Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, April 27, 2011

Sony Playstation Network Hacked

I'm so pissed off right now just got an E-mail from Sony that their network was compromised and all sorts of personal information was compromised. I know I will no longer be buying Sony products if they can not be professional enough to have robust security to protect my information they don't deserve my business. A copy of the E-mail follows below let me know what you think?

Valued PlayStation Network/Qriocity Customer:

We have discovered that between April 17 and April 19, 2011, 
certain PlayStation Network and Qriocity service user account 
information was compromised in connection with an illegal and 
unauthorized intrusion into our network. In response to this 
intrusion, we have:

1) Temporarily turned off PlayStation Network and Qriocity services;

2) Engaged an outside, recognized security firm to conduct a 
full and complete investigation into what happened; and

3) Quickly taken steps to enhance security and strengthen our 
network infrastructure by rebuilding our system to provide you 
with greater protection of your personal information. 

We greatly appreciate your patience, understanding and goodwill 
as we do whatever it takes to resolve these issues as quickly 
and efficiently as practicable.

Although we are still investigating the details of this incident, 
we believe that an unauthorized person has obtained the following 
information that you provided: name, address (city, state/province, 
zip or postal code), country, email address, birthdate, PlayStation 
Network/Qriocity password, login, password security answers, and handle/PSN 
online ID. It is also possible that your profile data may have been obtained, 
including purchase history and billing address (city, state/province, zip 
or postal code). If you have authorized a sub-account for your dependent, 
the same data with respect to your dependent may have been obtained. 
While there is no evidence that credit card data was taken at this time, 
we cannot rule out the possibility. If you have provided your credit card 
data through PlayStation Network or Qriocity, out of an abundance of caution 
we are advising that your credit card number (excluding security code) and 
expiration date may also have been obtained.

For your security, we encourage you to be especially aware of email, 
telephone, and postal mail scams that ask for personal or sensitive 
information. Sony will not contact you in any way, including by email, 
asking for your credit card number, social security, tax identification 
or similar number or other personally identifiable information. If you 
are asked for this information, you can be confident Sony is not the 
entity asking. When the PlayStation Network and Qriocity services are 
fully restored, we strongly recommend that you log on and change your 
password. Additionally, if you use your PlayStation Network or Qriocity 
user name or password for other unrelated services or accounts, we 
strongly recommend that you change them as well.  

To protect against possible identity theft or other financial loss, 
we encourage you to remain vigilant, to review your account statements 
and to monitor your credit or similar types of reports.  

We thank you for your patience as we complete our investigation of 
this incident, and we regret any inconvenience.  Our teams are working 
around the clock on this, and services will be restored as soon as 
possible. Sony takes information protection very seriously and will 
continue to work to ensure that additional measures are taken to 
protect personally identifiable information. Providing quality and 
secure entertainment services to our customers is our utmost priority.  
Please contact us at 1-800-345-7669 should you have any additional questions.

Sincerely,

Sony Computer Entertainment and Sony Network Entertainment


Digg!

Monday, May 19, 2008

MICROSOFT Blames Users For security Holes

MICROSOFT Blames Users For security Holes

Well well well, This goes down as one of the cutest excuses of the year award. Microsoft says "The number of virus infections found by a virus vendor does not necessarily equal poor security," wrote Kleef in a blog post. "In many cases it equals poor user behavior. If I, despite all prompting and consent behavior, choose to go to a (probably dodgy) website, accept the ActiveX control prompts to download (probably dodgy) code and I actually choose to execute that code then I'm hosed."

Well is that not convenient as the church lady would say from Saturday night live, Hmmm Maybe Satan made you you do it? When I write I try and think of things from the point of view of the average user, as thats what I am. I'm not a techy, and I'm most definitely not a computer software developer, but this sure as hell sounds to me like the hopelessly useless account user interface on Vista is being used as a way to blame user's for Window's flawed code.

I would like to ask Microsoft how many user's can tell what is a good active X control and what is dodgy? I know I can't, but I do know many websites have them and I can tell you when I say yes using Microsoft's account control it give's me no useful information whatsoever to tell me if it's dodgy or not, it just let's me know something is going on, but I have no idea if thats a normal process or not. Microsoft stop blaming the customer. I want to know what do you think? Is Microsoft right is the User to Blame?

Microsoft has claimed user "complacency" is to blame for malware infections, and denied that its Vista operating system is less secure than Windows 2000.

The claim that Vista is less secure than Windows 2000 was made last week by security vendor PC Tools, which said that over the past six months Vista had suffered 639 unique threats, whereas Windows 2000 has suffered 586. PC Tools's research was conducted by collecting data from customers using its ThreatFire behavioral detection software.


"Ironically, the new operating system has been hailed by Microsoft as the most secure version of Windows to date," said Simon Clausen, the chief executive of PC Tools last week.


"However, recent research conducted with statistics from over 1.4 million computers within the ThreatFire community has shown that Windows Vista is more susceptible to malware than the eight-year-old Windows 2000 operating system, and only 37 percent more secure than Windows XP," Clausen said.


However, Microsoft strongly hit back at the claims, blaming users for executing malicious code on their machines. On Tuesday, Technet blogger and Microsoft evangelist Michael Kleef said the number of infections found by PC Tools was an indication of poor user behavior.


"The number of virus infections found by a virus vendor does not necessarily equal poor security," wrote Kleef in a blog post. "In many cases it equals poor user behavior. If I, despite all prompting and consent behavior, choose to go to a (probably dodgy) website, accept the ActiveX control prompts to download (probably dodgy) code and I actually choose to execute that code then I'm hosed."


Kleef claimed the number of infections was not purely the operating system's fault, but said that "in some cases it's the user and their lack of knowledge and their implicit 'it-won't-happen-to-me' complacency" that causes them to get infected.


Kleef's comments followed on from a blog post on Friday by Austin Wilson, the director of Windows Client Security Product Management, which also denied that Vista was less secure than Windows 2000. Wilson said results collected from over 450 million uses of Microsoft's Malicious Software Removal Tool (MSRT) and published in Microsoft's most recent Security Intelligence Report show Vista is more secure than Windows 2000.


"Our results published in the April 2008 version of the Security Intelligence Report show that Windows Vista is significantly less susceptible to malware than older operating systems," wrote Wilson in the blog post. "Using proportionate numbers, MSRT found and cleaned malware from 44 percent fewer Windows Vista-based computers than Windows 2000 SP4 computers and 77 percent fewer than from computers running Windows 2000 SP3."


Digg!

Thursday, March 22, 2007

The Gozi Strikes Back ( Russian Gozi Trojan powering massive ID-theft ring)

I have just taken two points from the article below "Users state-of-the-art, modularized Trojan code" " Launch attacks through Internet Explorer browser exploits"

Now if you read The article it's rather scary, that all that information was being gathered and put up for sale and even might still be up. When is Microsoft going to take security seriously?

Even with Vista that was delayed a year, has bugs up the gazooo, one reason why a lot of Business are reluctant to jump on board.

My advice stay with XP and try and make sure you can be as secure as you can be. Remember though, even then you could still be prone to attacks as long as Windows chooses to make security a lower priority. Let me know what you think? Are you tired of this? What Should Microsoft Do?


Russian (Gozi) Trojan powering massive ID-theft ring by ZDNet's Ryan Naraine -- Researchers at SecureWorks have stumbled upon what appears to be a massive identity theft ring using state-of-the-art Trojan code to steal confidential data from thousands of infected machines in the U.S. The Trojan, which connects to a server in Russia, has so far pilfered information from more than 5,200 home computers with 10,000 account records. The [...]

Monday, March 05, 2007

WordPress Hacked/Cracked


It seems that the servers for Wordpress a popular program for Blog Publishing was Cracked.


An unknown cracker broke into a server hosting downloads of the popular WordPress blogging software and rigged the file with a remotely exploitable code execution vulnerability.
News of the hack comes directly
from WordPress creator Matt Mullenweg:
"If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately."

Mullenweg described the code planted into the download as "unusual and highly exploitable" and stressed that the 2.1.1 download was the only thing touched during the attack.
"This is the kind of thing you pray never happens, but it did and now we're dealing with it as best we can. Although not all downloads of 2.1.1 were affected, we're declaring the entire version dangerous and have released a new version 2.1.2 that includes minor updates and entirely verified files. We are also taking lots of measures to ensure something like this can't happen again, not the least of which is minutely external verification of the download package so we'll know immediately if something goes wrong for any reason, he added.
He did not say how the attacker was able to breach the server.
Now, WordPress is trying to get the word out to any user who may have downloaded the rigged version 2.1.1.

If your blog is running 2.1.1, please upgrade immediately and do a full overwrite of your old files, especially those in wp-includes. Check out your friends blogs and if any of them are running 2.1.1 drop them a note and, if you can, pitch in and help them with the upgrade.
If you are a web host or network administrator, block access to "theme.php" and "feed.php," and any query string with "ix=" or "iz=" in it.


Friday, October 20, 2006

McAfee, Symantec and vested interests

I found this to be an interesting article, as I do find it strange they want to hide the kernel so to speak and I'm really not sure why this guy supports that. It's my opinion that having something open makes it more secure, because more people get a chance to attack it and find ways to fix it.

Is it just me or does anyone see the irony in that Microsoft has had years of lax security that helped create the industry's that help protect those breaches, now late into the game Microsoft comes out with it's Onecare product line. So you have a company that is selling something that is flawed, and now are selling you the product to fix those flaws, anyone see a conflict of interest there?

http://blogs.zdnet.com/carroll/?p=1611&tag=nl.e622

McAfee, Symantec and vested interests Posted by John Carroll @ 9:25 am
Digg This!

Vested interests often force governments to continue with policies that are counter-productive, if not downright negative. Examples aren't hard to find. Even if congress had the will to confront the vested interests that protect all the various deductions in the US tax code and create something that is clean and simple, truckloads of lobbying dollars would be spent by tax preparation companies to block the changes. Mandatory minimum sentencing laws are strongly supported by the private companies that build and maintain many of America's prisons, even as those laws swell America's prison population to levels not typically found in nominally "free" nations. Likewise, the DEA and companies that support them can be expected to fight against any attempts to stop America's futile war on drugs, a war that sends Bolivian leaders into the arms of Hugo Chavez, funds both sides in Colombia's civil war (think Al Capone times 1 million) and provides a steady stream of cash to Afghani insurgents through sale of poppies - the raw material used in heroin.

Though Symantec and McAfee lobbying the EC on behalf of their ability to hook the Windows kernel doesn't wreak as much havoc as these other vested interests, as an instance of business interests using government to warp policy in selfish directions, it falls into the same category. This smells of companies trying to preserve the flaws in a product upon which they have built their businesses. Really, does anyone in these forums WANT third parties to have access to the Windows kernel? The fact that no one does is why McAfee/Symantec aren't trying to defend the inherent value of such access and opt instead for the "futility" argument. The core of the argument is that PatchGuard won't work and that hackers will find workarounds that McAfee will have to ride in and fix for Microsoft. Essentially, there's no point in Microsoft trying to protect the kernel because they will never make it bulletproof, anyway. Following that reasoning to its logical conclusion, Microsoft shouldn't bother to alter its software development processes so as to emphasize secure coding techniques, given that perfection is impossible, and from a business standpoint, deprives Symantec and McAfee of the opportunity to protect consumers from the consequences of those flaws. As noted, I'm not seeing many in ZDNet Talkbacks rushing to defend McAfee and Symantec in their quest, probably because they DON'T WANT Symantec and McAfee to have that kind of access.

If McAfee and Symantec want to do something useful, they should build products that help to to enforce the kernel protections represented by PatchGuard. What they should NOT be doing is trying to prevent Microsoft from locking down the kernel in the first place. People really should read this blog post by Stephen Toulouse, a program manager in Microsoft's Security Technology unit, as it clarifies considerably the situation as it pertains to kernel hooking past, present and future. http://www.stepto.com/default/log/displaylog1.aspx?ID=258

Some useful excerpts…

Regarding Microsoft's past encouragement of kernel hooks: Wrong. For the implementation of the 32 bit kernel of Windows, there existed undocumented and unsupported system hooks into the kernel. Their use was frowned upon, even inside Microsoft. It's simply not a safe practice to utilize these interfaces into the kernel. Regarding the termination of support for kernel hooks being something that is "new:" Wrong.

Kernel Patch Protection was implemented almost 2 years ago in Windows XP x64 edition and Windows Server 2003 x64 edition. Regarding supposed "insecurity" resulting from a ban on kernel hooks: What security vendors are misrepresenting, is that only through unrestricted access to modify the kernel at the highest level of privilege can they protect you.Of course, the referenced blog predates Microsoft's decision to enable in some as of yet undetermined fashion a means by which to enable kernel hooking "in a secure fashion."

On that note, consider the perils of such an approach as explained at the end of Mr. Toulouse's blog. First, you grant one, pretty soon you have to grant thousands. That's how many people are out there using these undocumented, unsupported interfaces into the kernel.

Second, the more exceptions you grant, the more you dilute the protection. Attackers will simply morph their attacks to try and mimic the "safelist" to get an exception – this may be as simple as malicious software “bundling” third party software in order to disable the protection.

Third, because the OS was still designed to be run with the unmodified kernel, you still have the problem of code running at highest possible privilege crashing the system or causing performance problems.

Fourth, by granting an exception list you introduce a huge performance problem into the kernel, as you force it to check a safelist with every single operation.

Fifth, how would the logistics for adding and removing exceptions work? Would it only be done in software updates? Service Packs? Would someone sue because we weren't fast enough implementing them into a safelist?

That last issue is particularly worrisome for Microsoft, and constitutes the problem with selectively allowing people to have access to the kernel. If McAfee and Symantec get access, you can expect most security companies to want comparable access, and once that happens, the question becomes: how big do you have to be to have access? Pandora's box, truly.

Like prison construction companies encouraging policies that lock up as many people as possible (let's not call them prisoners; let's call them "customers"), McAfee and Symantec are trying to encourage an architecture that "needs" the fixes of a McAfee and Symantec. In so doing, they show how self-interest and government controls over software design collide to create "solutions" that have little to do with benefitting consumers.

Thursday, October 12, 2006

Zero Day

Here is an article about even more security flaws in XP. I really don't understand how Microsoft can come out with operating systems that are so prone to problems like this.

Microsoft releases 6 patches for flaws

October 12, 2006 - 12:16PM

Microsoft has released six patches to fix software flaws that carry its highest threat rating, including three for defects that attackers were already trying to exploit.
The company said all six of the critical flaws could allow an attacker to obtain some access to other people's computers.

The software maker also released four other patches to fix vulnerabilities that the company deemed less severe.
Customers can download all the patches for free on Microsoft's security website and also can sign up to have them automatically delivered to their computers. The automatic update system went down for several hours on Tuesday, but the problem was later resolved.
Microsoft said last month that it knew attackers were already trying to take advantage of defects in its Windows operating system, Microsoft Word software and PowerPoint presentation program.

Christopher Budd, a program manager with the Microsoft Security Resource Centre, said that the company had seen limited attacks exploiting the flaws, but were nevertheless recommending that users apply those and other patches immediately.
Such vulnerabilities are rare. In most cases, security experts quietly provide Microsoft evidence of a security flaw, allowing the company to fix the problem in secret and release a patch before attackers can take advantage of it.
But recently, the company has been hit with a number of so-called "zero-day" attacks, in which flaws are targeted before Microsoft is aware of them or can release patches.
Such attacks have prompted some security researchers to release their own interim fixes. Microsoft also has occasionally taken the unusual step of releasing patches outside of its normal monthly fix schedule, so users can be safeguarded more quickly.

Budd said Microsoft isn't seeing any specific pattern to the burst of zero-day attacks. But he said the company is seeing more focus on attackers trying to infiltrate computers through applications - such as Word or PowerPoint - rather than the Windows operating system.
Microsoft software is a constant target of internet attackers, in part because the company's products are so widely used.
Microsoft has yet to release a patch for one other publicly known flaw - one affecting the Internet Explorer browser that is part of its Windows operating system. Budd said the company was seeing very few attacks as a result of the flaw.

AP