Advertisement
Home
Saturday, 22 November 2008
 
 
Last week attacks
O.S.  Defs.  %
Linux  8778  71.58%
Win 2003  1950  15.90%
Win 2000  722  5.89%
Solaris 9/10  402  3.28%
FreeBSD  226  1.84%
Other  185  1.51%

Total attacks: 12263 of which 4619 single ip and 7644 mass defacements

Polls
Should Zone-H continue mirroring defacements? (floods will be purged)
 
Main Menu
Home
Digital Warfare
Geopolitics
ITsec News
ITsec Advisories
Test Drive
360°
Digital Attacks Archive
Zone-H events
Publications
Zone-H Friends/Partners
Contact Us
Search
Download Area
Zone-H forum
About this website
Login Form





Lost Password?
No account yet? Register
ZONE-H In Numbers
 News: 14559
 Advisories: 11
 Managers: 1
 Administrators: 1
 Super Administrators: 3
 Operators: 3
 Registered Users: 38290
 Downloadable Files: 3888
 Digital Attacks: 2981160
 Attacks On Hold: 3066
 Online Users: 74
Syndicate
Visitors' Map
Highlight on most recent attacks
jiefanglu.gov.cn/zkn.txt by ZoRRoKiN       ytjj.gov.cn/zkn.txt by ZoRRoKiN       bislig.gov.ph by Ashiyane Digital Security Team       prefeiturajoseraydan.com.br by Fatal Error       semag.taquarussu.ms.gov.br by Fatal Error       pmsaltodolontra.com.br by Fatal Error       cmirituia.com.br by Fatal Error       pmriobrancodoivai.com.br by Fatal Error       prefeituraborrazopolis.com.br by Fatal Error       pmcurionopolis.com.br by Fatal Error       
Latest advisories
Latest on Digital Warfare
Latest on Geopolitics
The Dark Side of the Moon. PDF Print E-mail
User Rating: / 11
PoorBest 
Monday, 03 September 2007

 Latest reports indicate that in the first half of 2007 spam reached 59% of all the monitored email traffic, a substantial increase compared to the 54% of q4-2006.

A scaring 0,68% of these emails had a security threatening payload, in the form of a malicious attachment, which corresponds to a malware-based attack every 140 spam messages sent.

Since a few years now, crackers and criminal organizations that operate in the digital domain have been using a mix of social engineering and software exploiting techniques.

This mix has become more and more effective, aggressive and dangerous over time, and very lucrative too, so that we now see a flourishing global market of pre-made malware and crime-dedicated tools, growing stronger every day.

Sending malicious attachments by email is by large the most common vector of infection, since it's quite easy to exploit the weaknesses of the most spread email clients, and also because the end-users are not cooperating, seeming incapable of preventing and managing these kind of attacks.

In the last months, statistics showed the growing diffusion of modified PDF attachments used as a vector to execute and deploy trojan horses: these attacks were quite successful, overall, due to the overlapping and reinforcing consequences of different causes:

- acrobat reader is typically considered a harmless and necessary application , therefore it's allowed by default even on corporate PCs

- acrobat reader is exploited by taking advantage of vulnerabilies which are usually 0-day, undisclosed, or unpatched by the vendor

- users "believe" in PDF files, and are so used to them, coming from trustable sources all the time, that easily fall victim of the "PDF = good, official stuff" impression

- a PDF based attack can also exploit the users on a semantic level, and can reinforce a social engineering based scam, because of the trust that people have in them, especially when they look official (well written, professionally looking documents, discussing serious / interesting topics)

Protection against these kind of attacks can be obtained and enforced only if, or better when, end users will become part of the security chain, actively cooperating in all the countermeasures, from prevention to reaction. The only way to achieve this goal is to make them responsible in some way if something bad happens, or could have happened because of their wrong behaviour.

If we want to rise the security bar substantially, we must go beyond the obsolete idea that the end users are dummy, helpless, passive members of their organizations. Like every car driver knows, it doesn't take to be a mechanic to be able to drive safely: by respecting some basic rules which can save money, lives, and troubles, everyone behaves in a safer way, for his/her own interest.

So it's necessary to transfer some costs and responsabilities of the security process toward the end-user, by introducing proper regulations, sanctions, and reinforcing their personal interest in the secure flow of operations, at every level. ICT Security will never achieve better security than we already have, if we do not actively involve the end users in the loop. Problems arise not because of a lack of awareness and education, but because of a lack of involvement and responsability.

It's a huge, delicate, hot topic, which will be debated for years, so that we can just bring it to your attention for further discussion: but denying it would be like denying the existence of the dark side of the moon.


 
 


Comments Index (Total Messages: 2)
The Moon Written by Guest on 2007-09-06 10:06:42
  Re: The Moon Written by Guest on 2007-09-07 08:57:08

Powered by a Zone-H(ified) version of AkoComment 3.0!


DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The   author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice.
 
< Prev   Next >
Advertisement
 
Top! Top!