Thursday, June 16, 2011

Citi says 360,000 accounts hacked in May cyber attack

I had no sooner posted the previous blog when I saw this. Citigroup has some serious issues.

http://news.yahoo.com/s/nm/20110616/bs_nm/us_citigroup_hacking

Citigroup Left The Barn Door Open

A data breach at Citigroup may have compromised the personal information of more than 200,000 of the bank's credit card customers.

"During routine monitoring, we recently discovered unauthorized access to Citi’s Account Online," a company spokesman, Sean Kevelighan, explained in a statement on June 9.

Citi is no stranger to embarrassing disclosures of its customers' personal information. In February, it mailed about 600,000 of its customers' tax documents with their social security numbers printed on the outside of the envelope.

Last week I blogged about the “80 / 20” rule and how 80 percent of cyber intrusions and exploits can be prevented by "best practices".

The recent Citigroup attack seems to fall into the 80% category. News reports have said that Citigroup was exploited by "sophisticated" attacks. But security experts say that at least by today's standards, most of these attacks were far from advanced, except perhaps in their simplicity.

To begin with, statistically speaking, very few attacks pass the sophistication threshold. According to the 2011 Data Breach Investigations Report from Verizon, "only 8% of data breaches represented a 'high' attack difficulty," said Rob Rachwald, director of security strategy for Imperva, in a blog post.

Citigroup seems to have fallen victim to basic URL hacking – which is far from sophisticated.

Attackers "leapfrogged between the accounts of different Citi customers by inserting various account numbers into a string of text located in the browser's address bar," an unnamed security expert told The New York Times.

In other words, attackers took advantage of the fact that the Citi Card website failed to hide actual account numbers in the URL string. "It would have been hard to prepare for this type of vulnerability," said the security expert, who's familiar with the investigation.

In fact, it would have been easy to prepare for this type of vulnerability, known as "Insecure Direct Object References," which is so widespread that it ranks as the fourth most dangerous vulnerability on the Open Web Application Security Project top 10 list of Web application vulnerabilities.

Perhaps Citigroup's developers and automated code-scanning tools failed to spot the use of real account-related information in URL strings. But that's where penetration testing is supposed to fill in, and it's obvious from numerous recent breaches, involving Citigroup, Sony, and others that "pen testing" wasn't employed.

"When you look at how the breaches are occurring, it's like penetration testing 101. Ethical hackers are taught to test computer security on the good guy side," Alex Cox, principal research analyst at NetWitness, said in an interview last month.

"So, a lot of times people aren't applying the idea of, let's hire someone to break in and see if he can do something realistically. But if you've got a good pen-test team, that's a really good way to understand where your vulnerabilities are," he said.

Or to reverse Cox's advice, by not conducting penetration testing on their Web applications, businesses won't know where all of their vulnerabilities are, and thus won't be prepared to repel attackers. Which, like recent attacks, doesn't seem very sophisticated.

In summary, an analogy seems appropriate.

Tom: How’s your health?

Henry: Fine.

Tom: How do you know?

Henry: Because I feel fine and I don’t think I have any issues.

Tom: Have you been to a doctor recently for a checkup?

Henry: No.

Tom: Then how can you really be sure how healthy you are?

Well the same goes for Citigroup. They might have thought their online system was healthy, but without having made the effort to get it checked they really didn’t know – and in this case they weren’t very healthy.

Tuesday, June 14, 2011

APT - Advanced Persistent Threat - What is it?

APT - Advanced Persistent Threat - What is it?

The term was actually coined by the US Air Force in 2006 as a way to communicate with counterparts in the unclassified public world. If the USAF wanted to talk about a certain intrusion or attack with uncleared personnel, they could not use the classified threat name, so they choose APT as a common moniker that could apply to all such situations.

What is important when referring to an APT is that is references a specific threat from specific sources. It is not meant as a catchall description for some vague or unknown cyber-attack.

Heretofore, APT was most frequently applied to specific groups operating in the Asia-Pacific region, but there is considerable discussion as to whether adversaries in Eastern Europe operating using the same tools, tactics, and procedures as traditional APT, should also have the APT label.

In the commercial sector, an IT security professional usually does not make the distinction or really care where the threat is originating from, rather that he or she will take the same defensive actions regardless of the source or nationality of the adversary.

APT entered the common lexicon in early 2010 when Google announced its intellectual property had been the victim of a targeted attack originating from China. Although Google was far from the only victim, the company’s visibility and its high profile public disclosure put a new face on these types of attacks and the lengths attackers would go to gain access to proprietary corporate and military information.

Insofar as a definition, APT means:

Advanced means the adversary can operate in the full spectrum of computer intrusion. They can use the most pedestrian publicly available exploit against a well-known vulnerability, or they can elevate their game to research new vulnerabilities and develop custom exploits, depending on the target’s posture.

Persistent means the adversary is formally tasked to accomplish a mission. They are not opportunistic intruders. Like an intelligence unit, they receive directives and work to satisfy their masters. Persistent does not necessarily mean they need to constantly execute malicious code on victim computers. Rather, they maintain the level of interaction needed to execute their objectives.

Threat means the adversary is not a piece of mindless code. The opposition is a threat because it is organized, funded and motivated. Some people speak of multiple “groups” consisting of dedicated “crews” with various missions.

In brief, APT is an adversary who conducts offensive digital operations (called computer network operations or perhaps computer network exploitation) to support various state-related objectives.

APT is characterized by devotion to maintaining some degree of control of a target’s computer infrastructure, acting persistently to preserve or regain control and access. Unclassified briefings by counter-intelligence and military analysts use the term “aggressive” to emphasize the degree to which APT pursues these objectives against a variety of government, military, and private targets.

IS APT NEW?

When the Google attack entered the public arena, many people wondered if APT was something new. The answer to this question depends on one’s perspective, plus understanding some history. As mentioned earlier, the term APT is approximately 4 years old.

Richard Bejtlich, founder of TaoSecurity and director of incident response for General Electric describes APT activity in terms of offender, defender, means, motive, and opportunity.

He breaks APT targets into four phases:

1) late 1990s — military victims;

2) 2000-2004 — non-military government victims;

3) 2005-2009 — defense industrial base;

4) 2009-present — intellectual property-rich targets and software companies.

He points out that analysts currently assess APT activities as supporting four main goals.

· Political objectives such as maintaining internal stability.

· Economic objectives that rely on stealing intellectual property from victims. Such IP can be cloned and sold, studied and underbid in competitive dealings, or fused with local research to produce new products and services more cheaply than the victims.

· Technical objectives that further their ability to accomplish their mission. These include gaining access to source code for further exploit development, or learning how defenses work in order to better evade or disrupt them. Most worryingly is the thought that intruders could make changes to improve their position and weaken the victim.

· Military objectives that include identifying weaknesses that allow inferior military forces to defeat superior military forces.

WHAT SHOULD DEFENDERS DO TO COUNTER APT?

The most effective counter-APT weapon is a trained and knowledgeable information security analyst. Tools are always helpful, but the best advice is to educate business leaders about the threat so that they support organizational security programs conducted by competent and informed staff.

On a technical level, building visibility in to one’s organization will provide the situational awareness to have a chance to discover and hopefully frustrate APT activities.

Monday, June 13, 2011

The Disconnect Between Security & The Business

Saw an interesting item this morning and decided to re-tweet it as well as include it in my blog. (http://jadedsecurity.net/2011/06/07/the-disconnect-between-security-the-business/) Yes, there is a disconnect between security and “the business” and I believe it is the primary driver for so many successful exploitations. What many businesses don’t yet fully grasp is that security is a business mandate, not an IT function. Security needs to be driven from the top down and not delegated to the “guys down in IT”. As the article says, “The new buzzword of the times is GRC (Governance, Risk, Compliance)…..”. Certainly, IT has an important role, but IT is not the driver. Governance, risk and compliance starts at the top. If businesses really want to reduce information security risk they need to have processes and procedures in place that are driven by governance mandates where risk is assessed and ultimately mitigated by compliance with the processes and procedures. It’s not inexpensive, but it is surely less expensive that a breach and all the associated costs.

Friday, June 10, 2011

The Old 80 - 20 Rule

Attended ISSA-Baltimore chapter's second InfoSec Summit yesterday in Laurel Md. The keynote speaker was Dr. Ron Ross Ron Ross, computer scientist at National Institute of Standards and Technology (NIST). He had an interesting observation that 80 percent of cyber intrusions and exploits can be prevented by "best practices". Best practices might be defined differently depending on who you ask, but at the end of the day it’s the simple stuff - firewalls, good authentication, adherence to processes and policies, patch management, training, etc. Would your business pass the 80 – 20 test? In my experience most don’t, but I can show you how.

Tuesday, February 16, 2010

Chip and PIN: The technology is no

longer secure

Date: February 16th, 2010

Author: Michael Kassner



Chip and PIN transaction systems were thought to be secure. The only way to bypass the technology required a stolen card and knowing the PIN. That is no longer the case.


I first learned about Chip and PIN Security when writing a piece about counterfeit credit/debit cards. The point of the article was to shed light on how cybercriminals steal financial information and ultimately our money. I presented a technology called MagnePrint as one possible solution. Several TechRepublic members mentioned another technology that they thought was better called chip and PIN.

Chip and PIN Security

Chip and PIN systems were created to prevent skimming. Replacing the magnetic strip with an embedded microchip supposedly eliminates that possibility. In fact, many consider chip and PIN security a strong two-factor authentication.

Several members also mentioned that chip and PIN technology is prevalent in Europe and why cybercriminals are more focused on stealing credit/debit card information in the United States. This article goes far enough to say that adoption of Chip and PIN technology in the United States is inevitable for that very reason.

How it works

Customers do not see much difference when using a chipped card. It works like this:

1. At the checkout counter, a customer places his or her card in a Pin Entry Device (PED).

2. The PED accesses the chip on the card.

3. The card is then verified by the financial institution providing the card.

4. Once the card is proven authentic, the customer enters the PIN.

5. The PED verifies that the entered PIN matches the PIN cached on the chip.

6. If it is a match, the transaction goes through.

So, what’s the problem? Quite simply, it’s the cost. The article mentions that:

“The card issuers cite the enormous cost of rolling out chip and PIN technology, estimated to be around $5.5 billion, and they rest safe in the knowledge that it is the merchants in the U.S., and not the card issuers, who are responsible for the financial costs of credit card fraud.”

Not quite perfect

I have been studying chip and PIN technology for awhile now. It obviously makes it more difficult to obtain a person’s financial information. But, it’s not perfect. My first inkling of this came from watching the BBC news report Chip and PIN ‘security risk’.

Basically, the PEN hardware is compromised, allowing the criminal to obtain the card’s financial information and PIN digitally. For whatever reason, the transaction traffic to and from the PEN was not encrypted. Still the PEN has to be physically altered for this attack to work, making it a risky endeavor.

New flaw

The same University of Cambridge research team that uncovered the PEN hardware flaw recently discovered a new problem with chip and PIN technology. Professor Ross Anderson, a member of the team points out the seriousness:

“We think this is one of the biggest flaws that we’ve uncovered - that has ever been uncovered - against payment systems, and I’ve been in this business for 25 years.”

Susan Watts of the BBC, presented a documentary (http://www.bbc.co.uk/blogs/newsnight/susanwatts/2010/02/new_flaws_in_chip_and_pin_syst.html) about the research called New flaws in chip and PIN systems revealed. Unbelievably, a transaction can be completed without knowing the PIN. To explain, let’s step through the attack process:

1. The attacker obtains a stolen credit/debit card.

2. Next, the stolen card is inserted into the attacker’s card reader which is connected to a notebook.

a. Also connected to the notebook, is some hardware that interfaces with a fake card via a cable.

3. The criminal starts the payment process by inserting the fake card into the store’s PEN.

4. The PEN accesses the chip to verify the card’s authenticity.

5. Next, the PEN asks the attacker for the PIN via the display screen.

6. The criminal enters any 4 numbers, it doesn’t matter.

7. The software/hardware developed by the researchers then somehow fools the PEN into believing the correct PIN was entered and a signature authorized the purchase.

If you get a chance, watch the video in the documentary. It shows a simulated transaction and the Cambridge researchers explain how they accomplished the attack. The following illustration and picture depicts the equipment used to implement the attack (courtesy of the University of Cambridge research team): http://www.bbc.co.uk/blogs/newsnight/susanwatts/2010/02/new_flaws_in_chip_and_pin_syst.html

If I understand correctly, the PIN exchange only involves the card’s chip and the PEN. That information was leveraged by the researchers to create a Man-in-the-Middle attack. The research team’s paper Chip and PIN is broken (pdf) mentions:

“A man-in-the-middle device, which can intercept and modify the communications between card and terminal (PEN), can trick the terminal into believing that PIN verification succeeded without actually sending the PIN to the card.

A dummy PIN must be entered, but the attack allows anyone to be accepted. The card will then believe that the terminal did not support PIN verification, and has either skipped cardholder verification or used a signature instead. Because the dummy PIN is never sent to the card, the PIN retry counter is not altered.”

What’s next

One of the reasons I have been following chip and PIN technology, is to see if and when it will be adopted in the United States. I asked Professor Anderson about this and his response was:


“I’ll be talking about EMV (chip and PIN standard) at the Federal Reserve Bank’s conference in New York on April 1st. I’ll be arguing the Fed should insist that the EMV specification be
fixed before they allow its introduction in the United States.

The vendors are keen enough to sell the technology in the USA, where the card payment market is worth billions. If the result is a much improved EMV 5.0, then it will presumably come here to Europe in due course.”

One other area of concern that I found interesting is the transition credit/debit card. If the chip and PIN system gains traction, not every merchant will have the correct PED immediately. According to the researcher team’s report, this opens another attack avenue.

If the chip and PIN card includes a magnetic strip as a fall back method for making purchases, the card can still be cloned and the information may remain valid when that person obtains the official chip and PIN card.

Final thoughts

I am not sure where I read this, but it has a lot of “street cred”:

“The whole purpose behind security is to make it more difficult so thieves will go somewhere else as well as eliminating amateurs. Still no matter what you develop, there’s going to be someone who’s going to find a way around it.”

Michael Kassner has been involved with with IT for over 30 years. Currently a systems administrator for an international corporation and security consultant with MKassner Net. Read his profile or Twitter at MKassnerNet.