Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

The Dangers Of USB Drives

The Dangers Of USB Drives - Talking to a computer security researcher about Stuxnet is like asking an art critic to describe the finer points of the Mona Lisa. The world's top cybersecurity minds are absolutely in awe. Stuxnet, which was discovered in June and has since spread to millions of machines around the world, is the most sophisticated computer attack we've ever seen. Though its true purpose is unknown—teams of experts across the globe are poring through the code in an effort to divine its intentions—the deviousness of its design has prompted many researchers to call it a "cyber-weapon," one perhaps created by the United States or Israel to disrupt Iran's nuclear program.

Why should we think of Stuxnet as a weapon? Because it's the first digital worm known to infiltrate and secretly reprogram machines that run sensitive industrial processes—power plants, pipelines, telecommunications centers, airports, and ships. Iranian officials have said that Stuxnet infected employee computers at the country's Bushehr nuclear-power plant. Siemens, the German conglomerate, says that Stuxnet has already breached at least 14 factories running its software. (It hasn't caused any damage.) The worm, researchers say, is clearly the product of months or even years of work, perhaps by a large team with specialized knowledge about obscure industrial systems. In order to invade their targets, hackers often try to find a hidden bug—known as a "zero-day vulnerability"—in Windows or some other widely used software. Stuxnet's brilliant authors didn't find just one bug; the worm gets into Windows PCs using four distinct and previously unknown security holes. Its authors also managed to "sign" the worm with encryption certificates they'd stolen from two computer companies in Taiwan. These pilfered certificates allow Stuxnet to masquerade as legitimate Windows software.


http://img.slate.com/media/1/123125/2126996/2240593/2270000/101005_TECH_jumpDriveTN.jpg


But what's most interesting about Stuxnet isn't how smart its authors were; it's how dumb they guessed we all would be. How did the worm's creators expect to get it inside some of the most secure installations in the world? After all, sensitive machines often operate behind an "air gap"—that is, their networks are physically separated from the Internet and other dangerous networks where viruses can roam freely. Getting anything inside one of these zones requires the complicity of an employee. That's exactly what Stuxnet got, because its authors designed the worm to piggyback on the perfect delivery system—the ubiquitous, innocent-looking USB flash drive, the planet's most efficient vector of viruses, worms, and other malware.


Look at some of the most spectacular computer attacks in the last few years, and you'll usually find a USB stick at the center. Conficker, the worm that corralled millions of PCs into a giant botnet last year, got into the French navy and the city of Manchester, England—among many, many other organizations—through infected USB disks. (Manchester was temporarily unable to issue parking tickets as a result.) In August, William Lynn, the deputy secretary of defense, disclosed that the U.S. military was hit by a worm called agent.btz two years ago "when an infected flash drive was inserted into a U.S. military laptop at a base in the Middle East." (Lynn says that the attack was a deliberate effort by a "foreign intelligence agency," but security experts are skeptical that it was anything more than a routine infection.) In 2008, the central computer at the Spanish airliner Spainair was hit by a virus introduced through a USB drive; the malware slowed down a machine responsible for monitoring airplane failures, which an investigative report later fingered as one factor in the cause of the deadliest air disaster in Spanish history.

What makes USB drives so great at carrying malware? They're the mosquitoes of the digital world—small, portable, and everywhere, so common as to be nearly invisible. I've got half a dozen USB disks on my desk right now, several of unknown origin—I know I purchased a couple of them, but I've also picked up USB drives from friends, colleagues, and at trade shows, where they're handed out as freely as pens and candy. Funny story: At a conference in Australia last year, IBM handed out thumb drives that turned out to be infected by malware. It was a computer-security conference.

That gets to what's most dangerous about USB drives—many computer users are in the dark about their capacities for trouble. Over the last decade we've all grown used to the dangers of Internet-borne scams and malware. We know we shouldn't click on e-mail attachments from strangers, and we know we should be wary of typing our passwords into shady sites online. But the USB disk has somehow evaded our suspicion; few of us look at them and recoil at the dangers that could be lying within. Indeed, USB sticks evoke exactly the opposite emotion—if you saw a stray one on the street or lying around your office, wouldn't you pick it up and put it in your computer to try to identify the rightful owner?

Chester Wisniewski, a researcher at the security firm Sophos, says Stuxnet's authors might have exploited this naiveté when designing the worm. JMicron and RealTek, the two companies that own the digital certificates that were stolen for Stuxnet, are located in the same office park in Taiwan. Wisniewski offers the following theory: "What if the attackers dropped a couple USB drives in the parking lot between JMicron and RealTek, and then employees picked them up and stuck them into their computers?" Voila, instant infection.

For Stuxnet, sticking it in is all it takes. Sean Sullivan, a researcher at the security firm F-Secure, points out that most USB-borne malware operates on a Windows feature known as AutoRun. AutoRun was developed in the 1990s to make it easier for people to install software on their computers; when you insert a disk, Windows looks for instructions telling it what to do. Usually these instructions are benign—the disk tells the PC to install a legitimate application—but AutoRun could also be used by hackers to install malware instantly. Over the years, Microsoft, security firms, and IT managers have become much more sophisticated about fighting AutoRun viruses. New versions of Windows prompt users about the software on a disk before running it, and corporate IT staffers often disable Windows' AutoRun features. But Stuxnet evades those measures; it can infect PCs even when AutoRun is turned off. "All you have to do is open up the folder and view the contents, and you're infected," Sullivan says. "It's such a minimal action that's required—something anyone would do just to see what's on the disk. That's why it spread."

There is, of course, a failsafe way to prevent Stuxnet from infecting high-security machines—why not just prohibit users from sticking USB devices into computers that have been purposefully separated from the Internet? "That would have worked," says Sophos' Wisniewski, "but the reality is the world is still pretty crappy at security." Companies either don't have such policies or don't enforce them—maybe, perhaps, because selfish employees (like yours truly) consider USB sticks extremely convenient. If you want to hand over a huge PowerPoint presentation to your colleagues down the hall, what's easier than sticking it on a USB disk?

If a company wants to ratchet up security, it's not as simple as banning all thumb drives. To be extra careful, you'd have to ban iPods, cameras, and every other USB-based doohickey—all of those devices are capable of carrying Stuxnet-like viruses, too. I asked Sean Sullivan, of F-Secure, if he could imagine any failsafe IT policy that would have worked to thwart Stuxnet. "Well, in our malware test machines, sometimes we put glue in the USB ports," he joked. Wisniewski, of Sophos, says, the only hope is education: Don't trade USB sticks, don't stick an unknown one into your machine, and don't pick one up off the street and plug it in your machine just to see what's inside.

"But I don't know if we're ever going to win that battle," Wisniewski says. "It's human nature. If I were a normal person and I didn't work in this bubble of security? If I found a USB drive, the first thing I would want to do is want to plug it in, too." ( slate.com )

READ MORE - The Dangers Of USB Drives

Cleaning Up Your Digital Dirt

Cleaning Up Your Digital Dirt. Remember, prospective employers could be checking you out online. What happens on the Internet tends to stay on the Internet.

Merry Miller, an entertainment reporter, found that out the hard way. She did an interview last year with Holly Hunter on an ABC news show, and she made so many fumbles and gaffes that it ended up on YouTube titled "TV Disaster." To date, this video has received more than 1.5 million views and nearly 2,000 comments ridiculing the interview.


There's nothing worse than having unflattering information about you posted on the


Web. It's even happened to me, folks.


Unfortunately, you can't just sit back and hope it goes away. With hiring managers today checking out prospective employees on the Web, job seekers need to manage their online reputations -- or their résumés could end up in the do-not-call pile.


Kirsten Dixson, author of "Career Distinction: Stand Out By Building Your Brand," calls this type of negative stuff "digital dirt."


Recruiters are Googling you, she says, and "digital dirt" can quickly take you out of the running.


"We've had clients who had digital dirt about them on major news sites, but you can't just ask to take it down. You have to find ways to sweep the dirt under the rug," she maintains.


The first thing you need to do is Google yourself right now. Even set up a Google alert with your name so you can track all the new dirt when it first hits.


I'm not talking about defamatory information that may require legal action against the perpetrator. I'm talking about the things that may have a grain of truth in them -- like how silly you looked during a television interview, or a blogger's negative opinion about a research paper you wrote, or a MySpace confession you made when you were 17.


Burying those Internet skeletons


Many of us may want to find ways to erase the negative information about us on the Web, but that may not be the best strategy.


"What to do when you don't like the impression given by your online persona?" asks C. David Gammel, a corporate technology consultant. "The counterintuitive response is the best: Post even more content about yourself online."


However, he adds: "The content should be of a nature that is at least neutral, at best positive, for your career prospects. Blog about your professional interests. Discuss research you have conducted yourself on a topic of interest."


Gammel believes in burying the Internet skeletons in positive cyberdust. "Once the less-savory items are pushed off your first page of ego search results on Google, you'll be fine with most people," he notes. "That's why you have to post more -- not less -- to get rid of the impact of those skeletons."


If you have a profile on a social networking site such as Facebook or LinkedIn or BrightFuse, that content eventually goes to the top of Google searches when someone types in your name.


As for burying the negative information, you can politely ask a site owner to remove an item about you, and sometimes that works. But don't engage in tit for tat, says Lyn Mettler, who owns Step Ahead Web Strategies, which helps businesses manage their online reputations.


"It ends up looking defensive and can get ugly very quickly," Mettler says. "If there is misinformation and you can calmly clarify that in a post, response, comment, etc., do so, so the reader will see both sides."


She also suggests that you enlist the help of friends. "Third-party endorsements are much more credible than someone talking about themselves," she says.


Another tactic is to do a traditional public relations blitz, even embracing the dirt. That's what Merry Miller did, and she ended up on "The View" talking about her notorious Hunter interview.


"Based on my personal experience, the best thing to do is address it immediately, tell the truth, don't blame anyone and try not to take it personally because most vicious bloggers move to their next target really quickly," she says.


"Life isn't easy, but you don't have to go down with the bad stuff."


Bringing in the experts


You can also hire a firm that specializes in vacuuming up the digital dirt.


ReputationDefender is an online reputation management company. CEO Michael Fertik says about half of the negative information they find about their customers is self-inflicted, and half is inflicted by someone else. "Maybe someone wrote something about their eating disorder years ago and now it's among the top 10 results about them on Google," he says. "Or there's someone calling you a thief or a jerk, or a bad girlfriend or boyfriend."


ReputationDefender charges between $100 and $500 for its services, which include publishing so much accurate and positive information about an individual that the bad stuff gets pushed off the first page on Google.


The company also offers a service that provides manual removal of dirt, including asking site owners and bloggers politely to take down information.


None of this stuff is guaranteed, however, because too often the people who run these sites refuse to remove any data.


Indeed, even ReputationDefender has trouble defending its reputation on the Web.


When the firm first started, it tried to help one of its clients by asking a blogger to remove dirt about the individual. But the strategy backfired and the blogger ended up blogging yet again about the client's dirt -- and also slamming ReputationDefender.


In a recent Google search on "ReputationDefender," the negative post appeared as the third result. This proves how difficult it is, even for experts, to keep a cyber-reputation untarnished.


Getting out your cybermop


As I mentioned before, I have also been slammed on the Internet.


I came across a blog post written by Mark Story, a communications expert and adjunct faculty member at the School of Continuing Studies at Georgetown University, which blasted a story I had written for msnbc.com about social networking overload.


Story called my reporting "sloppy," which is probably the worst slam you can make against a journalist.


I decided to write a response on his blog. I'm a blogger at CareerDiva.net and msnbc.com's YourBiz, after all, and I should be able to take what I sometimes dish out.


I politely disagreed with him on his blog post and, to my surprise, he e-mailed me an apology.


He also blogged about our interchange saying, "In a moment that was likely based on blogger hubris and too much caffeine, a few weeks ago, I blogged about an MSNBC piece on social media overload and called it 'sloppy journalism.' "


I know, not all these stories will have similar happy endings. But if there's a chance you can control some of the digital dirt out there, why not take out a cybermop? ( msn.com )


READ MORE - Cleaning Up Your Digital Dirt

Google Results Polluted By Cybercrooks

Google Results Polluted By Cybercrooks. My original intent was to relay a heartwarming/heartbreaking story if you hadn’t heard it already. It’s a narrative you hear periodically in different forms with different details: A man found his long lost daughter via Google. However, in trying to find content referenced but not linked in the news articles about the subject I found nothing but malware traps right at the top of the results.

Very quickly the story, because it’s a good one. Twenty seven or so years ago, Dirk Pratt’s two-year-old daughter was taken off to Ecuador by her mother and he never saw her again. His ex-wife told him Francesca had died after being bitten by a mosquito. Dirk heard someone had been reunited with a family member with the help of a Google vanity search for their own name. So Dirk searched his name and found a message on a message board from his daughter. She was also told her father was dead, but was suspicious. Now they’re reunited.

My daughter is six months old and naturally when I read that story I was very touched and saddened and all that; I couldn’t imagine what that must feel like. So I went off in search of the message board. I wanted to see what the father saw. Eventually, I found a result for a Zabasearch message search result, but I can’t be sure this is same place he found it. The Zabasearch result was the sixth listing on Google. The top, where sponsored results often are, was a Google News result. The first through fifth results: all malware links.

Looking For Dirk Pratt


I only clicked on the first few links, which led to scareware. Upon closer look at the others it was obvious. They had strange URLs, irrelevant texts. One appeared to be a BBC link but the URL didn’t resolve to bbc.com. All of them, were indexed fairly recently.

Dirk Pratt Malware

Earlier I wrote about link velocity and Google’s apparent new favoritism of freshness is allowing cybercrooks and SEO blackhatters to manipulate and dominate Google’s search results. Google needs to fix this or users will lose trust quickly. If every time you tried to do research on popular subjects and all you were met with were attack sites, wouldn’t you?

I’ve contacted Google several times over the past couple of months since instances like this became more and more frequent. I have yet to hear back from them about what they intend to do about it.
READ MORE - Google Results Polluted By Cybercrooks