FACEbook

Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Monday, August 17, 2015

Government Websites Vulnerable to Phishing Scams

     The websites of several federal government agencies, including the National Weather Service (NWS), are unprotected from scammers looking to exploit a security weakness to fool potential victims. The sites in question allow what are known as "unvalidated redirects." An unvalidated redirect is a link to an external website that appears to be sanctioned by the sending website, but in reality can be created by anyone, including scammers and identity thieves. In many cases, the redirects do not even require an additional click; users are taken to the external website automatically after a short pause as an exit message is displayed.
     The website for the National Weather Service, www.weather.gov, has been a favorite target for those seeking to exploit the unvalidated redirect vulnerability. A Google search shows an extensive list of hundreds of websites linked with an automatic redirect. Some are legitimate, such as one on lightning strikes, but more common are those hawking website hosting, insurance, and even herpes cures:

     The links begin with the legitimate address of the National Weather Service, www.weather.gov. Clicking on these links, which can be embedded in other websites or included in an email, first brings up a page alerting users that they are exiting the NWS website and that the link does not constitute an endorsement of the site. However, the page also says, "NWS provides a link to this site because it may contain related information of interest to you." Following is a screenshot of the page that appears for about 10 seconds before, in this case, the user is taken to a video extolling the virtues of a natural cure for herpes:


     This is not the first time the federal government has exposed itself this way. In March 2014, an investigation by THE WEEKLY STANDARD found that the website of the US Senate, along with several others, were susceptible to this vulnerability. Soon after that story was published, the Senate website changed the exit message to include a more explicit warning and also to require an additional click. However, the website script still allows any web address to be entered as a redirect.
     The biometrics.gov website is another favorite platform for those seeking to exploit the unvalidated redirect. This website, pointed out in the 2014 story, is still being utilized more than a year later by dozens of external websites including a Turkish LGBT site, a site for diet pills, a poker blog, a site touting "manly yoga", and even a Bible study.
     Some sites are greater risks than others. For example, a subdomain of the website for the National Institutes of Health (nhlbi.nih.gov) is vulnerable. A malicious programmer could provide users what appears to be a legitimate NIH website address, but use a redirect to a website that could harvest personal and health information from unsuspecting victims. The NIH exit page contains some warnings, but since the page is only visible for 10 seconds before the automatic redirect kicks in, there is too little time to actually read the entire page. Serve.gov is yet another website with a complicated exit page that could misdirect those looking for opportunities for community service to a scammer's site instead.
     Many websites contain links to external sites, but the scripts to handle these links can be configured to prevent this type of manipulation. Due to the presumed authority of government websites, the unvalidated redirect vulnerability is particularly pernicious. The Open Web Application Security Project, a non-profit group that seeks to improve software security, lists the unvalidated redirect in its top ten list of security vulnerabilities, noting that "[w]ithout proper validation, attackers can redirect victims to phishing or malware sites, or use forwards to access unauthorized pages."



Note: A version of this post first appeared at The Weekly Standard.

Wednesday, January 14, 2015

Pentagon Calls Paris Attack 'Lone Wolf'' Event, Twitter Hacking 'Cyber Vandalism'

    The Pentagon called the hacking of the Central Command's (CENTCOM) YouTube and Twitter accounts Monday "cyber vandalism" in a letter to service members and their families to allay concerns about the incident. General Lloyd Austin said that the FBI is investigating the "alleged breach" of the two social media sites by hackers who claimed to be aligned with the Islamic State (ISIL.) While Austin said that "CENTCOM network was not compromised and no classified information," he acknowledged that the hackers posted "information obtained from the accounts," though he did not go into further detail.
    Austin also referred to "the threat of ‘lone wolf’ attacks by individuals who align with or are sympathetic to radical Jihadist elements," examples of which, according to Austin, are the "recent tragedies in Paris..., New York City and Ottawa, Canada." The general acknowledged that Monday's hacking included threats, but said there were no "no credible threats made to U.S. military personnel or their families."
    In any case, Austin said, the military is taking the threats "very seriously" and will "take all possible measures" to keep military personnel and their families safe.
    The full text of General Austin's letter is here:
This week, hackers claiming to be aligned with the extremist group ISIL took control of CENTCOM’s Twitter and YouTube accounts for approximately 30 minutes. They posted tweets with information obtained from the accounts and they also posted threats against military members and their families. 
I recognize that this has caused significant angst among family and friends who are understandably concerned about their loved ones’ safety. I want to personally reassure you that we are taking this matter very seriously and we continue to take all possible measures to keep our personnel safe. 
With respect to the alleged breach of our Twitter and YouTube accounts, The Federal Bureau of Investigation is in the process of conducting a full investigation. However, you should know that the CENTCOM network was not compromised and no classified information was obtained by the group. Also, as yet, there have been no credible threats made to U.S. military personnel or their families. 
That said, we do not take these threats lightly, and we will do what is necessary to mitigate them. Unfortunately, the threat of ‘lone wolf’ attacks by individuals who align with or are sympathetic to radical Jihadist elements exists today, and we’ve seen this demonstrated with the recent tragedies in Paris and before that in New York City and Ottawa, Canada. We must all take the necessary precautions and be highly vigilant to protect against these threats. 
Our people are our most important assets and our top priority and that includes our family members. And, we need to make sure that we are looking out for one another. All of you are an important part of our CENTCOM team, and I want to thank you for your many contributions and your strong support. If you need anything or have additional concerns please do not hesitate to reach out to your service member’s chain of command or the headquarters. 
Be safe!
GEN AUSTIN
COMCENT
    Although General Austin referred to the Paris attacks as 'lone wolf' events, there have been some possible links to al Qaeda uncovered as Thomas Joscelyn reports in the January 19 edition of THE WEEKLY STANDARD, including an eyewitness account that one of the killers said "You can tell the media that it’s al Qaeda in Yemen" during the attack on Charlie Hebdo's offices.


Note: A version of this post first appeared at The Weekly Standard.

Friday, February 28, 2014

Website of U.S. Commission on International Religious Freedom Hacked, Malware Found [Updated Again]

UPDATE: As of Friday morning, access to the site was no longer blocked.  But the diagnostic page with the detail of the intrusions remains.
UPDATE 2: I received an email back from the USCIRF explaining the problem:

Thanks for your inquiry we have been migrating the site to a new design and there was a problem with a redirect that triggered the Google alert. The redirect has been corrected and alert is removed.
-------------------------------

    From Obamacare's contraception mandate to Arizona Governor Jan Brewer's recent veto of her state's Religious Freedom Restoration Act, many feel that religious freedoms are increasingly under attack.  The attacks took on a cyber-twist this week with a hacking attack on the website of the United States Commission on International Religious Freedom.   The attack was deemed serious enough that Google has blocked access to the site from its Chrome browser; instead, the following screen appears:


    Google provides a detail of the attacks that the company has detected which prompted the warning. Google testing revealed that visiting "27 page(s) resulted in malicious software being downloaded and installed without user consent."  Google found malicious software on the site, including a "trojan" of which it is reported that "Successful infection resulted in an average of 3 new process(es) on the target machine."


    There is some ambiguity in Google's warning as the statement "this site has not hosted malicious software over the past 90 days" also appears.  This may be a reference to third-parties being responsible, as well as hackers using the site to "function as an intermediary" to infect other sites.