Re: Linked-in and its Phishing-like contacts option!

Mathew Want <[email protected]> Wed, 1 May 2013 15:50:42 +1000
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <CAKFczxaVoZ4Z79Ugc8tKAGGuFKhUXVAotTabMAYXg48TC6=q0A@mail.gmail.com>
--===============1600594403==
Content-Type: multipart/alternative; boundary=047d7b5d2c68c9e0bf04dba1b2ee

--047d7b5d2c68c9e0bf04dba1b2ee
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Read only access to the sites. I like that idea a lot.

Has anyone else come across this requirement or found a good way to do it
at a control point level? Perhaps at the IDS layer?

M@


On 1 May 2013 02:20, <[email protected]> wrote:

> > I'm honestly not sure how we could block this stuff in a web-proxy, or =
be
> > alerted by an IDS rule short of just blocking the sites.
> > (Maybe this will start more discussion.  How would one try this?)
>
> I have a lot of requests from customers to try to make the web read-only.
> The main use cases are for social network, blogs/wikis, and commenting on
> posts. The fundamental ways to do this are to 1) have MITM SSL decryption=
,
> and 2) block the POST method for specific sites. Most commercial proxies
> can do this and even squid does SSL MITM.
>
> By blocking POST to certain categories of sites and only allowing the POS=
T
> for the */logon pages, users can view all the facebook/twitter/youtube th=
ey
> want, but can't write anything outbound to the site. It's pretty effectiv=
e.
>
> e=C2=B2
> _____________________________________
>
> From: [email protected] [mailto:
> [email protected]] On Behalf Of Bruce Platt
> Sent: Friday, April 26, 2013 7:41 AM
> To: Firewall Wizards Security Mailing List
> Subject: Re: [fw-wiz] Linked-in and its Phishing-like contacts option!
>
> I have a love/hate relationship with these as well.  I was only tempted
> down this perfidious path a few years ago when a set of my Grandchildren
> asked me to get a Facebook account so we could interact that way as they
> live on the other coast from me.  I started disliking it within five
> minutes when a former employer sent me a request to "friend" him.  Then i=
t
> became an issue of who can I not be "friends" with among my contemporarie=
s.
>
> Same with Linked-In, same with Twitter.
>
> Up to this point I'm just addressing the personal inconvenience aspect of
> it, which is why I chose Crispan's post to which to reply.
>
> But, the larger issue is really the risk of exposing all sorts of persona=
l
> /  corporate information in a variety of unwitting ways.  This is the par=
t
> I hate.  We've had many discussions about the risks of allowing people to
> use social media web sites from work.  It's a losing battle.  Entering
> one's email password is just one, and Linked-In is not the only villain. =
 I
> just made some flight reservations yesterday.  The airline website offere=
d
> to add the reservation to my Calendar.  Not let me download a .cal file,
> but to directly insert it into my calendar.  Uh, no.  Not today.
>
> But, this now get's added to our list of worst practices and meet's Paul'=
s
> criteria of being part of overall operational security.  I'm honestly not
> sure how we could block this stuff in a web-proxy, or be alerted by an ID=
S
> rule short of just blocking the sites.  (Maybe this will start more
> discussion.  How would one try this?)
>
> Mix these with BYOD, and it makes a daunting task indeed.
>
> Cheers
>
> --
> +------------------------------------+
> Bruce B. Platt, Ph.D.
> V.P. Research
> ei3 Corporation
> 136 Summit Avenue
> Montvale, NJ 07645
> Phone: +1-201-802-9080 ext. 404
> Facsimile: +1-201-802-9099
>
> On Fri, Apr 26, 2013 at 12:53 AM, Crispin Cowan <[email protected]=
>
> wrote:
> I boycott all social media. I=E2=80=99m not opposed to social networking,=
 but I am
> opposed to some dot.com monetizing my relationships; I do all my social
> networking via open protocols like e-mail, and having a beer with a frien=
d
> =F0=9F=98=8A
>
> I broke this rule once, joining LinkedIn 5 years ago, because I needed a
> job. LinkedIn was a total failure at getting a job, but attending ToorCon
> and having a beer with someone I met there worked. I deleted my LinkedIn
> account when I got tired of the =E2=80=9CFoo wants to connect with you=E2=
=80=9D spam. I=E2=80=99m
> still getting LinkedIn spam.
>
> Screw social networking web sites. I don=E2=80=99t have a FaceBook page o=
r a
> Twitter account, and never will.
>
> Funny, I never envisioned myself as Clint Eastwood yelling at kids to get
> off my lawn, but here I am =F0=9F=98=8A
>
> Sent from Windows Mail
>
> From: Gautier . Rich
> Sent: =E2=80=8EThursday=E2=80=8E, =E2=80=8EApril=E2=80=8E =E2=80=8E25=E2=
=80=8E, =E2=80=8E2013 =E2=80=8E9=E2=80=8E:=E2=80=8E28=E2=80=8E =E2=80=8EPM
> To: Firewall Wizards Security Mailing List
>
> Thoughts? I=E2=80=99m wondering why User Operational Security falls under=
 the
> realm of Firewall Wizards..  Other than that, I=E2=80=99d say =E2=80=93 T=
hey=E2=80=99re not alone
> by any stretch of the imagination, and plenty of users seem to be perfect=
ly
> willing to accept the risk (or be unaware of it).  However, not much you
> can do on the firewall side other than turning off webmail access...
>
> Richard Gautier, CISSP
> Enterprise Architect, Federal Group
> 650 Massachusetts Avenue NW
> Suite 510
> Washington, DC 20001
> Office: (571) 226-8828  |  Cell: (703) 231-2156
> [email protected]  |  www.drc.com
>
> From: [email protected] [mailto:
> [email protected]] On Behalf Of Mathew Want
> Sent: Monday, April 22, 2013 7:30 PM
> To: Firewall Wizards Security Mailing List
> Subject: [fw-wiz] Linked-in and its Phishing-like contacts option!
>
> Hiya all.
>
> Has anyone else noticed the option to see who else they know is connected
> on Linked-in? Have you noticed that if you click on the outlook button it
> asks you for your WORK EMAIL PASSWORD!!!!!
> Bloody hell! It's not like the job of getting users to not submit this
> information to other sites isn't already hard enough without this!!! The
> "can't put brains in pumpkins " department must be having a field day ove=
r
> this.
> Am I the only one that think this is a touch negligent on the part of
> Linked-in? Or should I just accept that it is corporate facebook, accepts
> that they have the dame moral fibre and move on?
> Maybe I am expecting too much? Thoughts?
> --
> Regards,
> M@
> --
> "Some things are eternal by nature,
> others by consequence"
> ________________________________________
> This electronic message transmission and any attachments that accompany i=
t
> contain information from DRC=C2=AE (Dynamics Research Corporation) or its
> subsidiaries, or the intended recipient, which is privileged, proprietary=
,
> business confidential, or otherwise protected from disclosure and is the
> exclusive property of DRC and/or the intended recipient. The information =
in
> this email is solely intended for the use of the individual or entity tha=
t
> is the intended recipient. If you are not the intended recipient, any use=
,
> dissemination, distribution, retention, or copying of this communication,
> attachments, or substance is prohibited. If you have received this
> electronic transmission in error, please immediately reply to the author
> via email that you received the message by mistake and also promptly and
> permanently delete this message and all copies of this email and any
> attachments. We thank you for your assistance and apologize for any
> inconvenience.
>
> _______________________________________________
> firewall-wizards mailing list
> [email protected]
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>
>
> _______________________________________________
> firewall-wizards mailing list
> [email protected]
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>



--=20
"Some things are eternal by nature,
others by consequence"

--047d7b5d2c68c9e0bf04dba1b2ee
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Read only access to the sites. I like that idea a lot=
.<br><br>Has anyone else come across this requirement or found a good way t=
o do it at a control point level? Perhaps at the IDS layer?<br><br></div>M@=
 <br>
</div><div class=3D"gmail_extra"><br><br><div class=3D"gmail_quote">On 1 Ma=
y 2013 02:20,  <span dir=3D"ltr">&lt;<a href=3D"mailto:lordchariot@embarqma=
il.com" target=3D"_blank">[email protected]</a>&gt;</span> wrote:<=
br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left=
:1px #ccc solid;padding-left:1ex">
<div class=3D"im">&gt; I&#39;m honestly not sure how we could block this st=
uff in a web-proxy, or be<br>
&gt; alerted by an IDS rule short of just blocking the sites.<br>
&gt; (Maybe this will start more discussion. =C2=A0How would one try this?)=
<br>
<br>
</div>I have a lot of requests from customers to try to make the web read-o=
nly. The main use cases are for social network, blogs/wikis, and commenting=
 on posts. The fundamental ways to do this are to 1) have MITM SSL decrypti=
on, and 2) block the POST method for specific sites. Most commercial proxie=
s can do this and even squid does SSL MITM.<br>

<br>
By blocking POST to certain categories of sites and only allowing the POST =
for the */logon pages, users can view all the facebook/twitter/youtube they=
 want, but can&#39;t write anything outbound to the site. It&#39;s pretty e=
ffective.<br>

<br>
e=C2=B2<br>
_____________________________________<br>
<br>
From: <a href=3D"mailto:[email protected]">fir=
[email protected]</a> [mailto:<a href=3D"mailto:f=
[email protected]">firewall-wizards-bounces@lis=
tserv.icsalabs.com</a>] On Behalf Of Bruce Platt<br>

Sent: Friday, April 26, 2013 7:41 AM<br>
<div class=3D"im">To: Firewall Wizards Security Mailing List<br>
</div>Subject: Re: [fw-wiz] Linked-in and its Phishing-like contacts option=
!<br>
<div><div class=3D"h5"><br>
I have a love/hate relationship with these as well. =C2=A0I was only tempte=
d down this perfidious path a few years ago when a set of my Grandchildren =
asked me to get a Facebook account so we could interact that way as they li=
ve on the other coast from me. =C2=A0I started disliking it within five min=
utes when a former employer sent me a request to &quot;friend&quot; him. =
=C2=A0Then it became an issue of who can I not be &quot;friends&quot; with =
among my contemporaries.<br>

<br>
Same with Linked-In, same with Twitter.<br>
<br>
Up to this point I&#39;m just addressing the personal inconvenience aspect =
of it, which is why I chose Crispan&#39;s post to which to reply.<br>
<br>
But, the larger issue is really the risk of exposing all sorts of personal =
/ =C2=A0corporate information in a variety of unwitting ways. =C2=A0This is=
 the part I hate. =C2=A0We&#39;ve had many discussions about the risks of a=
llowing people to use social media web sites from work. =C2=A0It&#39;s a lo=
sing battle. =C2=A0Entering one&#39;s email password is just one, and Linke=
d-In is not the only villain. =C2=A0I just made some flight reservations ye=
sterday. =C2=A0The airline website offered to add the reservation to my Cal=
endar. =C2=A0Not let me download a .cal file, but to directly insert it int=
o my calendar. =C2=A0Uh, no. =C2=A0Not today.<br>

<br>
But, this now get&#39;s added to our list of worst practices and meet&#39;s=
 Paul&#39;s criteria of being part of overall operational security. =C2=A0I=
&#39;m honestly not sure how we could block this stuff in a web-proxy, or b=
e alerted by an IDS rule short of just blocking the sites. =C2=A0(Maybe thi=
s will start more discussion. =C2=A0How would one try this?)<br>

<br>
Mix these with BYOD, and it makes a daunting task indeed.<br>
<br>
Cheers<br>
<br>
--<br>
+------------------------------------+<br>
Bruce B. Platt, Ph.D.<br>
V.P. Research<br>
ei3 Corporation<br>
136 Summit Avenue<br>
Montvale, NJ 07645<br>
Phone: <a href=3D"tel:%2B1-201-802-9080%20ext.%20404" value=3D"+12018029080=
">+1-201-802-9080 ext. 404</a><br>
Facsimile: <a href=3D"tel:%2B1-201-802-9099" value=3D"+12018029099">+1-201-=
802-9099</a><br>
<br>
On Fri, Apr 26, 2013 at 12:53 AM, Crispin Cowan &lt;<a href=3D"mailto:crisp=
[email protected]">[email protected]</a>&gt; wrote:<br>
I boycott all social media. I=E2=80=99m not opposed to social networking, b=
ut I am opposed to some <a href=3D"http://dot.com" target=3D"_blank">dot.co=
m</a> monetizing my relationships; I do all my social networking via open p=
rotocols like e-mail, and having a beer with a friend =F0=9F=98=8A<br>

<br>
I broke this rule once, joining LinkedIn 5 years ago, because I needed a jo=
b. LinkedIn was a total failure at getting a job, but attending ToorCon and=
 having a beer with someone I met there worked. I deleted my LinkedIn accou=
nt when I got tired of the =E2=80=9CFoo wants to connect with you=E2=80=9D =
spam. I=E2=80=99m still getting LinkedIn spam.<br>

<br>
Screw social networking web sites. I don=E2=80=99t have a FaceBook page or =
a Twitter account, and never will.<br>
<br>
Funny, I never envisioned myself as Clint Eastwood yelling at kids to get o=
ff my lawn, but here I am =F0=9F=98=8A<br>
<br>
Sent from Windows Mail<br>
<br>
From: Gautier . Rich<br>
Sent: =E2=80=8EThursday=E2=80=8E, =E2=80=8EApril=E2=80=8E =E2=80=8E25=E2=80=
=8E, =E2=80=8E2013 =E2=80=8E9=E2=80=8E:=E2=80=8E28=E2=80=8E =E2=80=8EPM<br>
To: Firewall Wizards Security Mailing List<br>
<br>
Thoughts? I=E2=80=99m wondering why User Operational Security falls under t=
he realm of Firewall Wizards.. =C2=A0Other than that, I=E2=80=99d say =E2=
=80=93 They=E2=80=99re not alone by any stretch of the imagination, and ple=
nty of users seem to be perfectly willing to accept the risk (or be unaware=
 of it). =C2=A0However, not much you can do on the firewall side other than=
 turning off webmail access...<br>

<br>
Richard Gautier, CISSP<br>
Enterprise Architect, Federal Group<br>
</div></div><div class=3D"im">650 Massachusetts Avenue NW<br>
Suite 510<br>
Washington, DC 20001<br>
Office: <a href=3D"tel:%28571%29%20226-8828" value=3D"+15712268828">(571) 2=
26-8828</a> =C2=A0| =C2=A0Cell: <a href=3D"tel:%28703%29%20231-2156" value=
=3D"+17032312156">(703) 231-2156</a><br>
<a href=3D"mailto:[email protected]">[email protected]</a> =C2=A0| =C2=A0<a h=
ref=3D"http://www.drc.com" target=3D"_blank">www.drc.com</a><br>
<br>
From: <a href=3D"mailto:[email protected]">fir=
[email protected]</a> [mailto:<a href=3D"mailto:f=
[email protected]">firewall-wizards-bounces@lis=
tserv.icsalabs.com</a>] On Behalf Of Mathew Want<br>

Sent: Monday, April 22, 2013 7:30 PM<br>
To: Firewall Wizards Security Mailing List<br>
Subject: [fw-wiz] Linked-in and its Phishing-like contacts option!<br>
<br>
Hiya all.<br>
<br>
Has anyone else noticed the option to see who else they know is connected o=
n Linked-in? Have you noticed that if you click on the outlook button it as=
ks you for your WORK EMAIL PASSWORD!!!!!<br>
Bloody hell! It&#39;s not like the job of getting users to not submit this =
information to other sites isn&#39;t already hard enough without this!!! Th=
e &quot;can&#39;t put brains in pumpkins &quot; department must be having a=
 field day over this.<br>

Am I the only one that think this is a touch negligent on the part of Linke=
d-in? Or should I just accept that it is corporate facebook, accepts that t=
hey have the dame moral fibre and move on?<br>
Maybe I am expecting too much? Thoughts?<br>
--<br>
Regards,<br>
M@<br>
--<br>
&quot;Some things are eternal by nature,<br>
others by consequence&quot;<br>
</div>________________________________________<br>
<div class=3D"HOEnZb"><div class=3D"h5">This electronic message transmissio=
n and any attachments that accompany it contain information from DRC=C2=AE =
(Dynamics Research Corporation) or its subsidiaries, or the intended recipi=
ent, which is privileged, proprietary, business confidential, or otherwise =
protected from disclosure and is the exclusive property of DRC and/or the i=
ntended recipient. The information in this email is solely intended for the=
 use of the individual or entity that is the intended recipient. If you are=
 not the intended recipient, any use, dissemination, distribution, retentio=
n, or copying of this communication, attachments, or substance is prohibite=
d. If you have received this electronic transmission in error, please immed=
iately reply to the author via email that you received the message by mista=
ke and also promptly and permanently delete this message and all copies of =
this email and any attachments. We thank you for your assistance and apolog=
ize for any inconvenience.<br>

<br>
_______________________________________________<br>
firewall-wizards mailing list<br>
<a href=3D"mailto:[email protected]">firewall-wizards@=
listserv.icsalabs.com</a><br>
<a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"=
 target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall-=
wizards</a><br>
<br>
<br>
_______________________________________________<br>
firewall-wizards mailing list<br>
<a href=3D"mailto:[email protected]">firewall-wizards@=
listserv.icsalabs.com</a><br>
<a href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards"=
 target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall-=
wizards</a><br>
</div></div></blockquote></div><br><br clear=3D"all"><br>-- <br>&quot;Some =
things are eternal by nature,<br>others by consequence&quot;<br>
</div>

--047d7b5d2c68c9e0bf04dba1b2ee--

--===============1600594403==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--===============1600594403==--