Showing posts with label CERT Coordination Center. Show all posts
Showing posts with label CERT Coordination Center. Show all posts

Saturday, 26 September 2015

CERT / CC Warns Cookie Vulnerability In Browsers


One problem with the way placed HTTP cookies can ensure that attackers can circumvent HTTPS and can steal private information, warns the CERT Coordination Center (CERT / CC) at Carnegie Mellon University. The problem is in all major browsers.

The problem is that the standard for cookies specifies no mechanism for separation and integrity and browsers do not always authenticate the domain settings of a cookie. An attacker could use this to set a cookie that is used later for an HTTPS connection, instead of the cookie from the website. An attacker can therefore a cookie for example.com locations on the computer that the actual cookie for www.example.com overwrites the victim loads HTTPS content. By another vulnerability used in the server use the cookie to the attacker to obtain private information.

The investigators who have the problem during the last USENIX Security Symposium discussed state that a cookie a so-called "secure flag" may contain, indicating that it has to be sent only over a HTTPS connection. However, there is no corresponding flag that indicates how the cookie is placed. An attacker could via a man-in-the-middle thus inject cookies used on subsequent HTTPS connections. According to the CERT / CC are there attempts to secure cookie management undertaken but all failed due to a lack of a widely implemented standard.

As a solution, the organization that the standard must be adjusted for cookies. In the meantime, the researchers advise websites HSTS (HTTP Strict Transport Security) for a top-level domain to set up and use the "includeSubDomains" option.This partly avoids the possibility of an attacker to place top-level cookies cookies for a subdomain, such as www.domeinnaam.tld override. End users are advised to use the latest browser version. In particular IE users make wise here. Internet Explorer 11 is the only IE version that supports HSTS.

Thursday, 27 August 2015

Asus DSL Modem Router Vulnerable By Fixed Password


In several ADSL modem routers, including those of the Taiwanese manufacturer Asus, is called a "hard-coded" password is used, which allows remote attackers as an administrator can log onto the devices. Before that warns the CERT Coordination Center (CERT / CC) at Carnegie Mellon University.

The problem is present in the Asus DSL-N12E, DIGICOM DG-5524T, Observa RTA01N Telecom, Philippine Long Distance Telephone (PLDT) Speed ​​Surf 504AN and ZTE ZXV10 W300. The Asus model is also sold in the Netherlands. The permanent password allows an attacker to connect through telnet to the device. The password is partly based on the MAC address of the device, but it can be traced via SNMP (Simple Network Management Protocol (SNMP). Since there is no update is available, users are advised to ensure that telnet is not for " unreliable sources "is accessible and that SNMP is disabled on the routers.

Thursday, 13 August 2015

Researchers Hack Corvette Via SMS



A vulnerability ( pdf ) in a dongle which is used by insurance companies and fleet managers to monitor cars remote makes it possible for attackers to operate all kinds of parts via SMS. That the researchers today at the Usenix Security Conference show in Washington.

The C4 OBD2 dongle of the French Mobile Devices makes it possible to monitor the location, speed and efficiency of vehicles. The devices are plugged into the diagnostic port (OBD-II) of the car, that is usually located under the steering wheel.The device features a GPS receive, mobile phone chip and onboard microprocessor. If the car driving is the dongle communicates with CAN bus of the car. This is the internal network that controls the physical components of the car.

The dongle then sends information from the car via the GSM network to the provider. Researchers at the University of California managed by sending text messages to the dongle to control the CAN bus of the car. For their demonstration, the researchers used a red Corvette, as in the video below shows. Via text message, they could eventually turn the brakes and turn off and turn on the windshield wipers.

Update

The US insurance company which distributes the Metro Mile dongles in the US was warned in June by investigators for the leak. Both Mobile Devices as Metro Mile argue that they have rolled out an update that automatically over-the-air is installed.The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns that there is no way to verify that the update is installed.

Users who do not know whether their dongle is vulnerable therefore be advised to remove the device until the update can be confirmed. Through the leak, an attacker can cause damage to the car or provide human injury, according to the CERT / CC.According to Wired would still driving thousands of vulnerable cars, mainly in Spain.

Thursday, 18 June 2015

Serious Leak In Keyboard Software Samsung Smartphones


Researchers at the keyboard software installed on many Samsung smartphones found a vulnerability that could allow an attacker who between users and the Internet is to execute arbitrary code with system privileges on the device. Samsung Galaxy S phones, including the Mini S4, S4, S5 and S6 are standard version of Swiftkey keyboard.

This software runs with standard system privileges and regularly checks for updates. However, monitoring will take place over HTTP, which means that it is vulnerable to man-in-the-middle attacks. An attacker who can intercept this update checks and then offering a malicious update can execute arbitrary code as the camera with system privileges. Even if the software is used can not still be attacked, according to researchers from NowSecure . Who published a web page where users can check whether they are vulnerable. According to the researchers, the problem is present at about 600 million sets.

The CERT Coordination Center ( CERT / CC ) at Carnegie Mellon University suggests that the probability of an attack, depending on how often the software checks for updates, it is possible small. Samsung has now released a firmware update for telecom providers. In case users do not receive over-the-air update is still advised to avoid unreliable networks including open Wi-Fi networks. The use of unreliable networks increases the chance of becoming a victim of a man-in-the-middle attack, according to the CERT / CC.