Showing posts with label social engineering. Show all posts
Showing posts with label social engineering. Show all posts

Wednesday, August 18, 2010

Facebook Dislike Button Scam

All you overly paranoid Infosec people who scoff at the slightest hint of risk taking can just take a chill pill right now. It'll take you a few years to learn--and I hope you do learn for the sake of the companies you're supposed to be protecting--that there's no place for ultra paranoia in the business world.  Maybe I'll explain that in another post.

I bring up this point because I can just hear some infosec folks sniffing arrogantly when I admit that I use Facebook. Well, guess what, I am balancing risk versus benefit, something those sniffly infosec people should try sometime.

There are risks I'm taking using Facebook and, in fact, I did get partially snookered by the Facebook Dislike Button Scam. In that I clicked "like" when I saw the thing. I didn't actually use it.  And I'd like to believe that if I had, I'd get suspicious of it trying to do a survey and I would disallow access to it in the end.

Guess what, social engineering works beautifully, even occasionally on an infosec pro. There's no way to reliably patch wetware against it.

The best we can do is achieve a reasonable, helpful level of paranoia that prevents us from doing overly stupid things.

Then hope the rest of our technology defenses protect us from our slightly stupid mistakes.

Friday, July 03, 2009

Criminals Steal $415k from Bullitt County

I am getting kind of burned out on computer security. I know, I know, it's only been 14 years that I have been in the trenches and, after all, we are making such tremendous progress in the infosec industry in that brief span of time.

Now instead of curious geeks hacking computers for fun and irritating people, we have widespread criminal activity. Instead of passwords, we're now using... um. Nevermind. And we went from having no network boundary enforcement to... err... having no network boundaries. Software security bugs are a thing of the past. And present. And forseeable future. But hey, at least hackers are targeting networks and systems less. Now they're just targeting people and client software. Cool. That's lots better.

Speaking of criminal activity. Here's yet another example of a phishing attack working. Criminals stole over $400,000 from a municipality's bank account. Why did this attack work? You could blame user(s) for giving away the info, falling for the phishing scheme. Or blame it on a lack of awareness training. But folks, the phishing attacks are getting so sophisticated even very experienced infosec professionals have a hard time.

Seems to me these attacks work because it is difficult to reliably verify trustworthiness of messages or senders. The same issue makes it easy for spammers to make / steal money. With a widely deployed SMTP infrastructure, how do we make improvements?

Saturday, January 12, 2008

Helpdesk Social Engineering

This article discusses attacks on Xbox Live accounts. The key point is that of social engineering of helpdesk/support employees. Call up the helpdesk of the target, pretend to be the account owner, request password reset, et voila.

Same thing in IT security of course. Fundamentally it's an authentication issue. Or lack of one. You want to use a something-you-have, or more commonly, a something-you-know (and-others-don't) aka a secret.

I've set an optional password on bank accounts where they ask it before they can make any changes over the phone or even in person. Simple. Effective. We've all run into the common "please verify your mailing address for me" verification, usually following entry of an account number. If attackers know your name there's that little detail of online white pages to get them the info. In a previous incarnation, the company I worked for would verify you by your SecurID using a website. That's solid. But kind of a pain.

Once again it's a balance. Don't forget when looking at the risk of social engineering that there is also the risk of time lost to a cumbersome password reset process. You want optimal security, not ultimate security.

If your company's helpdesk isn't doing some reasonable authentication before doing password resets, then it's probably about time work with 'em to develop a new, simple process. With a priority based on risk analysis, obviously... but with this being an easy, common attack, I bet the risk ranks fairly high on the list.

You do have a risk list, don't you?