Home Blog Page 61

Network Security for Legal Eagles

Network Security

Today, no industry sector is safe from cyberattacks, as threat actors target businesses with a malicious aim of gaining information or monetary benefits. The digital age has undoubtedly ushered in beneficial changes in the life and work of many. But on the flip side, it has also been accompanied by an alarming rise in cybercrimes. This trend of continuous changes in the digital world that tends to attract more cybercrime has become a significant concern for cybersecurity specialists. Many organizations conduct businesses online by making their service or related information available online over a network of databases, applications, websites, etc. Thus, this network and the edge where it connects to the internet have become an entry point for hackers to initiate their intrusion.

By Bradley J. Schaufenbuel, Vice President and Chief Information Security Officer at Paychex

Network security has become a mandate when it comes to digital security in various industry sectors, as in today’s age, even losing information details of your client will in no time become a liability issue that needs to be settled through the court of law. Ironically no other industry than the legal sector and especially the law firms are in dire need of network security due to the significant amount of sensitivity and liabilities their business information holds. Though compromise of information security is relatively common in the digital landscape, its impact will differ with respect to the sensitivity of compromised data. The colossal amount of sensitive information available with law firms becomes the target of frequent cyberattacks by threat actors. The overhaul affects law firms that tend to store on their networks legal, proprietary, and personal/sensitive information related to their clients, which could be exploited to harm both the firm and the client.

Network security

Organizations tend to establish and implement a security architecture around their information processing cores to safeguard sensitive and confidential information. As the networks are the data transmission platforms that connect this core with the internet, without stable and robust security, the organization’s sensitive data such as the client’s personal information, financial records, business data, proprietary, and other legal data will be exposed tremendous risk. The security architecture built around an organization’s network aims to defend the digital assets and data against attacks such as trojans, viruses, spyware, malware, worms, Denial-of-Service (DOS) and Distributed Denial-of-Service (DDOS), sniffing, eavesdropping, spoofing, and much more [1].

See also: Why Network Security is Important in Today’s Digital World

Current Threat Landscape

The clients expect their law firm’s security standards to be of the level equivalent to that used or displayed by the IT industry as many law firms tend to run virtual offices to work with their overseas clients and global partners, making more than 90% of legal information available in digital form. The digital assets and data held by law firms keep increasing in quantity with a continuous accumulation. Unlike other information security compromises where the primary motive is a monetary benefit (due to digital fund transfer), attacks on law firms stem from the exploitation of sensitive information. Hence, ransomware attacks are one of the most prominent attacks in this sector.

As one could expect, the COVID 19 pandemic has propelled the digitalization of a business process, and law firms are no exception. Many jurisdictions, including those in developing countries, permit online filing systems, client briefs, and even interviews via phone and emails. Hence, it has become imperative for law firms and judicial bodies to prioritize information security. Coincidently, cyberattacks against law firms have also increased substantially since 2015 in the United States alone. Cybersecurity evangelists are concerned that law firms are either poorly aware of the cybersecurity-related risks or do not intend to discuss them publicly. According to a 2020 survey by American Bar Association’s (ABA) & Legal Technology and Resource Center (LTRC), less than half of the law firms used advanced computer and network security tools and techniques. Even less than 40% of them used what appears to be an essential security feature from the perspective of corporate MNC’s [2]. On multiple occasions, large US law firms have been criticized for not acknowledging or even discussing their breaches and compromise of information security.

Discussing the Current Challenges

Law firms operate in a complex and challenging environment that involves balancing multiple projects wherein each project is staffed with numerous attorneys working with a more significant number of clients. Many law firms conduct business over email and are responsible for the large volumes of sensitive digital data, and though they aim to secure these communication channels, there exist multiple challenges in implementing security controls. The lack of database and endpoint security, vulnerability assessment framework or tools, resources and budget, a framework to manage and mitigate insider’s threat, security awareness framework for employees, clients, and business partners, etc., constitute some of the significant technical and policy-based challenges faced by law firms.

Even if the above mentioned technical and policy-related challenges could somehow be resolved, there exists another issue pertaining to the ‘intent of the law firm or business associates, wherein the implementing cybersecurity faces roadblock due to various reasons such as:

  • Many law firms and associated businesses see security expense as a secondary aspect, as committees with limited cybersecurity knowledge tend to manage these firms.
  • Implementing security controls for endpoint or end-user is difficult as security compulsions are not able to bind end-users, clients, and partners.
  • Law firms tend to compromise some of their information, such as contact information, email, etc., as part of their much-needed advertisement campaign.
  • The interest of state-sponsored attackers when it comes to sensitive inter-state or international cases has become a leading security challenge for larger law firms that handle important clients with diplomatic connections.
  • Some in-house policies require the storage of sensitive information to be in-house, which may deny affordable and secure third-party database/cloud storage.
  • The lower job satisfaction rate among security professionals working for law firms compared to other industries or a limited number of professionals is tasked with the complete security architecture, leading to subpar performance.

What do law firms stand to lose?

The main repercussions of any security breach are financial loss, reputation damage, and legal suits, and the same stands true for law firms. Apart from this, law firms are primarily trusted with the client’s crucial and sensitive data. Hence, the trust takes the real and complex damage in the event of a security breach. The attorney-client privilege and standard of care provided yields a greater degree of trust between the client and attorney (and the law firm). It is inherent for clients to share secrets and expect a high level of confidentiality in return. This inherently also applies to the safekeeping of the sensitive information shared by the client. Hence, it could be said that apart from legal maturity, the information security capability of the law firm will also decide its reputation in the market. The clients tend to expect the highest security standards, similar to what their organizations use in their respective industries/sectors. Apart from trust and reputation loss, the compliance factors also kicks-in, where frameworks such as ISO27001, European Data Protection Law, and other legislative compliance for cybersecurity require firms to hold sensitive information to comply with its security in the digital space. Many of these compliances need the law firms to have an incident response plan to reduce the impact of damage caused in the event of an attack.

Mitigating the Threats

Comparing the security readiness of law firms to that of the IT businesses, it could be noted that the majority of law firms pose multiple vulnerabilities that could be exploited to compromise information security. These include unsecured devices and storage, open wireless networks, insecure remote communicating, poor state security with vendors and third-party service providers, and much more.

In order to strengthen the network security architecture, law firms need to build a robust security plan with a mitigation strategy for every security scenario that may arise. These plans and protocols should be versatile enough to include various security tools and seamlessly work with threat techniques such as:

  • Firewall, which is the first line of defense in any network’s security layer, and traffic flow through the set access control rules.
  • Intrusion detection systems/intrusion prevention systems (IDS/IPS), that assists the network security with the detection and prevention of any attempts of cyberattacks. These security measures are effective to prevent Distributed Denial-of-Service (DDOS) attacks and perform behavioral analytics for network traffic.
  • Using honeypot, that acts as acts a decoy for the original network and lures threat actors to study and record their behavior during network intrusion.
  • Segmenting the network to enforce different security policies onto the subnetworks. Splitting the network assets into segments will reduce the attack surface available for exploitation.
  • Using a virtual private network (VPN) that creates a virtual channel to securely connect users and a private network over the public network.
  • Enabling endpoint security that secures devices at the end of the data distribution chain. It involves VPN security, antivirus, and antimalware solutions, along with securing operating systems, email, and phishing & vishing solutions.
  • Implementing wireless security, that preventing unauthorized access/intrusion into a network through a wireless connection.
  • Implementing access control, that employs user and device authentication as a unified security architecture for network security.
  • Encrypting the network data that employs IPSec to protect private communication over IP networks.
  • Implementing SIEM (Security Information and Event Management) helps the incident response team to detect and managing security incidents.
  • Establishing Security Operations Center (SOC) in order to manage all the security activities mentioned.

The methods and protocols that any law firms should incorporate as part of their architecture design toward information security could be divided as a five-step road map that involves:

  1. Establishing a security governance body to make partners aware of the risks.
  2. Adopting a set of policies and standards aligned to an established risk framework, e.g., NIST CSF, ISO 27001, etc.
  3. Performing a gap assessment against these policies and standards.
  4. Prioritizing gap remediation efforts and obtain funding.
  5. Implementing process, technology and people to build security capabilities, eliminate gaps, and reduce risk.

Conclusion

When integrating information, tools, and applications across the internet in correspondence to digitalization, or emerging technologies to facilitate easier access, management, and processing, it is essential to assess the security implication as these changes bring multiple associated risks. Though legal sectors have made substantial attempts to ensure information security, there is still a lot to be done. Law firms in particular lag behind in cybersecurity readiness, which has led to multiple issues. It is imperative for law firms to prioritize safeguarding their client’s data and evaluating their security architecture to detect and fix problems. The network security architecture of the law firms needs to be reviewed and updated frequently, accompanied by establishing and implementing a security awareness program. Failing to improve the security can could lead to vulnerabilities that are signified as a potential lawsuit waiting to happen. Law firms and their management need to have a practical and comprehensive understanding of cybersecurity and implement security programs with the help of various tools and techniques.

References

[1] https://blog.eccouncil.org/securing-the-network-of-law-firms/

[2] https://www.americanbar.org/groups/law_practice/publications/techreport/2020/cybersecurity/


About the Author

Bradley J. SchaufenbuelBradley J. Schaufenbuel is currently Vice President and Chief Information Security Officer at Paychex. He leads his infosec professionals to manage and monitor tasks focused on crisis management, security training and awareness, risk and compliance, identity management, managed file transfer, security engineering, security investigations, cyber intelligence, vulnerability management, and security architecture and application security. He has multiple years of experience working with the financial sector and has authored numerous books and research publications wide variety of topics related to information security and governance. Schaufenbuel also holds a license to practice law in Illinois and is a U.S. Supreme Court Bar member. He has served on several corporate and non-profit boards and is a regular speaker at industry conferences.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


 

Cybercriminals Entice Employees to Deploy Black Kingdom Ransomware

Black Kingdom ransomware

In a new kind of insider threat campaign, cybersecurity researchers found a Nigerian cybercriminal group enticing unwitting employees by offering them a share of their presumed ransom if they deploy Black Kingdom ransomware, also known as DemonWare or DEMON, on corporate network systems. The ransomware operators reportedly offered one million or 40% of the $2.5 million ransom as bribe to employees if they deployed the ransomware physically or remotely.

Abnormal Security claimed that it blocked multiple emails sent to its employees, requesting them to be a part of the ransomware campaign. “We identified and blocked several emails sent to Abnormal Security customers soliciting them to become accomplices in an insider threat scheme. The goal was for them to infect the companies’ networks with ransomware. These emails allege to come from someone with ties to the DemonWare ransomware group,” Abnormal Security spokesperson said.

Active since 2019, Black Kingdom ransomware was used by threat actors to exploit Microsoft Exchange vulnerability CVE-2021-27065.

How Black Kingdom Ransomware Spreads?

The Black Kingdom operators provided two options to interested employees for further communication: Outlook email or Telegram. The attackers delivered the ransomware via email attachments or using direct network access.  Abnormal Security set up a fictitious persona to contact the ransomware operators.

Source: Abnormal Security

“As the conversation continued, it became clear that the actor was quite flexible in the amount of money he was willing to accept for the ransom. While the initial email insinuated the ransom would be $2.5 million, the actor quickly lowered expectations by indicating he hoped he could charge our fake company just $250,000. After our persona mentioned the company we worked for had annual revenue of $50 million, the actor pivoted and lowered the number even further to $120,000.

“The tactic used by this actor, however, allowed us to understand it better. Since the actor invited a target to get in touch with him, we did just that. We constructed a fictitious persona and reached out to the actor on Telegram to see if we could get a response. It didn’t take long for a response to come back, and the resulting conversation gave us an incredible inside look at the mindset of this threat actor,” Abnormal Security added.

Unpatched Microsoft Exchange Servers Under ProxyShell Attack

ProxyShell Vulnerabilities

While organizations are battling to boost their cybersecurity capabilities, cybercriminals continue to prey on security loopholes. Active exploitation of unpatched vulnerabilities has become a common attack vector today. The Cybersecurity and Infrastructure Security Agency (CISA) recently issued a warning about threat actors exploiting “ProxyShell” vulnerabilities in Microsoft Exchange servers.

In a security advisory, CISA stated that attackers are exploiting vulnerabilities, tracked as CVE-2021-34473CVE-2021-34523, and CVE-2021-31207, to execute arbitrary code on vulnerable systems. The flaws can enable threat actors to evade ACL controls and obtain privilege access on the Exchange PowerShell backend platform, allowing them to execute unauthenticated and remote code execution.

How were the ProxyShell vulnerabilities used?

ProxyShell vulnerabilities are often exploited to run malicious codes and infect the unpatched servers. Attackers used the three vulnerabilities as:

  • CVE-2021-31207 – This is a Microsoft Exchange Server security feature bypass vulnerability, allowing remote users to bypass the authentication process
  • CVE-2021-34523 – This is a Microsoft Exchange Server Elevation of privilege (EoP) vulnerability, allowing users to raise their permissions.
  • CVE-2021-34523 – This is a Microsoft Exchange Server remote code execution (RCE) vulnerability, allowing authenticated users to execute arbitrary code in the context of SYSTEM and write arbitrary files.

As per IT security firm Sophos, “Adversaries exploiting these vulnerabilities are first dropping web shells onto the compromised device through which they can issue additional commands such as downloading and executing malicious binaries. Sophos has observed threat actors establishing persistence on compromised devices by creating scheduled tasks to execute a suspicious binary periodically. As these vulnerabilities lie in CAS, which runs on IIS, malicious activity will stem from a w3wp.exe process, a worker process for IIS.”

Mitigation

CISA has asked organizations to find and update the vulnerable systems on their network by applying Microsoft’s Security Update from May 2021. Even Microsoft released the latest patch – July 2021 security updates for Microsoft Exchange – and urged companies to update their systems as early as possible.

Phishing Alert! XSS Vulnerability in UPS.com Distributes Malicious Invoice

xss vulnerability in UPS, Phishing Attack, spear phishing, phishing mails

Phishing is one of the most popular social engineering techniques cybercriminals use to distribute malware and steal personal information. As per recent reports, fraudsters have been leveraging an XSS vulnerability in UPS.com to circulate fake UPS Invoice MS Word documents. United Parcel Service (UPS) is a popular American multinational shipping and receiving, supply chain management company.

Security researcher Daniel Gallagher, in an interesting tweet shared, “Just saw one of the best phishing emails I have seen in a long time.”

The malicious UPS Invoice appears like a genuine-looking communication hinting that a package needs to be picked up by the customer. With the COVID uncertainty and distributed workforce scenario, we all receive couriers and packages from various sources and UPS, being a well-known service provider, would not invite much cross inspection or suspicion.

The fake malicious document has elements and links close to the actual invoice; however, they do not perform any malicious action. Whereas the tracking number is linked to the UPS website, which has the JavaScript XSS exploit.

What is XSS?

Cross-site scripting (XSS) is a type of security vulnerability typically found in web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.

Phishing still up on popularity chart

According to Verizon’s “2021 Data Breach Investigations Report,” phishing remains one of the top Action varieties in breaches and has been in that position for the past two years.

It attributes the top position to the pandemic-driven quarantine and the continued stay-at-home orders. The UPS.com breach is an example at hand that echoes the findings.

The number of phishing-related breaches has scaled to 36% from last year’s 25%.

The ease of having targets fall victim through this malicious distribution is incentive enough for hackers to continue with these threat vectors.

Related story: Five Phishing Baits You Need to Know [INFOGRAPHIC]

Is Your Website Hackable? Here Is How to Find Out

data integrity, website, security

There are nearly two billion websites on the Internet. Security flaws in many of them are fertile soil for easy takeover. Analysts claim that at least half of all content management system (CMS) installations are out of date and thus lack critical patches. About a quarter of web applications that run on sites are reportedly riddled with vulnerabilities.

By David Balaban, Computer Security Researcher, Privacy-PC.com

These statistics look staggering, don’t they? Let’s see how to prevent your website from ending up in the same boat.

The Classic Exploitation Chain

Based on the development peculiarities, any website falls into one of the following categories: hand-coded, made with turnkey website builders, and designed using a CMS platform such as WordPress, Drupal, Joomla, etc. The third type is prevalent and therefore targeted the most.

From an attacker’s perspective, content management systems are just like other online services. Since their code is publicly accessible, anyone can check it for security gaps and create exploits that piggyback on the discovered issues. Imperfections in third-party components such as plugins and themes significantly expand the attack surface.

In this scenario, the hack workflow is usually automated and targets multiple websites in one go. It involves bots that scan all sites within a certain range and determine which ones are susceptible to a specific exploitation vector.

Penetration testers follow the same logic, except that their objectives are benign. Before probing a website for weak links, they gather information about it using a tool like WhatWeb. It provides the big picture by determining the site’s CMS, the installed plugins, the geographic location, and the scripting language in use (PHP or jQuery).

Security Audit of a WordPress Website

If you need to pinpoint vulnerabilities in a website running WordPress, the world’s most popular CMS, an incredibly effective scanner called WPScan is your best bet. It retrieves a ton of site information, including the WordPress version, plugins, themes, usernames, unsecured wp-config files, database dumps, and open directories.

If any components are misconfigured or have known vulnerabilities, the tool will let you know by displaying exclamation marks next to them. WPScan is also equipped with a password brute-forcing feature so that you can find out what users have weak access credentials. Depending on how in-depth you want the report to be, you can choose between passive, aggressive, and mixed scanning modes.

One more tip is to add the CVE service to your handbook. It will allow you to explore all documented vulnerabilities in specific areas of the WordPress site. For example, you can browse known weaknesses in its PHP version. This is a great source of information about the potential entry points.

Looking for Joomla Website Vulnerabilities

The easiest way to check a Joomla site for security imperfections is to use a tool called JoomScan. Masterminded by specialists at the Open Web Application Security Project (OWASP), it determines the CMS version and provides a list of vulnerabilities with links to their CVE descriptions along with the associated public exploits. It additionally gives you a summary of all the open directories and fetches the hyperlink to the configuration file if the site administrator didn’t bother hiding it.

JoomScan is incapable of brute-forcing passwords. To try and retrieve such information, you may need a tool that works in concert with several proxy servers. Cracking weak credentials for the admin dashboard is very challenging because many Joomla sites use a plugin called Brute Force Stop. It blocks an attacker’s IP if the number of failed sign-in attempts reaches a predefined limit.

Checking websites that use Drupal and other CMS platforms

Unfortunately, a one-stop vulnerability scanner that would assess sites running Drupal and lesser-known CMS instances have yet to be created. A plugin-based tool called DroopeScan is perhaps the only option to automate the process. However, its report only includes basic site details that may not suffice to get actionable insights into vulnerable areas and other things that could improve.

With that said, you will have to take the manual route to explore the website’s security condition thoroughly. As part of this routine, look for proof-of-concept (POC) exploits on GitHub and scour the CVEdetails database for known vulnerabilities.

An illustration of what you can find this way is a bug tracked as CVE-2018-7600, which allows a perpetrator to run arbitrary code on sites using several Drupal versions from the 7.x and 8.x range. A little bit of further research will reveal a POC exploit for this vulnerability. Even if the automatic scanner only shows the CMS version and it turns out to be vulnerable, this information could be enough to compromise the website.

What about Hand-coded Websites?

There is no such thing as a scanner that checks a hand-coded site for obsolete web applications and known vulnerabilities. To bridge the gap, you need to look for potential flaws manually using the OWASP methodology or a tactic of your own. One of the best ways to systematize this process is to use the OWASP Web Security Testing Guide. It provides clear-cut rules for pinpointing the most critical web application vulnerabilities from the OWASP Top 10 list.

The previously mentioned WhatWeb scanner can point you in the right direction by listing all built-in services and their versions. If you find out that the website uses an old version of Apache Tomcat or Ruby on Rails application framework, you can search the web for the associated exploits.

The programming language version can also shed light on the potential vectors of compromise. For example, white hats are discovering new PHP vulnerabilities all the time, and the patches may take weeks to arrive.

The next thing on your to-do list is to run a content scanner like DIRB that will crawl the web server’s open directories and inspect the responses. A few more platform-neutral instruments that can help you spot common vulnerabilities are Burp Suite, Mantra Security Framework, nikto, OWASP Zed Attack Proxy (ZAP), skipfish, and w3af.

Keep Your Website Safe

If you use a CMS, avoid installing sketchy plugins, get rid of unused ones, and maintain proper software update hygiene. Web development specialists should thoroughly check the scripts found on the Internet before implementing them. It’s also important to comply with basic coding rules such as filtering database queries that contain special characters. Constant monitoring of your site’s performance will help to find any security issues before they can cause serious damage.

To steer clear of security issues with a custom-built website, the principle is similar: you need to check its web components for known vulnerabilities, purge it of all the elements you don’t use, and keep the others up to date. Another tip is to make sure that the web design studio that created the website provides a decent level of tech support.

It’s also a great idea to hire an unbiased penetration tester who will conduct a full audit of the site according to vulnerability assessment best practices. On a side note, some major companies run bug bounty programs and generously reward security professionals for finding security loopholes in their digital infrastructures, including official websites.

Final Thoughts

If you have a knack for spotting weak links in Internet-based services, the use of the OWASP Web Security Testing Guide is an amazingly effective way to hone your expertise. You can start with sandbox environments like virtual machines polluted by common vulnerabilities. If you get the hang of this activity, it can become a springboard for a brilliant penetration testing career.


About the Author

David BalabanDavid Balaban is a computer security researcher with over 15 years of experience in malware analysis and antivirus software evaluation. David runs the Privacy-PC.com project which presents expert opinions on contemporary information security matters, including social engineering, penetration testing, threat intelligence, online privacy, and white hat hacking. As part of his work at Privacy-PC, Mr. Balaban has interviewed such security celebrities as Dave Kennedy, Jay Jacobs, and Robert David Steele to get firsthand perspectives on hot InfoSec issues. David has a strong malware troubleshooting background, with a recent focus on ransomware countermeasures.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

How to Become an Ethical Hacker and Boost Your Career?

ethical hacker

Organizations cannot undermine the importance of cybersecurity strategies and the need for an ethical hacker community to keep their businesses afloat amidst a rise in cyberattacks. The increasing reliance on digital applications also raises privacy and security concerns globally. 

The demand for professional ethical hackers is only going to increase in the future. Security and IT (Information Technology) professionals consider taking a certification related to cybersecurity due to the lucrative opportunities.  

A Brief History of Hacking and Ethical Hacking 

Interestingly, the way we perceive hacking has also changed over the years. The term hacker refers to people who bypass security protocols and systems without authorization and with malicious intent. 

In the 1960s, the term hacking was related to activities performed by engineering students at the Massachusetts Institute of Technology. It was linked to finding new ways of hacking computer systems to make them work more efficiently. Hacking was used negatively in the 1970s after malicious hacking became more common with the increasing use of computer systems and technologies.  

The term ethical hacking was first used by IBM Vice President John Patrick in 1995 and has become a key concept in cybersecurity. Ethical hacking is the lawful or legal intrusion into a computer system, network, or application to find patches in the security and prevent cyberattacks by malicious hackers.  

Businesses are becoming wary of cyber breaches and data theft, and hence, they require ethical hackers to fortify their organization’s security.  

So, if you are a technical professional and wish to become a hacker, you need to brush up on your knowledge and polish your skills in ethical hacking. This article highlights the concepts of ethical hacking and the skills you need for a well-paying career as an ethical hacker. 

Who is an Ethical Hacker?

Ethical hackers are white hat hackers who penetrate a computer infrastructure to test target systems and report vulnerabilities. Organizations and government bodies employ cybersecurity professionals to identify potential threats and weak links in the network and prevent cyberattacks. An ethical hacker performs penetration tests on your IT infrastructure to detect internal and external risks.

Moreover, corporations are increasingly relying on cloud-based infrastructure to run their businesses, increasing the possibility of data breaches. Data theft costs firms a lot of money, so they hire a professional to find security weaknesses and fix them.

As per PayScale, the expected average salary of a Certified Ethical Hacker is currently $94,000 in the U.S.

So, if you want to advance your skills and IT career, the time is ripe to get Certified Ethical Hacker training and certification. Ethical hacking is a lucrative career path, and the demand for experienced hackers is on the rise. 

What Does an Ethical Hacker Do? 

An ethical hacker makes an authorized attempt to exploit a network’s security to identify vulnerabilities and report them to the organization. They use their skills to protect the company’s digital assets and prevent malware. They also employ the same tools and techniques that a black hat hacker does without malicious intent 

With the recent incidents of ransomware and increasing cybercrime, businesses and organizations need experts to perform penetration tests. There is a growing risk of security breaches because of digitalization and a transition to a remote work framework.  

Skills Required to Become an Ethical Hacker 

Many people often search the web for how to become an ethical hacker?. But before you take a plunge, you must be aware of the skills required to excel in this field. Ethical hacking encompasses a multitude of skill sets. To become a hackerand establish a career in the cybersecurity domain, one must first maintain high ethical standards. This is what differentiates an ethical hacker from the black hats or malicious hackers.  

A few of the important skills you need to acquire to pursue a career in this field are listed below:  

1. Networking and computer skills 

A firm and sound knowledge of computers and networks are crucial prerequisites for an aspiring hacker. Hacking involves exploiting computer systems and networks for locating potential threats. Therefore, aspirants need to be well-versed with computer and networking core concepts, including process injection, killing a thread, killing a process, etc. To enable ethical hacking, they should also have a stronghold on networking commands like OSI model, IP addresses, MAC addresses, subnetting, and routing.  

2. Knowledge of operating systems 

Another important ethical hacking skill to be familiar with is knowledge of operating systems. If you want to get Certified Ethical Hacker certification, you need to learn these concepts. An aspirant should have a strong understanding of LinuxMany web servers use Linux. Therefore, one should know operating systems like Linux, Ubuntu, Red Hat, etc., to check for cyber breaches and flaws. 

3. Proficiency in penetration testing methodologies and tools 

If you want to become a hacker, you must have a thorough knowledge and hands-on experience in penetration testing tools and techniques. White hats perform a penetration test on a company’s IT infrastructure to detect weak links. You can also take up a course to excel in this domain. 

4. Strong coding knowledge 

One needs to have strong programming skills to succeed in this field. As an aspiring ethical hacker, formal training in reading and analyzing codes can pave the way for your career in ethical hacking. Various programming languages are used for software and website development. Being adept in different programming languages like Python, BASH, and C++/C will help you identify malicious code or vulnerabilities in the code.  

5. Fundamentals of cybersecurity 

Another important skill to have when pursuing an ethical hacking certification program is understanding the key concepts of cybersecurity. If you are a beginner or a professional, you need to learn or know the basics, including antivirus, app protection, protecting a device, database management systems, password management etc.  

6. Cryptography Skills 

As an ethical hacker, one of your primary responsibilities is to ensure that texts or communication between different people in the organization are sent and received without compromising confidentiality and privacy. Cryptography is the process of transforming text messages into an unreadable form or ciphertextso that hackers are unable to read them if these are intercepted 

7. Problem-solving skills 

The field of cybersecurity is mired with challenges. With the advancement of technology, cyberattacks are also becoming more complex. Therefore, ethical hackers need to have analytical and critical reasoning skills to tackle these challenges. Problem-solving abilities and analytical skills are essential qualities ethical hackers require.  

Apart from these competencies, they must communicate effectively with various departments to increase system security. They can optimize their tasks by understanding hardware architecture and staying updated on new industry trends and insights to detect vulnerabilities. 

Learn Ethical Hacking with C|EH 

Before you learn how to be a hacker, it’s important to ask yourself why you are interested in hacking in the first place. If you wish to build a promising career in cybersecurity, you need to get trained in ethical hacking programs. Therefore, one should opt for a course that aligns with the skill sets mentioned above.  

EC-Council’s Certified Ethical Hacker (C|EH) program offers in-depth training in ethical hacking concepts. The program aims to teach participants the latest Cloud Security and IoT (Internet of Things) modules to understand system vulnerabilities better and improve security controls. 

The training modules offer a comprehensive understanding of penetration testing, malware analysis, attack vectors, scanning, information security powers, and various hacking threats.  

The Certified Ethical Hacker course has a high employability rate and recommendations from top government agencies such as the US Federal Government, the Montgomery GI Bill, and the National Security Agency (NSA).  

So, if you are excited to take yourethical hacker career forward, now is the time to get trained in the Certified Ethical Hacker program. 

20+ Job Roles | 10,000+ Job Openings | Avg. Salary of $93,000

Become a Certified Ethical Hacker.


FAQs (Frequently Asked Questions)

1. What is ethical hacking? 

Ethical hacking is the legal intrusion into a network or server to detect vulnerabilities. Ethical hackers report the suspicious activities to the system administrator. 

2. What are the coding languages that hackers use? 

A professional hacker should have a strong grasp of various programming languages such as Python, C/C++, Java, Perl, and LISP. So, with the help of these languages, ethical hackers can easily locate system and application vulnerabilities. 

3. Is hacking illegal? 

Hacking is not illegal if hackers have the authorization to break into system security. Hacking is illegal when hackers make an unlawful attempt to exploit system vulnerabilities, for financial gain or personal benefit.


Plug in this Mouse, Get Windows Admin Privileges!

windows admin privileges

Security researcher Jonhat shared a tweet exposing a zero-day vulnerability in Razer Synapse installation software. A simple plug-and-play USB or dongle can give you Windows admin privileges.

In the computer peripherals industry, Razer is known for its gaming mice and keyboards. The installation software called Synapse automatically gets downloaded when a new device is plugged in for the first time. It abuses the elevated explorer to open Powershell and get admin access.

To put it simply, if one can get admin access to Windows, they can get complete control of the operating system and install any software/hardware and play truant by also installing malware causing huge damage.

The security researcher reached out to Razer to share the vulnerability, however, he did not receive any response from them. He further disclosed the information about the zero-day vulnerability on Twitter, explaining how the bug works.

Once the exploitation began to be widely discussed and tweeted, Razer took cognizance and reached out to Jonhat. In an update, the researcher shared that he was contacted and assured by Razer that the company was working on a fix with high importance. He was also offered a bounty even though the bug was publicly disclosed.

What is PowerShell?

PowerShell is a task automation and configuration management framework from Microsoft, consisting of a command-line shell and the associated scripting language. Since the command opens with admin privileges by default, all the processes get admin access.

The Windows Vulnerability

A spate of critical vulnerabilities has been reported around Windows, the most recent being the Print Spooler bug (CVE-2021-36958). Microsoft had released security patches addressing 44 CVEs in the month of August alone.

U.S. State Department Hit by Cyberattack; Breach Extent Unknown

Department of State, state dep

In a recent tweet, Jacqui Henrich, the White House correspondent for Fox News, reported a cyberattack on the U.S. State Department. The breach was first notified by the Department of Defense Cyber Command.

According to the Twitter thread of the White House correspondent, the attack was believed to have occurred a few weeks ago, but no specific details were made available.

The attackers, the timing, and the extent of the breach are currently unknown.

In another tweet, Henrich mentioned the Senate Homeland Security Committee report for the month. In this report, the State Department’s overall information security was rated “D,” the lowest possible rating in the model, calling it ineffective in 4 of 5 function areas.

The Committee also reported that sensitive national security information like names, birth dates, and social security numbers used for passport vetting was at risk.  Interestingly, the tweet also shared that the State Department’s current mission to evacuate Americans and allied refugees from Afghanistan has “not been affected.”

In a statement, the State Department spokesperson said, “The Department takes seriously its responsibility to safeguard its information and continuously takes steps to ensure information is protected. For security reasons, we are not in a position to discuss the nature or scope of any alleged cybersecurity incidents at this time.”

Disruption in the Past

It seems virtually anything connected to the internet can be hacked. We reported multiple cyberattacks targeted at critical infrastructure and essential services in the recent past, including Florida City’s water supply, Colonial Pipeline, and JBS. There has been a constant attempt to cause large-scale disruption by these state-sponsored attacks, exposing the vulnerability which was earlier thought to be impenetrable.

Privacy Concerns Rise as Businesses Report Increased Personal Data Collection: KPMG

personal data collection, Personal data. Data Privacy

A new KPMG survey reveals a deep disconnect between corporate data practices and the general population’s expectations around transparency and data privacy. As companies collect more personal data, survey respondents are increasingly concerned about how their data is being used, and report concerns about the level of data collection.

KPMG’s survey confirms that data collection is rising, with 70% of the business leaders surveyed reporting that their companies have increased collection of personal consumer data over the last year. At the same time, survey respondents characterized as general population report feeling increasingly uneasy about these practices, with 86% of respondents saying data privacy is a growing concern for them and about two-thirds (68%) saying that the level of data collection by companies is concerning.

“This split between business and consumer sentiment isn’t new, but its persistence shows that businesses have a long way to go to make the public more comfortable with how they are collecting, using and safeguarding data,” says Orson Lucas, KPMG U.S. Privacy Services leader. “Failure to bridge this divide could present a real risk of losing access to the valuable data and insights that drive business growth.”

The findings in the “Corporate Data Responsibility: Bridging the Trust Chasm report are based on the results from two surveys. General population and U.S.-based workers: an online survey among a nationally representative audience of 2,000 U.S. adults, fielded from April 30 to May 6, 2021. Business leaders: an online survey among 250 director-level (or higher) decision-makers involved in security/privacy/data decisions at companies with 1,000+ employees from April 30 to May 12, 2021.

Respondents Wary of Personal Data Collection

General population respondents are worried about how organizations use their data, and many of these concerns are grounded in a fundamental lack of trust.

Key Findings

  • 83% would not willingly share their data to help businesses make better products and services
  • 64% say companies are not doing enough to protect consumer data
  • 47% believe their smart devices are listening to their conversations
  • 40% say they don’t trust companies to use their personal data ethically
  • 13% don’t trust their own employer to use their personal data ethically

Many business leaders acknowledge there is a reason for concern. Speaking about their own employer, 33% of business leaders say consumers should be concerned about how their company uses their personal data, and 29% acknowledge that their company sometimes uses unethical data collection methods.

“People tend to underreport behaviors that place them or their organization in a negative light,” says Lucas. “Having more than one in four report that their business sometimes uses unethical data collection methods is troubling and helps explain why consumers are wary.”

Businesses Can Help Bridge the Trust Chasm

To bridge this gap, enterprises must prioritize data protection and take meaningful action to build consumer trust. Approximately 62% of business leaders say their companies should be doing more to strengthen existing data protection measures. The vast majority of the general population respondents (88%) also say they want corporations to take the lead in establishing corporate data responsibility.

Businesses should consider ways to be more explicit and transparent about how consumer data will be used. Most general population respondents (76%) say they want more transparency about how companies are using their personal data, and 40% say they would willingly share their personal data if they knew exactly who would use it and how it would be used. Right now, only 53% of business leaders say their company shows how such data will be used.

“Businesses should consider how leveraging data discovery and governance tools, as well as exploring the implications of new use cases powered by emerging tech like machine learning and AI, can enhance data protection and build consumer trust,” says Martin Sokalski, KPMG U.S. Emerging Technology and Digital Solutions leader. “These technologies can help organizations build greater visibility into their data practices, from better data tracking to helping ensure integrity and fairness throughout the life cycle.”

Challenges and Applications of Digital Forensics

digital forensics, cyber forensics, forensics, digital identity

Crimes committed within the electronic or digital domains, particularly within cyberspace, have become general. They use technology as a footprint, commit offenses, and create new blueprints for law enforcement, attorneys and security professionals, and the legal departments. Digital Forensics has become an essential instrument in identifying and solving computer-based and assisted crime.

By Priyanka S. Joshi, CISO – Risk and Control Specialist and Technical Advisory, UBS

The digital age has undoubtedly revolutionized the life and work of many. On the flip side, the alarming rise in cybercrimes has become a major concern for cyber specialists as the continuous changes in the digital world attract more cybercrime. And experts use Digital Forensics to check this crime. Digital Forensics is the procedure of investigating computer crimes in the cyber world. The forensics process involves collecting, preserving, analyzing, and presenting evidence from digital sources.

Digital forensics experts have devised scientifically proven methods for identifying, collecting, preserving, validating, analyzing, interpreting, and presenting digital evidence derived from digital sources to facilitate the reconstruction of events that led to a breach.

Let’s discuss the major challenges of the digital world:

Technical Challenges: Encryption, data hiding in the storage space, covert channels are the major technical challenges today. Digital forensics experts use forensic tools for collecting shreds of evidence against criminals. And criminals themselves use such tools for hiding, altering, or removing the traces of their crime; this process is known as anti-forensic techniques. Another common challenge is operating in the cloud, time to archive the data, skill gap, and steganography.

Legal Challenges: There is an absence of guidelines and standards, and limitations of the Indian Evidence Act 1872. For instance, consider the case of dealing with the admissibility of an intercepted telephone call in a CDR (call data record). This was done without a certificate under Section 65B of the Indian Evidence Act, 1872. The court observed that the secondary electronic evidence without a certificate under Section 65B of the Indian Evidence Act, 1872 is not admissible and cannot be investigated by the court for any purpose whatsoever.

In most cases, the cyber police force lacks the necessary information that qualifies, and the ability to identify the possible source of evidence is unavailable. Often, the electronic evidence challenges the court due to its integrity, where the absence of proper guidelines and the non-availability of appropriate explanations of the details and acquisition gets dismissed.

Other common challenges are:

  • Privacy issues
  • Admissibility in the courts
  • The preservation of electronic digital evidence
  • Analyzing a running computer

Resource Challenges: Change in technology, volume and replication can be found in the resources area (Indian Evidence Act 1872). Due to rapid changes in the technology, operating system, and application software and hardware, reading digital evidence from an older version to support a newer version is a growing challenge. The confidentiality, integrity, and availability of e-documents are easily manipulated. In this, the WAN and the internet support a vast hand, which can share the data beyond physical boundaries, and creates the difficulty of understanding the origin of the data…To read the full story, subscribe to CISO MAG.

This story first appeared in the June 2021 issue of CISO MAG.


About the Author

Priyanka Joshi Priyanka Joshi is a Risk and Control Specialist/Technical Advisory at UBS. As an infosec professional, she believes knowledge and experience are pathfinders to success. Joshi also believes in maintaining the company’s legal and ethical integrity. Before joining UBS, Joshi was a Compliance Manager at a small firm for a health care company based in the U.S., where she was responsible for the HIPAA security enforcement on the business software and people working for it.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.