Thursday, 19 May 2016

Facebook made to serve phishing forms to users

Netcraft researchers have recently spotted an extremely convincing Facebook phishing attack.
The fraudsters made it look like the fake “Facebook Page Verification” form they’ve asked the victims to fill and submit is legitimate, as the page serving it is on a Facebook subdomain and uses HTTPS:


The attack will work whether the user is already logged in or not, and all the links on the page work as they should. This is because, apart from the bogus form, the rest of the page is legitimate.
The phishers have registered Facebook apps, and have managed to load the form inside it via iframes. The form is hosted on the crooks’ own servers, which also uses HTTPS, so no warnings about unsecure connections will pop up.
Another trick up the fraudsters’ sleeve is that they made the form return an “incorrect credentials” notification the first time the user submits them (whether they are correct or not). This trick is used to convince the most suspicious users, who might have inserted incorrect credentials on purpose, that the form works as it should and is legitimate.
On the second try, the form accepts the inserted credentials, sends them to the attackers’ servers quietly in the background, and shows the victim a response saying they will be contacted by the “Facebook Verification Team” within 24 hours.
“But of course, this email will never arrive,” says Netcraft’s Paul Mutton.
“By this point, the fraudster already has the victim’s credentials and is just using this tactic to buy himself some time. He can either use the stolen Facebook credentials himself, or sell them to others who might monetize them by posting spam or trying to trick victims’ friends into helping them out of trouble by transferring money. If more victims are required, then the compromised accounts could also be used to propagate the attack to thousands of other Facebook users.”
Potential victims are likely directed to the fraudulent form via bogus emails or messages supposedly sent by Facebook.

Cybercrime economy: The business of hacking

The profile of typical cyber attackers – and the interconnected nature of their underground economy – have evolved in the last several years. Adversaries are increasingly leveraging management principles in the creation and expansion of their operations to ultimately increase their impact and financial profits. Enterprises can use this inside knowledge against the attackers to disrupt the organizational structure and mitigate their risks, according to HP Enterprise.

 

The attackers’ value chain

Today’s adversaries often create a formalized operating model and ‘value chain’ that is very similar to legitimate businesses in structure, and delivers greater ROI for the cybercriminal organization throughout the attack lifecycle. If enterprise-level security leaders, regulators and law enforcement are to disrupt the attackers’ organization, they must first understand every step in the value chain of this cybercrime economy.
Critical elements to the attackers’ value chain models typically include:
Human resources management – Includes recruiting, vetting and paying the supporting ‘staff’ needed to deliver on specific attack requirements; the skills-based training and education of attackers also falls within this category.
Operations – The ‘management team’ that ensures the smooth flow of information and funds throughout the attack lifecycle; this group will actively seek to reduce costs and maximize ROI at every step.
Technical development – The front-line ‘workers’ providing the technical expertise required to perform any given attack, including research, vulnerability exploitation, automation, and more.
Marketing and sales – These teams ensure that the attack group’s reputation in the underground marketplace is strong and the illicit products are both known and trusted among the target audience of potential buyers.
Outbound logistics – This encompasses both the people and systems responsible for delivering purchased goods to a buyer, be it large batches of stolen credit card data, medical records, intellectual property or otherwise.
“Cybercriminals are highly professional, have robust funding, and are working together to launch concentrated attacks,” said Chris Christiansen, Program Vice President, Security Products and Services, IDC.


Disrupting the chain and advancing enterprise protection

HPE recommends a number of approaches for enterprise security professionals to better defend against these organized attackers:
Reduce the profits – Limit the financial rewards adversaries can realize from an attack on the enterprise by implementing end-to-end encryption solutions. By encrypting data at rest, in motion and in use, the information is rendered useless to the attackers, restricting their ability to sell and reducing profits.
Reduce the target pool – The expansion of mobile and IoT has dramatically increased the possible attack surface for all enterprises. Organizations must build security into their development processes, and focus on protecting the interactions between data, apps and users regardless of device to better mitigate and disrupt adversary attacks.
Learn from the adversaries – New technologies such as ‘deception grids’ provide methods of trapping, monitoring and learning from attackers as they navigate their way through a realistic duplication of the network. Enterprises can use this information to better protect their real network, disrupt similar attacks before they begin, and slow down the progress of attackers.

Online transaction fraud to reach $25 billion by 2020

Online transaction fraud is expected to reach $25.6 billion by 2020, up from $10.7 billion last year, according to Juniper Research. This means that by the end of the decade, $4 in every $1,000 of online payments will be fraudulent.


The implementation of CHIP and PIN services at POS (Point of Sale) locations in the US is likely to be a key factor driving activity in the online fraud space. The greater security afforded by CHIP and PIN would persuade fraudsters to switch their attention from the in-store environment to the CNP (Card Not Present) space.
The new study identified 3 hot areas for online fraud:
  • eRetail (65% of fraud by value in 2020 – $16.6 billion)
  • Banking (27% – $6.9 billion)
  • Airline ticketing (6% – $1.5 billion).
The study also claimed that eRetail would be particularly susceptible to online fraud, with the value of fraud in this sector increasing at twice that of banking and seven times that of airline ticketing. The research highlighted two key areas for fraud within eRetail: ‘buy-online, pay in-store’ and electronic gift cards.
It argued that the continuing migration to online and mobile shopping, of both digital and physical goods (reaching over $1.7 trillion in 2015) will provide a further incentive for fraudsters to focus their attention on these channels.

Countermeasures provide only temporary respite

Meanwhile, the research claimed that although banks are able to counter online banking fraud by deploying new technologies such as 3D-Secure and device fingerprinting, these measures often only provide temporary respite as fraudsters quickly find new ways to defraud.
Similarly, while extensive efforts by the airline industry to deploy sophisticated Fraud Detection and Prevention (FDP) systems has reduced fraud significantly for some major airlines, this industry has also seen fraudsters shift their focus to other perceived weak spots in the system.
“A few larger airlines claim that they have reduced eTicket sales fraud to less than 0.1% or 10 basis points of revenues” said research author Gareth Owen. “When thwarted, however, fraudsters quickly move on to easier pickings such as frequent flyer fraud, for example.”
“Just like we are moving away from static passwords as the sole means of verification, so must credit cards and Card Verification Values (CVVs) when making online purchases. Fraud can be dramatically reduced if a dynamic verification value is used instead of the static CVV. This dynamic card verification technology is available today on credit cards and mobile. It will bring a high level of trust between the vendor and the consumer who is making the purchase. In order for banks to ensure consumers continue to spend using their credit card, they must show them protecting their data is their number one priority,” Hakan Nordfjell, SVP of eBanking and eCommerce at Gemalto told Help Net Security.

Europol to get new powers to disrupt terrorists’ online presence

The EU police agency Europol is expected to gain new powers that will help it fight terrorism and cybercrime, thanks to new governance rules endorsed by Civil Liberties Committee MEPs on Thursday.
The draft rules, which have already been approved by the European Parliament and European Council, will make it easier for Europol to set up specialised units to respond immediately to emerging threats.
The new regulation also includes clear rules for existing units or centres such as the Internet Referral Unit, which ensures the swift removal of websites praising terrorist acts or encouraging EU citizens to join terrorist organisations.
Europol will in some cases be able to exchange information directly with private entities such as firms or NGOs, which should enable it to work faster. For example, it will be able to contact social network service provider Facebook directly to ask it to delete a web page run by ISIS or request details of other pages that might be run by the same user, so as to prevent the spread of terrorist propaganda.
In order to avoid information gaps in the fight against organised crime and terrorism, the new rules state that member states should provide Europol with the data necessary to fulfil its objectives.
MEPs have ensured that Europol’s new powers will go hand in hand with increased data protection safeguards and parliamentary scrutiny. The European Data Protection Supervisor (EDPS) will be responsible for monitoring Europol’s work and there will be a clear complaints procedure under EU law for citizens.
To ensure democratic control, Europol’s work will be overseen by a Joint Parliamentary Scrutiny Group with members from both national parliaments and the European Parliament.
Parliaments’ negotiators also ensured that all information exchange agreements between Europol and third countries will be assessed within 5 years after the entry into force of the new regulation, to ensure that they comply with data protection rules and EU standards for policing.

Hacker finds vulnerability in Mr. Robot’s website

A white hat hacker going by the name Zemnmez found the flaw on the new promotional website for upcoming season 2 of Mr. Robot. Mr. Robot was the biggest 'Hacking Drama' television show of 2015 and its second season will return to American TV screens on July 13, 2016. The vulnerability could have given Zemnmez an easy way to pawn fans of the show, tricking them into giving over much of their Facebook information. But, shortly after a quick note to Mr. Robot’s writer Sam Esmail, the vulnerability was closed off. The vulnerability known as cross-site scripting (XSS) was discovered on the day when the show launched its promo for the second series. During the launch ceremony, a clip of President Obama was shown condemning a destructive attack launched on the US financial system at the end of the first series, and a website, whoismrrobot.com, mimicking a mix of Linux command line and IRC chat. The series had already received praise for its relatively accurate portrayal of hacking, something other shows and films have failed at miserably. USA Network’s owner NBC Universal confirmed that the website was patched late Tuesday (May 10) night, hours after Zemnmez reported the flaw. XSS bugs are widespread. It’s the most common vulnerability class on the web. If the reporter would have been a malicious hacker, he’d have abused it to steal users’ Facebook information. In particular, he’d have targeted a section of the website that contains a quiz, whoismrrobot.com/fsociety, which requested access to players’ Facebook data. FSociety is the hacktivist collective that central character Elliot Alderson, played by Rami Malek joins early in series one.

Wednesday, 18 May 2016

If we can't handle seasonal flu, we aren't prepared for bioterror

If we can't handle seasonal flu, we aren't prepared for bioterror: Seasonal influenza provides an excellent indicator of pandemic preparedness. If states can’t handle routine, seasonal flu, then they’re unlikely to be able to handle more severe, widespread outbreaks or bioterrorist attacks. In the United States, responsibility for preventing a health crisis falls largely on the shoulders of state and local officials. So are US states measuring up? Flu vaccination rates serve as a good proxy for answering that question.

Forensic Anthropologists Find Rare Skull Condition in Modern Humans

Skulls can tell forensic anthropologists a lot about health conditions in past human populations. Take cribra orbitalia (CO), a skeletal disorder characterized by porous bones in the eye sockets, known as orbitals. The spongy sections of the eye sockets have traditionally suggested to researchers that the decedent may have been malnourished, or could have possibly had intestinal parasites. The condition was thought to be extinct in modern, more robust, populations, but new research has found that not only does CO still exist, it’s not even uncommon in today’s human populace—suggesting that modern man may not be that much healthier than its distant relatives. CO is thought to be triggered by dietary deficiencies in young individuals causing the blood vessels to form small legions in the cranial vaults. The exact cause or causes of CO are not still fully understood, and there are few known adverse health effects associated with the condition, researchers say. Researchers examined a total of 844 skulls from three different time periods: 245 prehistoric, 381 historic, and 218 modern specimens. The results were unexpected, said coauthor Ann Ross, director of the Forensic Sciences Institute at North Carolina State University. “We thought we might see some CO, but not to the extent that we did,” Ross said in a written statement provided by the university. “The high rates may stem from the fact that these remains were part of forensic cases – there were often related to cases of homicide or neglect. These cases are not representative of health for all children.” Researchers found that 12.35 percent of modern North Americans and 16.8 percent of modern South Africans have CO—rates that are both higher than their historic counterparts. “These findings drive home the fact that disadvantaged socioeconomic groups, and parts of the developing world, are still struggling with access to adequate nutrition,” Ross said in the statement. “Corn may give people a full belly, but it’s not going to give people all of the nutrients they need to be healthy.”