Bangladesh Bank hackers compromised SWIFT software, warning issued
reuters.com
reuters.com
SWIFT is not a system.
SWIFT is an instruction protocol tied to a network that SWIFT Alliance Access (mentioned in article) gives access to, SWIFTNet.
Without going into details of failings of SWIFT authentication, which are few, this appears to be simple phishing:
The use of malware, suggested here, seems simple:
* There are a lot of manual steps in fund transfers that are either initiated manually (submitting a paper-based payment request, or even change to a company's authorised signature list) or requiring various manifests such as letter or credit clearing.
* Malware means the typical system of checking inputs are indeed true and correct (an inputter of the paper form, and a checker to verify it is true and correct) can be disrupted by replacing the scanned file between scanning and input (based on scan) or direct system access changing key numbers of codes.
* This comment is not a slight on Bangladesh. It is a general comment on developing economies I've interacted with in banking operations across Asia: Staff are often under-trained at a branch level and expected to perform a multitude of tasks under under-trained management. Local actors, for example local banks, often have completely insecure systems compared to international banks despite acting as correspondent bank in many transactions (added to the security-failure tool-chain). This is in contrast with outsourced operations in similar countries that run large service centers and most-often do an excellent job.
This appears to be fully not an error of SWIFT, but of using (the power of) SWIFT in combination with discrete and serious errors in injecting false records in non-audited/un-auditable systems that interact with SWIFT instructions and SWIFTNet.
However, that malware is indicated suggests this could be to lax local lock-down of PCs. Pretty common. International banks should be pretty locked-down, but no reason to be complacent. I imagine various regional and country heads of compliance are aware of this right now, or have been already.
What is likely worrying local bank security managers is just how many VBA-type programs they're running as quick-fixes to operational problems that are vulnerable, the weak links. The number of hacked-together-at-the-weekend-bought-in-services in banking is astounding, especially in emerging markets.
Yes, these hack/programs exist in established international corporate banks.
I came into work one day and a colleague had a piece of paper on his desk requesting that we not touch his machine.
A macro was running which was switching between two open programs, highlighting fields, and copy and pasting data.
I'm still not sure if I should be alarmed or in awe. It was probably the most sensible option of the available options...
Anyway, it's accurate to think of protocol + SWIFT's mgmt systems as "the SWIFT system" given they work collectively to hanndle a SWIFT transaction.
[1] https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec...
It replaced a JNZ with NOP NOP. The BAE Systems blog post has lots of techincal detail: http://baesystemsai.blogspot.co.uk/2016/04/two-bytes-to-951m...
That's some good old-fashioned straightforward DRM cracking right there, I'm getting flashbacks from the 90s.
What would have prevented it was not letting them have root in the first place. Perhaps by running with Software Restriction Policies so only a whitelist of binaries can run in the first place.
Interesting enough, the successor to Burroughs is being made partly by BAE Systems. See crash-safe.org publication list.
Imagine if close to 1 Trillion $ was stolen from the Federal Reserve !
Edit - apparently its 85 Billion - not 1 Trillion - pretty embarrassing since I have a degree in maths -> shame .. ding ding .. shame.
And I don't know many westerners that would say that $951M is not a lot of money :)
* http://www.transparency-usa.org/who-we-are/mission-history/
* http://www.sfgate.com/news/article/Military-waste-under-fire...
* http://cagw.org/media/press-releases/taxpayer-watchdog-ident... federal-government-waste
* http://reason.com/blog/2014/12/02/federal-debt-soared-above-...
I need to clean up my resume.
> Computer disks and USB sticks were dropped in parking lots of government buildings and private contractors, and 60% of the people who picked them up plugged the devices into office computers. And if the drive or CD had an official logo on it, 90% were installed.
It sounds more like someone left usb sticks with logos on them in the parking lot.
B8 01 00 00 00 mov eax, 1 ; never reached: set result to 1 (fail)
This is why you should always initialize variables to "fail" in secure code, although in this case it probably wouldn't have helped.There's also https://news.ycombinator.com/item?id=11563690 which seems to be the technical analysis referred to by the story.