Blogs

AUSCERT at the 2020 FIRST Conference: virtual edition

25 Nov 2020

AUSCERT at the 2020 FIRST Conference: virtual edition We’ve all heard the story – 2020 has been a year marked with exceptional challenges and without a doubt, one of the most affected sectors from the Covid-19 pandemic has been the events and conferences industry. With travel restrictions in place for the foreseeable future, conference organisers have had to be creative in the delivery of their events.  In my role at AUSCERT, this meant having to pivot our very own annual conference into an entirely virtual format. I’ve posted my personal thoughts on working behind the scenes in delivering (a successful) AUSCERT2020 conference via LinkedIn here. Despite the challenges faced, the learnings I have taken away from this experience; coupled with my witnessing of our delegates, speakers and colleagues who all rose to the occasion in the spirit of camaraderie and innovation – will be something I’ll never forget or take for granted again in my career!  That aside, I had the pleasure of being on the “flipside” recently and was fortunate enough to participate as a delegate at the 2020 FIRST Conference: virtual edition. FIRST is the Forum of Incident Response and Security Teams and it brings together a wide variety of security and incident response teams including especially product security teams from the government, commercial, and academic sectors. This is FIRST’ 32nd annual conference and the theme was “Where Defenders Share”, highly relevant to the work that we do at AUSCERT. I tuned into all the keynotes and really enjoyed how they’d each varied from each other!Keynote 1Tracking Targeted Digital Threats: A View from the Citizen Lab by Ron Deibert, Director of  Citizen Lab (Munk School of Global Affairs, University of Toronto) In his presentation, Ron presented some super interesting evidence-based info from the work done at Citizen Lab. Their projects shed light on some increasingly critical issues at the intersection of race, surveillance, free expression, privacy, and power. My personal key take-away from his presentation was this message ‘not all high-end spyware, whatever does the trick!’ – a reminder that some of the biggest security issues we face don’t necessarily stem from high-end technology.  Keynote 2 Project Zero’s Disclosure Philosophy by Ben Hawkes, Project Zero Team Lead at Google ‘Untangling the vulnerability disclosure debate’ – before tuning into Ben’s presentation, I was extremely intrigued by his one-line premise and the content certainly delivered! In his presentation, it was made clear that Google’s Project Zero was of the opinion that the best way to combat the exploitation of zero-day vulnerabilities is by predicting attackers’ movements. Ben also revealed that Google’s elite bug-hunting team is looking to build a “crystal ball” for forecasting miscreants’ behaviour based on expert forecasts from cybersecurity professionals. His keynote was also covered by the team from PortSwigger here. Keynote 3Transforming Security: Optimizing Five Trends to Enable Security for Businesses of all Sizes by Kathleen Moriarty, CTO at Center for Internet Security Last but certainly not least, I tuned into the final conference keynote by Kathleen Moriarty who was recently appointed CTO at the Center for Internet Security. The key message from her presentation was that, in order to combat cyber threats, including those that impact SMEs that are part of the supply chain – we need to rethink how information security is delivered and managed. For me personally, this presentation really tied in to the concept of “3-Ps” of comprehensive cybersecurity – products, policies and people, an important reminder to get the basics right within every organisation and one that I thought was great session to tune into for the management folks in our sector.  As most of us are aware, conferences are a great way to learn new skills and access the latest trends and insight in the sector. For me personally, being a delegate at FIRSTCON20 allowed me to achieve greater awareness and understanding of both existing (mature) and emergent technologies – especially from the perspective of someone who doesn’t possess a technical background in the sector.  I have been informed that the conference recordings will be moved to permanent FIRST hosting and will be made publicly available via their website and YouTube channel shortly. Congratulations team FIRST, 1600 registrations from nearly 100 countries – that was an incredible feat, job extremely well done in 2020!Laura Jiew AUSCERT Events and Marketing Communications Specialist 

Learn more

Blogs

AUSCERT case study: an insight into our Incident Management service

5 Nov 2020

AUSCERT case study: an insight into our Incident Management service November 2020  AUSCERT case study: an insight into our Incident Management service Featuring Sean McIntyre, AUSCERT Senior Info Security AnalystYou recently assisted a client who came to us via Chris Gatford, a long-time AUSCERT supporter and contributor to our annual conference. Can you tell us a little bit more about the incident and what service category/categories did this fall under? Sure thing! A few weeks ago AUSCERT was called upon to assist Chris with a cyber security incident he was dealing with on behalf of a client. We won’t be able to disclose too many specific details out of respect for the client; but basically, the incident  involved a new threat actor that has popped up – Egregor (we recently shared an article about this on our ADIR) – a Sekhmet ransomware spin-off, also linked to the Maze threat actor group. We started off without knowing too much information on this particular ransomware nor its threat vectors; but with some research and a thorough scan of our various OSINT resources, I was able to find samples of the malware and some IOCs proved useful in assisting this client.  Another channel we tapped into was our connection with the various CERTs around the world. In particular, the APAC region – thanks to our international liaison expert, Geoff Thonon, who is also our Operations Manager here at AUSCERT.  Quite a few Egregor malicious URLs were discovered over this period of investigation and Chris had also provided a few more to be taken down. These requests were sent off to a number of  hosting and domain providers as per our routine Phishing Take-Down service procedure. And last but not least, we added these URLs to our Malicious URL Feed and IOCs to our MISP instance as a way of sharing the details with (i.e. protecting) our members.  I would say that this particular request falls under our Incident Management (although on the “lighter” side of a scale), Phishing Take-Down and Malicious URL Feed service categories.  Between receiving this request and to the time that the incident was resolved, can you outline the time it took our incident response team to resolve the issue? What do you think sets AUSCERT apart from a service delivery point of view? From AUSCERT’s perspective, we always initiate action on any request that comes through as soon as possible and definitely within a 24-hour period. In this instance, our expertise was sought after in regards to this new ransomware/threat actor. We were able to provide Chris with some of this threat intelligence and information over a couple business days of research work. Take-down requests for the initial URLs that were provided to us by Chris were submitted instantaneously, with follow-ups done whenever additional URLs were submitted on behalf of his client.   Even though these take-down requests were actioned promptly on our end, it’s important to note that we were reliant on the hosting providers to action them. Thankfully, most of the URLs seemed to stop functioning/existing within 1 business day or so after the request(s) was/were submitted.  I think what sets AUSCERT apart is our reach and connection with the CERT community, and also the fact that our member incident hotline is open 24/7. There’s a saying here at AUSCERT, “We exist for the greater good” – and we really try and showcase this with our members. Sean, what do you think are the 3 key takeaways from this incident, what can members or clients do to avoid something similar happening to them in the future?  Review your operating system (OS) compliance. It is super important to make sure unmaintained OSs such as Windows XP are taken off the network where possible. If an outdated OS is supplied by a vendor on a core system/endpoint – please work with them to upgrade all products. This is a super simple yet most effective way to avoid such incidents from happening within your SME. Ingest IOCs of known malware into firewalls/SIEM. These can be found via various OSINT sources or via a trusted partner such as AUSCERT. If you’re a member, utilise our 24/7 Incident Hotline or email us at auscert@auscert.org.au. Where possible, implement the “Essential 8” as outlined by the ACSC. This protocol provides a baseline for cyber security incident mitigation. Implementing these strategies as a minimum makes it much harder for adversaries to compromise systems.

Learn more

Blogs

AUSCERT2020 interview with Chris Gatford

5 Nov 2020

AUSCERT2020 interview with Chris Gatford AUSCERT2020 Conference Interview: Chris Gatford from Hacktive.io Leading up to the AUSCERT2020 conference, we sat down with Chris Gatford from Hacktive.io about his involvement in the conference and the recent work he has done for the SBS. Tell us about your professional career? I was the type of kid that would take my toys apart and put them back together with less parts, and then terrorise my sister. Looking back, I would like to think that this was the start of my hacking passion. I think it’s important to remember that hacking is not just about breaking into computer systems. It’s a way of thinking, and a method for approaching problems such as out-of-the-box thinking and solving problems by doing things differently. I was introduced to the IT industry as a child and after creating my own computer out of a cardboard box and motherboard, I soon realised I had a knack for this. After school, I completed a business computing degree and became a system administrator. I was responsible for looking after computer networks and had to draw on out-of-the-box thinking whenever an issue arose. During this role, my interest in security began to grow. After several years, I eventually jumped into The Big Four and got involved in IT consulting and testing computer security. You are the founder and Director of Hacktive.io, what does your company do? Hacktive.io is actually my second business. My first business venture was founded in 2008 and I sold it soon after. I learnt a lot from this experience and started my second business Hacktive.io. At Hacktive.io, we engage with organisations across the world and test their physical security and computer/network security. We focus on helping our clients understand the security vulnerabilities of their networks, applications, premises, and their people. Can you expand further on social engineering tests and how these tests are completed?  Often a customer will approach Hacktive.io and request that their company’s environment (a building or third party site) get tested. Firstly, we obviously get permission from the company. Then we will conduct the social engineering tests on the physical environment, the people/employees of the company, and their IT department. Following the social engineering test, we teach the company how they can better defend themselves against hackers. More so now, than ever before, individuals and employees are getting targeted by hackers. We equip businesses with common and useful tools that are available to everyone. What made you want to be a part of the AUSCERT2020 Conference? I have been a long believer and supporter of AUSCERT, and have attended every conference since 2003. The fact that it’s the oldest IT security conference, and it’s still going strong after all these years, is a huge testament to the company. To be among so many professionals who share information on staying secure is a huge honour. Can you tell us more about the tutorial you ran at the conference?  My tutorial was on “How to build a security awareness training program” and demonstrated how Hacktive had infiltrated and extracted sensitive information from organisations, and the mechanics involved in an attack. I discussed how to reverse the process and understand the mechanisms involved in breaking into the organisation. I am also a strong believer in computer-based training, while also reflecting on how to excite and energise a workforce to be interested in computer security again. You were recently interviewed on SBS, can you tell us more about this?  I was very lucky to have the SBS team alongside a Red Teaming Pen Test. SBS was able to capture the reasons behind our testing and record us walking away with a company’s equipment. We were able to show how easy it was to use a company’s own devices to hack back into their network.  What do you see as some of the biggest cyber threats in today’s society? The first cyber threat that comes to mind is that information security is hard, and breaking into systems can be a very easy job. However, it is really difficult to build systems, maintain them and in the long-term keep them secure. So it’s critical to have the right tools in place to monitor security, because ultimately ransomware is still an effective attacker. The second cyber threat that comes to mind is invoice fraud. I often hear instances of ‘customers’ pretending to change their bank account details and then the invoices are getting paid out to the wrong bank account. The financial fraud impact on business is massive and businesses must recognise that fraud is still alive and well.  

Learn more

Blogs

AUSCERT2020 MC: Adam Spencer

26 Oct 2020

AUSCERT2020 MC: Adam Spencer Prior to the AUSCERT2020 Conference, we caught up with Adam Spencer to chat about his involvement with the conference, and hear his thoughts around cyber security and observations on the year of 2020.   Can you start by telling us about your professional career? I could say lawyer and mathematician, although neither of those career paths really worked out. I am probably better to lead with stand-up comedian, from where I then stumbled into the world of radio and television where I continue to be thoroughly unprofessional. I have also written and co-written approximately ten different books trying to popularise mathematics. These are written for people who do really get mathematics and have a talent for it and want to get better at it. When writing, I’ve had the pleasure of reaching out to smart, switched on nerdy kids from about the age 12 and above—and I absolutely love it.   You are a self-confessed lifelong number nerd. What is your favourite number? As a kid, my favourite number was four. This was the first number that realised you could break into two even groups. For example, you couldn’t break down five or seven, but you could break down nine into three groups of three. It was from here that I started to get the concept of prime numbers and composite numbers just from breaking down the number four. I have now been fascinated by multiples of four for the rest of my life. For example, if we were to go for a drive and you turned the volume up to 31, I would need to change it to 32 so it could be a multiple of four.   How do numbers and maths play a role in cyber security? The basis of all computing and code of any sort is beautifully mathematical. I was lucky enough to interview Steve Wozniak who wrote the original Apple Source Code, back when it was just ones and zeros. Now, I’m not a specialist in that field, but from what I understand, no one has ever found a single error in Wozniak’s original programming and coding. Which is beyond belief for something as complicated as that not to have mistypes. The genius that underpins a system like that is incredible. Furthermore, the basis of the systems that we use to exchange credit card details online and not being hacked by a third party through the RSA algorithm, is just beautifully mathematical. Cyber security is a great example of how maths is still relevant. Mathematics permeates everything and we are just blissfully unaware.   You have been part of the AUSCERT conference for a few years now. What is it that first prompted you to be a part of it? The thing that I enjoy about my line of work as a professional MC and facilitator is that I’m rarely the smartest guy in the room on any given topic. But to learn anything, you need to expose yourself to the absolute best people in those fields. I’m a strong believer that if you speak to those passionate and informed about something, almost any topic can be interesting. For almost a decade I have been able to surround myself with people who are the best in the business (of Cyber Security) and hear about what’s on their mind about the cutting edge trends is incredible.  I remember first hearing mutterings about ransomware in the AUSCERT community years ago, and now it’s something that people have to deal with all the time. I feel like I am in the presence of people who really understand cyber security and having discussions that are ahead of the general population, is just so exciting.   Tell me about your most recent book, Numberland. I filled it with a bunch of stuff that blew my mind at the time. Looking back at it, I think I can best describe it as a compilation of stuff that I hope intrigues the ‘number curious’ amongst us. For AUSCERT members who are interested in my book, they can use the promo code ‘HOME’ to receive 20% off. Visit adamspencer.com.au to grab a signed copy.   Do you have any advice for someone who is passionate about maths or cyber security? Mathematicians will build this century—this is the century that will be built on ones and zeros. I think of many cyber security experts as mathematicians. So, for people with a passion in the area of cyber security, coding, app design, software, or statistics will have a role to play in building our future. It has never made more sense to find your passion in mathematics or cyber security, and take whatever skillset you have and maximise it. For young people coming out of high school and into the job market, my advice would be, if you can show that you have experience and knowledge in Mathematics, you’ll end up writing your own cheques in the workplace. There is no denying that mathematical thinking is going to underpin and build this century.      

Learn more

Blogs

AUSCERT2020 Member Organisation of the Year Winner

15 Oct 2020

AUSCERT2020 Member Organisation of the Year Winner AUSCERT2020 Interview: Leigh Vincent from Federation University Australia We recently had the pleasure of chatting with Leigh Vincent from Federation University Australia who won the AUSCERT Member Organisation of the Year for 2020. Leigh opened up about what it is like to be an AUSCERT member and how Federation University is dealing with new cyber security issues. Can you start by telling us about your professional career? I have been at Federation University Australia (formally known as the University of Ballarat) for about 16 years in a cyber security role. This role has developed over the years and last year, we officially doubled our team, so now there are two of us!  While working at Federation University, I have gone through extensive training in incident handling and response, web application, penetration testing, and digital forensics and analysis. Having been a one-person team for so long, I was often in the position where I needed to provide the resources and support to University staff myself. There have been many years where the University’s budget just did not have enough room to stretch when it came to security. During this time, we could not justify hiring support from outside organisations when I could upskill and undergo training myself. I’m sure many would agree that cyber security in the university sector is a very interesting beast to work with. This was actually my first role working in security as I had previously worked in a system network administrator role. Since moving into security, I’ve enjoyed almost every moment. How long has Federation University been an AUSCERT Member? Federation University has been a member for as long as I have worked there, so at least 16 years. Personally, I have attended several of AUSCERT’s conferences since 2004. The highlight is always having the opportunity to network and catch up with people over the conference period.  What value do you get out of the on-going AUSCERT membership? In my experience, I would say the advice that the AUSCERT team and other members provide is invaluable and having people there that you can bounce ideas off makes resolving an issue much easier. Back when I was a one-man-team, I went on long-service leave and AUSCERT acted as the primary point of contact for the University if issues popped up. So both at a personal and professional level, the AUSCERT membership has been very beneficial. Speaking of your membership… Congratulations on winning the Member Organisation Of The Year award! What does winning this award mean to you? It was a complete surprise! I had to read over the email a couple of times before I realised that we had won. Winning this award is not something we had thought about, we often just continue to go about our work every day, but the acknowledgement means a lot. Receiving that recognition, especially as a two-person cyber security team just shows that people really do take notice of you and how you contribute to the industry. If you had some advice for some other AUSCERT members, what would you say? The biggest piece of advice I could give would be get involved. Take the time to interact with AUSCERT and its members—it is a valuable industry tool. As the ‘good guys’ in cyber security, we need to work on communicating more. We know the ‘bad guys’ are great at communicating and that is why they are always one step ahead of us. Ultimately we are all fighting the same fight so use the tools provided by AUSCERT (such as the Slack channels) to get involved, communicate and most of all keep an ear to the ground. Have you had any cyber security challenges this year, and how have you addressed this? Money has certainly been the biggest challenge, there is no denying that the education sector has taken a huge financial hit recently. We have also had to alter our focus to keeping tabs on all the remote workers and moving the University’s systems online very quickly. By making these quick changes, we have had to reassess some of our security restrictions to ensure a smooth and easy transition to working online for staff and students. Our focus has had to be on delivering quickly and trying to keep everyone safe when they are not inside our walls anymore. We control less when people are working from home, so we have had to encourage people to ask questions relating to their home security and support them where possible. Because we have made the switch to online for all course material, the push is now that we should keep it all online and maintain those platforms. However the challenge is ensuring that security can be enhanced and maintained to meet what will become a permanent method of content delivery to students and capabilities for staff to work from home as required going forward. Alternatively, we could also create something parallel that is safe and secured correctly, not just a platform that can ‘make it work’. What do you see as some of the main cyber threats in today’s society and their accompanying risks? Personally, I see social engineering as one of the biggest risks in cyber security today. It is a very real issue and we see it constantly. However, we can only overcome it by increasing user awareness and education—without this it can be very difficult to fight. Until we can get on top of that and educate users to make decisions themselves, it will inevitably remain a problem.  What is some advice you would give to organisations and other IT cyber security professionals? Talk and share with one another. We are all fighting the same fight and facing the same challenges. We might be from different organisations and have different technology, but ultimately, we are all fighting the same enemy.

Learn more

Blogs

AUSCERT2020 Information Security Excellence Winner

13 Oct 2020

AUSCERT2020 Information Security Excellence Winner Congratulations to Michelle Price for being given the AUSCERT2020 “Information Security Excellence” award. During AUSCERT2020 we had a chat with her to learn more about her role as CEO at AustCyber, and her vision for the cyber security industry.   Tell us a little about your professional career? My first job was working in a small business that my family owned, that focused on food safety consulting and training. We also ran international conferences and created a lot of thought-leadership on the topic of food safety. Food safety in the mid-to-late 90s was an emerging issue in Australia; there were no standard practices. In the end, there were three companies (owned by my parents) that focused on risk, and the upside and downside of risk. I worked there for 10 years, starting in marketing and communications roles, and ending up doing food safety audits and strategy. I then moved into the advertising industry for a short stint, before moving into the federal government, with the majority of my time in National Security. The common thing across all the agencies I worked in at the government was risk and strategy. What was your role in the Prime Minister’s Department? When I was working in the Prime Minister’s Department, my first job was to work across all of national security, and I ended up running the National Security Budget and developing the world’s first national security strategic risk framework, and developing a framework of how to prioritise national security issues. That was under the Gillard government. Then when Prime Minister Abbot came in, I switched roles and moved across from high-level strategy on national security to focus on the cyber security area, and that’s how I ended up penning the 2016 National Cyber Security Strategy. How did you end up at AustCyber? After the strategy was launched, I was fortunate enough to have quite a few opportunities. I chose to focus on helping the Australian National University stand up a cyber policy function and to be able to better coordinate the growing area of cyber research across different disciplines. I didn’t stay there for as long as I thought I would, because I then got asked to come to AustCyber, and AustCyber was one of the initiatives in the Cyber Security Strategy that I had worked very hard on, so it was a no-brainer. Being born into a house of entrepreneurs it felt like a natural extension for me to end up running an organisation that is trail blazing around how to do the business of cyber security, and while we are doing that, is also creating an industry. That is the mission of AustCyber: To create an industry that is globally competitive and has impact for the country. Congratulations on winning the Information Security Excellent award. What does winning this award mean to you? Every time I think about it, I still get tingles. Partly because, cyber security is often a closed environment, but that is changing a lot. So, when someone like me turns up and writes a national strategy on something that I don’t have years of experience in, who am I to advocate for, and educate the country on a topic that is not natively my own. To have a community like the AUSCERT community that is dominated by traditional security leaders, that is composed of technical practitioners, to have someone like me recognised by them, and by AUSCERT, is so special to me. That’s why in my acceptance speech, I accepted it for the whole industry. We’ve started to mature, to grow up, and have so much to offer, and people outside of our industry have so much to offer as well. We are the enablers of the entire economy. To me this is an example of how our industry is shifting and changing for the better.   If you could give a piece of advice for organisations and security professionals, what would it be? Understanding other people’s context helps us work together. ‘Collaboration’ is a bit of an overused word, but it’s the right word, if we come together and work together to a common outcome. ‘Outcome’ is also an important word—it’s not just about outputs. If we continue to focus on outputs, we will never win the battle. Output is important, but to be able to achieve outcomes, we have to work together, and to work together, we need to understand contexts.  If we take a few moments in the day to understand who we are working with and what their context is helps us have a more open mind. We spend too much time focusing on the battle with each other, rather than coming together to focus on battling with our adversaries. They’re the ones who are ripping off the economy. They’re the ones who are affecting the physical and emotional lives of Australians. We all want the same outcome, and we can do better at collaborating. I know we can do this. #GAMEON  

Learn more

Blogs

AUSCERT at the 2020 ASEAN CERT Incident Drill

9 Oct 2020

AUSCERT at the 2020 ASEAN CERT Incident Drill AUSCERT is proud to have been involved in this drill earlier this week, alongside colleagues in the ASEAN and various neighbouring regions. Thank you to colleagues from the Cyber Security Agency of Singapore (CSA) for organising. The theme was especially pertinent this year – “Malware Campaign Leveraging the Pandemic Situation” – and we look forward to further collaborations with the wider group in the future. +++++ 15th iteration of ASEAN CERT Incident Drill tests CERTs’ preparedness against opportunistic COVID-19-related campaigns The Cyber Security Agency of Singapore (CSA) organised the 15th iteration of the ASEAN Computer Emergency Response Team (CERT) Incident Drill (ACID) on 7 October 2020. This was held in conjunction with the fifth Singapore International Cyber Week (SICW), the region’s most established annual cybersecurity event. An annual drill hosted by Singapore since 2006, ACID tests incident response procedures and strengthens cybersecurity preparedness and cooperation among CERTs in ASEAN Member States (AMS) and Dialogue Partners. This year’s theme, “Malware Campaign Leveraging the Pandemic Situation”, was chosen in view of the proliferation of malicious campaigns leveraging the ongoing COVID-19 pandemic as lures across multiple sectors, in many countries in the earlier part of the year. During a brief pre-drill dialogue, the participants also agreed that it was an opportune time to raise awareness and preparedness against opportunistic campaigns. The scenario injects are based on the Emotet malware campaign, given its prevalence, and the range of cybersecurity events that may occur following a successful Emotet malware infection. All the CERTs from the 10 AMS and five key Dialogue Partners from Australia, China, India, Japan, and South Korea, were represented in this year’s ACID. They were required to investigate, analyse, and recommend remediation and mitigation measures to a series of scenarios injects with varying levels of complexity. The drill this year was well-received and the participating CERTs provided positive feedback. Leading the exercise is Ms Goh Yan Kim, Deputy Director, SingCERT, CSA. Ms Goh said, “With the pandemic resulting in a heavier reliance on the internet, cybersecurity is now more important than ever. These exercises are essential to foster trust and preparedness among CERTs in ASEAN and our Dialogue Partners to respond to current and emerging threats. We look forward to conducting more of these exercises in future.” A copy of the original article can be found here: https://www.csa.gov.sg/news/news-articles/15th-asean-cert-incident-drill

Learn more

Blogs

AUSCERT at the forefront of Cybersecurity and AUSCERT2020 "We Can be Heroes"

7 Sep 2020

AUSCERT at the forefront of Cybersecurity and AUSCERT2020 "We Can be Heroes" [Editor’s notes: an edited version of this article features in the CyberAustralia Magazine 2020-2021] AUSCERT provides members with proactive and reactive advice and solutions to current threats and vulnerabilities. We help members prevent, detect, respond and mitigate cyber-based attacks. As a not-for-profit security group based at The University of Queensland Australia, AUSCERT delivers 24/7 service to members alongside a range of comprehensive tools to strengthen their cyber security strategy. The Australian Government Department of Home Affairs released their report on Australia’s 2020 Cyber Security Strategy recently and AUSCERT is very proud to have been involved in the consultation process late last year. The report included 60 recommendations to bolster Australia’s critical cyber defenses which are structured around a framework with five key pillars: Deterrence, Prevention, Detection, Resilience and Investment – all aligned to our core values here at AUSCERT: Deterrence: Any infrastructure reported by our members that proves to be malicious will be subject to persistent and escalating takedown notices. Prevention: The initiative of providing Indicators of Compromise, Indicators of Vulnerability, security advisories and bulletins provides strong proactive preventative information.    Detection: Bi-directional threat intelligence gathering through open source platforms where members are given real-time intel that help to automatically detect and block potential attacks. Resilience: AUSCERT partakes and assists to organise Asia Pacific regional cyber drills, as well as provide webinars to members to maintain cyber security awareness as front-of-mind. Investment: AUSCERT being a non-profit organisation reinvests all of our membership proceeds into service deliveries, improvements and the building of our membership cyber security capabilities.   Clear benefits for members AUSCERT leverages the resources provided by its membership base and The University of Queensland Australia. Our reach with international CERTS as well as other Australian organisations, increases the effectiveness of our action for malicious infrastructure take-downs, abuse advisory and this international co-operation enables an internationally recognised norm of incident response. With a 24/7 member incident hotline, AUSCERT enables our members to keep their incident response effective by providing assistance that complements existing capabilities. Cyber risks are owned by those best positioned to manage them Assistance in establishing risk assessment as well as an incident response plan are covered through AUSCERT education where an understanding of these concepts allows for efficient use of resources in preventing, mitigating the transfer of or avoiding cyber risks. AUSCERT members practice cyber security at home and at work With the increase in remote-working, AUSCERT assists our members no matter the physical location of their work setting may be. AUSCERT is a cyber security incident response team exemplar AUSCERT takes incident response seriously and trains its staff body to be able to handle incidents whenever they arise. This is done not only through internal training; all staff are also encouraged to attain industry certification(s) in line with their job requirement. This experience is then reinvested back to members in the form of advice publication, blog article(s) and educational events such as webinar sessions. Additionally, Indications of Vulnerabilities and Indications of Compromises are streamed to members on a daily basis, thus keeping our members aware of vulnerabilities, leaked credentials, misconfigurations as well as the availability of remedial advice. Trusted services, nationally and internationally AUSCERT as a trusted entity in cyber security is handed information on incidents and vulnerabilities from national and international sources.  AUSCERT2020 “We Can Be Heroes”  AUSCERT2019 “It’s Dangerous to Go Alone” gave delegates the tools to build knowledge within their teams. This year, the emphasis lies on the fact that anyone in your organisation can be your champion, your cyber security hero. Not only is it vital that you have a strong team behind you, but it is also equally important that you equip and encourage every individual in your organisation to assist in cyber and data security.  AUSCERT2020 will be held across 4-days; packed with world-class tutorials and presentations delivered by over 60 speakers from around the globe. With an audience of around 1000 delegates, this year’s confererence will be the largest held in recent years.  We’re especially proud to feature a number of AUSCERT content and speakers, namely – Colby Prior and his tutorial on the topic of “Running your own honeypot: An Introduction”, Mike Holm and his co-presentation with Leon Fouche from BDO on the topic of the “Joint AUSCERT and BDO Annual Cyber Security Survey Report 2019” and last but not least, Geoff Thonon on the topic of “Could Phishing be nastier by any other name?”. In addition to these AUSCERT presentations, UQ will also be represented by Mandy Turner from the SOC team, speaking on the topic of “Cybercrime” and the team from UQ Cyber from the EAIT Faculty will also be hosting a virtual booth at the conference.  The format of the conference delivery may be different this year, but AUSCERT is as committed as ever to providing you with meaningful and rich content – all from the comfort of your office or home environment. “Cyber security has never been more important”. The cyber security landscape is ever-changing, and AUSCERT is passionate about engaging with members to empower their people, capabilities and capacities. For more information on AUSCERT, please contact membership@auscert.org.au or +61 7 3365 4417. For further information on the AUSCERT2020 conference, please contact conference@auscert.org.au.     

Learn more

Blogs

AUSCERT investigating a data dump claimed to be from the Department of Education

3 Sep 2020

AUSCERT investigating a data dump claimed to be from the Department of Education 3:40pm 03/09/20 AEST Updated below to clarify that first and last name are also included in the data. This doesn’t change our assessment. Unless further developments occur, we believe no further research is required. Please notify us if you find that your staff or students have used the service and you have concerns.   4:30pm 02/09/20 AEST Working with Cosive, we’ve found signs that this is a re-publish of a dataset published in March 2020 or earlier, relating to a service called “K7 Maths”. The TLS on their site also correlates with what seems to be their Australian presence. It’s likely that the data came from an exposed Elasticsearch instance. There are no plaintext passwords exposed, just bcrypt hashes, although they can be cracked with enough effort. Members concerned that their staff may have used this tool and may be included in the full dump should, where possible: Check with teaching and admin staff for usage of the service. Check mailboxes for sign-up emails from schoolcentre.com.au, k7maths.com or schoolcentre.com before that date. If usage is found, we recommend: Consider that that credential may be compromised, and anywhere the password was re-used, may now be exploited. A password reset for internal services is usually worthwhile, but consider your environment before applying this advice. Monitor staff accounts for suspicious logins – email, VPN, etc. This can lead to business email compromise (BEC), unauthorised access to the network, malware being sent between users, and more. Notify AUSCERT. There’s a mitigating factor: the password hashes use the standard bcrypt algorithm, with a “cost factor” of ten rather than eight, which makes it four times harder than usual to crack. We think that the only personal information in the dump is email address and country (edit: as well as first and last name) which would likely not count as a notifiable data breach. Our investigation there is incomplete. Consult your usual legal team if you have concerns.   4:00pm 02/09/20 AEST We have a suspected source for the data, which is not a government agency. More information to follow.   9:50am 02/09/20 AEST The dump refers to “the Australian Department of Education (edu.au)”, and no such organisation exists. We’ve reached out to likely candidates for comment.   9:15am 02/09/20 AEST We’ve seen reports that an Australian educated-related data set of unknown origin has been published. We’re looking into it now and will update this post as we get more information. We’ll also be posting updates on Twitter and LinkedIn. The claim is that it’s from the Australian Department of Education, and was retrieved in 2019. The claimed fields are: country_id created_at email encrypted_password (may be a bcrypt hash?) first_name id is_admin is_guest last_mail_at last_name last_sign_in_at newsletter region_id tags subscription orders  

Learn more

Blogs

AUSCERT mailout: ProctorU breach

6 Aug 2020

AUSCERT mailout: ProctorU breach An apparent data breach of the ProctorU service, apparently published by a user named ShinyHunters, has been making news in the last week, including an article yesterday in the Sydney Morning Herald. AUSCERT has acquired a copy of the data and notified affected members. ProctorU gave us the following comment: On Monday July 27, 2020, we were made aware that some information purporting to come from ProctorU.com was posted to an internet message board. Although we are still investigating, none of the data analyzed so far from that posted data was from our active production servers and all of it was at least five years old. Therefore, we currently have no reason to believe that our active production servers or data of current clients and students from the last five years was implicated. We are continuing to investigate and will update you should that understanding change or with any additional information pertinent to you. How bad is it? You will need to assess it in the context of your own organisation. It appears that none of the data is newer than 2016. It includes personal information of ProctorU users, as well as institutional email addresses, and password digests. We’re not sure of the severity of the password digests – digests can be very easy or very difficult to crack depending what they incorporate. There are reports that they are bcrypt hashes.   Was my organisation affected? It affects mainly educational institutions who used ProctorU prior to approximately Q3 of 2016. We’ve notified affected members through their normal incident email alias. An administrator for your organisation can check in the member portal what that’s set to; if it’s current, and you haven’t heard from us, then you’re clear. Not all our educational members are affected.   I’ve received a file and don’t know how to decrypt it Please log in to the member portal and consult this page for the passphrase. You’ll need a program like Kleopatra for Windows or GPG for Linux/Mac. If using the command-line, enter this and type the passphrase: gpg --output your-domain.tsv --decrypt your-domain.tsv.gpg   I’m encountering a GPG error when decrypting the file GPG has some quirks. Please check the directory containing the encrypted file to see whether the decrypted file was created despite the error message. If it’s not there, please double-check the passphrase, and if that doesn’t work, reach out to us at auscert@auscert.org.au and we’ll assist.   How do I view a TSV file? We suggest opening it in Excel or another spreadsheet program, choosing “My file is delimited”, ensuring that it uses the “Tab” as a delimiter, and ensuring that columns are of type “general”. Excel will default to all of these. You’re also welcome to use a command-line utility to split on tab characters.

Learn more

Blogs

There's a hole in the boot

30 Jul 2020

There's a hole in the boot Introduction Responsible disclosure from Eclypsium has enabled the patches to the GRand Unified Boot Loader (GRUB) to be coordinated on the night of the 29th July 2020. Impact Modifications to the GRUB configuration file can result in the the execution of arbitrary code which can also allow UEFI Secure Boot restrictions to be bypassed.  Subsequently it is then possible to load further arbitrary executable code as well as drivers. To be able to exploit this vulnerability you first must have administrator or physical access to the target machine.  System affected The vulnerability affects Microsoft as well as Linux based distributions as it affect UEFI Secure Boot DBX, along with GRUB2. A non-exhaustive list of operating systems affected has been compiled by Eclypsium being: Microsoft UEFI Security Response Team (USRT) Oracle Red Hat (Fedora and RHEL) Canonical (Ubuntu) SuSE (SLES and openSUSE) Debian Citrix VMware Various OEMs … and others … Mitigation It is recommended that an organisation undertakes their own risk assessment, addressing the severity of the impact of administrative/root control with the need for the attacker to already have administrator or physical access to the target.  Microsoft notes that it is possible to detect this vulnerability using either Key Attestation or Defender ATP Eclypsium has outlined steps to mitigate this vulnerability as follows: Updates to GRUB2 to address the vulnerability. Linux distributions and other vendors using GRUB2 will need to update their installers, bootloaders, and shims. New shims will need to be signed by the Microsoft 3rd Party UEFI CA. Administrators of affected devices will need to update installed versions of operating systems in the field as well as installer images, including disaster recovery media. Eventually the UEFI revocation list (dbx) needs to be updated in the firmware of each affected system to prevent running this vulnerable code during boot. Advisories AUSCERT has issued out an AUSCERT Security Bulletins (ASB) [ASB-2020.135] and will be issuing out External Security Bulletins (ESB) as they come to hand. Below are excerpts of the Product Security Incident Response Teams (PSIRT) advisory that describe in brief the Impact and vectors of these vulnerabilities. Microsoft Tag Description ADV200011 To exploit this vulnerability, an attacker would need to have administrative privileges or physical access on a system where Secure Boot is configured to trust the Microsoft Unified Extensible Firmware Interface (UEFI) Certificate Authority (CA). The attacker could install an affected GRUB and run arbitrary boot code on the target device. After successfully exploiting this vulnerability, the attacker could disable further code integrity checks thereby allowing arbitrary executables and drivers to be loaded onto the target device.   Linux Distribution Tag Description CVE-2020-10713 Crafted grub.cfg file can lead to arbitrary code execution during boot process CVE-2020-14308 grub_malloc does not validate allocation size allowing for arithmetic overflow and subsequent heap-based buffer overflow.6.4 (Medium) / CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2020-14309 Integer overflow in grub_squash_read_symlink may lead to heap based overflow.5.7 (Medium) / CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H CVE-2020-14310 Integer overflow in read_section_from_string may lead to heap based overflow.5.7 (Medium) / CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H CVE-2020-14311 Integer overflow in grub_ext2_read_link leads to heap based buffer overflow.5.7 (Medium) / CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H CVE-2020-15705 Failure to validate kernel signature when booted without shim6.4 (Medium) /CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2020-15706 Use-after-free in grub_script_function_create6.4 (Medium) /CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2020-15707 Integer overflows in efilinux grub_cmd_initrd and grub_initrd_init leads to heap based buffer overflow5.7 (Medium) /CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H   Sources Media reports Forbes : https://www.forbes.com/sites/daveywinder/2020/07/29/boothole-secure-boot-threat-confirmed-in-most-every-linux-distro-windows-8-and-10-microsoft-ubuntu-redhat-suse-debian-citrix-oracle-vmware/#2537b652666e ZDNet : https://www.zdnet.com/article/boothole-attack-impacts-windows-and-linux-systems-using-grub2-and-secure-boot/ Threatpost : https://threatpost.com/billions-of-devices-impacted-secure-boot-bypass/157843/ Further information Key Attestation : https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/component-updates/tpm-key-attestation Defender ATP: https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection UEFI Forum: https://uefi.org/revocationlistfile Canonical : https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass PSIRT Information Microsoft: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011 Canonical: https://ubuntu.com/security/notices/USN-4432-1 Debian: https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot HPE: www.hpe.com/info/security-alerts Red Hat: https://access.redhat.com/security/vulnerabilities/grub2bootloader SUSE: https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/ VMware: https://kb.vmware.com/s/article/80181  

Learn more