Friday, January 6, 2012

Indian Hackers access an old version of Symantec Endpoint Protection code

There is news and rumors that the code of an old version of Symantec’s endpoint protection product is available with a hacker called YamaTough from an Indian group called “"The Lords of Dharmaraja”. In Hindu and Buddhist beliefs Yama Dharmaraja is the Lord of Justice and is sometimes referred to as Dharmaraja in reference to his unswerving dedication to maintaining order and adherence to harmony. Yama is also referred to as the Lord of Death. The rationale behind this hack is yet unknown.

If news reports are to be believed the code in question is Symantec Endpoint Protection 11.0 and Symantec Antivirus 10.2, approximately four years old. The current Endpoint Protection product is now at version 12.0 and 12.1. Symantec Antivirus 10.2 has been discontinued, though the company continues to service it. According to news reports the code was lifted from an Indian military agency.

Symantec Confirms Hackers Accessed Source Code of Two Enterprise Security Products


This article brings a few thoughts to mind. The first is obviously the safety of escrow code given by many firms to government agencies across the world. The second is how much of the code is reused in newer products and our knowledge of the full extent of the breach. The third is whether there was code from other yet unnamed products, lifted too.
At the moment, there is a lot of speculation. Let us wait for a full disclosure or rebut from Symantec before coming to conclusions.                                   

Thursday, January 5, 2012

2011 Put the spotlight on Business Continuity Planning for Large Enterprises and SMB’s

Business Continuity Planning involves understanding risks such as natural disasters, facilities and supplier outages to a business, and putting into place a robust mitigation plan for prevention and response in case any risk is realized. BCP is important for both large and small enterprises. In large organizations, BCP is driven by a systemic organizational process.
Three significant events in 2011 which put the spotlight on Business Continuity Planning were:
·         Natural Disasters in Japan and Thailand along with their unanticipated consequences
·         Online Activism and Hacktivism in UK and Middle East
·         Cloud and Telecommunication outages from global providers
Natural Disasters in Japan and Thailand along with their unanticipated consequences
The earthquake, tsunami and resulting impact on the Fukushima nuclear plant created a disruption in power, population unrest, and withdrawal of expats which disrupted supply chains of Japanese firms. For most of the large Japanese firms, the floods in Bangkok came as a second whammy as this led to further shutdowns. In the case of Japan, the country was well geared to face earthquakes, but the Tsunami and its unpredicted consequences amply demonstrated that its difficult to model the vagaries of nature.
The three learning’s from these incidents are:
  1. Natural Disasters cannot be accurately modeled or planned for. They do happen and due diligence in site selection helps.
  2.  In Thailand, costly equipment was damaged because the communication was not in an international language or as timely to foreign managers, hindering precautionary actions. this has to be anticipated and built into the plan.
  3. Time to recover varied from a minimum of 3 months onward for large firms
Online Activism and Hacktivism in UK and Middle East
Online activism in UK and Middle East, arose spontaneously  triggered by a single event like the death of Mark Duggan in UK—a 29-year-old father of four shot dead after being stopped by the police—and in Egypt, Khaled Said, a 28-year-old businessman who was pulled from an Internet cafe and beaten to death by security forces. This resulted in the virtual shutdown of several countries for months and in some cases, turning of the Internet partly or wholly which impacted businesses. The extreme form of online activism, Hacktivism, saw significant hacks such as that of Sony Playstation Network by Anonymous, a Hacktivist group which halted the company operations for over a month and ran up a loss of 200m$.
The three key learning from these incidents are:
  1. Online activism or Hacktivism can spontaneously result in disruption at a scale which is unprecedented. An analysis of the stability of the political environment and its impact on the functioning of the country is paramount to BCP planning.
  2. Resetting a country involves a regime or policy changes that take years. Therefore do not expect a short term effect on business operations
  3. Social unrest in a recessionary world is on an uptick and is not solely related to third world countries as believed prior
Cloud and Telecommunication outages from global providers
There were several cloud and telecommunication outages of major service providers in 2011. Reddit, Foursquare, and Quora were among the many sites that went down recently due to a prolonged outage of Amazon's cloud services. These outages lasted 3-4 days on average, and were primarily due to the inability of the service providers to understand the complexity of their infrastructure. So despite there being a robust Business Continuity Plan by these service providers it did not factor in their inexperience due to the newness of the technology, and limitation in understanding technology underpinnings and their interactions. Failure of Telecommunication services by an Indian service provider a few days before New Year impacted year end sales as well as customer services for both large and small enterprises.
The three important learning’s from these incidents are:
  1. Organization’s sourcing to the cloud must ensure that they are contractually covered for such outages. Atleast for another year, companies should expect such outages as a given.
  2. SMB’s should take precautions to build BCP plans when cloud sourcing which involve, at minimum, work around processes and data backup. 
  3. Large organization must assist small suppliers build a business continuity plan through mandatory BCP specifications in supplier agreements aswells as regular audit, and awareness training
Related Reads

A Strategic Approach to Security Risk while CloudSourcing

Midsized service firms face business continuity issues if senior executives leave with operational data

In 2011, Natural Disasters highlight importance of Business Continuity Planning

Wednesday, January 4, 2012

Does the leaked Stratfor password list speak positively for security awareness?

10% or 81000 passwords from the Stratfor password list were cracked in five hours using a simple password cracker and desktop computer reported the Tech Herald (Report: Analysis of the Stratfor Password List by Steve Ragan - Jan 2 2012). The simple fact is that password holds the key to the vault and a strong and secure password is the foundation of a secure system. A strong password is a function of an individual’s security awareness and psyche, as it is difficult to create and remember multiple passwords.

A positive aspect is that 90% of the passwords were not broken in less than 5 hours. These will eventually be broken because of the way the password was stored (plain hash and not further encrypted or salted, for the more technically inclined). From a technical perspective it’s a crucial flaw but from a security awareness perspective, individuals seem to have done a fairly good job on password creation. The fully decoded password list will tell the real story and we will soon know whether my deduction was correct.
The passwords which were cracked varied in length from 6 to 23 characters, were alphanumeric, and suffered from the following flaws:
  • Used common words and phrases
  • Used names of teams, words from religious text, computer phrases, and so forth
  • Used common names
  • Used passwords list available from previous breaches
Related Reads

Tuesday, January 3, 2012

Foreigners running an advance fee fraud racket targeting Indians caught in Mumbai

Six Nigerian nationals were arrested in India for an online prize advance fee fraud racket. While online prize money and other frauds are quite common, there were a few interesting points to note:
  1. Nigerians nationals ran the scam in India targeting Indian nationals on business visas. Usually these scams are run in different countries to make prosecution difficult
  2. The scamsters had in their possession many legal documents such as PAN cards and driving licenses in their names. These are documents, one should not be able to obtain on business visas
  3. Their operating equipment comprised of 14 laptops, 15 data cards, seven pen drives, 23 mobile phones, printer, laptop cards, various forged documents of the Indian Customs, the Reserve Bank of India and foreign courts, and government and private company documents. Obtaining a mobile connection in India requires submission of both a Government ID and address proof.
  4. They used software for generating e-mail ids and mobile numbers, randomly select them and send thousands of SMSes and e-mails daily
  5. They opened bank accounts in which the advance fee was deposited and then removed through an ATM card. Bank accounts in India need address verification and other proofs which they were able to obtain illegally
What surprises me, is that if sms can be traced to mobile phones, and advance fee fraudsters use these to send their messages, why do the telecom operators or cybercops act proactively!


For more details on these type of scams and how to avoid them:
How you get suckered in Online scams and the little one can do about it?