Saturday, March 10, 2018

Mazda Hack

We need to learn, as an industry, from our mistakes. When these are identified, as part of the SDLC, the oversights should be addressed immediately, based on the criticality of the issue. InfoSec is no different. If there is a vulnerability noted, it should be remediated as soon as possible. This may take a bit of time to resolve and may need to be implemented in the next model year of a product or software release, depending on the circumstances. If the issue is noted and acknowledged by the company and is not resolved within a reasonable amount of time, there is a bigger, more systemic problem to be considered.

Mid-year 2017, there was a compromise published with the Mazda vehicles targeted. The PoC was titled the Bad Valet attack, which exploited the USB port as the attack vector. The targeted models began with the 2014 model year. The exploit worked by the user plugging in a malware-laden USB. The malware involved accessed the Linux OS in the infotainment system, and allowed for modifications. Per Mazda, this was patched.

Along comes 2018 and two new researchers, with a like attack. This also used the USB stick and requires 10 seconds for the USB to be inserted into the port. This malware collects data from the user's smartphone (e.g. text messages, call records, photos, contacts, GPS history, and emails), along with vehicle's geographic location. The malware exploits the autorun option that had been enabled with the infotainment system.

These attacks indicate there are issues with the development team tasked with the OS. The DevOps should incorporate InfoSec. The cost and time savings of SecDevOps have been documented and should be applied.

Dangers of Open WiFi

Recently there was a symposium focussed on connected and automated vehicles and infrastructure. One of the services provided by the venue was WiFi for the attendees. This was a welcomed and well-used service, which was beneficial. The issue, however, was with the WiFi itself. The WiFi that was available to be connected with was not secure in any fashion or form. This should have been red-flagged by the persons present prior to connecting. This should also have been noticeable for the persons as they connected to the WiFi, as it did not include any security. This was notable from the connection itself and the terms and conditions (T&C). As the presentations continued, there was one person located near the rear of the room with his laptop open. He happened to be running an app which monitors and captures packets. From simply looking across a table, anyone was able to watch the activity and note that he had been recording this for a longer amount of time than what was necessary. Others, not aware of him recording their activities, where logging into and reviewing their stock portfolio, work emails (possibly containing sensitive and confidential information), personal emails, and Facebook.

The issues associated with WiFi that had not been secured are well-known. This provides another example that may be used for training purposes for the general staff and others. Anyone in the audience that did not want to use their data plan for these activities unwittingly, as they logged in with their credentials, allowed an unauthorized third party access to their private information.

Friday, March 2, 2018

Universities are still targeted!

Universities have been targets for years. There have been Universities that have been compromised multiple times within a year. The attackers acknowledge there is a plethora of knowledge available to be exfiltrated and later sold or used in an unauthorized manner. This value may be rather substantial as this is sold on the dark web.
In late 2016, one of the latest targets was Michigan State University. The University was breached on November 13, 2016. The data exfiltrated included the social security number, MSU ID number, and employee’s date of birth. Fortunately, the database compromised did not contain other information, which would have made the situation must worse. This would have included passwords, or information regarding the persons financial, academic, contact, gift, or health data. The breach involved 449 records which were exfiltrated. These were only a portion of a database with over 400K records. The attacks sent MSU an email in an attempt to extract a payment from the University.
Post-Breach Actions
The University took this rather seriously, which is a good thing. Too often the affected party has a quick knee-jerk reaction. The University worked through the issue and did not pay the “requested” fee. After this decision, the University began to notify the affected parties, consisting of students, alumni, staff, and faculty. The University did post a website with the updated information regarding the compromise. The usual disclaimer was also published with this. The University, to their benefit, is providing two-years of identity theft protection, fraud recovery, and credit monitoring for free.
Lesson Learned
Data is pertinent and valuable to different persons, for different reasons. The attackers focused on this, naturally. The areas holding these need to be secured, and subnet the segments where possible. The dB with confidential data should be reviewed with regularity, along with the logs. This is used to limit exposure, from a time perspective. With checking the logs regularly, the authorized staff is able to note when a compromise would have occurred more sooner than later. An attacker with free reign for several months has a greater potential for creating issues, than someone who has been noticed within a week.

Resources
Mencarini, M. (2016, November 21). MSU: Names and social security numbers accessed in data breach. Retrieved from http://on.freep.com/2g6BwmR

Mencarini, M. (2016, November 22). Michigan state university confirms data breach of server containing 400,000 student, staff records. Retrieved from http://www.wxyz.com/news/michigan-state-university-confirming-data-breach-of-server-containing-400000-student-staff-records

Miller, F. (2016, November 18). Update: MSU spokesman says hack was an extortion attempt. Retrieved from http://www.wix.com/content/news/MSU-data-breach-exposes-records-of-current-and-former-students-employees-401946226.html

WXYZ. (2016, November 22). Michigan State University confirms data breach of server containing 400,000 student, staff records. Retrieved from http://www.wxyz.com/news/michigan-state-university-confirming-data-breach-of-server-containing-400000-student-staff-records


PDFs are still problematic

There are a number of documents used in the business setting. These include resumes in the Human Resources Department, budgets in Finance, and budget costs for projects. These documents have a commonality in their functionality. Years ago, and recently resurfacing, an attack was envisioned and implemented. Office documents include the function of macros, which by design were intended to assist the user. These began to be included to complete malicious acts by third parties. These were exceptionally useful for the attacks to the point where the macro functionality was turned off by default. As time passed, this attack passed out of vogue, as it became ineffective, but started to be used again as this function was used more frequently.
Another form of a document likewise used throughout the business is the PDF. This commonly is used to form a document from another form, e.g. a Word document, or other documents are scanned as a PDF. This is used without hesitation as these are seen in virtually every single office. Although seemingly mundane, this well-used type of document is still weaponized and used against targets. This has been used extensively due to the ease of use of engineering the malware. In addition, the users are receiving these regularly, which has assisted in the acceptance and usage without applying a sense of security to receive the source of this (e.g. which person was sending the email containing the PDF).
The users should, through various training opportunities, learn to still be vigilant, even with PDFs. The users should still monitor who the emails are from.

Monday, February 12, 2018

Paying the ransom v. back-ups

    Over the last three years, hospitals and medical offices have been increasingly targeted by attackers. This trend will continue this year and well beyond. Hancock Health, a regional hospital located in Indiana, red-flagged suspicious activities indicative of an attack on January 1 of this year.
    The end manifestation of the attack was the employees being locked out of their systems and received a welcoming ransomware. This may not appear to be that debilitating, however when the extent of the encryption was noted, the issue was significant. The target was great than 1400 files. The file extensions were modified to add “.imsorry” at the end of the file. This rather daunting message was met with the hospital paying the ransom to secure the decrypt key. In the environment, this is not the norm. There are a number of significant issues with paying the ransom, including the attacker not providing the decrypt key, leaving behind a bit of special malware to be used later, other access points, and many other reasons not to pay.
    The hospital indicated no evidence of their patient information being released or sold. The curious aspect to this was hospital paid $55k to the attackers for the ransom, while they had viable back-ups. This is the anomaly, as it is mostly advised not to pay this. The rationale was the process to restore the back-ups would have cost more than the ransom. This calculation does not seem as if this took into consideration all the germane factors.
    The successful attack was not due to a phishing campaign, but through the hospital’s remote access portal, using a third-party vendor’s credentials. The ransomware applied was SamSam or Samas.
    This provides a lesson for other operators. This could have been avoided or mitigated with training and alert users. There are a number of programs available for training the users, which should be done throughout the year.

Thursday, February 8, 2018

Attackers-2; Indiana Hospitals-0


            The healthcare industry has been and continues to be targeted by the attackers in their attempts to compromise systems, exfiltrate data and information, and collect fees from ransomware attacks. A handful of the recent attacks have been phishing oriented, due partially to their previous successes. Hospitals present a great source of sale-able data for the attackers. This includes, but is not limited to, the patient’s medical records with various data points that may be divided and sold separately or bundled into a packet for each patient. This includes the social security numbers, insurance information, home address, phone numbers, the patient’s point of contact, and other information.
            Recently Hancock Health had the opportunity to pay $55k arising from a successful ransomware attack. The attack vector here was a phishing attack. On the same day Hancock Health experienced their issue, Adams Memorial Hospital likewise was hit with ransomware. The other attack was successful due to an employee noticing something was not quite right with her system on December 11, 2017. She contacted the help desk and system Admins regarding the issue. Upon further examination, the files read “Sorry” and the network went blank. The ransomware tool used was believed to be a subset of the “Im Sorry” ransomware variant. This worked via appending files with “.imsorry” as they are encrypted. Post-encryption, a text file is placed on the system stating the instructions for paying the ransom.
            Due to this, the physicians were not able to access their patient’s history files or appointment schedules. The scope of the attack was relatively limited with only 60-80 patients affected. As of January 19th, Adams Memorial Health had not stated if the ransom had been paid.
            This provides a valuable lesson for the Admins and the InfoSec department. The training to avoid such issues is needed and should be continued. This training would assist the staff in recognizing not only phishing emails, but also what to monitor for with other staff emails in the case these would have been compromised.



And you thought the Experian Compromise was Problematic

            Healthcare continues to bear the brunt of the attempted attacks. Over the last few years, the healthcare industry has been targeted repeatedly. This is due primarily to the data and information being held being marketable for a longer period of time than other forms of data and information. This coupled with lax security certainly is not helpful. For instance, with financial information, e.g. credit card numbers, the useful life is much shorter than other forms. Once the patient is aware of an issue arising from checking their accounts, a third party service or other form is contacted, the person simply has to call their credit card company, the present credit card number is voided by the credit card company, and a new card is issued to the user. The stolen credit card is no longer valid.
            With medical records, there is a different case. These have data that are useful for the attackers over a much longer period of time. Dependent on the record and the health care agency, the file’s composition may differ. These generally have the social security number, addresses, billing data, and other relevant, marketable data.
            The Health South-East Regional Health Authority, located in Norway, recently had the opportunity to experience an attack. The entity manages Norway’s hospitals located in its southeast region. Their system was compromised, which led to attackers to exfiltrate their client’s personal information and medical records. In the US, we are unfortunately becoming numb to this as there have been many of these over the last two years.
            Two factors stand out with this incident. The records exfiltrated counted at approximately 2.9M. This is over half of Norway’s population of 5.2M. This makes the breach relatively massive. In addition, the entity’s InfoSec staff did not notice any issues. The healthcare entity received a notification from HelseCERT regarding activity red-flagged as abnormal. Recently there had not been evidence of any patient issues arising from this compromise.
            The management does not quite appreciate though the long-term effects of this. The data is marketable for extended periods, which is inclusive of a few months. The attackers who compromised the systems don’t have to sell this immediately or use it for their gain within this time period.