bretz said in an interview with ISMG. `Merchants in industry verticals often use managed service provider systems. There might be 100 merchants that use a managed service provider that provides IT and payment services for their business.`

Read original article

Monday, 20 July 2015

Army National Guard Breach

The Army National Guard has exposed the personal information of more than 850,000 current and former members, by improperly handling a data transfer.

The servicemen and women may have had their names, home addresses, Social Security numbers, and dates of birth exposed when that data was transferred to a non-Department of Defense-accredited data center by a contract employee as part of a budget analysis.

An Army National Guard spokesperson described it as `more of a poor security practice,` than a breach, though classified as a breach.

`We believe the specific files containing personal information were safeguarded and not used to compromise anyone`s identity,` Kurt Rauschenberg told Army Times. `However, we want the public to know what happened just in case.`

IDT911's chairman and founder and the former director of NJ Division of Consumer Affairs, Adam Levin, told Infosecurity that the problem with most government agencies (and thousands of businesses) is that they have `perfected poor security practices as an art form.`

`These sub-par efforts leave the door open to breaches—and literally none was a serious as the recent breach of the Office of Personnel Management where over 22 million Americans have seen their most sensitive information exposed and are now at risk due to an epic security fail,` he said. With breaches having become the third certainty in life, we cannot afford to allow poor security practices to put our people—particularly the defenders of our way of life—in harm's way. This incident demonstrates once more that any system is only as secure as its weakest link and humans have proven yet again that we are the weakest link.`

Read original article