BrokeBerry

Attack Computer Wiz

A Security & Technology Weblog
Showing posts with label Security. Show all posts

From their website:

"The EC-Council CCISO Body of Knowledge covers all five the CCISO Information Security Management Domains in depth and was written by seasoned CISOs for current and aspiring CISOs. Domain 1 covers the Policy, Legal, and Compliance aspects of Governance. Domain 2 delves into the all-important topic of audit management from the CISO’s perspective and also covers IS controls. Domain 3 covers the Role of the CISO from a Project and Operations Management perspective. Domain 4 summarizes the technical aspects that CISOs manage in their day-to-day jobs, but from an executive standpoint. Domain 5 is all about Strategic Planning and Finance – crucial areas for C-Level executives to understand in order to succeed and drive information security throughout their organizations."

A discounted training voucher can be found at the below link, limited time only:

SaveLocal.com

http://ciso.eccouncil.org/


user Posted by Mike Wright

| More




Here is the registration link: https://ae.rsaconference.com/US14/portal/newreg.ww

Use one of the codes below to get your free Expo only pass. Be sure to visit the vendor whose code you used.

I will be updating them as I get them.

Duo Security - Booth #2518 - EC4DURY
F5 Networks - Booth #1801 - EC4F5NET
Proofpoint - Booth #1527 #520 and #3615 - SC4PROOFB or EC4PROOFE
APCOM - Booth # 632 - EC4APCON
OPSWAT - Booth #2531 - EC4PSWT



user Posted by Mike Wright

| More


I have been fortunate enough to once again be selected as a speaker for the RSA Conference in San Francisco. This years conference (2013) will be held at the Moscone Center from February 24 though March 1. I will be hosting a Peer2Peer (P2P) session entitled "To Report, or Not To Report, Will My Job Be At Risk? That is the Question" on Wednesday February 27, in Room 110, at 10:40. I am one of only 9 P2P sessions and attendance is restricted to only 25 people. If you want to participate be sure to get there early.

During this hour long session we will discuss ways to encourage our users to report policy violations and security incidents that they wittiness. If we can be informed of issues that arise early, before they get out of control, we can deal with them and mitigate further risk.

When was your last virus outbreak? Wouldn't it have been great if the very first user called and reported it before it spread? Do you have some war stories to share? Do you have some suggestions to bring? Is there something that does/does not work for your agency?

If you have any ideas please post them to comments or email me with them. I would love to hear your ideas and to see you there!

user Posted by Mike Wright

| More


As security practitioners we understand that prompt and accurate reporting of a security incident can save time, money, and can minimize damage. But when a user clicks a malicious link, replies to a spear phishing email, or gets a virus warning; they may confuse the need to report as an RGE (Resume Generating Event). How can we encourage users to report incidents without the fear of repercussion? There is nothing more frustrating then getting a phone call reporting an incident that occurred days, weeks, or months in the past.

Did the user really not notice for a month that their computer was gone and the cables were left dangling off their desk? Did they think it would just re-appear? What about a cell phone that is missing, was it just misplaced? How long should the user look for it before they report it missing? When is too long, too long? How can management create an environment that users are willing to come forward when the realize that a security incident has occurred? What can be done to encourage, or reward reporting?

These are the questions; what are the answers? Maybe my topic will be accepted at RSA 2012 San Francisco Peer2Peer and we will find out!

user Posted by Mike Wright

| More


I talk and write about it often. It was the subject of my final project during my Masters studies. I even spoke about the topic at the RSA Conference in 2012. For years one of my many hobbies has been to acquire storage media devices that people have disposed of and review them to find out what they left behind. I find devices at yard sales, laying on the ground, auctions, storage units that have been sold at auction, and pretty much anywhere you can think of. They are not always the old 256mb worthless drives either, recently I found a very nice 16gb SanDisk for 50 cents at a yard sale. Below is a very small sampling of my collection.


 USB Drives


I seem to be able to find two or three drives every couple weeks. Often these finds come with financial information, family photos, documents, bank statements, and of course nude personal photos. Unless you are living in a cave some where, in which case you are not reading this, you cannot turn your head without hearing about an identity theft or loss of data somewhere. Heck, I just saw a trailer for a movie called Identity Thief staring Jason Bateman and Melissa McCarthy, which looks hilarious by the way!

One would think with mainstream media and even Hollywood educating us everyday of the risks of identity theft, that everyone would be securing their devices or at best not keep sensitive data on them at all! Alas, this is not the case and in nearly every device I review I am able to find sensitive documents and images. In most cases simply by viewing it, rarely do I need to run any recovery tools to find them.

So until people figure out that they cannot simply toss or sell these items without proper sanitation, or encrypt them, or even better smashing them into little pieces rather then trying to get 50 cents, their precious documents and data will be used in ways they do not intend.

And Ashley, thanks for the naked pics.

Ashley
Want to see more? Click here >>> Just kidding ;)

user Posted by Mike Wright

| More




Setting up TrueCrypt Full Disk Encryption on a Windows 8 system is very straight forward and does not require anything new from previous versions of Windows. By following the below steps you can setup full disk encryption on your new Windows 8 system, or previous versions of Windows.

  1. Download and install the latest version of TrueCrypt. (7.1a at the time of this post) http://www.truecrypt.org/.
  2. Launch TrueCrypt and click on “System”, then “Encrypt System Partition/Drive...”.
  3. Choose a “Normal” or a "Hidden” system encryption, for this guide I am choosing “Normal”, click “Next”.
  4. Choose to “Encrypt the Windows system partition” or “Encrypt the whole drive”, for this guide I am choose whole drive, click “Next” *Choosing whole drive will take a considerable amount of time however all of your data on the drive will be secure, not just the Windows system.
  5. If prompted, acknowledge the 'User Account Control' by clicking “Yes”.
  6. Choose your option on whether or not to encrypt the “Host Protected Area”. *The host protected area may have drivers, such as RAID drivers, that need to be accessed ‘pre-boot’.
  7. Choose whether you have a single OS installed or are booting between multiple OS’s, click “Next”.
  8. Choose the 'Encryption Algorithm' and the 'Hash Algorithm' you want to use. Read each description and select the one that you feel is best for you. By clicking the “Benchmark” button you can estimate how many megabytes per second your encryption task may take. Click “Next”.
  9. Create your encryption password, the bigger the better, recommended is 20 characters, click “Next”. *Here is a link to check the strength of your password http://howsecureismypassword.net/.
  10. On the next screen you will see moving text. Simply move your mouse around your screen for a while to create a random data pool. Do this for as long or as little as you like, but you should give it a few seconds at the very least. Click “Next”.
  11. The next screen will show you the generated keys. You do not need to do anything here, just click “Next”.
  12. On the 'Rescue Disk' screen you need to specify a path for an ISO file to be created. You will need this ISO file in the event you need to boot your system from a disk. So “Browse” to a location and save your rescue disk. Click “Next”.
  13. Acknowledge the action and insert a blank CD into your CD burner. Choose your CD burner from the drop down box and click “Burn”.
  14. Now, before you continue, navigate to the location of the ISO file that you created in the last step. Copy that ISO file to an external location such as a thumb drive. If your disk is lost or broken you can use this ISO file to create a new one.
  15. Click “Close”, then click “Next” to verify that your cd is good, click “Next” again.
  16. Remove the burned disk, label it, and store it in a safe location.
  17. On the next screen you are asked if you want to wipe unused space on your disk. This can be important if you need to securely erase any data that can possibly be recovered. Choose your wipe mode (3 pass is sufficient) or choose “None” if this is not a concern to you. Click “Next”.
  18. Next you are asked to perform a 'Pretest'. Be sure that all of your applications are closed and your work is saved. Next click “Next”, agree to the terms, then click “Yes” to reboot your computer and begin the pretest.
  19. Assuming there are no issues, your computer will reboot normally and after the POST screen you are asked for your TrueCrypt password. Type the password that you created earlier and press “Enter” on your keyboard.
  20. Assuming there are no issues, your computer will start into Windows as it always does. Logon if needed and click on the “Desktop” button from your new start screen. Once on the desktop Trucrypt should be waiting for you. Simply press the “Encrypt” button to begin the whole disk encryption process. You may need to agree to the terms again and User Account Control may prompt you for permission again.
  21. At this point just sit back and wait.

Depending on the size of your disk and the level of encryption you chose you may be waiting a very long time. You can use your system normally during the encryption process. Just don’t do any intense gaming. Stick to Facebook and email until it is done.

When it is all done simply reboot your computer and you are done! You can now sleep better tonight.

user Posted by Mike Wright

| More


Posted below is my abbreviated presentation from the 2012 RSA Security Conference in San Francisco. I hate watching myself on video and no, despite my swaying back and forth, it was not film on a ship in rough seas.

Garage Sale Forensics: Data Discovery Through Discarded Devices

"A review of how data storage devices can be discovered and the data left on those devices used for unauthorized purposes. Individuals and organizations may dispose of a device without completely purging all data that resides or resided on it. This presentation will show where devices can be located, how data can be recovered, and how the organization or individual can protect themselves from loss."

user Posted by Mike Wright

| More


Chester Wisniewski over at Sophos posted an article yesterday on the inner workings of a fake anti-virus company. It is a good story and well worth the read. You can find it at the link below. Often support people and users ask me how these types of virus’, worms, etc., make it past our firewalls, AV, and other controls that they spend so much money on. This story points out that this particular fave AV vendor updates there payloads every two hours.

Wow!

This is an example of how technology cannot fix stupid human behavior. Really, how can vendors create definitions within a two hour window? Fake AV is not a technology problem, it is a people problem. In many cases fake AV is a social engineering trick that dupes the user into infecting their own system. People need to be educated on what these types of attacks look like, how to prevent them, and who to notify when they occur (or are suspected).

 "A sneak peek into fake anti-virus affiliate support"

user Posted by Mike Wright

| More


There are a number of rumors floating around and early bandwagon jumpers who are claiming that there is a bug that allows users to bypass the passcode, PIN, or password lock on an iPhone that has updated to iOS 5.1. This is untrue, the described bug is not a bug at all. It is a failure on the users part to properly set security timeouts on their device.

The videos and descriptions show how anyone can bypass the passcode on an iPhone by simply activating the new camera feature on a locked device, click on the gallery button, and then click the home button. The videos show that the unauthorized user is now logged in without a passcode. Well the fact is, the device was never locked, the screen was only turned off. If the user in the demonstration would have set this timeout to immediate, rather than 1 minute or more, then the device would have truly been locked and this alleged bypass would not work. Check your settings by tapping “Settings”, “General”, “Passcode Lock”, “Required Passcode”.  The Required Passcode setting should be set to “Immediately” to properly secure your device.

This is not an Apple failure this is a user failure!

9to5Mac
Sophos

user Posted by Mike Wright

| More


Here is a podcast that I did leading up to the RSA Conference 2012 in San Francisco. I should be able to post a video of a shortened version of my presentation that I was invited to do along with my full presentation later.


http://365.rsaconference.com/community/connect/blog/2012/02/14/rsac2012-podcast-das-403-garage-sale-forensics-data-discovery-through-discarded-devices

user Posted by Mike Wright

| More


Use the below codes and this link to register (https://ae.rsaconference.com/US12/portal/login.ww)

ProofPoint - EC12PRF
DeviceLock - EC12DVL
IronKey - EC12IRN
Symantec - SC12SYM
SF Bay InfraGrid - 1412RLPXPO
FortiNet - EC12FRT

user Posted by Mike Wright

| More


According to a study at Carnegie Mellon Cylab many children are becoming the victims of identity theft. Children are often easy targets for thieves because the theft can go unnoticed for many years. Often it is not until the child reaches adulthood and they apply for their first credit card or car loan is it discovered that their credit has been ruined. This is a huge problem and the credit reporting agencies do not help the issue, in fact, in my opinion, they aid the thieves.

If I wanted to see my credit report and determine if there are any fraudulent charges I simply need to visit https://www.annualcreditreport.com and I can have access to each of the three reports at no charge, once per year. But try to access your child's credit report, go ahead, try it... I can wait.

You will find, like I did that you cannot access the report online. They claim that they "do not knowingly maintain credit files on minor children". If this is the case, why are there credit cards issued to minor children and why is this information not being verified? Oh, I missed the 'knowingly" part... really? Is a killer less a killer because they did not "knowing" put bullets in the gun before they fired it?

So what now, assuming you are not lazy, and want to ensure that your kids are able to receive credit someday, you need to take proactive action and take that action sooner rather then later. In order to get the credit reports you must request them in writing from each of the three agencies. In order to do this you must:

  1. Write a letter of request,
  2. Include your name, address, phone number,
  3. A copy of your drivers license or other government issued identification with your current address,
  4. A copy of a current utility bill that shows your current address,
  5. Your child's full name, address, date of birth,
  6. A copy of your child's birth certificate,
  7. A copy of your child's social security card
Send your request to the below agencies:

Equifax
P.O. Box 740256
Atlanta, Georgia 30374

Experian
P.O. Box 9554
Allen, Texas 75013

TransUnion
P.O. Box 6790
Fullerton, CA 92834

Now sit back and wait for the magic of inconvenience, no technology, snail mail, and most likely 6- weeks.

Source

user Posted by Mike Wright

| More


All too often people simply dispose of their computers, disk drives, portable devices, thumb drives, etc. when they are done using them. By doing this, often they expose themselves to identity theft. Anyone can simply take that drive, connect to to a computer system, and read your information.

But you formatted it so your data was all erased, right? Wrong! The fact is, formatting a drive does nothing more then tell the allocation table on the drive (which is like the drives table of contents) that the data is available to be written over. That does not mean the data is gone, in fact the data is not gone.

In order to completely erase all data on your drive before you dispose of it s to wipe the drive with a tool that uses at least a three pass Department of Defense compliant wiping process. This process actually deletes all data on the drive, then writes useless data to every sector on the drive, then erases the drive again. The software will repeat this process at least three times eliminating the possibility of anyone recovering your data. There is a great free tool called Disk Wipe for this. I encourage you to use it, or a sledge hammer.

user Posted by Mike Wright

| More


According to the Federal Trade Commission, Identity Theft is number one in consumer complaints for 2010. There were 250,854 complaints about Identity Theft, of the 1.9 million total complaints, making it 19% of all reports. This is the 11th year in a row where ID theft has been at the top of the list according to CNNMoney.com.

Also according to the CNNMoney.com report fraudulent government documents were the top source of the ID theft complaints. For those of you that don't know, that is someone stealing and using your Social Security Number or other government issued document. At the 2011 RSA Security conference I listened to Kimberly Peretti a former senior litigator for the Department of Justice speak. She was the lead prosecutor in the Albert Gonzolez case speak. She confirmed that SSN's are still the number one target of ID thieves.

user Posted by Mike Wright

| More


Just last week at the TED conference in Long Beach California, Celebrity Ashton Kutcher had his Twitter account hacked, this according to reporters over at Threat Post. As my readers may recall I posted about FireSheep back in November of last year. It is a FireFox plug in that allows a hacker to intercept social networking session over un-secured wireless connections.

A sample of the messages posted to Kutchers' account are:

"Ashton, you've been Punk'd. This account is not secure. Dude, where's my SSL?"

"P.S. This is for those young protesters around the world who deserve not to have their Facebook & Twitter accounts hacked like this. #SSL"

user Posted by Mike Wright

| More


"Recently, a lot of high profile .EDU and .GOV where hijacked to redirect users to fake online stores. Google searches related to buying software ("buy windows 7 key", where to buy microsoft, "purchase microsoft word", "buy microsoft office", etc.) contain a long list of websites running on non-standard ports: www.kidsforkidsfestival.org:8080, en.jurispedia.org:4444, >www.notiuno.com:4577, etc. These links redirect users to online stores which claim to sell software at a discounted price."

Go to the Zscaler Research website to read the whole story.

user Posted by Mike Wright

| More


Digital Forensics: How to configure Windows Investigative Workstations

By: Derek Newton, Senior Technical Security Engineer at Time Warner Cable on the Security Incident Response Team.

user Posted by Mike Wright

| More


I stumbled upon a program called FireSheep today. This completely free utility can allow a hacker to access user accounts on websites such as FaceBook, Twitter, Flickr, and more. What is interesting and scary is that this application requires little to no technical know how to hack an account.

Here is how it works (and no it is not 100% effective 100% of the time):

1. The hacker installs the free application on their portable computer and travels to a free wireless network. You know, like the ones at McDonald's, Starbucks, the car wash, the hotel, your neighbors who does not secure their wireless access points.

2. Once connected the hacker presses the "Start Capturing" button and waits.

3. As soon as anyone on that network connects to a site that FireSheep knows about their information is displayed in the capture window. Now the hacker simply clicks the icon and they have just hijacked your account (see screen shot below).

How do you protect yourself? Don't use free wireless access points!

Photobucket

user Posted by Mike Wright

| More


Cybersecurity is our shared responsibility. That means everyone has the potential to make a difference and educate others. You can raise awareness within your school, your workplace, your community – or all three.

Show your support for NCSAM.

user Posted by Mike Wright

| More


Installing and configuring Ubuntu with full disk encryption is quite simple if you follow the below steps:

  1. Download the alternative installation iso and burn it to disk. (LINK)
  2. Boot from disk and accept the basic language and region settings, stop at partitioner.
  3. Choose "Guided - use entire disk and set up encrypted LVM".
  4. Choose the the disk that you are going to partition.
  5. Select "Yes" to confirm and write changes.
  6. Enter your encryption password/pass phrase.
  7. Choose the disk size.
  8. Select "Yes" to confirm and write changes.
  9. Now continue as normal with the Ubuntu installation.

user Posted by Mike Wright

| More