Wednesday, 18 January 2017

Scary new way to have your GMail password and account stolen.

This is an incredibly easy way for the evil doers to steal your GMail ID and password. This one could even catch out security people like me! 😱

So what happens is you receive an e-mail from somebody you know, who also had a GMail (note the emphasis on had). 

This e-mail will have a subject line of a previous e-mail conversation that you have had with that person and also, what appears to be an, attachment that had been attached in an earlier e-mail in that conversation. So far this e-mail is looking EXTREMELY legitimate.

That attachment, is actually an image in the e-mail with a link embedded in it and if you click on it, it will take you to, what appears to be, the GMail log-in screen, as follows:
Being asked to log-in like this would certainly trigger an alert in my mind that something was up. I would immediately check to see where this password page has come from, so I would look up at the address bar of the browser. This is what you would see:

So that looks OK doesn't it? https:// (nice and secure site) accounts.google.com (legitimate address) and the e-mail came from somebody I know, from an e-mail conversation I have had with them, that had an attachment, which was here again in this new e-mail. All very believable! So let me enter my GMail ID and password and ... you've now given the hackers your credentials.

Within minutes, they will have taken over your GMail account and will be sending this nasty surprise e-mail to your friends, family and colleagues.

So how do I know it's not a legitimate GMail login screen? Let's take another look at that address bar:

That first part of the address (highlighted) looks a bit odd, don't you think? It is very odd. It actually has a verrrrrrrrry long string of text, which stretches off beyond the end of what you can see in the address bar that executes a script, which brings up that log-in page.

Also, if you know your secure websites, you know that where there is proper https:// there is also a green padlock symbol like this:

That gives a high degree of confidence that the site is legitimate and properly secure.

Here's the best possible protection

I've said this numerous times. I tell everyone I know, that they must set this up to protect their accounts. 

It is known by many names - Two factor authentication or Two step verification or Login approvals.

I've a whole commandment dedicated to it, so please have a read and please implement it.

This protection, won't prevent you falling for the scam outlined above. What it will do is prevent the bad guys from accessing your account, even though they have your GMail ID and Password, they won't have your smart phone and as such won't be able to sign in as you.

Please implement Two factor authentication on all your on-line accounts. It really gives you the best possible protection.

h/t to the folks over on WordFence for the details on this.

Saturday, 31 December 2016

What will 2017 bring in Cyber Security?

5 Cyber Security Predictions for 2017

Lots of people do these type of lists, but since this is the end of my first year in business, I might as well be no different.😏

1. Ransomware levels will plateau, but constantly change

This might be an easy one to get right. Ransomware is already embedded in over 90%+ of all phishing e-mails, so there's hardly any further room to keep growing. We've already started to see the way it is changing though. As was reported earlier this month, you could get your files unlocked if you infected two friends with this Ransomware rather than paying money over to the hackers.

2. Smart Device Botnets will target the big service providers

We've seen record breaking botnets created this year by poorly designed and poorly secured smart devices (also referred to as IoT, e.g.- internet connected cameras, digital video records, internet routers, etc.). I suspect the evil doers are building a massive army, much bigger than anything we have seen to date. I believe that they will then carry out a coordinated attack on one of the big service providers (e.g.- Google, Amazon or Microsoft). The attack won't be fully successful, but will have caused sufficient disruption to make smart device security a focus for all manufacturers of such devices, as insecure devices will be banned from accessing the web.

3. There will be an even bigger data leak than 2016's revelation of the Yahoo! world record leak

Yahoo! has really had a bad year, setting a world record, having already had an even bigger world record. I believe bigger leaks have already happened and will be revealed next year. I reckon the bad guys are already combing through the data, cracking passwords and will then create tools that will take the IDs and passwords they have and try these against other services (e-mail, social media, etc.) to generate a list of compromised accounts, which are extremely valuable on the dark net.

4. Russia will be accused of interfering in elections occurring across Europe

Russia has shown form this year, interfering with the US Presidential Election. With elections happening in the bigger European Countries (Germany, France and The Netherlands) in 2017, I would not be very surprised to discover that the Russian state hackers tried to influence the results of these.

5. More Irish people will be protecting themselves from Cyber Threats


I'll be a bit selfish with this one as I will be the one helping these people to protect themselves. People knowing how to stay safe on-line will be the least likely to be affected by a Cyber Threat.

Happy New Year to you all!

So I'll come back in 364 days and see how I did. Then the following day, I'll make another list. 😃

Wishing all my clients and contacts and safe and secure 2017.

Let's be care out there.

Thursday, 29 December 2016

Facebook Messenger scam ... it's nothing new, but it's still effective.

I've seen evidence of this scam occurring amongst my Facebook friends this Christmas. It's a straightforward phishing scam, where one of your friends sends you a Facebook Message with an apparent link to a video of you. Sometimes they might ask "Is this you?" or tell you to go a specific point in the video to see yourself. Of course what has happened is your friend's account has been hacked and the scammers are using your friend's contact list to spread their evil wares.

This is an example of a message that a friend of mine received from one of their Facebook friends. I've blurred the pics and redacted the name to protect the parties involved:
This is pretty compelling. It looks like there is a video of you on YouTube with nearly 384K views. You've got to go see what everybody is looking at ... right? 

WRONG!

If you click on this, it will either take you to a web page that asks you to sign-in to Facebook with your ID and password or it tries to install a facebook app and looks for various permissions to your Facebook profile.

If you proceed with either signing in or installing the app, then your Facebook profile now belongs to the bad guys. They will mercilessly spam and phish your Facebook friends. 

If you have fallen for this, then first thing to do is remove the app from your Facebook account (if it has access). Go to Facebook -> Settings -> Apps and locate the offending app and remove it's access. You could also go into Facebook -> Settings -> Blocking and block the app there too.

Next thing you must do is change your Facebook password. You will find this under Facebook -> Settings -> General.

And finally, if you had used the same password for Facebook and for your e-mail, for the love of dogs, change your e-mail password right now and change it to something else completely different to your Facebook password. If the evil doers compromise your e-mail account, your online life will become a lot more troublesome for you than a few spammy Facebook messages.

Finally, finally - if you have not already done so, turn on Two Step Verification/Login Approvals/Two Factor Authentication, whatever they call it, on your all of the on-line accounts that you have, which have this feature. What this means is that not only do you have to have your user ID and password to access your account, but also a code generated by an App on your phone or a text message sent to your phone which adds another layer of protection. If the bad guys get your ID and password, they won't be able to compromise your account without access to your phone.

There's more detail about this subject here:

Let's be careful out there.

Thursday, 22 December 2016

Could the attempted theft of €4.3m from Meath County Council happen to your business?

As was widely reported at the weekend, Meath County Council were the victim of an attempted theft of some €4.3 million. A lot of the reportage was pointing to hackers and this being a cyber attack, but based on what is known, in my opinion, it's not really.

This attempted theft was facilitated by the use of technology, but not necessarily the abuse of it. They're no longer commenting about it now while the matter is investigated, so we'll need to await the outcome of that before we know for sure.

However this sort of theft is incredibly common and is known variously as CEO fraud or Business Email Compromise (BEC). Basically what the bad guys do, is send an e-mail or even a text message that appears to come from the CEO, the MD, the Head Honcho, the Big Boss. This e-mail/text is sent to somebody in the finance department and it instructs them to urgently transfer or wire funds to some account that is outside of the EU area. If the transfer was within the EU area, it can be recalled under SEPA regulations, but outside of the area the money can be a taken and never seen again. 

Wednesday, 21 December 2016

Don't ignore that e-mail from Lynda.com

I received two e-mails in recent days from online training provider Lynda.com customer care, this is because I have had two accounts with Lynda.com in the past. Both were set-up when they had a 30 day free trial offer, which I made use of.

I'm one of the 9.5 million customers/former customers of Lynda.com who have been contacted by them about a breach of their data security. They state that my contact information and courses taken were compromised, however they believe my password was not compromised. Here is the text of the e-mail:
We recently became aware that an unauthorized third party breached a database that included some of your Lynda​.com learning data, such as contact information and courses viewed. We are informing you of this issue out of an abundance of caution.
Please know that we have no evidence that this data included your password. And while we have no evidence that your specific account was accessed or that any data has been made publicly available, ​we wanted to notify you as a precautionary measure.
So this doesn't sound so bad. Right?

Tuesday, 20 December 2016

Yahoo! tries for new world record and wins ... but it already had the world record!

You all heard the headlines during the year about the massive Yahoo! hack, where in late 2014, hackers had stolen the names, addresses, mobile telephone numbers, dates of birth, security questions and passwords of 500+ million accounts. This was a new world record for the amount of user accounts stolen on the internet.

Well bless their cotton socks, Yahoo! had actually already done even better and they didn't even realise it. In 2013 over 1 billion accounts had the same type of information stolen, including poorly protected passwords. Yahoo! had no idea that this had happened. It wasn't until somebody provided the authorities with details that they had come across on the web. The authorities brought this to Yahoo! in October/November, which was when they were still thrashing around after the the September revelations about the 500m accounts, and I can just imagine their response...


Monday, 19 December 2016

Do you own a Netgear router? If so, you may have a serious vulnerability.

Netgear Routers Vulnerable


If you have one of the following Netgear router models, you could be exposed to a serious vulnerability:
  • R6250
  • R6400
  • R6700
  • R7000
  • R7100LG
  • R7300
  • R7900
  • R8000
There is a simple test that you can carry out to determine if you have a vulnerable router. From a device connected to the router, open the following link in a browser:
     http://www.routerlogin.net/cgi-bin/;echo$IFS'Vulnerable!'
If you see a simple webpage that says Vulnerable!, then you have an affected router.

The risk with this vulnerability is that hackers can scan the internet looking for these routers and if they detect one, they can take it over quite simply and use it for nefarious purposes.

Netgear have made some patches available, but not for every model at the moment. These patches require technical skills to install safely, so please contact your IT support provider. Don't expect your teenager to be able to do this, unless they have already had experience of flashing router firmware successfully before. Making a mistake when doing this, could render the router unusable.

While you await for the router to be patched, you can protect yourself by opening the following link in a browser:
Once you have done that try the previous link above to see if it still says Vulnerable! 

If you reboot/restart the router after this, you will need to open that last link above again.

If you have any questions or concerns, please contact us on info@L2CyberSecurity.com or call us on 087-436-2675.