::Trend Micro Threat Resource Center::

20 September 2011

Microsoft TechDays Singapore 2011

The premier technical conference is coming to Singapore!

TechDays Singapore 2011 provides IT Professionals and Developers with comprehensive insights on Microsoft cloud technology and learning opportunities to manage cloud infrastructure, integrate with cloud platforms and develop modern applications.

Check out the details here:
http://www.microsoft.com/singapore/techdays/

Register by 30 September 2011 to enjoy early bird pricing at S$69! (Standard pricing at S$99 applies thereafter). Click here to register now.

02 September 2011

Facebook pays bug hunters $40,000 in three weeks

The recently introduced Facebook bug bounty program has proved to be a great success, says Joe Sullivan, the company’s chief security officer.

"We know and have relationships with a large number of security experts, but this program has kicked off dialogue with a whole new and ever expanding set of people across the globe in over 16 countries, from Turkey to Poland who are passionate about Internet security," he added. "The program has already paid out more than $40,000 in only three weeks and one person has already received more than $7,000 for six different issues flagged."

He also pointed out that $500 was the minimum sum received for a discovery of a bug, but that one particular report brought $5,000 to its author. Unfortunately, he didn't disclose how the Facebook security team rates the discoveries and decides on the payout.

In spite of many requests to include bugs found in third-party applications and websites that can be connected to the users' Facebook identity, the bug bounty program remains limited only to bugs that could compromise the integrity or privacy of Facebook user data.

Bug bounty programs have previously been instituted by Google and Mozilla. And even though Adobe and Microsoft still decline to make that step, Microsoft has instituted a competition that aims to amply reward security researchers who develop innovative computer security protection technologies.

01 September 2011

Linux source code repository compromised

The Kernel.org website - home to the Linux project and the primary repository for the Linux kernel source code - sports a warning notifying its users of a security breach that resulted in the compromise of several servers in its infrastructure.

The discovery was made on August 28th, but according to the current results of the investigation mounted by the site's team, the break-in seems to date back to August 12 or even earlier.

The attackers are thought to have gained root access on a server via a compromised user credential, and to have escalated their privileges from there. How did they managed to do that, it is still unknown.

After having done that, they proceeded to modify files belonging to ssh (openssh, openssh-server and openssh-clients) and add a Trojan to the system start up scripts so that it would run every time the machine was rebooted.

Luckily for everyone, the Linux kernel source code is unlikely to have been tampered with.

"That's because kernel development takes place using the git distributed revision control system, designed by Linus Torvalds," it is explained. "For each of the nearly 40,000 files in the Linux kernel, a cryptographically secure SHA-1 hash is calculated to uniquely define the exact contents of that file. Git is designed so that the name of each version of the kernel depends upon the complete development history leading up to that version. Once it is published, it is not possible to change the old versions without it being noticed."

"Those files and the corresponding hashes exist not just on the kernel.org machine and its mirrors, but on the hard drives of each several thousand kernel developers, distribution maintainers, and other users of kernel.org. Any tampering with any file in the kernel.org repository would immediately be noticed by each developer as they updated their personal repository, which most do daily."

The 448 users of the site have been notified of the breach and have been advised to change their login credentials and SSH keys.

According to the notice, US and Europe authorities have been notified about the breach and asked to help with the investigation. The administrators have, in the meantime, proceeded to take the servers offline and reinstall them, and to make a thorough analysis of the code within Git (the distributed revision control system) in order to make absolutely sure that nothing was modified.

31 August 2011

Facebook Makes a Move Toward Security

Facebook recently published a guide for it's users on how to secure their online accounts from anything that threatens one's Facebook security. Among those covered are Wall, Chat, and Comment spams, weak passwords, fake applications, and account hacking.

Personally, I'm quite happy that Facebook is actually doing something constructive concerning user security, despite it being quite late come to think about it.

Still, better to have something than nothing.

The document guide contains practical tips and cases to illustrate the gravity of the attack if ignored. It also has some great, agreeable points that make it a good reference anyone can recommend to their friends and family who are on Facebook. Feel free to download here and distribute.

30 August 2011

Security flaw could expose credit card data

Do you have an account with BofA or Chase? Bank information may be at risk.
If you have a credit card account with Bank of America or Chase, two of the nation’s largest banks, a major security flaw has been exposed that could make your information vulnerable to an Internet crook – or even a nosy neighbor.

Consumer advocate Edgar Dworsky of ConsumerWorld.org, who discovered the flaw, says anyone who knows your phone number and has the last four digits of your Chase or BofA credit card number might be able access your account.

Here’s the flaw Dworsky uncovered: When you call a bank’s automated credit card account information system, the computer uses caller ID to compare the number you’re calling from with the one on the account (usually your home phone).

At BofA and Chase, if the phone number is a match, the verification process is streamlined. Rather than requiring the entire credit card number to be entered, the caller can usually access the account with only the last four digits. In some cases, a zip code is also required.

“The last four digits of your credit card number are just out there so predominantly,” Dworsky says. “If you look at any sales receipt, it always has those last four digits.”

In order for someone to take advantage of this security loophole, they’d have to trick the bank’s computer to make it appear the call is coming from your home phone. Internet “spoofing” sites make this incredibly easy to do. Con artists have been using this technology for years, and it is how those British tabloid reporters were able to hack into so many voicemail systems.

Here's more details of the flaw.

29 August 2011

Month-long hiatus

Apologies for the month long hiatus.

Was away traveling and decided to disconnect myself from the Internet world.

Hope I"m back fully recharged.

Cheers!