Showing posts with label incidents. Show all posts
Showing posts with label incidents. Show all posts

Monday, April 22, 2013

Hostgator post on an insider attack

Another day, another insider attack.  This one was detailed by Hostgator.  The link is to the post from NakedSecurity and their writeup of the breach - and how the insider got caught.

Here's the story.

Monday, October 3, 2011

Betfair accounts hacked

I haven't seen this story making the rounds in the security community.  Interestingly, I got this story from a mailing list for a card forum.  Apparently, 2.28 million"encrypted payment card account numbers and other details" were stolen OVER 18 MONTHS AGO.  Betfair just recently notified their clients.  Allegedly, 3.16 million "account user names with encrypted security questions" and 89,744 "account usernames with bank details" were also taken.

An article with more information is here.

Sure, it's good to hear that some information was encrypted.  However, a lot can happen in 18 months.  If someone has a link to an article with more technical information, I would love to see it.

Tuesday, July 19, 2011

DISA may have been hacked

Here's the link.

Keep your eyes on the news for more to the story.

Thursday, March 3, 2011

Ars Technica and HBGary

I'm not going to re-hash the HBGary story; Ars Technica has done a great job of following and chronicling the story.

Here are some of the great pieces I've read:

The Aftermath

How one security firm tracked down Anonymous - and paid a heavy price

Black ops:  How HBGary wrote backdoors for the government

I'll add more as I read more of their work.  Great stuff.

Monday, April 12, 2010

Web form incident

I received a call today for an interesting incident. Bear in mind that the customer doesn't have an incident response policy, but I think that is going to change.  It seems a staff member received an "anonymous" email that, while technically not threatening, was certainly personal, mean and inappropriate.

The staff member forwarded me the email, with all relevant headers.  Even though there was a "from" address on the email, I realized that email addresses can be spoofed.  However, digging through the headers, I found an "admin"@company.subdomain email address.  Thinking the website might have been tampered with, I perused the web sites directory.  The site only has 20 or so static pages with one contact form.  Thinking contact form, I contacted the webmaster to see how the sub-domain actually worked.  After some digging, I learned that there is one script on the sub-domain that processes the contact form.  Bingo.  Looking at the contact form, email address is not required.  So, I tested sending the form without entering an email address; and I was able to replicate the incident.

I am now working with them to fix two issues:  1) There needs to be a documented incident response policy, such that the client is protected.  2) The website needs to address how to handle submissions without an email address.

The security ball is rolling, so hopefully good things can come of the incident.

And, while we may be able to get the IP of the person that submitted the form, I'm not sure what that will buy us.

Monday, December 1, 2008

The AutoRun issue

I'm in San Antonio, getting ready for a testing engagement. While the flight in was a little bumpier than I would like, it was great landing in sunny and warm(er) weather. I spent about an hour at the Alamo, and I wish I could have spent more time there. Very interesting; and I admit, I remember reading about it in high school, but I really didn't know the story.

Anyway, I'm listing a couple of links regarding the AutoRuns situation. (Mostly because I'm exhausted and I really need some sleep...I need to re-read these articles.)

ThreatExpert has a post on Agent.btz and the Pentagon


ZeroDay has two posts on the issue:
- a post on affected systems in Afghanistan
- a guest post with a little historical perspective

LA Times article

Tuesday, February 26, 2008

The Linkin Park Stalker

First off, if you haven't signed up for the various newsletters from SANS, you should. They're great. Not only is there a list for recent vulnerabilities that have been released, but they have newsletters for relevant security news.

In today's NewsBites (Vol 10, No. 16), there is an article on the internet stalker that had been harassing the lead singer of Linkin Park, and his wife. I'm going to quote the article here:

--Internet Stalker Gets Prison Time
(February 21, 2008)
Devon Townsend has been sentenced to two years in prison for using
computers at her workplace to access private information about Linkin
Park lead singer Chester Bennington. Townsend was employed at Sandia
National Laboratories; from computers there, she managed to access
Bennington's email account, phone numbers, phone bill records, and
family photographs. She used some of the information she found to
threaten Bennington's wife.
There were two articles that the note linked to:
Link 1
Link 2

However, I remember a truly great article from Wired Magazine detailing the story. A little searching and I was able to find it. Click here to read the article.




Friday, September 14, 2007

Update

There is no update.

My manager told me that they found out who was bringing the laptop in from home and connecting to our network. My manager mentioned that they've "talked" to the individual and are "assured" it will not happen again.

Personally, I think they don't want to discipline/fire a second employee in as many days.

And I think this offense is more egregious.

Sheesh.

Tuesday, September 11, 2007

My first run in with CP

At 8:30 Monday morning, the Director of HR called me to her office. I thought, "I haven't been in long enough to get in trouble." Little did I know what would be ahead of me. I knew I had a full plate of fires to put out; what was coming would dwarf everything for the day.

I reached her office and was told to shut the door. It seems there was an incident over the weekend. A female employee had logged into a computer and found "pictures inappropriate for work." There was probably more to the story, but I wasn't privy to it. I was asked to prove or disprove the accusation; and, if it was there find out how and when.

I took my laptop and retired to a smaller conference room, I really didn't want to do this from my cube. After shutting the door, I mapped a drive to the suspect machine, surfed to the My Pictures folder. Sure enough, there were pictures there. So, without opening anything, I copied the entire directory to a cdrom. Upon viewing the cdrom I was quickly able to verify that there were images inappropriate for work.

Now for the how and when. The when was pretty easy, as all the dates were the same. Could they be faked? Sure, but I didn't think so in this case. Next, I opened up regedit and connected to the suspect computer's registry. I looked in the currentcontrolset key, and found an iPod and Creative MuVo that were listed. When I found the Dos:E\ key, I pieced together that it appeared that the iPod was last listed as the E:\. However, the dates didn't match up. I knew the only way we would prove definitively is to get a hold of the iPod.

Before I started to write up my findings, the Director of HR met me in the conference room where I was working. My co-worker had just joined me and we were going over some other leads we wanted to chase down. The Director asked to see the pictures, mostly to see if there were other employees visible. Talk about awkward. But, I guess I had better get used to it. The first couple of pictures were definitely something taken from websites. Another bunch could have gone either way. But, while viewing the last couple, the Director asked me how old the girl was. Uh-oh.

So, we next formulated the steps to take. My part was easy, I was going to provide the facts; as best I knew them, and what I suspected, in order to fill in the holes. But, I tried to impress upon her that all the ducks had to be in a row.

After lunch, I got called into my manager's office, to find the President and the Director of HR. They asked for the cdrom. Calls had already been made to the company attorney. My manager asked me and my co-worker to go through mail and see if the pictures had been mailed anywhere; both in the company and out. Well, we found one outgoing mail message that was pretty incriminating. It was to an external address. My co-worker noticed that the email address was familiar. What?

It turns out the email address turned up in the firewall logs where we logged failed connection attempts to IM. Right after the IM failures, there was another email address with failures. So, we looked up the IP that the failures were coming from, and son of a gun if it wasn't something in the DHCP scope. Uh-Oh. A look at the the DHCP server showed a lease to a computer that we didn't name.

We've gone from proving a simple case of inappropriate images on the computer, to using an unapproved computer on our network. A quick scan of the firewall logs showed that this rogue computer had been on and off the network for about a month; usually third shift, and usually on the weekends. The sites they were visiting were typically web sites that allow you to IM when the firewall blocks those ports. We've pretty much proved that someone is trying to deliberately circumvent the access controls.

We had a quick meeting with upper management. We gave our statements and left. While chasing some last leads we see the accused go to HR. Of course he denied it. When pressed, he finally admitted most of what we knew. He tried to give what he thought was a valid explanation; but it wouldn't hold up in the face of the evidence we had.

Sit down now.......they didn't fire him on the spot. They let him go back to work until they had heard from the attorney. My co-worker and I almost fell over. I ran to my cube, and checked my mapped drive...sure enough, all the evidence was just deleted from his machine. (I was't too worried; worse case, we would have undeleted it.) Here's the good part, we set up the My Documents folder to redirect to the network. Should we need to, it's a simple restore.

Fast forward to today. The accused was fired first thing in the morning. I still haven't heard what the attorney has done. I wouldn't be surprised if the company gets subpoenaed for the data so that the authorities can go after him. As for the rogue laptop, my manager supposedly knows who it is, but nothing has been done. (Personally, I think this is a bigger offense, and has more risk. But that's just me.)

I went home wiped out. I hope the company doesn't screw this up, but I'm not holding my breath.

The good news is I got my tix for Bruce's new tour.

Wednesday, July 25, 2007

A Monday Incident

It has to happen on a Monday.

And what a Monday it was.

I woke up and it was pouring out. And I mean pouring. It was raining so hard visibility had dropped to a hundred yards, at best. Driving to work, I passed three separate accidents; cars that had spun off the roads. At least they were getting assistance. This was definitely a day to stay home. The road that the plant is on was flooded, with a couple of inches of water. How fitting.

I get in a good half hour before the network administrator gets in which gives me plenty of time to put out the minor brush fires. It was about 20 minutes after he got in that he called me to his office and showed me an email he had received from our ISP. They (the ISP) were getting ready to dump our internet access (a T1) because of complaints due to alleged abuse coming from our public IP. We had about a day to figure it out.

Off to the firewall we went to see what was up. There did not appear to be anything fishy, at least from the firewall. Remember, the network admin is great at "admining" but security is an afterthought for him. I can only "suggest" policy and procedures. At about this time, the director of HR walks into the office. She proclaims that her laptop has crawled to a stop and she is unable to get any work done. We allay her fears and get back to work. I ask the network admin to check the logs for her IP. Lo and behold, we've found our problem. Connections. To and from her laptop. Hundreds of them. Thousands of them. Mail from her machine bypassing the DMZ and the mail server. P2P connections. And a whole bunch of things I didn't have time to ID. Whoa.

A little research turned up that the malicious code was a variant of the Storm Worm; I think Trend finally ID'd it as nuwar.IJ. I explain calmly to the HR director that we think we found the reason for her laptop being slow and I would need to take her laptop off the network, and remove it to the data center in order to check it out. So, we grab the laptop. The worm went undetected because it killed the AV programs first. Yea for Helix.....Rootkitrevealer proved what we thought. And we used Trend's RootkitBuster to clean the machine. Now, thinking of security, I suggested wiping and reloading. However, the network admin figured we had cleaned the machine sufficiently and we would give the machine back after a full virus scan.

When I gave the machine back I asked if there was anything she might have done to have contracted a virus or worm. She thought it might have occurred when she went to update a printer driver (why she had to update a printer driver is still a mystery.) After more pressing, she finally admitted to opening an email with a subject of "you have received a bluemountain greeting from a co-worker." She said she clicked the link too.

I'm still trying to tighten the firewall logs....p2p connections should not be coming in or going out of here. Period. That should have been our first red flag. I'm sure there's more to do; but I think the network admin is just glad our network access is not getting yanked.