LAS ADQUISICIONES DE ARMAMENTO Y MATERIAL DE LOS MINISTERIOS MILITARES EN ALEMANIA ENTRE 1939 y
LICENCIAS DE FABRICACIÓN.
I. 1.8 Los Heinkel He 111 meteorológicos
Viruses are often spread as e-mail attachments. Attachments might be compressed files (such as ZIP files), programs (such as .exefiles), or documents. Once the file is executed, the virus is released. Executing the file can be done by opening or
viewing the file, installing and/or running a program attached to the file, opening an attached document, or decompressing a file.
Many e-mail software programs provide a “Preview” pane that allows users to view message contents without actually opening it.This is a problem when viewing HTML e-mail, which appears as a Web page and may contain malicious content. Viewing HTML documents has the same effect as opening an HTML message. Computers can then fall prey to any scripts, applets, or viruses within the message. For protection, e-mail software should be set to view plaintext messages or anti- virus software that scans e-mail before opening it.
Antivirus software provides real-time scans of systems regularly. For example, Norton AntiVirus, McAfee Viruscan, Microsoft’s Forefront for Exchange Server, and Trend Micro PC-cillin scan every four seconds for new e-mail messages with attachments. If HTML content is part of the message, real-time scans also detect viruses embedded in the message. Anti-virus software can be installed at the e-mail server level as well, providing—in the case of Exchange—attachment and body scanning of all messages in the Information Store, regardless of whether or not the message has been delivered. Symantec Mail Security, McAfee Groupshield, and TrendMicro ScanMail for Exchange all work on the Microsoft platform. Many manufacturers, including McAfee,TrendMicro, and Symantec, have provided hard- ware appliances that sit between routers, firewalls, and mail servers to scan mail traffic destined for a company mail server, regardless of the OS or mail platform.
N
OTEFor more information about the Melissa virus and other situations where viruses have lead to criminal action, see Scene of the Cybercrime: Computer Forensics Handbook(Syngress Publishing, ISBN: 1-931836-65- 5) by Debra Littlejohn Shinder.
Even if antivirus software is installed on a system, there is no guarantee that it will actually catch the virus. As seen in the case of the Melissa virus, when people downloaded the file called list.zipfrom the alt.sexnewsgroup, they were infected with the virus. Regardless of whether these people had antivirus software installed, the signature files for the software did not have any data on the Melissa virus. Until a virus is known and an antivirus solution is created, a virus can infect any com- puter using antivirus software.
Head of the Class...
Another common reason why a computer with antivirus software can be infected with viruses is because the signature files have not been updated. Antivirus software manufacturers release new signature files regularly, and it is up to users to download and update them.To make this simple, many manufacturers provide fea- tures to automatically update the signature files via Internet.
Zero Day Attacks
It might be observed that most viruses originate overseas. Typically, this provides antivirus vendors an opportunity to scramble and produce an update for their product that is “aware” of the threat and can detect its presence in an e-mail or system. However, regardless of how diligent an administrator is in the automation and updating of antivirus software, some viruses are released into the user community before antivirus ven- dors can respond with a protective solutions. This is called a Zero Day Attack, because the virus has not been propagating for even a day.
In this situation, the signature of the file/attachment can be used to create rules on e-mail systems and directory servers (Group Policy, in Active Directory) to block the utilization of a file with that signature. Of course, this requires that you first get the signature of the file.
Spam
Spamis unsolicited bulk e-mail (UBE), much like the advertisements and other junk e-mail that frequently fills home mailboxes. Spam is junk e-mail that rarely is of any interest to users, is never requested, and is sent by people you do not know. The origin of the name is ambiguous at best and goes back to the early days of the Internet and Bulletin Board Systems (BBSes) run on individual computers to which people dialed in directly. Some believe it came from computer users at the University of California who made a derogatory comparison between the pro- cessed lunchmeat product made by Hormel and e-mail that nobody wants. Others believe the term comes from the song by British comedy group Monty Python, which was about the ubiquity of spam.Whatever the exact source, spam is some- thing that is not likely to disappear from the Internet anytime soon.
Spam often comes from lists of e-mail addresses or software that sends thou- sands or millions of messages. Many legitimate businesses avoid soliciting customers this way, because people do not like receiving spam. Also, many ISPs specify that bulk e-mail is a violation of the contract between themselves and their customers, so they can shut down sites or disable the accounts of customers who send spam.
Furthermore, the FTC warns that many states have laws regulating the sending of unsolicited commercial e-mail, making “spamming” illegal. Spam is considered to be a Denial of Service (DoS) attack since it has the ability to disable e-mail servers by overloading e-mail storage with junk messages.
E-mail users can deal with spam in a number of ways. One method is to read the spam message to see if there is a method of removing addresses from the mailing list. Legitimate companies will remove users from their mailing lists; how- ever, many spam mailers use these links to verify that the e-mail addresses the mes- sage was sent to are “live” addresses. Users may be removed from the list, but their e-mail is almost always sold again as it has been confirmed as a “live” address.
Another method of avoiding spam is by disabling cookies. Cookies are small text files sent by some Web sites that contain information about the user, and are stored in a folder on the user’s computer. Cookies are commonly associated with Internet browsers that access Web pages, but, because many e-mail programs allow users to accept messages in HTML format, HTML e-mails may contain cookies as well. Plaintext messages are safer than HTML messages because they are not capable of storing cookies and other damaging content.
Users can also contact companies they routinely deal with and ask them not to share or sell their information. Generally, privacy policies outline whether compa- nies share or sell client information. If they do share or sell information, the user has to decide whether or not to use those sites.
Spam filtersare programs that analyze the contents of messages to see if they have the common elements of spam. If a message does contain some of those ele- ments, the spam filter deals with the message in a specific way. For example, users can configure the filter to add the word spamto the subject line, so they know that the message is spam. Many antivirus vendors and hardware vendors (e.g., firewall and appliance like Barracuda) manufacture solutions that sit in the flow of traffic and filter this type of threat before it ever reaches the mail server. However, before investing in such software, users should visit the Web site of their ISP. Many ISPs offer spam detection and elimination services, in which spam-like e-mail is deleted on the server.This saves the ISP the cost of using bandwidth to send users e-mail they do not want. In addition, more and more clients are “spam aware.” Outlook 2003, 2007, and Windows Mail (the replacement for Outlook Express in Windows Vista) all utilize the Intelligent Message Filter spam detection software that is built into Exchange servers.These filters update their “knowledge” of what may or may not be spam not by what a user does, but by what Microsoft learns from its Hotmail and MSN mail communities, providing a nearly enterprise-level solution for desktop users.
Hoaxes
E-mail hoaxes are those e-mails sent around the Internet about concerned parents desperately searching for their lost children, gift certificates being offered from retail stores for distributing e-mails for them, and dangerous viruses that have probably already infected the user’s computer.
There are a lot of different ways to separate hoaxes from real information. Most of the time, it comes down to common sense. If users receive e-mail that says it originated from Bill Gates who is promising to give $100 to everyone who for- wards the e-mail, it is probably a hoax.The best rule of thumb is timeless—if some- thing seems too good to be true, it probably is.If a user is still not sure of the validity of an e-mail message, there are plenty of sites on the Internet that specialize in hoaxes. One of the more popular sites is www.snopes.com.
Virus hoaxes are a little different.Virus hoaxes are warnings about viruses that do not exist. In these cases, the hoax itself becomes the virus because well-meaning people forward it to everyone they know. Some virus hoaxes are dangerous, advising users to delete certain files from their computer to “remove the virus,” when those files are actually very important OS files. In other cases, users are told to e-mail information such as their password (or password file) to a specified address so the sender can “clean” the system of the virus. Instead, the sender will use the informa- tion to hack into the user’s system and may “clean” it of its valuable data.
How do users know whether a virus warning is a hoax? Since users should never take a chance with viruses, the best place to go is to the experts—the anti- virus companies. Most anti-virus companies have information on their Web sites that list popular e-mail hoaxes.The most important thing to remember about e- mail hoaxes is to neverfollow any instructions within the e-mail that instructs users to delete a certain file or send information to an unknown party.
Phishing
Phishing is a fairly new threat to the e-mail community.The basis of phishing is that there is a “lure” provided in the malicious e-mail, but not actually a virus.Where viruses can easily be detected because of their typically executable or “zipped” state, Phishing attempts are e-mails that are more or less completely benign.
Typically, the e-mail is drafted in such a way as to convey a sense of safety and security.Where some viruses fed on human curiosity with promises of attachments filled with pornographic images, phishing attempts often assert that they are the “Customer Service” department of your bank or the “Security Council” for a
partner organization.They often address the reality of Internet security threats within their e-mails!
It is what happens next that should alert the unsavvy user. A phishing e-mail often has a link to a site. Either within the e-mail or at the site, the victim is asked to simply provide two or three pieces of information to “update” their files, secu- rity setting, and so forth. Often, there is the indication that non-compliance will result in a loss of service to the individual (e.g. their ATM card will no longer work).The site, while designed very professionally and modestly, is simply an entry point for personal data that is sent all around the globe for the purposes of identity theft and fraud.
The nature of phishing has required a new approach to protecting and edu- cating the user community, and that has been in the combining of those two ele- ments. Microsoft’s latest release of Internet Explorer, IE7, includes a Phishing Filter that is updated by black lists maintained by Microsoft (Figure 3.15).This filter will block access, alert, and provide information on what threat may be on the Web site that the unsuspecting user is attempting to access.The filter will alert if the site is already flagged in its cache, or a user may choose to check the site before pro- ceeding.
The Phishing Filter is integrated into Windows Mail, the free mail client on Windows Vista, enabling mail client service that will prompt and block anything flagged as a phishing attempt, regardless of whether or not the message is clean from a virus point of view (Figure 3.16).
Figure 3.16 Phishing Filter Integrated Into Free Mail Client in Windows Vista Alerts Users
E
XAMW
ARNINGThe top ten items about e-mail security to remember for the Security+ exam are:
1. S/MIME looks to the headers to determine how data encryption and digital certificates are to be handled.
2. S/MIME messages are encrypted using a symmetric cipher (method of encrypting text), and a public-key algorithm is used for key exchange and digital signatures.
3. PGP uses a combination of public and private keys to secure e- mail.
4. PGP uses public key cryptography, which uses a “secret” or “pri- vate” key to encrypt and decrypt messages.
5. Using an open SMTP relay server gives a spammer free reliable delivery of their messages.
6. Fixes for SMTP relay are available for Microsoft and UNIX e-mail servers.
7. New e-mail servers that come with SMTP relay are disabled by default.
8. Spam is unsolicited e-mail messages, much like the advertise- ments and other junk e-mail that frequently fills home mail- boxes.
9. Users must know the methods for reducing the amount of spam they receive.
10. Virus hoaxes are warnings about viruses that do not exist; in these cases, the hoax itself becomes the virus because well- meaning people forward it to everyone they know.
Summary of Security+ Exam Objectives
Secure communications are a necessity in today’s world, and there are many tools available to users to protect information and networks from being compromised. Knowing how these tools work and how certain tools differ from other tools should be your goal when studying for the Security+ exam.
Remote Access Security
Although technology has made huge strides in remote access security, there are still many problems.Technologies such as RAS servers, NAS,VPN, authentication servers like RADIUS,TACACS, and TACACS+, and others were designed to address these problems.
It is the security professional’s responsibility to ensure that everything possible has been done to secure their networks. Security professionals have to find the bal- ance between offering users the ability to work from remote locations, and
ensuring that the network is protected.The 802.1x standard is used for securing the transfer of messages between a user and an access point.When a wireless user (or supplicant) wants to access a wireless network, 802.1xforces them to authenticate to a centralized authority called an authenticator. 802.1xuses the Extensible Authentication Protocol (EAP) for passing messages between the supplicant and the authenticator.The authenticator sends a request to the user requesting their identity.The client returns their identity to the authenticator, which is forwarded to an authentication server for verification.
VPNs use secure tunnels to allow remote users to connect to a network.VPNs can be configured in two forms: site-to-site VPNs or remote access VPNs.VPNs use IPSec, PPTP, or L2TP as the tunneling protocol. A tunnel is created by wrap- ping (or encapsulating) a data packet inside another packet and transmitting it over a public medium. PPTP is a Layer 2 (Data Link Layer) encapsulation (tunneling) protocol using port 1723 and TCP for its transport protocol. L2TP is also a Layer 2 encapsulation protocol, but uses port 1701 and UDP. IPSec utilizes one of two pro- tocols: AH or ESP in one of two modes—transport mode or tunnel mode. IPSec is “a framework of open standards for ensuring private, secure communications over IP networks, through the use of cryptographic security services.”
IPSec can be implemented in either tunnel mode or transport mode. IPSec uses IKE to manage keys and authenticate the two ends of a secure tunnel before IPSec transmissions begin. IPSec is made up of two separate security protocols: the (AH) and the ESP. IPSec offers nonrepudiation through the use of digital signatures. A
RAS authenticates a user, which means they determine who a user is. A RAS also authorizes the functions the authenticated user may perform. A RAS logs the actions of the user for the duration of the connection. RADIUS was designed to handle the authentication and authorization of dial-in users.
RADIUS is the most popular of all the AAA servers, which include RADIUS, TACACS,TACACS+, and DIAMETER.TACACS is another RAS developed during the days of ARPANET. Although TACACS offers authentication and autho- rization, it does not offer any accounting tools.TACACS+ is a proprietary version of TACACS that was developed by Cisco.TACACS+ is considered proprietary because the packet formats are completely different from those in either TACACS or XTACACS, making it incompatible with previous versions.TACACS+ is cred- ited with separating the AAA functions. Unlike previous versions (as well as
RADIUS) that used one database for AAA,TACACS+ uses individual databases for AAA.TACACS+ was the first revision to offer secure communications between the TACACS+ client and the TACACS+ server. Another difference between RADIUS and TACACS is that TACACS+ uses TCP as its transport instead of UDP.
Another tool that can be used to secure remote communications is SSH. SSH is a cryptographically secure replacement for standard Telnet, rlogin, RSH, and RCP commands. It consists of both a client and server that use public-key cryptography to provide session encryption. It also provides the ability to forward arbitrary ports over an encrypted connection. SSH is concerned with the confidentiality and integrity of the information being passed between the client and the host. Using SSH helps protect against many different types of attack, including packet sniffing, IP spoofing, and the manipulation of data by unauthorized users.
There are several vulnerabilities that can be exploited in RAS. Eavesdropping