FriendFinder Networks Accounts Exposed (November 13 & 14, 2016)

SANS NewsBites is a semiweekly high-level executive summary of the most important news articles that have been published on computer security during the last week. Each news item is very briefly

summarized and includes a reference on the web for detailed information, if possible.

Spend five minutes per week to keep up with the high-level perspective of all the latest security news. New issues are delivered free every Tuesday and Friday.

November 15, 2016

TOP OF THE NEWS

Hack the Army Bug Bounty Challenge
Microsoft Moving to Security Portal for Patch Tuesday
FriendFinder Networks Accounts Exposed
HNAP Protocol Flaw in D-Link Routers

THE REST OF THE WEEK'S NEWS

BlackNurse Requires Just One Laptop to Launch DDoS
OMB FISMA Memo Clarifies What Constitutes a Major Cyber Security Incident
OMB Releases Federal Website Policy Update
Australian Retailer Acknowledges Inadvertent Data Exposure
UK Approves Lauri Love's Extradition
Linux LUKS Disk Encryption Vulnerability
OAuth Vulnerability May Put Access and Data to a Billion Mobile Apps At Risk

INTERNET STORM CENTER TECH CORNER

INTERNET STORM CENTER TECH CORNER


*********************** Sponsored By Sophos Inc. ************************ Don't be a data loss headline! With data hacks getting ever more sophisticated, the best way to avoid being a victim - and a headline - is to secure all of your data, all of the time. Introducing Next-Gen Encryption: stop breaches, collaborate securely and stay compliant. Learn more: http://www.sans.org/info/189767 ***************************************************************************

TRAINING UPDATE

--Cyber Defense Initiative 2016 | December 10-17, 2016 | Washington, DC | https://www.sans.org/event/cyber-defense-initiative-2016

--SANS Amsterdam 2016 | December 12-17, 2016 | Amsterdam, Netherlands | https://www.sans.org/event/amsterdam-2016

--SANS Security East 2017 | January 9-14, 2017 | New Orleans, LA | https://www.sans.org/event/security-east-2017

--Cloud Security Summit & Training | San Francisco, CA | Jan 17-19, 2017 | https://www.sans.org/event/cloud-security-summit-2017

--SANS Las Vegas 2017 | January 23-30, 2017 | Las Vegas, NV | https://www.sans.org/event/las-vegas-2017

--Cyber Threat Intelligence Summit & Training | Arlington, VA | Jan 25-Feb 1, 2017 | https://www.sans.org/event/cyber-threat-intelligence-summit-2017

--SANS Southern California - Anaheim 2017 | February 6-11, 2017 | Anaheim, CA | https://www.sans.org/event/anaheim-2017

--SANS Secure Japan 2017 | February 13-25, 2017 | Tokyo, Japan | https://www.sans.org/event/secure-japan-2017

--SANS Secure Singapore 2017 | March 13-25, 2017 | Singapore, Singapore | https://www.sans.org/event/secure-singapore-2017

***************************************************************************


TOP OF THE NEWS

Hack the Army Bug Bounty Challenge (November 11 & 14, 2016)

The US Army has announced its first "Hack the Army" competition. Much like the "Hack the Pentagon" event that took place earlier this year, participants are invited to search for security issues in specified systems. But unlike the Pentagon's event, which limited the probing to static websites, the army's event will focus on the Army's digital recruiting infrastructure, which includes websites and databases that contain information about applicants and existing personnel. The event is by invitation only.


[Editor Comments ]

[Pescatore ]
Good to see this approach spreading across DoD. Time for the civilian side of the federal government to follow suit.


[Murray ]
Very clever, not to say cunning. Many hackers are more motivated by ego than dollars. The hackers will be exposed to the recruiting content. Some talent may be identified.

Read more in:

Dark Reading: US Army Challenges Security Researchers To 'Bring It On'
-http://www.darkreading.com/vulnerabilities---threats/us-army-challenges-security
-researchers-to-bring-it-on-/d/d-id/1327480?

Wired: The US Military Launches "Hack the Army," its Most Ambitious Bug Bounty Yet
-https://www.wired.com/2016/11/us-military-launches-hack-army-ambitious-bug-bount
y-yet/

Microsoft Moving to Security Portal for Patch Tuesday (November 14, 2016)

Starting next year, Microsoft will change the format for its monthly security bulletins. The index of static documents will be replaced with a database-driven portal called the Security Updates Guide. The portal is currently in preview; bulletins for November 2016, December 2016, and January 20176 will be published in both formats; starting with February's updates, patch information will be available only through the Security Updates Guide.


[Editor Comments ]

[Ullrich ]
About time. Microsoft security bulletins have become very hard to parse given the large number of Windows versions and configuration options they cover. Maybe Microsoft will even offer a standard parsable format (XML...)

Read more in:

ZDNet: Patch Tuesday overhaul: Microsoft to replace security bulletin index with database-driven portal
-http://www.zdnet.com/article/microsoft-to-replace-security-bulletin-index-with-n
ew-database-driven-portal/

FriendFinder Networks Accounts Exposed (November 13 & 14, 2016)

Hundreds of millions of users accounts for FriendFinder Networks have been compromised in an attack. The attack is believed to have occurred in October. It appears that the breach included information for deleted accounts as well as for active ones. The attack compromised nearly all account passwords.


[Editor Comments ]

[Williams ]
Perhaps the most concerning aspect here is that "deleted" accounts were also compromised. This announcement comes on the heels of discovering that Ashley Madison wasn't actually deleting accounts, either. If you store customer data, ensure you are telling the truth when you tell them their data is deleted.

Read more in:

Computerworld: Biggest hack of 2016: 412 million FriendFinder Networks accounts exposed
-http://computerworld.com/article/3141290/security/biggest-hack-of-2016-412-milli
on-friendfinder-network-accounts-exposed.html

ZDNet: AdultFriendFinder network hack exposes e412 million accounts
-http://www.zdnet.com/article/adultfriendfinder-network-hack-exposes-secrets-of-4
12-million-users/

HNAP Protocol Flaw in D-Link Routers (November 11, 2016)

The US CERT has issued an advisory warning of an HNAP-parsing vulnerability in D-Link routers. The flaw could be exploited to allow "a remote, unauthenticated attacker ... to execute arbitrary code with root privileges." The CERT advisory lists D-Link routers known to be affected (DIR-823, DIR-822, DIR-818L(W), DIR-895L, DIR-890L, DIR-885L, DIR-880L, and DIR-868L). D-Link has issued fixes for some of the affected products. The researcher who found the vulnerability says other devices could be affected as well.


[Editor Comments ]

[Ullrich ]
I do not believe there is any home/SMB router that is free of vulnerabilities in its admin interface. Do not provide access to the admin interface from outside your network, and if you have to, then lock it down as best you can with firewall rules. A strong password will not protect you against flaws like this one that do not require authentication.


[Williams ]
HNAP is, thankfully, falling out of favor. For perspective, while the security bulletin says this is "remotely exploitable," it means exploitable from the LAN only. D-Link routers ship with WAN administration disabled and HNAP should not be accessible from the WAN interface.

Read more in:

Computerworld: Another HNAP flaw in D-Link routers
-http://computerworld.com/article/3138023/internet/another-hnap-flaw-in-d-link-ro
uters.html

CERT: D-Link routers HNAP service contains stack-based buffer overflow
-http://www.kb.cert.org/vuls/id/677427

D-Link: Support Announcement: HNAP stack overflow
-http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10
066



*************************** SPONSORED LINKS *****************************

1) Watch Splunk experts discuss real-world examples of Splunk Enterprise Security frameworks, and also demo these frameworks. Join now! http://www.sans.org/info/189772

2) Everything you wanted to know about Security Information and Event Management (SIEM) but were afraid to ask. Get your copy of the Beginner