Ads 468x60px

Pages

Dec 18, 2020

SolarWinds Hack to Signal a new form of Warfare?

 The list keeps on growing... The new war. The new espionage. Call it what you will, but this was not a simple attack.




It started by manipulating SolarWinds Orion system updates hackers (state sponsored hackers, i.e. cyber warfare). This updated version allowed the hackers to access any of the servers which hosted the SolarWinds application, which is an IT monitoring and management tool used by administrators and network engineers. This allowed the hackers to have full administrator access to at least one server inside the victim's network, and download any additional malware they needed to get full access of the victims' networks. To set things in perspective, hackers breached the US nuclear weapons agency.

Source: Microsoft


The list of victims is huge. Till now, 40+ major companies or government departments and agencies have been identified. I expected the final number to reach at least a 100+ hi-profile victims. Hackers had around 9 months to do whatever they wanted without being caught. 80% of which are located in the United States, with the rest being spread across seven other countries —namely Canada, Mexico, Belgium, Spain, the UK, Israel, and the UAE. 


Companies breached so far:

- Microsoft
- SolarWinds
- Fireeye

Main US targets:

- The US Treasury Department
- The US Department of Commerce's National Telecommunications and Information Administration (NTIA)
- The Department of Health's National Institutes of Health (NIH)
- The Cybersecurity and Infrastructure Agency (CISA)
- The Department of Homeland Security (DHS)
- The US Department of State
- The National Nuclear Security Administration (NNSA)
- The US Department of Energy (DOE)
- Three US states
- City of Austin (also disclosed today)


While not the first attack of its kind, the fact that we are still at the tip of the iceberg in discovering the scale is worrisome. The types of victims, the amount of data that could have been stolen during a 9-month breach, and the fact that it is a state sponsored attack all indicate that the new wars will be fought online as well as with real weapons.


Finally, so many questions come to mind, and I am sure those would be answered within the coming days:

  1. How did the hackers bypass all internal SolarWinds controls, application controls and Quality Assurance to publish such a malicious update.
  2. How were they left undetected for 9 months.
  3. How many companies have been really breached and what type of data has been stolen
  4. What long lasting impact will this have on the cyber world, how can we ensure that software installed on our infrastructure is secure?
  5. Will the US retaliate?

Sep 9, 2020

Passwords.... Passwords

How long would it take to crack your password? This simple table explains it all!




 

Aug 22, 2020

Warning: A Google Drive 'Feature' Could Let Attackers Trick You Into Installing Malware

 


An unpatched security weakness in Google Drive could be exploited by malware attackers to distribute malicious files disguised as legitimate documents or images, enabling bad actors to perform spear-phishing attacks comparatively with a high success rate.

The latest security issue—of which Google is aware but, unfortunately, left unpatched—resides in the "manage versions" functionality offered by Google Drive that allows users to upload and manage different versions of a file, as well as in the way its interface provides a new version of the files to the users.

 

For more info, https://thehackernews.com/2020/08/google-drive-file-versions.html


Dec 3, 2018

So.... I'm back......

Looks like I'm back. 4 years and a half since my last post.... I'm back.

A lot has changed since then. On a personal level and on a bigger scale. Infosec and hacking have become on everybody's lips. So many hacks. So many issues. So many breaches and yes..... GDPR. GDPR everywhere.

Well..... This won't be a long post. I'll just leave you with this:




Aug 7, 2014

Companies to blame as much as end users!

People always ask me why it’s so easy to hack into their emails, get their accounts on Facebook or have their credit card data stolen. I usually always focus on end users. This post is about the programmers, the developers and companies which we “trust” with all our data.

Why am I writing this post? Well two days ago I was reading about how Mozilla (of FireFox browser) “accidentally” leaked 76,000 email addresses and 4,000 passwords! PF Chang was hacked for 8 months, until finally thought OOOPS we just realized. Domino’s Pizza was hacked.



When computers were being developed, no one had security in mind. When the internet was created, no one thought about security. Security came as an afterthought, years and years after people started using computers, programs and the internet. So when cyber criminals decided to cash in, a new domain called information security was created, and the game of cat and mouse started. Cyber criminals always have the upper hand, and security professionals are always running behind to fix the holes.



Almost in all situations, the problem in any security flow starts from the programmer(s) who design and write code. When programming languages were created, many security flows existed. Even though those flows are always being fixed, programmers are under a lot of pressure to finish their work in record time. They are barely given time to test a program let alone check it for security flows. What used to be an issue with lack of security knowledge has now transformed into an issue with management. Get the program out as soon as possible is what’s important; you can fix the problems later.

I used to think that since I live in a third-world country, it was an issue with companies in this country. I truly believed that in advanced countries, security is a prime concern and that the whole system would not allow for such flows. The more I read about the topic, and got interested in it, the more I realized that it’s a universal problem. How many “top” companies had defected products, systems hacked and passwords stolen?



The idea is that it is impossible to secure systems/website unless you don’t want to use them; that is have them inaccessible by anyone. Any other way? No!. The closest is having a dedicated security team of at least a 100 employees (which should all be competent)… Having the management on the security wagon. Programmers, network people and server people all sufficiently trained and believing in what it takes to secure the system. Only then would you have a chance of being partially secure.



Back to the initial question… Why is it easy to hack into our data… Well it’s because even if you do whatever you can do from your end as an end-user, and follow every single guideline… It’s still not in your hands! The truth is that many people working in the cyber world are incompetent, unhappy, pressured or just not interested. As long as we are playing the cat and mouse game, we will always be the losers. Security has to be part of any design of the future of internet… Not just a simple afterthought.

Jan 10, 2014

2014 Norfect Security Predictions!!!

It's a new year and it's time for Norfect's 2014 security predictions.... You can run away now!



But before that, a small message to my amazing wife. HAPPY BIRTHDAY! My life would mean nothing without you by my side.


So without further ado, here are my predictions!



1. Many house users, corporations and websites will be attacked by new vulnerabilities found in Windows XP, Office 2003, and Java 6. You see, support and security patches will be suspended for these products in 2014 as they have reached their end of support life cycle. This means anyone using these products won't be able to patch any newly found vulnerabilities. Can you guess who will benefit most?

2. Hackers will increase the use of ransom-ware. They will attack end-users and corporations in order to get easy money to use elsewhere. It will be "fast money" used for other bigger breaches.


3. Which gets us to the prediction that major data breaches will increase significantly. At the end of 2013, not a month passed without at least 1 million user ID and password were hacked from known companies. In 2014, even more world-wide companies will be hacked. More usernames and passwords will be published online.



4. Due to the whistle-blowing actions of Edward Snowden, more and more people will be aware about their online privacy. Users will have less trust in the internet because anything they do can and is being traced by governments. Web activists will be pushing towards an internet reform.



5. Corporate mobile devices will be targeted by specific malware to gather sensitive data/emails. Many of these malware will be left undetected for a long period of time. Antiviruses for mobiles in my opinion are still pretty weak with many false positives that make you ignore real threats.


6. With more and more people storing information on the cloud, at least one major cloud storage provider will be hacked and millions of terrabytes of user data will be exposed.



7. Attacks will become more personalized. The attackers will spend more time focusing on their targets to be able to craft personalized attacks via emails or the social network.


And that's the end folks! What are your predictions?

Dec 22, 2013

Computer Security Jokes ~ 3

Since it's been a long while and I am not having much time to blog since my second son was born, though I'd just share a few new jokes I've come across over the internet! Enjoy



Legitimate it is ....


Trust me, best source of complex passwords!






Finally, the smartest :p

Jun 17, 2013

Two-factor Authentication .... Microsoft/Outlook

Update: Changed the post title from : "A Simple Way to Keep Your Hackers Away" to better reflect the content.

So I’ve been away since a long time. Blame George RR Martin’s A Song of Ice and Fire. That thing is pure genius it makes you forget everything else!



(Ok that and I’ve been really busy lately)


Oh well, I keep on hearing from my friends and relatives at least monthly that someone hacked their accounts, be it an email, Facebook, blog, Twitter, LinkedIn… and it really sucks. I’m sure you've already read or heard about it, that’s not why I’m writing this post. 

To be honest, I am very careful and try my best to protect my accounts. To do that, I have to use whatever capabilities the companies I'm registered at provide me. We all know that usernames and passwords are the way we prove to a site that we are the owners of that account. That’s not enough, and it’s easily hacked by anyone who really puts his mind to it.

Hence, I have decided to use two-factor authentication for all my critical accounts. This post and the next ones will be about setting up and testing the two-factor authentication for the major companies out there. I already have two-factor authentication enabled for my main Google/Gmail account, so this post will be to enable it for my main Microsoft/Outlook (ex-Hotmail) account. The next will be about Google/Gmail.


Hold on a minute….WHAT IS TWO-FACTOR AUTHENTICATION???

Two-factor authentication is basically adding an extra layer to the password. The password is effectively something a person “knows”. The second layer would be something a person “owns”, for example, a code sent to his mobile phone. This would make hacking into your account very tough… Even if the hacker gets your password, he won’t be able to log in without having your mobile phone.



Very smart yet very simple.

So back to my Microsoft two-factor authentication experiment. I will illustrate it via images, and any explanations will be included in captions.

After Logging into outlook, press your name and then account settings

Press Edit Security Info

Microsoft double checks that it is truly you accessing your security info

After receiving the code on your alternate email, add it here. If you do not have an alternate email, create one asap. It is very useful when/if you lose your password.

The email received from Microsoft for double checking. To be honest, it looks fishy (phishing), yet it is legitimate!

After inputting the code, you reach this screen. Press "set up two-step verification"

After activation, Microsoft explains that some of your accounts might require special permission to be able to access your accounts.

Extra info on setting up your devices and applications. 
http://windows.microsoft.com/en-us/windows/app-passwords-two-step-verification



Seems pretty easy… Just a few clicks to enable my two-factor authentication. 

Note: You have to follow the steps in the link in the last picture to enable easy access to your account via your phone.

Please do comment below and provide me with your feedback in case you decide to go ahead with enabling two-factor authentication. Next post, Google/Gmail Two-factor authentication!!!!


Feb 17, 2013

Want to click? Think again…




How many times have you received an email like the one above? Or an email from your friendly FedEx informing you that your parcel was not delivered… What about an email from Facebook or LinkedIn or Hotmail or any other site that asks you to press links to view messages or invitations?



It pays to think… Thinking before clicking would save you, your PC and most probably the company you work in a lot of hassle. Why you ask???… Simple.

Let me explain. The easiest way these days is to attack any PC via the human interaction element. Why should the hackers bother with spending hundreds of hours to find a possible opening when we the users present them with the easiest path?


Those hackers infect one or two sites with malware. Then they send mass (or targeted) emails like the ones mentioned above. One click without thinking and BAAAAM! You’re their prey. They’d have almost unstoppable access to your PC.



During the last month alone, such a technique was used to attack Twitter, FaceboDuring the last month alone, such a technique was used to
attack Twitter, Facebook, New York Times and Wall Street Journal.

To make things worse, there are major flaws in the software we use. Java had a major security flaw that was being used to exploit the companies mentioned above. Now, Adobe PDF reader has a major flaw. Hint… DO NOT OPEN THOSE PDFs in emails you receive, especially if you do not know the sender… (More on that issue can be found on http://www.zdnet.com/dont-open-that-pdf-theres-an-adobe-reader-zero-day-on-the-loose-7000011241/?s_cid=e539)



Finally, I would like to mention a new initiative by the Lebanese government who has endorsed the importance of internet safety. The new site, www.e-aman.com contains very important tips for "National Internet Safety Lebanon". Keep up the good work!

Total Pageviews

On Top List

Online Marketing
Add blog to our blog directory

gob