Showing posts with label Address. Show all posts
Showing posts with label Address. Show all posts

Tuesday, 6 January 2015

Incognito Mode Does Not Protect Against Super Cookies

Users who use the incognito or private browsing mode of their browser are still to follow through so-called "super cookies", according to an online test of the British developer Sam Greenhalgh . The problem is caused by a security measure called "HTTP Strict Transport Security" (HSTS). The measure ensures that websites only be accessed through a secure connection.


In case a website HSTS enabled the browser via a special "flag" remember and ensure that there is made only over HTTPS connection. If the user specifies HTTP in the address he is automatically redirected to HTTPS. However, this automatic forwarding can also be used by a malicious website to save a unique number in the user's browser and follow him. This number can then be read by other websites. HSTS can also be used as a tracking mechanism in this way.

To give users more privacy browsers have for some time been added incognito or private browsing mode. These cookies are not shared with existing web sites and the user can delete the cookies so they can be tracked online. Because HSTS is a security measure and is not really meant for tracking, browsers go it differently than is the case with cookies.

Some browsers such as Google Chrome, Firefox and Opera are trying to resolve this issue by removing both cookies stored as HSTS-flags. According to Greenhalgh, existing HSTS-flags, unlike cookies, or shared with other websites, even if the user incognito or private browsing mode enabled. In the case of Safari, the problem seems to be even greater because Safari users on an Apple device have no possibility to remove the HSTS-flags. She even be synchronized with iCloud, so they can be returned if the user clears his extension.

"I do not know if the technique is used in the wild to track users, although that does not mean that this is not so," said Greenhalgh. He calls the technical community to see how the tracking area can be resolved while the value of HSTS retained. In a response to Google Chrome Security Team states that there are measures added to the browser to address the problem, but it is ultimately a tradeoff between security and privacy. This form of "fingerprinting" would therefore not be solved unless fundamental changes are made to the way the web works. "

Thursday, 9 October 2014

Botnet of 500,000 computers - Qakbot Malware

The Attack Chain


Researchers have identified a botnet of 500,000 computers discovered that 52% of machinery exists that run on Windows XP. A comparatively very high percentage, since it no longer supported by Microsoft operating system worldwide share of between 14% and 24%.

The computers have been infected with qbot via known vulnerabilities in Adobe Flash Player, Java, Adobe Reader and Internet Explorer, also known as Qakbot. On infected computers qbot steals all kinds of data for Internet banking. Researchers from Proofpoint found that the login data of 800,000 accounts online banking were intercepted. In 59% of these cases involved one of the five largest American banks.

Further figures ( PDF ) show that the malware on the American Internet has provided, since 75% of the infected computers over an American IP address available. especially In addition to steal login details infected machines are also offered for other cybercriminals. Paid as proxy These criminals can the infected computers as a springboard for other attacks use or for storage or transportation of stolen data.

Following are the steps How It works:

1. Infecting Legitimate Websites

Infecting Legitimate Websites

2. Filtering Targets- Traffic Distribution Systems.

Filtering Targets- Traffic Distribution Systems

3. Getting Into The User's Machines -Exploits

Getting Into The User's Machines -Exploits

4. Stealing User Banking Credentials - Malware

Stealing User Banking Credentials - Malware