Attacks/Breaches
2/20/2013
10:08 AM
50%
50%

Apple, Facebook Twitter Attacks: 6 Key Facts

FBI investigates how hackers compromised an iOS developer website to exploit Java plug-in vulnerabilities and breach major social networking and technology companies.

4. Facebook Spotted Attack After Suspicious Network Behavior

While antivirus software didn't spot or block the attacks, other security defenses in place helped at least some of the businesses spot the exploit. Notably, Facebook said its security team spotted signs of an infection, which it then chased down. "In this particular instance, we flagged a suspicious domain in our corporate DNS logs and tracked it back to an employee laptop," according to Facebook. "Upon conducting a forensic examination of that laptop, we identified a malicious file, and then searched company-wide and flagged several other compromised employee laptops."

"After analyzing the compromised website where the attack originated, we found it was using a 'zero-day' (previously unseen) exploit to bypass the Java sandbox (built-in protections) to install the malware," said Facebook. "We immediately reported the exploit to Oracle, and they confirmed our findings and provided a patch on February 1, 2013, that addresses this vulnerability."

Similarly, Twitter's information security personnel had "detected unusual access patterns that led to us identifying unauthorized access attempts to Twitter user data," according to a blog post at the time from Bob Lord, Twitter's director of information security, who said that attackers accessed data that included "usernames, email addresses, session tokens and encrypted/salted versions of passwords."

5. Hacked Companies Circled The Wagons

Apple, Facebook and Twitter being attacked wasn't unusual, but according to Facebook, having such an attack succeed was rare. "Facebook, like every significant Internet service, is frequently targeted by those who want to disrupt or access our data and infrastructure," it said. "As such, we invest heavily in preventing, detecting and responding to threats that target our infrastructure, and we never stop working to protect the people who use our service. The vast majority of the time, we are successful in preventing harm before it happens, and our security team works to quickly and effectively investigate and stop abuse."

In the case of this successful exploit, Facebook said it immediately shared threat intelligence with other affected businesses, though didn't name them. "Facebook was not alone in this attack," it said. "It is clear that others were attacked and infiltrated recently as well. As one of the first companies to discover this malware, we immediately took steps to start sharing details about the infiltration with the other companies and entities that were affected. We plan to continue collaborating on this incident through an informal working group and other means."

Facebook, working with a third party, also sinkholed the command-and-control server employed by attackers, reported Ars Technica.

6. Warning: More Mobile Developers Likely Exploited

Who else might have been compromised as part of this attack campaign? F-Secure's Sullivan said in a blog post that because the attackers who compromised Facebook and Twitter did so via sites that target developers of mobile apps, all mobile app developers -- whether using Mac OS X or Windows -- should assume they've been targeted.

"Twitter and Facebook obviously have dedicated security teams on the lookout for trouble. (They're big targets.) Unfortunately, other smaller Silicon Valley startups (with big user bases) don't have the same resources," said Sullivan. "There are hundreds of thousands if not millions of mobile apps in the world. How many of the apps' developers do you think have visited a mobile developer website recently?"

What were attackers looking for? That's not yet clear, but if the hackers behind the exploits are criminals, then they're likely pursuing any avenue that could lead to remuneration. Unfortunately for mobile code developers, that might include efforts to sneak backdoors into their mobile apps. Accordingly, "any developer who has Java enabled in his browser, has visited mobile developer websites in the last couple of months and finds evidence his computer is compromised, probably should use his source code versioning system to check recent commits," said Sullivan. "And if you don't use a source code version system (such as SVN or Git), have fun re-reading your entire code base."

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
adeeladil
50%
50%
adeeladil,
User Rank: Apprentice
2/20/2013 | 7:42:02 PM
re: Apple, Facebook Twitter Attacks: 6 Key Facts
here is a very interesting blog that talks about exactly what should be done to detect a breach early and to have a plan in place to react promptly to secure your data and limit the damage from a particular attach http://www.enpointe.com/securi...
adeeladil
50%
50%
adeeladil,
User Rank: Apprentice
2/20/2013 | 7:03:09 PM
re: Apple, Facebook Twitter Attacks: 6 Key Facts
According to FBI Investigation report major social networking sites like Facebook, Twitter and technology companies like Apple were infected. All three companies were apparently compromised after their mobile developers visited a popular website devoted to iOS development called iPhoneDevSDK.
I read an article on cyber securities by En Pointe Technologies that GǣThere are only two types of companies those that have been hacked and those that will be.Gǥ We should put together a strategic security plan that includes an assessment of your current security posture, identify system and policies vulnerabilities and invest in resources and technology to provide a multi layer protection against attacks.
Must find an IT Security Service on http://www.enpointe.com/securi...
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8891
Published: 2015-03-06
Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to escape the Java sandbox and execute arbitrary code via unspecified vectors...

CVE-2014-8892
Published: 2015-03-06
Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to bypass intended access permissions and obtain sensitive information via un...

CVE-2015-1170
Published: 2015-03-06
The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not properly validate local client impersonation levels when performing a "kernel administrator check," which allows local users to gain administrator privileges via unspecified API call...

CVE-2015-1637
Published: 2015-03-06
Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict TLS state transitions, which makes it easier for r...

CVE-2014-2130
Published: 2015-03-05
Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka B...

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industrys professional organizations about how security pros can get more involved with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.