Wednesday, September 13, 2017

Equifax Veri Sızması

 
 
Kuzey Amerika'da hata yaptın mı, bunun bir bedeli muhakkak oluyor. (Bazı durumlarda kantarın topuzunu biraz kaçırsalar da durum böyle.)
 
ABD'deki Equifax ismindeki kredilendirme kuruluşunun, kendi sistemlerinde kayıtlı yaklaşık 143 milyon kişinin kimlik numaralarını (social security number) ve kredi bilgilerini çaldırması üzerine Equifax firmasına davalar açılmaya başlandı:
 
 
Bu davaların gerisi de gelir gibi görünüyor. ABD Kongresi ve Dipartmınt of Homlent Seküriti de olaya müdahil olmak üzereymiş. EfBiAy da olayı ayrıntılı inceliyormuş bu arada.
 
Ama hacım ya!! Ne kadar abarttınız mevzuyu! Biz "Hayırlısı olsun!" der geçerdik böyle bir şey bizde olsaydı. İki sözcük, biraz hamaset ve hayat kaldığı yerden devam ederdi hiçbir şey olmamış gibi. Cidden çok abartıyosunuz bilader! Easy man! Easy! =))
 
Equifax hisseleri geçen Perşembe'den (07.09.2017) bu yana düşüşe geçmiş olsa da bunun borsadaki hisselere -henüz- çok aşırı bir etkisi olmamış(mış). Fakat Equifax hisselerinde büyük düşüşün olacağı beklenmekte. Bu vahim veri sızması olayından hemen sonra da üç hissedarın, toplam 1,8 milyon dolarlık Equifax hisselerini satmaları belki buna bir işaret olabilir. Equifax, 1,8 milyon dolarlık bu hisse satışlarının veri sızmasıyla ilgisi olmadığını açıklamıştı.
 
Hukuka merakı olanlar için davaların ayrıntılarına buralardan bakılabilir:
 
Biraz da komplo teorisi senaryosu yazalım şimdi: Sam amcanın, verilerin gizliliğini azaltma ve devlete bu konuda biraz daha fazla yetki verip, dolaylı olarak özgürlükleri kısıtlama konusunda elinde birkaç taslak vardır. Ama Sam amca, bu tasarıları hayata geçirmeye çalıştığı takdirde, kamuoyunun buna çok ciddi bir tepki vereceğini ve tasarıların kadük kalacağını, kendisinin de madara olacağını domuz gibi bilmektedir.
 
Bu olası tepkileri yok etmek ya da azaltmak için herkesi ilgilendiren ve herkesi gerilime geçiren "nationwide" bir olaya ihtiyaç vardır. Bunun için elinde zaten, önceden hazırlamış olduğu beş adet senaryosu bulunmaktadır ve bu senaryolardan birisini seçip, çoktan düğmeye basmıştır bile.
 
Bu sefer kurban olarak Equifax şirketini seçmiştir. Zaten Equifax şirketine uzun bir süredir de gıcık olmaktadır. Bu şirket kendisine, vakti zamanında çok pis "lolo" yapmıştır. Sam amca da bunu tabii ki unutmamıştır. Uzun zamandır da bu şirketi ucuza kapatmak niyeti de vardır. Equifax hisselerinin ve şirketin değeri düşünce de şirketi hemen satın almayı planlamaktadır. Bizim bildiğimiz Sam amca zaten, en az iki kuşu gözüne kestirmemişse, elini taşa sürmez. (Güzel bir Hollywood filmi senaryosu size.)

Wednesday, September 6, 2017

Chicken Wings vs. Cybersecurity

If you didn't provide against cyber threats then you cannot eat chicken wings. Not cybersecurity but chicken wings security. =))
 

Monday, August 14, 2017

Incident Respone Plan


It should be noted: if an Incident Response plan is not already in place, do not attempt to create one during an infection. Rather, remove the infected server from the network. Create a plan to systematically return the infected server to its pre-infected production condition before beginning the recovery process. Incident response is not a responsibility that a single person can handle. Recovering a compromised server in a haphazardly fashion can create more system issues and do more damage then the initial compromise.
 
...
...Incident Response Plans should not be created during a security incident nor should one person be assigned to develop an Incident Response Plan. Incident response should be the responsibility of different members from different groups in an organization...
...
 
...During an incident, panic will often set in. Do not let this happen...

----
Source:
SANS Institute InfoSec Reading Room
Source: Malware Analysis: An Introduction
 
 
 
 
 

Wednesday, August 9, 2017

Automotive Cyber Flaws

30 years ago, it could sound like a science fiction scenario but today we are moving slowly towards that point. Today automotive cyber flaw concept is a threat. It is only not that much widdespread.
 
Anything which has an IP address (IoT) is a target candidate of hackers. Naturally the "connected cars" aren't exception for this concept. A car which is connected to internet or to an intranet is defined as "connected car".
Think of that you are the main character of the following scenario: You own a connected car. It's a brand new, smart car. You paid a lot of bucks to buy it.
 
One day in the morning you got into your car and turned the car key as usual. But... Hey! It's not working. You tried it a couple of times but the engine couldn't be started. During that confusion and anger suddenly you noticed a message on the screen of your car. "Your car is compromised. Don't go to the police. The data in your car is encrypted. If you pay us blah blah..."
 
"What? What the hell does it mean now?" After a couple of phone calls you solved the puzzle. Gosh! Yeah! It was your turn to become a carsomware (car + ransomware) victim. The hackers requested 1,000USD to unlock your car. You called your contracted car service and they told you that they have to change the "brain unit" of your car and it will cost you about 2,000USD.
 
Now... The question is: Which choice would you prefer? Hackers' bid or your car service's offer?
This seems to be like a movie scenario today but we are getting closer to such troubles day after day.
 
There can be much more dangerous scenarios in car hacking than not being able to start the engine. Think of what can happen if the brakes of your car suddenly malfunctioned while you were driving with a speed of 120km/h (~75mph) in a crowded traffic.
 
DHS (Department of Homeland Security) warned the automotive industry against the automotive cyber flaws: https://fcw.com/articles/2017/08/03/auto-cyber-cert-rockwell.aspx
 
In one of the conferences In DEFCON 2017 (August 2nd) researchers presented a paper on "automobile system vulnerabilities": https://securingtomorrow.mcafee.com/mcafee-labs/defcon-connected-car-security/
Remarkable lines:
 
"According to Intel however, the 'connected car is already the third-fastest growing technological device after phones and tablets.' "
 
"Our connected cars today generate up to 4,000GB of data per 50Kb every second and using on-board cameras generates 20MB to 40MB per second."
 
"Fundamentally, a car is like a jigsaw puzzle with multiple components, so applying patches to cars the way we would a phone, for example, is not feasible."
 
If you want a cyber threats free car then I would recommend the following one. =))

Tuesday, August 8, 2017

Linux-based Malwares

 
Remarkable expressions about Linıx-based malwares from SANS Institute Infosec Reading Room:
 
5. Conclusions
Despite popular perception, Linux can be vulnerable to a variety of malware. Existing host-based defense such as antivirus software is marginal at detecting or preventing Linux malware threats. Based on organizational risk tolerance additional security controls may be required to prevent or identify Linux malware infections. Utilizing a combination of system hardening techniques and network based controls can provide an additional layer of security. Incident response capabilities may also require adjustment to detect and respond to the growing threat of Linux malware.