Tuesday, February 13, 2018

Week 10 - Olympic Destroyer Disrupts the Opening Ceremony


On Feb 9th, before the opening ceremony for the Winter Olympics in South Korea, there was a cyber attack on the Olympic IT infrastructure. The attack lasted about 12 hours and caused damage to systems, monitors, WIFI, and website. Some components were not reachable or disabled, causing much inconvenience for those involved in preparing for the big day. Also, some people could not print tickets which resulted in low attendance for the ceremony.

After security investigations, it was found that the attack was caused by a fast-spreading malware called the Olympic Destroyer. The worm can quickly jump from one machine to another, and shut down services, destroy data, and erase the boot record. The systems were unusable after a reboot. It seems the malware had 44 usernames and passwords in the code that originated from the domain pyeongchang2018.com. By using PSExec and Windows query language, the malware could obtain more credentials by searching browser’s data and system memory. The behavior of the malware is very similar to NotPetya and BadRabbit that targeted Ukraine’s systems, so Ukraine’s government, CIA, and other security firms think that this attack has ties to Russian hackers (GreenBerg, 2018). Also, since Russia has been banned from the Olympic games for the user of performance-enhancing drugs, they have a motive for the attack. Others are accusing North Korea of the attacks, but the country has nothing to gain from the intrusion.

If you are attending the Olympics game, be aware that there might be some technological challenges because there might be ongoing cyber attacks. If there are delays on the Olympic websites, be patient. And, beware of Olympic scams through email.

References


Greenberg, A. (2018, Feb 12). Olympic Destroyer Malware Hit Pyeongchang Ahead of Opening Ceremony. Retrieved from https://www.wired.com/story/olympic-destroyer-malware-pyeongchang-opening-ceremony/

Perlroth, N. (2018, Feb 12). Cyberattack Caused Olympic Opening Ceremony Disruption. Retrieved from https://www.nytimes.com/2018/02/12/technology/winter-olympic-games-hack.html

Sarkar, S. (2018, Feb 12). The Winter Olympics’ systems were hacked during Friday’s opening ceremony. Retrieved from http://www.techradar.com/news/the-winter-olympics-systems-were-hacked-during-fridays-opening-ceremony

Tuesday, February 6, 2018

Week 9 - Take Caution in the Use of Grammarly


Last Friday, Tavis Ormandy, a Google Project Zero researcher disclosed that there was a vulnerability in the popular grammar checker, grammarly.com.  The vulnerability allowed third-party websites to access the authentication token of Grammarly accounts which in turn allowed access to all the user’s documents, history, and website information. An authentication token allows repeated entry to the same website without entering credentials every time. This makes it convenient for users to leave the site and come back at another time. However, in this exploit, Mr. Ormandy shows that it was possible to use a script to create tokens that allow access to Grammarly accounts.

The security breach is devastating because there are 20 million users of the Grammarly application on Chrome and 645,000 users on Firefox. (Kovacs, 2018). However, after Grammarly was notified of the vulnerability, they patched it within a few hours. They also go on to say that there was no evidence that user information was compromised. The vulnerability affected only the text saved on the website, but not the keyboard editor, Microsoft add-in, or text typed in other sites.

If you use Grammarly, you don’t have to take any actions. All components of the software will be automatically updated. However, this is a warning to all users of the software. Be cautious of what is being exposed to the grammar checker. If the document or website is confidential, it is probably best to not use the application. The tool is excellent for checking school documents and is a great supplemental aid for writing. However, sensitive information should not be exposed to Grammarly.

References

Armasu, L. (2018, February 6). Grammarly Bug Could Have Exposed User Data To Any Visited Website. Retrieved from http://www.tomshardware.com/news/grammarly-bug-exposes-user-data,36464.html

Kanaracus, C. (2018, February 5). Grammarly Patches Chrome Extension Bug that exposed users' Docs. Retrieved from https://threatpost.com/grammarly-patches-chrome-extension-bug-that-exposed-users-docs/129794/

Kovacs, E. (2018, February 6). Grammarly Rushes to Patch Flaw Exposing User Data. Retrieved from http://www.securityweek.com/grammarly-rushes-patch-flaw-exposing-user-data