Interesting paper.
I suspect it would be more useful for Malware hiding from AV or other counter measures, than for data privacy or security.
PDF link http://www.recover.co.il/SA-cover/SA-cover.pdf
Esports & Computer Security Blog. For SC2 tournaments see clocks immediately below. Starts with Korean time at upper left, moves west around the world till you end with PDT/PST clock for Anaheim USA. I earn a small referral fee if you click the occasional Amazon links and then purchase item. It does not affect the purchase price. For more information see "Amazon Associates" link below & left of clocks.
Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts
Tuesday, February 19, 2013
Sunday, January 20, 2013
Security & Hacking: Malware & US Power Plants
Summation by Reuters http://in.reuters.com/article/2013/01/16/cyber-security-powerplants-virus-idINDEE90F0H720130116 of this ICS CERT Monthly Monitor (PDF) http://www.us-cert.gov/control_systems/pdf/ICS-CERT_Monthly_Monitor_Oct-Dec2012.pdf
I strongly suggest reading the PDF if you want to learn or understand the issue.
One of the things I noted on my first read of the PDF, was that not only was the one plant hit by Malware, but that two of their workstations that were critical to the operation of the plant had no backups, or even backup components on site.
This hints at the rather large scope of the problem for improving ICS security.
I don't have a background in ICS or Power Plants, my experience is more in physical security, but the impression I got from the ICS CERT Monthly Monitor was that many (most?) of these plants are used to winging things.
They are used to enough slack, or excess capacity, in the system or grid as a whole, that they haven't had to meet the type of uptime requirements many in IT fields take for granted.
If I understood correctly, a simple HDD or power supply failure of one of the critical workstations could have deadlined the whole plant for indefinite period.
Further Resources from US CERT Control Systems Security Program (CSSP):
I strongly suggest reading the PDF if you want to learn or understand the issue.
One of the things I noted on my first read of the PDF, was that not only was the one plant hit by Malware, but that two of their workstations that were critical to the operation of the plant had no backups, or even backup components on site.
This hints at the rather large scope of the problem for improving ICS security.
I don't have a background in ICS or Power Plants, my experience is more in physical security, but the impression I got from the ICS CERT Monthly Monitor was that many (most?) of these plants are used to winging things.
They are used to enough slack, or excess capacity, in the system or grid as a whole, that they haven't had to meet the type of uptime requirements many in IT fields take for granted.
If I understood correctly, a simple HDD or power supply failure of one of the critical workstations could have deadlined the whole plant for indefinite period.
Further Resources from US CERT Control Systems Security Program (CSSP):
- Introduction to Recommended Practices: http://www.us-cert.gov/control_systems/practices/
- Recommended Practices: http://www.us-cert.gov/control_systems/practices/Recommended_Practices.html
- Cyber Threat Source Descriptions: http://www.us-cert.gov/control_systems/csthreats.html
- Information Products: http://www.us-cert.gov/control_systems/csdocuments.html
Monday, January 14, 2013
Security & Hacking: Red October Malware
http://arstechnica.com/security/2013/01/red-october-computer-espionage-network-may-have-stolen-terabytes-of-data/
I tweeted about this earlier today, it is still way to early to have solid grasp of the scope of this Malware IMVHO, but the Ars article does good job of giving initial idea of the size of this attack.
Lots of things about this Malware are really impressive, but this part grabbed my attention, from Ars link at top:
There are exceptions, certain types of Terrorist attacks and/or Ideological attacks may chose well defended targets because they are not motivated my economic profit for example.
The amount of effort this shows, for re exploiting a targeted system, after Computer Security removed original exploit, has the definite mark of Military Intelligence to me.
I suggest the Ars article linked at top.
The comments to the Ars article are well worth reading for people wanting to learn more, you can find good insights and resources in the comments section whether your new to Computer Security or an expert yourself.
You do have to screen out the noise to find the signals of course.
Original article from Kaspersky is https://www.securelist.com/en/blog/785/The_Red_October_Campaign_An_Advanced_Cyber_Espionage_Network_Targeting_Diplomatic_and_Government_Agencies
[Edited to add this from link immediately above, Rocra (short for "Red October"), is shorthand name they are using for this Malware, might be useful for additional Google searches.]
I will certainly be blogging more about Red October.
I have created new Label Red October Malware, you can bookmark that, if you want an easy way to check for updates.
I will be adding that Label to the selected labels at left side of Blog.
Labels can be found at bottom left of every blog post, and here is a suggested list of Labels for people interested in Security & Hacking:
I am still looking for ways to improve searches on my blog, so far best I have found is simply using Google with Cliff's Esport Corner in search box, plus topic your interested in like Red October, if a Label doesn't work for you.
I have tested Google's gadget for Blogger, but it wasn't as useful as regular Google for finding material on my blog the last time I tested it.
I tweeted about this earlier today, it is still way to early to have solid grasp of the scope of this Malware IMVHO, but the Ars article does good job of giving initial idea of the size of this attack.
Lots of things about this Malware are really impressive, but this part grabbed my attention, from Ars link at top:
One novel feature contained in Red October is a module that creates an extension for Adobe Reader and Microsoft Word on compromised machines. Once installed, the module provides attackers with a "foolproof" way to regain control of a compromised machine, should the main malware payload ever be removed.This is one of the tidbits that make me think this is State sponsored, most criminals are opportunistic, in other words criminals tend to attack easy targets.
"The document may be sent to the victim via e-mail," the researchers explained. "It will not have an exploit code and will safely pass all security checks. However, like with exploit case, the document will be instantly processed by the module and the module will start a malicious application attached to the document."
There are exceptions, certain types of Terrorist attacks and/or Ideological attacks may chose well defended targets because they are not motivated my economic profit for example.
The amount of effort this shows, for re exploiting a targeted system, after Computer Security removed original exploit, has the definite mark of Military Intelligence to me.
I suggest the Ars article linked at top.
The comments to the Ars article are well worth reading for people wanting to learn more, you can find good insights and resources in the comments section whether your new to Computer Security or an expert yourself.
You do have to screen out the noise to find the signals of course.
Original article from Kaspersky is https://www.securelist.com/en/blog/785/The_Red_October_Campaign_An_Advanced_Cyber_Espionage_Network_Targeting_Diplomatic_and_Government_Agencies
[Edited to add this from link immediately above, Rocra (short for "Red October"), is shorthand name they are using for this Malware, might be useful for additional Google searches.]
I will certainly be blogging more about Red October.
I have created new Label Red October Malware, you can bookmark that, if you want an easy way to check for updates.
I will be adding that Label to the selected labels at left side of Blog.
Labels can be found at bottom left of every blog post, and here is a suggested list of Labels for people interested in Security & Hacking:
I am still looking for ways to improve searches on my blog, so far best I have found is simply using Google with Cliff's Esport Corner in search box, plus topic your interested in like Red October, if a Label doesn't work for you.
I have tested Google's gadget for Blogger, but it wasn't as useful as regular Google for finding material on my blog the last time I tested it.
Tuesday, October 9, 2012
Sophos and others starting to cover the Skype Malware going around.
See Sophos blog here http://nakedsecurity.sophos.com/2012/10/08/skype-worm-spreads/
and Ars link http://arstechnica.com/security/2012/10/skype-users-targeted-by-malicious-worm-that-locks-them-out-of-their-pcs/
My previous posts on this malware:
and Ars link http://arstechnica.com/security/2012/10/skype-users-targeted-by-malicious-worm-that-locks-them-out-of-their-pcs/
My previous posts on this malware:
Sunday, October 7, 2012
Security & Hacking: More on Skype Malware that is going around
http://zhurai.com/541-skype-chatspam-virus-notes/
If you have more info please post in comments or Tweet me @CliffsEsport || https://twitter.com/CliffsEsport
My previous posts on this:
If you have more info please post in comments or Tweet me @CliffsEsport || https://twitter.com/CliffsEsport
My previous posts on this:
Friday, October 5, 2012
PSA: Update on Skype Malware
See GFI Labs report here http://www.gfi.com/blog/infection-spreads-profile-pic-messages-to-skype-users/
I posted about this yesterday http://cliffsesportcorner.blogspot.com/2012/10/psa-skype-malware-alert.html
I posted about this yesterday http://cliffsesportcorner.blogspot.com/2012/10/psa-skype-malware-alert.html
Tuesday, August 21, 2012
Nerd News: "McAfee update chaos sparks user fury"
See story at SC Magazine's site http://www.scmagazine.com.au/News/312625,mcafee-update-chaos-sparks-user-fury.aspx
Personally I don't use McAfee's AV anymore, I think they have skills & talent to make decent AV software, but how they view and treat customers just doesn't make me feel like giving them my money.
I prefer Microsoft Security Essentials for Windows AV software (talking home & small business use, a business with some real money to throw at software could be different).
For Mac OS not sure yet, currently using and testing Sophos Free Mac AV.
So far for free AV it seems good, small bug issues couple of times, fixed with next patch, but other than that no complaints so far.
Personally I don't use McAfee's AV anymore, I think they have skills & talent to make decent AV software, but how they view and treat customers just doesn't make me feel like giving them my money.
I prefer Microsoft Security Essentials for Windows AV software (talking home & small business use, a business with some real money to throw at software could be different).
For Mac OS not sure yet, currently using and testing Sophos Free Mac AV.
So far for free AV it seems good, small bug issues couple of times, fixed with next patch, but other than that no complaints so far.
Thursday, August 9, 2012
Security & Hacking: Gauss Malware, linked to Flame
Saw this first on Ars http://arstechnica.com/security/2012/08/nation-sponsored-malware-has-mystery-warhead/
Original discovery & announcement from Kaspersky
I suggest reading whole story at above links, more detail from Kaspersky link:
Original discovery & announcement from Kaspersky
I suggest reading whole story at above links, more detail from Kaspersky link:
At the present time, the Gauss Trojan is successfully detected, blocked and remediated by Kaspersky Lab’s products, classified as Trojan-Spy.Win32.Gauss.
The company’s experts have published in-depth analysis of the malware at Securelist.com: http://www.securelist.com/en/analysis/204792238/Gauss_Abnormal_Distribution
A Gauss FAQ containing the essential information about the threat is also available: http://www.securelist.com/en/blog?weblogid=208193767
Stay tuned for updates by following our Facebook page: https://www.facebook.com/Kaspersky?ref=ts
Friday, July 27, 2012
PSA: Twitter Blackhole Malware Alert
See Sophos Naked Security Blog post for details.
Current versions are using tweet about is it you in photo, with link, but link installs malware.
Current versions are using tweet about is it you in photo, with link, but link installs malware.
Wednesday, June 20, 2012
Cool Story about Diablo 3 Malware
http://arstechnica.com/security/2012/06/hacker-uses-malware-built-in-chat-to-toy-with-researchers/
Interesting story, plus it gives an insight to how complex Malware can be, and how easy it is to get infested without doing anything that seems like high risk behavior.
Interesting story, plus it gives an insight to how complex Malware can be, and how easy it is to get infested without doing anything that seems like high risk behavior.
Tuesday, May 15, 2012
PSA: "Avira Antivirus update cripples millions of Windows PCs"
ZDNet, computer security News/Blog site that I follow, had this very disturbing story about Avira!
http://www.zdnet.com/blog/security/avira-antivirus-update-cripples-millions-of-windows-pcs/12129
I don't claim to be a Computer Security expert, but ever since my old XP machine got infested with malware after installing free AVG I have been very picky about what AV (AntiVirus) software I install.
I personally have had very good luck with Microsoft's free Security Essentials link http://windows.microsoft.com/en-US/windows/products/security-essentials
That was recommend to me by two friends that are true professional Computer Geeks, I am sure there are probably better AV products out there that require purchase (not free).
But I suspect you would need to use products designed for Business/Corporate use to see a real significant benefit over Security Essentials or other good free AV software.
Stay Safe,
Cliff
http://www.zdnet.com/blog/security/avira-antivirus-update-cripples-millions-of-windows-pcs/12129
I don't claim to be a Computer Security expert, but ever since my old XP machine got infested with malware after installing free AVG I have been very picky about what AV (AntiVirus) software I install.
I personally have had very good luck with Microsoft's free Security Essentials link http://windows.microsoft.com/en-US/windows/products/security-essentials
That was recommend to me by two friends that are true professional Computer Geeks, I am sure there are probably better AV products out there that require purchase (not free).
But I suspect you would need to use products designed for Business/Corporate use to see a real significant benefit over Security Essentials or other good free AV software.
Stay Safe,
Cliff
PSA: Rootkit Removal, Windows Defender Offline (free)
I have an old XP machine that I used to use to play Diablo 2 on, it is horribly infested with malware, free AV software was part of the problem from what I have been able to tell.
I tried a bunch of things to clean it, but wasn't sure it was clean so I stopped using it, with the Diablo 3 release I started thinking about it again.
Which led me to this free Malware removal tool that I didn't try on the XP machine, that is supposed to be good for removing rootkits & such http://windows.microsoft.com/en-US/windows/what-is-windows-defender-offline
If I felt halfway sure I got it clean there is data I would like to pull off of it, nothing critical, but some useful things.
I know, I should have it backed up but we are talking like maybe a dozen bookmarks that I could find again with couple days of work if I ever do need them, & some project Gutenberg books that I have on my Blackberry anyway but have been to lazy to download again on laptop or transfer from Blackberry to my laptop (I wish smartphones had USB 3!!!).
Anyway I though some of my readers would find this tool useful, you can put it on a DVD/USB and then boot with Windows Defender Offline, it will load ahead of the root kits during the boot from what I understand ( I am not a hard core computer nerd).
Hope that helps.
~Cliff
I tried a bunch of things to clean it, but wasn't sure it was clean so I stopped using it, with the Diablo 3 release I started thinking about it again.
Which led me to this free Malware removal tool that I didn't try on the XP machine, that is supposed to be good for removing rootkits & such http://windows.microsoft.com/en-US/windows/what-is-windows-defender-offline
If I felt halfway sure I got it clean there is data I would like to pull off of it, nothing critical, but some useful things.
I know, I should have it backed up but we are talking like maybe a dozen bookmarks that I could find again with couple days of work if I ever do need them, & some project Gutenberg books that I have on my Blackberry anyway but have been to lazy to download again on laptop or transfer from Blackberry to my laptop (I wish smartphones had USB 3!!!).
Anyway I though some of my readers would find this tool useful, you can put it on a DVD/USB and then boot with Windows Defender Offline, it will load ahead of the root kits during the boot from what I understand ( I am not a hard core computer nerd).
Hope that helps.
~Cliff
Thursday, February 2, 2012
Nerd News: Google Bouncer, Malware Screening of Android Apps
I prefer Blackberry devices myself, but I know Android phones are very popular with Nerds, you may find this Service from Google useful.
From Google Mobile Blog:
From Google Mobile Blog:
Today we’re revealing a service we’ve developed, codenamed Bouncer, which provides automated scanning of Android Market for potentially malicious software without disrupting the user experience of Android Market or requiring developers to go through an application approval process.
Thursday, January 19, 2012
Nerd News: McAfee Turning PC's into Spam machines ?!?
Evidently McAfee's SaaS Total Protection anti-malware service was allowing spammers to exploit PC's, seems rather ironic. Full story http://www.techspot.com/news/47104-mcafee-turns-customers-pcs-into-spam-servers-patch-incoming.html
Subscribe to:
Posts (Atom)