Showing posts with label cyberdefense. Show all posts
Showing posts with label cyberdefense. Show all posts

Wednesday, November 20, 2024

Data theft-It’s not just for medical facilities

 There’s been volumes written about data theft in medical facilities, methods, and effects. This is no

wonder given the mountain of data created daily from the patient care and operations. Another viable

target would be auto dealerships. This hold much the same data hospital would generally. When a

person purchases their vehicle, as a course of the process, they provide their name, address, data of

birth, SSN, financial information, and other data. The hospital or medical care facility collects much the

same, with additional data for the patient care.

In this case an automotive dealership was compromised. On or about May 27, 2023, the Jeff Wyler

Automotive Family an unauthorized party compromised their perimeter security and was able to access

the consumer information (e.g., name, date of birth, SSN, driver’s license or state ID #, medical

information, health insurance information, and financial information). This was detected on January 29,

2024.

The method of attack unfortunately was not detailed. Anytime this event occurs, there’s something to

learn and use to build up your defenses. This experience does highlight the need for regular

cybersecurity assessments. This, depending on the environment and budget, may consist of vulnerability

scans, per tests, and threat feeds for your equipment. This also includes working on the vulnerabilities to

remove these and secure your system.

SSH Tool Weaponized

 One of the more interesting facets of this industry is there’s always something new to learn. The

creativeness and inventive nature shine with the new tools introduced for attacks and subsequently to

improve defenses. One area that hasn’t seen many new tools created has been with SSH. This is widely

used and continue to be a primary security method.

The new security tool is SSH-Snake. This is an open-source tool. Originally released in January 2024, the

design was to work through a network using SSH private keys. This is done automatically. The program

through its work then creates a thorough network map and its dependencies. The result allows the

security staff to understand vulnerable points where an attacker could use SSH and private keys.

You can see the usefulness of this for the company. Like any tool, there are positive and negative uses.

The negative side of the coin here is the tool was weaponized. This was modified to self-modify and

replicate itself through the network. The upgraded tool has been coded to find locations where

credentials are generally kept and analyzes the shell history files.

As an additional aspect to circumvent security, the tool is fileless. While this is newer, it allows for an

increased level of difficulty in detecting the tool and allows it a greater level of flexibility. This is still a

tool to be used to improve your network security stance. The weaponized version should be on your

radar.

Saturday, March 9, 2024

EHR as a critical target

 

In the enterprise/traditional IT, there are the production networks. These must be up and operating at all costs. Without this in the business operations, not much is produced or sold. As a tool to defend against ransomware and other attacks, there are dedicated backups, policies, and procedures. In a perfect world, these would be checked periodically not only to verify they are present but also the backup data is viable when used.

In hospitals, there are EHRs (Electronic Health Records) used several times a day by the nursing staff for patient care. Among other data, these hold the patients’ prescriptions and dosage, which the nursing staff cannot get wrong. Liberty Hospital in MO recently had a cybersecurity issue with their HER. They were able to get this back up and running. This purely exemplifies the need for HER backups. Imagine you are the administrator for the hospital or rehabilitation center. You get the call at 4pm on Friday from IT. The staff member starts with “We have a problem.” Of the next few sentences, all you remember is “encrypted” and “ransomware”.

While taking time and resources to try the backup, this option is certainly better than finding out the backups are not viable after the attack begins. Wondering if the backups are viable in our present environment is not optimal. 



Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Capital Health Breached

 

No CISO wants to receive the urgent call from the SOC informing them of an issue. This may take the form of a request to make a missed vendor payment by month end or there’s a user that keeps on clicking on the internal phishing campaign emails. The conversation you don’t really want revolves around the defenses being breached. That is clear and immediate project.

Capital Health (NJ) had such an occurrence. LockBit 3.0 claims to have compromised the defenses and liberated over 10M files or over 7TB of confidential medical data. The estimated value of this was $250k. The group did have a bit of their conscious during the attack. They didn’t encrypt the data which quickly would have interfered with the patient care. It’s notable though LockBit 3.0 did not post evidence to document this. While this is the case, there were network outages near the end of December due to a cybersecurity incident. This is not a new event, as too many medical facilities have experienced this on some level.

There have been minimal details as to this which is the standard model. This does highlight the need for this industry to be hyper vigilant and maintain your info cybersecurity toolsets. Periodically when your contract is nearing renewal for the tools, scan the other vendors for their offerings and pricing. Running a PoC and going through the vendor vetting can take time, but it may be well worth it. 


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Wednesday, February 14, 2024

Cybersecurity Costs

 

I have consulted with a company recently. They were reviewing the ISO27001:2022 certification. This, depending on the circumstances, could be a heavy lift or not too bad. This is entirely dependent on the environment. After the initial review and recommendation, the first comment was the business didn’t have the budget for the tools, staffing or anything. This left me a bit confused, as the certification process is not inexpensive.

This reminded me of the budget process. The C-level and senior management don’t at times understand security’s role. They instead think like an accountant and try to arrive at an ROI (Return on Investment). This has the propensity to be very difficult. When you try to commoditize this, there are problems.

When I hear this, my thoughts run to how much would a network compromise cost with the additional ransomware thrown in for good measure, even with cybersecurity insurance? How much would it cost for your connected medical devices to be breached and malicious code put in the firmware, with three or four patients feeling the effects?

There are the direct costs, of course, but also the indirect cost of reputational risk. These are a few things to think through. 

Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) 


 charles.parker@mielcybersecurity.net 810-701-5511



Tuesday, June 29, 2021

Still(water) another medical facility breached

 

As of late, I have been tracking more closely the published breaches and their respective industries. The one industry that appears to be in the lead for breaches now are the medical facilities. Generally being in the lead is a good thing, but not in this instance. One of the latest incidences involved the Stillwater Medical Center. One June 13, 2021, they detected the unusual behavior and incident. This was not script kiddie testing out new software just purchased but affected a few systems. Naturally, as a hospital is attacked, the incident response team immediately took to action and began securing the issue. In addition, after the attack was controlled, they began in earnest to work on the forensic review with the help of a firm specializing in forensic work. Law enforcement was also notified. As this was an active attack, certain systems were placed on an off-line status until the immediate issue was resolved.

This reinforces the complete need for cybersecurity, adequate FTE, and budget. While an organization will not be able to defend against every single type of attack now or in the future, and adequate defense in depth is the best course of action.

Thursday, June 24, 2021

Here we go again; another ransomware pwnage

 

I remember the days of cameras, purchasing color film or if you wanted to be artsy, using the black & white film. There were several different manufacturers to choose from for the film. With time and technology, there has been a shift from the physical medium to digital. One firm still in the industry is FujiFilm. FujiFilm is probably the best known for its photography equipment. Curiously the company also manufactures a range of medical products. As a large firm, there is ample data gathered everyday from customer interactions, business operations, and other aspects of the business cycle. This provides for a substantial target.

It appears that FujiFilm was targeted and successfully attacked. This was evidenced by the company shutting down a portion of the network and disconnecting this from any external contact. It appears this was de to a ransomware attack.

This continues to be an issue across many industries. With the ease of use for ransomware tools and simply using encryption to accomplish the successful attack, this will likely continue and grow.

 

 

Wednesday, June 10, 2020

This doesn’t add up: Chartered Professional Accountants Canada Breached!

With most industries, there is a trade association or group. The focus with these is to bring together leaders and members to discuss issues, communicate messages to the membership and be a portal for the industry. Accounting is no different. In the US, we have the AICPA which functions to administer these tasks. This is accomplished is a timely, exceptionally professional manner. Canada is no different in that the accounting industry likewise has this for our northern friends. Another commonality is these are generally targets due to the data they hold for their clients. The Chartered Professional Accountants Canada (CPA Canada) recently found this out, as they were breached.

CPA Canada

Just as the name implies, the organization is involved with Canadian accountants, representing the over 210k members. The organization provides accounting and guidance for its membership. This service is vital for business, accounting firms, and the stock market.

 

Attack

 The organization was unfortunately the victim of a successful phishing attack. The organization on June 3, 2020 notified the affected parties of the breach. Curiously, the organization was aware of the attack on April 24th, meaning it took over a month to notify the persons. The organization will not be disclosing the methodology used in the attack. On a level, this is understandable. The organization may not want the details published as these may be used in other attacks as indications of their security posture. After the issue is corrected though, this could be used as a learning tool or use case for others.

 

Data

CPA Canada definitely held useful information for the attackers to focus on. This included the member's personal information. This included their contact details (names, addresses, email addresses, and employer name). The passwords and credit card numbers, fortunately, were encrypted. The list of persons was primarily composed of the CPA Magazine subscribers. This wasn’t just on the members, but also the stakeholders, totaling over 329k persons.  Granted the data involved was confidential. However, this could have been much worse if the other data was not encrypted, or if the attackers were able to pivot from this point and gain access elsewhere.

 

Post-Breach

The organization has notified its members and others whose data was affected, of the breach. The members and stakeholders were recommended to change their passwords. The organization is also working with cybersecurity personnel to verify the system is secure and exactly what data was copied from them. In addition, they naturally also contact the appropriate law enforcement, the Canadian Anti-Fraud Centre, and other privacy authorities.

 

One point from this to be used is phishing continues to and will be for the foreseeable future, an absolutely viable attack. This has proven to be successful and will not slow down. The organizations need to continue training for this with their employees. The system may be completely secure, however, all it takes is the right person in the right department to click the link, attachment, etc., and we are off to the races.

 

References

Solomon, H. (2020, June 4). Canadian accounting association website gets hacked. Retrieved from https://www.itworldcanada.com/article/canadian-accounting-association-website-gets-hacked/431712

 

Solomon, H. (2020, June 8). Canadian accounting association website gets hacked. Retrieved from https://business.financialpost.com/technology/tech-news/canadian-accounting-association-website-gets-hacked

 

The Canadian Press. (2020, June 4). Canadian accountants’ association suffers cyberattack; data of nearly 330k affected. Retrieved from https://globalnews.ca/news/7025862/cpa-canada-accountants-cyberattack/

 

The IJ Staff. (2020, June 4). CPA Canada hacked, subscriber information exposed. Retrieved from https://insurance-portal.ca/article/cpa-canada-hacked-subscriber-information-exposed/

 


Thursday, May 28, 2020

Spartans compromised: MSU breached


Michigan State University (MSU), located in East Lansing, Michigan, is one of the premier institutions in the Midwest. This is a 5,300-acre campus with 563 buildings, with nearly 20,000 cares throughout Michigan used for agricultural and natural resources research and education. In Fall 2019, there were 49,809 students. With such a large number of students, the amount of data generated by the students and administration staff is massive year after year. This data, including the confidential data from the students, provided a significant target for the attackers. This proved to draw these persons to the University’s servers and data.

Attack
Ransomware has been a nasty part of our environment from the last few years. This is a good attack tool due to its low operational overhead and potential large payoff. With this mode, it simply takes the right person in the right department to click on the malware or link. Unfortunately for MSU, the tool was used against the university successfully. The attackers were able to breach the network, access the targeted data, and exfiltrate this. The attackers have demanded a ransom to be paid within a week of the successful attack or they will publish the stolen files. If the university happens not to pay the ransom, the attackers are willing to leak the documents.

Data
The university believes, but is not certain, that the breach and subsequent intrusion was to one (1) isolated unit on the campus. While this is a good thing, the breach itself is still an issue. The files included student, e.g. passport scans, and other private, confidential data, along with university financial documents.

Attackers
The attackers apparently used Netwalker, sometimes referred to as Mailto, ransomware. The ransomware variant was coded to attack the enterprise, in comparison to individual user stations. With this ransomware variant, once the clock runs down to zero, the data and the decrypt key are automatically published.

Mitigation

This is a rather significant issue. There is a prominent university pwned, and their data is being held for ransom. After this was detected, the IT Department took offline the affected systems and servers. This was done to prevent further exposure. MSU’s IT Department notified law enforcement, including the MSU Police Department and Michigan State Police, of the successful attack and threats to begin the investigation.

The latest successful attack is yet another clear indication that we need more cybersecurity training that is relevant. Without this, these attacks will continue to be successful and cause an abundance of harm to the organization, staff, and other parties as part of the collateral damage.

Resources
Cimpanu, C. (2020, May 28). Michigan state university hit by ransomware gang. Retrieved from https://www.zdnet.com/article/michigan-state-university-hit-by-ransomware-gang/

Dissent. (2020, May 28). Michigan state hit by ransomware threatening leak of student and financial data. Retrieved from https://www.databreaches.net/michigan-state-hit-by-ransomware-threatening-leak-of-student-and-financial-data/

Freed, B. (2020, May 27). Michigan state hit by ransomware threatening leak of student and financial data. Retrieved from https://edscoop.com/michigan-state-hit-by-ransomware-threatening-leak-of-student-and-financial-data/

Guzman, W. (2020, May 28). Michigan state target of ransomware attack threatening to release university data. Retrieved from https://statenews.com/article/2020/05/michigan-state-target-of-ransomware-attack-threatening-to-release-university-data?ct=content_open&cv=cbox_latest

Marowski, S. (2020, May 28). Ransomware attack threatens to release stolen Michigan state university files. Retrieved from https://www.mlive.com/news/jackson/2020/05/ransomware-attack-threatens-to-release-stolen-michigan-state-university-files.html

Michigan State University. (n.d.). MSU facts. Retrieved from https://msu.edu/about/thisismsu/facts.php

Tuesday, May 26, 2020

Home Chef’s customer data for sale: Come and get it!



Home Chef, a US-based company, is a meal kit delivery service. If you don’t have time to go to the grocery store and am looking for healthy meals, you can contract with them for meal deliveries to your home. The ingredients show up in a box and you are ready to go! While not an overly complex process, this is still pertinent.

Data Breach
As part of the service, you would pay for the deliveries with your credit card. The company isn’t going to ship your food and hope you pay the bill. The organization does collect certain data from its clients to facilitate this, which is part of the standard operating procedure. Nearly all companies follow this model.  

In this case, there was a successful attack. The compromised customer information included the customer’s name, email address, phone number, and last four digits of the credit card numbers. This would be a much bigger issue; however, the Home Chef does not retain full credit card numbers. In addition, the encrypted passwords and certain account details (e.g. frequency of deliveries and mailing addresses) were also compromised.

Home Chef has not stated how many customers were affected. As a clue to the general number, the attackers responsible for this, Shiny Hunters, claim to be selling approximately 8M records. The price of this database was $2,500. Given the number of records and the data for each record, this is not that bad of a deal. To authenticate, Shiny Hunters also provided a sample.

The attack itself also is a bit of a mystery. The company is not stating this occurred, which is unfortunate. We could use this information as a learning tool. Curiously, Home Chef did not know this had occurred, which is a bit strange as the SIEM should have picked up a bit of unusual activity since, you know, a few records (8M) were compromised and exfiltrated. Home Chef learned of this after they discovered the records were being sold on the dark web. Oops. The InfoSec group probably should have picked up on this. It is also notable, in order to complete this compromise, there would need to be a bit of time involved. It is likely the attackers had access to the systems and data for an extended period as they completed their attack.

Mitigation
Naturally, when this occurs, there is a lot of activity very quickly. The company did state they were taking quick and aggressive actions to investigate the breach.

Follow-Up
Too frequently, companies are not overly aggressive in their timeline to contact law enforcement. Home Chef on the other hand handled this efficiently. And contacted them quickly. The company did email the affected customers, which was done quicker than other firms in like circumstances, which is a good thing. The company is also is recommending the customers change their passwords out of an abundance of caution. Remember, the passwords were encrypted, however, the company may have used weak encryption, which would be a problem.  If these were to be decrypted, there would be a big problem for the customers. This is a good idea also due to the potential for credential stuffing, or the attackers using your password to try access for other accounts. If the users did use the same password across several domains these also should be changed. The customers should also use MFA (multi-factor authentication) moving forward as an additional feature.

Resources
Abrams, L. (2020, May 20). Home chef announces data breach after hacker sells 8M user records. Retrieved from https://www.bleepingcomputer.com/news/security/home-chef-announces-data-breach-after-hacker-sells-8m-user-records/

GearBrain Editorial Team. (2020, May 21). Data breach weekly security report: Which company lost control of your information this week. Retrieved from https://www.gearbrain.com/data-breach-cybersecurity-latest-hacks-2633724298.html

Home Chef Help Center. (2020). Home chef data security incident. Retrieved from https://support.homechef.com/hc/en-us/sections/360008878052-Home-Chef-Data-Security-Incident

Mihalcik, C. (2020, May 20). Home chef confirms data breach after customer info reportedly sold on dark web. Retrieved from https://www.cnet.com/news/home-chef-confirms-data-breach-after-customer-info-reportedly-sold-on-dark-web/

S, G. (2020, May 21). Home chef hacked-Hackers selling 8M user records on a dark web marketplace. Retrieved from https://gbhackers.com/home-chef-hacked/

Whitney, L. (2020, May 21). How home chef’s sensitive data was compromised by a cyberattack. Retrieved from https://www.techrepublic.com/article/how-home-chefs-sensitive-customer-data-was-compromised-by-a-cyberattack/


Thursday, January 23, 2020

BaseCamp successful defense against credential stuffing

Many corporations use applications to track projects. These can be on-premises or in the cloud. These services tend to be very useful for the collaboration required for these projects. One such service is BaseCamp. While focused on helping with communication and collaboration, BaseCamp did experience an attack in early 2019.
Attack
It's not often that there is the opportunity to write about a successful defense. Either there is the breach/compromise, or the company breaks down and pays for new equipment or a ransom. In this case, the defense was successful. They defended the system against a massive credential stuffing attack. This occurred on January 30, 2019 @ 12:45p Central. The SOC was monitoring the systems and noticed a significant increase in login attempts. This continued as the attack focused on approximately 30k accounts. In an hour, there were more than 30k login attempts from a vast array of IP addresses.
Successful Defense Methods
The first step was to start to block the IPs associated with the attack. With this form of attack, depending solely on this was merely a folly. This acted only to start the process, not as a panacea. There would need to be a large number of people simply doing this activity for hours to have even an insignificant effect, given the attackers would just use new IPs. The second step was much more helpful. They enabled the CAPTCHA, which blocked further attacks. While this did work and was very useful in the defense, there were 124 users who did have their accounts breached. These were reset and the users were emailed.

Resources
Getlan, S. (2019, January 31). Basecamp successfully defends against credential stuffing attack. Retrieved from https://www.bleepingcomputer.com/news/security/basecamp-successfully-defends-against-credential-stuffing-attack/
Hashim, A. (2019, February 2). Basecamp endured a brute force attack. Retrieved from https://latesthackingnews.com/2019/02/02/basecamp-endured-a-brute-force-attack/ 
Newman, L.H. (2019, February 17). Hacker lexicon: What is credential stuffing? Retrieved from https://wired.com/story/what-is-credential-stuffing/
OWASP. (2019, February). Credential stuffing prevention cheat sheet. Retrieved from https:/github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Credential_Stuffing_Prevention_Cheat_Sheet.md

Toulas, B. (2019, February 1). Basecamp defends an hour-long credential stuffing attack. Retrieved from https://www.technadu.com/basecamp-credential-stuffing-attack/56537/

Tuesday, November 19, 2019

Tivit's Breach

There are IT firms across the globe on every continent. Even on Antarctica there is an IT function for their networks and other technical equipment. Brazil is no different. Tivit is a Brazilian IT services provider. In addition to this line of business, they also provide other business processes.
Attack
Any attack generally is focused on the target’s data or money. This instance was no different. The attack focused on the Tivit client’s data. There were nine Tivit employees who fell victim to a phishing email campaign. This exposed the client’s credentials online. The successful attack was confirmed by Tivit. For this to be so successful, all it took were the nine employees clicking on a link. The attack was able to gain access to data from 19 other companies. These included the kitchen appliance manufacturer Faber, Swiss insurance company Zurich, Brazilian financial organization Banco Original, software firm SAP, and many more. The attackers were successful enough so that they had gained access to Tivit’s database. Fortunately, the attack scope was limited only to the nine systems breached. The datacenters and client networks were not affected.
Detection
One would think, an IT service provider would have some form of a SIEM present and actively managed. The logs would simply be too huge for a human to make much sense of it. There should be a staff sufficiently supported so when there is an issue, it may be detected and resolved. This was not the case apparently. The breach was not detected by Tivit, but was by DefCON Lab. The signs included this affected various databases and servers in the cloud. DefCON Lab found nearly one thousand lines of code contained internal company routines and credentials of different large enterprise clients. The data appears to have internal process documents for the organization.
Remediation
Tivit was working through the issue. The organization also contracted with legal resources and IT support firm to ensure this did not happen again.
Comment
It is interesting that an IT company fell victim to a phishing attack. The number of victims was also notable. This issue continues to emphasize the need for employee training, through the year, even for IT companies.

Resources
Cyware. (2018, December 17). Massive data breach hits Brazilian IT firm tivit. Retrieved from https://cyware.com/news/massive-data-breach-hits-brazilian-it-firm-tivit-d47dc056

Mari, A. (2018, December 14). Brazilian IT firm tivit suffers data breach. Retrieved from https://www.zdnet.com/article/brazilian-it-firm-tivit-suffers-data-leak

Friday, October 18, 2019

Not all is lost! Great defenses count

Usually, the blogs detail a successful, in-depth attack. When possible, the attack vector is disclosed. There aren’t a tremendous number of success stories for various reasons. Seemingly most of the successful attacks use the same two or three attack vectors. These work most of the time for the attackers. 

Recently, an organization allowed a set of articles to elaborate on their trials and tribulations in the cyberland we call home. Having a company come forward to share their experiences in pleasant in comparison to most of the articles. 
Student Loans Company (SLC) 
The SLC is a government agency providing student loans for UK university and college students. This is financially a large organization with $117B in outstanding student loans per their 2017/2018 annual report. SLC manages data on its 8.1M registered clients. The data generally is financial in nature and is considered sensitive and confidential. 
Targetted 
Across the board, cybersecurity attacks are on the rise. The attackers figured out how to efficiently generate revenue from these endeavors and have been expanding their reach. The attackers are not going to waste time attacking an organization without a good reason. Their time is treated as a commodity. There is also too much potential liability with an attack. In this example, the sensitive information is ripe to be exfiltrated and sold on the dark web. The 8.1M records would bring a significant amount for the attackers. 
Attacks
In 2018, SLC was attacked 965,639 times. To put this in perspective, that would be on average 2,646 attacks every single day through the year, including weekends. These included malware attacks, DoS (denial-of-service), malicious calls, and other cyberattacks. Of all the blocked attempts throughout the year, there was one successful attack. Granted, based on where this occurred, the story could be fine or very bad. If this were to be in the finance or accounting office, there could be rather significant issues immediately. 

In this case, the issue was cryptocurrency focussed. Within the last five years, there has been much attention paid to this. People have been using crypto miners hoping to mine enough to purchase more equipment or at least make a decent return on their ROI for the equipment purchased. SLC was, unfortunately, a victim of this. Someone placed cryptocurrency mining malware on their system. Particularly, they used the Monero crypto jacking virus. The company’s website, slc.co.uk, hosted the virus. The visitors to the website became infected with this if they happened to still have the vulnerability open on their system, which would have been exploited. 
Robust
Although there was the crypto mining incident, the company continues with its mission of being aware of the network at all times and vigilant. Cybersecurity continues to be a top priority for the SLC. The focus continues to be protecting the cybersecurity for the confidential data. 

It’s easy to note this. However, in this case, the proof is present. All of the attacks through the years were unsuccessful, except for the one Monero crypto mining incident. This also was not entirely their responsibility. The attack occurred due to their third party plug-in allowing the malware onto the website. 
Lessons Learned 
The company quantified the attacks over the year, and these were rather substantial. The organization seems to be taking its cybersecurity seriously. A proper cybersecurity regiment takes time and expense to implement and maintain, however it is worth it in the short and long term. 

Resources
Ashford, W. (2019, February 4). Massive uptick in cyber attacks targeting student loans company. Retrieved from https://www.computerweeky.com/news/252456975 

Fadilpasic, S. (2019, February 4). UK student loans company hit by a million cyberattacks last year. Retrieved from https://www.itproportal.com/news/uk-student-loans-company-hit-by-a-million-cyberattacks-last-year/  

IT Pro. (2019, February). Student loans company hit by a million cyber attacks last year. Retrieved from https://www.itpro.co.uk/security/32902/student-loans-company-hit-by-a-million-cyber-attacks-last-year 

Muncaster, P. (2019, February). Student loans company hit by one million cyber-attacks. Retrieved from https://www.infosecurity-magazine.com/news/student-laons-comany-hit-one/ 

Ray, T. (2019, February 4). Student loans company hit by one million cyber attacks last year. Retrieved from https://www.informationsecuritybuzz.com/study-research/student-loans-company-hit/ 

Sowells, J. (2019, February 10). Student loans company hit by one million cyber attacks in 2018. Retrieved from https://hackercombat.com/student-loans-company-hit-by-one-million-cyber-attacks-in-2018/  

Tuesday, October 1, 2019

Bridport pwned!


Sir John Colfox Academy is a secondary school in Bridport, Dorset in the UK. The school has 828 students, aged between 11 and 18.
Attack
On a fateful work day, much like any other, a staff member received an email. This was one of the hundreds of emails received on a weekly basis. This however claimed to be a colleague at another Dorset school. Not thinking a malicious person would have sent this, the staff member opened the email and clicked on the content on February 28, 2019. While this may have seem innocent enough, the email actually appears to have been sent from China and forwarded from a server in Germany.
The click opened the door for the systems infection. The network had an issue. The malware was reported as ransomware and, as expected, immediately began to encrypt the files. The attackers, as with the next step of the ransomware playbook, demanded money to be paid to them for the decrypt key.  The school consulted with a police expert regarding the substantial issue. After a review, it was noted the attack did not likely exfiltrate any school data, and staff, student and parent data were not on the system that was breached. The research into this indicated the attack may have been part of a much larger international operation.
Data
In particular, for this case, Year 11 students submitted their coursework. This coursework was saved on the school’s network. Due to the issue, the coursework in the subject was lost. While the description is short, the devastation is significant. The hope is the student’s had this backed-up somewhere.
Mitigation
The school is working with a particular exam board to resolve the issue. They are also working with the Dorset Police cybercrime unit. Although there was a demand for funds, no payment was made. This is generally the policy to take due to the secondary potential issues with just making the payment. The school had to notify the parents and sent a letter explaining the issue.
Discussion
Targets are generally attacked to compromise their systems to gain access to data for exfiltration or to extort funds from them. In the early days, these may have been more of an exercise, however, the attackers have operationalized the model. Ransomware has proven itself to be a completely popular, viable, and successful attack tool. Over the last four years, this has been very profitable for the attackers.
Lessons Learned
Ransomware is used so often, it is becoming redundant. The frequency is mostly due to the simplicity of the attack, the financial awards, and this tends to shut down operations until the fee is paid (not advised) or the issue is remediated through installing back-ups, and a thorough review to ensure nothing was left behind by the attackers they could use later for re-entry.
There needs to be continued training for the staff. This removed a significant portion of the opportunity for an issue. If the staff know what the usual forms of the attack are, these are less likely to be clicked on, and fewer systems would be infected. There also needs to be back-ups, which are regularly checked to ensure they are viable.

Resources
Hussain, D. (2019, March 14). Secondary school is being held to ransom after a ‘chinese cyber attack’ caused the loss of year 11 student’s GCSE coursework Retrieved from https://www.dailymail.co.uk/news/article-6808845/Secondary-school-held-ransom-cyber-attack-caused-loss-students-GCSE-coursework.html

Sjouwerman, S. (2019, March 14). GSCE coursework lost in ransomware attack on UK bridport school. Retrieved from https://blog.knowbe4.com/gcse-coursework-lost-in-cyber-attack-on-uk-bridport-school

Speck, D. (2019, March 15). GCSE coursework lost in ransomware attack. Retrieved from https://www.tes.com/news/gcse-coursework-lost-ransomware-attack

Wakefield, J. (2019, March 13). GCSE coursework lost in cyber attack in bridport school. Retrieved from https://www.bbc.com/news/uk-england-dorset-47551331

Friday, September 13, 2019

Yet another AWS issue! Capital One breached


Capital One-Yet Another Breach
Charles Parker, II
#
There is a saying that we are our own worst enemy. While we may have the best intentions, at times we may create our own issues which act to our own detriment. This has been notable with a single-use case. The focal point has been with AWS and misconfigured servers. This has created so many issues for the data owners and managers. The latest victim is Capital One due to its misconfigured AWS. This certainly won’t be the last incident through the industry.
Breach
To note this was massive would be an understatement. This is one of the biggest data breaches involving a financial services company. There were 106M persons involved. The affected persons were not only in the US, however, were also located in Canada. The breach was open for an extended period of time, from March 19 through July 17, 2018.
Method
The focal point for the attack was the cloud servers rented from AWS. There was an issue with the cloud configuration. The attack was exceptionally successful due to a misconfigured WedApp firewall. The attackers used a special command to extract the files in the Capital One AWS. Oddly, on June 16, 2019, the attacker posted on Twitter exactly how it was done. This was a very odd event. Generally, if you are going to gain unauthorized entry, you don’t want everyone to know exactly who you are. In this case, the attacker did just this.
Data
The data was related to credit card applications filed between 2005 and early 2019. This is a rather large set of time to exfiltrate data for. The attacker accessed credit applications, social security numbers (approximately 40k in the US and 1M Canada social insurance numbers), bank account numbers (approximately 80k), names, addresses, dates of birth, and financial information (e.g. self-reported credit scores). Fortunately, no credit card account numbers or logins were exposed in the breach. Altogether, the total amount of data was approximately 30GB. Somehow, the attacker was able to exfiltrate this data over months, without anyone or an app examining the login or data access for an extended period.
Perpetrator
The FBI has arrested a person in this case. The speedy arrest was greatly due to the attacker letting everyone know who they are, and not trying to hide anything. The attacker previously worked as an Amazon Web services (AWS) engineer. The attacker’s name of record is Paige A. Thompson. Given her lack of intuitiveness, she is certainly a nominee for the Darwin Award. She bragged about the breach and crime on GitHub and social media. She tried to share the data online and not on the DarkWeb. To top off the award nomination, she used her full first, middle, and last name. She also stored the data in a GitHub account for the user “Netcrave”. The GitHub site also happened to have Paige’s resume (oops). She also used the alias “erratic”.

The criminal complaint was filed in the Western District of Washington. The hearing was on August 1, 2019. To further support the allegation with yet more evidence, the FBI executed a search warrant and seized electronic storage devices. The storage devices contained a copy of the data.
Mitigation
The AWS configuration has been corrected. They stated it was not likely the data was used fraudulently. It is very easy to state this, but exceptionally difficult to guaranty. They did promise to provide 12 months of credit monitoring for affected parties. They also are recommending for the affected parties to watch for phishing emails.

Resources
Corcoran, J. (2019, July 30). Former AWS engineer arrested as capital one admits massive data breach. Retrieved from https://threatpost.com/aws-arrest-data-breach-capital-one/146758/

Krebs, B. (2019, July 19). Capital one data theft impacts 106M people. Retrieved from https://krebsonsecurity.com/2019/07/capital-one-data-theft-impacts-106m-people/

McLean, R. (2019, July 30). A hacker gained access to 100 million capital one credit card applications and accounts. Retrieved from https://www.cnn.com/2019/07/29/business/capital-one-data-breach/index.html

U.S. Attorney’s Office. (2019, July 29). Seattle tech worker arrested for data theft involving large financial services company. Retrieved from https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arrested-data-theft-involving-large-financial-services-company

DirtySoc-Vulnerability does not sound like fun


Ubuntu and other Linux distributions are used worldwide. These offer many functions and attributes the other primary options don’t. These also happen to be open source. While beloved, these still may add aggravation and headaches when installing or attempting other tasks. While there has not been a multitude of attacks against this, as with the Windows monumental franchise, there was recently added one more-DirtySock.
DirtySock Vulnerability (CVE-2019-7304)
The researcher (Chris Moberly) published the proof-of-concept (PoC) code for this exploit. The research discovered the issue near the end of January 2019. As a responsible party, Moberly did work with Canonical to fix the issue.
Operates
Snapd are applications which “contain” the files, libraries, and programs required for an application to process and work. The vulnerability in the code does not allow the attacker to compromise the system. What it, however, does allow is the attacker greater access once the attacker finds and gains access to an unpatched system. This flaw is in the local privileges allows or this significant privilege escalation. In summary, this allows attackers to create root-level user accounts, when unauthorized to do so, which is a very bad option for the administrators. The vulnerability lies with the snapd daemon. The issue is a default with the recent Ubuntu version. The Snapd daemon manages the “snaps” beginning in 2014. This allows the user to download apps and install them in the .snap file format. The vulnerability allows access to a local REST API server. This allows the attackers to overwrite the UID variable and access any API function. This server interacts with the snap package during the installation process. The code allows the attacker to work-around the access control restrictions used by the API server. To authenticate this, the researcher provided two exploits as examples, which may be used for vulnerability.
Mediation
Ubuntu is open source, however, in certain instances, there is a license required. The licensing business, or parent company, is Canonical. They have issued a patch for the issue. Canonical continues to show their focus on updates to the OS. This was addressed in Snapd version 2.37.1. They also released security updates for Ubuntu Linux OS.
Resources
Abrams, L. (2019, February 13). Canonical snapd vulnerability gives root access in linux. Retrieved from https://bleepingcomputer.com/news/security/canonical-snapd-vulnerability-gives-root-access-in-linux

PenTest Tools. (2019, February 14). Snapd flaw lets attackers gain root access on linux systems. Retrieved from https://pentesttools.net/snapd-flaw-lets-attackers-gain-root-access-on-linux-systems/

Sowells, J. (2019, February 13). Attackers gain root access on linux system via dirty sock vulnerability. Retrieved from https://hackercombat.com/attackers-gain-root-access-on-linux-systems-via-dirty-sock-vulnerability/