Showing posts with label Adobe. Show all posts
Showing posts with label Adobe. Show all posts

Tuesday, 19 April 2016

Adobe: Flash Player Security Thwart Hackers


Adobe security measures in recent months have added to Flash Player ensures that hackers could not carry out successful attacks on the media player during a recent hacking contest, as the software company announced.

During the annual Pwn2Own contest hackers are rewarded for demonstrating unknown vulnerabilities in different browsers and Adobe Flash Player. During the last edition of March Flash Player was finally twice successfully hacked , but that number could be higher, says Peleus Uhley of Adobe. In preparation for the hack contest Adobe rolled several updates to enhance the security of Flash Player.

These measures paid off as several attempts to hack Flash Player failed thus said Uhley. Still, Flash Player has been successfully hacked twice. "These victories show that there is always more vendors can do to improve security," he continues. Uhley notes that companies such as Adobe, Microsoft and Google are engaged in a race with hackers.

Adobe invests in his own words than a lot of security and regularly adds features to thwart it. hackers as only goal. "Such measures are increasingly being added. The companies themselves will change on the frontline of this battle and to grow the more expensive." According Uhley help hacking contests like Pwn2Own software companies to develop. "While Pwn2Own each year seems to take the same required innovations and challenges to books every year results," said Uhley.

Wednesday, 10 February 2016

Adobe Close Critical Vulnerabilities In Flash Player And Photoshop



Adobe has patched critical vulnerabilities in Flash Player and Photoshop computers could allow an attacker to take complete. In the case of Flash Player is about 22 critical vulnerabilities which allowed an attacker to execute arbitrary code on the computer, such as installing malware by just visiting a hacked website or see it from an infected ad.

There was no further interaction required from users. As far as known vulnerabilities are not attacked on the Internet. Since attackers often develop after the release of Flash Player updates exploits to attack unpatched users, Adobe advises to update to Flash Player version 20.0.0.306 within 72 hours. This can be done via the automatic update function or Adobe.com. In the case of Google Chrome, Internet Explorer 10 and 11 on Windows 8 and 8.1 and Internet Explorer 11 and Microsoft Windows 10 Edge Embedded Flash Player will be updated using the browser. Through this Adobe page can be verified that the system version is installed.

There is also a security update for Adobe Photoshop CC and Adobe Bridge CC appeared. The update fixes three critical vulnerabilities that an attacker could take over your computer if opened a malicious file. Because Photoshop traditionally not been a target for attackers, Adobe advises users and administrators to install the update if it suits them. Updating via the built-in updater of drawing programs. In the case of Photoshop CC 02.04.2014 is the update to download only via Adobe.com.

Wednesday, 11 November 2015

Critical Vulnerabilities In Adobe Flash Player Poem



There is a new version of Adobe Flash Player that appeared in a total of 17 vulnerabilities were fixed, allowing an attacker in the worst case, the computer could take over completely. Through 16 of the leak, it was possible for an attacker to execute arbitrary code on the computer.

An example is to install malware. Only was visiting a hacked or malicious website is adequately, or viewing an infected ad.The remaining vulnerability allowed an attacker to bypass the security of Flash Player, which made it possible to attribute any data to the file system with the rights of the logged in user.

A researcher named Bilou discovered 11 of the 17 vulnerabilities and sold to HP's Zero Day Initiative, which then briefed Adobe. Users are advised to update within 72 hours to Flash Player version 19.0.0.245. This can be done via the automatic update feature or Adobe.com. In the case of Google Chrome, Internet Explorer 10 and 11 on Windows 8 and 8.1 and Internet Explorer 11 on Windows 10 and Microsoft Edge Embedded Flash Player will be updated via the browser. Through this page Adobe can check which version is installed on the system.

Saturday, 17 October 2015

Belgian Government Suspected Of Using FinFisher Spyware


The Belgian government is suspected of also using this year to have the controversial FinFisher spyware made. According to a new report published by the Canadian Citizen Lab, an organization dealing with human rights, security and IT.

The reason Citizen Lab with FinFisher concerned that some regimes used these spyware in the past, journalists and spy on law firms. FinFisher is being developed by International Gamma and consists of client software, which must be installed on the computer of a target, and server software. Via the server, which is installed on the server of the relevant government authorities, FinFisher the infected computer can be spied upon. In order to infect other computers, for example, be deployed counterfeit websites from Adobe.

Citizen Lab researchers were able to locate several of the FinFisher servers. On the basis of the IP addresses has drawn up a list of countries that are suspected FinFisher this year to have used it. As would have been operating a Belgian FinFisher server in January this year. In Europe, including Spain, Italy and the Czech Republic use the software. In total, 32 countries were identified. Last year the Belgian Government had already known that the vendor FinFisher 18,000 euros paid.

Thursday, 15 October 2015

Adobe Comes Up With New Emergency Patch For Flash Player Flaw


Adobe next week will release an emergency patch for a serious vulnerability in Flash Player that asset is used by attackers to infect computers with malware. The newest vulnerability in the software this week was discovered during attacks in various ministries.

The attacks took place via e-mails containing a link. The link pointed to a website with an exploit that used the vulnerability in Flash Player in order to infect the computer of the target. Adobe has now confirmed that the latest version of Flash Player, version 19.0.0.207, which is indeed a critical vulnerability has been used in a limited number of targeted attacks.

During the week of October 19 will Adobe therefore with an emergency patch to come. The zero-day vulnerability was reported on the very day that Adobe released version 19.0.0.207, where 13 vulnerabilities were fixed. According to anti-malware company Malwarebytes Now is the time to seriously consider switching from Flash Player in the browser or to remove completely from the computer.

Wednesday, 14 October 2015

Zero-Day Vulnerability In Latest Flash Player Active Attacked


In the latest version of Adobe Flash Player that came out yesterday is a zero-day vulnerability for which no update is available and actively attacked. Reported that the Japanese anti-virus company Trend Micro. Several foreign ministries would be attacked by the leak.

Victims receive a spear phishing email containing a link to a website. This website loads an exploit of the Flash Player flaw uses to install malware on the computer. The emails have subjects like: "Suicide car bomb targets NATO troop convoy in Kabul," "Syrian troops make gains as Putin defends air strikes", "Israel launches airstrikes on targets in Gaza", "Russia warns of response to Reported US nuke buildup in Turkey, Europe "and" US military reports 75 US-trained rebels return Syria ". Visiting such a malicious page with a vulnerable Flash Player is enough to get infected. There is no further interaction is required.

According to Trend Micro, the group behind the attack is also responsible for an attack in which a zero-day vulnerability was used in Java. Also, the group behind attacks on NATO, the White House, the German parliament and foreign ministries sit. The message of the anti-virus company coincides with the Tuesday patch from Adobe. Yesterday released a new version of Adobe Flash Player that 13 vulnerabilities were patched. Yet even Flash Player 19.0.0.207, the latest version now vulnerable to the observed attacks. Adobe would be informed of the new leak, but he has not yet written warning.

Sunday, 20 September 2015

Tip: Adobe Reader Lets You Open Any Embedded Files




In recent weeks, cyber criminals several times PDF files sent which was hiding a malicious Word document. Once users opened the PDF file they were asked if they wanted to open the embedded Word document.

The Word document contains another macro that installed malware on the computer. The macro is executed only if users set it, but in practice this is an effective method of attack. Users and administrators can easily avoid, however, Adobe Reader opens these embedded documents, says Didier Stevens, handler at the Internet Storm Center. Through the Trust Manager, available via the settings of the PDF reader option can be switched off, as Stevens Also in this video shows.

Monday, 7 September 2015

Vital Infrastructure USA Attacked Via Flash Leak


Vital infrastructure in the United States has become the target of an attack in which attempts were made to infect computers via a zero-day vulnerability in Adobe Flash Player with malware. It reports the Industrial Control Systems Cyber ​​Emergency Response Team (ICS-CERT) of the US government.

It was a spear phishing campaign that focused on different sectors, including chemicals, major manufacturing, energy and government facilities. The attackers sent out customized e-mails with links to different websites. On these sites was inserted malicious code that made ​​abuse of a zero-day vulnerability in Adobe Flash Player, so the ICS-CERT says. The vulnerability was patched by Adobe on June 23 and was already attacked at that time, according to Adobe.

The same group of attackers behind this attack used beginning in 2014, social engineering and social media to carry out explorations and business personnel to attack. In one case, the attackers used a social media account and pretended to be a possible candidate for this job. They approached the employees of a critical infrastructure environment and asked about the name of the IT manager and what software versions were used.

The attackers asked for feedback on a job application and sent it file "resume.rar" via e-mail. The rar file contained three files, including a malicious version of the open source TTCalc application, which the computer company employee with a backdoor infected. The attack was quickly discovered and the attackers would have had no access to control systems. "Although the motivation of the attackers remains unknown, allows the use of social media and zero-day exploits that they undertake serious efforts to gain access to the networks of critical infrastructure", according to the ICS-CERT (pdf).

Saturday, 25 July 2015

Cyber ​​Spies Added Linux Support To Allow Malware



A group of cyber spies who is held responsible for attacks on the Belgian government , the White House and a variety of other businesses , government agencies and institutions in Europe and the United States has developed new malware that also features Linux support.

The group is "Duke" and has been active for several years. Recently, a new instance of malware from the group discovered called "Seaduke". It is a Trojan designed to steal information and will be used against a small number of valuable objectives.According to both Symantec and Palo Alto Networks involves highly sophisticated malware.

Linux

Finland's F-Secure analyzed the malware and also saw that the Trojan is written in Python and supports both Windows and Linux. According to the virus fighter Seaduke is the first "cross-platform" malware of the Duke group. The first thing is to use the popular scripting language Python. Earlier malware cyber spies were written in the programming languages ​​C and C ++. In addition, the Python code for both Windows and Linux proves to be developed. "We therefore suspect that the Duke group same Python code Seaduke used to attack Linux users," says researcher Artturi Lehtiö.

Lehtiö leaves in front Security.NL know that there are no attacks against Linux users in the "wild" are found. "But it is safe to assume that they have added Linux support to the use," he notes. The question remains how Linux users would be attacked.The Duke group, for example, used a funny movie monkeys to attack Windows users, which in reality was an exe file. There are PDF documents containing exploits for vulnerabilities in Adobe Reader used to infect computers with malware.

Adding Linux support to malware is not new. Earlier this year it was discovered another group of cyber spies who had done this. The group decided to use social engineering to infect Linux users. Attacked users received a rogue HTML5 plugin offered which turned out to be in reality spyware.

Tuesday, 7 July 2015

Hacking Team Had Zero Day Vulnerabilities For Windows And Flash



The Italian developer of government spyware Hacking Team had zero day vulnerabilities for Windows and Adobe Flash Player, according to the files that were stolen from the company. Yesterday published attackers a file of about 400GB with all sorts of information that was captured by Hacking Team.

The files have now discovered two vulnerabilities for which no security update available yet, says security researcher The Grugq . It is a vulnerability in Windows that allows an attacker can increase his rights on the system. In this case, the attacker must already have access to the computer in order to use the leak. The second vulnerability is in Adobe Flash Player. Through this vulnerability, an attacker computers or completely take over, for example, when users visit a hacked or malicious website.

The embedded Flash Player in Google Chrome is vulnerable. According to security researcher Kevin Beaumont makes the leak is possible to escape from the sandbox of Chrome. Researcher Rik van Duijn of security Dear Bytes however, leaves know that a sandbox escape "through the published code is not possible and therefore a second exploit is required. Hacking Team, which develops spyware for government agencies, has in statement confirming that it has been hacked. "We think there are documents of the company have been stolen. We have launched an investigation to determine the extent of the attack and to determine what exactly is captured," said a spokesman. The company's website has been offline since yesterday.

Update

The National Cyber ​​Security Center (NCSC) government has a warning issued for the flaw in Flash Player. Through the leak, an attacker execute arbitrary code on the computer with the rights of the logged in user. The NCSC states that there is no update available for the leak yet.

Update 13:48

The attack on Hacking Team is claimed by the hacker who last year by spyware developer Gamma International managed to break in and there gigabytes of data was captured, says Vice Magazine . The hacker says soon come up with the details of how he managed to break into Hacking Team.

Update 15:09

Anti-virus company Symantec confirms that this is a zero-day vulnerability in the latest version of Flash Player. The virus firefighter expects that attackers will probably make use of the vulnerability.

Update 15:19

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns also the vulnerability and says that users can protect themselves by installing Microsoft EMET unreliable or not Flash content to perform.

Saturday, 4 July 2015

Malware Install Flash Player Update On Infected Computers


Vulnerable versions of Adobe Flash Player have become a popular target for cyber criminals to infect computers with malware. Reason for Kovter malware to update after infection from a computer to the existing Flash Player, so other malware can not infect the system.

Kovter can use computers to commit fraud ad (click fraud) or install ransomware. The malware can spread through various ways, such as contaminated ads that make unpatched Flash Player vulnerabilities use but can also be installed on computers that are already part of a botnet. Security Researcher JuK of the blog Malware Do not Need Coffee discovered the new method of malware.

The system that the researchers used for finding exploits suddenly decided to download Flash Player, whereas that was not the intention. The system must remain fragile namely, JuK notes. Further investigation revealed that it was the Kovter malware that the Flash Player update was downloaded and installed. It is not the first time that malware is taking measures to prevent infection by other malware. The betabot has, for instance an option to prevent attacks using Java and Adobe Reader.

Saturday, 27 June 2015

Trend Micro: New Flash Vulnerability Same Reason As Earlier Leak


The latest vulnerability in Adobe Flash Player which this week an emergency patch appeared to have the same cause as previous vulnerabilities in the popular browser plug-in. This enables the Japanese anti-virus company Trend Micro after analysis. This week, the vulnerability was with he CVE number 2015-3113 patched after the leak was previously used in targeted attacks. According to researchers, the leak is very similar to CVE-2015-3043 that Adobe patched in April.

Both vulnerabilities cause a buffer overflow. It also appears that an exploit for the vulnerability also published in April version 18.0.0.160 could crash (the latest Flash Player version before the emergency patch released this week). Both vulnerabilities are caused handle FLV with the Nellymoser audio codec and can be attacked through a specially prepared audio tag of an FLV file.

"This incident shows how important it is carefully developing patches to prevent vulnerabilities patched at a later time be attacked again," said the researchers. Which argue that software developers need to perform regression tests to ensure that old bugs are not a threat to new versions of the software.

E-mail

It was already known this week that the attackers left in emails used to lure targets to a malicious page where the Flash Player flaw was then attacked. Security company Websense says that the emails had used the subject line "2015 Program Kick Off". The text stated that the recipient was invited to a meeting. Through the attached link could be found more information about the meeting. The attackers would have mainly focused on the technological and scientific sectors.

Thursday, 25 June 2015

New Flash Player Flaw Attacked Through The Link In Emails


A critical vulnerability exists in Adobe Flash Player which yesterday an emergency patch released was attacked from links in emails. That informs the American security company FireEye that the zero-day vulnerability discovered and reported to Adobe.

A China-based group, according to FireEye behind the attack. The attacks were aimed at companies and organizations in different sectors, such as aerospace, defense, telecom, engineering and transport. The targets were emails sent with a link.Remarkably, there is no targeted emails were used, but messages that seemed almost on spam. "Save between $ 200-450 by purchasing an Apple Certified Refurbished iMac through this link. Refurbished iMacs come with the same one-year extendable warranty as new iMacs. Supplies are limited, but updated frequently. Do not hesitate...> Go to Sale , "the text in the message.

The link in the email pointed to a compromised server where the target was profiled via JavaScript. Once the victim was determined downloaded a malicious SWF and FLV file. Eventually this led to the installation of a backdoor. Through this backdoor received the attackers access to the system and the network of the organization was infiltrated. In announcing the emergency patch let Adobe know that IE users on Windows 7 and older and Firefox users on Windows XP were the target of the attack.

Thursday, 2 April 2015

Critical Vulnerability In Google Chrome Patched


Google has released a new version of Google Chrome released that fixes four vulnerabilities, including a critical vulnerability that the underlying operating system in the worst case could be full. Visiting a malicious or hacked website or see getting an infected ad would have been sufficient in this case.

This kind of critical vulnerabilities are rare in Google Chrome. Last year there were only three of these types of leaks reported in Chrome. Critical vulnerabilities allow an attacker to run arbitrary code on the computer can perform, such as installing malware, come because of the sandbox security in the browser rare. In addition to a leak in the browser must also be a leak in the sandbox are found to execute code on the underlying system.

The vulnerability, which consists of various bugs, was reported by an anonymous security researcher. Google rewarded the researcher before with a total of almost $ 30,000. Besides this leak is also a vulnerability patched during the Pwn2Own contest was demonstrated. Researcher Jung Hoon Lee aka "lokihardt" succeeded during the event in order to execute arbitrary code via various vulnerabilities. Update to Chrome 41.0.2272.118 will happen automatically in most cases.

Wednesday, 25 March 2015

Fake Email Wehkamp Spreads Ransomware


Mail order company Wehkamp warns Internet users for an email that already goes around a few days and seems to come from the company, but in reality that is spreading ransomware encrypts files for ransom.According to the email, the recipient would have placed an order with Wehkamp.

It is the computer game Fifa 15 for the PlayStation 3. The message notes for more information on the order to the included zip annex which has an order number. The zip annex again contains an .exe file with an icon from Adobe that the malware appears to be. It is a variant of CTB Locker, which stands for Curve Tor Bitcoin. This ransomware resurfaced last year for the first time. Once users the .exe file to open the computer becomes infected and all kinds of files encrypted. Then users get some days to pay the ransom for decrypting the files.

The infected e-mails using the name of Wehkamp went last week all around, according to a warning from security researcher Mark Loman Twitter. Since then notify all kinds of Twitter users that they have the message received . Increasingly it appears to the so-called order of the computer. "There is indeed a phishing email around that does not come from us. You can best remove him immediately and not open!", says Wehkamp via Twitter.

Saturday, 21 March 2015

Also, Google Chrome And Safari Hacked During Competition


After Internet Explorer and Firefox during the Pwn2Own contest in Vancouver also Google Chrome and Safari hacked. The Pwn2Own contest is an annual event organized at the CanSecWest conference where researchers and the safety of popular browsers, and browser plug-ins can be tested. During the first day of the event there were leaks in Adobe Flash Player (3) Adobe Reader (3) Windows (3) Internet Explorer 11 (2) and Firefox (2) demonstrated.

During the second day were 11 Internet Explorer and Firefox again to believe. Additionally died also Google Chrome and Safari on Mac OS X. The attacks on IE11, Chrome and Safari were demonstrated by Jung Hoon Lee aka "lokihardt". The researcher was awarded a total of $ 225,000. Most of it, $ 110,000, Lee received because of his attack on Google Chrome.The researcher also showed also two Windows Leaks which he could execute code with system privileges.

In total there are 21 vulnerabilities demonstrated during the two days for which no security updates are available from the respective vendors. Microsoft leads with five vulnerabilities in Windows and four leaks in IE11 the list. Details on the vulnerabilities found will be made public until the updates are available.

Friday, 20 March 2015

Zero-Day Vulnerabilities In Flash, Windows, IE11 And Firefox Shown


During the Pwn2Own contest in Vancouver researchers have multiple zero-day vulnerabilities in Adobe Flash Player, Adobe Reader, Windows, Internet Explorer and Firefox demonstrated. The Pwn2Ownd contest is an annual event organized during the CanSecWest conference where researchers and the safety of popular browsers, and browser plug-ins can be tested.

In total on the first day of the event three vulnerabilities in Adobe Reader, three vulnerabilities in Adobe Flash Player, three vulnerabilities in Windows, two vulnerabilities in Internet Explorer 11 and two leaks in Firefox displayed. Through the vulnerabilities could allow an attacker full control of the computer without user interaction is much here for required. This involves visiting a hacked or malicious Web site or open a malicious PDF file.

None of the demonstrated vulnerabilities A security update is available, so there is zero-day vulnerabilities. However, the Pwn2Own rules state that only details may be shared with the organization. Which will then inform the relevant suppliers. Only after a security update is available researchers may publish details of the vulnerabilities.

In total, the researchers for their leak 317,500 dollars , which researcher Nicolas Joly dragging $ 90,000 knew inside. The Keen Team, consisting of several researchers, however, managed to leak in Adobe Flash Player and Adobe Reader, as well as bugs to earn the rights to increase Windows, totaling $ 140,000. Later today , various researchers are trying to re-hack Firefox and IE but there are now planned attacks on Google Chrome and Apple Safari.

Saturday, 14 March 2015

Critical Security Update For Adobe Flash Player


There is a critical security update for Adobe Flash Player appeared that resolves eleven leaks, nine of which could give an attacker full control over the computer. It would be visiting a hacked or malicious Web site or see getting infected Flash ads suffice.

Through the remaining two vulnerabilities an attacker could bypass the restriction for uploading files, as well as a cross-domain policy. Ten of the eleven remedied vulnerabilities were found by external researchers include Google, Intel Labs and NCC Group. Windows and Mac users are advised to update within 72 hours to Adobe Flash Player 17.0.0.134. This can be done via the automatic update feature and Adobe.com .

In the case of Internet Explorer 10 and 11 on Windows 8 and Windows 8.1, the embedded Flash Player will be updated automatically. Microsoft had the appropriate Flash updates already on March 10 released two days before Adobe published them. Also in the case of Chrome embedded Flash Player will be automatically updated. Like Google, Microsoft published on 10 March a new Chrome version , but this is not stated whether the Flash vulnerabilities have been fixed. Through this Adobe page Internet to see whether and which version of Flash Player installed on their system state.

Monday, 23 February 2015

Shop Sees Increase In Adware Mac Users


A US store warns Mac users to download software only from the official supplier, after it saw an increase in clients who were infected with adware. According to Annie Hayes iCape Solutions is the number of Mac customers that come along because adware increasing.

"Although Macs are resistant to viruses, we have an increase of adware / malware seen as Genio and Install mac," says Hayes. This is because according to its Mac users software such as Adobe Flash Player for free outside the official Adobe website. Once active adware modifies the home page and search engines and injects ads. "In order to avoid this kind of programs you should only download programs from a reliable place. For example if you need the latest version of Flash, make sure that you are on the genuine Adobe website."

Another problem that the Mac store regular customers see return is MacKeeper. This is a program that claims to optimize Mac OS X systems and to protect the privacy of users. "I can give you a million reasons to avoid it, but I refer to this article on iMore , "Hayes says. "Ordinary users do not need anti-virus software or cleaner, and much of what is in circulation resembles MacKeeper, a program designed to let you pay for a service."

Tuesday, 16 December 2014

FBI used Metasploit to identify Tor users



The FBI has used a component of the popular Metasploit hacking tool to identify Tor users. Metasploit is a tool that penetration testers and security experts test the safety of systems and networks. It is now being developed and managed by security company Rapid7.


Wired reports that the FBI in 2012 set in part of Metasploit to successfully identify different Tor users through Adobe Flash Player. The US investigation department made ​​use of an abandoned Metasploit project called " Decloaking Engine ". It was one in 2006 developed experimental concept where multiple tricks were used to identify users of a service such as Tor anonymity via a specially crafted Web site. In case the Tor user had his installation secure he could not be identified through the website. However, if users made ​​a mistake their real IP address is visible.

Flash Player

One of the tricks was the use of a Flash application. Adobe Flash Player can set up a direct connection to the Internet and thus leak the IP address of the user. A known problem and the Tor Project advises users therefore not to install Flash Player. Finally appeared in 2011, a version of the Tor Browser, the software to access the Tor network, allowing users were better protected and the test site that was set up for the Decloacking Engine almost no users identified more.

However, the FBI used Decloaking Engine as a basis for an operation against child pornography sites on the Tor network. The investigation department had access to several of these sites and then let them run Flash programs in visitors' browsers in order to determine their true IP address. A total of 25 users in the United States were identified and an unknown number elsewhere. According to Wired is to use the first time the FBI spyware-like software to all visitors of a website started in place against certain individuals.

Identification

However, it is unknown whether the FBI standard Decloaking Engine has used or a customized version. HD Moore, the original developer of Metasploit and Decloaking Engine, argues that his release could barely identify Tor users. Only suspects with very old Tor version or who had gone to great lengths to install Flash Player would have been at risk.

In this way, the FBI would only have to suspects with the worst operational security-oriented instead of the worst offenders. A few months later, the FBI provided the weather on Tor users. Then there was an exploit for a known Firefox vulnerability used to determine the IP address and MAC address of Tor users. Again it came to users with poor operational security, as it attacked Firefox leak was already in the latest version of Tor Browser solved .