
Sign up to save your podcasts
Or


In this very busy segment, Craig addresses a number of tech issues that are in the news right now. First off BEC scams. Business Email Compromises are also commonly known as Spear Phishing scams and target executives. In the past, many came from outside the US but this has changed. Next, he discusses what happened with Excel and the loss of some Covid data. Then he explains why the IRS is looking at Cryptocurrency on people's tax returns. So let's get into it!
For more tech tips, news, and updates, visit - CraigPeterson.com
---
FBI, DHS says hackers have gained access to election systems
The IRS Is Being Investigated for Using Location Data Without a Warrant
Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.
5G in the US averages 51Mbps while other countries hit hundreds of megabits
IRS may put cryptocurrency question at the top of 1040 to catch cheaters
Publishers worry as ebooks fly off libraries’ virtual shelves
25% of BEC Cybercriminals Based in the US
What's Really Happening in Infosec Hiring Now?
---
Automated Machine-Generated Transcript:
Craig Peterson (2): [00:00:00] Well, we've got a story here about how Excel may have lost some 16,000 potential COVID cases. A little story about the IRS and really happening in info security right now. Great career.
Hi, everybody listening to Craig Peterson.
Oh, cybersecurity. IT cybersecurity, I think is a great profession. It is a difficult profession. Don't get me wrong. I talk with people in IT all the time about how it is just kind of overwhelming. How they just got this major inferiority complex in Infosecurity understandably so. There's so much going on, it's a very high-stress job.
There is a great article that was out in Dark Reading earlier this year, talking about what was predicted for security roles going forward. Due to the pandemic scare, what matters.
Six months later, Dark Reading went back and had a look at it. What they've found is it's just as tough to fill open cybersecurity positions as it was pre-pandemic. In fact, there are new problems now that I, I hadn't really even thought about, frankly. 30% of businesses that responded to the survey said that their security teams are hiring now. 45% said that they need additional staff, but are restricted by hiring freezes or spending limits. So add those two together where it's 75% of companies are looking to get more cybersecurity people. 12% said that they were recently forced to cut security staff. Which is obviously in my view, more than a little short-sighted, right?
So they went in and started looking at it a little more deeply. It's a years-old story now, and it typically takes about eight months to replace a security analyst and about four months to train a replacement. There is right now a huge shortage of appropriately skilled workers. Others are claiming it's an unreasonable set of expectations amongst employers, and that job listings that are put out there are difficult to decipher.
I think that's funny considering its cybersecurity, right? Get it - decipher. I have thought long and hard about maybe offering some sort of cybersecurity training course. That's what the cybersecurity mastery thing is all about. Getting you the basics of cybersecurity and then have a couple of phone calls a month to answer questions that people have that are in the program.
That's the whole thing behind understanding cybersecurity or mastering cybersecurity program because employers want the right skill set. There just aren't enough people out there.
The pay is very good depends on what you consider good, I suppose. Right now for a not particularly well-skilled person, the salaries are in the hundred thousand dollars a year range, Which is why statistically looking at this whole thing a business that has fewer than 500 employees with standard revenue based on how much revenue per employee cannot afford a cybersecurity team. You just can't afford it because it's so darn expensive.
You're much better to find an outsource team. That'll do it for you. It'll save you a whole lot of money. So keep that in mind.
A business email compromise is a very, very big problem. We've talked about it before. FBI is talking about all of the hacks that have occurred via BEC. I've had firsthand experience with it that is how we picked up a couple of clients. We do a cyber health assessment for one company and this company had a few different servers and some desktop machines. We did a whole, what we call an NSAAP, which is a network security assessment and action plan.
So we gave them this action plan. These machines need to be upgraded. These machines this software needed to be upgraded. These machines were not properly protected. These ports were open. They shouldn't have been right. So it was a really good network plan for them. I think it was like 300 pages long of stuff they needed to do.
Again, this was a very small company. I think they've only got maybe three or four dozen employees and gave it to them. Thanks. Appreciate it. Bye-bye. Then we got a call from them. I don't know what was it? Eight months later because they had become, I'm a victim of a business, email compromise attack.
This happens all the time now. This is where someone sends an email pretending to be someone they're not usually within the organization, but sometimes they pretend to be a vendor. One of the attacks that I know of here, that's pretty common, comes out of Eastern Europe.
Hey, Mr. CFO. They send this while the owner, CEO, the president is out of town and unreachable, and they know that because the owner posted it on Facebook and the bad guys have been tracking the company for a little while and said, Oh, he's going to be down in Bermuda. This period of time in February.
So they send an email to the CFO and supposedly from the business owner, and there are methods they use so that they can use a legitimate email address, or it looks really like it is from the business owner. The email says something like, Hey, we started using this new vendor. We haven't paid their invoices. We're three months behind unless you wire this $120,000 that is going to go away and can really hurt the company. Can't deal with this right now. Please just go ahead and wire the money and then the CFO does it.
We saw this happen to Shark Tank's Barbara Cochran. You know her from Shark Tank. She's one of the sharks, big real estate investors. Her assistant got tricked into wiring out - Was it 300,000? I can't remember. It was a fair amount of money. She got tricked into wiring it overseas.
Now the FBI tells us that once that happens, 90 seconds later that money can no longer be recovered. It just disappeared. We have clients that have had the money disappear. Of course, we picked them up after it's disappeared, right? Just like this customer that did not do what we told him he should do. Right.
Even if they did it themselves, they would have been ahead of the game. They didn't have to hire us to do it. We gave them an action plan as part of our NSAAP evaluation. Right? They lost, last I heard, actually, it has gone up, a $180,000. So they lost money right out of their operating account. It got emptied and they also ended up incurring all kinds of fees and then they couldn't deliver some things. So they had problems with customers, right.? It just goes on and on and on.
This stat is something that was a bit of a surprise for me. There's a study that was just done looking at business email compromises and found that the attacks are coming one-quarter of them from the United States. One-quarter of all of the business emails is coming from the US. Of course, many times these people are caught by the FBI and end up in prison. But of these attackers located in the US, nearly half of them are in these five States, California, Georgia, Florida, Texas, and New York. So be very, very careful.
Interesting reports got information from more than 9,000 defense engagements from this year between May and July, right? 2200 of them, by the way, they could identify the likely location of the attackers. So interesting stuff. That's a problem.
IRS is saying that they may have a question and on the top of the new form, 1040 asking filers if they dealt in virtual currency in 2020, we talked about the IRS earlier in the show today. The IRS is concerned that people are making money off of these blockchain things, like Bitcoin, and are not reporting the capital gains that they had from these cryptocurrencies. So be careful with that. IRS is starting to take that very seriously.
Then COVID, we put all kinds of systems in place because of the panics around the Wuhan virus and worry about people having the COVID-19 symptoms. Apparently in the UK, more than 50,000 potentially infectious people may have been missed by the contract tracers. How?
Well, Microsoft has a million row limit on the Excel spreadsheet. Now, if you have a spreadsheet with a million rows in it, you are misusing spreadsheet software that really needs to be in a database somewhere. Okay. That's not something to do in a spreadsheet. Apparently what they were doing in the UK is hospitals, et cetera, or we're sending in spreadsheets. We're probably doing the same thing here in the US and then those spreadsheets are being pulled into one master spreadsheet and almost 16,000 positive tests were left off the official daily figures which translate to more than 50,000 potentially infectious people running around. A great little story from the guardian.
Again, all of this stuff is up on my website. I have a great newsletter people love, and I'd love to have you on it. Where I talk about these things. We do a little bit of training. I answer people's questions. You'll find it all @craigpetersohn.com slash subscribe. Make sure you're on that list so you can stay on top of these things.
Take care, everybody we'll be back next Saturday at one.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Good morning, everybody. I was on WTAG this morning with Jim Polito. We got into a lengthy discussion about Hunter Biden and the legitimacy of the emails and how to tell, also about computer repair shops and then a little about Steve Scully's tweet and his lies about it. Here we go with Jim.
For more tech tips, news, and updates visit - CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] That is a dead give away and these news agencies such as Fox who have seen both emails, I'm sure dug into it because they said these emails were legitimate because we now have a second source.
Hello everybody. Craig Peterson here. Thanks for joining me this morning with Mr. Polito. We did a deep dive into one topic and that is because of what's happened with Hunter Biden's computer.
What are your legal rights? What can you expect? What are these guys going to do?
I even reveal a company that I know that was doing something I consider very nefarious. So here we go with Jim.
Jim Polito: [00:00:42] You know, we're going to call a little bit of an audible here with our good friend, Craig Peterson, the Tech Talk guru cause we got a lot of stuff we could talk about.
How about cryptocurrency? The IRS tracking your location with all those things. But, we want to talk about Hunter's laptop. What it would mean for you? What's this all mean? Your data? So let's bring him on board. Our good friend, the tech talk guru. Craig Peterson. Good morning, sir.
Craig Peterson: [00:01:12] Hey, good morning, Jim.
Jim Polito: [00:01:13] Craig, you're the guy, you're the go-to guy for something like this. So let me just lay it out for you. So let's say it's not Hunter Biden. Let's say it's me. I bring my laptop to a repair shop. They give me a receipt that says, look, Jim, if you don't pick it up within 90 days, it's ours. Do they, can they really do that?
Then do they own all of my data? It's one day you own that piece of it equipment, right? Because it's a piece of equipment, but inside that piece of equipment, there's a lot of data. Do they own that? So I guess that's where I'd like to start with.
Craig Peterson: [00:01:50] Yeah. It's a very good question and many people just don't pay attention to.
Apparently, Hunter signed that receipt when he dropped it off saying, yeah, you don't makeup at 90 days, it's yours. This is similar to a mechanics lien where someone comes to your home does some repairs, maybe the oil company delivers oil. They now I have the ability to, without even your knowledge, go ahead and get a lien on your property. That's valid until it's paid for.
This is the case when it comes to computers as well. You leave that computer, particularly when they bring it up to you saying, Hey, listen, you have 90 days to pay after it's repaired and at that point it becomes ours. That's pretty darn common now.
As far as the data goes, Jim, there are some steps you should take in advance.
Also, one other thing that I have heard from someone who knew this first hand that I think people need to be aware of. That is some of these shops that you take your computers into. The one I'm thinking of is one that pretty much everybody knows it's a national chain. They have little deals going on where they'll get paid, this was the case as of a couple of years ago, if you bring the computer in and one of the technicians find something, like child pornography on that computer. It may not even know it's a child right there. It's crazy what they're doing with porn nowadays, but they get a $300 bonus for every computer where they look at the contents that are on that computer and then report it to law enforcement. There's bounties on our computers out there.
Jim Polito: [00:03:44] Wow. So I do remember that so-called organization. When you bring your computer in, we won't give them any at free advertising. Not that I would support anyone that would have child pornography on their thing, but that's interesting.
So I guess, uh, you, you bring your computer over there. It's you might as well as open it up. To the stranger and say, you can, you can look at whatever you want.
Craig Peterson: [00:04:15] Yeah. You know, I had a case, I was a witness, an expert witness in the case out of New Jersey, and in this case, it was also a computer that was found to have kiddie porn on it, apparently.
Here's the problem with this, Jim. You and I, we have our computers at home and our computers at the office as well. If you're a business like mine is we have servers. Very frequently what happens is our devices are taken over. They are controlled, remotely. There are remote controls. There's a whole name for that. That called rats, which is remote access or various types of remote access.
But anyway, they have been using our computers to share child pornography, to share pictures, videos of beheadings of Americans, of burning Americans to death inside this state. I'm not even gonna get into that horrific. On our computers using our business computers, our home computers that just were not properly secured.
So things are tough and there are some things you really should do before you take your computer to a repair shop for repairs. But in reality, you never really know what's on that computer unless you look at it thoroughly.
Jim Polito: [00:05:41] So what do you think the chances are that this is really his? Have you been following the story?
Craig Peterson: [00:05:49] Yeah, I've been following it pretty closely. Cause, of course, it does intersect with my business. Where we're trying to secure things and I think from everything I've seen, particularly now that there are corroborating emails from other people that we're in those email chains. I think it's legitimate.
The way you corroborate these emails isn't just, you look at the text of the emails. But you look at the headers of the emails. Every time an email goes through a server or goes through a mail filter it is assigned a unique serial number.
Jim Polito: [00:06:23] Ok.
Craig Peterson: [00:06:24] So. Any emails, probably gone through three, four, five different servers have these serial numbers. They're all timestamped. And putting those together makes that a very unique identifier for that email.
So if two people have emails that did go through the same servers and they will have at least gone through one server, that's the same. It will have a unique email. Oh, you don't see that. Normally if you're using outlook, you click on an email, you right-click on it and say view source, and then you can see it. But that is a dead giveaway.
These news agencies such as Fox who have seen both emails. I'm sure dug into it, because they said that these emails are legitimate because we now have a second source. There may be a third source very soon now.
Once you've got those types of sources and the serial numbers and the timestamps all match up. Now you've got corroboration that these are the legitimate emails
Jim Polito: [00:07:29] We're talking with Craig Peterson or a tech talk guru. You know what Craig, why not? Why not just switch to something else? Not Jeffrey Toobin. I promise you, I won't bring up Jeffrey Toobin and his Zoom call. But let's bring up somebody else.
Steve Scully, the reporter or the anchor for C-SPAN. He wrote a direct message to Anthony Scaramucci, the MOOCH, and he thought he was writing a direct message and he actually tweeted it and it exposed him as probably having a bias against the President. He was supposed to be the moderator for the second presidential debate. But he did the old, I don't understand why they do this. It's so stupid. I was hacked.
I mean I was waiting for Tobin to say that, but he was smart enough not to. I got hacked. That's ridiculous because you could tell me in no time at all if I had been hacked and determine whether or not I was telling the truth,
Craig Peterson: [00:08:31] This is an interesting problem, right? Here he is a public figure saying that his account was hacked. It looked like a legitimate message that he might send, right? It wasn't anything outlandish. It wasn't, Hey, send me $10,000 in Bitcoin and I'll send you 20,000 back.
Jim Polito: [00:08:48] Right.
Craig Peterson: [00:08:49] Which is very suspicious? Yeah. And when somebody likes Scully goes ahead and says, I was hacked and a police investigation gets started. That's when the ball really starts to roll. Apparently, the FBI has gotten involved in this. I'm not sure if charges will be coming. It is quite easy to figure out whether or not it's been hacked. If you have access to the account and the information. So C-SPAN suspended him after he admitted to lying.
But in this case, the only place that would really know would be Twitter who has logs of the TCPIP address, the home address, if you will of Scully. Where it was posted from? Where he usually posts from? They also have information about the GPS coordinates from once it was posted. You can tell a lot of this stuff now.
I mean it's such a stupid excuse to try and fall back on.
Yeah
Jim Polito: [00:09:55] You're going to get caught in a second. You really are. There are so many different ways to catch you for saying that. It's such stupid. As usual, Craig, I know this is outside of the realm of tech, but when you caught doing something wrong, don't cover it up because the coverup is often worse than a crime.
If Scully, just comes out and said, yeah, you know, I was asking for some advice. And it was no big deal. You know, it was no big deal. It story would have ended.
Craig Peterson: [00:10:26] What happened after that. Mr. Nixon.
Jim Polito: [00:10:33] Very good Craig. All right, Craig Peterson, folks, you can catch him on WTAG, WHYN Sunday mornings at 11 o'clock with a great show. Then Danny, Steve, and Kevin, they all drop the show in when there are other openings on the weekend. But, Craig, how do folks get in touch with you?
Craig Peterson: [00:10:53] Well, if you have any questions or you want to get on my newsletter where I cover all of these topics every week. Yeah, we are going to cover this whole Hunter Biden and what the steps are you should take when you take your computer to a repair shop, just go to Craigpeterson.com. If you sign up for my newsletter, I'm not going to beat you up on anything, right. This isn't a marketer thing. I. I really want to get the information out.
So just go to Craig Peterson slash subscribe. I get questions every week that I answer. In fact, I've been putting them in my newsletter the last few weeks with the answers, obviously not exposing who you are. I'm not including those message IDs. okay.
Really a lot of great information. Yeah. You can send the question to just me. M E @craigpeterson.com.
Jim Polito: [00:11:41] All right, Craig, it's always great to have you onboard, especially days like today. Always a pleasure. And we look forward to talking with you again.
Craig Peterson: [00:11:50] All right. Take care, Jim. Thanks. Bye. Bye.
I probably won't be back to WGAN is doing a post-election thing. They've got a little election going on, so I will be back this weekend. And although this is a crazy week, so what I'm going to do is have part of the show will be fresh and new, because I got to cover these going back to the repair shop things. I also might have a couple of segments that are best of as well. This weekend.
Take care, everybody. We'll talk again soon. Bye-bye.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome!
Good morning, everybody. I was on WTAG this morning with Jim Polito. We got into a lengthy discussion about Hunter Biden and the legitimacy of the emails and how to tell, also about computer repair shops and then a little about Steve Scully's tweet and his lies about it. Here we go with Jim.
For more tech tips, news, and updates visit - CraigPeterson.com
---Â
Automated Machine Generated Transcript:
Craig Peterson: [00:00:00] That is a dead give away and these news agencies such as Fox who have seen both emails, I'm sure dug into it because they said these emails were legitimate because we now have a second source.
Hello everybody. Craig Peterson here. Thanks for joining me this morning with Mr. Polito. We did a deep dive into one topic and that is because of what's happened with Hunter Biden's computer.
What are your legal rights? What can you expect? What are these guys going to do?
I even reveal a company that I know that was doing something I consider very nefarious. So here we go with Jim.
Jim Polito: [00:00:42] You know, we're going to call a little bit of an audible here with our good friend, Craig Peterson, the Tech Talk guru cause we got a lot of stuff we could talk about.
How about cryptocurrency? The IRS tracking your location with all those things. But, we want to talk about Hunter's laptop. What it would mean for you? What's this all mean? Your data? So let's bring him on board. Our good friend, the tech talk guru. Craig Peterson. Good morning, sir.
Craig Peterson: [00:01:12] Hey, good morning, Jim.
Jim Polito: [00:01:13] Craig, you're the guy, you're the go-to guy for something like this. So let me just lay it out for you. So let's say it's not Hunter Biden. Let's say it's me. I bring my laptop to a repair shop. They give me a receipt that says, look, Jim, if you don't pick it up within 90 days, it's ours. Do they, can they really do that?
Then do they own all of my data? It's one day you own that piece of it equipment, right? Because it's a piece of equipment, but inside that piece of equipment, there's a lot of data. Do they own that? So I guess that's where I'd like to start with.
Craig Peterson: [00:01:50] Yeah. It's a very good question and many people just don't pay attention to.
Apparently, Hunter signed that receipt when he dropped it off saying, yeah, you don't makeup at 90 days, it's yours. This is similar to a mechanics lien where someone comes to your home does some repairs, maybe the oil company delivers oil. They now I have the ability to, without even your knowledge, go ahead and get a lien on your property. That's valid until it's paid for.
This is the case when it comes to computers as well. You leave that computer, particularly when they bring it up to you saying, Hey, listen, you have 90 days to pay after it's repaired and at that point it becomes ours. That's pretty darn common now.
As far as the data goes, Jim, there are some steps you should take in advance.
Also, one other thing that I have heard from someone who knew this first hand that I think people need to be aware of. That is some of these shops that you take your computers into. The one I'm thinking of is one that pretty much everybody knows it's a national chain. They have little deals going on where they'll get paid, this was the case as of a couple of years ago, if you bring the computer in and one of the technicians find something, like child pornography on that computer. It may not even know it's a child right there. It's crazy what they're doing with porn nowadays, but they get a $300 bonus for every computer where they look at the contents that are on that computer and then report it to law enforcement. There's bounties on our computers out there.
Jim Polito: [00:03:44] Wow. So I do remember that so-called organization. When you bring your computer in, we won't give them any at free advertising. Not that I would support anyone that would have child pornography on their thing, but that's interesting.
So I guess, uh, you, you bring your computer over there. It's you might as well as open it up. To the stranger and say, you can, you can look at whatever you want.
Craig Peterson: [00:04:15] Yeah. You know, I had a case, I was a witness, an expert witness in the case out of New Jersey, and in this case, it was also a computer that was found to have kiddie porn on it, apparently.
Here's the problem with this, Jim. You and I, we have our computers at home and our computers at the office as well. If you're a business like mine is we have servers. Very frequently what happens is our devices are taken over. They are controlled, remotely. There are remote controls. There's a whole name for that. That called rats, which is remote access or various types of remote access.
But anyway, they have been using our computers to share child pornography, to share pictures, videos of beheadings of Americans, of burning Americans to death inside this state. I'm not even gonna get into that horrific. On our computers using our business computers, our home computers that just were not properly secured.
So things are tough and there are some things you really should do before you take your computer to a repair shop for repairs. But in reality, you never really know what's on that computer unless you look at it thoroughly.
Jim Polito: [00:05:41] So what do you think the chances are that this is really his? Have you been following the story?
Craig Peterson: [00:05:49] Yeah, I've been following it pretty closely. Cause, of course, it does intersect with my business. Where we're trying to secure things and I think from everything I've seen, particularly now that there are corroborating emails from other people that we're in those email chains. I think it's legitimate.
 The way you corroborate these emails isn't just, you look at the text of the emails. But you look at the headers of the emails. Every time an email goes through a server or goes through a mail filter it is assigned a unique serial number.
Jim Polito: [00:06:23] Ok.
Craig Peterson: [00:06:24] So. Any emails, probably gone through three, four, five different servers have these serial numbers. They're all timestamped. And putting those together makes that a very unique identifier for that email.
So if two people have emails that did go through the same servers and they will have at least gone through one server, that's the same. It will have a unique email. Oh, you don't see that. Normally if you're using outlook, you click on an email, you right-click on it and say view source, and then you can see it. But that is a dead giveaway.
These news agencies such as Fox who have seen both emails. I'm sure dug into it, because they said that these emails are legitimate because we now have a second source. There may be a third source very soon now.
Once you've got those types of sources and the serial numbers and the timestamps all match up. Now you've got corroboration that these are the legitimate emails
Jim Polito: [00:07:29] We're talking with Craig Peterson or a tech talk guru. You know what Craig, why not? Why not just switch to something else? Not Jeffrey Toobin. I promise you, I won't bring up Jeffrey Toobin and his Zoom call. But let's bring up somebody else.
Steve Scully, the reporter or the anchor for C-SPAN. He wrote a direct message to Anthony Scaramucci, the MOOCH, and he thought he was writing a direct message and he actually tweeted it and it exposed him as probably having a bias against the President. He was supposed to be the moderator for the second presidential debate. But he did the old, I don't understand why they do this. It's so stupid. I was hacked.
I mean I was waiting for Tobin to say that, but he was smart enough not to. I got hacked. That's ridiculous because you could tell me in no time at all if I had been hacked and determine whether or not I was telling the truth,
Craig Peterson: [00:08:31] This is an interesting problem, right? Here he is a public figure saying that his account was hacked. It looked like a legitimate message that he might send, right? It wasn't anything outlandish. It wasn't, Hey, send me $10,000 in Bitcoin and I'll send you 20,000 back.
Jim Polito: [00:08:48] Right.
Craig Peterson: [00:08:49] Which is very suspicious? Yeah. And when somebody likes Scully goes ahead and says, I was hacked and a police investigation gets started. That's when the ball really starts to roll. Apparently, the FBI has gotten involved in this. I'm not sure if charges will be coming. It is quite easy to figure out whether or not it's been hacked. If you have access to the account and the information. So C-SPAN suspended him after he admitted to lying.
But in this case, the only place that would really know would be Twitter who has logs of the TCPIP address, the home address, if you will of Scully. Where it was posted from? Where he usually posts from? They also have information about the GPS coordinates from once it was posted. You can tell a lot of this stuff now.
I mean it's such a stupid excuse to try and fall back on.
Yeah
Jim Polito: [00:09:55] You're going to get caught in a second. You really are. There are so many different ways to catch you for saying that. It's such stupid. As usual, Craig, I know this is outside of the realm of tech, but when you caught doing something wrong, don't cover it up because the coverup is often worse than a crime.
If Scully, just comes out and said, yeah, you know, I was asking for some advice. And it was no big deal. You know, it was no big deal. It story would have ended.
Craig Peterson: [00:10:26] What happened after that. Mr. Nixon.
Jim Polito: [00:10:33] Very good Craig. All right, Craig Peterson, folks, you can catch him on WTAG, WHYN Sunday mornings at 11 o'clock with a great show. Then Danny, Steve, and Kevin, they all drop the show in when there are other openings on the weekend. But, Craig, how do folks get in touch with you?
Craig Peterson: [00:10:53] Well, if you have any questions or you want to get on my newsletter where I cover all of these topics every week. Yeah, we are going to cover this whole Hunter Biden and what the steps are you should take when you take your computer to a repair shop, just go to Craigpeterson.com. If you sign up for my newsletter, I'm not going to beat you up on anything, right. This isn't a marketer thing. I. I really want to get the information out.
So just go to Craig Peterson slash subscribe. I get questions every week that I answer. In fact, I've been putting them in my newsletter the last few weeks with the answers, obviously not exposing who you are. I'm not including those message IDs. okay.
Really a lot of great information. Yeah. You can send the question to just me. M E @craigpeterson.com.
Jim Polito: [00:11:41] All right, Craig, it's always great to have you onboard, especially days like today. Always a pleasure. And we look forward to talking with you again.
Craig Peterson: [00:11:50] All right. Take care, Jim. Thanks. Bye. Bye.
I probably won't be back to WGAN is doing a post-election thing. They've got a little election going on, so I will be back this weekend. And although this is a crazy week, so what I'm going to do is have part of the show will be fresh and new, because I got to cover these going back to the repair shop things. I also might have a couple of segments that are best of as well. This weekend.
Take care, everybody. We'll talk again soon. Bye-bye.
---Â
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome,
Good Monday morning, everybody. Craig Peterson here. You will find here a different host this morning on NH Today. Jack Heath has moved on to another radio group. I was on with Scott Spradlin. We discussed election security in the light of revelations by the FBI and DHS about Nation-State Actors accessing our election systems through known vulnerabilities. Here we go with Scott.
These and more tech tips, news, and updates visit.
- CraigPeterson.com
---
Automated Machine Generated Transcript:
Craig Peterson: How vulnerable are the web pages where these final tallies are as well. So we've got now known nation-state hackers into our systems. We've got them into web sites as well, where the tallies are displayed. We've got to be very, very careful. Jack Heath has left, and now we have Scott Spradling and at least for the time being.
[00:00:23] I like Scott. He's a professional news guy reporter for many, many years, and that's who I was on with this morning. Jack has apparently moved to another radio network. So we'll see what happens with him there. Best of luck goes out to him. So here we are this morning with Scott Spradling.
[00:00:41] Scott Spradling: You've heard me on with him before, but I think it's been a little while. Let's talk a little bit about what the FBI is doing and how technology might be used to protect our elections' integrity. Craig Peterson from Tech Talk joins us now on the air.
[00:00:54] Good morning, Craig. How are you?
[00:00:56] Craig Peterson: Hey, good morning, Scott. And as you may know, I've been involved with the FBI for some years now. In fact, I ran there and their entire webinar program for what they call Infragard. And InfraGard is trying to get regular businesses all the way through government agencies, whereof what's going on out there.
[00:01:18]We've got a new one that just came out on Friday. It turns out that the FBI and the Department of Homeland Security have now confirmed that hackers and, in this case, nation-state hackers, which means countries like China and Russia and Iran, and maybe others, including North Korea, have gained actual access to our election systems.
[00:01:42]They went in, and they would use multiple vulnerabilities to get in over something I've been warning about on my show forever, and that is misconfigured VPN. So this isn't going to help matters.
[00:01:56] Scott Spradling: So how many States, and this is not a fair pop quiz.
[00:01:59]Approximately how many States have a lot of their voter type information or access to the totals electronically that are vulnerable. The reason I ask is that if nothing else, Bill Gardner has a system that is in my mind, largely offline. Cause if the electronics go sideways, we've got paper ballots as a backup.
[00:02:18] So we can hand count if we have to in New Hampshire and assure a good election result. Are a lot of States moving more towards paperless and then being vulnerable.
[00:02:29] Craig Peterson: Well, Justin brought up, of course, the year 2000 in the wonderful times we had passed then. That really woke up a lot of States. Many of the States are using that same system that Bill Gardener's using here. It's phenomenal. It's the only way to go, which are you fill out a paper ballot? It goes into a machine. It can be spot-checked to make sure the machine looks like it's accurate.
[00:02:53] Where the problem has been coming in that we're most worried about here is Scott, because so many have moved to that, is how the votes are finally tallied.
[00:03:02]In many States, what they do is the federal government go to the state's webpage to collect the totals. The question might be asked how vulnerable are the web pages, where these final tallies are, as well.
[00:03:19]We've got now known nation-state hackers into our systems. We've got them into websites, as well where the tallies are displayed. We've gotta be very, very careful. I, too, have heard Bill talk about what they're doing, and I think we're in pretty good shape. But we've got to pay a lot of attention here because the hackers really are after it. They're just trying to upset our election.
[00:03:44] I think they might be successful. Not to mention all of these other potential problems that are out there.
[00:03:50]Justin McIssac: One of the freelance jobs I used to have was going around and collecting election results from different towns in Rochester and then calling them into the AP.
[00:03:56]The way in New Hampshire works is. You get the fill in the circle thing, and you feed it into that machine, at the end of the voting cycle, that spits out a receipt, like an actual receipt telling you who got what.
[00:04:08] So almost like here's a real deep cut for sci-fi dorks. It's almost like an Admiral Adama situation where he had the Battlestar Galactica offline so the Cylons couldn't hack in. We don't have to go that far. Do we, Craig, take everything completely offline? If we have those types of backups with a physical paper printout, or what do you think?
[00:04:27] Craig Peterson: I think that's a pretty good way to do it and keep those ballots around and allow people to inspect them. I don't know if we have to go totally Admiral ADAMA on this. I am concerned that we have 50 individual state elections, and every state's doing it differently. Every state has different competencies, and that boils all the way down to what you were talking about, Justin. It's really the towns that are doing some of these tallies. I get a little bit worried about those things. Final tapes in some States they're using these touch screen devices, and then it spits out a little audit trail that looks exactly like what you might get at the grocery store. Those things fade over time. If someone leaves them on a dashboard, they will go black.
[00:05:11]I have a little less worry here in New Hampshire than I do for other States. Scott started by talking about what's going to happen nationwide. Will we know by that deadline on December 14th who the President is?
[00:05:24] I am very, very concerned because of an over-reliance on technology. These systems are hacked by the FBI and Homeland security. All of the hacks that happened. We're using software that had patches out. These were sometimes known four months and a couple of them for more than a year, but the local States and towns did not bother applying. So it's a real problem.
[00:05:52]Here in New Hampshire, we're great. We have these devices, and they are loaded with ROMs. One of my sons is a ballot inspector. He went and physically looked at the machine, although there were a couple of problems with the machines used in his precinct, the final device, a little memory stick, if you will, that's inside, that machine did have the right seals on it. It had not been tampered with when he checked it. So I like what we're doing.
[00:06:19] I think we got to pay a lot of attention.
[00:06:21] Scott Spradling: Good final thought. Hopefully, technology and paper ballots will combine nicely for a clear result with no debate by the time we're done at the end of election night, or at least within a couple of days. So we'll see.
[00:06:33] Craig Peterson: Yeah, that'll happen, Scott.
[00:06:34] Scott Spradling: I like it. I like your optimism. Craig Peterson from tech talk. Thank you so much. My friend, I appreciate you being on the air with us.
[00:06:42] Craig Peterson: Take Care. Saturday 1130. I'll be right back here.
[00:06:44] Scott Spradling: Excellent. We'll see you then. You're listening to New Hampshire Today.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Welcome,
Good Monday morning, everybody. Craig Peterson here. You will find here a different host this morning on NH Today. Jack Heath has moved on to another radio group. I was on with Scott Spradlin. We discussed election security in the light of revelations by the FBI and DHS about Nation-State Actors accessing our election systems through known vulnerabilities. Here we go with Scott.Â
These and more tech tips, news, and updates visit.
-Â CraigPeterson.com
---Â
Automated Machine Generated Transcript:
Craig Peterson: How vulnerable are the web pages where these final tallies are as well. So we've got now known nation-state hackers into our systems. We've got them into web sites as well, where the tallies are displayed. We've got to be very, very careful. Jack Heath has left, and now we have Scott Spradling and at least for the time being.
[00:00:23] I like Scott. He's a professional news guy reporter for many, many years, and that's who I was on with this morning. Jack has apparently moved to another radio network. So we'll see what happens with him there. Best of luck goes out to him. So here we are this morning with Scott Spradling.
[00:00:41] Scott Spradling: You've heard me on with him before, but I think it's been a little while. Let's talk a little bit about what the FBI is doing and how technology might be used to protect our elections' integrity. Craig Peterson from Tech Talk joins us now on the air.
[00:00:54] Good morning, Craig. How are you?
[00:00:56] Craig Peterson: Hey, good morning, Scott. And as you may know, I've been involved with the FBI for some years now. In fact, I ran there and their entire webinar program for what they call Infragard. And InfraGard is trying to get regular businesses all the way through government agencies, whereof what's going on out there.
[00:01:18]We've got a new one that just came out on Friday. It turns out that the FBI and the Department of Homeland Security have now confirmed that hackers and, in this case, nation-state hackers, which means countries like China and Russia and Iran, and maybe others, including North Korea, have gained actual access to our election systems.
[00:01:42]They went in, and they would use multiple vulnerabilities to get in over something I've been warning about on my show forever, and that is misconfigured VPN. So this isn't going to help matters.
[00:01:56] Scott Spradling: So how many States, and this is not a fair pop quiz.
[00:01:59]Approximately how many States have a lot of their voter type information or access to the totals electronically that are vulnerable. The reason I ask is that if nothing else, Bill Gardner has a system that is in my mind, largely offline. Cause if the electronics go sideways, we've got paper ballots as a backup.
[00:02:18] So we can hand count if we have to in New Hampshire and assure a good election result. Are a lot of States moving more towards paperless and then being vulnerable.
[00:02:29] Craig Peterson: Well, Justin brought up, of course, the year 2000 in the wonderful times we had passed then. That really woke up a lot of States. Many of the States are using that same system that Bill Gardener's using here. It's phenomenal. It's the only way to go, which are you fill out a paper ballot? It goes into a machine. It can be spot-checked to make sure the machine looks like it's accurate.
[00:02:53] Where the problem has been coming in that we're most worried about here is Scott, because so many have moved to that, is how the votes are finally tallied.
[00:03:02]In many States, what they do is the federal government go to the state's webpage to collect the totals. The question might be asked how vulnerable are the web pages, where these final tallies are, as well.
[00:03:19]We've got now known nation-state hackers into our systems. We've got them into websites, as well where the tallies are displayed. We've gotta be very, very careful. I, too, have heard Bill talk about what they're doing, and I think we're in pretty good shape. But we've got to pay a lot of attention here because the hackers really are after it. They're just trying to upset our election.
[00:03:44] I think they might be successful. Not to mention all of these other potential problems that are out there.
[00:03:50]Justin McIssac: One of the freelance jobs I used to have was going around and collecting election results from different towns in Rochester and then calling them into the AP.
[00:03:56]The way in New Hampshire works is. You get the fill in the circle thing, and you feed it into that machine, at the end of the voting cycle, that spits out a receipt, like an actual receipt telling you who got what.
[00:04:08] So almost like here's a real deep cut for sci-fi dorks. It's almost like an Admiral Adama situation where he had the Battlestar Galactica offline so the Cylons couldn't hack in. We don't have to go that far. Do we, Craig, take everything completely offline? If we have those types of backups with a physical paper printout, or what do you think?
[00:04:27] Craig Peterson: I think that's a pretty good way to do it and keep those ballots around and allow people to inspect them. I don't know if we have to go totally Admiral ADAMA on this. I am concerned that we have 50 individual state elections, and every state's doing it differently. Every state has different competencies, and that boils all the way down to what you were talking about, Justin. It's really the towns that are doing some of these tallies. I get a little bit worried about those things. Final tapes in some States they're using these touch screen devices, and then it spits out a little audit trail that looks exactly like what you might get at the grocery store. Those things fade over time. If someone leaves them on a dashboard, they will go black.
[00:05:11]I have a little less worry here in New Hampshire than I do for other States. Scott started by talking about what's going to happen nationwide. Will we know by that deadline on December 14th who the President is?
[00:05:24] I am very, very concerned because of an over-reliance on technology. These systems are hacked by the FBI and Homeland security. All of the hacks that happened. We're using software that had patches out. These were sometimes known four months and a couple of them for more than a year, but the local States and towns did not bother applying. So it's a real problem.
[00:05:52]Here in New Hampshire, we're great. We have these devices, and they are loaded with ROMs. One of my sons is a ballot inspector. He went and physically looked at the machine, although there were a couple of problems with the machines used in his precinct, the final device, a little memory stick, if you will, that's inside, that machine did have the right seals on it. It had not been tampered with when he checked it. So I like what we're doing.
[00:06:19] I think we got to pay a lot of attention.Â
[00:06:21] Scott Spradling: Good final thought. Hopefully, technology and paper ballots will combine nicely for a clear result with no debate by the time we're done at the end of election night, or at least within a couple of days. So we'll see.
[00:06:33] Craig Peterson: Yeah, that'll happen, Scott.
[00:06:34] Scott Spradling: I like it. I like your optimism. Craig Peterson from tech talk. Thank you so much. My friend, I appreciate you being on the air with us.
[00:06:42] Craig Peterson: Take Care. Saturday 1130. I'll be right back here.
[00:06:44] Scott Spradling: Excellent. We'll see you then. You're listening to New Hampshire Today.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses a new Phishing Scam that is targeting Republicans with a legitimate email but that adds an attachment with a nasty trojan payload.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Trojan Malware Targets Trump Supporters
Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0
Tyler Technologies finally paid the ransom to receive the decryption key
5G in the US averages 51Mbps while other countries hit hundreds of megabits
Apple's T2 security chip has an unfixable flaw
Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance
Android Ransomware Has Picked Up Some Ominous New Trick
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Hi, everybody. We're going to be talking about some new Trojan malware that targets Trump supporters. Some new tools that are out there. Ransomware being paid by one of the country's biggest online providers right here.
Hey everybody. I'm Craig Peterson. Today we are going to with no exception, get into some of the things that you need to know. Some of the things that you might not really be aware of, you've always wanted to know, but I'm here to explain it to you. This is the sort of stuff I like to do, and I've done pretty well for many years.
So let's get right into this malware. We've talked about phishing before and for a quick introduction for the rest of you guys, phishing is where someone is trying to get you to do something and they are just trying to trick you into it.
So you might be familiar with some of the old phishing staff, the Nigerian Prince scam nowadays, they've gotten much more sophisticated, try and get you to click on a link to do that something. So they might be phishing so they can put a Bitcoin miner on your computer.
They might be phishing to do something malicious, maybe. very malicious right now. There are some bad guys out there who are phishing Trump supporters. Here's what they're doing.
They're taking legitimate emails that have been sent out by other Trump supporters. Some of these political action committees. That is really single focused on one thing or another, and they'll be supporting a candidate that supports their, so there's these PACs on both sides of the aisle and all the way in between. All right.
The biggest problem, if you ask me about DC is, that's where the money goes and so that's where all the attention goes.
So you're online. You're looking at your email and you see an email that has a subject line that starts with forward. I got to point out in case you weren't aware of it, subject lines that start with forward, like FWD colon, or re R E colon, as in regards to. Those subject lines tend to attract a lot of attention. The only subject line that tracks more attention is if someone has your name in that subject line.
So these emails that are being sent out by, we're not sure who yet have. Forward or re: up in the subject line and, we'll talk a little bit more about what is in that subject line. So there are things like breaking President, Trump, suspends funding to the WHO that is one of the most common ones they're using right now.
Of course, we're looking at President Trump and he's been calling the world health organization corrupt and seen an email like this would get you to open it. Wouldn't it? You know what, frankly, between you and me, so would people on the other side of the aisle, right? Cause they want to hear what's Trump doing this time.
So the idea, yeah, it is it's political. Another one is an email with a subject line that says stand with Trump again, that's definitely targeted at Republicans who want to open it because they want to stand with President Trump. And they're also using something called display name spoofing.
If you look at emails, you receive, you'll see, it says it's from so and so. Well, that's not necessarily who it's actually from there's some spoofing you can do there and a lot of these guys are doing it. There are ways to block phishing. Phishing, by the way, it's used a lot by ransomware. That's not what this is. We'll get into what this is exactly a minute.
But you've got to have some really great stuff in place. Hey, if you're interested in it. our friend of mine, Guy, he had sent me a thing on LinkedIn this week about that's a really great little ransomware checklist. It goes through the basics of what you should be doing to protect yourself against ransomware.
And if you want me to. I'll dig it up for you and send it off. Just email [email protected] and in the subject line put ransomware. I'll notice that. I will, I'll send it to you. Just send it to [email protected]. And it's a great little checklist on ransomware, and it's telling you should be doing things if you are a system administrator like looking for specially signed DNS records and other things that are going to help identify the reality of who they're talking to. Very important. DMark is one of those types of tools.
Now they are also using hijacked legitimate, the email addresses, and they'll use those to send out these emails. So they'll take an email from a PAX, a legitimate email. They will forward it, quote-unquote to you. It looks like a foreword for all intents and purposes. It is, and it has all of the links in it that the original email had and all of those links, some, the original email will work and they'll take you to the places that you expect to go to. The problem with this one is that they have a word document attached. Not that having a word document attached isn't necessarily a huge problem. We've had problems in the past where it was effectively a drive-by download. Sometimes you did not even have to open the email in order to get the infection nowadays unless you have very out of date software nowadays, you do have to open it.
So if you get that email, you click on the attachment. You open the attachment. That's when the real pain starts, because inside that attachment is a Microsoft word document that has something inside of it called the downloader. So you open up that document down comes EmoTet and once Emotet is on your system, that's when it all hits the fan.
What happens with EmoTet is really nasty. It starts to try and spread within your network. It scans for open services. I'm looking at a whole chart here on EmoTet which is known as S zero three six seven. It'll start to scan ports on all of the systems on your network, on your own system. It uses the most common ports that you might think of port 80, 80, 84, 43.
In one instance, it has used. port four, four, five, which is an SMB exploitation. SMB is windows file sharing. So it uses a number of different types of attacks here to go after services that are available on your network, on your computer, and on your network. And then it spreads laterally and it starts to scan other machines.
This is where EmoTet is different than some of the others. It acts like a worm. And that's the very first piece of malware I had. That's what got me going on cybersecurity. Cause back then, I'm pretty much, nobody had even heard of a worm before.
What a worm is for those that don't know. Is it some piece of software that gets onto one computer and tries to crawl through other computers all the way out?
Now you can see where the problem comes in because it now will try using all of these different protocols, try and get onto another computer. Now we can get on another computer as simple as getting onto your file server.
Are you using the VPN in your business operation? A lot of our people are at home. This is one of the real dangers of VPNs. VPNs do not make you safer. Don't think that they make you safer because in almost no cases, do they help with the safety. What's gonna happen with the VPN, if you're connected, is something like EmoTet or some of these others that spread like worms are going to try and crawl through your VPN to the other side.
You say, Oh, we've got a firewall quote, unquote, in the other side, We've got a SonicWall, we've got whatever it might be.
Is that configured to stop a worm from crawling through and getting into other machines? And you might say, Yes. Yes, of course, it is. We block out all other servers that user at home only has access to the file server and their own computer acting as a file server isn't that just hunky Dory. The problem is it has access to the file server. Your typical ransomware even is going to start pulling files off of the file server, sending them over to Eastern Europe for examination to see if they can use it for extortion or to see if they want to use it for ransom, just hold the encrypted and hold your data ransom. All of that stuff can happen over your VPN. Just as if you're sitting there locally at the office.
Remember that you've got to have all of your security, not just in the office, not just maybe at the edge of the firewall, but everywhere.
We're setting up systems now, that one packet will be examined five times as it flows through different firewalls within the organization. So that someone who's sitting there working on something is going to have to go in and out of firewalls just to get to that server.
It's not just the packets that are examined nowadays. We're talking about having the data examined, completely reassembling the streams, and looking at it and looking at it all very closely.
Hey, you're listening to Craig Peterson stick around because we will be right back. We're going to be talking about a new scanning tool release and what that's all about. So stick around.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses a new Phishing Scam that is targeting Republicans with a legitimate email but that adds an attachment with a nasty trojan payload. Â
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Trojan Malware Targets Trump Supporters
Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0
Tyler Technologies finally paid the ransom to receive the decryption key
5G in the US averages 51Mbps while other countries hit hundreds of megabits
Apple’s T2 security chip has an unfixable flaw
Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance
Android Ransomware Has Picked Up Some Ominous New Trick
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Hi, everybody. We're going to be talking about some new Trojan malware that targets Trump supporters. Some new tools that are out there. Ransomware being paid by one of the country's biggest online providers right here.
Hey everybody. I'm Craig Peterson. Today we are going to with no exception, get into some of the things that you need to know. Some of the things that you might not really be aware of, you've always wanted to know, but I'm here to explain it to you. This is the sort of stuff I like to do, and I've done pretty well for many years.
So let's get right into this malware. We've talked about phishing before and for a quick introduction for the rest of you guys, phishing is where someone is trying to get you to do something and they are just trying to trick you into it.
So you might be familiar with some of the old phishing staff, the Nigerian Prince scam nowadays, they've gotten much more sophisticated, try and get you to click on a link to do that something. So they might be phishing so they can put a Bitcoin miner on your computer.
They might be phishing to do something malicious, maybe. very malicious right now. There are some bad guys out there who are phishing Trump supporters. Here's what they're doing.
They're taking legitimate emails that have been sent out by other Trump supporters. Some of these political action committees. That is really single focused on one thing or another, and they'll be supporting a candidate that supports their, so there's these PACs on both sides of the aisle and all the way in between. All right.
The biggest problem, if you ask me about DC is, that's where the money goes and so that's where all the attention goes.
So you're online. You're looking at your email and you see an email that has a subject line that starts with forward. I got to point out in case you weren't aware of it, subject lines that start with forward, like FWD colon, or re R E colon, as in regards to. Those subject lines tend to attract a lot of attention. The only subject line that tracks more attention is if someone has your name in that subject line.
So these emails that are being sent out by, we're not sure who yet have. Forward or re: up in the subject line and, we'll talk a little bit more about what is in that subject line. So there are things like breaking President, Trump, suspends funding to the WHO that is one of the most common ones they're using right now.
Of course, we're looking at President Trump and he's been calling the world health organization corrupt and seen an email like this would get you to open it. Wouldn't it? You know what, frankly, between you and me, so would people on the other side of the aisle, right? Cause they want to hear what's Trump doing this time.
So the idea, yeah, it is it's political. Another one is an email with a subject line that says stand with Trump again, that's definitely targeted at Republicans who want to open it because they want to stand with President Trump. And they're also using something called display name spoofing.
If you look at emails, you receive, you'll see, it says it's from so and so. Well, that's not necessarily who it's actually from there's some spoofing you can do there and a lot of these guys are doing it. There are ways to block phishing. Phishing, by the way, it's used a lot by ransomware. That's not what this is. We'll get into what this is exactly a minute.
But you've got to have some really great stuff in place. Hey, if you're interested in it. our friend of mine, Guy, he had sent me a thing on LinkedIn this week about that's a really great little ransomware checklist. It goes through the basics of what you should be doing to protect yourself against ransomware.
And if you want me to. I'll dig it up for you and send it off. Just email [email protected] and in the subject line put ransomware. I'll notice that. I will, I'll send it to you. Just send it to [email protected]. And it's a great little checklist on ransomware, and it's telling you should be doing things if you are a system administrator like looking for specially signed DNS records and other things that are going to help identify the reality of who they're talking to. Very important. DMark is one of those types of tools.
Now they are also using hijacked legitimate, the email addresses, and they'll use those to send out these emails. So they'll take an email from a PAX, a legitimate email. They will forward it, quote-unquote to you. It looks like a foreword for all intents and purposes. It is, and it has all of the links in it that the original email had and all of those links, some, the original email will work and they'll take you to the places that you expect to go to. The problem with this one is that they have a word document attached. Not that having a word document attached isn't necessarily a huge problem. We've had problems in the past where it was effectively a drive-by download. Sometimes you did not even have to open the email in order to get the infection nowadays unless you have very out of date software nowadays, you do have to open it.
So if you get that email, you click on the attachment. You open the attachment. That's when the real pain starts, because inside that attachment is a Microsoft word document that has something inside of it called the downloader. So you open up that document down comes EmoTet and once Emotet is on your system, that's when it all hits the fan.
What happens with EmoTet is really nasty. It starts to try and spread within your network. It scans for open services. I'm looking at a whole chart here on EmoTet which is known as S zero three six seven. It'll start to scan ports on all of the systems on your network, on your own system. It uses the most common ports that you might think of port 80, 80, 84, 43.
In one instance, it has used. port four, four, five, which is an SMB exploitation. SMB is windows file sharing. So it uses a number of different types of attacks here to go after services that are available on your network, on your computer, and on your network. And then it spreads laterally and it starts to scan other machines.
This is where EmoTet is different than some of the others. It acts like a worm. And that's the very first piece of malware I had. That's what got me going on cybersecurity. Cause back then, I'm pretty much, nobody had even heard of a worm before.
What a worm is for those that don't know. Is it some piece of software that gets onto one computer and tries to crawl through other computers all the way out?
Now you can see where the problem comes in because it now will try using all of these different protocols, try and get onto another computer. Now we can get on another computer as simple as getting onto your file server.
Are you using the VPN in your business operation? A lot of our people are at home. This is one of the real dangers of VPNs. VPNs do not make you safer. Don't think that they make you safer because in almost no cases, do they help with the safety. What's gonna happen with the VPN, if you're connected, is something like EmoTet or some of these others that spread like worms are going to try and crawl through your VPN to the other side.
 You say, Oh, we've got a firewall quote, unquote, in the other side, We've got a SonicWall, we've got whatever it might be.
Is that configured to stop a worm from crawling through and getting into other machines? And you might say, Yes. Yes, of course, it is. We block out all other servers that user at home only has access to the file server and their own computer acting as a file server isn't that just hunky Dory. The problem is it has access to the file server. Your typical ransomware even is going to start pulling files off of the file server, sending them over to Eastern Europe for examination to see if they can use it for extortion or to see if they want to use it for ransom, just hold the encrypted and hold your data ransom. All of that stuff can happen over your VPN. Just as if you're sitting there locally at the office.
Remember that you've got to have all of your security, not just in the office, not just maybe at the edge of the firewall, but everywhere.
We're setting up systems now, that one packet will be examined five times as it flows through different firewalls within the organization. So that someone who's sitting there working on something is going to have to go in and out of firewalls just to get to that server.
It's not just the packets that are examined nowadays. We're talking about having the data examined, completely reassembling the streams, and looking at it and looking at it all very closely.
Hey, you're listening to Craig Peterson stick around because we will be right back. We're going to be talking about a new scanning tool release and what that's all about. So stick around.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses one of the security tools he uses and why you should use it too.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Trojan Malware Targets Trump Supporters
Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0
Tyler Technologies finally paid the ransom to receive the decryption key
5G in the US averages 51Mbps while other countries hit hundreds of megabits
Apple's T2 security chip has an unfixable flaw
Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance
Android Ransomware Has Picked Up Some Ominous New Trick
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Remember everybody, don't open those email attachments. I'm going to talk about a new tool released out there that if you're involved with security, you probably need it. So here we go.
Hi everybody. Craig Peterson here.
I want to talk right now about this great tool that I've been using for decades now, I think. It's called Nmap. Now it's something that I cover. In my cybersecurity mastery course, but it's something you can do to learn a lot about yourself online. There are YouTube videos about it and many others. But the idea behind Nmap is to be able to check and see what's on your network and not just what's on your network, it'll also tell you about what that particular device is, and it just does a whole bunch of things for threat management. It'll check ports. Some of this stuff can go so far as to actually try and break into the systems. Now, Nmap isn't designed to do that. It really is using fingerprints to figure out the operating system that's in use, which is really handy.
Particularly for the internet of things devices that might be attached to your network.
This is great for home use, as well.
If you're a little bit of a techie, they have new protocol libraries. They've got payloads. Now that they've added for host discovery, port scanning version detection, which is really important to make sure that you have the latest version of different software on your systems. So you're not running something outdated.
They've fixed a whole bunch of bugs. They've got some different improvements and code quality improvements. But one of the biggest things is that they're using a new driver for raw packet capturing and sending out on the windows side and the Unix side it's been stable forever, but on the windows side, there's never been a really great way to do this.
There's something called WinPCap, but that driver has not been updated in the last seven or eight years. It doesn't always work on windows 10. It's using deprecated Windows APIs.
I know this is a lot of. TLAs write three-letter acronyms for everybody out there.
But bottom line, there is a new driver that lets software like Nmap send and receive its own packets it creates.
Normally if you are writing just regular old software where you would open a network connection to a server and then speak whatever protocol you wanted to. You would ask the operating system, Hey, open up a TCP session on port 82, this web server, and so on that remote server. Obviously, I had to get them an IP address, ultimately on that far server.
There's a web server and it's listening for requests on port 80. That TCP session requires five packets going back and forth, and then it's established, and then you send your get requests. So it would be like getting space HTTPS slash one dot one or whatever it might be. Whatever version of the HTTP protocol you're trying to use space. then the file you want and the server name. Then the remote server responds. It goes back and forth. There are a lot of packets that are exchanged between your computer and the remote computer, whether it's a web server remotely, or might be a file server remotely could be almost anything remotely.
There's a lot going on if you're trying to do diagnosis on the network, if you're trying to figure stuff out, you want to get down to that level. Really.
Remember I said, though, that the initial TCP session took five packets in order to set it up. That takes quite a bit of time in internet time because those packets have to go back and forth.
Google, in fact, came up with a new version of the protocol that requires less handshaking going on.
Software like Nmap that is going to connect to that web server itself wants to see all of the packets. It does not want the operating system to be sitting there, setting up the connections, and sending the data back and forth. It wants to do it.
That's the whole idea behind the raw packet capturing and creating is all about. On, the Unix world, which includes Linux, Mac OOS, solarise BSD they've had great packet capture. Code running forever, but this is brand new for Windows. So if you've tried it before and it didn't always work, try it again. Nmap N M A P online, just do a search for it, or you can download it from the Nmap.org, N M A P.org.
As I said, this is one of the tools we teach and answer questions about in my cybersecurity mastery course, because it's just so important. So Nmap is basically a command-line type program, but there's something called Zenmap that you can get as well as right there on the Nmap.org site that gives you a graphical front end.
If you would like to tinker you probably we should grab it and download it. It's already compiled. Although you can get the source code for you can also check signatures, GPG, signatures, and SHA one hash is for the different releases they've got install, guides, everything. They try and make it very easy for you.
The idea is once you have it there on your computer, You can then go ahead and run the latest release, which is right there on the homepage again. Nmap that's November Mike Alpha, Papa N M A P.org. You can just download it from right there and you're off and running. It is very handy.
So you run it against your network. It's gonna come back now and show you a whole bunch of information that you need on your network. So there are penetration testing uses, Nmap defense, of course, uses Nmap. There's a bunch of stuff. Password audits, vulnerability, scanners, just all kinds of stuff that you can use right there. On the Nmap.org site. This is going to take you off-site.
Now, if you're on a Unix distribution, like a Linux distribution, You can just grab RPMs for your distribution, whatever it might need be. If you're on a Mac, I think brew has it use brew. That's what I use all of the time for managing third-party software. Like this open-source stuff. It'll just download and install it for you, which is really cool.
Use the least concept of least privilege. Which is what you really want to do.
They've got a, they've got a reference guide that's showing you absolutely everything.
There's an SSH service that it discovered on this machine. It's going to tell you which version of SSH it is. It's going to tell you what the operating system is. It's going to give you a key that you can use now to distinctly or uniquely, I should say, I say, identify what it is.
I'm looking right now at a scan and it's showing me there's an SSH service. That's what I use in order to connect remotely to a computer and do command line stuff. It's showing me that there is an open Apache server, which is a web server. And it even tells me the version it's HTTPD protocol, a 2.2 0.14 running Ubuntu. Very handy stuff, because you can then feed this into other tools to know.
Is it up to date? Do I need to do updates? In fact, this Nmap stuff is used as the basis for the code that uses. Cause we'll use Nmap, it'll do scans, it'll find stuff and create a database. Then we take that database back.
If you have us do an audit for you, for instance, you give us the database. We don't even have to run the software. You just run it. It does all of his scans, puts it in a database. You send the database back to us in a zip file. We run it into a whole bunch of process software that lets us know exactly what's going on and also compares the versions.
Check it out. Nmap. November Mike alpha, Papa dot org. Absolutely valuable tool for everybody.
Hey, we're going to talk about paying ransoms when we get back in and what Tyler technologies did and why. So stick around.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses one of the security tools he uses and why you should use it too.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Trojan Malware Targets Trump Supporters
Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0
Tyler Technologies finally paid the ransom to receive the decryption key
5G in the US averages 51Mbps while other countries hit hundreds of megabits
Apple’s T2 security chip has an unfixable flaw
Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance
Android Ransomware Has Picked Up Some Ominous New Trick
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Remember everybody, don't open those email attachments. I'm going to talk about a new tool released out there that if you're involved with security, you probably need it. So here we go.
Hi everybody. Craig Peterson here.
 I want to talk right now about this great tool that I've been using for decades now, I think. It's called Nmap. Now it's something that I cover. In my cybersecurity mastery course, but it's something you can do to learn a lot about yourself online. There are YouTube videos about it and many others. But the idea behind Nmap is to be able to check and see what's on your network and not just what's on your network, it'll also tell you about what that particular device is, and it just does a whole bunch of things for threat management. It'll check ports. Some of this stuff can go so far as to actually try and break into the systems. Now, Nmap isn't designed to do that. It really is using fingerprints to figure out the operating system that's in use, which is really handy.
Particularly for the internet of things devices that might be attached to your network.
This is great for home use, as well.
If you're a little bit of a techie, they have new protocol libraries. They've got payloads. Now that they've added for host discovery, port scanning version detection, which is really important to make sure that you have the latest version of different software on your systems. So you're not running something outdated.
 They've fixed a whole bunch of bugs. They've got some different improvements and code quality improvements. But one of the biggest things is that they're using a new driver for raw packet capturing and sending out on the windows side and the Unix side it's been stable forever, but on the windows side, there's never been a really great way to do this.
There's something called WinPCap, but that driver has not been updated in the last seven or eight years. It doesn't always work on windows 10. It's using deprecated Windows APIs.
I know this is a lot of. TLAs write three-letter acronyms for everybody out there.
But bottom line, there is a new driver that lets software like Nmap send and receive its own packets it creates.
Normally if you are writing just regular old software where you would open a network connection to a server and then speak whatever protocol you wanted to. You would ask the operating system, Hey, open up a TCP session on port 82, this web server, and so on that remote server. Obviously, I had to get them an IP address, ultimately on that far server.
There's a web server and it's listening for requests on port 80. That TCP session requires five packets going back and forth, and then it's established, and then you send your get requests. So it would be like getting space HTTPS slash one dot one or whatever it might be. Whatever version of the HTTP protocol you're trying to use space. then the file you want and the server name. Then the remote server responds. It goes back and forth. There are a lot of packets that are exchanged between your computer and the remote computer, whether it's a web server remotely, or might be a file server remotely could be almost anything remotely.
There's a lot going on if you're trying to do diagnosis on the network, if you're trying to figure stuff out, you want to get down to that level. Really.
Remember I said, though, that the initial TCP session took five packets in order to set it up. That takes quite a bit of time in internet time because those packets have to go back and forth.
Google, in fact, came up with a new version of the protocol that requires less handshaking going on.
Software like Nmap that is going to connect to that web server itself wants to see all of the packets. It does not want the operating system to be sitting there, setting up the connections, and sending the data back and forth. It wants to do it.
 That's the whole idea behind the raw packet capturing and creating is all about. On, the Unix world, which includes Linux, Mac OOS, solarise BSD they've had great packet capture. Code running forever, but this is brand new for Windows. So if you've tried it before and it didn't always work, try it again. Nmap N M A P online, just do a search for it, or you can download it from the Nmap.org, N M A P.org.
As I said, this is one of the tools we teach and answer questions about in my cybersecurity mastery course, because it's just so important. So Nmap is basically a command-line type program, but there's something called Zenmap that you can get as well as right there on the Nmap.org site that gives you a graphical front end.
If you would like to tinker you probably we should grab it and download it. It's already compiled. Although you can get the source code for you can also check signatures, GPG, signatures, and SHA one hash is for the different releases they've got install, guides, everything. They try and make it very easy for you.
The idea is once you have it there on your computer, You can then go ahead and run the latest release, which is right there on the homepage again. Nmap that's November Mike Alpha, Papa N M A P.org. You can just download it from right there and you're off and running. It is very handy.
So you run it against your network. It's gonna come back now and show you a whole bunch of information that you need on your network. So there are penetration testing uses, Nmap defense, of course, uses Nmap. There's a bunch of stuff. Password audits, vulnerability, scanners, just all kinds of stuff that you can use right there. On the Nmap.org site. This is going to take you off-site.
Now, if you're on a Unix distribution, like a Linux distribution, You can just grab RPMs for your distribution, whatever it might need be. If you're on a Mac, I think brew has it use brew. That's what I use all of the time for managing third-party software. Like this open-source stuff. It'll just download and install it for you, which is really cool.
Use the least concept of least privilege. Which is what you really want to do.
They've got a, they've got a reference guide that's showing you absolutely everything.
There's an SSH service that it discovered on this machine. It's going to tell you which version of SSH it is. It's going to tell you what the operating system is. It's going to give you a key that you can use now to distinctly or uniquely, I should say, I say, identify what it is.
 I'm looking right now at a scan and it's showing me there's an SSH service. That's what I use in order to connect remotely to a computer and do command line stuff. It's showing me that there is an open Apache server, which is a web server. And it even tells me the version it's HTTPD protocol, a 2.2 0.14 running Ubuntu. Very handy stuff, because you can then feed this into other tools to know.
Is it up to date? Do I need to do updates? In fact, this Nmap stuff is used as the basis for the code that uses. Cause we'll use Nmap, it'll do scans, it'll find stuff and create a database. Then we take that database back.
If you have us do an audit for you, for instance, you give us the database. We don't even have to run the software. You just run it. It does all of his scans, puts it in a database. You send the database back to us in a zip file. We run it into a whole bunch of process software that lets us know exactly what's going on and also compares the versions.
Check it out. Nmap. November Mike alpha, Papa dot org. Absolutely valuable tool for everybody.
Hey, we're going to talk about paying ransoms when we get back in and what Tyler technologies did and why. So stick around.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
Craig discusses why State and Local governments are getting ransomware and who is actually at fault.
For more tech tips, news, and updates, visit - CraigPeterson.com
---
Trojan Malware Targets Trump Supporters
Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0
Tyler Technologies finally paid the ransom to receive the decryption key
5G in the US averages 51Mbps while other countries hit hundreds of megabits
Apple's T2 security chip has an unfixable flaw
Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance
Android Ransomware Has Picked Up Some Ominous New Trick
---
Automated Machine-Generated Transcript:
Craig Peterson: [00:00:00] Hey, Tyler technologies, you might not have heard of them, but you've almost certainly use them. And we'll tell you why they got nailed by these human-operated ransomware pieces that are floating around there as part of phishing expeditions. Here we go.
Hey, thanks for joining me. This is Craig Peterson of course.
Tyler technologies, you might not have heard of these people. They are the largest provider of software to the United States public sector. At the end of September, Tyler technologies disclosed that they had been nailed by a ransomware attack.
Its customers, which are public sector companies, Or not obviously not companies, but organizations like towns, counties, States, it's customers reported finding suspicious log-ins and. What is called the RATS on their networks? A rat is a remote access tool. Remember I've told you how we found Chinese back doors on networks, time and time again and we continue to find them. Those are rats. Those are remote access tools.
What happens is your network gets infected bad guys, gets onto your computers and they install software that gives them remote access. Isn't that just phenomenal? Oh, we have the majority of states here in the country that are using Tyler technology services and software. Some of those, at least I have found remote access tools on their networks. That is a very bad thing apparently.
According to security affairs.co, apparently Tyler notified law enforcement about it. It took place on September 23rd and they brought in a forensics firm to investigate the incident and trying to figure out what did the bad guys get.
That is a very big question. Did you know that if you are a business, you are required to be able to figure this out? Under certain federal contracts or DOD particularly you are required to keep long-term logs. Those you have to have logs of everything that's been happening on your network for the term of the contract. I think it's plus three years, depending on the contract, that is a long time.
That's a lot of logs gets pretty expensive, pretty fast. When you're a company like Tyler technologies you'd think they would have some absolutely amazing logging software. But do they? No. No, of course not.
I see this all the time. We've got to be careful people. We've got to keep the logs that come in from our firewalls, the logs on our computers. They need to be basically vacuumed up and put into a database for at least a few weeks so that an investigation can occur. If something were to happen.
One of the things that we've got to keep in mind too, is that from the time the machine is infected until the time they are moving around in the network right now is about a week. You have five to seven days to notice that you've been infected and to shut it down before they start expanding.
So having a few weeks worth of detailed logs of everything going in and out of your firewall and everything going on your computers can quickly Put an end to the types of hacks that Tyler experienced.
As I said, depending on the regulations you're under, you could be in trouble. I had probably about a dozen people this week asked me for my audit kit. So if you'd like a copy of my audit kit, if you are in a state or a local government, or you are in business, I have an audit kit that covers everything, all of the major stuff anyway.
FINRA requirements. If you are a financial organization dealing with personal information, identifiable information, et cetera, just send me an email in the subject line. Just say audit. Kit. I'll email one out to you so that you have that I'm not charging for any of this stuff.
It is a checkmark thing. This thing's over 300 pages just long. Okay. It has all of these different standards in it, but it's something you can use. You can sit down and go through it with your IT provider or your internal IT people.
Or you can sit around at the conference room table with your senior managers and go through it because there are different sections in it.
So the very first section is just general high-level stuff to make sure that you're going, to have general compliance. And then it gets right into the national Institute of standards, technology stuff, the NIST 800-171, and some of the other sections that are needed. So it even goes to absolute detail here bit by bit if you want that.
So I can send that to you if you want. I'd be glad to. It's a PDF. I found a lot of people had it bounce, though. I think the majority of them, cause it was a huge and like 20 megabytes, which is crazy. So I compressed it. I use PDF Expert on my Mac to compress it down to about 12 megabytes, which is still too big to send by email.
As a general rule email shouldn't be used for anything that big and by the way, a lot of email filters we'll assume if it's a big piece of email, a big attachment like that it's malware.
I'll probably just send you a link to my Dropbox account so you can pull it right out of there when you want. Anyhow, that's just me, M E at craigpeterson.com audit kit. Be glad to send it to you.
It's useful for home users as well. You're not going to, of course, delve into all of the more detailed stuff for specialized businesses, but you are going to be able to have the nice high-level stuff that is going to help you out.
Immediately after this attack friends over at Tyler technologies said that the incident only impacted the internal network and phone systems. Yet, it looks like they got the ransom X ransomware. This is human-operated, ransomware. This is the type of stuff I've been talking about.
It's a RAT. It's remote access. It allows them to get in, like a Chinese back door. With human-operated ransomware, they get onto the computers and they start poking around.
Back in June this year. Ransom X again was used in an attack on the Texas department of transportation. In September effected systems over at IPG photonics, which is this high-performance laser developer. Bleeping Computer, which is a great site for keeping up on some of this stuff is also talking about now how Tyler technologies paid a ransom to receive the decryption key and recover encrypted files.
Now you might ask yourself, how do they figure out what ransom they should charge, right?
A home user's not going to be able to afford the same ransom that a city can afford and just ask Atlanta. How many times have they had ransomware and paid ransoms and been down for months, some of their systems, just crazy. They do it with this type of ransomware, where you've got a human-looking around figuring out what is this? Is this a business? This, a home user. Okay. So we'll charge them a couple of hundred bucks. Oh, this is a city. So let's spread laterally. Let's poke around. Let's see what the weaknesses are in their internal networks.
Remember I said earlier in the show, that we run sometimes through firewalls here at five or six times, that's called ZeroTrust and that's to stop these attacks. We gotta be able to stop them. We absolutely have to be able to stop them.
All right. Crazy times we live in, you're listening to Craig Peterson.
I'm feisty stick around. Cause coming up, we're going to talk about the five G in the U S of A.
---
More stories and tech updates at:
www.craigpeterson.com
Don't miss an episode from Craig. Subscribe and give us a rating:
www.craigpeterson.com/itunes
Follow me on Twitter for the latest in tech at:
www.twitter.com/craigpeterson
For questions, call or text:
855-385-5553
From the publisher's feed