Friday, February 09, 2007
Corporate computer threats 'moving to Adobe'
They are likely to begin focusing more attention on looking for vulnerabilities in software such as Abobe Systems' Acrobat Reader, security experts said at the RSA Conference 2007 here on Wednesday.
Today, most spyware and other "crimeware" applications target flaws in client-side applications, explained Jeff Moss, who founded the Black Hat and Def Con hacker conventions. These attacks involve sending an employee or home user a modified file, or a hyperlink to a Web download, that will compromise their system if executed.
"Office 2007 is much better architected, and the fine-grained capabilities are much better (than Office 2003), so you're going to see a lot less application attacks against Office. And because of that you're going to see less attacks against Vista that are successful," predicted Moss.
"So, where do the attackers go? Every other app that you are running. That's going to be Acrobat, and we've already started seeing that in the last couple of months. They just go for the lowest-hanging fruit," Moss said.
Moss added that Adobe has recently begun patching more quickly, because it has become more of a target for these attacks. In January, Adobe admitted that its PDF Reader application contained a major security hole, which exposes a user's hard drive to attack.
Attendees of the RSA Conference heard that crimeware is a rapidly growing threat facing both companies and individuals. Criminals are using Trojan horses, rootkits, keyloggers and other pieces of malicious software in a concerted attempt to steal personal data, log-in codes or banking details.
Doug Camplejohn, chief executive of Mi5 Networks, which sells antispyware products, cited analyst firm Gartner's prediction that 75 percent of businesses will fall victim to a piece of financially motivated spyware in 2007. However, he wasn't sure that the recent launch of Office 2007 will have a significant effect on the problem.
"Not everyone is going to move to Vista overnight. So there's going to be a broad period of time when there's a broad user base that is going to have the existing vulnerabilities to deal with," Camplejohn said.
According to Moss, a team of malicious hackers might spend a month working on a client-side exploit before releasing it, but may devote as much as nine months perfecting a server-side attack, trying to get it exactly right before launching it. If the attack relies on a previously unknown flaw, they may only have one shot before security vendors wake up to the problem and issue protection.
Because computer crimes often rely on an individual running an application or clicking on a link, education should be a key part of a company's defense strategy, some conference attendees said. Locking down nonessential applications to limit the company's exposure to danger was also recommended.
"If I've got a user who isn't supposed to go onto the Internet, why am I allowing them Internet access?" asked Andre Gold, director of information security at Continental Airlines.
Camplejohn agreed that a more prescriptive, proactive approach may be better. "User education is nice, but I think that for the most part it falls on deaf ears," he said. "What we find most effective is to basically slap someone's hand right when they're doing something--a screen pop-up that tells them 'You can't do this' because that's confidential data that's going out that door."
"In some cases, people don't know that's something that they shouldn't be doing. And also, they know someone's watching."
Hacker leaves explosions on nuclear Web site
OTTAWA (Reuters) - Red-faced officials at Canada's nuclear safety watchdog on Thursday said they were probing how a hacker had managed to litter its official Web site with dozens of color photographs of a nuclear explosion.
The Ottawa Citizen newspaper said every media release on the Canadian Nuclear Safety Commission's Web site had been labeled as a security breach on Wednesday. When opened, each document had a headline reading "For immediate release" and underneath was a large photo of an exploding atomic bomb.
"We are in discussions with the (Internet service) provider. When we were informed the Web site had been tampered with, we immediately disabled the media module," said commission spokesman Aurel Gervais, dismissing the suggestion that the hacker had been able to access secret information.
"The external Web site was the only Web site that was tampered with. There was no internal information that was compromised," he said.
The media site at http://www.nuclearsafety.gc.ca/eng/media/ was working normally on Thursday.
The Citizen -- which published a color photograph of one of the tampered pages -- said the hacker had left a message saying "Please dont (sic) put me in jail ... oops, I divided by zero".
Thursday, February 08, 2007
Google Opens Gmail Signups Further
After opening its formerly invitation-only Gmail webmail service to anyone with a mobile phone in August 2005, Google removed that requirement Wednesday. Now, anyone can signup for a Gmail account by creating a Google Account.
The mobile phone requirement was designed to prevent Gmail accounts from being created by robots and stop spammers from signing up multiple times. As of Wednesday afternoon, the Gmail signup URL still redirected users to the SMS-based method, but a support article on Google's site says the world is now welcome without an invitation or phone.
Wednesday, February 07, 2007
Wi-Fi hacking, with a handheld PDA
Wi-Fi hacking, with a handheld PDA by ZDNet's Ryan Naraine -- The palm-sized PDA tucked away in Justine Aitel's pocketbook just might be the most scary device on display at this year's RSA security conference.
Internet backbone at center of suspected attack
There are signs that hackers attacked key parts of the backbone of the Internet on Tuesday, but no damage seems to have been done, experts said.
The attack appears to have focused on the Domain Name System, which maps text-based domain names, such as "News.com," to the actual numeric IP addresses of servers connected to the Internet, and vice versa. Several key DNS servers saw traffic spike in the early morning on Tuesday, several experts said--a sign of an attack.
"It is an unusual large amount of traffic that is hitting DNS servers," said John Crain, chief technical officer at the Internet Corporation for Assigned Names and Numbers, which operates one of the main so-called root DNS servers. "We see large attacks on a regular basis, but this hit quite a few servers, so it was fairly large."
Yet the DNS servers were able to withstand the onslaught, Crain added. "It was irritating. It ruined my night's sleep. It was extraordinary in the fact that it happened to multiple systems at once, but this is not affecting Internet users," he said.
DNS serves as the address books for the Internet. There are 13 official root DNS servers, which sit at the top of the DNS hierarchy. These root servers get queried only if other DNS servers, like those at an internet service provider, don't have the right IP address for a specific Web site.
If part of the DNS system goes down, Web sites could become unreachable and e-mail could become undeliverable. But DNS is built to be resilient, and attacks on the system are rare. In 2002, a similar denial-of-service attack also failed.
"The main thing is that there was very little impact on the general public, the servers were able to hold up against the attacks," said Zully Ramzan, a researcher at Symantec Security Response. "The Internet in general was designed to even withstand a nuclear attack."
The barrage of data being apparently targeted at the DNS system started around 2.30 a.m. Pacific Time on Tuesday. Multiple root servers saw a traffic spike, but the "G" server, run by the U.S. Department of Defense, and "L," run by ICANN, seem to have gotten the brunt of it, Ramzan said. ICANN's Crain confirmed that impression.
While ICANN and Symantec didn't see any effect on the Internet at large, Internet service provider Neustar did see slow downs on the Net. "We would call it a brownout instead of a blackout. It was significant, but it did not take anything down," a representative for the company said.
The true cause of the traffic surge still needs to be determined, both Ramzan and Crain said.
Tuesday, February 06, 2007
Microsoft raises support fees for Windows, Office
Microsoft raises support fees for Windows, Office by ZDNet's Mary Jo Foley -- Microsoft quietly raised last week its per-incident support prices across the board for Windows and Office. Officials are attributing the changes to a desire "to provide more personalized support options based on customers’ technology usage."
Screen Gallery: When is a firewall not a firewall? When it’s Vista’s built-in firewall
Screen Gallery: When is a firewall not a firewall? When it’s Vista’s built-in firewall by ZDNet's David Berlind -- Configuring Vista's firewall isn't easy. In fact, it's so difficult that the Windows Firewall is actually worse than having no firewall at all. Mere mortals shouldn't bother configuring it.
Saturday, February 03, 2007
Windows Vista’s three killer features
Windows Vista’s three killer features by ZDNet's Ed Bott -- Should you upgrade to Windows Vista? Sorry, there's no one-size-fits-all answer to that question. But I can put to rest some myths about how well Vista runs on older hardware, and I've found three killer features that haven't received nearly the attention they deserve.
Friday, February 02, 2007
Demo 07: Wireless control of your car
Demo 07: Wireless control of your car by ZDNet's Dan Farber -- Inilex launched Kepler Advantage, which a GPS-enabled wireless device for security and monitoring that plugs into a car’s data bus. From a phone, PDA or other device, you can set alarms, start the engine, unlock doors and receive messages, such as "your vehicle has been stolen." The QuickFence service locates the vehicle and sets a [...]
Users find ways around early Vista licensing hurdles
Users find ways around early Vista licensing hurdles by ZDNet's Mary Jo Foley -- The first wave of Windows Vista users are hitting some licensing glitches that are making them none too happy.