After seeing as a mistake in the security of a web content manager such as Drupal and a couple of outdated plugins have resulted in the publication of customer and company data in what has been known as «Panama papers », Let's see some of the most famous computer security flaws of all time.
And it is that no operating system is free from suffering from time to time a security breach, which does not have to be catastrophic, but sometimes it does generate an important problem.Sooner or later, the design errors of the software can come to light and computer failures are no longer something generic, to become a specific problem.Let's see some of them.
Windows XP and the Sasser and Blaster viruses
The one now yearned for by many Windows XP had two very important security problems, which were used by the Sasser and Blaster viruses to infect millions of computers, causing computers to constantly restart and many companies had to deal with millionaire losses.They took advantage of the buffer overflow in RPC DCOM and spread through TCP, which in a few days its expansion grew exponentially throughout the world.
The effect was such that installing a computer with Windows XP without updating to a few minutes after it was infected .Fortunately, "vaccines" came out quickly and Microsoft soon published the necessary patch which solved this problem, at the same time that numerous security firms released updates of their products to eliminate the infection.Yes, the damage was already done.
Verisign, when the fault is a security company
Verisign is one of the most prestigious companies in the world at the time of issuing SSL certificates , which guarantee the identity of the websites, and in regards to domain validation and control.That is to say, it is responsible for certifying that the page we are visiting is authentic and not a forgery.In 2010 it suffered an attack that they did not report until 2011.
The problem was that no information or the indispensable minimum was provided, without knowing how much the company's systems were compromised.The hackers obtained access to the systems and privileged information , so Verisign certificates were compromised.
LastPass, WHAT if the master password is at risk?
Something similar happened in 2015 with LastPass.It is a password manager, which allows you to safely store all the passwords of the websites where we identify ourselves.The attackers had access to all LastPass systems exposing the master passwords of the users.
To improve security, after a short time, they set up a two-step verification system, so that in order to identify ourselves, in addition to the password, an additional code is needed that they send us to the mobile phone or that we generate through of the company's own app.
The DNS failure that affects all Internet
The researcher and security expert Dan Kaminsky detected a failure in the DNS that could compromise Internet security in 2008.Recently he has discovered another problem that allows web browsers to be deceived through the response of excessively long DNS names by part of the servers, causing a buffer overflow.
This allows to carry out attacks and execute remote code , so that it is possible to take control of the equipment.Correcting the problem for which a patch exists could take a long time, since it depends on the update of a Linux library, Glibc, the operating system used by many of the affected servers.
Stuxnet, there is always SOME INGENUO that connects a USB memory
Stuxnet can be considered the first information weapon .It was created by the governments of the United States and Israel to attack Iran’s nuclear enrichment program.USB sticks that distributed around the central area in the hope that someone, at some point, would connect it within the system.
And it happened.Somebody skipped all security protocols and connected an infected memory.tuxnet was programmed to cause a system malfunction, no messages appeared or a system restart, just the results of the enrichment of Uranium were not expected.This caused a delay of more than two years in the Iranian nuclear program.
Ashley Madison, the most private is made public
When a web service has discretion as its main claim, it cannot afford security problems.This is what happened to Ashley Madison, a social network designed to find new partners to be unfaithful to the current one.A security breach allowed a hacker to seize the database of all users.
I try to negotiate with the social network, but finally the lack of agreement caused the data to be made public , with the corresponding damage to its users and to the image of the company, which was seriously compromised, in addition to revealing some non-ethical practices.
Ransomware, you shouldn't have opened that email
One of the last problems we have had has been Ransomware attacks .In this case, they take advantage of the ignorance or confidence of users to open an email and run a program that is disguised as email notification, bank notice, etc.It's what is called social engineering , which seeks to gain the trust of the person on the other side of the keyboard to run a program.
From here, the files on the hard disk of the computer are encrypted , as well as the network drives that are connected, so if we want to recover the files, we can only pull backup or pay the ransom that they ask us to obtain the encryption password, something that on the other hand does not offer any guarantee.
The information security is a very sensitive issue .A good investment is needed to keep the systems up to date and secure, but it is not visible immediately, but is raised late, at the time it is verified that things did not do well after having suffered an attack.
Images | pixelcreatures | geralt | EssaRiuta | MasterTux
Comments
Post a Comment