Service Desk 0300 300 2212

Archive for February, 2012

Updated penetration testing factsheet available

Monday, February 27th, 2012

We’ve published a revised edition of our penetration testing fact sheet. The revisions focus on the Tiger Scheme, which is now widely used to gain CHECK accreditation. It some of the most frequently asked questions we receive about penetration testing as well as terminology and the different services available.

STRATFOR Response

Thursday, February 16th, 2012

We’ve decided to write an “incident of the month” feature to highlight the unseen work that Janet CSIRT does. These articles won’t feature in depth technical or forensic analysis of the latest threats, but we do hope to provide an insight into how a Incident Response team operates. The recent STRATFOR hack was mentioned in the latest edition of Janet News, and that provides as good a starting point as any.

On Christmas Eve the hacker collective ‘Anonymous’ accessed the web servers of STRATFOR, a Global Intelligence think tank based in Austin Texas, and copied 200 gigabytes of data. The account details of approximately 860,000 subscribers have been compromised following this attack including passwords used by 1,500 Janet users at 200 sites. The account details were quickly uploaded to pastebin.com and other distribution sites. The timing was unfortunate and occurred over Christmas during our reduced working hours. By the time we were able to investigate the original source of data had disappeared.

In early January the data had reappeared in an easier to digest form where anyone could quickly search through the large volume of data to pull out only relevant account details. We were able to extract over 1,500 accounts with e-mail addresses in .ac.uk domains, and began to process them.

Dealing with large incidents that affect hundreds of customers presents a dilemma. Should the entire event be considered as a single incident in our incident handling system, or should each customer be allocated their own incident? Handling the incident per customer allows us to better triage our workload according to the needs and requirements of each customer and so this is the approach we usually opt for. Considering the event to be a single incident is perhaps conceptually tidier and more “correct”, but can quickly become cumbersome.

Automated scripts match the e-mail addresses in the data to specific customers which is not a simple task. Institutions can have long and short form domains, as well as a large number of domains belonging to departments and projects. The script created tickets in our incident handling system and dispatched e-mails containing details of the incident to each customer. As soon as replies started arriving from customers, these incidents are manually handled just like any other. The number of incidents we were handling more than doubled during this period.

By the time the information had reached us, some of the compromised data had already been abused. Since many people reuse passwords across many systems, e-mail accounts were easily accessed. These accounts were quickly secured when we alerted institutions to this risk. Some of the data also contained credit card details. These had been quickly abused and most people had already been notified by their banks of fraudulent transactions. Thankfully most in the majority of cases people just had to have a long hard think about how they chose and use passwords.

Online Briefing: Incident response and cloud computing

Thursday, February 16th, 2012

As part of a series of online briefings on cloud computing we’ve arranged for Brian Honan of IRISS-CERT to give a half hour talk on Thursday 8th March 2012 from 12:30-13:30.

“Moving to cloud computing can bring about many advantages in terms of flexibility, scalability and other benefits. But have you thought about the security challenges? In particular, in the event of a security breach how should you deal with the impact? This talk examines security issues and ways to address them.”

There will also be an opportunity after the talk to ask any questions and of course members of Janet CSIRT and the Brokerage team will also be on hand.

Janet can register for the event now. We look forward to seeing you there,

JANET CSIRT Incident Statistics for January 2012

Wednesday, February 1st, 2012
Category Count
Compromise 275
Copyright 287
Denial of Service 4
General Query 2
LEA Query 2
Legal/Policy Query 1
Malware 278
Net/Security Query 12
Other 13
Phishing 10
Scanning 40
Social Engineering 2
Unauthorised Use 16
Unclassified 0
Unsolicited Bulk Email 57
Total 999

Contact Us: irt@csirt.ja.net
PGP Key ID: 0x4EC70D66

0300 999 2340
+44 1235 822 340

Service Hours:
08:00 to 18:00 Mon-Fri
18:00 to 00:00 Mon-Fri*
09:00 to 17:00 Sat-Sun*
(*reduced service)

News:

Incident of the month: DOS Attacks? (18/4/12) more

JANET CSIRT Incident Statistics for March 2012 (1/4/12) more

Twitter: