This is a guest post by the SAP security expert Juan Pablo Perez-Etchegoyen,
CTO of Onapsis. Enjoy reading:
At Onapsis we are continuously researching in the ERP
security field to identify the risks that ERP systems and business-critical
applications are exposed to. This way we help customers and vendors to increase
their security posture and mitigate threats that may be affecting their most
important platform: the one that stores and manages their business’ crown
jewels.
if you’re following this blog regularly or if you’ve ever attended an
ERNW-led workshop which included an
“architecture section” you will certainly remember the “Seven Sisters of
Infrastructure Security” stuff (used for example in
this post).
These are a number of (well, more precisely, it’s seven ;-)) fundamental
security principles which can be applied to any complex infrastructure, be that
a network, a building, an airport or the like.
As part of our upcoming
Black Hat
and
Troopers
talks we will apply those principles to some VoIP networks we (security-)
assessed and, given we won’t cover them in detail there, it might be helpful to
perform a quick refresher of them, together with an initial application to VoIP
deployments. Here we go; these are the “Seven Sisters of Infrastructure
Security”:
On Friday we released our latest technical newsletter with the fancy title
“Sell Your Own Device – A Field Study on Decommissioning of Mobile
Devices”. It is the result of a field study on decommissioned mobile business
devices bought on eBay and about how stored data may be extracted in different
ways.
As always we love to share plenty of practical advise: At the end of the
newsletter you will find the mitigating controls to securely handle mobile
devices at the end of their life cycle process.
Hi everyone,
it’s me again with another story of a toll fraud incident at one of our
customers (not the same as
the last time
of course ;-)).
The story began basically like the last one: We received a call with an urgent
request to help investigating a toll fraud issue. Like the last time I visited
the site in order to get an idea on what was going on exactly. The customer has
a VoIP deployment consisting of the whole UC Suite Cisco offers: Call Manager,
Unity Connection for the voice mailboxes, Cisco based Voice-Gateways and of
course, IP phones.
Visual Voicemail (VVM) is a common feature of phone providers which allows
accessing the good old voice-mailbox through the phone’s visual interface. In
contrast to the classical voicemail approach, VVM allows intuitive navigation
through voice-messages without dealing with an automated voice which tells you
about message count and possible options. However, this implies the need of
actually loading the messages of missed calls on the phone. The VVM-app displays
missed calls and downloads corresponding messages which have been left by the
initial caller. The software comes with your iPhone and is not intended for
uninstallation. However, providers have to support it and will have to activate
it for supporting clients. This feature is available on iPhones since August
2009 and became available on BlackBerrys and few Nokia phones later. Android
doesn’t implement VVM in general. However some telecommunication providers offer
their own apps to add this feature. Since version 4.0, Android offers an
official Voicemail Provider API enabling better integration for the mobile OS.
I’m currently involved in creating an up to date approach to handling external
connections (read: temporary/permanent connections with external parties like
business partners) of a very large enterprise. Currently they have sth along the
lines of: “there’s two types of external connections, trusted and untrusted. the
untrusted ones have to be connected by means of a double staged firewall”.
Which – of course – doesn’t work at all in a
VUCA
world, for a number of reasons (the demarcation between trusted and untrusted is
quite unclear – just think of mergers & acquisitions –; “business doesn’t like
implementing 2-staged firewalls in some part of the world where they just signed
the memorandum for a joint venture to build windmills in the desert”; firewalls
might not be the appropriate control for quite some threats anyway – see for
example slide 46 of
this presentation– and
so on). Not to mention that I personally think that the “double staged firewall”
thing is based on an outdated threat model, in particular when implemented with
two different vendors (for the simple reason that the added operational effort
usually is not worth the added security benefit. see
this post for
some discussion of the concept of “operational feasibility”…).
One of our customers called us recently and asked for some support in
investigating a toll fraud issue they encountered in one of their sites. Their
telecommunications provider had contacted them informing them that they had
accumulated a bill of 30.000€ over the last ten days.
Without knowing anything more specific, I drove to the affected site to get the
whole picture.
They have a VoIP deployment based on Cisco Unified Communications Manager (CUCM,
aka Call Manager) as Call Agent. The CUCM is connected via a H.323 trunk to a
Cisco 2911 ISR G2 which is acting as a voice gateway. The ISR has a primary rate
ISDN (PRI) Interface which is connected to the PBX of the telco. Furthermore
they use a feature called Direct-inward Dial (DID) or Direct Dial-in (DDI) which
is offered by Telco’s to enable calling parties to dial directly to an extension
on a PBX or voice gateway.
This is a guest post by the SAP security experts of BIZEC. Enjoy reading:
On March 20^(th), the first BIZEC workshop will be held
at the amazing Troopers conference in Heidelberg, Germany. For those still
unfamiliar with BIZEC: the business application security initiative is a
non-profit organization focused on security threats affecting ERP systems and
business-critical infrastructures.
The main goals of BIZEC are:
Raise awareness, demonstrating that ERP security must be analyzed
holistically.
Analyze current and future threats affecting these systems.
Serve as a unique central point of knowledge and reference in this subject.
Provide experienced feedback to global organizations, helping them to increase
the security of their business-critical information.
Organize events with the community to share and exchange information.
The
“BIZEC workshop at Troopers 2012”
will dive into the security of SAP platforms. Still to this day, a big part of
the Auditing and Information Security industries believe that Segregation of
Duties (SoD) controls are enough to protect these business-critical systems.
By attending this session, InfoSec professionals and SAP security managers will
be able to stop “flying blind” with regards to the security of their SAP
systems. They will learn why SoD controls are not enough, which current threats
exist that could be exploited by evil hackers, and how to protect their
business-critical information from cyber-attacks.
Once moreShmooCon is the place to be for some days in late
January. Great con, great people and five ERNW guys amongst them 😉
We regard Shmoo(Con) as one of the most important community events at all and it
allows us to meet fellow researchers from the US who we can’t easily sit down
with to chat very often.
And some lucky guys from ERNW will even continue the trip to head to San Diego
(!) for NANOG and
NDSS. Not to
mention they stay in some fancy beach resort ;-), while I myself fly back today.
(Getting older I don’t enjoy staying away from home for a week anymore and I
have been missing my kids since some days…)
It’s done. The exciting (and demanding) process of selecting talks for Troopers
is complete (for the record: second round of talk selection was
here,
the first
here).
We’re quite happy and looking forward to the event 😉
==================
Rodrigo Branco: Into the Darkness – Dissecting Targeted Attacks
The current threat landscape around cyber attacks is complex and hard to
understand even for IT pros. The media coverage on recent events increases the
challenge by putting fundamentally different attacks into the same category,
often labeled as advanced persistent threats (APTs). The resulting mix of
attacks includes everything from broadly used, exploit-kit driven campaigns
driven by cyber criminals, to targeted attacks that use 0-day vulnerabilities
and are hard to fend off – blurring the threat landscape, causing confusion
where clarity is most needed.