FACEbook

Showing posts with label Cyber. Show all posts
Showing posts with label Cyber. Show all posts

Wednesday, January 14, 2015

Pentagon Calls Paris Attack 'Lone Wolf'' Event, Twitter Hacking 'Cyber Vandalism'

    The Pentagon called the hacking of the Central Command's (CENTCOM) YouTube and Twitter accounts Monday "cyber vandalism" in a letter to service members and their families to allay concerns about the incident. General Lloyd Austin said that the FBI is investigating the "alleged breach" of the two social media sites by hackers who claimed to be aligned with the Islamic State (ISIL.) While Austin said that "CENTCOM network was not compromised and no classified information," he acknowledged that the hackers posted "information obtained from the accounts," though he did not go into further detail.
    Austin also referred to "the threat of ‘lone wolf’ attacks by individuals who align with or are sympathetic to radical Jihadist elements," examples of which, according to Austin, are the "recent tragedies in Paris..., New York City and Ottawa, Canada." The general acknowledged that Monday's hacking included threats, but said there were no "no credible threats made to U.S. military personnel or their families."
    In any case, Austin said, the military is taking the threats "very seriously" and will "take all possible measures" to keep military personnel and their families safe.
    The full text of General Austin's letter is here:
This week, hackers claiming to be aligned with the extremist group ISIL took control of CENTCOM’s Twitter and YouTube accounts for approximately 30 minutes. They posted tweets with information obtained from the accounts and they also posted threats against military members and their families. 
I recognize that this has caused significant angst among family and friends who are understandably concerned about their loved ones’ safety. I want to personally reassure you that we are taking this matter very seriously and we continue to take all possible measures to keep our personnel safe. 
With respect to the alleged breach of our Twitter and YouTube accounts, The Federal Bureau of Investigation is in the process of conducting a full investigation. However, you should know that the CENTCOM network was not compromised and no classified information was obtained by the group. Also, as yet, there have been no credible threats made to U.S. military personnel or their families. 
That said, we do not take these threats lightly, and we will do what is necessary to mitigate them. Unfortunately, the threat of ‘lone wolf’ attacks by individuals who align with or are sympathetic to radical Jihadist elements exists today, and we’ve seen this demonstrated with the recent tragedies in Paris and before that in New York City and Ottawa, Canada. We must all take the necessary precautions and be highly vigilant to protect against these threats. 
Our people are our most important assets and our top priority and that includes our family members. And, we need to make sure that we are looking out for one another. All of you are an important part of our CENTCOM team, and I want to thank you for your many contributions and your strong support. If you need anything or have additional concerns please do not hesitate to reach out to your service member’s chain of command or the headquarters. 
Be safe!
GEN AUSTIN
COMCENT
    Although General Austin referred to the Paris attacks as 'lone wolf' events, there have been some possible links to al Qaeda uncovered as Thomas Joscelyn reports in the January 19 edition of THE WEEKLY STANDARD, including an eyewitness account that one of the killers said "You can tell the media that it’s al Qaeda in Yemen" during the attack on Charlie Hebdo's offices.


Note: A version of this post first appeared at The Weekly Standard.

Thursday, April 3, 2014

Security Breaches of Personal Information at Federal Agencies More Than Double Since 2009

    Millions of individuals who recently entrusted personal, medical, and financial information to the federal government while enrolling in Obamacare via Healthcare.gov may find a recent trend reported by the Government Accountability Office (GAO) rather unsettling.  The number of security breaches involving Personally Identifiable Information (PII) at federal agencies more than doubled in recent years, increasing from 10,481 in 2009 to 25,566 in 2013.  Perhaps even more disturbing, the GOA found that "none of the seven agencies [in a related study] consistently documented lessons learned from PII breaches."
    A graph accompanying the GAO report illustrates the dramatic and consistent upward trend in PII-related breaches over the last several years:


    A data breach may consist of something as simple as mailing documents containing PII to the wrong recipient, but also includes incidents involving massive loss of sensitive data as illustrated by these examples in the report:
  • [I]n May 2006, the Department of Veterans Affairs (VA) reported that computer equipment containing PII on about 26.5 million veterans and active duty members of the military was stolen from the home of a VA employee. 
  • In July 2013, hackers stole a variety of PII on more than 104,000 individuals from a Department of Energy system. Types of data stolen included Social Security numbers, birth dates and locations, bank account numbers and security questions and answers...
  • In May 2012, the Federal Retirement Thrift Investment Board (FRTIB) reported a sophisticated cyber attack on the computer of a contractor that provided services to the Thrift Savings Plan. As a result of the attack, PII associated with approximately 123,000 plan participants was accessed. According to FRTIB, the information included 43,587 individuals' names, addresses, and Social Security numbers, and 79,614 individuals' Social Security numbers and other PII-related information. 
    While the increasing number of incidents is concerning, the GAO also found that "agencies have had mixed results in addressing" information security "and most agencies had weaknesses in implementing specific security controls."  An earlier GAO report in December 2013 covered the responses to PII data breaches of seven federal agencies, including the IRS; the Centers for Medicare and Medicaid Services (CMS), the agency charged with implementing and running Obamacare; and the Veterans Administration (VA).  That report found agency responses broadly inconsistent.  For example:
  • only one of seven agencies reviewed had documented both an assigned risk level and how that level was determined for PII data breaches
  • only two agencies documented the number of affected individuals for each incident 
  • only two agencies notified affected individuals for all high-risk breaches
  • the seven agencies did not consistently offer credit monitoring to affected individuals
  • none of the seven agencies consistently documented lessons learned from their breach responses
    The GAO report also gives a preview of an upcoming report specifically on cybersecurity at federal agencies, and preliminary results are not encouraging.  The GAO has found effective and consistent response to cyber incidents in only about 35% of cases:
While these results are still subject to revision, we estimate, based on a statistical sample of cyber incidents reported in fiscal year 2012, that the 24 major federal agencies did not effectively or consistently demonstrate actions taken in response to a detected cyber incident in about 65 percent of reported incidents.
    The full GAO report on cybersecurity will be completed and issued later this spring.


Note: A version of this post first appeared at The Weekly Standard.

Monday, March 10, 2014

Senate, EPA, Treasury Websites Vulnerable to Phishing Scams [Updated]

UPDATE: The exit message on the Senate website has changed since this post ran at The Weekly Standard.  It's not perfect because it just lumps potential scamming sites in with the ones that Senators actually want to link to, but it is still an improvement.

--------------------

    Less than a month after the exposure of a widespread vulnerability on government "open data" websites, another perhaps even more insidious opening for abuse of government websites has come to light.  The problem is known as an "unvalidated redirect," and has been found on the websites of the Environmental Protection Agency, the Treasury Department, and even the Senate, among others. The vulnerability is not a new one and could extend back months if not years, and is not an uncommon problem on commercial websites either.
    A "redirect" is a web address that automatically opens a webpage or, in many cases, even a completely different website that the original address, or URL, indicated.  Generally when a government website directs a user to an external site, a warning or disclaimer appears alerting the user. For instance, the Centers for Medicare and Medicaid Services website places a small "world" icon next to external links, and the site has a page explaining the disclaimer:

 
     Other government sites follow a different protocol where a special disclaimer page is displayed for several seconds after the external link is clicked before the users is automatically taken to the new page or site.  While this protocol is not a problem in and of itself, if the website code does not restrict the ability to redirect only to sites approved by host sites, any web address can be substituted.  This can allow unscrupulous website operators to provide a link in a website or an email that begins with a legitimate government address, such as senate.gov or epa.gov, but then quickly and automatically transport users to any website they choose.
    The website for the Senate is an especially serious example of this vulnerability because of the complete lack of a disclaimer on the "exit" page before the redirect takes place.  Senators often will direct website users to pertinent news articles, stories concerning constituent issues, or government services on other federal websites.  However, the following screen is all that users see before they are bounced to the new page or site:

    Since the script for the exit page is not restricted, anyone can establish a link by entering a [web address] after this prefix: http://www.senate.gov/cgi-bin/exitmsg?url=[web address]  For example, this link directs users to Google.com after bouncing off of Senate.gov:  <http://www.senate.gov/cgi-bin/exitmsg?url=http://www.google.com>  But replacing "www.google.com" with any website works just the same way to direct users to that site.  This opening could easily be exploited by inserting this type of link in a phishing email or a website and inviting users to simply click on what appears to be a Senate website address but in reality is a redirect to a phishing site.  At that point, personal information could be solicited with the apparent endorsement of the Senate.
    A bold scammer could even explicitly tell users, for example, that "you will see a message that you are exiting the Senate web server system and being transferred to our secure data collection site."  Without a restriction on redirect links or even a disclaimer, there is nothing to warn an unsuspecting user that the Senate is in no way connected with the linked site.
    The Senate's site is not the only government website vulnerable to this kind of exploitation.  A subdomain of the Treasury Department's website, publicdebt.treas.gov, has a similar problem.  While there is a more complete exit page provided, with a disclaimer ("You're going to a website that is not managed or controlled by the Bureau of the Public Debt. Its privacy policies may differ from ours."), the user is still bounced to the new site (again, using google.com as an example) with the apparent blessing of the Treasury:



    A Google search suggests that this vulnerability does not exist simply in theory, but has been used either innocuously or maliciously already.  Here is a screenshot of a Google search as it existed on March 9:

    Clicking on each of these links automatically transfers users, after eight seconds of the exit page, to a website not connected to or endorsed by the Bureau of the Public Debt of the Treasury Department, yet without a clear warning to indicate such.
    Other vulnerable websites include biometrics.gov, fmcsa.dot.gov, and epa.gov.  Unvalidated redirects linked from these government websites include sites for pornography, weight-loss site, and even a Bible study.  Despite the obvious opening provided for phishing, no actual examples of linked phishing sites were found during the investigation for this story, although phishing attempts are often made via unsolicited mass emails.  In any case, David Kennedy of the information security company TrustedSec,asked to comment for this story, said that these unvalidated redirects are "definitely an exposure."
    The House of Representatives is a good example of a government site that not only has a stronger disclaimer on its exit page, but disallows users from substituting a different web address in its exit URL.  For instance, Rep. Paul Ryan recently linked to a John McCormack piece at THE WEEKLY STANDARD.  The exit page informs users that they are leaving the House website, and users must manually click on the link before being redirected instead of the redirect happening automatically. Additionally, users are told that "Neither the House office whose site contains the above link, nor the U.S. House of Representatives is responsible for the content of the non-House site you are about to access."  Furthermore, an attempt to change the redirect address to a different site or page is met with a "File Not Found" error.
    The unvalidated redirect exposure is an unsophisticated yet effective tool for scammers.  No hacking is required as the referring websites do not actually host any unauthorized pages, but the simplicity actually works to the advantage of potential scammers or those simply seeking to direct additional traffic to their websites.  On the upside, the simplicity also means a relatively simple fix at the affected websites.  But until more government websites follow the example of the House or the Centers for Medicare and Medicaid Services, the unvalidated redirect will remain a prime opportunity for marketers or scammers looking to trade on the authority and sense of security conferred by a connection to the federal government.


Note: A version of this post first appeared at The Weekly Standard.

Friday, February 21, 2014

Widespread Vulnerability Found in Dozens of Government 'Open Data' Websites [Updated]

    At first glance, a page on the Health and Human Services (HHS) website seems to be giving that agency's official advice on the "The Health Benefits of Nootropics," a classification of purportedly memory-enhancing drugs.  The page is found on the website's subdomain of the Assistant Secretary for Planning and Evaluation (ASPE) as part of the Health System Measurement Project.  The page contains the official logo of HHS, the domain in the URL ends with the legitimate HHS address containing "hhs.gov", and the "https://" indicates the connection is even a secure one.  Further down the page, there is even a link to a website selling related products.  A partial screenshot of the profile page at HHS.gov appears as follows:



    Similar pages on the site offer information and counsel on shampoo, surgery, and health issues suffered by computer users.  However, in spite of all the apparently reassuring elements and features of these pages, Health and Human Services had nothing to do with their creation or content, and does not recommend or endorse either the information or the linked products.
    Nevertheless, while the pages are not official HHS information, neither are they technically cases of hacking.  Rather, the creators have exploited a weakness in the "open data" system used by dozens of government websites.  The platform was developed by a company called Socrata.  The system allows users to create profiles and then manipulate data tables that various governments (federal, state, local) host on their websites.  The results can be shared with others for statistical analysis, research, and other purposes, as some users have done. However, in cases like the ones above, a profile page itself can be used to promote a product or information in a way that gives viewers the impression that the host government entity approves or even endorses.  A legitimate looking link could even be included in an email to direct recipients to what they may easily perceive as government-provided information.
    THE WEEKLY STANDARD first reported this opening in January when some internet marketers had created profiles at data.healthcare.gov, the federal government's Obamacare website.  Within a day  after the story ran, Healthcare.gov disabled public access to profiles created for its data site.  At the time, David Kennedy, the CEO of TrustedSec, an information security firm, remarked that the opening could allow scammers to fool users with a "website that’s legitimate to make them believe its something else," and that "an attacker can basically create a functioning website and host any content they want there and under the umbrella of healthcare.gov."
    Use of the profiles can be especially effective since the profiles contain no disclaimers that the government entity does not endorse the content, and there are no warnings when clicking on links that "you are now leaving the website for an external site", a common warning on government sites.
    Health and Human Services is not the only government agency at risk.  The White House announced "Project Open Data" in May 2013 with dozens of federal agencies and sub-agencies taking part.  As recently as January 14, the White House released a Fact Sheet on the White House Safety Datapalooza,  an initiative to safeguard government data that is "part of the Administration’s larger commitment to unleash the power of open data."
    Other examples of profiles such as the one above are numerous, including other federal agencies, plus state, county and local governments.  The products and information being pushed range from private loans to debt consolidation to even "artificial turf":











    Each of the pages above (and dozens of others discovered in the preparation of this story) contains a link to an external website that is obviously not an officially sanctioned site by the government host, but neither are there any disclaimers to warn potential viewers.  The pages appear to violate the Terms of Service of the Socrata platform since "[u]nsolicited promotions, political campaigning, advertising or solicitations" are prohibited.
    More malicious sites could be used for data harvesting or even identity theft since scammers are able to trade on the credibility conferred by the official government websites that host these profile pages.  THE WEEKLY STANDARD has no direct evidence that such activity has yet taken place via an "open data" website, but at this point, clearly the door is wide open to such abuse.  
   An email to an official at Data.gov seeking comment was referred to another official who has not yet responded.  An emailed request to Socrata for comment was initially returned Tuesday evening with a promise of a response, but so far, no additional response has been received.

UPDATE: By the end of the day on Thursday, public access to Socrata profiles had been disabled.  Clicking on links to the profiles now redirect users to a login page.  Neither the government nor Socrata ever acknowledged the vulnerability nor issued any statement regarding the issue despite earlier promises to respond.  Tim Cashman, a Senior Content Strategist at Socrata, initially responded to an email Tuesday night with a promise to "be in touch with a response shortly", and Steven Gottlieb, a Socrata PR contact, and Bill Glenn, VP of Marketing, were both cc'd on his reply.  Several followup emails to all three Socrata representatives, however, were ignored.


Note: A version of this post, before the update, first appeared at The Weekly Standard.

Wednesday, February 12, 2014

Feds' Climate Change Website Hacked By Online Drug Seller

    The website of the U.S. Global Change Research Program (USGCRP) was repeatedly hacked on Monday and Tuesday this week by an online drug retailer.  A Tuesday Google search of the site, www.globalchange.gov, revealed dozens of pages hawking everything from Xanax to Levitra to Ambien. A partial list is shown in the screen grab below:


    Clicking on the links immediately redirected users to a website called "HealthLife", which bills itself as "the leader in delivering medications throughout the world".  The site appears to be registered in the United States:



    While the links were redirects, a cached page (no longer available) revealed that the Global Change site itself contained unauthorized pages as well, such as this one:


    By Tuesday afternoon, the hacking had apparently been discovered and the unauthorized pages were deleted.
    The U.S. Global Change Research Program identifies itself as dealing not only with climate change, but "land productivity, oceans or other water resources, atmospheric chemistry, [and] ecological systems":
The U.S. Global Change Research Program (USGCRP) is a Federal program that coordinates and integrates global change research across 13 government agencies to ensure that it most effectively and efficiently serves the Nation and the world. USGCRP was mandated by Congress in the Global Change Research Act of 1990, and has since made the world’s largest scientific investment in the areas of climate science and global change research.
    An email to the USGCRP requesting comment has not yet been returned.


Note: A version of this post first appeared at The Weekly Standard.

Friday, October 4, 2013

HHS-Run Website Hacked; Now Selling NFL Jerseys, Ugg Boots, Armani Fragrances [UPDATED]

    A portion of the website of the Substance Abuse and Mental Health Services Administration (SAMHSA) was apparently hacked as long as two months ago.  SAMHSA is an agency of the Department of Health and Human Services (HHS).  HHS also runs the new Obamacare insurance marketplace, Healthcare.gov.
    Dozens of pages hawking retail merchandise have been uploaded to the SAMHSA site, ranging from NFL jerseys to Uggs shoes to Armani fragrances.  Screen captures of the various pages are shown here:






     Clicking on the pages in some cases takes users directly to an external website; other times, certain functions seem to operate within the samhsa.gov site.  Of the websites investigated, two domains are registered in the United States and one in China.
    All of the instances uncovered by this investigation are under the sub domain nace.samhsa.gov, which is the Native American Center for Excellence.  The first breach discovered dates back to July 29 of this year, and the unauthorized pages are still on the site.
    In September, a portion of NASA's website was hacked by a Brazilian group protesting reports of spying in that country by the National Security Agency.



UPDATE:  Shortly after this story was posted, the site (nace.samhsa.gov) returned an error message saying that the site could not be found.  Later, the following message appeared on the site (misspelling included, [since corrected]): "This site is undgoing maintenance. We are sorry for any inconvenience this has caused you."  Here's a current screen capture:


    While clicking on the original links in the story above return "file not found"messages, at least one of the pages is available via a Google cache here showing how the page appeared as of October 3.  A Google search of the site still turns up dozens of links to other pages from the hacking.  The "undergoing maintenance" message on the SAMHSA website comes in spite of the fact that many government websites have been shuttered or severely limited due to the ongoing federal government shut down.


Note: A version of this article first appeared at The Weekly Standard.