ShatterDOC Original Material

Friday, May 22, 2015

LogJam Exposed: 575 Cloud Services Potentially Vulnerable to Man-in-the-Middle Attacks



CLOUD SECURITY ALLIANCE | MAY 21, 2015
By Sekhar Sarukkai, VP of Engineering, Skyhigh Networks 

LogJam, the latest in a spate of web vulnerabilities, was exposed on Tuesday evening by a team including Mathew Green, assistant research professor at Johns Hopkins University, experts from University of Michigan and the University of Pennsylvania, and researchers from Microsoft Research and INRA, who were part of the team that initially discovered the FREAK vulnerability. The vulnerability is derived from an encryption flaw, essentially created by USGov requirements. Specifically, any servers that support export grade DHE cipher suits are vulnerable to LogJam.
 
https://blog.cloudsecurityalliance.org/2015/05/21/logjam-exposed-575-cloud-services-potentially-vulnerable-to-man-in-the-middle-attacks/

Until websites convert to Hackproof Technologies new server technology these security issues will continue. 

Thursday, May 7, 2015

The Main Cyber Threats to Web Sites and Visitors

Based on and quotes from an article by Symantec - CSO | The Resource for Data Security Executives

"Cyber attackers are leapfrogging defenses in ways companies don't even have the insight to anticipate"

Phishing attacks and their highly targeted siblings spear-phishing attacks involve targeted messages being sent to individuals, But there are attacks on websites instead of people that affect every visitor. And you may not be aware your website is spreading malicious infections!

"In a watering hole attack attackers infiltrate places people go. For example, they might inject a vulnerability into a website they know their visits. This bypasses the measures put in place to block malicious email.

"A variation of this is bad actors infiltrating software used in specific industries with malicious payloads. For example, if a mining company uses a specific application, a hacker could infect that software at the developer’s site so that the malicious payload enters the mining company through a seemingly legitimate channel." [Key chain attack]


Because GPUs can NEVER be completely protected website owners will ALWAYS be playing catch-up and endangering their visitors (Paraphrase from Dr.M)

There IS a solution on the way...

Just-released WordPress 0day makes it easy to hijack millions of websites [Updated] | Ars Technica

Just-released WordPress 0day makes it easy to hijack millions of websites
Exploit code lets attackers gain administrative control sans authorization


Update - apparently fixed.

Monday, April 27, 2015

Secure Your Website So Your Customers Don't Get Mugged

Secure Your Website So Your Customers Don't Get Mugged
PCMAG | APRIL 23, 2015

"You don't expect to get mugged when you walk into a store," said Tom Kellerman, Trend Micro's Chief Cybersecurity Office, "You expect facility security."
""We've seen a 25 percent increase in watering hole attacks globally," said Kellermann, "Half are in the U.S., and 45 million appeared in the first half of the year." A watering hole attack is a seemingly innocuous website that can automatically infect visiting browsers, without any interaction by the user. Just as the jungle predator waits for prey and then leaps, the malicious code activates when a likely victim arrives. And any website with insufficient security can be injected with code that turns it into a watering hole."
http://www.pcmag.com/article2/0,2817,2482393,00.asp/?utm_medium=referral&utm_source=shatterdoc.com

Cyber warfare experts know a dirty little secret: It is mathematically impossible to prevent cyber attacks on a general purpose computer. Fortunately there's a new technology being developed that will forever stop website hijacking and watering hole attacks. Watch this blog for an announcement!

Citigroup Report Chides Law Firms for Silence on Hacking


Every month it seems another American company reports being a victim of a hacking that results in the theft of internal or customer information. But the legal profession almost never publicly discloses a breach.


Clouds Are Not Really Very Safe! – Here are 9 Security Threats Everyone Needs to Understand | Internet, Information Technology & e-Discovery BlogInternet, Information Technology & e-Discovery Blog


A report explained from the  Cloud Security Alliance (CSA) explained how the cloud is not as safe as many people think it is based on "nine major categories of threats that face cloud technologies" which organizations "must weigh these threats as part of a rigorous risk assessment, to determine which security controls are necessary." CDW issued a White Paper entitled "Playbook: Overcoming Cloud Security Concerns" which explained how to deal with the 9 CSA threats and explained the difference between data loss and data breach...