IMPORTANT NOTIFICATION

This site is an archive of Simon's first blog.
Current writing and commentary is now published at
simonedwards.com.
Showing posts with label criminal economy. Show all posts
Showing posts with label criminal economy. Show all posts

Tuesday, 2 November 2021

The Coming Mac Threat (Revisited)

Foreword

The following article was written and published in 2008. The first iPhones were less than six months old and Apple's OS X operating system was just seven years old. The previous year Apple launched a version of OS X that could run on Intel systems. The following year OS X could *only* run on Intel systems. This could have made life easier for attackers, as they faced a familiar underlying system.

A lot has changed since then. According to some statistics the use of OS X (now MacOS) has risen between 2009 and 2021 from below 4% to around 16%. This is clearly a significant rise, but with around 75% of computer users still staring at Windows, the value to an attacker of MacOS exploits is still relatively low.

Attackers have targets and the chances of a valuable one using a Mac is now five times as likely. We've seen news reports of exploits targeted Apple-based devices. NSO's Pegasus spyware is now widely recognised as being a threat that targeted civilians, including journalists.

Tuesday, 6 May 2014

Video: Hacking a botnet

It's illegal under certain circumstances, but hacking hackers is always an interesting subject.

And what better than to watch someone (else) doing it?

"Hacking Zeus was never so easy," writes Xylitol, a French security researcher who published a video demonstrating an attack on a Zeus botnet command and control (C&C) server.



The video above shows Xylitol using information from his CyberCrime Tracker Zeus-tracking website to access a botnet's control webpage.

Friday, 2 August 2013

Choosing a secure PIN

Credit, debit and ATM cards are usually protected by a four-digit number.

This Personal Identification Number (PIN) is supposed to prevent an unauthorised person from using the card.

Choosing a good PIN makes a great deal of sense. Here's how to pick a good one, or at least how to avoid a bad one.

It seems that good sense is lacking with many people, who use predictable PINs such as 1234, 1111 and 0000.

How do we know this? Nick Berry, from DataGenetics, analysed passwords that had been leaked onto the internet. He concentrated on the four-digit passwords, working on the fair assumption that if people are using four-digit passwords for internet services then there will be some correlation between their choices and the numbers people choose for bank cards and other systems that use four-digit PINs.

He discovered that, out of 3.4 million records, the three sequences above were by far the most common. They were almost certainly chosen with intent, rather than being generated randomly.

The top 20 PINs accounted for 26.83 per cent of all passwords in the database, which means that a bad guy would only need to try 20 codes to achieve success in one quarter of sessions.

Within the top 20 you will find all repeated sequences of a single number: 0000, 1111, 2222, 3333, 4444, 5555, 6666, 7777, 8888, 9999.

So in other words, if you want to guess someone's PIN try each of the above sequences in turn and you stand a very good chance of success.

The least popular choice was 8068. So we should all start using that one, right? Definitely not. As Nick writes:
Warning - Now that we’ve learned that, historically, 8068 is (was?) the least commonly used password 4-digit PIN, please don’t go out and change yours to this! Hackers can read too! They will also be promoting 8068 up their attempt trees in order to catch people who read this (or similar) articles.
The key to a secure PIN is to choose one that is not predictable. So maybe looking at the most- and least-used ones published in such articles is a good idea so that they can be avoided. You want your PIN to be lost in the middle ground.

One quite amusing part of Nick's research is that the number 2580 crops up fairly high on the list, at #22 Look at your telephone key pad to discover why this is a popular choice.

I know of at least one PIN-protected door to which no-one who uses it can tell you the PIN. They have all memorised the combination using a visual pattern (e.g. top left, bottom-right, middle-right, middle-left) rather than by the numbers (1964).

Thursday, 14 March 2013

Seagate website infects visitors

A website run by hard disk manufacturer Seagate has been infecting visitors with malware for nearly a month (at least).

According to a report from Sophos:
SophosLabs has been tracking an infection of Mal/Iframe-AL on Seagate's blog since late February.
SophosLabs informed Seagate of the issue back in February, but at the time of writing the site remains infected.
Apparently the technical culprit is a couple of dodgy web server components (Apache modules) that are directing visitors to malicious websites using iFrames.

The malicious sites are using Blackhole exploit toolkits to infect victims' systems.

Thursday, 31 January 2013

Howto: Secure Java in three easy steps

Java has had a poor security reputation for some years now but January 2013 saw spectacular failures. Despite numerous fixes internet threats continue to break into victims' computers using security holes in Java.

If you uninstall Java you will be significantly safer than if you don't, but is that really the answer? After all, you may need to use Java to run some important piece of software. Or Minecraft.

The Java attacks that everyone is talking about are varied but occur when the victim browses an infected website. You can increase your computer's security massively by disabling Java in the browser, rather than throwing the baby out with the bathwater and ditching Java entirely.

Here's how you do it.

1. Open the Windows Control Panel and select the Java section.
2. Click on the Security tab.
3. Untick the option called 'Enable Java content in the browser' and click OK.

3. Untick the option called 'Enable Java content in the browser'
These instructions won't work if you are using a version of Java earlier than Java 7 Update 10. You should always update Java as a matter of course so, if you don't have the option listed in step three above, update and then try again.

Wednesday, 17 October 2012

Anti-counterfeit invisible QR codes

Academics have developed an anti-counterfeit system that uses QR codes printed with invisible ink.

Researchers from the University of South Dakota are able to print the codes, which can contain vastly more information than a standard barcode, using nanoparticles. A laser is required to display the code, which can then be decoded using a regular smartphone.

This is more than security through obscurity, though. Jeevan Meruga, who led the study, said, "We can take the level of security from covert to forensic by simply adding a microscopic message in the QR code... which then requires a microscope to read [it]."

The video below describes the process in more detail.


Monday, 17 September 2012

Malware on new PCs not installed at factory

Microsoft has reported that some new computers are infected with malware.

The mainstream and technical media has taken up this disturbing story and published nearly identical versions, complete with the same quotes.

Sadly they often miss the main point of this incident.

What most stories on this subject claim: malware is pre-installed on new computers at the factory.

What Microsoft's document actually states: malware was found on a computer bought from a shop.

In the report's own words:
"Microsoft’s researchers purchased a Windows laptop computer from computer reseller in Shenzhen, China, which had been carelessly or intentionally infected with Nitol.A."
The Guardian's story uses the headline, "Malware being installed on computers in factories, warns Microsoft" and opens with, "Criminals are installing malware on PCs before they leave the factory, according to Microsoft."

The BBC's version of events claims that, "Malware inserted on PC production lines, says study" continuing with the same flawed statement, "Several new computers have been found carrying malware installed in the factory, suggests a Microsoft study."

The Daily Mail's over-long headline warns that, "Hacker warning as research finds malware installed on computers before they even leave the production line". The report then uses the now-familiar, albeit grammatically incorrect, opening gambit of, "Criminals are installed malware on PCs before they even leave the factory."

There are a vast number of cookie cutter stories very similar to those above on the web.

Microsoft never made this claim, though. In fact its initial research was into the security of supply chains, rather than the internal security of factories. It is far more likely for a small business on the low-margin retail end of the line to engage in this sort of criminal activity than it is for a major manufacturer to compromise itself in this way.

Only one in 20 computers bought by Microsoft was infected.

In its report Microsoft claims to have found a copy of malware known as Nitol on just one of 20 computers that a researcher purchased. Three other PCs contained a few files that (unspecified) anti-virus software detected as being malware. This does not necessarily equate to an infection, though. In fact, as Microsoft notes, "The computer that contained the Nitol virus was the only one that was actively running."

Microsoft has published an article about its findings, which links to the document mentioned above, on its blog.

While this particular piece of research has been misrepresented, there have been verified cases of malware being installed at factories in the past:


18/03/2010 Energizer Trojan keeps going

Friday, 3 August 2012

Computer attack statistics

Did you know that global cost of cyber crime is $1 trillion?

Or that buying counterfeit software DVDs is likely to contain malware?

The great $1 trillion scandal

$1 trillion is a lot of money, especially considering that the United States makes around $14 trillion a year.

It is possible, of course, that this figure is not accurate. In fact, it is very likely that this amount is wrong.

This has not stopped the media, leading politicians and other high-profile figures from quoting it.

Notable persons include US President Obama and NSA director General Keith Alexander. And security firm McAfee, which dropped the figure into a report it published last year.

Wired has published an insightful article that investigates the origin of the $1 trillion figure for money lost to cyber crime.

It found that a number of researchers and other experts had contributed in one way or another to the report, and that few of them recognised the veracity of the figure.

Here are some of their comments when asked about it:

Ross Anderson, security engineering professor, University of Cambridge
“I would have objected at the time had I known about it. The intellectual quality of this [$1 trillion number] is below abysmal.”
 Jackie Rees Ulmer, associate professor, ProPublica
"I expressed my concern with the number as we did not generate it... It is almost certainly the case that I would have told them the number was unsupportable."
Sal Viveros, a McAfee's PR person who oversaw an older McAfee report, said that the figure was calculated as a result of a survey. The company took the total lost revenue that was reported and "multiplied it by the number of similar companies in the countries we studied," according to Viveros.

Does pirated software put you at risk of identity theft?

In October 2007 I met with Michala Alexander, then Microsoft's UK head of anti-piracy. I was news editor of Computer Shopper.

She claimed to have research that found, depending on which country you visit, that there was a good chance pirated software on physical media would be infected with malware.

Alexander told me, "People who buy pirated software are putting themselves at risk of cyber crime and identity theft."

The research did not appear to be available from Microsoft, though, and I discovered that the figures came from an IDC report called The Risks of Obtaining and Using Pirated Software. This seemed promising because, although the report was sponsored by Microsoft, IDC is both respected and independent.

However, IDC's report was based on research that involved software downloads. It explicitly did not address physical disks on sale abroad.
"IDC did not test physical media. We did, however, review the work Microsoft conducted earlier in the year analyzing disks obtained by Microsoft employees who purchased mid-grade counterfeit software in various countries around the world."
And so we return full circle to Microsoft, which provided some data for the same IDC report that it had sponsored.

Microsoft's own research does not support its own headline conclusions of heavy malware infections. In fact it does not mention malware at all, although it does refer to additional program files and tools used to bypass copy protection controls.

Microsoft placed research on physical counterfeit media into a report otherwise wholly dedicated to the malware threat of downloading counterfeit software. This made a close association, causing Microsoft to make incorrect conclusions in its press releases and press briefings.

Today Microsoft's anti-piracy web page states things a little more clearly:
"In an IDC study, 25% of web sites studied that offered counterfeit or pirated software also attempted to install spyware or Trojans... In studies conducted on counterfeit versions of Microsoft software... more than 40% of the... counterfeit disks installed contained additional programs or binaries with known vulnerabilities."
It's interesting to note that installing any version of Windows, even from trustworthy media, will install programs with known vulnerabilities.

Wednesday, 18 April 2012

Video: Cyber gang member arrested

The suspect, dressed
The arrest of a member of the Carberp cyber gang has been televised on NTV.

The footage shows dark figures abseiling down a multi-storey building before beating their way through a window using a crowbar.

A whimpering suspect is heard and then appears, sitting on the ground in y-front underpants.

As law enforcement officers pack up evidence the suspect is seen in a variety of poses, with facial expressions ranging from sick to bored.






Thursday, 12 April 2012

OS X security (2002)

Ten years ago I wrote an article about OS X security for Mac User magazine.

The article noted that Mac users were now using a new operating system that was far more likely to face threats such as malware.

In light of the recent Flashback threat, and the resultant interest in Mac threats, I've pasted it below. Most of it is still relevant today.

[Note: If you are worried about the Flashback threat, you can check and clean your system using one or more of these tools.]

Securing Mac OS X

by Simon Edwards

Mac OS X opens more potential security holes to hackers. So how do you protect yourself?

Your Mac is at risk from hacker attacks, now more than ever. And if you don't take active steps to secure it you will be used as a Spam gateway, an unwitting accomplice of further hacker attacks or even a stooge in a bank robbery.

This isn't hype, it's reality. When Apple started shipping Macs loaded with OS X it was making a very powerful operating system available to thousands of users. But while people rejoiced in a new user interface and greater stability, many have not realised that by adopting a well-known operating system (UNIX) they have also opened themselves up to a raft of old and new security vulnerabilities.

The reason that Macs have been relatively free of remotely exploitable security holes is because the people who find and use such holes are only interested in the operating systems that they will commonly find on the Internet. Mac OS 9 is not common in comparison with Solaris, AIX, Windows NT and Linux operating systems, which is why the latter have been plagued by hackers for what feels like forever.

But OS X works in much the same way as Linux, Solaris and other UNIX-based systems. It can use the same software and, therefore, inherits the same benefits and vulnerabilities. The solution is not to revert to OS9, though. Instead, read this feature and you'll be able to lock down your Mac OS X machine against the most prevalent attacks.

First line of defence

OS X is a multi-user operating system, which means that many different people can use the computer at different times. Their application settings, e-mail and other files are kept separate so that one user cannot delete another's important data, or read his e-mail. While this means that the system is potentially more secure than a Mac OS 9 system, with regards to local users, the level of that security is only as good as the users' passwords. A recent survey found that 25 per cent of users believe that 'banana' is a strong password. This is incorrect for a number of reasons.

Firstly, banana is a real word that can easily be guessed by a password-cracking tool. Cracking tools work using dictionaries, and only resort to the very slow method of brute-forcing after all dictionary words have been tried. The brute force approach works like this: the cracker starts at 'a' and works through the alphabet, then adds another letter and continues through every permutation of letters, numbers and punctuation marks. This can take months, and it took our 700MHz system 28 days to crack the simple password 'rumble9'.

If you insist on using passwords of less than eight characters (not recommended), at least change them every month. That way you will foil this kind of attack most of the time. You should also use a mixture of capital and lower-case letters, numbers and punctuation marks. 'Mac_+Us3r01' is a good password but 'macuser' is not.

Service included

Programs such as a Web server, FTP server or a remote access utility are known as services. An Internet host is of little use unless if provides at least one service, but by doing so it is exposing itself to attack. A hacker needs something to hack at, and an old SMTP (mail), DNS, or Web server is sometimes all that is necessary. The trick is to run only those services that are really necessary.

Allowing remote access with older versions of Mac OS X meant enabling Telnet. This service lets you log in from a terminal on another computer, be it a Mac, PC or even PDA, and control the server as if using its own keyboard.

While this may seem like a very useful feature, Telnet is not a secure method of working. The problem is that when you log on using Telnet you have to enter your username and password, which is sent across the network (and maybe even the Internet, if you are logging in to a Web server installed in another building). Telnet sends these details in plain text, which can be intercepted by a hacker using a network sniffer. He will see 'user fred.bloggs' followed by 'password BaNa_na9'. Even though Fred has used a strong password, the hacker now knows it and can hack the system.

Mac OS X v.10.0.1 has replaced Telnet with SSH (Secure Shell), which is much better. It encrypts the connection so that instead of seeing the username and password, the hacker just sees digital garbage instead.

FTP also suffers from the same plaintext vulnerability as Telnet. You can replace FTP with the SSH equivalent, SFTP (Secure FTP) or SCP (Secure Copy). For details on setting up and using SSH, see the walkthrough below.

Updates

As we've already seen, updating your software can avoid some major problems. But even if you have a perfectly working Web server with SSH installed, things are not always as safe as they seem. New security holes emerge all the time and you'd be wise to subscribe to the main security mailing lists if you intend your Internet-connected Mac to survive. The best ones include the large selection at SecurityFocus (www.securityfocus.com).

For example, during the month in which this article was written, security updates were released to fix holes found in the Apache Web server, SSH, the Web scripting language PHP, the printing system, Internet Explorer 5.1, crontab, fetchmail, the firewall software ipfw, Telnet and a whole load of others. Failing to updates any of these packages could result in a hacker taking remote control of your computer, which is the ultimate goal for them and the ultimate nightmare for you.

The best way to update your software is to set the Software Update program to check for updates every day, or every week if you only connect to the Internet sporadically. To run this utility open the System Preferences and select Software Update option.

Buffer overflows

Security holes come in a number of shapes and sizes, and you can even create your own if you're not careful. The most common threat comes from buffer overflow attacks. The principle behind these is that a program installed on your system is written in such a way that when an attacker feeds it too much information it crashes.

In an analogy where the computer's memory is an empty glass and the incoming data is a flow of milk, a buffer overflow would occur if you tried to pour a pint of milk into a half-pint glass. Obviously some milk is going to spill onto the table, which results in a mess - or a crash, in the case of a computer system. But a clever hacker can cause the overflowing data to move into another part of the computer's memory, where it will be run. This is how they gain access to your system without even bothering about cracking your passwords.

Firewalls

One way to restrict a hacker's access to your system is by using a firewall. This program decides which information can flow out of and into your system. You can use a firewall to allow Internet users to access your Mac on port 80, which is the networking port used by most Web servers, but to deny access to any other port. SSH usually runs on port 22, so you'll probably want to allow external access to this port as well, if you want to administer the Web server from any Internet-connected location in the world.

But your file sharing ports, networked printer port and ports for other services that should only be available to the local network, not the Internet, need to be blocked off. Disallow all but the most necessary ports for outbound traffic too. That way you prevent malicious applications from sending important data out to an attacker on the Internet (see Viruses and backdoors below).

For a detailed description of setting up the firewall supplied with Mac OS X, see Configuring Mac OX X's firewall with BrickHouse, 19 April 2002, p79.

Wireless networks

While wireless networks are doubtless very cool and quite useful, remember that they increase the range of your network beyond your office. If you don't use encrypted networking (such as with SSH) you might as well stick a network port on the wall outside and wait for the hackers to jack in. There are plenty of tools that hackers can use to locate and crack your wireless network, but with a little care you can make it not worth their while to try.

If you're running a seriously expensive business over a wireless network consider setting up a virtual private network (VPN) to provide the encryption, and place dedicated firewalls between the wireless section of the network and other workstations. By treating the wireless part as an untrusted network, just as you would treat the Internet, you reduce the risk of a wireless attack massively.

Viruses and backdoors

While there are not many viruses that can affect UNIX operating systems directly, they are more than capable to moving through UNIX mail servers and onto the Mac and PC systems further down the chain. If your Mac is being used as an e-mail server you should consider installing an anti-virus program, which will strip out viruses intend on damaging your users' OS 9 Macs and Windows PCs. McAfee and Symantec have released Mac OS X anti-virus programs that will do the job.

The direct danger to Mac OS X systems is that once a hacker has compromised the security, using a buffer overflow attack or by exploiting some other weakness, he will install a backdoor that will allow him to return more easily. You can patch your system until you're blue in the face, but if you don't know about the backdoor you might as well give up.

When a hacker installs a backdoor he may replace some of your useful files with doctored versions that seem to behave properly but are actually helping to hide the hacker's files and activities. For example, he might have placed a stash of useful files in a directory called /hacks. The less command would display this directory, but a doctored version could be made that displayed every directory except this one.

We need a way to discover if files have been changed. CheckMate is a program that can scan essential files and create a special index of them, using checksums (see the Jargon box). If an important file is replaced the checksum will change and CheckMate will notify you that something is up. Knowing that your system has been compromised this heavily will help you save time when trying to work out what's wrong. If you find your basic files have been replaced there is only one thing to do - reinstall. Then install every possible update and run CheckMate again before connecting to the Internet.

File encryption

When you send an e-mail across the Internet it can be read by a large number of people, whether you know it or not. E-mail is created, sent and received in plain text, and passes through a number of systems on its journey to the intended recipient. Hackers with snuffer programs, mail system administrators and people with access to the computer used by your contact can all read the message, which is why sensitive information should always be encrypted.

Files stored on your hard disk should also be encrypted if they are sufficiently important. For example, if you've used CheckMate to generate an index of checksums you'll need to be sure that the hacker hasn't edited it to avoid an alert. Encrypt it and he's locked out. To encrypt e-mail and local files you'll need a good encryption package like PGP or GnuPG. The former is very easy to use and comes with a graphical installer, the latter is free but needs to be loaded from the Terminal command line.

To do this you'll need to download the GNU Privacy Guard file (GnuPGOSX1.0.6r6.dmg.gz) from http://macgpg.sourceforge.net, as well as the Darwin patch, which is called gnupg-1.0.6-darwin. Next, type:

tar -ax gnupg-1.0.6.tar.gz
To copy the Darwin patch into the folder that this creates, patch the software and install it type the following lines in order:

cp gnupg-1.0.6-darwin.diff gnupg-1.0.6/
cd gnupg-1.0.6/
patch -p 1 < gnupg-1.0.6-darwin.diff
./configure
make
sudo make install
You can now download the plethora of GUI helper tools from the same site. Or download the non-commercial version of PGP from pgpi.com.

Conclusion

If this article has started you worrying about Internet security, it has done its job. But while the Internet can be a hostile place, taking the simple steps listed here will make you almost invulnerable to the most common attacks. Just being aware of the risks puts you in a minority, and it's a good club to join.

Talk the talk

Buffer overflow A common but highly technical type of hacker attack, that is avoided by keeping software on the computer as up-to-date as possible. A successful attack allows the hacker to run commands on your system at the highest possible level of authority.

Checksum A checksum is a code that can be generated to represent a file. It is virtually impossible for two different files to have the same checksum, so it can be thought of as a fingerprint or DNA profile. This makes check summing an ideal technique for detecting if a file has been changed by a hacker.

Encryption The scrambling of a file or message so that it is readable only by the person for which it is intended. Encryption can be used for Internet traffic too (see SSH below), and is most commonly encountered when buying from a Web site - those yellow padlocks are indicative of an encrypted Web session.

Firewall A software program or hardware device that controls the type of network traffic able to pass through it. Usually used to protect computers or even whole networks from the Internet, they are now being installed by some to keep wireless networks safe.

Ports Different Internet services running on the same computer use different ports. This means that someone trying to connect to a system using FTP won't interfere with the Web server on the same machine. FTP uses port 21 whereas Web servers usually run on port 80. Services: A server is a computer that provides services to other users. Examples included POP3 mail, telnet or SSH remote access and Domain Name Services (DNS). Services are controlled by a file called /etc/inetd.conf.

SSH The Secure Shell creates an encrypted connection to your Mac, which means that hackers cannot see what you're up to, or what your password is. SSH can also be used to create virtual private networks (VPNs) across the very unprivate Internet.

Trojan A file that looks like something you want to run, but carries a less pleasant payload such as a computer virus or backdoor that creates a secret entry point for a hacker into your system.

UNIX These days UNIX is considered to mean a type of operating system, rather than a specific one. Solaris, Linux, FreeBSD and AIX are all types of UNIX, or are based on UNIX. Mac OS X is based on Darwin, which in turn is a version of BSD UNIX.

Using SSH

For security purposes, a server is any computer hooked up to the Internet that's capable of providing network services such as Web, FTP or mail. If you want to control your Mac OS X server remotely you'll need to use SSH, which has replaced the less secure Telnet originally shipped with the operating system. If you've never updated your installation you won't have SSH. You are strongly advised to download the very latest updates as soon as possible, particularly if your system spends any time at all connected to the Internet - even using a dial-up modem connection.

In this walkthrough we are assuming that your system is fully up to date and that you want to administer your computer from somewhere else on the local network. There is no real difference between doing this and coming in from the Internet. If you want to do connect from the Net you will need to ensure that any protective firewalls between you and the Internet will allow connections through port 22 or it won't work.

STEP ONE

Enabling remote access

Go to the Sharing System Preferences panel and choose the Sharing option from the Internet and Network section. Tick the Allow Remote Login box, which enables the Secure Shell (SSH) service. This operates on port 22, which is the default used by just about everybody. You absolutely must ensure that you are using Mac OS X version 10.0.1 or later, otherwise your remote access will be provided via Telnet, which is significantly less safe to use. We are using version 10.1.4 here.

STEP TWO

Establish a connection

Here we are assuming that you have two computers connected to the same network, one allowing remote access and that has an IP address of 10.0.0.1. You can determine the IP address of your remote server by going to System Preferences, choosing Network and viewing the settings for Built-in Ethernet. Start a terminal session on the non-remote access Mac (Terminal is available from the Utilities folder) Type: 'ssh username@10.0.0.1'. Use your own username and enter your password when prompted. Answer 'yes' when asked if you want to connect.

STEP THREE

Run commands

You can now administer your computer over the network, or even over the Internet. You'll need to have administrator rights to be able to change the system. These are provided in System Preferences from the Users option. Running 'top' will show you what processes (programs and background operations) are running. You can use the sudo command to run critical commands that require the ultimate level of authority. To reboot the Mac type 'sudo shutdown -r'.

STEP FOUR

Copying a file

Use the scp to copy a file from the server. Here we typed 'scp spge@10.1.22.23:backup backup', which has the effect of running scp, connecting to the server at 10.1.22.23, grabbing a file called backup and saving it as 'backup' on our system. The following line in the screenshot lists all files beginning with the letter 'b'. Using the list command (ls) with the -l switch shows more information, such as the file size, the date of its creation and who has permission to read or edit it.

Further information

Pretty Good Privacy (PGP) E-mail and general file encryption utility that can make your files unreadable to everyone but yourself
Free, for personal use
http://www.pgpi.com

GNU Privacy Guard Essentially a free version of PGP, you'll also need to download some other utilities to make it extra friendly to use.
Freeware, even for commercial use
http://macgpg.sourceforge.net

CheckMate Generate and compare checksums of essential files to discover if a hacker has altered your system.
Free, while in beta
http://personalpages.tds.net/~brian_hill/checkmate.html

Hints and tips

Watch your logs!

When a hacker takes over you system is won't be quietly, but unless you look through your log files you'll never know what's happened. It is necessary to know how a hacker broke in, even if you are going to reinstall your whole system, because that way you can fix the problem. Reinstalling will just reset your computer and the hacker can come back in the same way he did before. You'll find your logs in the directory called /var/log. Type 'last' from the terminal to see who's been logging in, and when.

Keep an eye on your users

If only you and a couple of other people are using the Mac there should only be a handful of names in the user list accessible from System Preferences - Users. If odd entries appear you can be sure that someone has administrator-level control of your system. If you want to know who's logged in at any one time type: w from the terminal command line to see a list. You should also check the /Users directory to see if any extra sub-directories have been created. This would indicate that someone has gained access to your system.

First Published in MacUser, Vol 18 No 13, 28 June 2002.

The above article is © Dennis Publishing Limited 2002. UK property of Dennis Publishing Ltd. This article may not be reproduced or transmitted in any form in whole or in part without the written consent of the publishers.

Wednesday, 11 April 2012

Free Mac malware removal tools (Flashback)

OS X, the operating system that powers modern Apple Mac computers, has been under attack by a threat that may have compromised more than half a million computers.

The Flashback Trojan is possibly the most prevalent malware threat yet unleashed against the Mac. So far Apple has made little comment but recently announced that it would create a tool to detect and remove the threat. It also suggests disabling Java, which seems a rather short-term and inconvenient solution.

Until that tool arrives worried owners can check their systems and remove the threat courtesy of anti-virus companies keen to help and, no doubt, hoping to make a good first impression on a significant new market.

Dr.Web Anti-Flashback online checker
To see if you are infected...

Dr.Web Light Scanner for OS X
(direct download | web page)
...to clean the system, if you are. This is a free anti-virus scanner for OS X.

F-Secure Flashback Removal
(direct download | web page)
Dedicated Flashback removal tool.

Kaspersky Flashfake Removal Tool
(direct download | web page)
Dedicated Flashback removal tool.

Symantec OSX.Flashback.K Removal Tool
(direct download | web  page)
Dedicated Flashback removal tool.

---

UPDATE (12/04/2012): I have uploaded a ten year-old article I wrote about OS X security. Much of it is still relevant today, sadly.

UPDATE (12/04/2012, 1714): Added Symantec OSX.Flashback.K Removal Tool.

UPDATE (13/04/2012, 1058): Apple has announced the Java security update, which takes the extraordinary measure of disabling Java applets. You can turn them on but, if you don't use that feature for an unspecified period of time it will disable them again. I understand the logic of this approach, but it seems a little anti-user rather than anti-malware to me.

Monday, 2 April 2012

UK mass internet monitoring

There are plans for new laws that will allow the UK government to monitor its citizens' phone calls, web site visits and email (incoming and outgoing).

This will, I predict, cost a lot of money and will fail to deliver what you might expect.

Let's put aside the possibly massive abuse of civil liberties that such a scheme invites and focus on how useful it will be for its intended purpose.

Who will pay?

It looks like the Internet Service Providers (ISPs) will be doing the bulk of the work. The additional work will cost money, which will almost certainly be passed to the customers (us).

What will be tracked?

According to the BBC, the system will:
"enable intelligence officers to identify who an individual or group is in contact with, how often and for how long."
My understanding of this is that ISPs will track who receives emails from who, but not the content. So if Individual A (Alan) sends an email to individual B (Brian) then the government can discover this fact, although without necessarily knowing the content of that email.

No doubt IP addresses will be tracked too, adding to the likelihood that Alan really is Alan, and that Brian is Brian.

From the sketchy information available so far it seems that this will allow the government to track fairly low-level criminals who have the technical naivety of Luddites.

Organised criminals have been using 'burner' mobile phones for years, treating their devices as disposable. Buy a phone for cash, set up a free webmail account and it would be tough for anyone to work out if you were Alan, Brian or Ayman Al-Zawahiri.

Rik Ferguson from Trend Micro agrees that dangerous criminals have at least a semblance of security sense:
"If national governments and law enforcement organisations truly believe that online criminals and international terrorists don’t know how to hide their online traces, then we have a bigger problem than we thought (sending an encrypted email with spoofed sender address from an Internet café is only lesson one)."

Thursday, 29 March 2012

Why even experts need antivirus

[This article is written in response to Wired's recent article, Is Antivirus Software a Waste of Money? As is usually the case, when you see a headline posed as a question, the answer is usually "no".]
"I don't run anti-virus, actually," he said, "and I've never had a virus."

"Really?" I asked. "How do you know?"

"I think I'd know," he scoffed.

I had that conversation with the UK head of marketing for an anti-virus company that, while not one of the top brands, is certainly quite well known in Europe. We probably spoke around 2008.

Scroll back to the eighties and possibly even early nineties and he'd probably be at least half right. Viruses might hide for a while but they usually gave away their presence at some stage, possibly by deleting or encrypting files, sending a cheeky message or producing a graphic effect that was hard to ignore.

In the later parts of the nineties things started to change. Malware began to commercialise, and it made sense for these malicious programs to be more subtle. Dialers were one of the first such threats. They resided silently on victims' systems and made phone calls to premium numbers.

Once malware started to hide, the game changed. Without appropriate tools even an expert would not know that a system was infected. Even then, sensible behaviour, such as avoiding pirated software, license key generators and pornography websites was sufficient to avoid most problems.

Halfway through the noughties (around 2005-6) a new approach rendered the classic advice of "be careful" fairly useless.

Criminals started compromising legitimate websites, loading malware from otherwise innocent sites onto visitors' computers. In many cases users would have no idea that this was happening. Even a paranoid expert would have a tough time using the internet in a useful way without exposing their computer to such threats.

Rootkits are also now prevalent. It is hard to detect these threats even with specialised software, let alone some sort of tuned-in, Jedi-like human virus-detector sense.

In Wired's article Is Antivirus Software a Waste of Money? a startup CEO called Dan Guido was quoted as saying, "If it weren’t for [compliance] nobody in the security industry would run [anti-virus]."

I contacted Dan to see if he was happy with the angle of the article. He was, by and large, and claimed that,
"The issue with AV is that their virus detection capabilities only become effective after tens of thousands of people have been compromised with the same virus and days or weeks after that virus was first observed."
Having seen how some anti-malware tackles new attacks, sometimes involving zero day exploits, I don't agree with his blanket statement. He went on to make other very general assumptions about how anti-virus software works. One notable point of view was,
"At the time of infection, every major attack group has procedures that allow it to avoid all the known checks that AV runs through."
In other words, criminals check their malicious software before releasing it, checking to see if anti-virus will catch it. This is certainly true.

Underground versions of VirusTotal-style services exist but I find it hard to believe even the most advanced attacker is capable of running a full end-to-end test to ensure success without alerting the anti-virus vendors.

For example, they must either allow or block cloud service queries. Block these queries and the test is not complete. Allow them and information is fed back about the new threat to the vendor.

I polled a few security professionals, in an admittedly unscientific study, and found that they all used anti-virus. No one believes that anti-virus is a panacea. It's just daft to run without it.

Despite this Lance Spitzner sent me a Twitter message, guessing that maybe experts don't use anti-virus "because most security professionals use a Mac :)" Having been to very many security conferences I have to admit that he has a point.

Wednesday, 28 March 2012

The fake anti-virus business: in pictures

Ever wondered what the point of fake utilities like anti-virus was? Or how online crime really works?

Trend Micro has put together a handy illustration that shows how different criminals work together to steal money from victims.

It's worth noting how the different jobs are split, as is the personal risk of those involved. Plenty of individuals are contributing to the process but only a few are exposed to arrest. These will be the carders and the money mules. You can bet they will be the worst paid of the lot. 

Click on the image to see the larger, readable version.


Tuesday, 27 March 2012

Pirate or puppet?

When you use pirated software or services, are you acting freely or are you being used as a pawn in a larger game?

When the now-failed TV business ITV Digital (aka On Digital) went bust pirates were freely accessing its services using widely-distributed codes. The service failed to make enough money and went under.

The pirates might, in an effort to justify their actions, argue that the services were over-priced. They might claim that information should be free.

They may simply feel that they are going to do what they want and do not care about the consequences.

I have a feeling that any user of 'stolen' services/content would care a great deal if they discovered that they were being manipulated by a large corporation. BBC's Panorama claims to have discovered that this happened in the case of ITV Digital.

The documentary alleges that a News Corporation company called NDS developed a 'hacker' website and encouraged its official owner to distribute set-top access codes for its rival's service.

When ITV Digital implemented counter-measures, the website (www.thoic.com - now closed) was used to distribute information on how to defeat those measures.

If the accusations are correct then those users of the THOIC forums were not only behaving illegally but they were puppets being manipulated by one of the large corporations that they most likely despise.

This same situation could easily apply to some of the media-savvy hacking groups currently making headlines. It is impossible to know who really pulls their strings. It is quite likely that large numbers of members don't even know the answer to that.

The irony is that those who believe they are behaving with more freedom than the rest of us, accessing whatever information and other systems that choose, are not exercising their full right to free choice. They don't have enough information to know whether or not they are working to fulfil someone else's agenda.

They could be unknowing agents of criminals, corporations or even geopolitical adversaries (spies).

It's worth thinking about, before downloading that new, illegal copy of a movie, album or ebook.

[This situation reminds me about a story once told to me by a fairly well-known anti-virus company. It had put a license code for a significant length of time (say nine months or more) on the cover disc of a magazine I once worked for.

Some individuals had leaked this code to an internet forum and the anti-virus vendor had seen a large jump in user numbers. This was in the tens of thousands - I think about 30k. Those who distributed the code obviously felt that they had got one over on "the man".

This attitude became more evident when the company decided to 'leak' more of its codes to the internet on purpose. The forum distributed these semi-legitimate codes for a while before realising that it was being influenced by the company it was trying to rip off. It then removed the codes from its site, unhappy that it was being tricked.

I suppose that the thrill of stealing disappears once you know that the apparent victim is glad that you are a potential customer merely sampling the goods.]

Monday, 26 March 2012

Video: Microsoft raids hosting company

The first 45 seconds are the most interesting to my mind, mainly because you see the raid, albeit one without much physical resistance.


The rest of the footage is only interesting if the idea of internet crime is news to you.

How many dollars is a 'Like' worth?

Criminals are selling Facebook recommendations (by clicking the Like button) for $27 per 1,000 'Like's.

Companies that wish to increase their visibility by promoting their profiles can pay individuals or groups to click the Like button using multiple accounts.

The particularly sinister part to this story is that the criminals don't set up lots of their own accounts. They have found it more efficient to take over victims' accounts and abuse those instead.

In a post on Kaspersky Labs' blog, which actually focusses on a security issue with Google Chrome extensions, Fabio Assolini notes that an extension called Trojan.JS.Agent.bxo is hosted on the official Google Chrome Web Store.

The malicious extension gains control of the victim's Facebook profile. Among other features, including the inevitable ability to spread itself, "the script also has commands to use the profile of the victim to 'Like' some pages."

The reason for this ability is to make money. Fabio includes a screenshot from a website that clearly offers a Likes-for-cash service.

Friday, 23 March 2012

0-day a criminal or media obsession?

[0-day (ō dā) n. 1. A generally undisclosed security hole in software.]

1. Do criminals, spies and cyber-warriors want to know about zero day (0-day) vulnerabilities?

- Undoubtedly.

2. Do they spend vast amount of time seeking them out and developing exploits?

- Doubtful.

Which of  the two statements above is more exciting for a journalist to follow up on?

I'd say the first. The concept of shady organisations knowing something that no one else does, and then using that knowledge to perform movie-style techno-magic is intriguing.

The truth, depending on who you talk to and believe, is altogether more mundane.

Earlier this year, at the Kaspersky Threatpost Security Analyst Summit, I was talking to Greg Hoglund about targeted attacks. You might imagine that this type of attack would be at the cutting edge of malware. However, Greg said that, "a lot of what we see is not 0-day. The victims aren't patching."

(left to right) Greg Hoglund, Simon Edwards,
Paul Judge, Karthik Raman and Terry McCorkle

This makes complete sense when you understand that criminals and others are having plenty of success using fairly well-known threats. Why run when you are not being chased?

Dancho Danchev has compiled a sound analysis of the situation in his article Seven myths about zero day vulnerabilities debunked.

[How many people have to know about an 0-day before it's not an 0-day any more?]

Thursday, 12 January 2012

Stupid QR code scam

Websense has released details of spammers using QR codes in what appears to be one of the least imaginative and, quite possibly, most ineffective scams I've seen in a long time.

The Register picked up on the story a couple of days later, yesterday.

QR threat or PR effort?

Why is this a stupid scam? Because no one is going to fall for it. It is only interesting to the media because it uses QR codes, which have the potential for causing havoc.

But this is not a case of havoc-making but rather publicity-making.

QR codes are potentially dangerous for two main reasons:

  1. They can direct unwary users to sites they don't want to visit.
  2. They open a route for an attacker to compromise the system running the QR code scanner.
As we will see, Option 1 is relevant to this story. Option 2 is not.

Option 1 works along the same lines as TinyURL and the many other URL-shortening (and obscuring) services that are available. They are very useful but ultimately provide a way for someone to access a URL without really knowing where they will end up until the site is loaded into their browser.

Obscuring URLs

When you use a URL-shortening service like TinyURL or goo.gl you take one URL and turn it into another, much shorter one. Thus, you can convert
into

This is ideal for using in Twitter posts, where the number of characters allowed in each message is very limited.

However, the URL http://goo.gl/DKRoa gives no clue as to where you will end up. The longer http://simonedwards.blogspot.com URL will indicate to any potential visitor that they about to visit a blog written by someone called Simon Edwards.

QR codes are similar, although they are primarily designed for mobile devices. Rather than typing in http://simonedwards.blogspot.com using a barely usable virtual keyboard, phone users can scan in an image such as the one used at the top of this article.

This will take them to a site, but which one? Until you scan it in you don't know. The one above links to this blog. Or does it? Try it, if you trust me...

Why is this scam useless?

The QR code sits next to
the destination URL
A QR code scam only works if people don't know what site they are going to visit. In the case discussed by Websense the actual URL appears next to the QR code.

So there is no scam here beyond publishing a URL to a pharmaceutical site, in clear text, within a spam email message.

The article from Websense is disappointing because there are plenty of significant scams around, and there is plenty of potential for the bad guys to abuse QR codes. It would be better to concentrate on those rather than to attempt name-checks in the media for what amounts to a non-issue.

25 years of computer viruses in pictures

F-Secure has produced a graphical summary that shows some of the most talked-about computer viruses.

You can view the entire 'infographic' or download a high-resolution version from F-Secure's blog.

To summarise, quickly, the history starts with Brain; runs through the likes of Melissa, Code Red and Love Letter (aka ILoveYou); and concludes with Stuxnet and Conficker.

Interestingly the chart includes Sony's used of rootkit-like technology. This not a virus, but uses an approach also used by some malware. Additionally, many of the other threats are actually worms rather than viruses.