Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts
Sunday, March 12, 2017
Hackers Claim Million Dollar Bounty for iOS Zero Day Attack
Hackers Claim Million Dollar Bounty for iOS Zero Day Attack
HACKING APPLES IOS isnt easy. But in the world of cybersecurity, even the hardest target isnt impossibleonly expensive. And the price of a working attack that can compromise the latest iPhone is apparently somewhere around $1 million.
On Monday, the security startup Zerodium announced that its agreed to pay out that seven-figure sum to a team of hackers who have successfully developed a technique that can hack any iPhone or iPad that can be tricked into visiting a carefully crafted web site. Zerodium describes that technique as a jailbreaka term used by iPhone owners to hack their own phones to install unauthorized apps. But make no mistake: Zerodium and its founder Chaouki Bekrar have made clear that its customers include governments who no doubt use such zero-day hacking techniques on unwitting surveillance targets.
In fact, Bekrar tells WIRED that two teams of hackers had attempted to claim the bounty, which was announced in September with an October 31st deadline. Only one proved to have developed a complete, working iOS attack. Two teams have been actively working on the challenge but only one has made a full and remote jailbreak, Bekrar writes. The other team made a partial jailbreak and they may qualify for a partial bounty (unconfirmed at this time).
Bekrar confirmed that Zerodium plans to reveal the technical details of the technique to its customers, whom the company has described as major corporations in defense, technology, and finance seeking zero-day attack protection as well as government organizations in need of specific and tailored cybersecurity capabilities. Zerodiums founder also notes that the company wont immediately report the vulnerabilities to Apple, though it may later tell Apples engineers the details of the technique to help them develop a patch against the attack.
According to the rules of the bounty offer made public in September, the iPhone attack must be achievable remotely, reliably, silently, and without requiring any user interaction except visiting a web page or reading a text message. Only two iOS web browsers were designated as fair game for the bounty: Google Chrome and Apples own Safari. Bekrar didnt respond to a question from WIRED as to which of those two browsers the successful exploit had targeted. Apple hasnt yet responded to a request for comment.
Little is known about Zerodium, Bekrars zero-day brokering startup that launched in July. But Bekrar has been more vocal about his older company Vupen, a hacking firm based in his native France that builds rather than buys zero-day attack techniques. Vupen has at times publicly flaunted that it doesnt help companies to patch the attacks it builds and sells to surveillance clients, including the NSA.
Bekrar has pointed to Vupens policy of selling those hacking techniques only to NATO governments and NATO partners. But civil liberties and privacy groups have nonetheless criticized Vupen for selling the bullets for cyberwar. Googles security staffers have publicly argued with Bekrar and gone so far as to call him an ethically challenged opportunist.
Vupen doesnt know how their exploits are used, and they probably dont want to know, Chris Soghoian, the lead technologist at the ACLU, told me in 2012. As long as the check clears.
Bekrar responds that this iOS exploit will likely only be sold to US customers. And more broadly, his two companies havent been shown to be doing anything illegaltrading in intrusion software is generally not a crime, at least for nowhence his brazenly public bounty and payout announcement. We planned initially to not release any information about the outcome of the bounty but weve decided to do it to inform the community about the security of iOS which is definitely very hardened but not unbreakable, Bekrar writes to WIRED. Those who have any doubt about that may be surprised. Not as surprised, of course, as the iPhone users who could soon be the victim of a $1 million zero-day surveillance technique.
Go to link Download
Friday, December 9, 2016
Hackers Getting Closer to US Grid
Hackers Getting Closer to US Grid
Much has been said about the danger of hackers attacking the U.S. power grid. However, Electric Light & Power writes that hackers "are already here and getting closer to their objectives all the time." Experts say all thats left is money and motivation for an attack.
Meanwhile, the U.S. Department of Energy has reported more than 1,100 cyberattacks from 2010 to 2014, with 14% as successful, and the cybersecurity rating firm BitSight says the power industry only ranks "fair to middling" on cybersecurity. Could a major attack really come in the next three years? What can be done to stop it?
Security expert says successful hack against power grid likely
Hackers are not coming to attack U.S. energy infrastructure. They are already here and getting closer to their objectives all the time.
Using the parallel of wartime, these hackers are virtual enemy patrols which have probed into the front lines, looking for weaknesses and attack points that present the best possible chance of success. They may want credit card information or even notoriety.
Sometimes their motivation is terror, chaos and infrastructural damage, such as trying to bring down part of the power grid within a city or even blacking out giant swathes of the U.S.
The knowledge is out there, the intent is out there, and the capacity is out there, said Jonathan Pollet, founder of Houston-based cyber firm Red Tiger Security. Now were just waiting for someone motivated enough, by money or political events, to take advantage.
This hasnt happened yet, but the potential is getting closer as bad actors compile knowledge of the grids cyber weaknesses and gather illicit financial support for their efforts.
A recent USA Today report indicated that the U.S. Department of Energy was under constant siege in recent years, with 1,131 attempted cyberattacks from 2010-2014. The hackers were successful about 14 percent of the time, or in 159 of the attempts, according to the article.
I think its very likely an attack on a utility company could be successful someday soon, maybe within three years, Pollet added.
Another report, this one released Tuesday by cybersecurity ratings BitSight, indicates that the energy industry only ranks fair to middling when it comes to cybersecurity efforts. The energy-utility sector was ranked fourth among sectors, slightly above health care and behind finance, government and retail. Education was categorized, far and away, as the most vulnerable to cyber attack by BitSight.
BitSight researchers noted a dip in the energy-utility sector, finding it most vulnerable to malevolent bugs such as Poodle and Freak. The report indicated a growing concern about the cybersecurity posture of these companies even as more control systems are being brought online.
Cybersecurity is kind of like the offensive line in football. The casual fan only notices them when something goes wrong. Its a thankless task but one which has to be done better than it has been, according to report.
This is going on inside companies every day, said Stephen Boyer, co-founder and chief technology officer of BitSight. There is a battle going on between attackers and defenders. Its very, very hard to be perfect.
Hacker attacks against Target, Sony and Ashley Madison certainly gained much attention, embarrassed many and have alarmed consumers, but Boyer said the scary parts of cybersecurity for utilities are the things we dont know about.
Hackers glean inside knowledge, trick users into giving up passwords and protocols and leave footprints that take precious time to track down. Cybersecurity experts in the U.S. are well aware of the threats coming from China, Russia and Iran, among many other places, but the attacks could originate from anywhere, even on American soil.
Attribution is very hard, Boyer said. The power goes off and no one knows who it is.
One saving grace, surprisingly, is that the U.S. power grid is not one seamless piece, but rather numerous systems. For that reason, many experts do not think that cyber terrorists could pull off a continental-wide blackout. But they could be a threat to turn off power within a city or region.
Del Rodillas, solution lead for SCADA and industrial control systems at Palo Alto Networks, said he couldnt rank the energy-utility sectors preparedness compared to other industries. What he worries most about is a perceived disconnect between two distinct, yet connected parts of the power companies.
What I can say is within the energy-utility organization, there is a stark contrast in the level of security between the IT (information technology) environment and operational technology (OT) environment, Rodillas said in an emailed response to questions. Keep in mind, though, that the staff securing IT environments in energy and utility companies are typically separate from the staff in OT responsible for security and not always working in unison. The IT environment in the energy-utility may be cutting edge, but the OT environment is typically lagging.
For instance, through various and relatively easy means the world-class hacker can find the name of a SCADA engineer working for a utility. They try to get that engineers email address and, once theyve gone that far, they send the engineer an email that entices the prey to click on something that might be of personal or professional interest.
Once clicked, a rootkit is released into the desktop that both masks the softwares existence and intent and also allows the hacker remote access to the computer, Pollet pointed out. For the past two years, his company has identified kits moving through the corporate networks, looking for open platform communications (OPC) servers and gaining more database information about SCADA systems.
I know they have access to the system, and theyre able to read information off the system, Pollet said. We have not seen an adversary remotely command a SCADA systemthats the last piece they are missing. I think they are close.
What to do, what to do? BitSights Boyer said he was actually encouraged about the USA Today report on the hacks into the U.S. Department of Energy. Once every four days there is a physical or virtual attack on the U.S. power infrastructure, so putting utility defenders on higher alert is a good idea.
The awareness is probably at an all-time high, Boyer said. They are very much aware and asking these sort of questions.
The federal government is getting on board. A new cybersecurity framework, directed by the White House and supported by industry, was announced last year by the National Institute of Standards and Technology. The NERC CIP and ICS-specific standards like NIST SP800-82 certainly have helped increase awareness, Palo Alto Networks Rodillas noted.
It helps with raising the bar for successful cyber attacks, Rodillas said. However there is still a ways to go to have these personnel understand how targeted attacks work.
Forget about deploying tools for detecting and stopping (attacks), he added. Many OT personnel dont even know these tools exist. Getting ones organization education is an important first step.
Red Tiger Security is advising its clients to isolate their control systems from corporate networks. The industry also needs to do a more work securing the growing smart meter infrastructure, given the bi-directional nature of that communication.
Harden the perimeter, Pollet added. Sounds like war. And it sounds imminent.
I think its very likely, he said. I think its above 60 to 70 percent likely that it could happen in the next five years.
Go to link Download
Subscribe to:
Posts (Atom)