Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, December 28, 2012

Malware that steals from point-of-sale systems detected

A data stealer designed to collect users' personally identifiable information from point-of-sale (POS) systems has been detected.

Research by Trend Micro said that the malware was found in POS systems at hotels and other businesses. “Currently, the arrival infector remains undetermined,” said Jason Pantig, senior threat response engineer at the Tokyo-based security software company. However, it is unlikely that the malware is downloaded from malicious sites, as the POS systems are typically not used for web browsing.

Point-of-sale terminals are typically where payment for goods and services occur, Pantig said. "Given the wealth of data found on these payment hubs, it's expected that these are the next targets of cyber criminal activities.”

The company's analysis determined that BKDR_DEXTR.A, also known as Dexter, downloads files, sends information and checks memory for information, among other tasks.
“The center piece of the malware is its ability to collect and send certain information to a remote server,” said Pantig. Some of the data that can be stolen from POS systems includes username, hostnames, a key to decrypt the sent information, OS information and a list of running processes, he said.

This data is then presumably duplicated by remote malicious users. "The malware executable is found to be packed or encrypted and when loaded, it loads long garbage code to decrypt the actual code," he said. However, this decryption routine involves only a combination of XOR and ADD instructions, with the use of a hardcoded key. The perpetrators behind Dexter malware probably did this to make analysis difficult, he added.

Trend Micro further said that unlike other spyware, like Zeus and SpyEye, this malware does not directly infect users' systems to gather data, such as payment card details. “Instead, the crooks behind BKDR_DEXTR figured that they can generate the same result by infecting certain POS systems,” Pantig said.

* Thanks to scmagazine.com

Thursday, September 27, 2012

POS Hackers Sentenced for Multi-Million Dollar Payment Card Data Theft

Two Romanian nationals have plead guilty for participating in an international, multimillion-dollar scheme to remotely hack into and steal payment card data from hundreds of U.S. merchants’ computers, including a great number of Subway restaurants. Federal prosecutors noted that the conspiracies involved more than 146,000 compromised cards and more than $10 million in losses.
Iulian Dolan and Cezar Butu agreed to serve seven year and 21 month prison sentences respectively. Dolan, 28, of Craiova, Romania, pleaded guilty to one count of conspiracy to commit computer fraud and two counts of conspiracy to commit access device fraud, while Butu, 27, of Ploiesti, Romania, pleaded guilty to one count of conspiracy to commit access device fraud. A third co-conspirator, Adrian-Tiberiu Oprea, is currently awaiting trial in New Hampshire. The defendants admitted in their guilty pleas, that during a period roughly from in or about 2009-2011, they participated in Romanian-based conspiracies, to hack into hundreds of U.S.-based computers to steal credit, debit and payment account numbers and associated data. They then used the stolen payment card data to make unauthorized charges on, and/or transfers of funds from, those accounts (or alternatively to transfer the stolen payment card data to other co-conspirators who would do the same).       
The official judgment is a warning signal to all operators concerning POS security and describes how the hackers carried out the scheme. According to the official judgement, Dolan admitted that he, along with Oprea, remotely hacked into U.S. merchants’ point of sale (POS) where customers’ payment card data was electronically stored.
“Specifically, Dolan first remotely scanned the internet to identify U.S.-based vulnerable POS systems with certain remote desktop software applications (RDAs) installed on them. Using these RDAs, Dolan logged onto the targeted POS systems over the internet. These were typically password-protected, so Dolan would attempt to crack the passwords, where necessary, to gain administrative access. He would then remotely install software programs called ‘keystroke loggers’ (or ‘sniffers’) onto the POS systems. These programs would record, and then store, all of the data that was keyed into or swiped through the merchants’ POS systems, including customers’ payment card data.”
               
The co-conspirators hacked into several hundred U.S. merchants’ POS systems. It was reported that Dolan stole payment card data belonging to approximately 6,000 cardholders and was aware that Oprea was engaged in similar conduct. Dolan would periodically remotely hack back into the compromised merchants’ POS system to retrieve the card data that he would transfer to electronic “dump sites,” where the data would then be used to make unauthorized chargers and transfers or sold to other conspirators.
“The Subway case is a clear indication that privileged and administrative accounts are increasingly targeted and used by criminals to steal sensitive information,” says Adam Bosnian, vice president of products, strategy and sales at Cyber-Ark Software www.cyber-ark.com.  “In this case, the attackers were able to simply do an Internet search for remote desktop applications that were used by the restaurants, and through simple password cracking techniques, they were able to gain administrative access to the systems.  This enabled them to easily steal sensitive financial information from unsuspecting customers.”
Bosnian contends that often sensitive accounts are protected by passwords that are too simple or default passwords that are rarely changed. This case is a warning to operators utilizing POS systems to shore up their security by taking steps to make their accounts more difficult to breach and therefore less attractive to hackers.
“These privileged and administrative accounts act as a gateway to any organization’s most sensitive information, which is why they’ve emerged as the primary target for attackers,” Bosnian continues, “The reality is that anyone with an Internet connection can search for, identify and target  remote applications that businesses rely on – the problem facing the industry is that there is not sufficient security and protection around the entry points to these applications. Once inside, attackers have free reign on the network. If you examine the list of the recent, high-profile data breaches that have plagued organizations, including Global Payments, the U.S. Chamber of Commerce, the Utah healthcare breach, etc…, the common denominator is that the attackers focused on gaining access to the privileged or administrative accounts.” 

- Thanks to HT

Thursday, January 21, 2010

The Darker Side of Cloud Computing

We've been hearing about "computing in the cloud" for some time now. Sounds fluffy... peaceful... idyllic... effortless. Wake up, people! Cloud computing is just another term for outside your control.

Cloud computing is a marketing buzzword that's thrown around an awful lot today. A vague (but useful) definition is that cloud computing refers to data, processing, or experiences that "live" out there somewhere in the cloud we call the Internet. Everyone's got something going on in the cloud these days: collocating or hosting Web or e-mail servers, social networking, software as a service (SaaS), even infrastructure as a service (for example, off-site online storage). Cloud computing is becoming very popular, primarily as a money-saving technique—cloud services don't require expensive in-house hardware, software, and staff. In addition, cloud services are usually available for a small monthly fee rather than a huge up-front expense, which makes them even more attractive from a budgeting standpoint. Like many things that seem to have only an upside, cloud computing makes me nervous.

The cloud is burgeoning. Businesses are using Salesforce.com for CRM; Zoho, Microsoft Office Live, and Google Apps for office productivity; Intuit QuickBase or a hosted Microsoft SQL Server for databases—and the list goes on. More features, less expense, and fewer IT resources? It almost sounds too good to be true. And it may be. Much the way in the early eighties we asked "Where's the beef?" we should now be asking "Where's the security?"

To secure data, you need to understand something I like to call the data life cycle: How data is collected, entered, processed, transmitted, stored, reported, and exported. Any one of these stages may contain multiple vulnerabilities, some ubiquitous and some particular to your environment. To assess the security of corporate data, you'll have to understand the risks that apply to each stage of the data life cycle. You will be able to take proactive steps to prevent data from being compromised by understanding the integration of security risks, business processes, and the data life cycle.

By now you are probably beginning to see the downside to cloud computing—it's difficult enough to protect data that doesn't leave your control as part of ordinary business, but in the cloud you've relinquished control. Depending on your contract, you may not even own your cloud-resident data! And worse, there are clouds within the cloud—your provider may subcontract with another provider for data storage, and that provider might also subcontract for data storage management. Your provider may not even be able to tell you where your data is, or even which country it is in and whether the laws that apply to you regarding data security and breach disclosure even apply in that twice-removed jurisdiction.

Gartner published a great report in early June that is the industry's first attempt to identify the security risks of cloud computing. In it, Gartner urges something that we at PC Magazine have been advocating for decades: full disclosure (aka "transparency") with regard to security practices and procedures. The reasoning is simple: If your provider can't tell you exactly what it does to protect your data at each stage of the data life cycle, then how good a job do you think that provider is doing?

What other recommendations spring from Gartner's findings?

  • Apply internal risk assessment and controls to all externally sourced (cloud) services.
  • Assess all legal, regulatory, and audit issues associated with location independence and service subcontracting.
  • Demand transparency. Anything less is a deal breaker! Don't contract for IT services with a vendor that refuses to provide detailed information on its security and continuity management programs.

Yes, cloud computing is a set of powerful technology solutions that are here to stay. It provides cost savings that may temporarily blind you to the risks. But don't dive in simply to save money and time. Evaluate each service's security the same way you would evaluate off-the-shelf hardware and software. Ask tough questions about data security. If your provider refuses to answer, or his answer doesn't adhere to your current security policy, look elsewhere. I've sat through countless vendor meetings and I guarantee you this: Every time a security concern is dismissed as "taken care of" without explanation, it's a potential problem.

Thanks to pcmag.com