What the average guy might call a con is known in the security world as social engineering. Social engineering is the criminal art of scamming a person into doing something or divulging sensitive information. These days, there are thousands of ways for con artists to pull off their tricks (See: Social Engineering: Eight Common Tactics). Here we look at some of the most common lines these people are using to fool their victims.
Social Networking Scams
"I'm traveling in London and I've lost my wallet. Can you wire some money?"
Social networking sites have opened a whole new door for social engineering scams, according to Graham Cluley, senior technology consultant with U.K.-based security firm Sophos. One of the latest involves the criminal posing as a Facebook "friend." They send a message or IM on Facebook claiming to be stuck in a foreign city and they say they need money.
"The claim is often that they were robbed while traveling and the person asks the Facebook friend to wire money so everything can be fixed," said Cluley.
One can never be certain the person they are talking to on Facebook is actually the real person, he noted. Criminals are stealing passwords, hacking accounts and posing as friends for financial gain.
"If a person has chosen a bad password, or had it stolen through malware, it is easy for a con to wear that cloak of trustability," said Cluley. "Once you have access to a person's account, you can see who their spouse is, where they went on holiday the last time. It is easy to pretend to be someone you are not."
"Someone has a secret crush on you! Download this application to find who it is!"
Facebook has thousands of applications users can download. Superpoke is one example of a popular application many users download to enhance their Facebook experience. But many are not trustworthy, according to Cluley.
"It is impossible for Facebook to vet all of the applications people write," he said.
Sophos, which tracks cybercrime trends, is seeing Facebook applications that install adware, which cause pop-up ads to appear on a user's screen. The other danger, according to Cluley, is that installing many of these applications means you give a third-party access to your personal information on your profile.
"Even if they are legitimate, can you trust them to look after your data properly?" said Cluley. "A lot of these applications are really jokey. You don't really need those. People should consider carefully which ones they choose to accept."
"Did you see this video of you? Check out this link!"
Sophos is also seeing an increase in Spam on Twitter, the popular social network where users "Tweet" quick one line messages to others in their network (Read: 3 Ways a Twitter Hack Can Hurt You).
A spam campaign on Twitter in recent weeks involved a Tweet that said "Did you see this video of you?"
"If you think the link is from a friend, you are much more likely to click on it," said Cluley.
Unfortunately, users who clicked on the link ended up at a bogus site that only looked like the Twitter web site. Once there, unsuspecting Twitterers entered passwords, which then ended up in the hands of hackers.
Office Offenses
"This is Chris from tech services. I've been notified of an infection on your computer."
Before there were computers, email, web browsers and social network sites for communication, there was the phone. And although it may seem archaic now, it is still a handy way to pull off a social engineering scam, according to Chris Nickerson, founder of Lares, a Colorado-based security consultancy.
Nickerson said scammers often take advantage of a timely event to strike. The Downaup worm that is currently infecting many PCs is a good example (Read Downadup Worm Now Infects 1 in every 16 PCs). Nickerson's firm conducts what he calls 'Red Team Testing' for clients using techniques that involve social engineering to see where a company is vulnerable.
"I will call someone and say "I've been informed that you've been infected with this worm.' And then I walk them through a bunch of screens. They will see things like registry lines and start to get nervous with the technicality of it. Eventually, I say 'Look, why don't I fix this for you? Give me your password and I will deal with it and call you back when I am done.'"
The strategy plays on a person's fear and lack of comfort with tech, said Nickerson.
"If you can put someone in a position where they think they are in trouble, and then be the one to fix it, you automatically gain their trust."
"Hi, I'm from the rep from Cisco and I'm here to see Nancy."
Nickerson recently pulled off a successful social engineering exercise for a client by wearing a $4 Cisco shirt that he got at a thrift store (Read: Anatomy of a Hack).
Criminals will often take weeks and months getting to know a place before even coming in the door. Posing as a client or service technician is one of many possibilities. Knowing the right thing to say, who to ask for, and having confidence are often all it takes for an unauthorized person to gain access to a facility, according to Nickerson.
Well, cookies can't hurt either. Nickerson said he always brings cookies when he is trying to gain the trust of an office staff. In fact, a 2007 diamond heist at the ABN Amro Bank in Antwerp, Belgium involved an elderly man who offered the female staff chocolates and eventually gained their trust with regular visits while he pretended to be a successful businessman.
"It was just plain old chocolate," said Nickerson. "Sweets loosen everybody up."
Ultimately the bank lost 120,000 carats of diamonds because the man was able to gain enough trust to be given off-hours access to the bank's vault.
"Can you hold the door for me? I don't have my key/access card on me."
In the same exercise where Nickerson used his shirt to get into a building, he had a team member wait outside near the smoking area where employees often went for breaks. Assuming his team member was simply a fellow-office-smoking mate, employees let him in the back door with out question.
This kind of thing goes on all the time, according to Nickerson. The tactic is also known as tailgating. Many people just don't ask others to prove they have permission to be there. But even in places where badges or other proof is required to roam the halls, fakery is easy, he said.
"I usually use some high-end photography to print up badges to really look like I am supposed to be in that environment. But they often don't even get checked. I've even worn a badge that said right on it 'Kick me out' and I still was not questioned."
Phishing Lures
"You have not paid for the item you recently won on eBay. Please click here to pay."
"We see emails impersonating complaints from eBay for non-payment of winning bids," said Shira Rubinoff, founder of Green Armor Solutions, a security software firm in Hackensack, New Jersey. "Many people use eBay, and users often bid days before a purchase is complete. So, it's not unreasonable for a person to think that he or she has forgotten about a bid they made a week prior."
Rubinoff, who was once a phishing victim herself and was inspired to found Green Armor after the incident, said this kind of ploy plays to a person's concerns about negative impact on their eBay score.
"Since people spend years building eBay feedback score or "reputation," people react quickly to this type of email. But, of course, it leads to a phishing site."
Rubinoff recommends not clicking on any emails of this kind. Instead, if you are concerned about something like your eBay score, go to eBay directly by typing the url into the browser bar on your own.
"You've been let go. Click here to register for severance pay. "
With the economy in the state it is in now, people are afraid for their jobs and criminals are taking advantage of that fear, said Rubinoff. A common tactic includes sending an email to employees that looks like it is from the employer. The message appears to relay news that requires a quick response.
"It can be an email that appears to be from HR that says: 'You have been let go due to a layoff. If you wish to register for severance please register here,' and includes a malicious link."
No one wants to be the person that causes problems in this economy, so any email that appears to be from an employer will likely elicit a response, noted Rubinoff. Lares' Nickerson has also seen cons that use fake employer emails.
"It might say, 'In an effort to cut costs, we are sending W-2 forms electronically this year,'" said Nickerson.
source : PCWORLD
Hackers steal thousands of Wyndham credit card numbers
Posted by Unknown | 6:28 PM | Security | 0 comments »Hackers broke into a computer at Wyndham Hotels and Resorts last July and stole tens of thousands of customer credit card numbers, the hotel chain warns.
The break-in occurred at a property belonging to a Wyndham franchisee, but that computer was linked to other company systems. "That intrusion enabled a hacker to use the company server to search for customer information located at other franchised and managed property sites," the company said in a statement disclosing the breach.
The data was then uploaded to a Web site during July and August of 2008, Wyndham said. The company estimates that 41 Wyndham hotels and resorts were affected by the breach before it was discovered by the company's information security team in mid-September. The incident did not affect other Wyndham properties such as Days Inn, Ramada or Super 8.
Wyndham has not said how many guests were affected by the theft, but it may have affected as many as 21,000 customers in Florida according to that state's attorney general. Wyndham's representatives did not return calls seeking comment on the breach.
The criminals were able to get guest names, credit card numbers and expiration dates as well as data from the card's magnetic stripe, Wyndham said.
That magnetic stripe information, sometimes called a card verification value (CVV) code, is critical if the thieves want to make fake credit cards, according to Avivah Litan, an analyst with Gartner Research.
"That's the hot information," she said. "You can sell that information for much more on the black market." CVV codes were also taken in the high-profile Heartland Payment Systems and The TJX Companies credit card thefts.
When fraud is perpetrated using fake cards that include the CVV codes, the banks are responsible for the charges; when the fraudsters have only the card numbers and expiration dates -- the information used in online transactions for example -- then the retailer is responsible for the charges. "The banking industry is all up in arms whenever bank stripe data is stolen," Litan said.
After an eight-week investigation, Wyndham notified the U.S. Secret Service, which investigates financial crimes, as well as credit card companies. Customers were made aware of the breach in December. Last week, it posted more details on the incident to its Web site.
source : computerworld
Attackers are already exploiting a bug in Internet Explorer 7 that Microsoft Corp. patched just last week, security researchers warned today.
Although the attacks are currently in "very, very small numbers," they may be just the forerunner of a larger campaign, said Jamz Yaneza, threat research manager at Trend Micro Inc. "I see this as a proof-of-concept," said Yaneza, who noted that the exploit's payload is extremely straightforward and explained that there has been no attempt to mask it by, say, planting a root kit on the victimized PC at the same time.
"I wouldn't be surprised to see this [exploit] show up in one of those Chinese exploit kits," he added.
The new attack code, which Trend Micro dubbed "XML_Dloadr.a," arrives in a spam message as a malicious file masquerading as a Microsoft Word document. If the fake document is opened, the exploit hijacks PCs that have not been patched with the MS09-002 security update Microsoft issued last Tuesday as part of its eight-patch February batch of fixes.
That update, which plugged two holes in IE7, was rated "critical" by Microsoft at the time.
"We first saw this over the weekend," said Paul Ferguson, an advanced threat researcher at Trend Micro. "But we're not sure if it's just a targeted attack or they're staging for something larger. It's hard to tell at the moment."
It's not unusual for hackers to swing into action with a new exploit only days after Microsoft has patched a previously-unknown vulnerability. "They know it takes users a while to patch," Ferguson added. "Even months after Microsoft patched, the Conficker worm was still able to infect millions of PCs because of lousy patching. That's not lost on the bad guys."
The "Conficker" worm, also known as "Downadup," continues to compromise millions of machines daily, even though, as Ferguson noted, Microsoft patched the vulnerability exploited by the worm nearly four months ago.
Yaneza and Ferguson speculated that the current attacks are precursors to a much larger assault that will revive a campaign that tempted users with news about Tibet. Those attacks, which Trend Micro reported in January 2008, share some characteristics with the newest exploits, including malware disguised as Word documents. Yaneza also said that it appears as though the hacker's command-and-control server is based in China, lending more credence to their theory.
"This is the 50th anniversary of the Tibetan freedom movement," said Ferguson, who said it's likely that a large-scale attack based on this exploit would use that news as bait. In 1959, when the People's Republic of China took full control of Tibet, the Dali Lama fled to India, where he is the head of a Tibetan government-in-exile.
One security expert has called on Microsoft to sever the links between IE and Windows to better protect users from attack. According to Wolfgang Kandek, the chief technology officer at Qualys Inc., people plug IE holes no faster than other critical Microsoft vulnerabilities, something that might change if Microsoft split the browser from the operating system and increased the frequency of its IE patches.
source : www.computerworld.com
Research In Motion Ltd. has patched a piece of software for Windows PCs that could leave them vulnerable to attack when loading new applications onto BlackBerry devices.
The flaw lies in an ActiveX control used to load third-party applications onto BlackBerries connected to a PC via a USB cable. An ActiveX control is a small add-on program that works in a Web browser to facilitate the downloading of programs or security updates. However, the controls have been prone to vulnerabilities.
RIM said in a security advisory that a vulnerability is introduced to a PC when someone runs the BlackBerry Application Web Loader Version 1.0 ActiveX control with any version of Microsoft Corp.'s Internet Explorer browser. The advisory contains a link to the patch.
The vulnerability is an exploitable buffer overflow, which is a problem in memory that could allow an unauthorized program to run on systems. RIM didn't give details on how the flaw might be exploited.
However, the U.S. Computer Emergency Readiness Team (US-CERT) said an attacker could be able to execute arbitrary code with the system privileges of a user by getting the user to view a specially crafted HTML document. The vulnerability also could cause IE to crash, according to an advisory issued by US-CERT.
The flaw was given a score of 9.3 on the Common Vulnerability Scoring System, a tool used by vendors to evaluate the potential dangers of vulnerabilities. A CVSS score of 10 is the highest possible, and anything above a seven is considered to be highly dangerous.
RIM advised users to apply the new software patch. In Microsoft's latest security updates on Tuesday, the software vendor also released a "kill bit" for the affected ActiveX control to block it from running within IE.
source : Computerworld
Must-Have Security Fixes for IE7, Microsoft Servers
Posted by Unknown | 4:09 PM | Security | 0 comments »Today's monthly patch batch from Microsoft fixes a critical flaw in Internet Explorer 7 that could allow a malicious Web site to install malware on a vulnerable PC, along with a patch for the Visio diagramming software. And businesses that run a Microsoft Exchange or SQL server will want to apply essential fixes right away.
Microsoft's bulletin says attack code that targets the MS09-002 IE7 flaw "can be crafted easily," so be sure you get this one via Windows Update. The Internet Storm Center posts that there aren't yet any known attacks, but it affects both XP and Vista. But only IE7, interestingly, and not earlier versions of the browser.
You'll also find a fix for the Visio software which can allow an attacker to run any command if you open a hacked Visio file. The program is popular among network and server administrators who typically have far-reaching permissions on their networks, so I wouldn't be at all surprised to see a targeted attack come along that goes after this flaw. Get more info and the patch from the MS09-005 bulletin.
The other two fixes are for servers - Exchange and SQL server. There has been exploit code out there for the SQL server flaw since December, according to the ISC, so if you have a publicly accessible SQL server at your company (via a Web site) schedule an emergency fix to prevent a SQL injection or other attack. Get details at the MS09-004 page.
Do the same for your company Exchange server, which could be taken over by a specially crafted TNEF message sent to it by an attacker. No known attacks against this one just yet, according to the ISC, but don't wait for one to show up. This one's MS09-003.
Update: Regarding the MS09-004 SQL server vulnerability, Microsoft says that while the flaw can be targeted after a successful SQL injection attack, the MS09-004 flaw isn't itself a SQL injection vulnerability.
source : PCWORLD