Reply needed 1 One major attack reported between 2001 and 2003 was the Code Red Worm buffer overflow. This overflow compromised a tremendous amount of systems in the Microsoft Internet Information servers. Another major attack reported was the SQL Slammer worm which compromised computers running the Microsoft SQL server 2000. After these buffers were compromised Windows revamped their security focus when these major attacks were occurring around 2001. However, buffer overflow attacks are still a consistent threat to the company. In recent years, there was a buffer overflow in a Linux driver which left millions of routers vulnerable to attacks. This is a serious issue that needs to be combatted (Rouge, 2016).
Rouge, M. Buffer overflow. 2016. Retrieved from: http://searchsecurity.techtarget.com/definition/buffer-overflow
Reply needed 2 A wiper is a malware whose single purpose is to destroy or disrupt a system and/or data. Some wipers will destroy the system but not the data and vice versa. There is no financial motivation in wiper attacks unlike ransomware attacks which holds the data for ransom. Wipers can vary from overwriting files to the destruction of the entire file system.
Nyetya was an attack that was launched in June 2001. Nyetya was a targeted attack that used the supply chain as a means of attack. Nyetya was deployed through software update systems for a tax software package. This software was used as a way to execute their own code in the victims system. The malware had access to the victims system for several months then a highly destructive payload with effective spreading mechanisms was released. The payload was designed to deceive investigators as to the identity of the authors and it took advantage of legitimate Windows protocols and tools. Using a password harvesting tool to obtain the victims credentials it was able it mimic the victims usual behavior so it was hard to detect anything was wrong. It also adjusted its destruction mechanisms to the anti-virus present on the victims system.
Nyetya used the remote code vulnerability nicknamed EternalBlue and the remote code execution nicknamed ExternalRomance to destroy the victims system. Nyetyas payload used two methods to ensure file destruction. First, it encrypted the first megabyte of each file. Then if it had enough privileges it would replace the master boot record with a custom bootloader which would perform the file destruction completely bypassing the operating system.
A few ways to prevent or minimize the effects of a wiper attack are to keep your system up to date with the latest patches and fixes. Also have a cybersecurity incident response plan (CSIRP) to help you know what to do as a response to the malware. You should also have a cybersecurity-aware business continuity plan. This plan can contain plans to run backup software on non-Windows systems, how to segment the backup network and advice on using different usernames and passwords. A network and user segmentation plan is also a way to minimize or prevent wiper attacks. Segmenting the network gives the organizations the capability to contain malicious activities within a branch, factory or VLAN. Also not all users need to log onto all systems.Most cyber-attacks happen because vulnerabilitiesin system or application software. Buffer Overflow, SQL Injection, Code/OS Command Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery and Race Conditions are very common vulnerabilities. (Refer to both NIST/DHS and MITRE databases of common vulnerabilities (http://nvd.nist.gov/cwe.cfm; http://cwe.mitre.org/top25/).) For this conference, explain what a specific vulnerability is, describe a famous attack that leveraged it (For example, the Morris worm leveraged the buffer overflow vulnerability), and how it can be prevented/minimized.
Due Nov 2nd
I will be expecting two documents, one for the initial post and one for the replies. See attached for the replies needed








Recent Comments