Showing posts with label e-crime. Show all posts
Showing posts with label e-crime. Show all posts

Wednesday, 27 April 2011

Experimental attack on mTAN

F-Secure reports (link in german) that the trojan SpyEye has a new attack on the mTAN online banking security system. Users of infected PCs are tricked into installing malware on their Symbian mobile phones.
In order to do so, the attacker needs the phone's IMEI number, which is not a security credential in itself, but a user should become suspicious nowadays if their bank wants to know their IMEI number. Therefore I suggest to categorize this attack as experimental.
The urgent question behind this is: why did the Symbian developers base the security of their operating system on IMEI numbers?

Botnets Transfer 11 Million Dollar to China

The FBI reportsthat the usual suspects, namely ZeuS and SpyNet were used to steal 11 Million dollars and transfer that money to China.
Probably the victims were attacked using targeted "spearphishing" emails.
This issue is known since long, how long will it take until this will be eventually fixed?

Sunday, 20 March 2011

RSA Incident Neboulous

Intruders may have stolen data pertaining to RSA one time password (OTP) tokens. However, RSA won't tell the general public what has happened. There is a support note which is accessible only to customers.
OTP uses keys that need to remain secret, but I don't think these keys have been stolen.



Wednesday, 2 March 2011

Malware on Android

As everyone reports: there has been malware on Google's Android market. I have to add that such a thing removes the remaining security from SMS-TANs or similar two factor authentication schemes. One way out of that problem would be to use an additional trusted execution environment on smart phones.

Saturday, 12 February 2011

CISCO report on malware

Cisco published an interesting report on the 2010 developments on the malware scene. They discuss the economics of malware, the recruiting of mules (people who funnel stolen money on criminal's accounts) and future developments. The prediction I find most interesting is that Apple computers will be targeted next year. Another prediction is of course that smartphones will targeted.

Monday, 8 November 2010

ZeuS uses unpatched IE exploit

The Eleonore toolkit, which is the tack vector for the ZeuS malware, got support for the
recent CSS vulnerability of IE 8
which is still not fixed. This means that there will be more broken webservers distributing the exploit and bigger damage to affected users.




Position:Zeppelinstraße,München,Deutschland

Monday, 1 November 2010

ZeuS Botnet under Reorganisation

Reuters reports that the author of the ZeuS botnet announced that he will stop developing and maintaining ZeuS. Probably he has sold the sources and the customer base to a competing botnet , Spy Eye. Spy Eye has been fighting hard against ZeuS, but could not overtake ZeuS.

One may safely assume that the ZeuS author will use this sabbatical to come back with something even more dangerous, as it was the case in 2007 and 2008 when he also took a break.

Tuesday, 28 September 2010

ZeuS attacks m-TAN

ZeuS e-crime toolkit now supports man in the mobile also. It seems that the malware on the PC tricks the user into installing malware on their phone with a classic social engineering manipulation.
The fraud is then straightforward: The trojan on the PC starts a transaction, the telephone malware grabs the m-TAN confirmation message and forwards it to the malware on the PC where the fraudulent transaction is completed.
This will become increasingly dangerous with the success of smartphones, which allow more attack vectors, in particular if the telephone is regularly connected to the PC, e.g. for synchronizing or charging.
I have written about this problem already one month ago.

Sunday, 15 August 2010

Smartphones Not Ready for Mobile TANs

In the last weeks we had an outbreak of security issues with smart phones. The most famous was the pdf font bug that hit the iPhone and other iOS devices which was fixed by Apple with iOS 4.0.2. This one was really dangerous because it could infect iPhones just by opening an infective web site.
Then we had a rootkit for Android phones. A first criminal exploitation was a Trojan, also for Android, that sent text messages to premium numbers.
Of course there is much more. The reason for this is, of course, that there is no magical security for telephones. Old-style telephone-and-SMS-only phones were simply too dumb to be hacked (if we disregard the occasional bluetooth hack). Modern smartphones are normal computers that happen to contain a radio baseband chip.
However, we have that security feature M-TAN or Mobile TAN for online banking. When a M-TAN user has entered their transaction into the online banking website, they get a SMS with some details on the transaction and the M-TAN number. If the details of the transaction look good, they enter the M-TAN into the web site to complete the transaction.

So, here is the criminal master plan:
  1. own as many PCs as you get
  2. own as many smartphones as possible
  3. match smartphones and PCs
  4. start phony transactions on the PC
  5. capture the resulting SMS
  6. send the M-TAN to the Trojan on the PC
  7. Profit
Sounds complicated, but if everyone has a backup of their smart phone on the PCs step 3 should be quite easy and the only remaining issue for the criminal is whether they find enough matches so that the plan is worth the effort.

A promising version of this plan would be to attack the smart phone via the infected PC. In iPhone speak this would be called the "trojan jailbreak". If this can be done without the user noticing it, the M-TAN is completely broken.

I don't recommend using M-TANs on a smartphone.

Sunday, 30 May 2010

German Police publishes ATM Crime Numbers

The german federal police has published the 2009 numbers for ATM fraud. 964 ATM machines have been manipulated, that#s 20% more than 2008. Usually the PIN is spied out and the magnetic stripe data of the banking card is read. The data is transferred via a wireless connection who make a copy of the card and use that at another ATM.

Usually customers won't note the manipulations. Removing the magnetic stripe would improve the situation, but note that the cards must be authenticated with a real challenge-response protocol if a real security improvement is the target.

Friday, 12 February 2010

EMV Broken by Inventing Card Response

EMV user verification uses several methods, one of them is a PIN entered by the user. However, please note that this proves the user identity to the card, not to the terminal. If no-one checks the security state of the card, this is pretty pointless. They simply catch the verification request sent to by the terminal to the card, throw it away and reply with a code that means "PIN was OK".
So what now? Actually, the responsibility for a correct transaction is with the merchant, because only the merchant has at least a possibility to ensure a correct transaction: If a proper terminal is used and there is no strange cable coming out of the card (see the video on the linked page) the transaction is still good. However, the damage goes to the customer, not the merchant.
And, of course, there is a huge hole in the protocol.
There is only one way to do it properly:
  • User enters PIN
  • Terminal asks card to sign the transaction
  • card signs the transaction if and only if it has received the correct PIN
And everything done with mutual authentication end, message confidentiality and message integrity.

Where is the problem with this? It requires chips that are a little more expensive than the most simple ones. It's called "dynamic data authentication"and "Transaction Cryptogram" in the EMV world, but unfortunately it is not used in this case.

Friday, 18 December 2009

Credit Card Abuse, Again

Employees of a call center in Bremen, Germany allegedly have abused the credit cards of customers of British Airways. This has been reported be the TV magazine "buten un binnen". A team manager has been arrested. Certainly this is only the tip of the iceberg.
It is well known and accepted that credit cards offer no security all. Users will reclaim their money, if they read their credit card statement. Fraud costs will be distributed to the general public via insurances and merchant fees.
However, a normal smart card won't fix this because it can't be used with a call center. The only viable options here are the internet with secure online banking and OTP. Both options require that dedicated security hardware is used by the end customer. There is no free lunch.

Wednesday, 9 December 2009

Phishing Damage Estimations

Trusteer operatates the anti-phishing browser plugin Rapport. Based on measurements performed by Rapport, they were able to estimate the average damage done by phishing. A succesful phishing attack is counted if the Rapport plugin detects that the user tries to enter credentials into a phishing web site.
Assuming that each successful phishing attack steals between 500$ and 2000$ they arrive at an average damage of 2$ to 9$ per online banking user per year.
This seems a lot but it also explains why banks seem to take phishing so lightly: Any kind of security token will certainly cost more per user and year.
What about Rapport itself? It seems to be well suited here if it helps against phishing and costs the bank less than the 9 Dollars mentioned above. Which is no surprise, as all the numbers come from Trusteer. I would like to know whether it also helps against trojans and man-in-the-middle attacks.

Monday, 16 November 2009

"Anomalies" in Spain Speed up EMV Transition

It's not really clear what has happened there. It seems that massive amounts of credit card data were lost at a spanish credit card processor. New cards are sent to customers. At least some of these actually have an EMV chip. Another nail in the coffin of the obsolete magnetic stripes.
Update: Tonight it was in the news: more than 100 000 cards have been exchanged.

Sunday, 25 October 2009

Nigeria Closes down Spammers

The Nigerian Anti-Fraud commission EFCC states on its website that they started an operation against spam that has already resulted in the termination of 800 web sites. Nigeria is the home of the 419 scam emails where people are promised a substantial amount of money from questionable origin if the make some advance payments.

Will this reduce the amount of spam? I do not think so: 419 scams are almost neglegible in my spambox. However, if they actually shut down the scammers, it might help Nigeria's internet reputation, which might help Nigeria's economic development.

Tuesday, 6 October 2009

The URLZone Trojan

RSA Fraud Action Research Lab publish an article about a online-banking trojan called URLZone. This trojan has an interesting new feature:
It can determine if whether requests for new "mules" come from a botnet member or a security company. If the request comes from a security company or researcher, the server will respond with account data of innocent people, thus protecting their mules from prosecution.
The accounts are people who received a legitimate transfer from a URLZone victim before.

'Mules' are the people who receive payments from infected PCs and forward them to the gangster's accounts. That's money-laundering, and not only criminal, but also quite dangerous. The fake mule responses will put innocent people under suspicion of money laundering.

Sunday, 13 September 2009

Linux Botnet

The Register reports a new linux server botnet originally reported here. It is not yet clear how the servers are infectected. The purpuse of these servers is to serve malware from an additional webserver installed on listening on port 8080. It seems to me that people look at their web forum security again very closely: Not only can be used to exploit a server, but also if it is possible to post links at public discussion sites it is also possible to post links to such malware.

Sunday, 30 August 2009

Real Time Keylogging

According to New York Times the trojan Clampi is able to send key presses in real time. This means that it can be used to attack one time password (OTP) systems.
From here on, it seems necessary to consider a more complex mode of OTP known as EMV CAP respectively Visa DPA. Here a challenge is sent from the server which is signed by a smart card. Therefore the attacker cannot submit the stolen OTP signature for any other purpose than it was originally intended for.

Sunday, 2 August 2009

Economics of Spam

An experiment about spam conversion rate (the rate by which spam emails result in purchases) show that less than 0.00001% of spam emails result in sales. The experiment was performed by infiltrating the storm botnet and sending out spam emails referring to fake sales pages operated by the researchers (I won't comment on whether I consider this method ethically acceptable. At least, no damage is done to the test subjects).
As sending out spam comes with a cost, this low conversion rate poses a problem to the spammers. The authors assume that the retail price for sending out spam is $80/million spam mails. That's not a business because one million emails result in only 0.1 conversions by the conversion rate quoted above.
The conclusion in the cited paper is that the storm botnet is "vertically integrated" and thus operates at lower costs than $80 per million of sent spam emails.
The good news is that spam business seems to operate at the border of profitability. If this is true, then measures that reduce spam profitabiity further might effectively reduce the quantity of spam.

Monday, 27 July 2009

Massive Credit Card Data Theft

Credit card data of more than half a million people have been stolen. I don't think that such events can be avoided unless the architecture of web servers is fundamentally changed to make them more error-resilient.