Showing all posts tagged "Cuda Blog Ideas"
Podcast: Inside Microsoft's Efforts to Fight Against Botnets | SecurityWeek.Com
Inside Microsoft's Efforts to Fight Against Botnets (27:30)
Date: November 15, 2013
By: Security Conversations
Description: In this edition of Security Conversations, Ryan Naraine is joined by Richard Boscovich , assistant general counsel in the Microsoft Digital Crimes Unit to talk about the new Microsoft Cybercrime Center and the ongoing battle to stop the proliferation of botnets around the world.
Microsoft Opens High Tech Cybercrime Center
By Mike Lennon on November 14, 2013
Microsoft said Thursday that it has opened a new cybercrime center that combines the software giant's legal and technical expertise along with cutting-edge tools and technology and cross-industry expertise to combat cyber crime.
Located at Microsoft's campus in Redmond, Washington, the center houses technologies that enable teams to visualize and identify global cyberthreats developing in real time, including SitePrint, which allows the mapping of online organized crime networks; PhotoDNA, a leading anti-child-pornography technology; cyberforensics, a new investigative capability that detects global cybercrime, including online fraud and identity theft; and cyberthreat intelligence from Microsoft’s botnet takedown operations.
The Cybercrime Center also has a secure location for third-party partners, including from academia and law enforcement, allowing cybersecurity experts from around the world to work in the facility with Microsoft’s experts for an indefinite period of time.
“With nearly 100 attorneys, investigators, technical experts and forensic analysts based around the world, the Microsoft Cybercrime Center is well positioned to make it safer for people online worldwide," Microsoft said in a statement.
“In the fight against cybercrime the public sector significantly benefits from private sector expertise, such as provided by Microsoft," said Noboru Nakatani, executive director of the INTERPOL Global Complex for Innovation. “The security community needs to build on its coordinated responses to keep pace with today’s cybercriminals. The Microsoft Cybercrime Center will be an important hub in accomplishing that task more effectively and proactively."
Microsoft produced the video below which explains more about the new Cybercrime Center .
Posted on December 10th, 2013
11 sure signs you've been hacked - Network World
11 sure signs you've been hacked
InfoWorld - In today's threatscape, antivirus software provides little piece of mind. In fact, antimalware scanners on the whole are horrifically inaccurate, especially with exploits less than 24 hours old. After all, malicious hackers and malware can change their tactics at will . Swap a few bytes around, and a previously recognized malware program becomes unrecognizable.
To combat this, many antimalware programs monitor program behaviors, often called heuristics, to catch previously unrecognized malware. Other programs use virtualized environments, system monitoring, network traffic detection, and all of the above at once in order to be more accurate. And still they fail us on a regular basis.
[ Verse yourself in the 7 sneak attacks used by today's most devious hackers , 14 dirty IT security consultant tricks , 9 popular IT security practices that just don't work , and 10 crazy security tricks that do . | Learn how to secure your systems with the Web Browser Deep Dive PDF special report and Security Central newsletter , both from InfoWorld. ]
Here are 11 sure signs you've been hacked and what to do in the event of compromise. Note that in all cases, the No. 1 recommendation is to completely restore your system to a known good state before proceeding. In the early days, this meant formatting the computer and restoring all programs and data. Today, depending on your operating system, it might simply mean clicking on a Restore button. Either way, a compromised computer can never be fully trusted again. The recovery steps listed in each category below are the recommendations to follow if you don't want to do a full restore -- but again, a full restore is always a better option, risk-wise.
Sure sign of system compromise No. 1: Fake antivirus messages
In slight decline these days, fake antivirus warning messages are among the surest signs that your system has been compromised. What most people don't realize is that by the time they see the fake antivirus warning, the damage has been done. Clicking No or Cancel to stop the fake virus scan is too little, too late. The malicious software has already made use of unpatched software, often the Java Runtime Environment or an Adobe product, to completely exploit your system.
Why does the malicious program bother with the "antivirus warning"? This is because the fake scan, which always finds tons of "viruses," is a lure to buy their product. Clicking on the provided link sends you to a professional-looking website, complete with glowing letters of recommendation. There, they ask you for your credit card number and billing information. You'd be surprised how many people get tricked into providing personal financial information. The bad guys gain complete control of your system and get your credit card or banking information. For bad guys, it's the Holy Grail of hacking.
What to do: As soon as you notice the fake antivirus warning message, power down your computer. (Note: This requires knowing what your legitimate antivirus program's warning looks like.) If you need to save anything and can do it, do so. But the sooner you power off your computer, the better. Boot up the computer system in Safe Mode, No Networking, and try to uninstall the newly installed software (oftentimes it can be uninstalled like a regular program). Either way, follow up by trying to restore your system to a state previous to the exploitation. If successful, test the computer in regular mode and make sure that the fake antivirus warnings are gone. Then follow up with a complete antivirus scan. Oftentimes, the scanner will find other sneak remnants left behind.
Posted on December 10th, 2013
Facebook users warned of leaked Snapchat photos phishing threat
http://grahamcluley.com/2013/12/facebook-users-warned-leaked-snapchat-photos-phishing-threat/?utm_source=rss&utm_medium=rss&utm_campaign=facebook-users-warned-leaked-snapchat-photos-phishing-threat
Facebook pages claiming to link to leaked photos distributed via the Snapchat smartphone app can be attempting to steal your passwords. Be on your guard, and warn your friends to be more careful about what they "Like".
IT Security
via Graham Cluley http://grahamcluley.com
December 03, 2013 at 05:36AM
Posted on December 3rd, 2013
How to Crack a Wi-Fi Network's WPA Password with Reaver
How to Crack a Wi-Fi Network's WEP Password with BackTrack
You already know that if you want to lock down your Wi-Fi network, you should opt for WPA encryption because WEP is easy to crack. But did you know… Read…
Your Wi-Fi network is your conveniently wireless gateway to the internet, and since you're not keen on sharing your connection with any old hooligan who happens to be walking past your home, you secure your network with a password, right? Knowing, as you might, how easy it is to crack a WEP password, you probably secure your network using the more bulletproof WPA security protocol. P
Here's the bad news: A new, free, open-source tool called Reaver exploits a security hole in wireless routers and can crack most routers' current passwords with relative ease. Here's how to crack a WPA or WPA2 password, step by step, with Reaver—and how to protect your network against Reaver attacks. P
In the first section of this post, I'll walk through the steps required to crack a WPA password using Reaver. You can follow along with either the video or the text below. After that, I'll explain how Reaver works, and what you can do to protect your network against Reaver attacks. P
First, a quick note: As we remind often remind readers when we discuss topics that appear potentially malicious: Knowledge is power, but power doesn't mean you should be a jerk, or do anything illegal. Knowing how to pick a lock doesn't make you a thief. Consider this post educational, or a proof-of-concept intellectual exercise. The more you know, the better you can protect yourself.
What You'll Need P
You don't have to be a networking wizard to use Reaver, the command-line tool that does the heavy lifting, and if you've got a blank DVD, a computer with compatible Wi-Fi, and a few hours on your hands, you've got basically all you'll need. There are a number of ways you could set up Reaver, but here are the specific requirements for this guide: P
- The BackTrack 5 Live DVD. BackTrack is a bootable Linux distribution that's filled to the brim with network testing tools, and while it's not strictly required to use Reaver, it's the easiest approach for most users. Download the Live DVD from BackTrack's download page and burn it to a DVD. You can alternately download a virtual machine image if you're using VMware, but if you don't know what VMware is, just stick with the Live DVD. As of this writing, that means you should select BackTrack 5 R3 from the Release drop-down, select Gnome, 32- or 64-bit depending on your CPU (if you don't know which you have, 32 is a safe bet), ISO for image, and then download the ISO. P
- A computer with Wi-Fi and a DVD drive. BackTrack will work with the wireless card on most laptops, so chances are your laptop will work fine. However, BackTrack doesn't have a full compatibility list, so no guarantees. You'll also need a DVD drive, since that's how you'll boot into BackTrack. I used a six-year-old MacBook Pro. P
- A nearby WPA-secured Wi-Fi network. Technically, it will need to be a network using WPA security with the WPS feature enabled. I'll explain in more detail in the "How Reaver Works" section how WPS creates the security hole that makes WPA cracking possible. P
- A little patience. This is a 4-step process, and while it's not terribly difficult to crack a WPA password with Reaver, it's a brute-force attack, which means your computer will be testing a number of different combinations of cracks on your router before it finds the right one. When I tested it, Reaver took roughly 2.5 hours to successfully crack my password. The Reaver home page suggests it can take anywhere from 4-10 hours. Your mileage may vary. P
Let's Get Crackin' P
At this point you should have BackTrack burned to a DVD, and you should have your laptop handy. P
Step 1: Boot into BackTrack P
To boot into BackTrack, just put the DVD in your drive and boot your machine from the disc. (Google around if you don't know anything about live CDs/DVDs and need help with this part.) During the boot process, BackTrack will prompt you to to choose the boot mode. Select "BackTrack Text - Default Boot Text Mode" and press Enter. P
Eventually BackTrack will boot to a command line prompt. When you've reached the prompt, type
startx
and press Enter. BackTrack will boot into its graphical interface. P
Step 2: Install Reaver P
Update: This step is no longer necessary, as Reaver comes pre-installed on Backtrack 5 R3. Skip down to Step 3. P
Reaver has been added to the bleeding edge version of BackTrack, but it's not yet incorporated with the live DVD, so as of this writing, you need to install Reaver before proceeding. (Eventually, Reaver will simply be incorporated with BackTrack by default.) To install Reaver, you'll first need to connect to a Wi-Fi network that you have the password to. P
- counter(item, decimal) .
- Click Applications > Internet > Wicd Network Manager
- counter(item, decimal) .
- Select your network and click Connect, enter your password if necessary, click OK, and then click Connect a second time.
Now that you're online, let's install Reaver. Click the Terminal button in the menu bar (or click Applications > Accessories > Terminal). At the prompt, type: P
apt-get update P
And then, after the update completes: P
apt-get install reaver P
If all went well, Reaver should now be installed. It may seem a little lame that you need to connect to a network to do this, but it will remain installed until you reboot your computer. At this point, go ahead and disconnect from the network by opening Wicd Network Manager again and clicking Disconnect. (You may not strictly need to do this. I did just because it felt like I was somehow cheating if I were already connected to a network.) P
Step 3: Gather Your Device Information, Prep Your Crackin' P
In order to use Reaver, you need to get your wireless card's interface name, the BSSID of the router you're attempting to crack (the BSSID is a unique series of letters and numbers that identifies a router), and you need to make sure your wireless card is in monitor mode. So let's do all that. P
Find your wireless card: Inside Terminal, type: P
iwconfig P
Press Enter. You should see a wireless device in the subsequent list. Most likely, it'll be named
wlan0
, but if you have more than one wireless card, or a more unusual networking setup, it may be named something different. P
Put your wireless card into monitor mode: Assuming your wireless card's interface name is
wlan0
, execute the following command to put your wireless card into monitor mode: P
airmon-ng start wlan0 P
This command will output the name of monitor mode interface, which you'll also want to make note of. Most likely, it'll be
mon0
, like in the screenshot below. Make note of that. P
Find the BSSID of the router you want to crack: Lastly, you need to get the unique identifier of the router you're attempting to crack so that you can point Reaver in the right direction. To do this, execute the following command: P
airodump-ng wlan0 P
(Note: If
airodump-ng wlan0
doesn't work for you, you may want to try the monitor interface instead—e.g.,
airodump-ng mon0
.) P
You'll see a list of the wireless networks in range—it'll look something like the screenshot below: P
When you see the network you want, press Ctrl+C to stop the list from refreshing, then copy that network's BSSID (it's the series of letters, numbers, and colons on the far left). The network should have WPA or WPA2 listed under the ENC column. (If it's WEP, use our previous guide to cracking WEP passwords.) P
Now, with the BSSID and monitor interface name in hand, you've got everything you need to start up Reaver. P
Step 4: Crack a Network's WPA Password with Reaver P
Now execute the following command in the Terminal, replacing
bssid
and
moninterface
with the BSSID and monitor interface and you copied down above: P
reaver -i moninterface -b bssid -vv P
For example, if your monitor interface was
mon0
like mine, and your BSSID was
8D:AE:9D:65:1F:B2
(a BSSID I just made up), your command would look like: P
reaver -i mon0 -b 8D:AE:9D:65:1F:B2 -vv P
Press Enter, sit back, and let Reaver work its disturbing magic. Reaver will now try a series of PINs on the router in a brute force attack, one after another. This will take a while. In my successful test, Reaver took 2 hours and 30 minutes to crack the network and deliver me with the correct password. As mentioned above, the Reaver documentation says it can take between 4 and 10 hours, so it could take more or less time than I experienced, depending. When Reaver's cracking has completed, it'll look like this: P
S Expand
A few important factors to consider: Reaver worked exactly as advertised in my test, but it won't necessarily work on all routers (see more below). Also, the router you're cracking needs to have a relatively strong signal, so if you're hardly in range of a router, you'll likely experience problems, and Reaver may not work. Throughout the process, Reaver would sometimes experience a timeout, sometimes get locked in a loop trying the same PIN repeatedly, and so on. I just let it keep on running, and kept it close to the router, and eventually it worked its way through. P
Also of note, you can also pause your progress at any time by pressing Ctrl+C while Reaver is running. This will quit the process, but Reaver will save any progress so that next time you run the command, you can pick up where you left off-as long as you don't shut down your computer (which, if you're running off a live DVD, will reset everything). P
How Reaver Works P
Now that you've seen how to use Reaver, let's take a quick overview of how Reaver works. The tool takes advantage of a vulnerability in something called Wi-Fi Protected Setup, or WPS. It's a feature that exists on many routers, intended to provide an easy setup process, and it's tied to a PIN that's hard-coded into the device. Reaver exploits a flaw in these PINs; the result is that, with enough time, it can reveal your WPA or WPA2 password. P
Read more details about the vulnerability at Sean Gallagher's excellent post on Ars Technica. P
How to Protect Yourself Against Reaver Attacks P
Since the vulnerability lies in the implementation of WPS, your network should be safe if you can simply turn off WPS (or, even better, if your router doesn't support it in the first place). Unfortunately, as Gallagher points out as Ars, even with WPS manually turned off through his router's settings, Reaver was still able to crack his password. P
In a phone conversation, Craig Heffner said that the inability to shut this vulnerability down is widespread. He and others have found it to occur with every Linksys and Cisco Valet wireless access point they've tested. "On all of the Linksys routers, you cannot manually disable WPS," he said. While the Web interface has a radio button that allegedly turns off WPS configuration, "it's still on and still vulnerable. P
So that's kind of a bummer. You may still want to try disabling WPS on your router if you can, and test it against Reaver to see if it helps. P
You could also set up MAC address filtering on your router (which only allows specifically whitelisted devices to connect to your network), but a sufficiently savvy hacker could detect the MAC address of a whitelisted device and use MAC address spoofing to imitate that computer. P
Double bummer. So what will work? P
I have the open-source router firmware DD-WRT installed on my router and I was unable to use Reaver to crack its password. As it turns out, DD-WRT does not support WPS, so there's yet another reason to love the free router-booster. If that's got you interested in DD-WRT, check their supported devices list to see if your router's supported. It's a good security upgrade, and DD-WRT can also do cool things like monitor your internet usage, set up a network hard drive, act as a whole-house ad blocker, boost the range of your Wi-Fi network, and more. It essentially turns your $60 router into a $600 router. P
How to Monitor Your Internet Usage So You Don't Exceed Your Data Cap
Internet data caps are becoming a reality and can seriously suck. If you're stuck with the limitation, the best thing you can do is monitor your … Read…
Get More Out of Your DD-WRT Router with an External Drive
You've supercharged your router with DD-WRT, you're using it to monitor your bandwidth use, and yet you still wish it could do more. Well… Read…
Further Reading P
Thanks to this post on Mauris Tech Blog for a very straightforward starting point for using Reaver. If you're interested in reading more, see: P
- Ars Technia's hands on P
- This Linux-centric guide from Null Byte P
- The Reaver product page (it's also available in a point-and-click friendly commercial version. P
Reddit user jagermo (who I also spoke with briefly while researching Reaver) has created a public spreadsheat intended to build a list of vulnerable devices so you can check to see if your router is susceptible to a Reaver crack. P
Have any experience of your own using Reaver? Other comments or concerns? Let's hear it in the comments. P
Posted on November 27th, 2013
Something you know v something you have
Posted on November 27th, 2013
IT Best Practices: The Polarity of Security and Privacy | Connected Social Media
IT Best Practices: The Polarity of Security and Privacy
For more information on Intel IT best practices , please visit www.intel.com/IT
IT Best Practices : Security and privacy are like magnets. When they are turned in the right direction they are perfectly binding. But if one starts turning, they start to push away from each other. Listen to Malcolm Harkins, Intel Chief Security and Privacy Officer, discuss how organizations can manage the polarity of security and privacy with collaboration and a balanced approach.
Related posts:
- IT Best Practices: The 21st Century CISO (Chief Information Security Officer) IT Best Practices: From the book “Managing Risk and Information Security: Protect to Enable" by Malcolm Harkins As the technology environment continues to evolve, many people believe we’re moving toward a future in which organizations outsource much of the delivery...
- Inside IT: Malcolm Harkins – Business Velocity in the Changing Security Landscape IT Best Practices: Episode 61 – In this podcast we engage in a wide-ranging discussion on business velocity, security, and privacy with Intel’s Malcolm Harkins. Harkins has a unique view from his position as the Chief Security and Privacy Officer...
- Inside IT: Security and Business Intelligence IT Best Practices: Episode 45 – Intel’s approach to security has evolved. The current strategy looks to apply reasonable protections that allow information to flow through the organization. This reduces risk, but maintains a quality user experience. A big component...
- Intel IT Best Practices: Rethinking Information Security with Intel CISO In this short IT Security vblog, Malcolm Harkins, Intel CISO, talks about why Intel IT has undertaken a radical new five-year redesign of our information security architecture. Malcolm says that compromise is inevitable under almost any compute model, find out...
- IT Best Practices: Rethink Privacy IT Best Practices: Consumers care about privacy, is your company or organization paying attention? This video shows why companies and organizations should incorporate privacy early in their design, development, and deployment process – whether they’re working on products, programs or...
- IT Best Practices: Information Security and Cloud Computing Intel CISO, Malcolm Harkins shares his perspective on security and the cloud. ...
- Inside IT: Stopping Viruses and Threats IT Best Practices: Episode 15 – Information Technology has changed dramatically in just a few years, and the security threat has changed along with it. The opportunities for bad actors to infiltrate an organization have grown, and the nature of...
- Intel IT Best Practices: Intel CISO Discusses Misperception of Risk Intel CISO, Malcolm Harkins believes that underestimating or over exaggerating risk is one of the biggest vulnerabilities we face. Watch this short vblog to hear Malcolm’s explanation. ...
- IT Best Practices: Intel IT Embraces Social Computing Intel CISO, Malcolm Harkins suggests we embrace social media and social computing to reduce risk. ...
- IT Best Practices: Protecting the Perimeter IT Best Practices: From the book “Managing Risk and Information Security: Protect to Enable" by Malcolm Harkins At Intel, we are well aware of the risks associated with social media, but attempting to stop the use of external social media...
Posted in: Corporate , Featured , HD Video , Information Technology , Intel , Intel IT , IT@Intel , Security , Video Podcast
Tags: data security , governance , information security , information technology , Intel , Intel IT , IT Best Practices , IT Business Value , IT Whitepaper , IT@Intel , Malcolm Harkins , privacy , privacy principles , protect to enable
Posted on November 27th, 2013