English

Hello 

Create Profile

Creating your profile will enable you to submit photos and stories to get published on News24.


Please provide a username for your profile page:

This username must be unique, cannot be edited and will be used in the URL to your profile page across the entire 24.com network.

Settings

Location Settings

News24 allows you to edit the display of certain components based on a location. If you wish to personalise the page based on your preferences, please select a location for each component and click "Submit" in order for the changes to take affect.









Facebook Sign-In

Hi News addict,

Join the News24 Community to be involved in breaking the news.

Log in with Facebook to comment and personalise news, weather and listings.

 
 

Hack shows zero day danger

2010-01-29 13:27
line

kalahari.com

San Francisco - The recent hacking attack that prompted Google's threat to leave China is underscoring the heightened dangers of previously undisclosed computer security flaws - and renewing debate over buying and selling information about them in the black market.

Because no fix was available, the linchpin in the attack was one of the worst kinds of security holes. Criminals treasure these types of "zero day" security vulnerabilities because they are the closest to a sure thing and virtually guarantee the success of a shrewdly crafted attack.

The attackers waltzed into victims' computers, like burglars with a key to the back door, by exploiting such a zero day vulnerability in Microsoft Corp's Internet Explorer browser. Microsoft rushed out a fix after learning of the attack.

How did the perpetrators learn about the flaw? Likely, they merely had to tap a thriving underground market, where a hole "wide enough to drive a truck through" can command hundreds of thousands of dollars, said Ken Silva, chief technology officer of VeriSign Inc. Such flaws can take months of full-time hacking to find.

"Zero days are the safest for attackers to use, but they're also the hardest to find," Silva said. "If it's not a zero day, it's not valuable at all."

Valuable flaws

The Internet Explorer flaw used in the attack on Google Inc required tricking people into visiting a malicious website that installed harmful software on victims' computers.

The attack, along with a discovery that computer hackers had tricked human-rights activists into exposing their Google e-mail accounts to outsiders, infuriated Google and provoked a larger fight over China's censorship of the internet content.

Google has threatened to shut down its censored, Chinese-language search engine and possibly close its offices in China.

Pedram Amini, manager of the Zero Day Initiative at the security firm TippingPoint, estimated that the IE flaw could have fetched as much as $40 000. He said even more valuable zero day flaws are ones that can infect computers without any action on the users' part.

Zero days refer to security vulnerabilities caused by programming errors that haven't been "patched", or fixed, by the products' developers. Often those companies don't know the weaknesses exist and have had zero days to work on closing the holes.

In this case, Microsoft actually knew about the flaw since September but hadn't planned to fix it until February, as companies sometimes prioritise fixing other problems and wait on the ones they haven't seen it used in attacks.

Microsoft often fixes multiple vulnerabilities at once because testing patches individually is time-consuming and costly, said Chris Wysopal, co-founder of security company Veracode Inc.

Not difficult

But criminals know how the patch cycle works, and Wysopal said the Google attackers may have realised their zero day flaw was getting old - and thus struck in December just before they thought Microsoft was going to fix it.

"They likely thought the bug would be fixed in January or February," he said. "They were right."

Microsoft certainly could have fixed the bug earlier and prevented it from being used on Google, but security experts caution that an adversary that is well-funded or determined could have easily found another bug to use.

"Zero days aren't difficult to find," said Steve Santorelli, a former Microsoft security research who now works with Team Cymru, a non-profit research group. "You don't have to have a Ph D in computer science to find a zero day exploit. It really is a factor of the amount of energy and effort you're willing to put in."

In fact, such exploits are widely available for the right price.

VeriSign's iDefence Labs and 3Com Corp's TippingPoint division run programs that buy zero day vulnerabilities from researchers in the so-called "white market". They alert the affected companies without publicly disclosing the flaw and use the information to get a jump on rivals on building protections into their security products.

There's also another, highly secretive market for zero days: US and other government agencies, which vie with criminals to offer the most money for the best vulnerabilities to improve their military and intelligence capabilities and shore up their defences.

High price

TippingPoint's Amini said he has heard of governments offering as high as $1m for a single vulnerability - a price tag that private industry currently doesn't match.

Little is publicly known about such efforts, and the US government typically makes deals through contractors, Amini said. Several US government agencies contacted by The Associated Press did not respond to requests for comment.

One researcher who has been open about his experience is Charlie Miller, a former National Security Agency analyst who now works in the private sector with Independent Security Evaluators. Miller netted $50 000 from an unspecified US government contractor for a bug he found in a version of the Linux operating system.

Whether to pay - and seek payment - is hotly debated among researchers.

"I basically had to make a choice between doing something that would protect everybody and remodelling my kitchen - as terrible as that is, I made that choice, and it's hard," Miller said. "It's a lot of money for someone to turn down."

Loss of life

Companies whose products are vulnerable generally won't pay outside researchers for bugs they've found. Microsoft said offering payment "does not foster a community-based approach to protecting customers from cybercrime". The company declined further comment on its practices and the timing of the fix for the flaw used in the Google attack.

Computer vulnerabilities are so dangerous that one day private companies such as Microsoft might be pressured into buying from the black market to prove they're doing all they can to keep customers secure - especially the most critical ones such as the military and power companies.

"I think it's only a matter of time," said Jeremiah Grossman, founder of WhiteHat Security Inc. "Something really bad has to happen first, and it hasn't yet. When a virus runs through a children's hospital and causes loss of life, it's going to matter a lot."

- AP

Add your view to this conversation - comment below

Read more on:    cybercrime  |  technology

Read News24’s Comments Policy

Comment on this story
3 comments
Add your comment
Comment 0 characters remaining

inside news24

 

140
1
1 of 10

Latest comment in Sci-Tech

Blackpoison says... Sounds like aliens on Venus are trying to hide something from us earthlings.... Read the article...

 
Traffic
Lottery
 
  • Wednesday Ladysmith - 22:09 PM
    Road name: N11 Both Ways
    ROADWORK - two sets of stop / go controls just south of the R68 Dundee exit - expect waiting times of up to 20 minutes between Ladysmith and Newcastle (ends March 2013)
  • Saturday Pretoria - 08:07 AM
    Road name: N1 Both Ways
    ROADWORKS - lane closures on both carriageways for long term roadworks between the N4 Witbank Highway Interchange and the Zambesi Drive exit - EXPECT DELAYS (until Jan 2013)
 
More traffic reports...
 

Jobs [change area]

Cars[change area]

VOLKSWAGEN

CitiGolf 1.4i 5-dr MY04
2007
R 69,990.00

TOYOTA

Yaris 1.0 T1 5-dr AC
2006
R 95,995.00

TOYOTA

Condor 2400i Estate TX MPV MY03
2004
R 139,995.00

Property [change area]

Vulintaba Country Estate, Upper Drakensberg

A lifestyle estate beyond compare. Home Package Options From R990 000

HOUSES FOR SALE IN Still Bay

Houses R 2 350 000

Travel - Look, Book, Go!

Casa Rex, Vilanculos

Spend 5 nights in at the magical Mozambican resort of Casa Rex from R7983 per person sharing. Includes accommodation, return flights, taxes and transfers. Book now!

Kalahari.com - shop online today

Darksiders II

Something threatens earth and ironically it’s up the Horseman of Death to be the saviour of mankind. Buy now.

Hot new releases on DVD

Fresh off the cinema circuit and straight into your personal collection. Buy now

Cool music for Dad

Fishing, driving or relaxing, get the tunes that make up the soundtrack to suit Dads every mood. Buy now.

Great books to consider

Gripping titles and best sellers that will inspire the dormant reader within anyone to resurface. Buy now.

Helicopters

Get into the Pilots seat with the Syma Radio Control Helicopter. Buy now.

OLX Free Classifieds [change area]

pool table

For Sale, Toys - Games - Hobbies in South Africa, Gauteng, Johannesburg. Date May 6

Lexus: IS

Vehicles, Cars in South Africa, Gauteng, Johannesburg. Date May 7

stylish bachelor furnished in sandton from 1st of june

Real Estate, Houses - Apartments for Rent in South Africa, Gauteng, Johannesburg. Date May 7

BlackBerry Curve 9360

The BlackBerry Curve 9360 smartphone comes preloaded with Blackberry OS7...

From R2699.00

I'm shopping for:

Horoscopes
Aquarius
Aquarius

Your heart is with a friend who is going through a difficult time, but your soul is with an activity that you know brings you...read more

There are new stories on the homepage. Click here to see them.