My Quote

“Cyber criminals are real.Never let them into your network.As long as they believe in absurdities they will continue to commit atrocities” Beware!!!!

Thursday, July 21, 2011

Insider threats and critical infrastructure: Sometimes, the news is worth worrying about


by CSO, Salted Hash – IT security news analysis, over easy!

My instinct is almost always to look at something scary and tell you why there's no real reason to be afraid. But when it comes to malicious insiders working in nuclear power plants, a little fear may be justified.
I bring this up after reading all the reports about how Osama Bin Laden was planning an attack for the 10th anniversary of 9-11. The Department of Homeland Security issued a report that malicious insiders sent by the terrorists may already be on the inside at nuclear and other facilities essential to maintaining our energy supply, in positions of deep responsibility.
And so here we are, on guard like we've been so many times before, with the TV news people telling us to be afraid -- very afraid.
Exhibit A: This ABC report featuring Brian Ross, who is, in my opinion, one of the biggest doom-and-gloom-we're-all-gonna-die reporters out there:
Sabotage by an insider at a major utility facility, including a chemical or oil refinery, could provide al Qaeda with its best opportunity for the kind of massive Sept. 11 anniversary attack Osama bin Laden was planning, according to U.S. officials.
A new intelligence report from the Department of Homeland Security issued Tuesday, titled Insider Threat to Utilities, warns "violent extremists have, in fact, obtained insider positions," and that "outsiders have attempted to solicit utility-sector employees" for damaging physical and cyber attacks.
"Based on the reliable reporting of previous incidents, we have high confidence in our judgment that insiders and their actions pose a significant threat to the infrastructure and information systems of U.S. facilities," the bulletin reads in part. "Past events and reporting also provide high confidence in our judgment that insider information on sites, infrastructure, networks, and personnel is valuable to our adversaries and may increase the impact of any attack on the utilities infrastructure."
By the way, purely by coincidence, I discovered that this report is all the more ominous when you play the song "Making the Bombs" by the Circle Jerks in the background.
I've learned to be skeptical of a lot of things mainstream media reports, because much of what was reported on years ago never came to pass. For example, in the days after Hurricane Katrina in 2005, as New Orleans' lower ninth ward continued to be submerged in putrid water and death, ABC decided it could get a lot of mileage from a series of reports on all the potentially catastrophic threats we face.
One show dealt with what would happen if a nuclear bomb were detonated in a major American city. Another segment focused on a strain of bird flu that was killing people in Cambodia, Vietnam and other nations in that part of the world.
If the virus were to mutate so it could easily pass from human to human, a huge percentage of the global population could be killed off, as happened with the 1918-19 Spanish Flu pandemic, Ross reported. After that report, the world spent the next year on edge as human cases were found elsewhere in the world. Doom was imminent. Modern medicine was ill-equipped to stop it. And then -- nothing.
We did have a flu pandemic in 2009, but it wasn't the bird flu we had been watching for. This was a much milder pandemic.
So here's Ross again, warning that we're in for some potentially nasty stuff. I want to shrug and change the channel as I've learned to do.
But this time, I stop and watch the whole report. And, I find myself taking it very seriously.
Why?
Because I've done a lot of writing about the insider threat in recent years. I've reported on malicious insiders stealing critical intellectual property and selling it to their employer's biggest competitors.
I've seen a lot of smaller cases where disgruntled insiders tampered with computer systems and damaged data.
The insider threat is real.
So when I see reports that potential terrorists may be working inside energy plants with evil intentions, I'm inclined to worry a little more than I normally would.
Not that I'm going to go hide under the living room couch. I wouldn't fit, anyway.
The good news is that the government is on to this potential plot, so a surprise attack is less likely. The bad news is that the government has demonstrated remarkable incompetence in the face of disaster before. I again refer you to Hurricane Katrina.
The greatest opportunity to avert disaster can be found where it usually is, in the private sector.
Now would be a good time for all our critical infrastructure suppliers to keep a sharp eye on the workforce, monitoring for any unusual behavior.
That may not be enough in the end. But we already know these companies have plenty of room for improvement.
This is an excellent opportunity to work on that.
--Bill Brenner

Wednesday, July 20, 2011

Cisco expands data center networking gear

LAS VEGAS -- Cisco this week expanded its Unified Computing System networking portfolio in an effort to improve the scalability and performance of the data center consolidation system. 
At its Cisco Live customer conference, Cisco added fabric interconnects, a virtual interface card, a chassis I/O module and an update of its UCS management software to the UCS portfolio. The extensions are intended to address challenges IT managers face in adopting virtualization, controlling costs, and scaling to meet growing business demands.
CISCO LIVE KEYNOTE: Chambers: Cisco will be leaner, faster, more attentive
Travelport, a service provider for the travel industry, is using UCS to make server provisioning faster and more agile as traffic growth strains the company's network and IT infrastructure. 

"We were spending a lot of IT man-hours cabling individual servers to access switches," says Steven Senecal, manager of global server engineering for Travelport. "There was an increased risk of human errors through recabling, and our business growth was outpacing the scale of our infrastructure."
UCS and its associated products allowed Travelport to deploy 190 servers in six hours, with service profiles for applications assigned and provisioned, and turned over to other IT teams within three days. The firm turned up another 1,304 blades this week with several hundred more planned by October, just before a heavy travel season with the end-of-year holidays.
"Our problem now is that the product teams think we can turn over servers really fast now," Senecal said, adding that UCS is increasing server performance eightfold.
UCS' momentum recently allowed Cisco to become the third leading blade server vendor worldwide, and second in the U.S. in the first quarter. To keep that momentum going, Cisco this week rolled out the networking extensions for UCS.
First is the Fabric Interconnect 6248UP. This supports Cisco's Unified Port capability, which allows IT managers to designate any port to be Gigabit Ethernet, 10 Gigabit Ethernet, Fibre Channel (2/4/8 gigabits per second) or Fibre Channel over Ethernet. It doubles the UCS system switching capacity to 1Tbps and 48 Unified Ports, and results in a 40% reduction in end-to-end latency, Cisco says.
Next is the Fabric Extender 2208XP Chassis IO Module, which doubles bandwidth to the blade chassis to 160Gbps.
Third, Cisco unveiled a Virtual Interface Card -- the VIC 1280 -- that quadruples bandwidth to the server through dual 40G interfaces, up from dual 10G on previous VICs. VIC 1280 also supports 256 virtual interfaces, double the number of previous-generation VIC interfaces.
VIC 1280 is based on the IEEE's 802.1Qbh standard for Bridge Port Extension and also supports RedHat's KVM hypervisor.
Last, Cisco updated the UCS Manager with Release 2.0. The software, which manages all system configuration and operations for UCS, now supports VMware vCenter virtualization management to enable IT to organize, provision and configure the virtualized environment across branch offices and the data center.

UCS Manager 2.0 also now allows users to run the UCS Fabric in End Host Mode rather than switch mode, and can connect management, backup, production and test networks to the Fabric Interconnect in End Host Mode.
All UCS enhancements announced this week are interoperable with the existing UCS 5108 Blade Chassis for investment protection, Cisco says.
Cisco says it now has 5,400 UCS customers and is adding 1,000 every quarter. Sixty percent of these customers are in the U.S., with 55% to 60% of them in enterprises, 20% in service providers, and the remainder in the public sector.
Sixty percent to 70% of UCS customers used to be HP server customers, while others were IBM and Dell, said Soni Jiandani, vice president of Cisco's Server Access Virtualization Business Unit.

Monday, July 4, 2011

10 reasons to stay in IT


By Alan Norton July 1, 2011, 1:27 PM PDT
Takeaway: Thinking about quitting IT? Alan Norton did — more than once. See why he says there are 10 good reasons to hang in there. In his article 10 reasons for quitting IT, Jack Wallen listed some rationales for leaving the IT profession. I would like to offer a different viewpoint, with a few thoughts of my own that may help elucidate why you should stay in IT.

1: Money, money, money
 While it is true that you work hard for your money, IT professionals are well compensated for that hard work. The pay isn’t just good, it’s great. According to the U.S. Bureau of Labor Statistics’ An Overview of U.S. Occupational Employment and Wages in 2010 (Chart 6, PDF), computer and mathematical sciences ranked third in 2010 of all major occupational groups with an annual mean salary of $77,230. Only the management and legal occupations had higher earnings.

2: The professionals
If you are like me, who you work with is extremely important. After all, more than one quarter of your working life will be spent with them. I have worked with professionals and those who weren’t so professional. I prefer the former and run from the latter. I have met professionals in other occupations, the defense industry to name one, but the professionalism of IT workers ranks right up there at the top.

3: Career continuity
The second time I left IT, I wanted to take time off and do nothing. I found out, too late, that being away from your career can make it harder to return. The biggest problem is how you are perceived by a potential employer. Employers don’t like gaps in your resume. You may have the unfortunate opportunity to discover the hard way that discrimination of the unemployed is real.

4: The challenges
One reason I chose to write computer programs was that I found it challenging. When coding, not a day that went by that I didn’t run into at least one obstacle in my path. IT professionals thrive on solving puzzles and problems. With the right mindset (which is necessary to be successful in IT), obstacles become challenges. Information technology is challenging, but you won’t find it boring. No matter what your role is in IT, the challenges you encounter tomorrow will likely be different from those you experience today.

5: The rewards
Challenges, when met, are rewarding — another reason to choose and stay in IT. I have never been more professionally satisfied than when a program I wrote actually worked as designed, without errors, or when a long-term systems project was successfully completed on time. Okay, so you’re probably not saving lives. But if you support the medical profession you are helping to save lives. And you’re saving blue- and white-collar workers the drudgery of tasks that can and should be done by a machine. Few people enjoy doing the grunt work. The systems I built during my career replaced numerous menial tasks. I can honestly say that except for a few rough patches, I left work at the end of the week satisfied, knowing that I was helping others do their jobs better. No matter what role you play in IT, helping people and a job well done create self-esteem and a sense of achievement that are highly rewarding. As TR member Chronological put it, “Most challenging jobs ever? Maybe. Most enriching jobs? — 100% sure.”

6: Marketability
IT professionals have a much better chance of finding and keeping a job. The future looks bright for IT pros — at least in the United States. Five of the top 20 and 14 of the top 50 highest paying jobs with the most growth potential are IT jobs, as ranked by CNN Money and Pay Scale.

7: The skills
Those who want to work in IT are typically quite intelligent with unique attributes and skills. IT attracts the analytical thinkers and technically inclined of the world. If you have these qualities and skills, you can find a home in IT. Another good reason to stay in IT is to keep your skills up to date. Leave IT for too long, and your skills will become rusty or even obsolete. Before you leave IT, consider that your employer is paying for you to learn new skills and keep your existing skills current. Those skills are an investment in your future.

8: The respect
Jack mentioned in his article that IT professionals get no respect from the general public. I know from your feedback in the forums that many of you agree and feel that you aren’t getting the prestige and respect that you deserve. If you are doing your job well, your perceived lack of respect may be due to the ignorance of the beholder and not through any fault of your own. The general public may well be a tough sell, but you can find respect from your peers. The knowledgeable and wise professional values the contributions of others and shows respect for his or her peers. IT is a great place to earn respect. If you can’t earn respect in IT, you probably won’t be able to earn it in any profession. Perhaps I have just been lucky or naïve, but I have always believed that I had the respect of my managers, associates, and clients. Perhaps most important, respect is a matter of attitude, your attitude, and your perception of how others see you.

9: The geek factor
IT is the perfect place to satisfy your craving for cutting-edge technology. Where else are you going to meet your geeky needs and get paid for it? If you enjoy thinking in bytes, gigahertz, flowcharts, milestones, and IF THEN ELSE statements, you will like working with others who share your interests and unique language.

10: The love of IT
  Most people who choose to work in IT love what they do. Come on, admit it. Deep down you love your work. For those who don’t, it’s all relative. When you consider the other jobs available to the masses, and their pay, you just gotta love IT. If you can find nothing you like about you and your IT job, perhaps it is time you parted ways. In one discussion thread, IT_Goddess may have said it best: “How many peeps can say they really like/love their jobs? So many people I know, outside of IT, dread going into work. Most IT folk I know love their jobs, as long as they are getting fairly compensated for what they actually do.”

The bottom line
I have been away from “formal” IT for quite some time now. I have learned from the school of hard knocks the many reasons for staying. Truth be told, I miss each of the above items, more or less in the order listed. When you get right down to the basic reasons for working in IT, more needs of the technically minded are met by IT than by other professions. And the jobs are good jobs. According to the Wall Street Journal, Two of the top five jobs for 2011 were IT jobs: software engineer and systems analyst. I understand the grueling daily grind all too well, the stress of shouldering responsibilities day in and day out, the long, tiring hours, and the many never-ending frustrations. When your focus is on checking off one more to-do item and answering one more email, it’s not hard to understand why you can’t see the forest for the trees. I guess it is often human nature not to recognize the positive aspects of where you are in the here and now. As Joni Mitchell once sang, “Don’t it always seem to go that you don’t know what you’ve got ’til it’s gone.” It’s not really necessary to leave IT, like I had to, to appreciate its many benefits.

Thursday, June 30, 2011

IP Spoofing: An Introduction


Criminals have long employed the tactic of masking their true identity, from disguises to aliases to caller-id blocking. It should come as no surprise then, that criminals who conduct their nefarious activities on networks and computers should employ such techniques. IP spoofing is one of the most common forms of on-line camouflage. In IP spoofing, an attacker gains unauthorized access to a computer or a network by making it appear that a malicious message has come from a trusted machine by “spoofing” the IP address of that machine. In this article, we will examine the concepts of IP spoofing: why it is possible, how it works, what it is used for and how to defend against it. History The concept of IP spoofing, was initially discussed in academic circles in the 1980's. While known about for sometime, it was primarily theoretical until Robert Morris, whose son wrote the first Internet Worm, discovered a security weakness in the TCP protocol known as sequence prediction. Stephen Bellovin discussed the problem in-depth in Security Problems in the TCP/IP Protocol Suite, a paper that addressed design problems with the TCP/IP protocol suite. Another infamous attack, Kevin Mitnick's Christmas Day crack of Tsutomu Shimomura's machine, employed the IP spoofing and TCP sequence prediction techniques. While the popularity of such cracks has decreased due to the demise of the services they exploited, spoofing can still be used and needs to be addressed by all security administrators. Technical Discussion To completely understand how these attacks can take place, one must examine the structure of the TCP/IP protocol suite. A basic understanding of these headers and network exchanges is crucial to the process. Internet Protocol – IP Internet protocol (IP) is a network protocol operating at layer 3 (network) of the OSI model. It is a connectionless model, meaning there is no information regarding transaction state, which is used to route packets on a network. Additionally, there is no method in place to ensure that a packet is properly delivered to the destination. Examining the IP header, we can see that the first 12 bytes (or the top 3 rows of the header) contain various information about the packet. The next 8 bytes (the next 2 rows), however, contains the source and destination IP addresses. Using one of several tools, an attacker can easily modify these addresses – specifically the “source address” field. It's important to note that each datagram is sent independent of all others due to the stateless nature of IP. Keep this fact in mind as we examine TCP in the next section. Transmission Control Protocol – TCP IP can be thought of as a routing wrapper for layer 4 (transport), which contains the Transmission Control Protocol (TCP). Unlike IP, TCP uses a connection-oriented design. This means that the participants in a TCP session must first build a connection - via the 3-way handshake (SYN-SYN/ACK-ACK) - then update one another on progress - via sequences and acknowledgements. This “conversation”, ensures data reliability, since the sender receives an OK from the recipient after each packet exchange. As you can see above, a TCP header is very different from an IP header. We are concerned with the first 12 bytes of the TCP packet, which contain port and sequencing information. Much like an IP datagram, TCP packets can be manipulated using software. The source and destination ports normally depend on the network application in use (for example, HTTP via port 80). What's important for our understanding of spoofing are the sequence and acknowledgement numbers. The data contained in these fields ensures packet delivery by determining whether or not a packet needs to be resent. The sequence number is the number of the first byte in the current packet, which is relevant to the data stream. The acknowledgement number, in turn, contains the value of the next expected sequence number in the stream. This relationship confirms, on both ends, that the proper packets were received. It’s quite different than IP, since transaction state is closely monitored. Consequences of the TCP/IP Design Now that we have an overview of the TCP/IP formats, let's examine the consequences. Obviously, it's very easy to mask a source address by manipulating an IP header. This technique is used for obvious reasons and is employed in several of the attacks discussed below. Another consequence, specific to TCP, is sequence number prediction, which can lead to session hijacking or host impersonating. This method builds on IP spoofing, since a session, albeit a false one, is built. We will examine the ramifications of this in the attacks discussed below. Spoofing Attacks There are a few variations on the types of attacks that successfully employ IP spoofing. Although some are relatively dated, others are very pertinent to current security concerns. Non-Blind Spoofing This type of attack takes place when the attacker is on the same subnet as the victim. The sequence and acknowledgement numbers can be sniffed, eliminating the potential difficulty of calculating them accurately. The biggest threat of spoofing in this instance would be session hijacking. This is accomplished by corrupting the datastream of an established connection, then re-establishing it based on correct sequence and acknowledgement numbers with the attack machine. Using this technique, an attacker could effectively bypass any authentication measures taken place to build the connection. Blind Spoofing This is a more sophisticated attack, because the sequence and acknowledgement numbers are unreachable. In order to circumvent this, several packets are sent to the target machine in order to sample sequence numbers. While not the case today, machines in the past used basic techniques for generating sequence numbers. It was relatively easy to discover the exact formula by studying packets and TCP sessions. Today, most OSs implement random sequence number generation, making it difficult to predict them accurately. If, however, the sequence number was compromised, data could be sent to the target. Several years ago, many machines used host-based authentication services (i.e. Rlogin). A properly crafted attack could add the requisite data to a system (i.e. a new user account), blindly, enabling full access for the attacker who was impersonating a trusted host. Man In the Middle Attack Both types of spoofing are forms of a common security violation known as a man in the middle (MITM) attack. In these attacks, a malicious party intercepts a legitimate communication between two friendly parties. The malicious host then controls the flow of communication and can eliminate or alter the information sent by one of the original participants without the knowledge of either the original sender or the recipient. In this way, an attacker can fool a victim into disclosing confidential information by “spoofing” the identity of the original sender, who is presumably trusted by the recipient. Denial of Service Attack IP spoofing is almost always used in what is currently one of the most difficult attacks to defend against – denial of service attacks, or DoS. Since crackers are concerned only with consuming bandwidth and resources, they need not worry about properly completing handshakes and transactions. Rather, they wish to flood the victim with as many packets as possible in a short amount of time. In order to prolong the effectiveness of the attack, they spoof source IP addresses to make tracing and stopping the DoS as difficult as possible. When multiple compromised hosts are participating in the attack, all sending spoofed traffic, it is very challenging to quickly block traffic. Misconceptions of IP Spoofing While some of the attacks described above are a bit outdated, such as session hijacking for host-based authentication services, IP spoofing is still prevalent in network scanning and probes, as well as denial of service floods. However, the technique does not allow for anonymous Internet access, which is a common misconception for those unfamiliar with the practice. Any sort of spoofing beyond simple floods is relatively advanced and used in very specific instances such as evasion and connection hijacking. Defending Against Spoofing There are a few precautions that can be taken to limit IP spoofing risks on your network, such as: Filtering at the Router - Implementing ingress and egress filtering on your border routers is a great place to start your spoofing defense. You will need to implement an ACL (access control list) that blocks private IP addresses on your downstream interface. Additionally, this interface should not accept addresses with your internal range as the source, as this is a common spoofing technique used to circumvent firewalls. On the upstream interface, you should restrict source addresses outside of your valid range, which will prevent someone on your network from sending spoofed traffic to the Internet. Encryption and Authentication - Implementing encryption and authentication will also reduce spoofing threats. Both of these features are included in Ipv6, which will eliminate current spoofing threats. Additionally, you should eliminate all host-based authentication measures, which are sometimes common for machines on the same subnet. Ensure that the proper authentication measures are in place and carried out over a secure (encrypted) channel. Conclusion IP Spoofing is a problem without an easy solution, since it’s inherent to the design of the TCP/IP suite. Understanding how and why spoofing attacks are used, combined with a few simple prevention methods, can help protect your network from these malicious cloaking and cracking techniques.

Tuesday, June 28, 2011

Russian CEO Arrested for Alleged DDoS Attack on Rival .

One of the most controversial figures in Russia’s online world, ChronoPay co-founder and CEO Pavel Vrublevsky, has been arrested on suspicion of ordering a DDoS attack against a rival firm.

By John E Dunn


1

0
Share

0
Share

4

0
Click here to find out more!
June 27, 2011 — One of the most controversial figures in Russia's online world, ChronoPay co-founder and CEO Pavel Vrublevsky, has been arrested on suspicion of ordering a DDoS attack against a rival firm.
According to news sources, Vrublevsky was last week believed to have fled the country after a hacker associated told the country's FSB security services that he'd been hired by the head to attack Assist.ru, a rival in the lucrative digital payments processing sector.
On Friday, however, the fugitive CEO turned up in a Russian court where he was denied bail and a court appearance was scheduled for a month's time, according to The Financial Times.
The attack that has landed Vrublevsky in trouble took place last summer as his company company was bidding against rivals, including Assist.ru, for the contract to handle online payments for Russian national airline, Aeroflot.
The DDoS charges aside, Vrublevsky and his company ChronoPay have become one of the country's most notorious Internet companies, connected to a range of shady Internet businesses allegedly pushing and taking payments from scams including fake anti-virus software and pharmacy spam. ChronoPay has denied involvement in fake antivirus scams, including recent ones targeting Mac users.
Expert security journalist Brian Krebs has covered the firm's intricate web of operations in a long-running series of blog posts.
The arrest could be evidence Russia is at last making serious efforts to clean up its abysmal reputation as a breeding ground for Internet criminality.
Several weeks ago, Microsoft published a series of ads in Russian newspapers announcing its intention of pursuing those said to be involved with the notorious and now-defunct Rustock botnet, brought down in March. That previously unthinkable event - that Russians allegedly involved in online criminality might be pursued in their own country with the aid of the law - has hinted that the country's attitude to its poor image might be evolving.