![Talkin' About Infosec News - 7/6/2021 — Talkin' Bout [Infosec] News cover](https://img.transistor.fm/AukI425sRBc3M3UIa9lVng7qjeNeYEQ8BZfzCEXhALs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xZTA1/ZWZhNDcxZGM4ZTFj/ZGJhMTMwNmYzMmJj/ZjBkNi5wbmc.jpg)
Articles discussed in this episode: 00:00 - BHIS | Talkin’ Bout News 2021-07-06 02:32 - Story # 1 - CISA self-assessment audit tool - https://www.bleepingcomputer.com/news/security/cisa-releases-new-ransomware-self-assessment-security-audit-tool/amp/ (htt
Loading summary
A
Okay, so here's the deal, Cassia. We're gonna say it differently. Everyone come up with your own version. Every time you say kisea Cassia. Cassia casa. There it is. Everyone's gotta say it different.
B
Okay.
C
Cassia.
A
All right, let's. Let's go live. Screw it.
C
Let's get going.
A
Hello, everyone, and welcome to another edition of Black Hills Information Security. Talking about the news in this particular episode. Going to have Alyssa tell us how to pronounce. Kaseya. Kaseya.
We're going to have Alyssa teach us how to say that properly. We're going to talk about cyber liability insurance. And it's just a. It's just a real quiet week in the world of computer security. Not a lot going on, except for remote exploits for Windows systems and quite possibly the world's largest ransomware attack. All coming up.
What the hell, Ryan?
C
Oh, my God.
A
Added that.
D
That wasn't me.
E
That is nice.
D
That was nice.
A
He doesn't take credit for, like, coding in himself. Yeah.
F
Whose hand is that?
A
Whose hand is that? We were trying to. I. I like that thought. Like, whose hand is that? And what are those numbers in the background? Fein. And every time we do that, there is always somebody that goes through the effort to try to decode what's back there. So we've got to be.
D
Well, usually it's you.
A
There we go.
So we're joined by Max. Max, please say hi. Hello. If you've been on our Discord Channel, you've seen him. You know who he is. He's always around. He's always helping out. We're also joined by Alyssa, who's directly above me in the Brady Bunch squares. I've known Alyssa a long time. I realized that. I think I've known Alyssa longer than I've known some of my own children. She has. Yeah. How do you like that for creepers?
She used to teach me at a previous organization, and now she's doing freelance stuff. And she's one of the smartest endpoint forensics people, memory forensics people, just general security practitioners that I know. And she has a rocking class that we teach. So let's go ahead and let's get started. Ryan, what's the first. What's the first news story that you want to throw up for us?
D
That I want to throw up.
C
Hmm.
D
I'm going to talk about. Good. Warm up, I think.
A
Yeah, I think it is. So this is cisa, which I want to just make it clear that CISA has been crushing it, and I hope that they continue I do have a fear about them becoming too bureaucratic and getting too weird. But they just released the Ransomware Readiness Assessment or the RAA or rra and then also the Security Cybersecurity Evaluation Toolkit to help people get ready for ransomware style attacks. I really have a hard time with a lot of these different things as they come out because I feel like they come out ultimately just to make people feel better if they're like, oh my God, what do we do for ransomware? The answer to that question is literally what we've been telling people to do in the world of computer security for the past 20 years. It's not like this tool or this kind of what is it? Prepare, assessment and results and all these different things is really going to tell you anything all that different. But I feel like it's very targeted for ransomware. So maybe people will use this as like a gateway drug getting into computer security. They'll start here, maybe they'll start doing other things for security. What is everybody else's thoughts on these types of tools whenever they come out?
F
I think, hey dawn, thanks for the intro. But the detection tool is laden with indicators that are going to tell organizations whether they're owned or not. And I think that's a little bit of a different slant than just pushing out laundry lists of domains and hashes and file names is what we've seen before from cisa. So I'm interested in whether folks find the detection tool viable, whether they find it helpful.
D
And that's it.
C
And that's it.
D
That's all we got. Nobody else has opinion. I think we lost John again.
A
Did we lose John?
E
It's like he's there. Camera.
C
Yeah, the, the satellite has moved and now we have no more John.
E
Micrometeors.
D
Micrometeors and lightning strikes.
C
I mean, I'm not really sure if we need any more ransomware assessment tool stuff. I mean, it's not happening at all. So.
Obviously that's, that's a very poignant, not quite as fun joke about all the ransomware that's going on. I mean, yeah, it's good putting out more detection tools and signatures for those kind of things. It just, I don't know, like, I think of it like a warm up, like, like a workout, right? If you work out every day, you can get better, stronger, so on, so forth, healthier. Maybe the same way with your security posture inside your organization because we're going to see more of this ransomware. I hate saying that. Like I feel, is this only the beginning that's the real question I have.
A
Aren't we in the blue?
F
Like, I wonder if they pull together the detection tool because a lot of the.
Well anticipated impacted parties are more small businesses, more on the small, medium side of the house, therefore may not have been in the trenches pulling together indicators for enterprise scanning. So maybe it kind of speaks to the impact of parties.
A
Well, this does get into kind of a bigger issue with security. Kind of like what you touched on is a lot of these smaller organizations, if you're talking mom and pop bicycle shops, small credit unions, a lot of them can't afford like Mandiant to come in or BHIS to do a pen test. You know, they just can't. And I think the more of these tools that are available, I think the better. But question is, how much of this is the echo chamber? They're just going to go to the people that already know about cisa, already know about ransomware. Is it actually going to be helping the people that we need to be reaching out to?
C
Like a grassroot ransomware detection movement right.
In there.
A
What was the two worms back in like the early 2000? I want to say it's 2003. I want to say it was Nachi and Blaster or Welchi, I can't remember. But there was one worm that was released that literally would go through and patch computers. Like it was trying to get ahead of the evil worm, but it was going through and it was trying to be a white hat worm, as they were calling it back in the day. I don't know if we need anything like that. I guess technically and legally, I have to say that's a freaking bad idea. Don't do that. However, that being said, it definitely gives one positive.
C
But I mean, don't you think about back then, you know, this was more, less financial motivation than we have today. Yeah, this, I mean, I think that's the big thing we're really running up against here. We have an industry now. We don't just have, you know, a couple people who came up with a new attack method or something. You know, this is, this is people making money. I mean, you know, in some of these hacks, so many companies that they just were like, couldn't keep track and they're like given a Groupon to just pay them off.
A
Are you literally calling this like that the ransomware groupon? It's like if everyone gets together, we're gonna drop the price from 70 million to 50 million. And if you can bring friends and family in, we're Going to actually drop it down even further to 25.
C
It is so sad that it's funny because it sounds. That's what it is. That's what it sounds like, right?
A
That sounds like where we're actually headed with all this. But you talk about the money aspect of it. People are relatively new to this. This is huge business. I mean, this is billions of dollars that these organizations, these hacker organizations are making off of this. And they are straight up, seriously like businesses. Some of them actually have offices, they have staff, they actually have customer support. I don't know if you've worked a ransomware gig or not, but you can actually call a number and they will walk you through how to purchase cryptocurrency to pay them. It's just, like, absolutely insane. And on the other side of it, people that are going to be making a lot of money. Brian, do we want to talk a little bit about insurance on this? A little bit? Because.
D
Sure, let me find that one here.
Again.
A
So while we're talking. You can bring it up. I'll bring it up. So they're projecting that the cost of cyber insurance is going to be increasing by about 32%. And I like the byline, it said with no sign of. How do you think insurance companies feel about all of this? Like, I almost feel like they had a bunch of actuaries and a bunch of math nerds. And I'm not using that as a pejorative, like, oh, my God, they're nerdy people. But what I mean is they're actually really into math. And they're like, well, you know, the amortized rate of, you know, these particular attacks and the total damage of these attacks is this. And they set up all these different formulas and all these things, and they're like, this is what we should charge for ransomware or cyber liability insurance. This is what we should actually charge for it. And then 20, 21 hit. And it was like, oh, our math was way off on this. So what? Also, I should point out that if you're working an incident dealing with ransomware, you can almost always talk the attackers down. If you say, look, my ransomware policies for 5 million, they're like, so great. We get 5 million or nothing. Like, yeah, that's pretty much my policy. Here it is. Here's the policy. Like, okay, we'll take the 5 million. So I think that part of it is the attackers are actually hitting that ceiling again and again and again. So naturally, the cyber insurance companies are going to have to raise it. I've also heard of some insurance companies that are going to stop cyber liability insurance completely or they're going to have specific riders for ransomware. So I don't know if anybody else has any thoughts on this whatsoever.
B
Well, I think about the financial aspects. You have to consider that even for us who are in the field of security, it's really difficult to determine or to guess how many businesses or organizations are going to get breached. And the insurance companies have to factor that in. And they're working with a really big unknown right now. Because, first of all, this is still rather new, I think. So, for one thing, there is not a lot of data from the past to go on about, and it's also very dynamic.
A
So some.
B
Some new big breach happens or some new vulnerability is disclosed, and suddenly everybody is hacking into organizations.
Deploying ransomware. You can't really. I think it's very difficult to model this properly with chances, how likely it's going to happen.
A
Well, and I think you talk about the modeling, and I think that's the key. I think that they base the modeling on what has happened over the past 10 years. If you look at what's happened over the past 10 months, I think that that entire model has changed dramatically. Alyssa, you were going to say something, too.
F
The fact that now we're pulling in to the ttps, like the actors, TTP is whether their.
Track record is to negotiate or not. It's so fascinating. That's a whole other aspect when we talk about the commoditization. Am I saying that correctly? But, like, how the roles are becoming more specialized within the ransomware industry. They actually employ negotiators. I mean, as you were talking about, things are getting way more specialized, sophisticated, and we're seeing far greater success than days of old. Because, hey, if someone's paying me to specialize in just negotiations, I'm going to get pretty good at it. But I find it fascinating. Like the. Our evil or revel that we're discussing is known to negotiate. Don't quote me on that. Yeah, yeah. Like.
Didn'T they. They were asking for like, 50 million from JBS and came down to 11.
C
Yeah.
A
Well, so let's talk about that negotiation a little bit. There was a masterclass. There was a video where somebody was talking about hostage negotiations and how to actually negotiate with somebody that's taken hostages. And a lot of those exact same types of techniques that you use, and that type of horrible situation are many times the exact same types of techniques that you use for negotiating with ransomware. So you basically give them props like, wow, you guys really got us. That was really super impressive. Maybe say something like, hey, we had a pen test in the pen testing company. They didn't even figure this out. So, you know, great job on that. Kind of build up their ego a little bit and then seriously talk about what it is you can and cannot do and kind of hold those lines and kind of establishing that personal rapport the entire time because they're kind of inter weeding with each other. So there's lots of videos and TED talks on this type of thing. But Alyssa, I think it's interesting. It's almost like this is now a skill that the security industry needs. Right? Like, you know, we're about pen tester. We need someone that does forensics and oh yeah, we need someone that can do negotiation with evil cyber.
C
There's broker services already too, that will broker deals like this. Right.
A
And that. And they specialize in it.
C
They specialize in it, yes.
A
And they actually have long standing relationships with people at these firms. So, you know, it's.
C
And they'll be like, yeah, I brokered this deal when this company got hacked. You know, I brokered this other deal when this company got hacked. And, you know, I, I know what I'm doing. Right. I have, you know.
But it's also.
A
Interesting, like the value of that ransomware negotiation is, let's say ransomware attackers are coming in and they want 100 million and you talk them down to like 50 million. That organization is like, wow, you just saved us $50 million. Here's your check for like X thousands of dollars. Good on you. So there's always this kind of quantifiable value statement that you can have for somebody with these skills to basically say, hey, quantifiably, this is how much money I have saved organizations over the past year. Once again, it's a crazy thought that we now have this brand new skill set in the industry.
C
So what do you do here? Well, I'm a ransomware negotiator.
A big business.
F
Would that lower the insurance rates for a company if they actually had a full time negotiator? I wonder if that would be.
A
Kills me because it's like, do we just move in? That's the industry.
C
Like, forget the security. No, no, no, the industry.
A
Negotiating.
C
Negotiating the pet.
It's wild.
A
It was my money. Why does this feel dirty to me? Why does this feel like compliance negotiations, like all of a sudden? So it just seems very, very strange. So the other thing that's kind of interesting that I'm seeing with the insurance companies is they used to require like a certain level of due diligence. And yes, I probably will be having roasted cockatiel tonight for dinner. Delicious.
So one of the problems that I have with this is insurance companies are looking at how they're going to get out of this hole. They can do it a number of ways. They can raise the cost of providing insurance, they can cut it completely out of their insurance portfolio. They can also make sure the companies have higher penetration testing to make sure that there's some level of due diligence that's being done. But the other thing that I just heard from one of our customers last week was the insurance company itself is getting into the pen testing and assessment game and they're literally starting to do security assessments for their customers because they don't trust third party pen testers. Or the other thing that they do is they basically say, we will only trust these four or five companies. And that spooks me out too, because usually what happens, they end up with like Booz, Allen, Hamilton, Accenture, PricewaterhouseCoopers. And that's gonna lead to a massive change in this industry as well.
E
Yeah, but if they don't restrict it to certain vendors that they know will provide a certain service, then there's nothing to prevent the people that get hired to say like, oh, yes, we did a pen test, but what they really did was run an ESSA scan.
A
Well, and that's ultimately what most of these, these larger consulting firms do.
C
Right.
A
I mean, we know the pen test puppy mill industrial complex. And a lot of these insurance firms are going to ask questions like, exactly how many assessments can you do per year? And if you're not over a certain line to make sure that you can actually handle that influx, they're going to go someplace else.
C
Hold on, John.
A
Playing in volume. They're kind of lowest common denominator. Yeah, rough.
C
The other thing too is they're going to be like, well, how much of a deal if we push this much work, are we going to get a 25% discount? You know, so on that it just drives a whole different market where, you know, return, you know, insurance. Whenever insurance starts setting the rate for these things, it goes crazy. Prices go up, deals and quality don't go with that price. It's, it's insane.
A
So. Well, and we've kind of seen this before in the industry. Like if you look at PCI asv, you know, the whole idea of PCI sv, and I say it's a racket, because it is. And you Know, I sunk lots of money into it. And you always have these large organizations that try to establish some type of standards and some type of pay gate for the certain type of quality of service that's supposed to be done. And it very rarely does it that way. So I'll give you an example. So like in the ASV standards for pci, you got to go through to become an ASB to be associated like service vendor to actually do a scan and do an ASV PCI scan against a fake company. We did this years ago and we did full packet captures, tracked absolutely everything, found all the different vulnerabilities that we could and they came back and they were like, hey, you missed this database port that was open and vulnerabilities associated with it. You failed. And we could actually show them that we could send a SYN packet to that port and we received a reset that particular service was not alive. And they said, nope, you missed it, you failed, you got to pay us a another $20,000. As this went on and I was talking to people like Renault from Tenable and other firms, Secure Ideas was another one, I found out that absolutely no firms actually passed the ASV PCI test the first time out. They almost always had to go two or three times before they actually were successful. Now I'm using this narrative because if we go down the same thing where insurance companies are going to say, you've got to be a vendor that's doing this. You got to be Crest certified, you got to be something certified. It's going to do exactly what Ralph was talking about. How do you actually get cost actually doing that type of service as low as possible?
B
So what's the chance that we're going to get a new compliance standard out of this.
A
Industry?
C
DSS or 100% certified ransomware compliant industry. I don't know. Right. Insert your name.
A
I think it's coming. There's already entire training classes around ransomware that are starting to come up, which I think is interesting because I'd really like to know, other than a few modules on negotiation and cryptocurrency and how to handle these things, like what is fundamentally different? It's all the standard good hygiene of computer security for detection and response and prevention that we've been talking about. It's not like whole new cloth, so. But there are some things like ransomware negotiator, that's new.
C
Yeah. The sophistication too is increasing and we kind of just hit on that because of the price and like the value. Billion dollar industry you tend to get better operators, better attacks, right? So it's not, you know, it's not like all the same really, really bad stuff is necessarily happening. But we have a much bigger group, more focused going down this avenue, and they're more skilled attackers. So it's just, you know, it's another wave, and it's profitable, so they're gonna keep doing it.
A
Ralph, I also want to call out real quick. So Ben Webb, I don't know if I was on the episode that he was on where he basically said, that's odd. A couple of weeks I said that this would turn into the next pci, and you all told me I was wrong. So I'm about to do something that's never ever happened before on the Internet. Like, this is it. This is the first time this has ever happened. So, Ben, I want to make this very clear. We were wrong, you were right.
Congratulations. We've just cracked the ice on the Internet, so for sure it's going to be on Reddit. It's like somebody on the Internet admits that they were wrong. Oh, my God. So.
So thanks, Ben, for rubbing our noses in it. We do appreciate it.
C
Bad dog.
A
So who wants to talk about printing?
C
Oh, boy. I love printers. Hp. I mean, is there other brothers?
B
Those are great printers.
A
Just say hp. Others.
D
HP and others.
E
Sorry, I'm not a printer dude, so I. I'm jealous.
A
So a little bit I wish I.
E
Didn'T know about printers.
F
Yeah, please. Where do we stand with this right now? The article that he's showing, where do we stand?
A
So right now.
Burn printers to the ground. Take them out office space style.
E
Breaking their printers, just smashing them.
C
This is the vulnerability.
A
I have to destroy it right here. Right here. I went on Twitter as soon as this one came out. As soon as I saw it, I'm like, whoever did this vulnerability, please do fax machines next, because I hate fax machines. I hate them so much. Is this bad? I mean, if we just got rid of all printing and we just did PDFs and signing things, it would be a good thing, right?
C
Honestly, save the planet.
A
All right, so a little bit of technical background on this particular vulnerability. So with printer, you have the prints for service, okay. And the Prints Ruler service allows you to do things like spool off print jobs. It also allows you to add new printers, which is pretty stock and common for anything when you're dealing with printers. However, what this particular vulnerability allows an authenticated user remotely to do is basically cause the system to add a new printer with your own Driver which allows you to execute arbitrary code, which, once again, if that seems bad, that's because that's bad. There was a patch that came out, the patch was less than effective. And now basically what everyone is saying is the same thing. It's like, what do we got for solutions here? Solution one, Microsoft, option one, stop and disable the printing service. Option two, disable inbound remote printing through group policy. Okay. Option three, block RPC and SMB ports at the firewall. So it's basically like just shut printing down.
C
Just shut her off, buddy.
A
Never print the chance. We're just going to shut this down. So, Alyssa, we have some common friends that have had some experience in the exploit dev world. And the thing that I find interesting is if we could talk to them. Like, the idea of the standard heap and buffer overflow attacks, those are going away very quickly, especially at like, core operating system level exploitation that we would do traditionally, smashing the stack or heat feng shui or whatever the hell we want to, we want to do. That's getting rarer and rarer and rarer. But this almost seems to me like, it's almost like a business logic error in code. Like it's less saying, oh, well, there's a. There's a buffer overflow or heap overflow or something like that. And more like, oopsies. This particular service can just load random drivers and run them as system. So do you see this as like kind of a different type of class of exploitation? Like, how do you look at this style of exploitation versus the traditional heap and stack?
F
Is a fair point.
C
Right.
F
This is pretty egregious, as loading drivers is like what you taught me, having a critical impact on the entire functioning of the system. Ah, yeah. Not your typical vulnerable. There's another buffer overflow vulnerability in Wireshark and let the cards fall where they may. This one seems almost preposterous.
A
Yeah.
And kind of the history. The other thing I think is interesting, like Windows 11, they're going to require you to have a trusted platform module on your CPU in order for it to run. And we've been always talking about embedding security inside of the microprocessor and trying to get that.
I hate mentioning this to people, but that won't stop 98% of the attacks. It's going to stop some rootkit stuff that we were really worried about.
C
Eight.
A
To 10 years ago. But for a lot of these types of vulnerabilities, the service just randomly loads a driver because why the hell not? Or vulnerabilities that are Just application level back doors. It's almost like you have these parallel paths where everyone's doing all this deep research on how we can get security deeper and deeper into the micro architecture. And then it's like, nope, somebody just ran this random driver. And it's now exploited a number of different computer systems. I think that there's this huge disconnect on where security research is going, which is always interesting from a technical perspective, but still like 95 plus percent of the attacks are like, hey, Bill, click the link from a stranger that had malware. And we still haven't solved that fundamental problem yet either.
F
Yeah, or you partnered with the wrong IT management software company. So your trust relationships are flawed but couldn't have done anything about IT type of thing.
A
You talk about that relationship with a third party. I don't think anybody that's on this was on this test a number of years ago. We were testing an organization and I might have told this story, but just give you an idea just how common it is to have these types of vulnerabilities. This particular customer had a web portal for self customer support. So for their own employees, they were having trouble like, let's say printing or something like that. They could go to a website and they could go and put requests and they could put in all these different updates and do these things. It was a really neat little self help portal. Reset your password, send little pins to your phone. All these things were there. Now we, I think it was Derek Banks and I can't remember who else was on this particular assessment, but what happened was they were able to get access to this portal. Once they were in the portal, you could actually submit a Word document describing your issue to Help Desk, which if you're an attacker, that's like manna from heaven. You're like, you're allowing me to upload files and send those files to other people. Well, hot diggity dock. That sounds like a good day. So they did just that. They created malware, they sent it in. Then you called Help Desk and then you told Help Desk, this is my case number. They could go to that file. And as soon as Help Desk opened that particular file up, they're like, oh, well, it says something about macros. And the testers are like, just run it. And the Help Desk person ran it and we got access to this particular company. Except it wasn't the company that hired us to do the pen test. The company that hired us to do the pen test never told us that their entire portal was completely outsourced. To a third party organization. And this third party organization had hundreds if not thousands of other customers that they did help desk support for. So we realized this mistake relatively quickly. The point was it literally took them about half a day to build that entire attack and actually gain access to this particular organization. Now, John. Yeah, go ahead.
C
How long did it take you guys to do the pen test and all those other companies?
A
So it actually was funny because the administrator, the help desk technicians had full domain administrator access to every single one of the other organizations.
C
That's a requirement.
A
Yeah, yeah. They had to have it right for customer support and.
D
Oh no, I think he froze again.
C
Shifted again.
F
Does anyone know the end of the story? I mean, I mean how did it get out?
A
They all died.
E
It was just a classic Hamlet ending. They all died.
C
They all died. Reboot again. Obviously Windows 11 is installing right now. So John is on pause.
D
Come back to that story.
E
Yeah, yeah, yeah, I did want to. One thing that I was just. You should not have the print spooler service running on your domain controller. That's basic like Windows Server hardening. You, you also in like the one case where you should have the spooler is if you're using your domain controller as a print server, in which case you shouldn't be doing that either. So there is no need. Like this shouldn't be as big of an issue. I mean, yeah, it's not great. Like it's, it's. But it could be better if we did proper OS hardening of our Windows servers and proper segregation of our various network VLANs.
C
I was talking to some other buddies about that and I remember doing DISA sticks. This is like the DISA hardening guides. If you go through a DISA hardening guide, you can really secure your Windows system. You might break a couple of things. That's a fact also because there's a lot of recommendations that are just going to break things. But there is a ton of great information in there and it's surprised how many people don't do that. Right. Or just don't go through the process.
A
So Ralph, do you remember the disick old disks?
C
Oh yeah.
A
The automated assessment had a little button. It's like remediate selected vulnerabilities. When I was doing security at the NRO and nsa, we give it to systems administrators and we tell them, you see the shiny button? Don't click that button.
C
Yeah, don't.
A
Don't click it. We'd say, okay, so you saw me, you're not going to click the Button. No. Not going to click the button. Not going to click the button at all, Mr. Strand?
E
No.
A
All right. Then I'd leave, and all of a sudden, like, half of our server infrastructure would go down, and I'd show up and they'd be like, well, John gave me this CD and it had this button and I clicked it. I'm like, the button I told you not to click, you click that button. Well, I figured it would be faster in the long run if I just click the button and it automatically fixed it.
C
Yes.
A
People wonder why people in security drink.
D
So is that what happened to your computer? Did you click a button on your computer?
A
No. This is my life now.
This computer, doing a web stream. John was hardening his system, I was hardening my system. I had to remediate selected vulnerabilities, and I'm locked up. So I don't know how long I have. I don't think anybody really knows how long they have.
It's just. It's just that. It's just that I think whenever I get done with this, I'm going to buy a new computer or motherboard. I'll probably call Ralph because he gets excited about these things.
C
That's true. I do, weirdly enough.
A
Yeah. People are like, why did you get into pen testing? You must really like computers. No f and hate them.
The way. Just the way it works. So what other stories do we have here?
D
We got Casio.
C
Like the little watch where you had the calculator on it.
E
Yes, they do that. They also make keyboards. Not like typing keyboards for computers, but.
C
Like, you know, portable pianos.
A
Yeah.
C
Portable piano.
A
So we joke, but this whole. This Cassia vulnerability that we're dealing with, so. So people are calling it bigger than Solar Winds. I've even saw somebody on Twitter that say this is quite possibly one of the largest hacks in history. I don't think they're wrong.
And I want to make it very, very clear that I don't necessarily blame Kaseya on this. Did I. Did I do it right?
F
Yeah.
E
There we go.
A
I think it's better if it's Cassia.
Later.
Yeah. But once again, I think it's easy for people to blame the company that got compromised. And I suppose time will tell, but I don't know. We've been doing this Ralph, you know, for a long time. Max has been doing pen testing for a long time. Noah's just getting started. Alyssa's been cleaning up messes of pen testers and hackers for, like, a over a decade now. It. You Know, companies getting hacked with this, they aren't necessarily the exception, it's the rule. So, you know, light a candle, say a prayer, give an R to to the fine security folks that are trying to deal with this incident as it is now.
C
You know, what I would be interested to, to know is like, did they accidentally hack them? Was this like, you know, they, they had to get into some other company and then somehow you know, ended up like in your story, ended up as you know on one of these systems and was like, oh, this is interesting.
A
Let's see where this goes. You see somebody at re evil or revil or whatever we want to call them the lesser or two revils saying, a boss boss.
Like John, we'll get to you. You can go to the bathroom without raising your hand. No, I don't have to go potty this time. Come here. They're like, oh my God, what the hell did we just get access to?
E
Where were you trying to go? Oh, well, there was the MA shop down on the corner of Main street and I wound up here.
A
Yeah, how did that happen?
C
Well, it's actually a ice cream shop. And now I'm here and this is amazing. There's everything.
F
It's pretty fascinating to pedal that article. I think that is a common.
Misperception that the whole supply chain, you know, oh, it's a supply chain. If, if some of the customers were impacted, it must have been a supply chain attack.
A
Which.
F
Yeah, that can get a little bit muddy.
A
Well, okay, so this gets into an interesting thing about the supply chain. There's a ton of firms out there that provide services where they scan companies and then they give them a security scorecard and they're like, well, Black Hills Information Security has these four vulnerable servers. We're giving them a D minus on their security and their thought is if they can scan and find these vulnerabilities on the outside, they can give you a score. And it's like you're trying to assess the security of a vendor in your supply chain by what their mail records are configured to. I don't know how that's going to work out, especially since BHIS has a crap ton of honey pots out there.
C
You love honey.
A
Yeah, we do.
C
Well, I've been on plenty engagements. Right. And you're on this internal network. It's a large organization, they happen to have, you know, business to business relationships with other large organizations. And sometimes they have some kinds of connections, you know, simply like maybe an FTP or something where they're sending files back and forth I mean, this happens all the time. And you go in and you'll see. I've seen this on multiple engagements. I'll see companies that I had done tests for on another company's test, and they're doing, you know, like, it's just you keep seeing this stuff over and over again. It's not that hard to, after you break into one, kind of break it into the next one. This isn't like, oh, well, we did a full survey of how this company operates and figured out that the most vulnerable way to attack the most amount of people was to get this. No, they probably accidentally landed there.
A
Yeah. I would almost have to guess this was an accident. I would agree. Now, one article that I was talking about said, this isn't even the scariest company that does this type of service out there. Like, whenever you're talking about supply chain, there's a large number of other companies that are far more embedded. Not just Microsoft, Google and Apple, but there's a lot of companies out there that are very embedded into a large, large number of other organizations.
C
You know what's wild, A lot of those organizations, you don't even know their name. And, like, someone's like, that is a huge company. They do a ton of stuff. They're all connected. And you're like, I don't even know how to pronounce it. How do you pronounce it?
D
It's Casio. It's Casio.
A
One of my favorites is Akamai. Like, there's very few people walking around the street that know Akamai. And, like, what it actually does and how it's actually so tied into absolutely everything everywhere. Now I know that there's people that are going to be like, what is this? How do I get rid of the Akamai on my computer? Where is this coming from? When you start looking into things like CDNs, all this. Actually, this is all starting to sound a lot like Paul Dixie's talk at Way West Hack Infest. I think the whole gist of his talk, I can't remember the exact title, but it was like something around the lines of we're screwed. Congratulations and welcome to the surveillance state. Let's go drinking. It's just so bad how many companies are so embedded in so many different places.
C
I don't think that was the title, John, but I think that does sum it up.
B
Yeah, I did.
A
I tried to sum it up as best I could. Paraphrase.
I'm sure Paul wouldn't have a problem paraphrasing and going with the title of his presentation.
D
Yeah, Max knows it's something about the void.
B
No, I think, wait. Gazing into the Abyss, I think was the one.
A
The more the abyss gazes back at you.
C
So that's deep.
B
So one more thing about the Kaseya thing. There was some talk on Twitter that apparently the vulnerability that was exploited to gain access to the MSS providers, I believe had been just recently been discovered by security researchers from the Netherlands. And I think it was the people who were on the Darknet Diaries episodes called the grumpy old hackers. I think I might be connecting wrong people here, but I think that that was it. And basically they said they report the vulnerability and Kaseya was basically very close to pushing out a patch for it. And then this incident happened, so.
E
Ouch.
A
Well, and that's Max, that's interesting because I think that that also shows like a level of liability that security restraint researchers run into. Right. So if you're working with a firm and you have a vulnerability, you're always a little bit worried that somebody's going to find that vulnerability first and release it. And guess who gets blamed, Right? It's the security researcher that you're talking to. We've actually had that happen at the his. So hopefully it all works out for you.
B
I guess one point about that is also you don't really know if somehow the information got leaked somewhere and if it did, you don't know where it got leaked.
A
Yeah, because you're right, because once you share with that company, you could share it with help desk. It shared with the security team, gets shared with the systems administrators. There's a number of people that could actually take that and leak it directly to the public.
C
Loose lip sync ships.
There was a. What is it the gift. I read an article recently about gift cards and I believe it was. Was it Apple gift cards or Best Buy? I can't remember. Anyways, and they had the guy who was working on the program figured out a way to actually just take money from gift card or Xbox. That's what it was. Microsoft, it became this huge thing and they were stealing tons of money from gift cards, was writing pretty much blank gift cards and selling the money. And the point is kind of like once that was, you know, once he figured it out. Right. Like that it was known in there and just kept running it and making all kinds of money and selling crypto and also the wild stuff.
A
Yeah. And this has. This has been a big problem in the gift card industry for a while. And even prepaid cars, credit cards, it Used to be that you could buy prepaid credit cards from Walmart. A number of years ago, I went to Walmart and I bought like 30 of them. And I tried to get the serial numbers as closely as I could. I think they were MasterCard gift cards, if I'm not mistaken. But I basically tried to get the serial numbers as close as I possibly could on these cards, and.
C
He froze.
A
I don't know how this story ended.
F
He sucked me in again. I should have. I was trying to protect myself and not fall into the trap, but he did it again.
C
Actually, gift cards are really used for a lot of money laundering, too. It's a big, big way to transfer money back and forth, which may be where he was going with that, because it's kind of like not real money. It's fake money.
E
Are you saying John was going down the route of. And I bought all these gift cards in serial number order and then I laundered money with them? Is that what you're trying to say?
D
As soon as you said serial numbers, he was gone. Yeah.
C
No, I knew that the storage is going.
I'm not exactly sure that's what happened, but pretty sure.
D
Oh, boy. He says it's not booting back up.
A
No. Oh, no.
D
You finally fried it.
E
Please send help.
C
Please send help. We got a drone.
E
Light a candle, say a prayer. That's what I was just told.
C
What else we got today, Ryan?
D
All right, moving on. We have a NET Core thingamabob.
E
Whoa, wait, what's Net?
C
What is Core? Yeah, it's that thing that doesn't work for everything that you would normally use PowerShell for or net. All right, cool, great.
E
Yeah, that one.
D
So we got Microsoft.
This is the show about names today. Because there's so many names.
C
Is that what you're trying to say?
A
Azure. I don't know how to say any.
D
Of these things.
C
John.
D
Real time follow up, John. He's calling it in. The computer cannot take it anymore.
C
That's it.
E
I'm a death right now.
C
What is it? This is a NET Core vulnerability code execution, which is interesting. I'm guessing that if you're using net5.net Core, there is a remote code execution inside of those versions.
D
So that's fun. Be aware of your NET Core.
B
I think if you scroll to the middle, shows the packages that are vulnerable, I suppose might be something if you use these packages for a web application that uses. Net. Maybe.
There'S not that much more information in the article, unfortunately.
D
Well, that was nice and quick.
C
Yeah, I know, right? I didn't even know about that one. Honestly, there's been so much news recently, it's just been like. There has been a lot digest that.
E
We're still mourning the loss of John.
C
I know.
D
So here's the next one. Intuit to share payroll data. What could go wrong with that?
E
No, wait, you didn't finish the title.
A
Equifax.
E
They're sharing it with Equifax.
C
They should just xed out the Equifax and said devil. Just with the devil.
E
With the entire world at this point.
C
How many times has Equifax been hacked anyways?
D
Not enough, apparently. Because it seems like someone's thought it was a good idea to give them more information.
C
Well, yeah, and I mean, it sounds like they're going to be doing. Yeah, and I knew. I knew that Krebs was going to go into, you know, Equifax, like the 2017 breach and, you know, what, 145 million background. Yeah, right. Like that didn't happen. No, it was cool. We messed up. We fired the guy who was in charge. We're better now.
E
I heard it was an intern.
C
It was definitely an intern.
But. Okay, so here's the big question, right? So as we get into these bigger online services, right? So TurboTax just doing all of your Turbo or doing all of your tax data, and then Equifax and just sharing of all of this data. I mean, don't I feel like it's time for like a GDPR or whatever, some kind of framework. But we don't have anything. Like, we're just kind of like, well, it's out there, it's free. You guys want to buy it, or, you know, you want to sell it.
D
Or you want to steal it, you.
C
Want to steal.
And then you can sell it. I don't know, it's just one of those things that I think that, you know, more of this information should have some more like, rules and stipulations, as opposed just like, well, you gave it to us, so now we're going to sell it to other people or other companies or what do you think?
E
And you're using the term gave loosely sometimes. I mean, if we're talking about. If we're talking about payroll data, I mean, that would mean if I am an employee of a company who's using QuickBooks for the payroll, I may not have expressedly said like, oh, no, that's perfectly fine for you to share my payroll data with them. Of course they're going to be doing some sort of anonymization you know.
D
Terms.
E
Of service are really relative term. I went and got a job that wasn't necessarily something that I chose.
D
I'm just saying you didn't choose the job.
E
Well, I mean I chose the job, but I didn't necessarily be like, oh yeah. And as a stipulation of this job, like I would like to like willingly hand over some of my precious data here so that you can share it with someone else. You know, is then they are going to share it with someone else. On top of that, you know, when.
D
You accepted this job, you sign the terms of service that says there's an HOA behind this job. Now you have to pay them with data.
E
But you mean that, you mean that 35 page document that I didn't read because it's 35 pages long.
C
You can always opt out though, don't worry. You just gotta get to that point.
D
And you just gotta call a phone number.
E
Yes you can. And as we know with the Equifax breach of 2017, like they're opting out and they're informing services are perfect with their form that you could go and see if you were affected and you could basically type your name like multiple times and it would change the results every so often. So yes, I definitely trust that opt out page like that that will be taken seriously.
C
You know what's funny about all this is that they have this data and they're like, oh, we're going to share with each other. Google already has all of it so they don't even need to share with each other.
E
Meanwhile in Googleville.
B
Yes, the silver linings here is though that you know, in the near future a lot of people are going to get free credit monitoring probably.
E
Oh no, I've already got free credit monitoring for life at this point. I think like I have no concern like who could steal my credit with the phenomenal quality of free credit monitoring that they keep giving me.
F
It all runs concurrently though. It doesn't run back to back to back.
C
Now you can't stack them up like aol, like.
E
No, I just have a, I have a stack of papers from various people who are like, oh yeah, here's some free credit. So like I'm like, oh, my credit monitoring expired and I go to the like folder labeled credit monitoring. Pull out the next page, like, oh, here's a code. Let's see if this one works.
D
It's a QR code. You just scan it.
F
Every other one.
C
I just.
E
Meanwhile the credit monitoring is done by Equifax or something like that so, like, you give Equifax more information so they can protect your information.
C
Yeah, it is true. The only thing you could do now is just freeze your credit. I think I froze all of them just as like one fell swoop. Just freeze them all. They're not all free to do this. This, this industry is a whole trip. It is like, it's like a scam of the century. Holding the data, charging other people for the data, charging you to freeze the data, and then charging you to get credit monitoring service because of the data that they lost.
A
Well, and then, and then, yes.
E
But then I've also been seeing this new one where they're like, do you want to improve your credit score? Well, you can just pay us money and give us more information and we'll make the data that is saying bad things about you better. And I'm like, how is that not like bribing something? Like, how is me paying you improving the credit score? Well, like, other than the fact that like I paid you and now you're like, oh, no, he's much more trustworthy for that home loan.
C
I just keep thinking of the song this Is America.
F
There's a couple things I wanted to get in. I have to jump soon, but I.
A
Wanted to make sure.
F
Yeah, everyone knows that the Digital Forensics research workshop is next week. It starts, it runs Monday to Thursday and it's only 150 bucks to attend. So that's a pretty sweet deal. You can still. Oh, you have that one up. Thank you very much. And it's not like filled to the gills yet. Unlike, I wanted to give a shout out to the Diana Initiative as well. The Diana Initiative, though they are saying it's sold out. But that's going to be next Friday, Saturday. So if you've managed to snake your way in and get a ticket, the lineup looks phenomenal. Good stuff. Alyssa Miller's opening given the keynotes on Friday, so that'll be good. Oh, and then there was like the last one because I, I help a lot of folks who are just coming into cybersecurity, like, you know, mentees. There was.
D
Is this yours? Your class? Yeah.
F
Oh, no, no. Oh, I wasn't even going to mention that.
D
Oh, we got to mention that it.
F
Has the word advanced in it. No new to security, folks are going to be jumping in, but yeah, yeah. So that's my class there. And the next run is slated for the 27th to the 30th. That's of July. And so it's just four hours a day. There's, there's the schedule. Wait, the first day is five hours for Foster, but yeah, Advanced Endpoint Investigations.
D
Well, the first hours to get students into the class, get their stuff that they need, all the technical details to get running.
F
Yeah, we had a great.
D
Don't panic.
F
Yeah. So we. I just taught the class.
B
Oh.
F
Probably two and a half way west. Seems like it was months ago now. But it was two and a half weeks ago. Yeah.
A
Yeah.
D
Time's flying by. What was, what was the other thing you were going to say?
F
Oh, just that the active countermeasures is. Oh, yes, they have a. They have a webcast. Yeah, that's the one.
D
Foundations, network security.
F
The foundations and network security. It's a bit of a mystery when you're new.
Packet analysis. So Hannah's gonna do a bang up job in filling everybody in. I'm certain of it. So.
E
Yeah.
B
Thank you.
F
Those are my like shout outs. You gotta know what's going on because with that digital forensics research workshop, that's normally where like the most academic stuff comes out. Like people have been slaving away working and working for years and years on particular research projects and this is their time in the limelight, I guess you could say, to really get the word out on a new artifact or if that's your cup of tea, if that's where you spend a lot of your time as artifact recovery, discovery and recovery, then that might be something you want to check out. So thanks very much for dropping the links. It's cool.
D
You're welcome. And thanks for coming on the show with us. We definitely appreciate you being here.
F
John has a sad story now. I'm not going to be able to sleep tonight until here.
C
He just needs to tell more stories and just drop off. Just the cliffhanger.
A
Killing it, man.
D
Just come back next week.
C
Yes, yes, come back next week. Right.
D
Well, I think exciting conclusion of serial numbers and gift cards.
C
Yeah. Right. With that, with that all being said, I think that's. I think that's all the stories we had for today. Right.
D
One, one more. If we want to get through it real quickly. If we have the audacity to get through it really quickly.
C
Oh, Jesus.
D
This should be a quick way.
C
See what you did there?
A
Yeah.
C
So Audacity is pretty much making spyware now. So it's from what I read in a couple of articles, not just this one, but that they got bought out by another company and then they started inserting some pretty much.
Metric tracking or analytics on what you're doing using the software and now it's pretty much turned into spyware. And a lot of people on top.
E
Of that, and on top of that, they don't want anyone under the age of 13. This is before they rescinded it, but they didn't want anyone under the age of 13 using it because basically they didn't want to deal with the COPA loss for storing that data either. So, you know, lots of confidence instilled.
A
With that as well.
E
But they did rescind it afterwards.
C
I think this is kind of the gross side of when you take this like open source software and then kind of like buy the name and then start maintaining it and then just start to, you know, to, to your own bidding. Right. And in this case, it seemed like they were looking for ways to monetize it, and that's where it kind of started turning into pretty much spyware. It's useful software and people just assume that, you know, it. The updates don't include these, you know, but nobody's necessarily doing full due diligence. Oh, someone else bought it and it's not just open source and blah, blah, blah. You know, now they're adding this, this and this to it. So, yeah, it pretty much made a pretty big stink this weekend.
B
Not an expert on open source licensing per se, but wouldn't it be possible just take an old version that's GPL or whatever it was?
A
This is true.
D
Well, that's exactly what people are doing. Yeah, folks are doing. They are forking it on GitHub and I don't know if it was on this specific page, but one of the websites. Yeah, here we go. It's. Oops, sorry I left you up, Max. I was reading. I was reading the other webpage. Here we go. So users on GitHub and Reddit are calling. Well, they said they're calling to fork Audacity, which will likely happen.
C
Yeah, yeah, they'll probably make it, call it something else. It'll be some random name and, you know, it'll be the same exact software, just minus all of that crap that got added. And it'll just continue to drive forward. It's just kind of messed up when companies do this and just grab, you know, or they may have paid for the name. That's really it. Right. Because it was open source before and then they changed the EULA and then try to move it forward and eventually people caught on. So that's it.
E
Super popular among podcasters or whatnot. You know, there's a lot of people that use it.
D
It's been around for a very long time.
E
Renamed something like.
Never mind. I don't know. I had a name in my head.
Yes. Name it Casio. I'm sure that's what they'll do.
D
That's not going to infringe in anything else at all.
C
Well, that's a good job. But yes, that is it.
D
That was the final link.
C
Avoid. Wait for the. The fork to come out. Right. Or grab an older version from the repo. If you are using it.
E
They'll call it Obscene D or something like that. That was the name I was thinking of.
A
Whatever.
C
Yeah, whatever they call it.
D
It's time. Time to go. Happy hour, dinner, whatever you're doing.
C
Yeah, I got to go get ready for a hurricane that's gonna hit my house.
D
Oh, yeah, that's right.
C
I gotta do.
B
Well, you're.
A
You're close.
C
I'll be standing outside with the American flag and. Perfect.
D
We can make that a gift. We'll start with that for next week's opener.
C
Perfect.
B
Your computers.
C
Well, thanks everybody, for joining us for another exciting episode. And hopefully John will make it through through the next one and get through those cliffhangers and we'll figure out what.
D
Happened with the gift cards.
Podcast: Talkin' 'Bout [Infosec] News
Host: Black Hills Information Security
Episode: Talkin' About Infosec News - 7/6/2021
Date: July 12, 2021
This lively episode features the Black Hills Information Security (BHIS) crew and friends dissecting the most significant stories in infosec from the previous week, focusing heavily on ransomware trends, cyber liability insurance, and recent notable vulnerabilities (especially Kaseya and PrintNightmare). The conversation blends deep expertise, industry insights, and a dose of humor, all while delving into the evolving threats and responses within cybersecurity.
[02:32 - 06:14]
[07:27 - 14:49]
[08:32 - 19:33]
[20:48 - 29:44]
[31:32 - 39:10]
On ransomware "Groupon" discounts:
“Are you literally calling this like the ransomware groupon? It's like if everyone gets together, we're gonna drop the price from 70 million to 50 million.” — Host [07:27]
On ransomware negotiations as a job:
“So what do you do here? Well, I'm a ransomware negotiator.” — [14:20]
“Would that lower the insurance rates for a company if they actually had a full-time negotiator?” — [14:27]
On security automation:
“People wonder why people in security drink.” — Host [30:40], after a story of sysadmins clicking the 'Remediate' button that crashed half the server infrastructure after being told not to.
On compliance rackets:
“The whole idea of PCI asv, and I say it's a racket, because it is.” — Host [17:10]
On the scale of supply chain risk:
“There’s a ton of firms out there that...give you a security scorecard and they’re like, well, Black Hills Information Security has these four vulnerable servers, we’re giving them a D minus on their security...by what their mail records are configured to.” — Host [34:31]
On credit monitoring:
“Oh, my credit monitoring expired and I go to the like folder labeled credit monitoring. Pull out the next page, like, oh, here's a code. Let's see if this one works.” — Panelist [47:04]
On open source “betrayal”:
“It's kind of the gross side of when you take this open source software and then kind of like buy the name and then start maintaining it and then just start to, you know, to your own bidding.” — Panelist [53:06]
The episode offers a well-rounded, humorous but insightful commentary on the present and future of cybersecurity: ransomware’s evolution into a legitimate business, insurance companies and compliance introducing their own new challenges, persistent vulnerabilities in legacy tech like printing, and the risks buried in the supply chain. Blending practical advice, war stories, and a healthy dose of skepticism toward industry trends, the BHIS team demystifies the sometimes absurd state of infosec in a rapidly shifting threat landscape.
Note: For stories dropped due to technical difficulties (e.g., the unresolved gift card serial number tale), tune in next week!