Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Monday, May 17, 2010

I am a hacker - whether I like it or not

[... and not the bad cyber criminal type.]

For the latest ITWeb Security Summit (which was amazing) I was chosen as a speaker.

I had the following challenge -

  • talk about the different InfoSec Standards available
  • do it at 3:40pm 
  • do it straight after the tea break
  • make sure that the attendees don't fall asleep
Needless to say - it took a lot of thought but I eventually managed to keep them interested according to some positive reports I got after the talk.

I'm not going to go into the details of the talk here but after quite a bit of re-assessment I realised that I had basically "hacked" the standards. Hacked - in the good sense. There was no "piracy" involved (me maytee) and everything was above board. (and above plank.) 

But to keep the attendees interested in the talk I basically took the standards and applied them in ways they were just not designed to be used. And that is the true definition of hacking. 

In the past 4-ish years or so I have tried to model myself as a serious Information Security Professional. I have tried to put away the "hacking" part of me and concentrate on "working for the Man" but it seems that, without me trying, that part of my brain will find a way out. 

So, I will set my aim for the next year to nurture the "hacking" side of my brain and mold it into something I can use as an Information Security Professional. 

Wednesday, January 23, 2008

Prediction 1 for 2008 - Facebook hacked

Ok, finally, here it is.


For the impatient - Facebook will be hacked. Alternatively, a major Facebook application will be hacked.


Right...the impatient can go now. The rest - read on.

[Personal note first]
I decided that my Blog was becoming too important. I have a host of blog posts that are just not quite as well written as I'd like and since my blog is somewhat a reflection of my writing skill (skillz?) I decided that I'd need to fix them up, when I have time.. well, I've changed my mind - my blog is now an indication of my thinking skills as it was always intended to be, hence the name. It is an indication of my quick writing skill and how I write under time constraints. So, ignore the strange terms, spelling and grammer. Read the content.

This is also the reason why I don't have a "my top 10 predictions for 2008". There is no list that I am working from - as I think them up, I wil blog about them.
[end personal note]

Last year when Facebook made their application language available I was very excited and signed up as an "application developer". I even wrote an application which is about the level of complexity of a "hello world" program. I think it is a box that greets the Facebook-er by name. Woopy-doo.

But what I found quite interesting is that the application runs on my server and my database but queries information from Facebook. This makes creating applications so much easier and is probably what led to the Facebook explosion in the first place. However, users may not be aware that every time they add an application they are increasing the risk that their Facebook information can be compromised.

I like to believe that Facebook is big enough to be able to throw money at security. I think that their product is simple enough to secure. So, there should not be too much opportunity to hack into Facebook. I could be wrong. Facebook certainly is a huge target for both those hackers who want to make some good money, those that want email addresses (to spam) and those that want to make a big bang and a name for themselves.

But my money is on a large Facebook application being hacked - its a way to get in through the back door.

Monday, August 27, 2007

The TJX stock is just not co-operating!

According to wikipedia :
The TJX Companies, Incorporated is the largest international apparel and home fashions off-price department store chain, based in Framingham, Massachusetts in the United States.

[...]

On January 17, 2007, TJX announced that it was the victim of an unauthorized computer systems intrusion.

TJX ended up as the default PCI black sheep. PCI, for those not in the know, is an industry standard created by the credit card companies telling stores how to protect their customer's information, specifically credit card information.

Basically TJX did everything wrong including storing information they should never have stored in the first place. 45 million credit card numbers are now being traded on the black market because of this breach.

Net income for their 2nd quarter dropped 57% due to information security costs related to the breach.

Bad news for the company, right? Wrong. Maybe someone can explain this to me but on January 16th, 2007 the share price was $29.94. Friday's closing price was $30.75. Man, did the market get them (not)! To be fair they have underperformed the S&P500 until recently but the company does not seem to be very hurt by the breach.

Thursday, July 5, 2007

eNatis: Nothing to see here, move along.


For those that read my column and are not from South Africa - eNatis is a new system that the Department of Transport (DOT) has implemented. It has a website portal and is the system used for registering cars, licenses, paying fines, etc. It has a lot of personal information. The website was hacked and the papers jumped on the story, though most calling it (correctly) a non-event.

Web hacks are (apparently) easy to do.

This is part of the reason why no company worth their salt (and some not even worth that) recommend that the webserver does not contain important information. That should be stored in a database and if the webserver needs to read the data, it should make a connection through a firewall. And the database should be closed up as tight as possible.

In fact, it is almost expected that the webserver will be hacked and the company (or government department) should have an incident response in place to deal with this minor breach.

I liken this hack to the real-life-equivalent of a criminal trying to break into an office of the D.O.T, not succeeding and spraying graffiti on their gate.

The media has jumped on this hack because of the issues eNatis has had in the past, but its the equivalent of reporting on a graffiti incident - the result of the attack is very embarrassing because of the fact everyone can see it but, no real loss occurred and once the mess is cleaned up there will be no further issue.

So, what sort of hack is news worthy? One that will not make it all the way into the papers! A newsworthy hack would be one where a criminal (or hacker..whatever terminology you choose) gets into the eNatis database, manages to manipulate the data for self gain or steal personal information from the database.

This will not get into the paper because:
  1. The user will not make it public that he has done anything wrong, it would make it easier for him to get caught.
  2. The D.O.T may not even know it has happened. Stealing information is not like other crime where if someone steals your stuff, you have no stuff left. Information can be stolen but a copy could be left in place.
  3. If the D.O.T finds that a hack has taken place in their database the last thing they will do is inform the press. (my guess)
  4. If information is stolen from the D.O.T, it may be used for identity theft purposes. (ie. pretending to be someone so you can get credit in their name or get access to their personal assets) and the investigation (if it gets that far) may not know the true source of the information used in identity theft.

That is not to say that I know of an instance where eNatis has had its database hacked, nor am I saying that it has been hacked or ever will be in the future. I'm saying that, if it were hacked in a way that was newsworthy, we probably would not be reading about it in the newspaper.

Friday, June 1, 2007

eNatis (Part 2) - Quick Quote

Hi,

The Beeld newspaper did all the hard work for me so here is a quote from their newspaper:

Beeld can now reveal the conclusions of the report, which is the second of three audits compiled by the A-G:

  • it is possible to hack into eNatis;
  • one does not need a password to log on as an eNatis administrator;
  • documents on eNatis are not secured; and
  • eNatis files can be circulated unprotected without any problem.
  • This is just a quick post on what the newspaper has to say. I will reply with more information and some analysis soon.


    The full article is here.