Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Tuesday, 2 February 2016

Cyber attack on Israel Electricity Authority

According to SANS Industrial Control Systems Security Blog, Dr. Yuval Steinitz (Minister of National Infrastructure, Energy, and Water Resources) confirmed at the CyberTech Conference that massive cyberattack taken place on January 25th, 2016 and was aimed on Israeli Electricity Authority.

According to Eyal Sela cited by Robert M. Lee, cyber attack was simply ransomware delivered via phishing emails to the regulatory body's office network and it appears in no way endangered any infrastructure [1].

The Israeli Electric Authority is a regulatory body of ca. 30 individuals and this "cyber attack" is only referencing their networks, not the electric grid or electric companies.
 
Steinitz told Cybertech Conference attendees in Tel Aviv, Israel, that his agency has already identified the virus and is now prepared to deploy the software that will work to neutralize the bug on computer networks [2] [3] [4].

The attack on Israel comes one month after hackers caused the power blackout in Ukraine in December 2015, when the SCADA systems were hit with a trojan named BlackEnergy that resulted in the power cuts across the Ukraine's Ivano-Frankivsk Oblast.

Israel had suffered from cyber attacks previously including coordinated attack by anti-Israeli groups which was first conducted on 7th April 2013 and repeated every year, codenamed #OpIsrael. #OpIsrael targets web sites with DDoS. A denial-of-service attack (DdoS) is characterized by an explicit attempt by attackers to prevent legitimate users of a service from using that service. #OpIsrael attempt in 2015 failed to bring down government websites, however numerous web sites of organizations and individuals were taken down. According to Michal Margalit and Ran Boker, major government websites were targeted but were not brought down, including the sites for the Knesset, Education Ministry and the government portal [5].

About Israeli Electricity Market Regulatory Authority

In 1996, the Israeli Electricity Market Regulatory Authority was was established. Its purpose is, among others, to balance between maintenance of a fair rate framework to be imposed upon electricity consumers, and support of private entrepreneurs in the field and the promotion of electricity production in a competitive and equitable manner.

About Dr. Yuval Steinitz

Dr. Yuval Steinitz was appointed Minister of National Infrastructure, Energy and Water Resources (May 2015). Minister Steinitz kept his leading role on behalf of the Israeli government in the international campaign against the Iranian nuclear program and is overseeing the Israeli Atomic Energy Committee from the previous government. Prior to his current position, Minister Steinitz was the Minister of Intelligence 2013 - 2015. In that capacity, Dr. Steinitz was responsible for overseeing the intelligence community, including the Mossad (Israeli CIA), Shin-Bet (Israeli FBI) and Israeli Atomic Energy Committee. Minister Steinitz was also in charge of economic aspects in the Israeli-Palestinians peace talks.

Sources

  1. Context for the Claim of a Cyber Attack on the Israeli Electric Grid https://ics.sans.org/blog/2016/01/27/context-for-the-claim-of-a-cyber-attack-on-the-israeli-electric-grid?reply-to-comment=312
  2. Israel’s Yuval Steinitz: ‘Severe Cyber Attack’ Shuts Down Electricity Authority’s Computer Systems http://www.executivegov.com/2016/01/israels-yuval-steinitz-severe-cyber-attack-shuts-down-electricity-authoritys-computer-systems/
  3. No, Israel's power grid wasn't hacked, but ransomware hit Israel's Electric Authority http://www.computerworld.com/article/3026609/security/no-israels-power-grid-wasnt-hacked-but-ransomware-hit-israels-electric-authority.html
  4. Israeli Power Grid Authority Suffers Massive Cyber Attack http://thehackernews.com/2016/01/power-grid-cyberattack.html
  5. Israeli sites targeted by annual Anonymous 'OpIsrael' cyber attacks http://www.ynetnews.com/articles/0,7340,L-4644894,00.html
 

Tuesday, 6 September 2011

Unicart Ltd. and Yonita Inc. join forces to address cyber security threts in Bulgaria.

MOUNTAIN VIEW, Calif. & SOFIA (September 6, 2011): Yonita Inc. and Unicart Ltd. today announced that the two companies have signed an agreement to provide Web Scanner solution to domain name holders on Bulgarian market. 

Yonita Web Scanner provides unique capabilities for automatic detection of vulnerabilities that can affect online application owners. A successful attack against a company’s site or an online application can result in a wide spectrum of negative consequences including expenses of restoration of an IT infrastructure to its original “pre-attack” state, the cost of stolen, compromised, or otherwise degraded data, as well as loss of reputation and damage to the brand.

The President and CEO of Yonita Inc., Dr. Andrzej Bartosiewicz said: “We are happy to start cooperation with leading Bulgarian domain Registrar. Our companies focus now on providing the most advanced on-line security scanning tool for the Bulgarian community”

Yonita Web Scanner performs dynamic verification of web applications based on automated tests generated by the Smart Test Generator and Randomized Data Generator. The main threats detected by the Smart Web Scanner are:
  • Defects in authentication, authorization, and session management
  • Injections, such as script injection, OS command injection, SQL injection, CRLF injection, and others
  • Cross-site Scripting (XSS)
  • Cross-site Request Forgery
  • Defects in forward and redirect mechanisms
  • Content spoofing
  • Buffer overflow
  • Direct object references
Service provided by REGIA.BG to their customers will include premium customer’s service and full spectrum of configuration capabilities. Technical Support will be provided by Yonita Inc. from its center located in Warsaw, Poland, serving Europe, Middle East and Africa Region.

About Unicart Ltd.

REGIA.BG is the domain registrar and web hosting branch of Unicart Ltd., a top Bulgarian company working in the field of publishing, printing and IT services. REGIA.BG started in 2008  with the goal to provide domain registration in all existing TLDs and quickly became one of the top 10 domain registrars in the country and the top place for domain registration in all TLDs. Apart from domains, REGIA.BG provides web and VPS hosting, SSL certificates and useful software.

About Yonita Inc.

California-based Yonita, Inc., offers a family of products dedicated to the detection of security vulnerabilities and the identification of other quality defects in software early in a development lifecycle. Yonita Inc., founded in 2010 and headquartered in Silicon Valley, Mountain View with R&D center in Warsaw, Poland, is one of the leading companies offering solutions for automated software engineering.

Contact

Andrzej Bartosiewicz, CEO and President
800 West El Camino Real
Suite 180
Mountain View, CA 94040
+1 650 249 3707

Monday, 13 June 2011

CEO of Yonita, Inc. invited by ICANN to join the team of experts.

CEO and President of Yonita Inc., Dr. Andrzej Bartosiewicz has been invited by ICANN to join the IDN Variant Issues Project as an expert.

The IDN Variant Issues Project undertakes work to identify issues associated with the beneficial and safe delegation of IDN (Internationalized Domain Names) variants of the Top Level Domains. Managing IDN variants is a complex and important subject and the success of the project is dependent on significant community expertise input and cooperation in doing the work.

On June 9th, ICANN announced the formation of six case study teams, comprising a total of 66 top experts from 29 countries and territories. Case Study members provide expertise in the following areas: DNS, IDNA, linguistics, security & scalability, policy, registry/registrar operations, and community relations.

ICANN is responsible for the global coordination of the Internet's system of unique identifiers like domain names (like .org, .museum and country codes like .uk) and the addresses used in a variety of Internet protocols that help computers reach each other over the Internet. Careful management of these resources is vital to the Internet's operation, so ICANN's global stakeholders meet regularly to develop policies that ensure the Internet's ongoing security and stability. ICANN is an internationally organized, public benefit non-profit company.

For more about IDN Variant TLD Case Study visit ICANN:
http://www.icann.org/en/announcements/announcement-3-09jun11-en.htm

Thursday, 9 December 2010

Operation Payback

updated on UltraDNS Anycast solution on Dec 9, 0815 EST 
updated on Visa, MC on Dec 10, 0600 EST 
Here is the follow up of the story of Amazon, VISA, MasterCard, PayPal, SwissPost and many more companies involved in "cablegate". More than week ago those companies took WikiLeaks.org web page and WikiLeaks donations off-line (more: [1] [2] [3]).Today WikiLeaks' supporters are taking them down.

Due to the DDoS (Distributed Denial of Service) attack called "Operation Payback" both VISA and MasterCard's web pages were off-line on Thursday. People behind so called Operation Payback campaign are targeting all corporations that have withdrawn services from Wikileaks.

What is DDoS?
DoS (Denial of Service) attack is an attempt (successful in case of VISA and MasterCard) to make a computer resources unavailable to its users. In case of a DDoS (Distributed Denial of Service) attack, large numbers of computers distributed across the networks attack a single target. Computers used for the attack are either compromised systems (botnets) or legitimate hosts managed by people who decide to use their machines to flood the victim. In the Operation Payback most of the "attackers" were legitimate hosts deliberately used by their owners to send large number of queries to the Visa and MC servers.  (D)DoS attack can force different services of the victim including Web site (WWW), e-mail or transaction systems to cease operation. In some cases denial of service attack can also destroy files in the affected computer systems.

DDoS attacks are tools used by "hacktivists" as form of protest or revenge (WikiLeaks case). Today DDoS are generally used for cyber criminals to profit from:
  • ransom payed by victim to stop the attack and avoid further financial losses,
  • companies who want to knock out competitors from the market (sabotage, brand damage)
Current situation
As of December 9th, 2010, 0740 EST, VISA.com has not been reachable, but at least their Name Servers were reachable. In the contrary neither MASTERCARD.COM's web page nor their Name Servers have been reachable. Due to the fact that Name Servers of MasterCard haven't been reachable, it's likely that not only web page but also e-mail service were disrupted.

UPDATE: After 8+ hours of inaccessibility, web pages of VISA and MasterCard were back on-line.


And the winner is...
Attack on VISA and MasterCard shows, that "Operation Payback has actually one big winner - NeuStar's UltraDNS service. VISA made a good decision choosing UltraDNS as DNS provider. UltraDNS is using so called "UltraDNS Managed DNS Service" with the ability to advertise the same public IP addresses out of multiple machines and networks. By using IP Anycast, UltraDNS is bringing the answers for a DNS query closer to the end user, and it becomes far more likely that the query will reach its destination and be responded to quickly. IP Anycast makes DDoS attacks much more difficult, requiring more botnets or attacking computers to be involved in the attack. As UltraDNS says IP Anycast and BGP protect our network from security threats and Distributed Denial of Service attacks. Because queries are routed based upon where they enter the UltraDNS network, DDoS attacks will be "distributed" amongst our servers, thus "diluting" the strength of any DDoS attack.


VISA.COM - ping on Dec 9, 0815 EST
Ping 72.52.5.101
[visa.com]
Timed out
Destination network unreachable
Timed out
Timed out
Destination network unreachable
Destination network unreachable
Timed out
Timed out
Destination network unreachable
Timed out

Average time over 10 pings: 0 ms



VISA.COM - Name Servers query on Dec 9, 0815 EST
Retrieving DNS records for visa.com...
DNS servers
pdns3.ultradns.org
pdns2.ultradns.net
pdns1.ultradns.net
pdns6.ultradns.co.uk
pdns5.ultradns.info
pdns4.ultradns.org


Answer records
visa.com
TXT
3600s
visa.com
TXTv=spf1 ip4:198.80.42.3 ip4:198.241.159.4 ip4:69.20.125.232 ip4:198.241.175.106 ip4:216.251.253.98 ip4:67.208.216.61 ~all3600s
visa.com
SOA
server:pdns1.ultradns.net
email:hostmaster@visa.com
serial:2010120909
refresh:10800
retry:3600
expire:604800
minimum ttl:300
300s
visa.com
A72.52.5.101300s
visa.com
MX
preference:10
exchange:portal5.visa.com
3600s
visa.com
MX
preference:10
exchange:portal2.visa.com
3600s
visa.com
MX
preference:10
exchange:portal1.visa.com
3600s
visa.com
NSpdns6.ultradns.co.uk86400s
visa.com
NSpdns5.ultradns.info86400s
visa.com
NSpdns4.ultradns.org86400s
visa.com
NSpdns3.ultradns.org86400s
visa.com
NSpdns2.ultradns.net86400s
visa.com
NSpdns1.ultradns.net86400s

Authority records

Additional records
portal5.visa.com
A198.241.174.1383600s
portal2.visa.com
A198.241.159.33600s



MASTERCARD.COM ping on Dec 9, 0815 EST
IP address:
Error: Try again

Host name: mastercard.com
Alias:
mastercard.com
is from () in region



TraceRoute to [mastercard.com]
Hop(ms)(ms)(ms)
IP AddressHost name
Trace complete

Retrieving DNS records for mastercard.com...
DNS servers
dns2.mastercard.com [209.64.210.34]
dns1.mastercard.com [216.119.210.196]

DNS server returned an error: Name server failed

Sunday, 16 May 2010

May 12: DNS blackout in Germany

On May 12, 2010, Internet in Germany faced serious problems. According to German media (Focus, Spiegel, Chip, Frankfurter Allgemeine etc.) most of the web pages with addresses ending with .DE were not available between 11:30 UTC and 15:45 UTC. During the "blackout" DNS queries returned NXDOMAIN (Name Error RCODE), indicating probable existence of some errors during the process of uploading of the zone file into the DNS servers. This information has been briefly confirmed by Peter Koch from DENIC eG. It's quite likely that the defective or incomplete zone files have been uploaded into DNS servers.

Background

Usually domain registration and maintenance systems are separated from Domain Name System (DNS is resolving queries send by Internet users, translating domians into IP addresses). Normally there is no "direct" connection between registration system and live DNS. Those two "worlds" are connected when the registry system is exporting* zone file(s) and the zone file is uploaded into primary DNS server (and than distributed to the secondary Name Servers).

German accident is similar to the case from Spain (in 2006 the empty zone file has been uploaded) and Sweden (in 2009 incorrect DNSSEC-signed zone file has been uploaded). Unfortunately in both mentioned situations this critical part of the process has not been secured by automatic checks verifying the newly generated zone file.

Solution 

To avoid such incidents, automatic verification mechanism(s) can be used to check the differences between the new generated zone file and the previous one (the last correct zone file). If the number of changes is higher than usual, it indicates that some errors are quite likely to happen and the process should be terminated. It's the common practice in many different industry sectors, to check if the changes in the computer databases, physical storage, resources or energy consumption etc. are not deviated from what is expected from statistical estimations. The idea behind such statistical checks is to eliminate major errors using automatic verification systems. Of course such (statistical) methods don't eliminate minor problems, requiring more sophisticated control solutions to be implemented.

Explanations
*There is also another solution for updating zone files called "dynamic updates", allowing small portions of domains to up updated more frequently than zone files reloads. German registry is not using this method to update DNS.