LSEC Information Security Newsletter 19.04.2011

LSEC Infosecurity Mid-Week Report

Every Wednesday LSEC publishes the LSEC Infosecurity Information Security Newsletter, a Mid-Week Report with a list of IT-security issues you may want to have a look at, a few freeware tools to test or use and a few reports to read. It is called the LSEC Infosecurity Mid-Week report, still providing you a couple of days to manage the most critical issues.

Information is collected from various sources and has been reviewed and edited by some of our experts.

Web Site Management : Google search tip for securitypeople Nr 1

If you have a site you can search everything Google knows about it (and is showing the world). This is quite simple. You type - site:mysite.com (or whatever the name of your site) - and you will see all the pages that were found by Google. If you have a big site you can add certain special words after it like - “admin or logon or password” - or any other function or page that you thought was hidden. If you have interactive functions on your site or you want to search for spammers that are abusing your site you can add “porn mp3 viagra warez” and you will find all their references. If you have a site you should also make a Google account and insert the Google code in your site so that Google knows that you are the owner of that site. If your site is infected or defaced you will have it easier to ask Google to update the index of the site after you have cleaned it up and Google can even send you a warning if it thinks your site is infected. You can also make Google Alerts so that you will receive an email every time Google finds a new page for your site (even if you didn’t update it lately) or discovers new spammers who have been inserting bad links in your forum.

Patches part 1 : Oracle

Oracle launched 73 patches April 19th, nearly half of them are highly critical because they allow to take ownership of the application or database remotely without authentification. You will have to test them on a virtual version of your applications before installing them definitely if the application developers did add some personal functions to it. Meanwhile you will have to monitor your applications more closely for any dangerous connections.

Patches part 2 : Microsoft

Professionals follow the discussions about and the issues with the monthly Microsoft patches through the Internet Storm Center because it is where you heard it first. First there could be some issues with Exchange servers running on windows2008 R2 but this is not confirmed yet. Secondly these pathes are really important and they will protect you against a whole set of new attacks and harden your systems. These patches are not to be overlooked and network adminstrators should really follow the patchrate (number of machines against those patched with the latest patches) very closely especially for machines that are used by possible ‘targeted’ managers. Secondly don’t be fooled about the colors of the urgency, you will have to install all of them anyway. And last but not least, patching will only work perfectly on machines running the latest OS. If you are still running Vista, XP or older, you are vulnerable to a whole set of attacks even if you apply those patches.

Attacks against some of those security vulnerabilities (indicated ‘Patch Now’) were already taking place.
The ‘Patch Now’ indication means that you should update your internetconnected servers immediately even if you have a traditional ‘waiting and test period’. In practice it means that those patches will be installed immediately on servers that have internetconnections while the ‘internal backoffice’ will have to be tested before.

Individual users should go to http://update.microsoft.com

Network administrators should start controlling the state of the installed windows updates (and the presence of an updated antivirus on the machine) before giving machines access to critical resources. (Network Access Policy).  Most VPN-SSL, Firewalls and proxies now have this feature available.

Patches part 3 : Adobe

Adobe has updated the Flash player and this should be followed immediately as there are now attacks taking place against this vulnerability. Normally Firefox will warn you if your flashplayer is out of date.

Adobe is for the moment not only taking a beating from the malware developers but also from the security community and the network administrators because they don’t seem able to catch up with the stream of attacks that are hitting their products. The proof is that the next patches for Adobe products are only ready late april and june which is rather late as a response to ongoing attacks.

The PDF reader for windows (version x) has now a sandbox that will limit the success of attacks because it will stop any code from leaving the document and installing itself on the computer or connecting to the internet. The best thing to do is to upgrade the PDF readers - especially for managers - and activate the sandbox.

Sometimes one could wonder where the simple secure PDF document has gone. It did nothing special but was very secure. Nowadays a PDF can do nearly everything but it seems as if every new line of code or new function introduced also ten times more vulnerabilities and mistakes. It could be interesting to re-launch a simple stupid read-only PDF document that has as little coding and functionality as absolutely necessary. “Cut the crap” - a manager would say.

Patches part 4 : And you didn’t forget to update

* Java client. This is a very important (older) update that we need to remind you of because the number of online attacks against unpatched local javaclients is still growing. The problem for network administrators is that some internal applications may not work with the updated javaclient and that the application may need some upgrades. The solution is to disactivate the old javaclient except when it is needed by that application while using the more secure javaclient when surfing the internet.

* Browsers like Firefox, Chrome, Internet Explorer, Opera etc.....  XP users should use Internet Explorer 8 while Vista and Windows7 should upgrade to Internet Explorer 9. Only Windows7 users can test Internet Explorer 10 beta. This is another reason why critical machines shouldn’t be on XP anymore. As internetservices have become essential in any business and have also become the main method for infecting machines your browser is the most important free line of defence against attacks your antivirus can’t handle (yet).

* Servicepack 1 for windows 7 and Servicepack 2 for windows 2008. Available on many DVD’s of computermagazines if you don’t like to download it.

* Apple or Macintosh users have major updates and will also receive now an integrated antivirus because there are finally also viruses against Apple.

Some interesting databreaches that made the news in 2011

* Even the best get hurt : Barracuda Networks got breached when they took their webapplication firewall offline for maintenance during a few hours. On their OLD IIS 6 server the SQLinjection attacktool found some script that allowed the attackers to download their internal employee list and a list of future clients. 

useful attention points :  - It is very difficult to protect an IIS 6 server, upgrade to IIS 7 and windows 2008.
- If you have such old infrastructure you can never leave it without an Application Firewall.
- Of all hacked IIS servers, the IIS6 is by far the most popular victim.
- SQL injection is still the most popular and effective attacktool

* SSL certificate seller Comodo had two affliates who were breached with a SQL injection which gave the hacker access to a server which gave access to a desktop on which the hacker found the necessary technical information and programs to analyze and understand how he could register some certificates for very important internetdomainnames through the local backoffice without any control by the main server at Comodo. This is not the case with many other important sellers of certificates.  Maybe it is time that the sellers of certificates are .... audited and certified.

attention points :
- You should make sure that your users have upgraded their browsers so they have revoked the stolen SSL certificates.
- at Comodo it isn’t the first time even if they have promised to review their security, they will stay the a popular target.
- Breached once means that you will always be tarteged.

* Millions of emailaddresses were compromised because of a breach of a major databroker in the US. All compromised accounts should receive an email (and a flood of spam and scams).

attention points : 
- It is important that your users don’t use their workrelated emailadresses for private newsletters or communication.
- hacking of servers and forums in search of data about users is becoming epidemic. It is important that users use different emailaddresses for different kinds of online activities. With some emailproviders you can also create and delete aliases.

DNS.Be in the news

DNS.be is the organisation responsable for the management of the .be domainextension. It has been twice in the news lately. The first incident was an article that claimed that the .be domainextension was nearly thrown off the internet after a technical incident. The truth seems to be more complicated. DNS.be had some (undocumented) technical problems when they implemented DNSsec on the opensource Bind software that runs on their DNS servers. Some people believe that such critical infrastructure shouldn’t rely solely on opensource software for such complicated tasks. If you want to implement DNSsec you should take those issues into account because they won’t be acceptable for your business clients or contacts.

The second article claimed that DNS.be was nearly pushed off the web by an attack from a botnet. The first thought was revenge because DNS.be is refusing botnetdomains since many months now.  After an investigation by CERT it seemed the reason was a bad configuration by a botnet with a DDOS effect. The problem with the article is that you shouldn’t publish important technical details that we are not going to repeat here. DNS.be will now have to ‘up the ante’. After all it was a good exercise for the the anti-ddos procedure. You should also have an anti-ddos protection and procedure if you have a critical network or function because DDOS has become one of the many problems networkadmins have to deal with on a frequent basis.

DNS.be says that it has a backup system of servers and that the internetusers didn’t notice anything.

Some updated freeware to add to your library

Systernals is the best free collection for windows if you need to analyse some processes, logs or software on the server or PC.

wireshark is the best free datasniffer and has been updated because of some securitybugs.

metasploit is the best free attack tool that is also used to test webservices for vulnerabilities before they are put on the internet. It is now updated with beta plugins so that new exploits and attacks can be inserted in this platform before all the bugs are found.

Dead site alert

‘Google Video’ will stop. Youtube won’t take over the video’s automatically, so you will have to transfer them manually before the 13th of May.

If you have tips or research that may be of interest you can send it to midweekreport@lsec.be.

By Ulrich Seldeslachts

19-Apr-2011

Are you a leader in Security ? Do you want to share your expertise and join the Leaders in Security as a Core Expert Member ?
Contact us via email! Or call +32.16.32.85.41 for a direct contact and more information.
An information set and your Membership Welcome Pack awaits you.

 

Copyright LSEC vzw 2007-2008 with the support of the IWT.

LSEC vzw Kasteelpark 10 - 3001 Heverlee - VAT BE BE 478 045 395 - fax. +32.16.32.19.69 - info @ lsec.be

Expert: Cognitive Security

Providing detailed intelligence against highly sophisticated network attacks.

Expert: Courion

Leader in IAM Solutions

Expert: Oracle

Oracle Belgium & Luxemburg

Expert: Option

Wireless data security enablers

Expert: TNO

TNO Research and Innovation

Expert: Control & Protection

Automatisering SCADA, PLC; Meettoestellen en brandbeveiliging

Expert: Thales Group

Thales Group

Expert: On2It

Smart IT Security We Are On To It

Expert: Mobco

Mobile Fleet Management

Expert: TITANS

TITANS ICT Consulting

Expert: G Data

G Data Anti Virus Solutions

Expert: Outpost 24 - Vulnerability Management Made Easy

Outpost 24 - Vulnerability Management Made Easy

Expert: Regify - Trusted and Binding Secure eMail

Regify - Trusted and Binding Secure eMail

Expert: Mobila - Mobile Enterprise Applications

Mobile Enterprise & Applicatinos

Expert: Lancelot Institute

Lancelot Institute - Training in Information Security, IT- Risk & IT - Auditing

Expert: CSI Tools

CSI tools is an expert software solution provider specialized in powerful tools for IT architects and auditors who are focused on maximizing GRC project development efficiency in SAP environments.

Expert: Intrinsic-ID

Content Protection, Unique Device Identification, Key Storage, PUF Physical Unclonable Functions

Expert: Belgacom ICT

Belgacom ICT Security Solutions for Large, Medium and Small Enterprises

Expert: Qualys

On Demand Vulnerability Management and Policy Compliance

Expert: Trend Micro

Securing your web world

Expert: Egemin

Egemin provides process and handling automation engineering and Secures Industry Automation

Expert: AEP Networks

More than 60 countries ... protected by AEP Networks

Expert: Palo Alto Networks

Next Generation Firewalls

Expert: Atos Origin Belgium & Luxemburg

A leading IT services provider. Ranks 1 in telecom outsourcing. Via Atos Worldline specialized in financial transactions.

Expert: Websense

Leading provider of unified content security

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: Axl-Trax

axl & trax are highly qualified experts in providing leading edge GRC services for SAP

Expert: VintiQ

VintiQ - Security Management Services

Expert: T-Systems Belgium

T-Systems is Deutsche Telekom's corporate customer arm.

Expert: LIN.K nv - LINKID

LIN.K is a provider of online user authentication, identification with the system LINKID

Expert: Devoteam Belgium

Devoteam Belgium, one of the major European ICT consultancy specialists with offices in 23 countries

Expert: CHB Technologies - Celadon Hailstone Biometrics

Celadon Bailstone Biometrics

Expert: Barracuda Networks

Worldwide supplier of email and internet security

Expert: Sophos

Sophos is the Utimaco is a leading global provider of data security solutions, enabling mid- to large-size organizations to safeguard their data assets against intentional or unintentional data loss, and to comply with privacy laws.

Expert: Dimension Data

Dimension Data

Expert: Bull

Bull

Expert: Check Point Software Technologies

Check Point Software Technologies

Expert: MMS-Secure

MMS-Secure nv, a distributor with a specific focus on network and systems security

Expert: F-Secure Corporation

F-Secure - Fastest Focused Anti-Virus Protection

Expert: C-Cure

C-Cure are Information Security architects already since 1998

Expert: IS4U

IS4U - Cronos specializes in Identity and Access Management

Expert: UCL Crypto Group

The Crypto Group of UCL, the UC of Louvain-la-Neuve is a research group specialized in cryptography and information security.

Expert: eID Company

eID company provides a flexible easy to integrate eID in any web application. Access to eID as a webservice.

Expert: ACA IT-Solutions

ACA IT-Solutions, end to end IT solutions and IDM Expert. Probably the largest and most successful independent J2EE solution provider.

Expert: RSA - Security Division of EMC

RSA - The Security Division of RSA. One of the leading companies in the world in IT Security. Enterprise wide Data Security solutions, suites and Services.

Expert: Unisys

Security Unleashed – At Unisys, we’re looking at security in an entirely new way.Security is no longer a defensive measure. It’s an enabling catalyst for achievement.Unisys Secure Business Operations help to unleash your full potential.

Expert: Zion Security

ZION SECURITY is the leading European application security company. Our mission is to secure your business value by securing your business applications.

Expert: Zetes

For those who want to see the difference!

Expert: Vasco

VASCO designs, develops, markets and supports patented User Authentication products for e-business and e-commerce.

Expert: SUN Microsystems

Everyone and everywhere connected to the network.

Expert: Security4Biz

Security4Biz offers ICT security consultancy services.

Expert: SecurIT

The value proposition to our customers is the competence and experience of highly qualified people, combined with best-in-class solutions from leading suppliers, and our entire focus on Identity and Access Management.

Expert: Sealed

Expert in implementation of e-Security, e-Proofs and e-ID within the management of business & document flows & processes, or within the management of your enterprise content in the broad sense.

Expert: McAfee

McAfee is the world largest dedicated security companY;

Expert: NXP (founded by Philips)

Sense & simplicity. Help customers to transform initial ideas into competitive products and cost-efficient manufacturing solutions within healthcare, lifestyle and technology.

Expert: KPMG

PMG Information Risk Management (IRM) focuses on inherent risks in technology systems used to support your business objectives and grow your business.

Expert: EMC2

EMC Corporation is the world's leading developer and provider of information infrastructure technology and solutions.

Expert: Deloitte

In addition to the qualities of a leading Belgian audit and consulting firm, Deloitte is different through the values it shares daily with clients and employees.

Expert: Certipost

Specialist in secured electronic document exchange for companies, the state, and for residential customers.

Expert: Ascure

World class information risk management services!

Expert: Verizon Business

Verizon Business is now the leading provider of managed security services worldwide with acquisition of Cybertrust.

Expert: K.U. Leuven

Computer Security and Industrial Cryptography (COSIC): Cryptography to protect data against passive and active fraud.

Expert: ATOS Worldline nv

Specialist in end-to-end secure payment systems.

Expertise: UTM

UTM - Unified Threat Management

Expertise: End Point Security

End Point Security

Expertise: DLP - Data Leakage, Data Loss Prevention and Protection

DLP - Data Leakage, Data Loss Prevention and Protection

Expertise: SOA - Service Oriented Architectures

Expertise: Identity Management

Identity Management (IdM) enables organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access

Expertise: Crypto

Cryptography - Cryptografie - Cryptographie

Expertise: Secure Application Development

Secure Application Development. Security does not only start at user name and password login, from the first entry of a software security needs to be integrated.

Expertise: RFID

passive and active low-cost wireless tags

Expertise: Application Security

encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system

Expertise: Wireless Security

Expertise: Appliances

protect computer networks from unwanted data traffic, intruders, email spam, enforce policies, and may also be used to create and manage VPNs.

Expertise: Access Control

the ability to permit or deny the use of something by someone.

Expertise: Risk and Vulnerability Assessment

process of identifying and quantifying vulnerabilities in a system..Cataloging assets and capabilities (resources) in a system

Expertise: Penetration Testing

A method of evaluating the security of a computer system or network by simulating an attack by a malicious user, commonly known as a hacker.

Expertise: Physical Security

describes measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media. It can be as simple as a locked door or as elaborate as multiple layers of armed guardposts.

Expertise: Remote Access

computer program that lets you access your PC from another PC via the Internet, LAN, or phone connection and work on your computer ...

Expertise: Security Policy

security policy is a definition of what it means to be secure for a system, organization or other entity. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries

Expertise: Anti-Virus

Software that detects, repairs, cleans, or removes virus-infected files from a computer.

Expertise: Spyware

Software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes.

Expertise: Authorization

The process of enforcing policies: determining what types or qualities of activities, resources, or services a user is permitted. Usually, authorization occurs within the context of authentication.

Expertise: Authentication

Provides a way of identifying a user, typically by having the user enter a valid user name and valid password before access is granted. The process of authentication is based on each user having a unique set of criteria for gaining access.

Expertise: Computer Virus

Program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document.

Expertise: Smart Cards

smart card or chip card, is defined as any pocket-sized card with embedded integrated circuits which can process information such as a SIM for a mobile phone or an eID card

Expertise: UTM and Appliances

Unified threat management (UTM) is a term which is used to describe network firewalls that have many features in one box, for example junk e-mail filtering,or anti-virus capability, along with the traditional activities of a firewall.

Expertise: NAC

Network access control (NAC) is a method by which hardware and software grant access to enterprise network resources after first authorizing the user and device and verifying the device's compliance with the enterprise's security policy.

Expertise: Biometrics

Biometrics (ancient Greek: bios ="life", metron ="measure") is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Expertise: DRM

Expertise: eID - Electronic Identity Cards

The electronic identity card (eID) is an official electronic proof of one's identity. It also enables the possibility to sign electronic documents with a legal signature.