<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CISSP &#124; Information Security Training &#124; CISSP Certification &#124; CISSP Training - Shon Harris&#187; CISSP</title>
	<atom:link href="http://cissp.logicalsecurity.com/tag/cissp/feed/" rel="self" type="application/rss+xml" />
	<link>http://cissp.logicalsecurity.com</link>
	<description>CISSP Blog by Shon Harris - CISSP - Information Security Training - CISSP Certification - CISSP Training - Security Training - Logical Security - Shon Harris</description>
	<lastBuildDate>Tue, 13 Dec 2011 21:42:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Zeus Toolkit Gangs Staging Mass Attacks on Banking Applications</title>
		<link>http://cissp.logicalsecurity.com/information-technology-security/cissp/zeus-toolkit-gangs-staging-mass-attacks-on-banking-applications/</link>
		<comments>http://cissp.logicalsecurity.com/information-technology-security/cissp/zeus-toolkit-gangs-staging-mass-attacks-on-banking-applications/#comments</comments>
		<pubDate>Mon, 08 Nov 2010 11:51:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[CISSP]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Technology Security]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[logical security]]></category>
		<category><![CDATA[mass attack]]></category>
		<category><![CDATA[shon harris]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[zeus]]></category>
		<category><![CDATA[zeus toolkit]]></category>

		<guid isPermaLink="false">http://cissp.logicalsecurity.com/?p=383</guid>
		<description><![CDATA[Zeus, or Zbot, is a software toolkit that enables malware coders to build hard-to-detect Trojan horses, ones typically employed against the bank accounts of unsuspecting owners. (A Trojan horse is malicious software, secretly embedded in a system or application, that is “turned on” at a time of the attacker’s choosing.) Launched from behind command and [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Zeus</strong>, or <strong>Zbot</strong>, is a software toolkit that enables malware coders to build hard-to-detect Trojan horses, ones typically employed against the bank accounts of unsuspecting owners. (A Trojan horse is malicious software, secretly embedded in a system or application, that is “turned on” at a time of the attacker’s choosing.) Launched from behind command and control servers, Zeus is known by various names— Zeus, Zbot, Wsnpoem, PRG, Kneber, and Gorhax.</p>
<p>Since 2007, illicit organizations have employed Zeus to launch damaging, highly publicized attacks targeting the login credentials and other personal data associated with millions of computers, thousands of organizations, and uncounted numbers of users and their accounts. Relatively small groups of sophisticated criminal bands based in various nations&#8211;particularly in Eastern European countries such as Russia and Ukraine&#8211;have stolen tens of millions of dollars.  Computers in 196 countries have been subject to attack. The countries most affected include the U.S., U.K., Saudi Arabia, Egypt, and <a title="Turkey" href="http://en.wikipedia.org/wiki/Turkey">Turkey</a>.</p>
<p>In a typical scenario, malicious developers generate malware. The malicious code can be purchased on the cyber underground. Black-hat hackers who are part of criminal organizations break into and compromise computers. On the machines, they insert a Trojan which, when activated, pilfers the credentials of targeted persons, and penetrates the targets’ bank accounts. Meantime the thieves’ command and control server collects this sensitive data. The targets can be banks, ATM machines, credit card companies, social networking sites, telecommunication and other firms, and private individuals.</p>
<p>The hackers then transfer funds from these accounts to “mules.” Networks of mules consist of developers, non-technical individuals, and other illicit organizations. Often, they are foreigners who acquire fake passports and other identification in order to enter the country whose individuals and corporations are the targets of the attack.  After opening bank accounts, they “launder” the funds in the accounts to prevent tracking of the stolen funds. In addition, they transfer the funds to the organizers of the illicit scheme, in return for a percentage of the moneys procured.</p>
<p><em>For full article visit</em><em> </em><em><a title="Logical Security Articles" href="http://www.logicalsecurity.com/resources/resources_articles.html">Logical Security Resources</a></em></p>
<p><strong><em>Other Information:</em></strong></p>
<p><strong></strong><strong><a style="font-size: 12px; font-family: Verdana,Arial,Helvetica,sans-serif; color: #224a42;" title="CISSP - Certified Information Systems Security Professional" href="http://www.logicalsecurity.com/education/education_courses_cissp.html">Certified Information Systems Security Professional (CISSP)</a></strong></p>
<p><a title="Free CEH online course" href="http://www.logicalsecurity.com/resources/resources_videos.html"><strong>Free CEH online course</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://cissp.logicalsecurity.com/information-technology-security/cissp/zeus-toolkit-gangs-staging-mass-attacks-on-banking-applications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is There Really Someone Out to Get You?</title>
		<link>http://cissp.logicalsecurity.com/information-technology-security/cissp/is-there-really-someone-out-to-get-you-by-shon-harris/</link>
		<comments>http://cissp.logicalsecurity.com/information-technology-security/cissp/is-there-really-someone-out-to-get-you-by-shon-harris/#comments</comments>
		<pubDate>Wed, 29 Sep 2010 08:29:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Technology Security]]></category>
		<category><![CDATA[advanced persistent threat]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[CISSP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[shon harris]]></category>

		<guid isPermaLink="false">http://cissp.logicalsecurity.com/?p=229</guid>
		<description><![CDATA[&#160; Many times hackers are just scanning systems looking for a vulnerable running service or sending out malicious links in emails to unsuspecting victims. They are just looking for any way to get into any network. This would be the shotgun approach to network attacks. Another, more dangerous attacker has you in his crosshairs and [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">Many times hackers are just scanning systems looking for a vulnerable running service or sending out malicious links in emails to unsuspecting victims. They are just looking for any way to get into any network. This would be the shotgun approach to network attacks. Another, more dangerous attacker has you in his crosshairs and he is determined to identify your weakest point and do with you what he will.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">As an analogy, the thief that goes around rattling door knobs to find one that is not locked is not half as dangerous as the one who will watch you day in and day out to learn your activity patterns, where you work, what type of car you drive, find out who your family is, and patiently wait for your most vulnerable moment to ensure a successful and devastating attack.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">In the computing world, we call this second type of attacker an advanced persistent threat (APT). This is a military term that has been around for ages, but since the digital world is becoming more of a battleground – this term is more relevant each and every day.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">How APTs differ from the regular old vanilla attacker is that it is commonly a group of attackers, not just one hacker, who combines its knowledge and abilities to carry out whatever exploit that will get them into the environment they are seeking. The APT is very focused and motivated to aggressively and successfully penetrate a network with variously different attack methods and then clandestinely hide its presence while achieving a well-developed, multi-level foothold in the environment. The ‘advanced’ aspect of this term pertains to the expansive knowledge, capabilities, and skill base of the APT. The persistent component has to do with the fact that the attacker is not in a hurry to launch and attack quickly, but will wait for the most beneficial moment and attack vector to ensure that its activities go unnoticed. This is what we refer to as a “low-and-slow” attack. This type of attack is coordinated by human involvement, rather than just a virus type of threat that goes through automated steps to inject its payload. The APT has specific objectives and goals and is commonly highly organized and well-funded – which makes it the biggest threat of all.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">A virus is not an APT, a worm is not an APT, a bot is not an APT. An APT is commonly custom developed malicious code that is built specifically for its target, has multiple ways of hiding itself once it infiltrates the environment, may be able to polymorph itself in replication capabilities, and has several different ‘anchors’ so eradicating it is difficult if it is discovered. Once the code is installed, it commonly sets up a covert back channel (as regular bots do) so that it can be remotely controlled by the attacker himself. The remote control functionality allows the attacker to transverse the network with the goal of gaining continuous access to critical assets.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">APT infiltrations are usually very hard to detect with host-based solutions because the attacker puts the code through a barrage of tests against the most up-to-date detection applications on the market. A common way to detect these types of threats is through network traffic changes. When there is a new</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">IRC connection from a host that is a good indication that the system has a bot communicating to its command center. Since there are several technologies that are used in environments today to detect just type of traffic, the APT may have multiple control centers to communicate with so that if one connection get detected and removed – it still has an active channel to use. The APT may implement some type of VPN connection so that its data that is in transmission cannot be inspected.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">The ways of getting into a network are basically endless (exploit a web service, email links and attachments to users, gain access through remote maintenance accounts, exploiting os and application vulnerabilities, compromise connections from home users, etc.) Each of these vulnerabilities has their own fixes (patches, proper configuration, awareness, proper credential practices, encryption, etc.). It is not only these fixes that need to be put in place, we need to move to a more effective situational awareness model. We need to have better capabilities of what is happening throughout our network in near to real time so that our defenses can react quickly and precisely.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">Our battlefield landscape is changing from ‘smash-and-grab’ attacks to ‘slow-and-determined’ attacks. Just like military offensive practices evolve and morph as the target does the same, so must we as an indusIs There Really Someone Out to Get You? &#8211; by Shon Harristry.</div>
<p>Many times hackers are just scanning systems looking for a vulnerable running service or sending out malicious links in emails to unsuspecting victims. They are just looking for any way to get into any network. This would be the shotgun approach to network attacks. Another, more dangerous attacker has you in his crosshairs and he is determined to identify your weakest point and do with you what he will.</p>
<p>As an analogy, the thief that goes around rattling door knobs to find one that is not locked is not half as dangerous as the one who will watch you day in and day out to learn your activity patterns, where you work, what type of car you drive, find out who your family is, and patiently wait for your most vulnerable moment to ensure a successful and devastating attack.</p>
<p>In the computing world, we call this second type of attacker an advanced persistent threat (APT). This is a military term that has been around for ages, but since the digital world is becoming more of a battleground – this term is more relevant each and every day.</p>
<p>How APTs differ from the regular old vanilla attacker is that it is commonly a group of attackers, not just one hacker, who combines its knowledge and abilities to carry out whatever exploit that will get them into the environment they are seeking. The APT is very focused and motivated to aggressively and successfully penetrate a network with variously different attack methods and then clandestinely hide its presence while achieving a well-developed, multi-level foothold in the environment. The ‘advanced’ aspect of this term pertains to the expansive knowledge, capabilities, and skill base of the APT. The persistent component has to do with the fact that the attacker is not in a hurry to launch and attack quickly, but will wait for the most beneficial moment and attack vector to ensure that its activities go unnoticed. This is what we refer to as a “low-and-slow” attack. This type of attack is coordinated by human involvement, rather than just a virus type of threat that goes through automated steps to inject its payload. The APT has specific objectives and goals and is commonly highly organized and well-funded – which makes it the biggest threat of all.</p>
<p>A virus is not an APT, a worm is not an APT, a bot is not an APT. An APT is commonly custom developed malicious code that is built specifically for its target, has multiple ways of hiding itself once it infiltrates the environment, may be able to polymorph itself in replication capabilities, and has several different ‘anchors’ so eradicating it is difficult if it is discovered. Once the code is installed, it commonly sets up a covert back channel (as regular bots do) so that it can be remotely controlled by the attacker himself. The remote control functionality allows the attacker to transverse the network with the goal of gaining continuous access to critical assets.</p>
<p>APT infiltrations are usually very hard to detect with host-based solutions because the attacker puts the code through a barrage of tests against the most up-to-date detection applications on the market. A common way to detect these types of threats is through network traffic changes. When there is a new</p>
<p>IRC connection from a host that is a good indication that the system has a bot communicating to its command center. Since there are several technologies that are used in environments today to detect just type of traffic, the APT may have multiple control centers to communicate with so that if one connection get detected and removed – it still has an active channel to use. The APT may implement some type of VPN connection so that its data that is in transmission cannot be inspected.</p>
<p>The ways of getting into a network are basically endless (exploit a web service, email links and attachments to users, gain access through remote maintenance accounts, exploiting os and application vulnerabilities, compromise connections from home users, etc.) Each of these vulnerabilities has their own fixes (patches, proper configuration, awareness, proper credential practices, encryption, etc.). It is not only these fixes that need to be put in place, we need to move to a more effective situational awareness model. We need to have better capabilities of what is happening throughout our network in near to real time so that our defenses can react quickly and precisely.</p>
<p>Our battlefield landscape is changing from ‘smash-and-grab’ attacks to ‘slow-and-determined’ attacks. Just like military offensive practices evolve and morph as the target does the same, so must we as an industry.</p>
<p><em><strong>Other Information:</strong></em></p>
<p><strong><a style="font-size: 12px; font-family: Verdana,Arial,Helvetica,sans-serif; color: #224a42;" title="CISSP - Certified Information Systems Security Professional" href="http://www.logicalsecurity.com/education/education_courses_cissp.html">Certified Information Systems Security Professional (CISSP)</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://cissp.logicalsecurity.com/information-technology-security/cissp/is-there-really-someone-out-to-get-you-by-shon-harris/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

