Monday, September 5, 2011

Operation Black Tulip Report: DigiNotar Certificate Authority Breach

http://www.rijksoverheid.nl/ministeries/bzk/documenten-en-publicaties/rapporten/2011/09/05/diginotar-public-report-version-1.html

Background

The company DigiNotar B.V. provides digital certificate services; it hosts a number of Certificate Authorities (CA‟s). Certificates issued include default SSL certificates, Qualified Certificates and „PKIoverheid‟ (Government accredited) certificates.

On the evening of Monday August 29th it became public knowledge that a rogue *.google.com certificate was presented to a number of Internet users in Iran. This false certificate had been issued by DigiNotar B.V. and was revoked1 that same evening.

On the morning of the following Tuesday, Fox-IT was contacted and asked to investigate the breach and report its findings before the end of the week.

Fox-IT assembled a team and started the investigation immediately. The investigation team includes forensic IT experts, cybercrime investigators, malware analysts and a security expert with PKI experience. The team was headed by CEO J.R. Prins directly.

It was communicated and understood from the outset, that Fox-IT wouldn't be able to complete an in- depth investigation of the incident within this limited timeframe. This is due to the complexity of the PKI environment and the uncommon nature of the breach.

Rather, due to the urgency of this matter, Fox-IT agreed to prepare an interim report at the end of the week with its preliminary findings, which would be published.


-------------------------------------------------------------------------------------

Diginotar Investigation:
Visualisation of OCSP requests for the rogue *.google.com certificate by Fox-IT
http://www.youtube.com/watch?v=wZsWoSxxwVY

-------------------------------------------------------------------------------------

Here are a couple of statements in the report that catch my eye:

  • Page 8 - "On August 4th the number of request rose quickly until the certificate was revoked on August 29th at 19:09. Around 300.000 unique requesting IPs to google.com have been identified. Of these IPs >99% originated from Iran."
  • Page 9 - "In at least one script, fingerprints from the hacker are left on purpose, which were also found in the Comodo breach investigation of March 2011."
  • Page 9 - "The list of domains and the fact that 99% of the users are in Iran suggest that the objective of the hackers is to intercept private communications in Iran.
  • Page 9 - "The most critical servers contain malicious software that can normally be detected by anti-virus software."
  • Page 9 - " The software installed on the public web servers was outdated and not patched. No antivirus protection was present on the investigated servers."    

Why Al Qaeda is Unlikely to Execute Another 9/11

Via STRATFOR (Security Weekly) -

It is Sept. 1, and that means we are once again approaching the anniversary of al Qaeda’s Sept. 11, 2001, attacks against the United States. In the 10 years that have passed since the attacks, a lot has happened and much has changed in the world, but many people can still vividly recall the sense of fear, uncertainty and helplessness they felt on that September morning. Millions of people watched United Airlines flight 175 smash into the south tower of the World Trade Center on live television. A short while later they heard that another plane had struck the Pentagon. Then they watched in horror as the World Trade Center’s twin towers buckled and collapsed to the ground.

It was, by any measure, a stunning, cataclysmic scene, a kind of terrorist theater that transformed millions of television viewers into vicarious victims. Excerpts of the just-released memoir of then-Vice President Dick Cheney demonstrate that it was not just ordinary people who were affected by the attacks; America’s leaders where shocked and shaken, too. And judging from the statements of foreign citizens and leaders in the wake of 9/11, those who proclaimed, “We are all Americans,” it was also apparent that the toll on vicarious victims did not stop at the U.S. border.

[...]

Fast forward a decade and we are now commemorating 9/11’s 10th anniversary, which seems more significant somehow because it is a round number. Perhaps of more meaningful significance is that this anniversary closely follows the death of al Qaeda leader Osama Bin Laden on May 2, 2011. Indeed, the buzz regarding this coincidence has caused many of our clients and readers to ask for our assessment of the terrorist threat inside the United States on this 10th anniversary of 9/11.

While we believe that today holds some degree of symbolism for many, the threat of an attack on Sept. 11, 2011, is no higher than it was on Aug. 11 or than it will be on Sept. 12, and below we explain why.


----------------------------------------------------------

An excellent read for anyone interested in the current capability of AQ inside the US.

Diginotar: Iranians – The Real Target

Via TrendLabs Malware Blog -

In this blog posting, we present concrete evidence that the recent compromise of Dutch Certification Authority Diginotar was used for spying on Iranian Internet users on a large scale.

We found that Internet users in more than 40 different networks of ISPs and universities in Iran were confronted with rogue SSL certificates issued by Diginotar. Even worse: we found evidence that some Iranians who used software designed to circumvent censorship and snooping on traffic were not protected against the massive man-in-the-middle attack.

[...]

On August 29 2011, the rogue Google.com SSL certificate issued by Diginotar was discovered. This rogue certificate makes snooping on Gmail traffic possible in man-in-the-middle attacks. Trend Micro has concrete evidence that these man-in-the-middle attacks happened indeed on a large scale in Iran.

[...]

Attack Targeted Iranian Users

For domain validation.diginotar.nl, we see a very remarkable pattern in recent weeks: it was mostly loaded by Dutch and Iranian Internet users until August 30, 2011. Domain name validation.diginotar.nl is used by Internet browsers to check the authenticity of SSL certificates that are issued by Diginotar. Diginotar is a small Dutch Certification Authority with customers mainly in the Netherlands. We therefore expect that this domain name is requested by mostly Dutch Internet users and perhaps a handful of users from other countries. Not by a lots of Iranians.

From analysis of Smart Protection Network data, we see that a significant part of Internet users who loaded the SSL certificate verification URL of Diginotar were from Iran on August 28, 2011. On August 30, 2011 most traffic from Iran disappeared and on September 2, 2011 about all of the Iranian traffic was gone and Diginotar received mostly Dutch Internet users, as expected.

These aggregated statistics from Trend Micro Smart Protection Network clearly indicates that Iranian Internet users were exposed to a large scale man-in-the-middle attack, where SSL encrypted traffic can be decrypted by a third party. For example: a third party probably was able to read all e-mail communication an Iranian Internet user has sent with his Gmail account.

Closer analysis of our data revealed even more alarming facts: we have seen that outgoing proxy nodes in the US of anti-censorship software made in California were sending web rating requests for validation.diginotar.nl to the cloud servers of Trend Micro. Very likely this means that Iranian citizens, who were using this anti censorship software, were victims of the same man-in-the-middle attack. Their anti-censorship software should have protected them, but in reality their encrypted communications were probably snooped on by a third party.


--------------------------------------------------------------------------------------

cui bono?

Who has the most to gain from spying on everyday normal Iranians inside Iran?

The Iranian government would be the most likely answer.

Pakistani Forces Capture Senior Al-Qaeda Leader in Quetta

Via The Long War Journal -

The Pakistani military claimed it captured Younis al Mauritania, a senior al Qaeda leader who was directing attacks against the US, Europe, and Australia, along with two associates during a raid in the southwestern city of Quetta.

The Pakistani Army announced today that al Mauritania and "two other senior Al Qaeda operatives, Abdul Ghaffar Al Shami (Bachar Chama) and Messara Al Shami (Mujahid Amino)" were captured in a joint raid that was conducted by the Inter-Services Intelligence Directorate (ISI), the military's notorious intelligence service, and the Frontier Corps Balochistan. The arrests were "conducted with technical assistance of United States Intelligence Agencies," the Pakistani military's press release stated. The date of the raid was not announced. A grainy file photograph of al Mauritania was released.

Al Mauritania "was tasked personally by Osama Bin Ladan to focus on hitting targets of economical importance in United States of America, Europe, and Australia," according to the Pakistani military's announcement.

[...]

Last year al Mauritania, who was previously an unknown figure, jumped into the spotlight after he was identified as directing a plot by al Qaeda to attack multiple targets in Europe in a Mumbai-like terror assault. Several news reports incorrectly claimed that he was al Qaeda's so-called "number 3," or third in command. The number 3 designation is often assigned to al Qaeda's suspected operations chief. [See LWJ report, Al Qaeda's #3 misidentified again, for more information.]

But in fact, US intelligence officials told The Long War Journal last year that al Mauritania is a senior member of al Qaeda's external operations council, the division that is tasked with hitting the US, Europe, and allied nations. Al Mauritania, Adnan el Shukrijuma, and Ilyas Kashmiri are believed to be the senior-most members of the external operations council. Kashmiri is rumored to have been killed in a Predator strike in early June, but the report has never been confirmed.

Sunday, September 4, 2011

Mars Rover Discovery Elates NASA

Via New York Times -

It has been driving on and off for more than seven years, but now it has reached its new destination. Opportunity, a small exploratory rover that landed on Mars in 2004, has trundled to a crater called Endeavour.

And the first rock it looked at has already opened a new chapter in the study of Mars, NASA scientists said Thursday. On a telephone news conference, mission scientists giddily described that rock: full of zinc and bromine, elements that, at least for rocks on Earth, would be suggestive of geology formed with heat and water.

“This rock doesn’t look like anything else we’ve seen before” on Mars, said Steven W. Squyres, a professor of astronomy at Cornell and principal investigator of the rover mission.

The rim of Endeavour — a 14-mile-wide depression that was carved out by an impact long ago — consists of rocks from an earlier geological era that the impact lifted up from below. If the aging rover holds up, it could spend years examining the new terrain, giving NASA scientists ample grist for discovery.

Scientists are most interested in a close-up look at clay deposits that have been detected from orbit by another craft — NASA’s Mars Reconnaissance Orbiter — but that Opportunity has yet to find. Clay forms in the presence of liquid water, and the deposits suggest a warmer, wetter period in Mars’s past that may have offered friendlier conditions for life.

“This is a brand new mission, brand new landing site for all intents and purposes, geologically,” Dr. Squyres said. “A whole new set of puzzles for us to go off and solve.”

Opportunity and a twin rover, Spirit, arrived on Mars in January 2004, landing on different sides of the planet with the goal of exploring the surface for signs of past water. Spirit got its wheels stuck in a sand trap in May 2009 and could not get its solar panels pointed toward the sun; unable to generate enough electricity, it stopped communicating in March 2010 and is not expected to be heard from again.

But Opportunity, about the size of a golf cart, continues rolling on. It has now driven 20 miles. It had been designed to travel about two-thirds of a mile.

[...]

Opportunity is no longer in pristine condition, however. It is now usually driven backward to even out the wear on the gears. One of the joints on the robotic arm is stuck. Care is taken to minimize the movement of the camera to avoid wearing out the motor.

“All in all, we have a very senior rover that’s showing her age,” said John Callas, the project manager. “She has some arthritis and other issues, but in general, she’s in good health.”

Both Spirit and Opportunity have discovered evidence of liquid water, albeit water that is highly acidic, like sulfuric acid, that made parts of ancient Mars potentially habitable, at least intermittently.

[...]

The two rovers were not designed to look for signs of life, past or present. Even NASA’s next Mars mission, which involves an S.U.V.-size rover named Curiosity that is scheduled for launching later this year, does not carry any life-detection experiments. But it will be able to identify some of the molecular building blocks for life.

DigiNotar Damage Disclosure

https://blog.torproject.org/blog/diginotar-damage-disclosure

About an hour ago I was contacted by the Dutch Government with more details about the DigiNotar Debacle. It seems that they're doing a great job keeping on top of things and doing the job that DigiNotar should've done in July. They sent a spreadsheet with a list of 531 entries on the currently known bad DigiNotar related certificates.

The list isn't pretty and I've decided that in the interest of defenders everywhere without special connections, I'm going to disclose it. The people that I have spoken with in the Dutch Government agree with this course of action.

This disclosure will absolutely not help any attacker as it does not contain the raw certificates; it is merely metadata about the certificates that were issued. It includes who we should not trust in the future going forward and it shows what is missing at the moment. This is an incomplete list because DigiNotar's audit trail is incomplete.

This is the list of CA roots that should probably never be trusted again:

  • DigiNotar Cyber CA
  • DigiNotar Extended Validation CA
  • DigiNotar Public CA 2025
  • DigiNotar Public CA - G2
  • Koninklijke Notariele Beroepsorganisatie CA
  • Stichting TTP Infos CA
The most egregious certs issued were for *.*.com and *.*.org while certificates for Windows Update and certificates for other hosts are of limited harm by comparison. The attackers also issued certificates in the names of other certificate authorities such as "VeriSign Root CA" and "Thawte Root CA" as we witnessed with ComodoGate, although we cannot determine whether they succeeded in creating any intermediate CA certs. That's really saying something about the amount of damage a single compromised CA might inflict with poor security practices and regular internet luck.

[...]
Without any further delay, I've uploaded the original spreadsheet and a CSV text file for people who don't trust spreadsheets. The information contained in both files should be the same.

Saturday, September 3, 2011

Haqqani Network Directed Kabul Hotel Assault by Phone From Pakista

Via The Long War Journal -

Afghanistan's National Intelligence Directorate (NDS) recently disclosed that it intercepted communications on June 28 between fighters who were assaulting the Intercontinental Hotel in Kabul and their Haqqani Network handlers based in Pakistan. In an intercepted phone call, Badruddin Haqqani, a top leader of the terror network, is heard directing one of the fighters and laughing during the attack that killed 11 civilians and two Afghan policemen as well as nine members of the attack team.

On Aug. 31, NDS officials briefed reporters in Kabul on the phone intercepts between Badruddin, another Haqqani Network commander known as Qari Younis, and two of the members of the Continental suicide assault team. The NDS said the phone calls from the Haqqani Network handlers originated from Pakistan, according to Al Jazeera.

Younis is heard giving a Taliban fighter known as Rohullah directions on how to root out foreign guests in the hotel. He advises the fighters in the hotel to conserve their ammunition, send a team downstairs to fight, and then come up with a plan to search the rooms and kill those hiding.

"Use grenades and talk with each other," Younis advises. "If you're in agreement go and break down one or two doors. Or, if possible, throw a grenade into the room and then pull back."

"Whatever you do, make sure these guys don't get away. OK?" Younis orders.

Badruddin Haqqani is later heard talking to another Taliban fighter named Omar. Badruddin asks Omar if he has enough ammunition and if it is possible to change his location due to a fire in the hotel. Omar says he has "a lot of ammunition" but is unable to move.

[...]

Badruddin, an operational commander in the Haqqani Network who also sits on the Taliban's Miramshah Shura, is one of five senior Haqqani Network leaders to have been added to the US's list of specially designated global terrorists. Also designated are Sirajuddin Haqqani, the overall leader of the Haqqani Network as well as the leader of the Taliban's Miramshah Regional Military Shura; Nasiruddin Haqqani, a key financier and "emissary"; Khalil al Rahman Haqqani, a key fundraiser, financier, and operational commander for the Haqqani Network; and Mullah Sangeen Zadran, a top military commander in eastern Afghanistan. All five commanders have close ties to al Qaeda.

The back-and-forth during the Intercontinental attack between the Taliban fighters and their handlers in Pakistan is reminiscent of at least three other attacks carried out by terror groups in the region. In all three attacks, the terrorists were directed by commanders based in Pakistan.


--------------------------------------------------------------------------------

STRATFOR: Taliban Hotel Attack: Low Death Toll, High Psychological Value
http://www.stratfor.com/weekly/20110706-taliban-hotel-attack-low-death-toll-high-psychological-value

DigiNotar Compromise

http://blog.gerv.net/2011/09/diginotar-compromise/

On Monday August 29th at 6.30pm BST Mozilla was informed by Google about a misissued certificate for *.google.com which was being used in active attacks on users in Iran. This certificate was chained to the root of the Dutch CA “DigiNotar”. Since that notification, I have been part of the Mozilla team working on our response.

The Compromise

DigiNotar discovered evidence of compromise of their systems on the 19th of July, but decided not to inform embedders of their root, including Mozilla. We have now been given details of 247 certificates, covering 23 CNs, which were misissued around this time, from a number of different DigiNotar intermediate certificates, including their EV intermediate. (These are the ones Chrome has explicitly blacklisted.)

Mozilla has a spreadsheet of certificate data from the certificates, but not copies of the certificates themselves. It seems that the attackers tried to make their certificates as like the genuine ones as possible by filling in the correct company names and locations.

[...]

The CNs concerned were as follows:

*.10million.org
*.balatarin.com
*.google.com
*.logmein.com
*.microsoft.com
*.mossad.gov.il
*.skype.com
*.torproject.org
*.walla.co.il
*.wordpress.com
addons.mozilla.org
azadegi.com
DigiCert Root CA
Equifax Root CA
friends.walla.co.il
login.yahoo.com
Thawte Root CA
twitter.com
VeriSign Root CA
wordpress.com
www.cia.gov
www.facebook.com
www.sis.gov.uk

If that had been it, we might never have known. However, it has now emerged that DigiNotar had not noticed the full extent of the compromise, because for one particular intermediate certificate (the DigiNotar Public 2025 CA, the “2025 intermediate”), the attackers had managed to hide the traces of the misissuance – perhaps by corrupting log files. It is from this intermediate that the *.google.com certificate which recently came to light was issued. This certificate was issued on the 10th of July, a week before the 247, and is not a short-life cert. Up to now, due to the lack of logging, DigiNotar has been unable to determine how many certificates were misissued from this intermediate, or what their CNs or serial numbers were. (And not knowing their serial numbers makes it impossible to revoke them.) From looking at OCSP requests for unknown serial numbers, it seems there are at least 4, but there could be many more. This, to me, shows a greater level of sophistication; it is at least possible (but entirely speculative) that an initial competent attacker has had access to their systems for an unknown amount of time, and a second attacker gained access more recently and their less subtle bull-in-a-china shop approach in issuing the 247 certificates triggered the alarms.


-------------------------------------------------------------------------------------------

http://www.rnw.nl/english/bulletin/security-dutch-government-websites-jeopardy

The Dutch Interior Minister Piet Hein Donner has given a press conference in the early hours of Saturday morning after an internet security firm appears to have been hacked by Iranian hackers.

The Dutch internet solicitors' firm Diginotar supplies certification for secure sites which guarantee their reliability. However, Iranian hackers have reportedly managed to surpass the certification system so that the Iranian authorities can read gmail and google messages of people in Iran.

According to a computer expert on Dutch public broadcaster NOS, the government can no longer guarantee the security of its websites. This means, for instance, that the internet identification site DigID is no longer reliable, which citizens use for various government services.

Government sites have not been shut down, but visitors to the sites will be warned that the sites are not secure.

Thursday, September 1, 2011

Suspected North Korean Cyberattack on a South Korean Bank

Via Washington Post -

After nearly half of the servers for a South Korean bank crashed one day in April, investigators here found evidence indicating that they were dealing with a new kind of attack from an old rival: North Korea.

South Korean officials said that 30 million customers of the Nonghyup agricultural bank were unable to use ATMs or online services for several days and that key data were destroyed, making it the most serious of a series of incidents in recent months. But even more troubling was the prospect that a belligerent neighbor had acquired the tools to disrupt one of the world’s most heavily wired nations — and that even more damaging attacks could be in store.

“This was an unprecedented act of cyberterror involving North Korea,” said Kim Young-dae, a senior South Korean prosecutor in charge of the investigation.

Conclusively identifying who ordered a cyberattack is notoriously difficult. But Western analysts who studied the incident agreed that the aggressor was probably North Korea and described it as the first publicly reported case of computer sabotage by one nation against a financial institution in another country.

Cyberwarfare offers high potential for asymmetric threats, providing poor nations with easy opportunities to inflict damage on a richer, more developed rival. Such an attack is relatively cheap to launch, but playing defense is costly: After the incident, the South Korean bank pledged to spend $476 million by 2015 on network security.

“They are doing massive damage with simple means,” said Georg Wicherski, a researcher with U.S.-based McAfee Labs, who analyzed the attack. “This is Cyber­warfare 101.”

[...]

South Korean investigators said they determined that 10 servers used in the bank incident were the same ones used in previous cyberattack operations against South Korea, including one in 2009 and another in March, that they blamed on the North. Investigators say they determined, for instance, that a “command and control” server used in the 2009 operation was registered to a North Korean government agency operating in China.

Investigators say the April bank attack occurred when a contractor inadvertently downloaded a malicious program onto a laptop computer, giving hackers the ability to control the computer remotely. Then, over a period of weeks or months, the hackers placed malicious code throughout the bank’s network, which allowed them — with the equivalent of a squeeze on a cyber-trigger — to make hundreds of servers crash at once.

North Korea has denied any role in the attack, saying in a statement carried by the state-run Korean Central News Agency that the South was “clinging to confrontation with its compatriots through crudely fabricated schemes.”

Wednesday, August 31, 2011

Dutch Site Claims Mozilla, Yahoo, Wordpress, Tor Project All Targets in Diginotar Certificate Theft

Via Threatpost.com -

There are more signs that a July compromise of Diginotar, a certificate authority based in the Netherlands, may have been driven by political motives. A Dutch Web site, nu.nl, reported on Wednesday that digital certificates belonging to Mozilla, Yahoo.com, Wordpress and The Tor Project were among dozens reported stolen from Diginotar.

The story, based on information from a confidential source, fills in details about which other firms were among "dozens" that Diginotar and its parent company Vasco have admitted were victims of the break in. It also adds weight to speculation that the hack may have had links to the Iranian regime and may have had, as its goal, the surveillance and identification of political activists and bloggers within the country.

Vasco, Yahoo and The Tor Project didn't immediately respond to requests for comment from Threatpost.

The forged certificates could be used most easily in man in the middle attacks, allowing attackes to carry out very sophisticated spear phishing attacks using Web sites that would appear to be legitimate, said Chris Nutt, a principal consultant at Mandiant Inc. of Alexandria, Virginia.

"We align certificate authority hacks with attacking organizations who are encountering security at target organizations that they wish to work around," he told Threatpost. "These are the same types of people who would be interested in breaching a company like RSA."

In the case of Diginotar, there have been suggestions from the very first that the hack may have been directed by Iran. For one thing, the first reports about man in the middle attacks using forged Google certificates originated in Iran. A subsequent review of Diginotar's Web site found a page that was defaced with the name of an Iranian hacking group.

Attribution for the hack will probably never be determined. However, Nutt said that attacks of this caliber - involving a multi stage attack against sophisticated organizations - are often perpetrated by nation states. "This is consistent with other nation-state sponsored attacks," he said.

[...]

Writing on Securelist, the blog of Kaspersky Lab's research group, Kaspersky Lab Expert Roel Schouwenberg said that statements from the company about the extent of the breach don't add up. Among other things, Diginotar claims that the breach was limited to a "few dozen" rogue certificates, while Google has blocked more than 250 of them. The company, Schouwenberg adds, may not actually know how many rogue certificates were generated -either because no logs exist or because they were deleted after the attack was complete.

Assuming that the Diginotar attack has links to Iran's government, it could be an effort by supporters of the regime to monitor political dissidents within the country using compromised Web browsers, blogging software (Wordpress), by snooping on Web mail sessions (Yahoo and Google) or unravelling efforts to mask a user's identity using Tor and other anonymity services.

[...]

Nutt said the Diginotar hack, combined with those on RSA and the certificate authority Comodo are bound to prompt some soul searching among security professionals, governments and Internet governance groups.

"This is a serious trend. You're talking about attacking the foundational security mechanisms of the Internet. Two factor authentication and certificates are used everywhere, so this really shakes the confidence of the security mechanisms we have in place today," he said.

Mac OS X Can't Properly Revoke Dodgy Digital Certificates

Via PC World -

A programming glitch in Apple's OS X operating system is making it hard for Mac users to tell their computers not to trust digital certificates, exacerbating an ongoing security problem with a Dutch certificate authority that was recently hacked.

Mac users began reporting problems Tuesday when they tried to revoke digital certificates issued by DigiNotar, a Dutch company whose servers were compromised last month and used to issue fraudulent digital certificates. Mac users revoked the certificates on their computers, but still saw some sites that used those certificates being marked as trustworthy.

Digital certificates are an important part of the way the Internet works, and are essential whenever two computers try to connect using the HTTPS protocol. The problem is that Apple's operating system does not allow users to revoke DigiNotar certificates properly, and marks some websites as trustworthy when it shouldn't.

[...]

Most users don't revoke digital certificates themselves; they let the browser makers handle it. Chrome, Firefox and Internet Explorer have all blocked DigiNotar certificates, but Apple hasn't said what it plans to do with its Safari browser. That means that, for now, Mac Safari users will have a hard time solving the problem.

Ryan Sleevi, a software developer who has contributed to Google's Chrome project, noticed the issue too. After poking around the Mac OS X source code, though, he uncovered the cause. Users can revoke a certificate using Keychain, but if they happen to visit a site that uses the more-secure Extended Validation Certificates, the Mac will accept the EV certificate even if it's been issued by a certificate authority marked as untrusted in Keychain.

"When Apple thinks you're looking at an EV Cert, they check things differently," Sleevi said in an interview Wednesday. "They override some of your settings and completely disregard them."

[...]

It's troubling that such a basic component of Internet security could have such an obvious flaw on the Mac, several security experts said Wednesday. "In a real-world sense, it probably won't affect a lot of people, but for me it's a little bit troubling that the security advice on what you're supposed to do plain doesn't work," said Jeremiah Grossman, chief technology officer with WhiteHat Security.

Apple, which is often tight-lipped about anything to do with computer security, did not return messages Wednesday seeking comment.

---------------------------------------------------------------------------------

Reason #101 not to use Safari, even on Mac OS X.

I personally use Chrome 13 and Firefox 7 Beta on my MBP. Google has already updated Chrome to deal with the DigiNotar incident. Mozilla has released new release versions of Firefox and will be fixing the issue in the beta versions (7) very soon.

STRATFOR: Reconstructing the Monterrey Arson Attack from Surveillance Footage

STRATFOR Vice President of Intelligence Fred Burton demonstrates how video surveillance footage is used to reconstruct the recent arson attack in Monterrey, Mexico.

http://www.stratfor.com/analysis/20110830-above-tearline-reconstructing-monterrey-arson-attack-surveillance-footage

Pakistani Government Warns ISPs to Block Encrypted Traffic / VPNs

Via Softpedia -

Pakistan's The Express Tribune reports that the Pakistan Telecommunication Authority (PTA) has sent warning notices to ISPs about the continuous use of encrypted virtual private networks.

"In line with [Monitoring & Reconciliation of International Telephone Traffic] Regulations 2010 and national security, Authority prohibited usage of all such mechanisms including encrypted virtual private networks (EVPNs) which conceal communication to the extent that prohibits monitoring. It is observed that the aforementioned directive has not been followed in true letter and spirit as EVPNs are heavily being used on the Licensees Network," reads a letter received by one ISP.

The new telecom law, which was adopted in July, is meant to make it harder for militants to use secure communications and easier for national security agencies to monitor them. Unfortunately, these regulations affect all Internet users in the country and if the government go as far as to block all forms of encryption, including HTTPS, they might have serious effects.

"The problem is that banning every sort of 'communications concealing' technology online would destroy the very fabric of the internet's law-abiding use. There would be no SSH, no SSL, no TLS, no HTTPS. There would be no Wi-Fi security. Online commerce would implode," writes Sophos security expert Paul Ducklin.

FireEye Advanced Threat Report 1H2011

Via FireEye Blog -

This report [PDF] really illuminates the sophistication of the new breed of cyber-attacks and the success cyber criminals are having penetrating today’s corporate networks. Based on 1H 2011 data, we found a significant gap in today’s enterprise IT defenses. After reviewing hundreds of thousands of infection cases, 99% of enterprises had malicious infections in their network. Plus, 80% of the enterprises facing more than a hundred new infections per week. The bottom line: Today’s existing traditional enterprise IT defenses are not keeping up with highly dynamic, multi-stage attacks that cyber-criminals now use to attack today’s enterprises and federal agencies. We highlight the top infections for 2011, and the (not-so-surprising) fact that attackers continue to rely on customized malicious code toolkits to develop and distribute their threats.

----------------------------------------------------------------------------------------

http://www.fireeye.com/resources/pdfs/FireEye_Advanced_Threat_Report_1H2011.pdf

Key findings:
  • 99% of enterprise networks have a security gap despite $20B spent annually on IT security.
  • Successful attacks employ dynamic, “zero-day” malware tactics. 90% of malicious binaries and domains change in just a few hours; 94% within a day.
  • The fastest growing malware categories are Fake-AV programs and Info-stealer executables.
  • The “Top 50” of thousands of malware families generate 80% of successful malware infections.

Drug War Sparks Exodus of Affluent Mexicans

Via Washington Post -

For years, national security experts have warned that Mexico’s drug violence could send a wave of refugees fleeing to the United States. Now, the refugees are arriving — and they are driving BMWs and snapping up half-million-dollar homes.

Tens of thousands of well-off Mexicans have moved north of the border in a quiet exodus over the past few years, according to local officials, border experts and demographers. Unlike the much larger population of illegal immigrants, they are being warmly welcomed.

It goes counter to the conventional wisdom about the Mexican presence in the United States,” San Antonio Mayor Julian Castro said. The influx “is positive, it is entrepreneurial . . . and one of the keys to a very successful growing city like San Antonio.”

Castro estimates that Mexicans own at least 50,000 of the approximately 500,000 homes and apartments in his city of 1.3 million, which has a vibrant Hispanic culture. Many are in gated communities that have sprung up in the city’s sun-baked northern hills.

[...]
Affluent Mexicans have long visited the United States for business and shopping. What’s different now is that they are coming to stay, fleeing cartel wars that have left more than 37,000 Mexicans dead in four years, according to U.S. and Mexican officials and analysts. The number of investment visas granted to Mexicans has risen sharply over the past five years.

“It’s a very substantial flow; I would say probably the largest since the 1920s, the last great period of upheaval in Mexico,” said Henry Cisneros, a former mayor of San Antonio who served in President Clinton’s Cabinet. “We have whole areas of San Antonio that are being transformed.”

The size of the new wave is difficult to measure, since some of the new arrivals hold dual citizenship or U.S. work visas or already had American vacation homes. One Mexican think tank, the Security and Civic Culture Observatory, estimated last year that 230,000 people had fled the violence-wracked border city of Juarez, with half going across Mexico’s northern border.

But Aaron Terrazas, a policy analyst at the Washington-based Migration Policy Institute, found in a recent study that most of those fleeing Juarez appeared to be moving to other parts of Chihuahua state, not the United States. Still, Terrazas said he found a noticeable increase in one segment of those actually leaving Chihuahua: “the highly educated.”

Tuesday, August 30, 2011

DigiNotar Says Its CA Infrastructure Was Compromised

Via Threatpost.com -

VASCO, the parent company of DigiNotar, says that the fraudulent certificate for Google's domains that the certificate authority issued was just one of many such bogus certificates it handed out in recent months, and blamed the growing scandal on an attack on its CA infrastructure.

In a statement responding to stories detailing the use of the fraudulent--but valid--wildcard certificate DigiNotar issued to an unknown third party for Google domains, VASCO officials said that the company became aware of the attack on its CA infrastructure on July 19, which is nine days after the Google certificate was issued. DigiNotar has stopped issuing certificates for the time being while it tries to figure out what happened.

"On July 19th 2011, DigiNotar detected an intrusion into its Certificate Authority (CA) infrastructure, which resulted in the fraudulent issuance of public key certificate requests for a number of domains, including Google.com. Once it detected the intrusion, DigiNotar has acted in accordance with all relevant rules and procedures," the statement says.

"At that time, an external security audit concluded that all fraudulently issued certificates were revoked. Recently, it was discovered that at least one fraudulent certificate had not been revoked at the time. After being notified by Dutch government organization Govcert, DigiNotar took immediate action and revoked the fraudulent certificate."

---------------------------------------------------------------------------

Dark Reading: Digital Certificate Authority Hacked, Dozens Of Phony Digital Certificates Issued

But security experts say the problem is that if the fake certificates were used for man-in-the-middle attacks, the damage may already have been done. "This press release only has made me more worried about how much this may be just the tip of the iceberg," says Roel Schouwenberg, senior antivirus researcher for Kaspersky Lab. "The google.com cert was only revoked yesterday afternoon EST."

Schouwenberg says DigiNotar's statement raises more questions. "The conducted audit does not inspire any confidence. How did they miss the Google cert? How did they miss the website hacks pointed out by F-Secure?" he says, referring to a F-Secure Mikko Hypponen's post today showing what appears to be evidence of Iranian hackers having broken into DigiNotar's servers, and one page by alleged Turkish hackers back in 2009.

Hyponnen weighed in on DigiNotar's statement as well. "It raises more questions than answers. Diginotar indeed was hacked, on the 19th of July, 2011. The attackers were able to generate several fraudulent certificates, including possibly also EVSSL certificates. But while Diginotar revoked the other rogue certificates, they missed the one issued to Google. Didn't Diginotar think it's a tad weird that Google would suddenly renew their SSL certificate, and decide to do it with a mid-sized Dutch CA, of all places?" Hypponen, chief research officer of F-Secure blogged. "And when Diginotar was auditing their systems after the breach, how on earth did they miss the Iranian defacement discussed above?"

[...]

Another problem is that revocation isn't a sure thing. The rogue certs could be used for one-off, targeted attacks, and therefore would be tough to pinpoint, experts say.

"Additionally, there are ways to bypass revocation notices. So currently, we're depending on browser updates to fully protect us," Kaspersky's Schouwenberg says. "The average turnaround time is rather suboptimal. Let's hope Apple will be faster than with the Comodo case."

He says it also appears that not all of the CAs have been revoked, either: A separate DigiNotar CA handles the EV-SSL certs, and Chrome currently appears to be still accepting that CA, he says.

APT: Breaching Defense Contractor Data

Via AviationWeek (August 30, 2011) -

A couple of years back, it was reported that hackers had compromised the Joint Strike Fighter program’s internal information system. The reports were partially correct, but were not denied by the Pentagon because official sources could then state that the JSF program had not suffered extensive data loss. That was because JSF was not the target.

The hack had been aimed at a classified program. Not only could intruders extract data—they could become invisible witnesses to online meetings and technical discussions. After the break was discovered, the program had to be halted and was not restarted until a new—and costly—security system was in place.

Announcing the Defense Department’s new cyberwarfare strategy in July, Deputy Defense Secretary William Lynn noted that “a foreign intelligence agency” had hit a major defense contractor in an exploit discovered in March, and exfiltrated 24,000 files concerning a developmental system. The Pentagon was still reviewing whether the system (which Lynn did not identify) will need to be redesigned. That could be necessary if the compromised information will not only help the intruder develop similar systems, but also methods of attack and defense.

Meanwhile, China’s unveiling of the Chengdu J-20 stealth fighter prototype at the end of 2010 took Western observers by surprise (DTI February, p. 32). Then-Defense Secretary Robert Gates’s prediction in 2009 that China would have no stealth aircraft in 2020 and only a handful in 2025 had started to look optimistic—but was contradicted by U.S. Air Force Vice Chief of Staff Gen. Phillip Breedlove’s Senate testimony in July. China, he said, can close the technology gap faster than expected because of “the way they’re intruding into the nets of our manufacturers and our government.” Breedlove added: “When they say they’re going to build 300 [J-20s] in the next five years, they will build 300 in the next five years.”

China has made rapid progress in other areas. Images appearing on the Internet show that the updated J-10B single-engine fighter probably has an active, electronically scanned array (AESA), in addition to an infrared search-and-track system and updated defensive avionics.

Other pictures show J-11B fighters (bootlegged versions of the Sukhoi family) with Chinese engines, indicating that China is making progress toward overcoming a critical limitation on its fighter industry—dependence on Russian propulsion. And as a J-10B with a domestically developed engine appeared, China announced its intention to supply Pakistan with such aircraft (DTI July/August, p. 8).

These advances are emerging 5-6 years after cybersecurity professionals detected what came to be dubbed the advanced persistent threat, or APT—in other words, reducing the time taken from conceptual design of a military system to prototyping.

The APT was barely mentioned in public until last year (DTI May 2010, p. 16). Even now, few people in industry or government call it what it is—a massive campaign of cybernetwork exploitation (CNE) originating in China.

[...]

The direct damage caused to the target is hard to assess. Was a contract lost due to a rival’s inside knowledge, or other factors? In the case of technical data, [Dmitri] Alperovitch [of McAfee] notes, “it may be several years before stolen schematics turn up in a product, but by then it might be too late.” Compromised information could also help a development in ways that are invisible—for example, the ability to pick one of several technical approaches without testing all of them, or avoiding blind-alley concepts.

Cyberespionage, experts note, is different from classic spycraft. Software agents are expendable. The result is that a classic dilemma of intelligence—the risk that acting on it or disseminating it widely will compromise sources and methods—is absent, as are barriers between intelligence operatives and end users. It’s entirely possible to conceive of a defense manufacturer having its own intelligence operation, combining open-source and CNE methods, accepting direct tasking from program leaders.

[...]

There are two big issues, Alperovitch says. One is the “sheer scale and magnitude” of the operation, “a wholesale transfer of intellectual property . . . They are using our resources for their R&D.” That, and the ability to compromise bid data, can cause “a direct loss of jobs.” The other is the potential for “escalation from espionage to cybernetwork warfare. The difference between escalation and attack may be a click of a button.”

Fake Facebook Page Targets Pro-Revolution Syrian Users

Via Information Warfare Monitor -

The Information Warfare Monitor (IWM) has uncovered an attempt to use a fake URL and login page to lure Facebook users into providing their login credentials. Given the nature of the content being linked to, this appears to be an attempt to target pro-revolution Syrian Facebook users. The link (hxxp://facebook.com-video-php-v222423423.homsrev.webgoof.com/video/video.php) attempts to mimic the URL and login page of Facebook, as seen in Figure 1. It has been distributed through multiple Syrian Twitter accounts, which describe the content as a “fascinating video clip showing an attack on Syrian regime”. The use of Twitter accounts to distribute malicious links is a common tactic and has been documented by past Information Warfare Monitor research.

IWM researchers were able to login to this Facebook page using newly created login credentials, at which point we were re-directed to the legitimate Facebook login page. Tweets from August 29, 2011 have added a note explaining “you will be asked to login twice as an extra security measure”. This is likely an attempt to mask the suspicious URL by immediately re-directing to a legitimate one.

The source code of the fake Facebook page contains a description in Arabic which reads “An excellent operation by Khalid brigade that killed 6 Shabiha in the Syrian city Homs.” Shabiha is an Arabic term used by Syrian opposition groups to describe the regime’s militias. This message provides further evidence that this page was indeed set up to target pro-revolution Syrian users.

[...]

Previous research of the Information Warfare Monitor has documented activities of the pro-regime Syrian Electronic Army, which included compromising several Facebook pages run by Syrian opposition groups. However, we are not able to determine who is behind this particular attempt to harvest Facebook credentials.

DigiNotar: Attackers Obtain Valid Cert for Google Domains, Vendors Move to Revoke It

Via H-Online.com -

A fraudulent SSL certificate for "*.google.com" issued by Dutch certificate authority (CA) DigiNotar, possibly to the Iranian government or its agents, has triggered a wave of updates from software makers to stop applications trusting the CA. The certificate was issued on 10 July to unknown persons in Iran.

Several security experts, such as Moxie Marlinspoke, confirmed that the SSL certificate came from DigiNotar; one pastebin entry detailed the contents of the suspicious certificate, while another called for the "internet death sentence" because the company's "carelessness may have resulted in deaths in Iran". The Electronic Frontier Foundation said in a blog posting that it believes the attacks have been used to intercept searches and private email. It is unknown who the certificate was actually issued to and whether or not any other bogus certificates were issued.

The attack was initially noticed by Google Chrome users because Chrome 13 and later implements certificate pinning which ensures that the browser will only accept certificates for Google from a whitelist of certificate authorities; DigiNotar was not a CA on the whitelist and users of Chrome were alerted that something was amiss with the certificate they were being presented. The certificate was revoked yesterday, 29 August, at 16:59 GMT, but because many browsers do not check for revoked certificates by default, software vendors have had to take action to prevent the continued exploitation of the bogus certificate. It is also currently unknown if any other bogus certificates were issued by DigiNotar, therefore the vendors are opting to block all certificates signed by the CA.

Microsoft has released a security advisory and updates for all supported Windows operating systems – including Vista SP3, Server 2008 SP2 and Windows 7 SP1 – which revoke trust in the CA's root certificate. Windows XP SP3 and Server 2003 SP2 will receive separate updates as these systems do not use the centrally managed Microsoft Certificate Trust List.

Mozilla has announced that it is releasing updates for Firefox (3.6.21, 6.0.1, 7, 8 and 9) and Firefox Mobile (6.0.1, 7, 8 and 9), Thunderbird (3.1.13 and 6.0.1) and SeaMonkey (2.3.2), which will also revoke trust in DigiNotar's root certificate. Mozilla has also released instructions on how to delete the DigiNotar Root CA certificate from Firefox manually.

Google is also disabling DigiNotar's certificate in Chrome "while investigations continue" even though Chrome detected the fraudulent certificate. The Chrome browser was only able to do that for google.com subdomains and if there are other fraudulent certificates for other domains Chrome would be unable to detect the deceit.

This is the second fraudulent certificate incident this year: in March, SSL certificates for addons.mozilla.org, Yahoo, Skype, Microsoft Live and Google were created by an intruder into a Comodo reseller.


--------------------------------------------------------------------

Additional Resources:
http://www.f-secure.com/weblog/archives/00002228.html

Based on this photo in THN, the fraudulent certificate was issued on 7/10/2011.
http://www.thehackernews.com/2011/08/iranian-man-in-middle-attack-against.html

Monday, August 29, 2011

IPv6: Some Chinese Surf Freely, for Now

Via VOA News (August 22, 2011) -

A new web technology being championed by China is allowing a short-term gap in its so-called “Great Firewall,” which blocks Chinese Internet users from sites blacklisted by the government in Beijing. Experts say how the gap is closed could have ramifications for the entire world.

[...]

To answer the [IPv4] shortage, China has been a leader in rolling out IPv6. But it’s only available to a small slice of the population, mainly in the big cities and around large universities. At least some of these users seem to be able to surf without blocking or filtering.

“We have been testing IPv6 connectivity to China for the past year, and so far, it seems like the Chinese government is not paying attention to it at all,” said Andrew Lewman, the executive director of the TOR Project, an open network that helps people protect their identity online.

[...]

Lewman said the number of people using IPv6 is probably in the “tens of thousands,” but he expects China to start paying attention as soon as those numbers reach a critical mass.

Another reason there’s no IPv6 firewall is the hardware is not plentiful.

“There are just not enough vendors selling the equipment to use on an IPv6 Great Firewall,” Lewman said. “Basically [the Chinese government] just has to say to vendors that there are billions of dollars to be made here.”

Once this happens, things could get very interesting.

[...]

Hal Roberts, a fellow at the Berkman Center for Internet & Society at Harvard University and an expert on Internet filtering circumvention and Internet surveillance, said IPv6 could present a double-edged sword.

On one hand, the creation of a nearly infinite number of new IP addresses could be a boon to anonymity, which largely relies on the ability of an anonymous surfer to quickly change IP addresses on the fly to avoid detection.

On the other hand, Roberts said there’s a movement, pushed largely by U.S. law enforcement agencies and the Recording Industry Association of America to build a strong association between hardware and IP addresses.

In other words, since there would be so many IPv6 addresses, it would be possible to hardwire every computer, cell phone or any other type of hardware that connects to the Internet with an IP address, making anonymity virtually impossible.

“That’s a debate that’s still happening,” said Roberts. “We don’t know which way that will go.”