Story image

Inside NZ's 'ethical hacking' firm and its quest to make systems safer

26 Jun 17

New Zealand's first ethical hacking company has issued a critical warning to those using Microsoft Edge and Internet Explorer after it discovered zero-day vulnerabilities back in May.

Attackers are able to exploit the vulnerabilities and gain access to sensitive information. They could also run malicious code on victims' machines, Security-Assessment reports.

The company's principal consultant Scott Bell discovered the vulnerabilities in May, and Microsoft patched them in the same month.

“Security-Assessment follows responsible disclosure guidelines. This means alerting the vendor to the vulnerabilities immediately and not releasing information about the vulnerabilities until they are fixed. This is to prevent malicious actors from actively exploiting the vulnerabilities," Bell explains.

Despite being patched by Microsoft, the company is urging users to apply the patches or face being attacked.

Practice lead Phil Doole says there could be worrying repercussions for those who do not apply the patches.

“The ability for an attacker to run malicious code on a victim’s machine could have dramatic and severely damaging impact for both organisations and individuals,” he says.

"These vulnerabilities are known as 'memory corruption'. The vulnerabilities allow a malicious user to craft a special web page which, when visited, can download a payload to allow access to the victim's machine. This is typically delivered via a technique called spear phishing. Such vulnerabilities are often used by state-sponsored actors (APT) to gain a foothold in the target network," the company adds.

This year the company has facilitated seven security advisories, the most of any New Zealand security firm, it claims.

In one case, the company helped to provide incident response and forensics after a state-sponsored APT group infiltrated a client's network.

The company says that with a 100% hit rate in penetration test this year alone, it means there hasn't been one engagement in which it hasn't identified vulnerabilities.

"User awareness is key. Educating users on the dangers of clicking unsolicited links in emails can help to prevent spear phishing attacks from succeeding. For organisations running Windows 7 or older, upgrading to Windows 10 will bring additional enhancements that help to protect against such vulnerabilities," the company says in a statement.

Security-Assessment was established in 2002. In 2007, it became a wholly-owned subsidiary of Dimension Data and continues to operate as a vendor-neutral offensive security consultancy, providing security, assessment and assurance services for organisations. Dimension Data has offices in Auckland, Wellington and Singapore.

How to stay safe when shopping online
Online shopping is a great way to avoid the crowds – but there are risks.
Dell EMC embeds security in latest servers
Dell EMC's 14th generation of PowerEdge servers has comprehensive management tools to provide security across hardware and firmware.
Why data backups should be a part of daily operations
"Disaster recovery needs to address complete system failure and provide a set of security policies to govern disaster incidents."
Businesses focusing on threats from within - survey
Over 50% of respondents reported that 100 days of dwell time or more was representative of their organisation.
GCSB welcomes Inspector-General's report on intelligence warrants
Intelligence warrants can include surveillance, private communications interception, searches of physical places and things, and the seizure of communications, information and things.
Corelight and Exabeam partner to improve network monitoring
The combination of lateral movement and siloed usage of point security products leaves many security teams vulnerable to compromise.
SailPoint releases first identity annual report
SailPoint’s research found that many organisations are lacking maturity in their governance processes over identities.
Disruption in the supply chain: Why IT resilience is a collective responsibility
"A truly resilient organisation will invest in building strong relationships while the sun shines so they can draw on goodwill when it rains."