Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Why Hackers Found Easy Targets At IMF, Citigroup

Security experts say simple tactics succeeded in breaching major organizations in recent weeks because companies failed to conduct their own penetration testing.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
How are attackers exploiting major organizations? RSA said it was felled by an advanced persistent threat (APT). More recently, news accounts have said that the International Monetary Fund and Citigroup were exploited by "sophisticated" attacks.

But security experts say that at least by today's standards, most of these attacks were far from advanced, except perhaps in their simplicity.

For starters, statistically speaking, that's because few attacks pass the sophistication threshold. According to the 2011 Data Breach Investigations Report from Verizon, "only 8% of data breaches represented a 'high' attack difficulty," said Rob Rachwald, director of security strategy for Imperva, in a blog post.

Furthermore, looking closely at recent attacks, most involved spear phishing (RSA, IMF) or URL hacking (Citigroup), neither of which is very sophisticated. In terms of spear phishing, that goes for state-sponsored attacks that target specific victims--Rachwald's definition of an APT--as well as automated attacks launched en masse and aimed at a lowest common denominator, such as using an email purporting to offer the image of a dead Bin Laden.

"With APT, they are more of a 'one off' tailor-made nature, while in automation it is a 'one size fits all' approach," he said. "The APT attitude costs much more--which makes it only relevant for very motivated parties. But make no mistake: It isn't very sophisticated."

Lack of sophistication also featured in the Citigroup breach. For that exploit, attackers "leapfrogged between the accounts of different Citi customers by inserting various account numbers into a string of text located in the browser's address bar," an unnamed security expert told The New York Times.

In other words, attackers took advantage of the fact that the Citi Card website failed to hide actual account numbers in the URL string. "It would have been hard to prepare for this type of vulnerability," said the security expert, who's familiar with the investigation.

In fact, it would have been easy to prepare for this type of vulnerability, known as "Insecure Direct Object References," which is so widespread that it ranks as the fourth most dangerous vulnerability on the Open Web Application Security Project top 10 list of Web application vulnerabilities.

Perhaps Citigroup's developers and automated code-scanning tools failed to spot the use of real account-related information in URL strings. But that's where penetration testing is supposed to fill in, and it's obvious from numerous recent breaches, involving Citigroup, Sony, and almost any site exploited by LulzSec, that "pen testing" wasn't employed.

"When you look at how the breaches are occurring, it's like penetration testing 101--ethical hackers are taught to test computer security on the good guy side," Alex Cox, principal research analyst at NetWitness, said in an interview last month. (NetWitness, which was acquired by RSA in April, doesn't offer penetration testing.)

"So, a lot of times people aren't applying the idea of, let's hire someone to break in and see if he can do something realistically. But if you've got a good pen-test team, that's a really good way to understand where your vulnerabilities are," he said.

Or to reverse Cox's advice, by not conducting penetration testing on their Web applications, businesses won't know where all of their vulnerabilities are, and thus won't be prepared to repel attackers. Which, like recent attacks, doesn't seem very sophisticated.

Black Hat USA 2011 presents a unique opportunity for members of the security industry to gather and discuss the latest in cutting-edge research. It happens July 30-Aug. 4 in Las Vegas. Find out more and register.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18898
PUBLISHED: 2020-01-23
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14...
CVE-2019-19837
PUBLISHED: 2020-01-23
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests.
CVE-2020-7210
PUBLISHED: 2020-01-23
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
CVE-2019-19835
PUBLISHED: 2020-01-23
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
CVE-2020-5216
PUBLISHED: 2020-01-23
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/override_content_security_policy_directives, a newline could be injected leading to limited header injection. Upon seei...