Expert: E-ZPass vulnerabilities ignored at state’s peril

path

Three months after the state learned that the E-ZPass system was vulnerable to cyberattacks, it’s not even known if the issue has been addressed. State officials, from state cybersecurity chief Michael Balboni to Gov. Chris Sununu, have not responded to messages asking for updates, and E-ZPass’s default login still remembers user credentials. It is set to

To make matters worse, the company the state has hired to oversee cybersecurity, Portsmouth’s Atom Group, has its own vulnerability problems. UK-based Andy Jenkinson, a globally recognized cyber expert, tested his website for Atom Group and found several errors that allowed hackers to break into the site and obtain personally identifiable information (PII). I found

Jenkinson also tested the website of the town of Peterborough, which Primex, a municipal insurer, asked Atom Group to beef up after the town lost $2.3 million to internet scammers in 2021. to Jenkinson.

City of Peterborough administrator Nicole MacStay did not respond to a request for comment when provided the Jenkinson vulnerability chart.

Jenkinson had warned the Federal Aviation Administration that its computer system was vulnerable, but he said the agency ignored his warning. The cause of the system crash that temporarily brought the airline to a halt on Wednesday has yet to be determined, but Jenkinson said it could be an issue he didn’t listen to.

The problem is that even Internet technology experts are unaware of the links between Domain Name System (DNS) vulnerabilities and serious cyberattacks. It is generally believed that the most a hacker can achieve is to take over his website without access to company files.

Recognizing that the current voluntary approach has failed to protect the nation from cyberattacks, the federal government is moving towards comprehensive cybersecurity regulation with a particular focus on critical infrastructure. The government now mandates reporting of known issues and encourages, but does not enforce, measures to protect data.

The new directive requires weekly scanning of Internet assets such as domains, subdomains, servers and DNS. Jenkinson focuses on insecure DNS.

Risk

Jenkinson said in a LinkedIn post that while the U.S. is still taking “small steps” to secure the Internet, “they’re making it harder for cybercriminals to catch up with decades of DNS manipulation and exploitation to make cyberattacks.” I had to deal with the fact that I started ”

According to Jenkinson, “DNS is still very neglected, ignored, and ignored,” but more and more attacks are coming through these vulnerabilities. The attacks on the Ukrainian government, the FBI, LastPass, MediBank, and the highly publicized SolarWinds were all carried out via DNS vulnerabilities.

Trying to explain the complex problem in terms that a novice can understand, Jenkinson compared it to the local post office.

“The content delivery network is comparable to DHL or FedEx global delivery networks,” he says. “In both cases, ‘packets’ are delivered, but only packets of data are delivered in the digital world. All packets must be secure throughout their journey. …In its early days, DNS was designed purely for convenience, to allow humans to work with website addresses (letters) and computers to work with numbers (IP addresses). It didn’t take long for DNS operations to be understood and enabled for access, data capture, data collection, and even data modification on the fly. This exploitable vulnerability allows governments to collate, collect, monitor, and more.

“Towards the end of 2018/2019, just as the upgrade and enforcement of HTTP to HTTPS to enhance security coincided with the government’s decades-long Cybercriminals launched their own DNS attacks and began exploiting the exact same DNS vulnerabilities that institutions were blatantly exploiting.

“Many organizations, even security professionals, mistakenly think of their website as their final destination. I believe this often involves client PII data, this is a serious error, this is where the “tire hits the road” and can be easily exploited if unsafe because it is sexual. ”

Jenkinson used charts to show how easy it is to hack into an insecure DNS location and connect directly to a company’s website if you understand the process. Attackers can collect data and redirect users to malicious websites to obtain, modify, or repurpose data. This includes manipulating login her passwords and banning users from accounts and networks.

“By doing so, an attacker can obtain credentials, data, transactions, login details, emails, etc. of a company and its clients. are often completely undetected due to the lax security of Internet properties.”

“Once you achieve DNS takeover, you can host any service you like and log the entire process,” he said.

This article was shared by a partner of the Granite State News Collaborative. For more information, see: Collaborationnh.org.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *