OnDemand Includes 4 Months Access to Course Content - Special Offers Available Now!

Newsletters: NewsBites

Subscribe to SANS Newsletters

Join the SANS Community to receive the latest curated cyber security news, vulnerabilities and mitigations, training opportunities, and our webcast schedule.

SANS NewsBites
@Risk: Security Alert
OUCH! Security Awareness
Case Leads DFIR Digest
Industrial Control Systems
Industrials & Infrastructure

SANS NewsBites is a semiweekly high-level executive summary of the most important news articles that have been published on computer security during the last week. Each news item is very briefly summarized and includes a reference on the web for detailed information, if possible.

Spend five minutes per week to keep up with the high-level perspective of all the latest security news. New issues are delivered free every Tuesday and Friday.

Volume XVI - Issue #14

February 18, 2014


Health and Human Services IG to Examine Networked Medical Device Security
Mobile Apps Don't Detect Phony SSL Certificates
Thieves Use USB Sticks to Rob ATMs


Security Update Planned for Duo Security WordPress Two-Factor Authentication Plugin
Flaw in Asus Routers is Being Exploited to Access Connected Drives
South Korean Financial Regulators Impose Penalties on Credit Card Companies After Data Breach
Kickstarter User Data Compromised
TheMoon Malware Targets Linksys Routers
VFW Website Used in Watering-Hole Attack
Forbes User Data Compromised
Tesco.com Customer Data Compromised



*********************** Sponsored By Symantec ****************************
Webcast: Recent Retail Breaches in the News - What Can You Learn? March 4 10:00 AM Pacific. At what points can an attack happen? What are the best practices for securing your devices? How can you protect your servers and endpoints? Gain insights from Symantec's Security Response Team on how targeted attacks are being perpetrated and how a properly configured endpoint can block even the most determined attackers.

- --SANS Scottsdale 2014 Scottsdale, AZ February 17-22, 2014 6 courses. Bonus evening presentations include Offensive Digital Forensics; and Cloud IR and Forensics.

- --SANS Cyber Guardian 2014 Baltimore, MD March 3-8, 2014 7 courses. Bonus evening presentations include Continuous Ownage: Why You Need Continuous Monitoring; Code Injection; and How the West was Pwned.

- -- ICS Summit Orlando Lake Buena Vista, FL March 12-18, 2014 Come join us at the ICS/SCADA Security Orlando Summit where we will take a deep look at embedded system attack surfaces, discover what you can do to improve their security, and take away new tools that you can put to use right away! Summit led by Mike Assante - ex-CSO of NERC, plus 7 courses.

- -- SANS Northern Virginia Reston, VA March 17-22, 2014 11 courses. Bonus evening presentations include Windows Exploratory Surgery with Process Hacker; Continuous Ownage: Why You Need Continuous Monitoring; and Real-World Risk - What Incident Responders Can Leverage from IT Operations.

- -- SANS 2014 Orlando, FL April 5-14, 2014 42 courses. Bonus evening presentations include Effective Phishing that Employees Like; and The Law of Offensive Countermeasures. Active Defense, or Whatever You Wanna Call It.

- --SANS Brussels 2014 Brussels, Belgium February 17-22, 2014 4 courses.

- --SANS Secure Singapore 2014 Singapore, Singapore March 10-26, 2014 7 courses. Bonus evening presentations includes Incident Response and Forensics in the Cloud.
- --Can't travel? SANS offers LIVE online instruction.
Day (www.sans.org/simulcast) and Evening courses (www.sans.org/vlive) available!

- --Multi-week Live SANS training
Contact mentor@sans.org

- --Looking for training in your own community?

- --Save on On-Demand training (30 full courses) - See samples at

Plus Canberra, Munich, Austin, and Malaysia all in the next 90 days.

For a list of all upcoming events, on-line and live: http://www.sans.org



Health and Human Services IG to Examine Networked Medical Device Security (February 10, 2014)

The US Department of Health and Human Services (HHS) Office of Inspector General (OIG) plans to take a close look at the security of certain medical devices. The review will be a part of a broader look at security issues in healthcare as laid out in the Fiscal Year 2014 HHS OIG Work Plan. The OIG wants to find out if hospitals have adequate security controls in place to safeguard patient information on networked medical devices, such as dialysis machines and medication dispensing systems. The OIG also plans to examine the security of the Affordable Care Act website and the security and privacy posture of organizations participating in the HITECH electronic health records program.
FY 2014 HHS OIG Work Plan:
[Editor's Note (Assante): The explanation by officials of what is at stake dances around the most material issue. The loss of patient information is given as the consequence to avoid, this is of course a concern for patients, but the integrity of the information at its point of generation (a device) or processing by a health care specialist is paramount. I have personally relied upon the information-intensive healthcare system for life preserving treatment. Even with high integrity data there were near-miss mistakes in treatments. The loss of integrity of medical-device-generated data, in any kind of scale, would add to existing fears and further chip away at the confidence we place in our medical institutions.
(Pescatore): This would be a good area for the HHS IG auditors to use the Critical Security Controls as way to focus their efforts at these important, but very broad, efforts. In particular, a rapid investigation of just the ability of hospitals to even know how many medical devices are on their networks (Critical Security Control 1) would point out an enormous shortcoming. It would be nice to see some focus, with some rapid action on foundational issues - rather than yet another yearlong effort with a phonebook-sized report of deficiencies followed by a year of magazine-sized response memos. ]

Mobile Apps Don't Detect Phony SSL Certificates (February 14, 2014)

Phony SSL certificates currently being used pose a significant risk to people conducting online banking on smartphones. There appear to be dozens of the fake certificates allowing attackers possessing them to conduct man-in-the-middle attacks to steal data from users who believe they have legitimate connections to banks, shopping sites, and social networks. The certificates are not signed by trusted authorities, so major browsers will detect them, but users conducting banking and other transactions through apps and other non-browser software could be vulnerable.

[Editor's Note (Pescatore): Way too many apps are getting published without working certification validation, often driven by using components like Amazon and PayPal merchant SDKs and many shopping cart objects that didn't validate. The Apple App Store and Google Play ought to put more focus on validating app and server side SSL hygiene before allowing such apps to be published.
(Ullrich): The problem isn't as much that these fake SSL certificates exist, but that mobile applications are fooled by them.
(Murray): One would hope that an app from one's bank would be able to establish a trusted connection to the bank. ]

Thieves Use USB Sticks to Rob ATMs (February 13, 2014)

An organized group of criminals used USB sticks to empty four ATMs of their cash. The thieves managed to open the machines to plug in the USB sticks, which contained malware that allowed the attackers to take control of the machines. Money mules then withdrew the cash. So far, just one person - a money mule - has been arrested. What makes this attack different from the majority of ATM thefts is that funds are stolen from the bank itself, not from individual accounts. The attacks occurred somewhere outside the US.

[Editor's Note (Henry): As organizations continue to increase security in certain areas, adversaries will constantly seek out other attack vectors. While this occurred outside the United States, domestic institutions seem equally vulnerable to this technique and should take additional precautions to prevent physical access to their equipment.
(Murray): At one time ATMs were hardened devices, on bank premises, using proprietary purpose-built software, proprietary protocols and networks, operated and serviced by banks. Today ATMs are appliances, often on merchant premises, using commodity software running on Windows, over public protocols and networks, and operated and serviced by third parties. Moreover, dedicated ATM cards have been replaced by multi-use "check" (debit) and credit cards. The increase in attack surface, vulnerability, and successful attacks is dramatic but, perhaps, not surprising or disproportionate. ]

************************** Sponsored Links: ******************************
1) Live from New York! SANS presents: The SANS Financial Cybersecurity Trends and Challenges briefing. Join John Pescatore, Tony Sager and Alan Paller for this important event for the Financial Community. Set in the heart of the NY Financial District, this FREE breakfast briefing provides critical information on upcoming security trends, an end-user security panel on how your colleagues are dealing with threats, and information from sponsors on the future direction of their solutions. Join us! http://www.sans.org/info/151470

2) Webcast: The Critical Security Controls and the StealthWatch System. Thursday, February 20 at 1:00 PM EST featuring John Pescatore, SANS and Charles Herring, Sr. Systems Engineer, Lancope. http://www.sans.org/info/152112

3) Webcast - Cybersecuring DOD ICS Systems.Tuesday, March 4, 1:00pm EDT with Michael Chipley, PhD PMP LEED AP BD +C GICSP. http://www.sans.org/info/152117


Security Update Planned for Duo Security WordPress Two-Factor Authentication Plugin (February 14 & 18, 2014)

Duo Security plans to release an update for its WordPress two-factor authentication plugin to address a vulnerability that could be used to bypass the security it is meant to provide. The problem exists in multisite deployments where the plugin is enabled on a site-by-site basis. The issue affects Duo WordPress plugin versions 1.8.1 and earlier.


Flaw in Asus Routers is Being Exploited to Access Connected Drives (February 17, 2014)

A vulnerability in Asus routers could be exploited to access data stored on devices connected directly to the router through the USB port on the back. The flaw was disclosed in June 2013; at that time, Asus said it "was not an issue." Devices could be accessed even when users do not deliberately enable services to make hard drive contents available over the Internet. The Asus vulnerability has been exploited thus far by someone who placed text file warnings about the situation on the vulnerable drives. The Asus attack together with the Linksys worm suggests that attackers are starting to turn their attention to routers.


[Editor's Note (Ullrich): The last couple of weeks have been bad for multiple types of routers/devices connected to public networks. Mass exploitation of Linksys, Synology, AVM's Fritzbox, and ASUS Routers, just to name the few that come to mind. Consumer level devices without the ability to receive automatic patching should probably not have the ability to be administered remotely. ]

South Korean Financial Regulators Impose Penalties on Credit Card Companies After Data Breach (February 16 & 17, 2014)

Three South Korean credit card companies have been fined and barred from issuing cards for three months after a Korea Credit Bureau temporary employee stole card details of at least 20 million people over a 14-month period and sold the information to telemarketers. The South Korean Financial Supervisory Commission said that KB Kookmin Bank, NH Nonghyup Card, and Lotte Card "neglected their legal duties of preventing any leakage of customer information." Each of the companies has each been fined six million won (US $5,660) and will not be permitted to issue new cards until May 16, 2014.

[Editor's Note (Henry): It's not clear if there was obvious negligence on the part of any of the companies here, but imposing serious sanctions should be a deterrence to irresponsible behavior. The inability to issue new cards for a three month period will have a significant economic impact on each of these companies, and likely be the impetus for wide-scale review of security protocols and policies.
(Honan): It is great to see a financial regulator step up to the plate with regards to credit card breaches. I am willing to bet that companies in South Korea that process credit cards are paying more attention to credit card security as a result of these penalties than any PCI DSS assessment. ]

Kickstarter User Data Compromised (February 15, 16, & 17, 2014)

Crowd-funding site Kickstarter says that thieves stole user data. Kickstarter says that credit card data were not compromised, but usernames, email addresses, encrypted passwords and other data were accessed. Older Kickstarter passwords are encrypted with SHA-1, while newer passwords are encrypted with bcrypt.



TheMoon Malware Targets Linksys Routers (February 14 & 17, 2014)

A worm that has been dubbed TheMoon has been infecting certain Linksys routers. Now a proof-of-concept exploit for the vulnerability that worm exploits has been made public, as have technical details about the vulnerability itself.



[Editor's Not (Ullrich): We still don't know a lot about this worm. Just how it spreads. So far, we gained a bit more insight on its command and control (C&C) channel; but aside from that, the purpose of the worm isn't clear. ]

VFW Website Used in Watering-Hole Attack (February 14, 2014)

Attackers compromised the US Veterans of Foreign Wars (VFW) website to exploit a zero-day vulnerability in Internet Explorer 10 (IE10) on the computers of site visitors. The attackers used JavaScript to add an IFRAME to the site's HTML code so that the malware would be loaded in the background, requiring no action from users.



[Editor's Note (Ullrich): Yet another Microsoft Internet Explorer 0-day that can be avoided by installing Microsoft's free EMET tool. ]

Forbes User Data Compromised (February 14 & 17, 2014)

Vandals attacked the Forbes website, posting phony stories and stealing user email addresses and passwords. Forbes is urging users to change their passwords, even though the company says the stolen passwords were encrypted. The passwords are, in fact, salted and hashed. The attack affects anyone who has registered with Forbes.com. The company has alerted law enforcement.


[Editor's Note (Northcutt): Without fail, this week I am going to add a character to every one of my online passwords. And there is only one that is 8 characters and it will be 10 before the sun sets. NewsBites can only report the breaches that have been announced, what about the ones that have not been detected? ]

Tesco.com Customer Data Compromised (February 13 & 14, 2014)

Supermarket chain Tesco has suspended more than 2,000 online customer accounts after data thieves posted associated passwords and other login details. The information appears to have been stolen from other websites, as it affects Tesco users whose username and password combinations were the same across multiple sites. The customers whose accounts were compromised reported that vouchers were stolen from their Tesco clubcard accounts. Tesco says it will replace the stolen vouchers.





--What Will Microsoft's New CEO and the Return of Bill Gates Mean to Windows Security? SANS Director of Emerging Security Trends John Pescatore takes a look and largely focuses on if Microsoft will emphasize security at it tries to compete with the Apple Apps Store and Google Play app stores.

--Bit9 Acquires Carbon Black Bit9 is an executable whitelisting company that was founded in 2003 and has now received a total of $120M in investment funding over that period. CarbonBlack is endpoint forensics software that came out of vulnerability and malware research firm Kyrus in 2011. Cost and complexity has resulted in both of these areas remaining niche on desktops, but application whitelisting on servers has shown strong growth, with little business disruption. Bit9 has said it will maintain the CarbonBlack brand and product, so growth will mostly be upselling CarbonBlack to the Bit9 installed base.

The Editorial Board of SANS NewsBites

John Pescatore was Vice President at Gartner Inc. for fourteen years. He became a director of the SANS Institute in 2013. He has worked in computer and network security since 1978 including time at the NSA and the U.S. Secret Service.

Shawn Henry recently retired as FBI Executive Assistant Director responsible for all criminal and cyber programs and investigations worldwide, as well as international operations and the FBI's critical incident response. He is now president of CrowdStrike Services.

Stephen Northcutt teaches advanced courses in cyber security management; he founded the GIAC certification and was the founding President of STI, the premier skills-based cyber security graduate school, www.sans.edu.

Dr. Johannes Ullrich is Chief Technology Officer of the Internet Storm Center and Dean of the Faculty of the graduate school at the SANS Technology Institute.

Ed Skoudis is co-founder of CounterHack, the nation's top producer of cyber ranges, simulations, and competitive challenges, now used from high schools to the Air Force. He is also author and lead instructor of the SANS Hacker Exploits and Incident Handling course, and Penetration Testing course..

Michael Assante was Vice President and Chief Security Officer at NERC, led a key control systems group at Idaho National Labs, and was American Electric Power's CSO. He now leads the global cyber skills development program at SANS for power, oil & gas and other critical infrastructure industries.

Mark Weatherford is a Principal at The Chertoff Group and the former Deputy Under Secretary of Cybersecurity at the US Department of Homeland Security.

William Hugh Murray is an executive consultant and trainer in Information Assurance and Associate Professor at the Naval Postgraduate School.

Sean McBride is Director of Analysis and co-founder of Critical Intelligence, and, while at Idaho National Laboratory, he initiated the situational awareness effort that became the ICS-CERT.

Rob Lee is the SANS Institute's top forensics instructor and director of the digital forensics and incident response research and education program at SANS (computer-forensics.sans.org).

Tom Liston is a Senior Security Consultant and Malware Analyst for InGuardians, a handler for the SANS Institute's Internet Storm Center, and co-author of the book Counter Hack Reloaded.

Dr. Eric Cole is an instructor, author and fellow with The SANS Institute. He has written five books, including Insider Threat and he is a founder with Secure Anchor Consulting.

Mason Brown is one of a very small number of people in the information security field who have held a top management position in a Fortune 50 company (Alcoa). He leads SANS' efforts to raise the bar in cybersecurity education around the world.

David Hoelzer is the director of research & principal examiner for Enclave Forensics and a senior fellow with the SANS Technology Institute.

Gal Shpantzer is a trusted advisor to CSOs of large corporations, technology startups, Ivy League universities and non-profits specializing in critical infrastructure protection. Gal created the Security Outliers project in 2009, focusing on the role of culture in risk management outcomes and contributes to the Infosec Burnout project.

Alan Paller is director of research at the SANS Institute.

Brian Honan is an independent security consultant based in Dublin, Ireland.

David Turley is SANS operations manager and serves as production manager and final editor on SANS NewsBites.

Please feel free to share this with interested parties via email, but no posting is allowed on web sites. For a free subscription, (and for free posters) or to update a current subscription, visit http://portal.sans.org/