SANS NewsBites is a semiweekly high-level executive summary of the most important news articles that have been published on computer security during the last week. Each news item is very briefly summarized and includes a reference on the web for detailed information, if possible.
Spend five minutes per week to keep up with the high-level perspective of all the latest security news. New issues are delivered free every Tuesday and Friday.
Volume XI - Issue #90
November 13, 2009
Cyber warfare came out of the shadows this morning in a remarkable story from National Journal's national security reporter, Shane Harris. (The first story in Top of the News).
Also this morning the newest version of the Consensus Audit Guidelines (20 Critical Controls) was released by CSIS and also posted at SANS. The new version contains actual tests auditors and inspectors general can use to test the *effectiveness* of each of the controls.
At the same site you'll find a list of tools that have been user-vetted for automating many of the controls.
The second story in this issue provides provocative new data on why 40% of government agencies and many large companies have begun using the 20 critical controls for their security compliance testing. The breakthrough enabling this change was the published proof that the 20 controls are a perfect, risk-based subset of the NIST 800-53 Priority One controls, and that they measure security effectiveness. Focusing on the 20 controls fully meets the FISMA requirement of risk-based testing within the NIST 800-53 framework.
TOP OF THE NEWSCyber War Expose
Fixing Federal Cybersecurity: C&A Reports Cost $1,400 Per Page And Are Out Of Date When Signed
For One-Third of US Government Agencies, Security Incidents Are a Daily Occurrence
THE REST OF THE WEEK'S NEWSResearchers Describe Weakness in Government Wiretap Technology
UK Considering Raising Maximum Data Breach Fine
Indian Outsourcer Arrested for Selling British Patients' Medical Files
Modified Xbox Consoles Banned From Xbox Live
Apple Issues Safari Update
Eight Indicted in Massive, Coordinated ATM Fraud
Microsoft Issues Six Security Bulletins
Windows Kernel Flaw Likely to be Exploited Soon
iPhone Data Stealing Exploit Released
Bank Fraud Linked to Stolen Employee Data
Microsoft Investigating Reports of Zero-Day SMB Flaw in Windows 7 and Windows Server 2008 R2
************************* Sponsored By Q1 Labs *************************
*** FREE WEBINAR November 17 - Utility Companies: Improve Your Network Security Through Log, Threat and Compliance Management ***
Numerous government agencies have stepped up regulations (like NERC) to significantly improve the overall security of the infrastructure that supports the delivery of energy in North America and Europe.
Learn how to meet compliance requirements and substantially reduce the risk of network-based threats and cyber-terrorism.
10 AM ET Session
OR 2 PM ET Session
-- SANS Vancouver, November 14-19
-- SANS London, UK, November 28-December 6
16 courses, bonus evening sessions: Hex Factor, Forensics Mini Summit and more
-- SANS CDI, Washington DC, December 11-18
-- SANS Security East 2010, New Orleans, January 10-18, 2010
19 courses, bonus evening presentations
- -- SANS AppSec 2010, San Francisco, January 29-February 5, 2010
- -- SANS Phoenix, February 14 -February 20, 2010
- -- SANS 2010, Orlando, March 6 - March 15, 2010
Looking for training in your own community?
Save on On-Demand training (30 full courses)
- See samples at https://www.sans.org/ondemand/
Plus New Delhi, Tokyo and Geneva all in the next 30 days.
For a list of all upcoming events, on-line and live: http://www.sans.org
TOP OF THE NEWS
Cyber War Expose (November 13, 2009)The covers are off the cyber warfare story. Shane Harris provides data about where and how cyber warfare has and is being used. He also has a fascinating discussion of how Mike McConnell employed potential financial cyber attacks as a game changer in military cybersecurity.
Fixing Federal Cybersecurity: C&A Reports Cost $1,400 Per Page And Are Out Of Date When Signed (November 12, 2009)
The US State Department cracked a vexing cybersecurity problem through continuous monitoring and a focus on the 20 critical controls (the most important defenses based on actual attack data compiled by NSA and other agencies). Result: measurable, major improvement of security while lowering the cost. Justifying the transformation: State had paid for 95,000 pages of certification & accreditation and follow-up reports at a cost of $1,400 per page, totaling $130 million over six years, and much of the data was outdated by the time it is printed.
[Editor's Note (Paller): This is the cyber equivalent of the 1983 expose of the $605 toilet seat. Shifting some of the $1.3 billion per C&A cycle to continuous automated monitoring is a great way for the federal government to lead by example and make huge improvements security while saving hundreds of millions of dollars. ]
For One-Third of US Government Agencies, Security Incidents Are a Daily Occurrence (November 10 & 11, 2009)A CDW-Government survey of 300 US government IT professionals found that 44 percent of agencies noted an increase in the number of security incidents over last year. Thirty-one percent of respondents said their agencies experienced at least one cyber security incident every day. The top areas of concern reported by respondents were malware, inappropriate employee activity or network use, managing access for approved remote users, and data encryption.
************************ Sponsored Links: ***************************
1) Be sure to REGISTER NOW for the upcoming webcast: Cloud Security 101: Web Application Security Trends & Why It Should Be Top Priority Now!
2) What open source tools are the best-kept secrets? Find out - the Incident Detection Summit December 9-10.
THE REST OF THE WEEK'S NEWS
Researchers Describe Weakness in Government Wiretap Technology (November 11 & 12, 2009)Researchers at the University of Pennsylvania say they have discovered a vulnerability in the technology the government uses to conduct wiretaps. The surveillance communication is transmitted between telecommunications companies and government agencies over a 64-Kbps data channel. People who think they are being monitored could effectively launch a denial-of-service (DoS) attack by sending a glut of text messages or VoIP calls, which could overwhelm the system. The researchers discovered the vulnerability by examining ANSI Standard J-STD-025, which "defines how switches should transmit wiretapped information to authorities."
UK Considering Raising Maximum Data Breach Fine (November 12, 2009)The UK Ministry of Justice is considering raising the maximum penalty for violations of the Data Protection Act that result in serious data breaches to GBP 500,000 (US $830,000). The Information Commissioner's Office (ICO) presently has the authority to impose a maximum fine of GBP 5,000 (US $8,300) for serious Data Protection Act violations. The possible significant increase in the maximum penalty is seen as a deterrent to lax security provisions, as is the fact that proceedings following a breach would be conducted publicly according to a recently added clause to the law. The Ministry of Justice is also looking at jail sentences for malicious breaches and pending legislation would allow the ICO to conduct data protection inspections.
Indian Outsourcer Arrested for Selling British Patients' Medical Files (November 10 & 12, 2009)Police in India have arrested the chief of an outsourcing company for allegedly selling British patients' medical records. Vikas Dhairyashil Bansode and his accomplices claimed to have obtained the data from IT companies in India that were hired to computerize medical records. According to the UK's Data Protection Act, it is illegal to send this sort of information outside the country unless its security can be guaranteed. The compromised information includes addresses, dates of birth and details of medical conditions. The police began to investigate Bansode and his accomplices following a documentary that aired in October in which the filmmakers posed as individuals who wanted to buy medical information so they could market health-related products pertinent to the individuals' situations.
[Editor's Note (Schultz): If outsourcing to India has in many cases turned out to cause serious security problems, think of the security problems that cloud computing does and will cause. ]
Modified Xbox Consoles Banned From Xbox Live (November 11 & 12, 2009)In an attempt to combat piracy, Microsoft is permanently banning modified Xbox consoles from accessing Xbox Live. The ban also applies to gamers who have played games downloaded in violation of copyright laws. The ban will affect between 600,000 and one million players. Users can recover their online profiles if they purchase another console. The plan raises concerns because it is the console rather than the player that is banned, so the people who purchase the devices second hand could find themselves unable to access Xbox live.
Apple Issues Safari Update (November 11 & 12, 2009)Apple has released Safari 4.0.4 for both Mac and Windows. The updated browser addresses seven security flaws; the vulnerabilities could be exploited to allow arbitrary code execution and disclosure of information and to cause unexpected application termination. The most serious of the vulnerabilities affects only Windows versions of the browser. One of the vulnerabilities fixed in the Windows version of Safari was patched for most Mac versions in September.
[Editor's Note (Schultz): The updated browser addresses seven security flaws; the vulnerabilities could be exploited to allow arbitrary code execution, disclosure of information and to cause unexpected application termination. ]
Eight Indicted in Massive, Coordinated ATM Fraud (November 10 & 11, 2009)A US federal grand jury in Atlanta, Georgia has indicted eight men in connection with the RBS WorldPay security breach. The men allegedly used a team of cashiers to steal more than US $9.5 million from ATMs in just a few hours. They allegedly broke into the RBS WorldPay network last November and stole information including account numbers for prepaid payroll cards and reverse engineered the associated PINs. They then allegedly raised the limits on the cards. Cashiers in 280 cities around the world withdrew the money from 2,100 ATMs in less than 12 hours. Those accomplices allegedly were allowed to keep 30 to 50 percent of the money they withdrew.
[Editor's Note (Honan): Kudos to all the law enforcement agencies involved in this operation. ]
Microsoft Issues Six Security Bulletins (November 10 & 11, 2009)On Tuesday, November 10, Microsoft released six security bulletins to address a total of 15 security flaws. Microsoft is recommending that users apply one of the fixes, MS09-065, immediately. It addresses three flaws in Windows kernel-mode drivers, one of which has been rated critical. It can be exploited simply by manipulating users into viewing infected web pages. Two of the remaining five bulletins also have maximum severity ratings of critical. The flaws affect Microsoft Windows and Microsoft Office.
Windows Kernel Flaw Likely to be Exploited Soon (November 11, 2009)Researchers are in agreement that in the next few weeks, cyber criminals are likely to exploit the Windows kernel vulnerability for which Microsoft released a fix earlier this week. The problem lies in the way the kernel parses Embedded Open Type fonts and can be exploited in drive-by attacks, meaning users do not have to take any action to become infected other than visiting a compromised or maliciously-crafted website.
iPhone Data Stealing Exploit Released (November 11, 2009)The same vulnerability that was used to spread a relatively harmless worm is now being exploited to allow attackers to steal data from jailbroken iPhones. An estimated six to eight percent of iPhones are jailbroken, meaning they have been modified to allow applications and other code to run on the devices even if that code has not been signed by Apple. The attackers can access music, photos, email, text messages and other information. Both attacks gain access to iPhones through default SSH passwords; users who choose to jailbreak their iPhones are advised to change the default SSH password if they have installed that utility.
[Editor's Note (Northcutt): This is just the beginning. It is the classic features versus security story. The iPhone rocks; it has the features people want; it has a far better interface than any other phone; so it will keep selling and keep ending up as a business PDA. Perhaps it won't be the standard, but rather the device allowed as an exception. Try to hold the line, the Blackberry is a far safer device, keep it as the standard. When exceptions are granted, ask those business folks not to put the entire company directory on their phones. It is just a matter of time until security applications start to become available for this platform, but we need to try to minimize data loss until then. ]
Bank Fraud Linked to Stolen Employee Data (November 10, 2009)A data security breach of a server at the Vancouver (Washington) School District exposed employee information, including Social Security numbers (SSNs) and bank account information of employees who use direct payroll deposit. The district superintendent is urging all employees to let their financial institutions know about the breach so they can be monitored for suspicious activity and to contact credit reporting agencies to place fraud alerts on their accounts. The district notified all area banks about the breach as soon as they learned of it. Several employees say that their banks alerted them to suspicious account activity following the breach.
Microsoft Investigating Reports of Zero-Day SMB Flaw in Windows 7 and Windows Server 2008 R2 (November 11 & 12, 2009)Microsoft is investigating reports of a zero-day flaw in Windows 7 and Windows Server 2008 Release 2 that could be exploited to crash vulnerable computers. The flaw is in Windows Server Message Block and could be exploited to "trigger" an infinite loop on the SMB protocol rendering the entire system unresponsive. There is no evidence that the flaw could be exploited to compromise a system.
The Editorial Board of SANS NewsBites
Eugene Schultz, Ph.D., CISM, CISSP is CTO of Emagined Security and the author/co-author of books on Unix security, Internet security, Windows NT/2000 security, incident response, and intrusion detection and prevention. He was also the co-founder and original project manager of the Department of Energy's Computer Incident Advisory Capability (CIAC).
John Pescatore is Vice President at Gartner Inc.; he has worked in computer and network security since 1978.
Stephen Northcutt founded the GIAC certification and currently serves as President of the SANS Technology Institute, a post graduate level IT Security College, www.sans.edu.
Dr. Johannes Ullrich is Chief Technology Officer of the Internet Storm Center and Dean of the Faculty of the graduate school at the SANS Technology Institute.
Ed Skoudis is co-founder of Inguardians, a security research and consulting firm, and author and lead instructor of the SANS Hacker Exploits and Incident Handling course.
Rohit Dhamankar is the Director of Security Research at TippingPoint, where he leads the Digital Vaccine and ThreatLinQ groups. His group develops protection filters to address vulnerabilities, viruses, worms, Trojans, P2P, spyware, and other applications for use in TippingPoint's Intrusion Prevention Systems.
Prof. Howard A. Schmidt is the President of the Information Security Forum (ISF) and author who has served as CSO for Microsoft and eBay and as Vice-Chair of the President's Critical Infrastructure Protection Board.
Tom Liston is a Senior Security Consultant and Malware Analyst for Inguardians, a handler for the SANS Institute's Internet Storm Center, and co-author of the book Counter Hack Reloaded.
Dr. Eric Cole is an instructor, author and fellow with The SANS Institute. He has written five books, including Insider Threat and he is a senior Lockheed Martin Fellow.
Ron Dick directed the National Infrastructure Protection Center (NIPC) at the FBI and is the incoming President of the InfraGard National Members Alliance - with 22,000 members.
Mason Brown is one of a very small number of people in the information security field who have held a top management position in a Fortune 50 company (Alcoa). He is leading SANS' global initiative to improve application security.
David Hoelzer is the director of research & principal examiner for Enclave Forensics and a senior fellow with the SANS Technology Institute.
Mark Weatherford, CISSP, CISM, is Chief Information Security Officer of the State of California.
Alan Paller is director of research at the SANS Institute.
Marcus J. Ranum built the first firewall for the White House and is widely recognized as a security products designer and industry innovator.
Clint Kreitner is the founding President and CEO of The Center for Internet Security.
Brian Honan is an independent security consultant based in Dublin, Ireland.
David Turley is SANS infrastructure manager and serves as production manager and final editor on SANS NewsBites.
Please feel free to share this with interested parties via email, but no posting is allowed on web sites. For a free subscription, (and for free posters) or to update a current subscription, visit http://portal.sans.org/