Showing posts with label Black Hat Hackers. Show all posts
Showing posts with label Black Hat Hackers. Show all posts

Saturday, 8 August 2015

WSUS Allows Attacker Distribute Infected Windows Updates



Companies and organizations that their Windows Server Update Services (WSUS) have not configured securely give attackers the ability to provide the entire corporate network from infected Windows updates.WSUS acts as a proxy for Windows Update. Companies can deploy effectively via WSUS Windows updates within their local network.

Instead of all company computers to connect to Microsoft servers to download updates, this is done once by WSUS. The WSUS server is installed in the corporate network and all connected business computers then will their Windows updates downloaded from the WSUS server. By default, WSUS, however not enabled to use HTTPS. An attacker who already has access to the corporate network can use to take then other company computers.

That researchers Paul Stone and Alex Chapman at the Black Hat conference demonstrated in Las Vegas ( pdf ). To prevent attacks via Windows Updates Windows only accepts updates that are signed by Microsoft. The researchers showed that an attacker Microsoft signed files can reuse to inject malicious updates, which are then to execute arbitrary commands on the attacked computers.

The attack, according to Stone and Chapman easy to avoid, namely setting up SSL. Most companies would also do this, so let them versus SC Magazine know. Companies, however, have not brought the risk that a system at one time the entire corporate network can compromise, the researchers said. In addition to enabling SSL by companies that use WSUS, Microsoft may also screwing security. The software giant would namely to use a separate certificate for the signings of Windows updates.

Thursday, 6 August 2015

Gang Stealing An Estimated $ 100 Million Of Accounts


A large group of more than 50 cyber criminals stole recent years to an estimated $ 100 million of bank accounts and between 20 and 30 terabytes of data captured. The FBI and security Crowd Strike and Fox-IT today announced at the Black Hat conference in Las Vegas announced.

The gang used the Game Over Zeus malware, a Trojan horse that was on the infamous Zeus Trojan based and was mainly used to steal data from online banking and other services. Game Over Zeus botnet was last June by the FBI, Europol, several companies and police forces from the extracted air . Early this year, the FBI put $ 3 million on the head of a Russian man suspected of developing Game Over Zeus.

Today published data show that the botnet from an average of about 200,000 systems existed. Besides also steal money from bank accounts, the gang held behind Game Over Zeus engaged in espionage in Eastern European countries. In total, there would be via the malware 20 to 30 terabytes of data have been stolen. It also appears from the investigation of the criminals that they are well organized. The gang calls itself the "business club" and consists of more than 50 people. The Russian man who is wanted by the FBI was always seen as a mastermind Game Over Zeus, but he would not be the sole leader of the group of criminals. According to the researchers, there is someone else with whom he leads the gang together.

Wednesday, 22 July 2015

Brakes Chrysler Cars To Be Operated By Remote Leak


Two well-known security researchers have discovered a vulnerability in cars of Chrysler manufacturer, making it possible to remotely activate the brakes of hundreds of thousands of vehicles, and also to turn off to turn off the motor at low speeds.

It is also possible to control the climate control system and to control the radio, and windshield wipers. The researchers are working on the possibility to take control of the wheel. Currently this is only possible if the car is in reverse. The problem is in Uconnect, a component that gives the cars online capabilities and that the entertainment and navigation are operable. The functionality even offers a wifi hotspot and makes phone calls possible.

Uconnect allows anyone with a vehicle connection as long as the IP address of the car is known. After the connection had been made with a car managed researchers Charlie Miller and Chris Valasek therein in order to adapt the firmware of the system. This custom firmware can then send instructions via the internal network of the car to the physical components such as the engine and the wheels.

The attack would work on any Chrysler vehicle features Uconnect and the end of 2013, has been delivered in 2014 or early 2015. According to researchers, there would be an estimated 471,000 vulnerable cars are in the United States. The researchers will present their work at the upcoming Black Hat conference demonstrated, in which part of the exploit will be published, reports Wired .

Update

Chrysler was almost nine months ago already informed by the researchers. The manufacturer warned car owners on July 16 that an update was available. However, it is a cryptic message saying that a software update is available that improves the cars' electronic security "and communication systems, without letting you know what the impact of the vulnerability can be repaired. An additional problem is that the update of Chrysler manually using a USB flash drive must be installed. Users can do this yourself or have it done through the dealer. However, chances are that this many vehicles will never receive the update.