Showing posts with label Brute Force. Show all posts
Showing posts with label Brute Force. Show all posts

Wednesday, 18 March 2015

IP Box Can Lock Screen iPhones Brute forcing


Researchers have discovered a device that makes it possible to brute forcing the lock screen of iPhones and iPads. IP Box, as the device is called, would be used by telephone repairmen to bypass the screen lock of iOS. "This obviously has major implications for the safety and of course was something that we wanted to investigate and validate" said researchers MDSec .

They did eventually get to 200 pounds one of the devices. The IP Box appears to simulate via the USB connection to enter the PIN and also tries all possible pin combinations. According to the researchers, this has been known, but the device also works if the option is enabled to delete the data after 10 attempts.

"Our initial analysis indicates that the IP Box to circumvent the restrictions by making direct with the power of the iPhone connection and aggressively to break the flow after each unsuccessful PIN, but before the attempt is synchronized in the Flash memory." Entering a PIN would therefore take about 40 seconds. A four-digit PIN can therefore be outdated in some 111 hours.

The attack has been tested on iOS 8.1. An attack on iOS 8.2 will follow. The research would show that it is possible to have a leak was discovered last year, but this has yet to be confirmed. The researchers made ​​the following video on YouTube in which the device and the attack will be demonstrated.


Wednesday, 7 January 2015

ISC: Another Port For SSH Is Not Meaningless



Who SSH (Secure Shell) to log on to remote computers and servers will benefit from it to change the default port 22, as late as a handler of the Internet Storm Center (ISC) know. SSH is a popular protocol for managing computers. Standard protocol listens on port 22.

This will also be a lot of scans and attacks on this port. At present, there Reddit , in response to this article , a discussion or change the default port is wise. One of the criticisms is that " security through obscurity "is not a security measure, but only one way to slow an attacker and therefore offers little value. "While it is true that it is difficult to stop a determined attacker to cause you provide, any measure that prevents arbitrary script kiddies and scanners to your SSH look not entirely meaningless," says ISC handler Rick Wanner.

Wanner says more than 15 years SSH on a non-standard port to run, such as port 52222. "Of course this is not the only security measure that I use. I patch daily use hosts.allow where possible, keys and passphrases instead passwords and use Deny Hosts ", he tells. ISC handler notes that he does not use port 22 because of "security through obscurity" benefits, but because it eliminates all noise on port 22.

Port 22 is a favorite target of brute force attacks and port scans rising every year. These activities cause Wanner as much noise in the logs. "Why would you tolerate it if it is not needed?", He notes. The default port change he would attack traffic are much diminished that he occasionally his defense test to see if it still works.

Tuesday, 6 January 2015

IBM: Most stores In US Attacked via Command Injection


Most stores in the United States that it was the last year the target of an attack were attacked through command and SQL injection, according to a study ( pdf ) from IBM. According to the company halved the number of attacks against American chains, but there were or 61 million records stolen. Every day some 3,000 attacks would be observed, although IBM does not let you know where exactly consist. However, there was an increase in the number of attacks on cash-malware, which criminals infect the systems used by stores to checkout.

Despite several major incidents involving cash-malware played a leading role involved in most incidents in the retail sector command and SQL injection. In command injection are vulnerable applications through commands on the underlying server. SQL injection allows an attacker to execute SQL commands, making it possible for example to read sensitive data from the database.

"The complexity of SQL implementations and the lack of data validation by managers shall ensure that databases are a major target," said the researchers from IBM. Thus, command injection attacks against at nearly 6,000 stores observed. Whilst also brute force attacks and Shellshock leak used by attackers.

Saturday, 20 December 2014

US warns of SMB worm that was used against Sony



The Computer Emergency Readiness Team (US-CERT) of the US government has issued a warning for an SMB (Server Message Block) -worm that started against Sony. The worm uses brute force authentication to spread through shared Windows SMB shares.


Every five minutes makes the malware connects to the server command of the attackers to send data successfully to another Windows computer via SMB port 445 has infected. The tool also listens for connections on TCP port 195 and TCP port 444. Furthermore, the worm has a backdoor that allows to download files and execute commands. The worm can so via Universal Plug and Play (UPNP) ports in your firewall to discover routers, gateways and port mappings.

Thus it is possible to attacked computers that are behind a NAT (Network Address Translated) network are to allow incoming connections. The part of the worm that is most striking is the "clear", which overwrites the Master Boot Record of the hard drive and thus makes the system unusable. The delete function is also used against systems that are accessible via shared network folders. The malware attempts to log on to these computers via a number of usernames and passwords that are previously specified by the attackers.

The US-CERT warns that organizations that deal with this malware get must take account of the theft of intellectual property and the disruption of critical systems. As a solution to get the system advised to use virus scanners and keep up-to-date, operating systems and software to keep up-to-date, "defense in depth" to apply strategies and a plan to establish order with destructive malware to go.