Showing posts with label Cisco. Show all posts
Showing posts with label Cisco. Show all posts

Thursday, 15 October 2015

Microsoft Tackles Infections By Tesla Crypt-Ransomware


For Windows users against ransomware to protect Microsoft millions of computers on the presence of the Tesla Crypt-ransomware checked. Tesla Crypt is a form of ransomware that appeared in March this year and like other kinds of ransomware encrypts files for ransom.

What Tesla Crypt apart is that it searches for a large number of file extensions to encrypt and this has provided the specific iTunes and computer games. In recent weeks left tens of thousands of Windows users infected with this form of ransomware. In the first half of 2015 would Tesla Crypt and CryptoWall, another notorious ransomware families, more than a half million Windows computers have been infected. The victims of Tesla Crypt  had to pay almost 500 euros to recover their files.

Earlier versions of Tesla Crypt made ​​a mistake, making the files without paying could be decrypted via a free tool from Cisco. However resolved in new versions this error. Although there is a decrease in the number of infections is still Microsoft has decided to malware via the Malicious Software Removal Tool to detect (MSRT) and remove. The MSRT is a virus removal tool built into Windows that every month during the monthly patch cycle is updated with new virus definitions and perform a scan at the same time on the system.

Monday, 12 October 2015

Companies Hacked Via Leak In Cisco Web VPN


Attackers abuse a vulnerability in the Cisco Clientless SSL VPN to hack into companies and organizations, warns security firm Volexity. The Cisco SSL VPN Service, also referred to as Cisco Web VPN, is a web-based Virtual Private Network (VPN) to employees via their browser to access the corporate network and servers can get.

To log in to the VPN, users must enter a user name and password. A vulnerability in the Cisco Web VPN, which was patched in October 8, 2014, makes it possible to add malicious code to the login page. Remote attackers can do this and have developed a password or other credentials required. Through the malicious code that is placed on the login page it possible to store the credentials of users, which the attackers themselves can then login.

Cisco warned in February this year for attacks where the vulnerability was used, but that still take place, according Volexity. Medical companies, universities, academic institutions, manufacturing companies and think tanks could now be attacked using this method worldwide.

According to the security company, it is not clear whether the vulnerability has been used for all attacks. It is not excluded that some other attacks observed the attackers themselves already had access to the login page and so could add malicious code. It does not matter if companies use two-factor authentication since the second code to be entered when logging can be intercepted using the custom login page.

Sunday, 11 October 2015

Cisco Unveils Previous Malware Attacks On Routers



It was recently announced that networking giant Cisco routers had become the target of malware, but in the past have more of these incidents took place. In total there are six malware attacks that have been discovered over the past four years and examined, let Cisco know themselves.

The most recent incident concerns the SYNFUL Knock-malware, with attackers install a custom operating system on routers. Through the malware continue to keep the attackers access to the corporate network, even resetting the router. To install malicious operating system make the attackers use physical access or stolen credentials.

The first two incidents where malware was used date from 2011 and 2012. These were probably created malware specifically targeted against a particular target. Also in this case, the routers of the control system was modified, with the aim of weakening of the encryption. The traffic seemed therefore still encrypted, but the attackers could then decrypt the traffic with less effort.

IPv4 packets

Two other incidents were identified in 2013. Again knew the attacker with stolen credentials of the administrator to access the router was added code. This code ensured that certain IPv4 packets were sent to the attacker. In addition, the attacker using the additional code reach an IPv4 address that was normally not accessible from the Internet.

End 2014 the fifth incident was noticed. Again, the attack began with stolen credentials. Compared to previous ones, the attackers used this time advanced malware that was able to survive a reboot of the router. This malware also aimed to intercept certain packages and provide the attacker access from the public Internet.

Cisco says it has taken since the discovery of the first malware various measures to better protect the equipment. The attacks, however, continue to evolve. Therefore, the networking giant says that it will add to the medium detection and recovery capabilities to the equipment.

Wednesday, 7 October 2015

Cisco Disrupts Extensive Network Of Cyber Criminals


Network manufacturer Cisco has disrupted an extensive exploit kit network that criminals tried to infect surfers with ransomware and other malware. How many people have been victimized and how many criminals have earned the ransomware is unknown.

The action was directed against the Cisco Angler-exploitkit, used by cyber criminals to infect Internet users via vulnerabilities in Adobe Flash Player, Silverlight and Internet Explorer with malware. Cisco researchers discovered that the Angler-exploitkit used a large number of proxy servers, which were located primarily in the provider Limestone Networks. The study showed that the Angler-exploitkit one party was used extensively. This party was for 50% of all activity of the Angler exploit responsible and tried every day 90,000 people to infect via the aforementioned vulnerabilities.

Infections can only occur when users are using vulnerable software, for example, because they have no security updates have been installed. By working with Limestone was extensive information about the Angler-exploitkit are collected.Eventually all hosting providers where the proxy servers were informed, who then Switch off servers. Therefore, the cyber criminals had no access to the Angler-exploitkit.

Juggling With Figures

Cisco sets the announcement about the operation that cyber criminals through the exploitkit $ 60 million per year earned by ransomware. It is important to mention that this is an assumption and not a fixed amount. There is no hard evidence how many criminals have earned through their ransomware. The estimate of Cisco is based on several assumptions. For example, pointed to previous research showing that 40% of Internet users being attacked via the Angler-exploitkit also touches actually infected.

Further, it would be installed in 62% of infections via Angler ransomware. In addition, the average ransomware amount would be $ 300. According to figures from Symantec would actually pay 2.9% of the victims. Because all that matters to multiply with each Cisco eventually comes to an amount of 60 million dollars. As stated, this is an unconfirmed amount based on certain assumptions.

Thus, researchers from Dell SecureWorks to 0.4% of the ransomware victims pay the demanded ransom. Other studies a percentage of 0.27% to the front. If Cisco with these percentages, the amount would have expected would be much lower outage, which includes fluctuations in the number of successful infections and the number of ransomware installations.

Saturday, 22 August 2015

Apple Close Critical Holes In Windows Version QuickTime


For users of QuickTime there's a new version appeared which have been addressed several critical vulnerabilities. Through the nine vulnerabilities, an attacker can crash the Program, or any computer can perform, such as installing malware.

The opening of a malicious media file would be sufficient in this case. Six of the nine vulnerabilities were found by researchers from network giant Cisco, while one vulnerability on account of Apple came. Apple advises users to upgrade to QuickTime 7.7.8, which through Apple.com and Apple Software Update to download.

Sunday, 2 August 2015

Cisco Warns Of Emails With "Windows 10 Upgrade"


Cyber criminals have seized the launch of Windows 10 to distribute emails that attempt to infect surfers with ransomware. Before warns network giant Cisco . Windows 7 and Windows 8.1 users can upgrade to the new Windows version.

And cyber criminals now play in. The emails have the subject line "10 Free Windows Update" and seem to come from update@microsoft.com. The message that the recipient can upgrade to Windows 10. For this, the attached "installer" should be opened. In reality, the e-mail attachment "Win10installer.zip" a variant of the CTB Locker, a known form of ransomware that encrypts files on the computer for ransom.

Then users get 96 hours to pay the ransom in bitcoin, otherwise they lose their files. According to Cisco, the ransomware is now widely distributed. The networking giant also advises users to backup their files and keep these offline, so they can not be attacked by cyber criminals.

Hashes:

SHA256: ec33460954b211f3e65e0d8439b0401c33e104b44f09cae8d7127a2586e33df4 (zip)
aa763c87773c51b75a1e31b16b81dd0de4ff3b742cec79e63e924541ce6327dd (executable)

Sunday, 28 June 2015

Researcher: Root Certificates Added Quietly Windows


Microsoft has quietly 18 new root certificates to Windows without notice has been here somewhere. So says a researcher with the alias " Hexatomium ". Root Certificates determine which SSL certificates are trusted by the operating system.

It is therefore important to know which organizations and certificate authority's root certificate is added. The researcher reports that he is the new root certificates through the RCC-auditing tool has discovered. Through the program, users can control which root certificates are heard in the Windows root CA to store and which have been added quietly.

In addition to the SHA1 hash of the license and the name of the associated certificate authority is no additional information is available. On Hacker News lets a user know that the certificate authority named RXC C2 is actually Cisco. Remarkably Cisco sets its own documentation Cisco RXC certificate policy ( pdf ) which certificate authorities should always use meaningful names. Feather in the list of additional root certificates include certificates of Swedish, Tunisian and Indian authorities.

Saturday, 27 June 2015

Cisco Fixes Problems Again With Standard SSH Keys


Cisco offers weather updates for different products released due to the use of standard SSH-keys. Using the default SSH keys, an attacker remotely without valid credentials on a login system with root privileges. The only thing that is required is that the attacker can connect to the platform.

According to Cisco, the problem is that all installations of the Web Security Virtual Appliance (WSAV), Email Security Virtual Appliance (Esau) and Content Security Management Virtual Appliance (SMAV) share the same authorized SSH key for the remote support functionality. Also, an attacker via the SSH host key can also all appliances is the same, and all communications between virtual appliances decrypt and mimic.

Cisco has released updates to fix the problems. Last October there appeared an update of a similar problem in the Cisco Unified Communications Manager Domain. The networking giant has announced that to their knowledge the newly discovered problems are not yet attacked or were previously known on the Internet.

Wednesday, 6 May 2015

Malware Destroys MBR Hard Disk During Analysis



It is known that malware creators do all sorts of tricks to analysis to prevent their creation but a new one does go very far and "destroy" the Master Boot Record (MBR) of the hard disk, so the computer will not boot. Let researchers know Cisco.

The MBR contains information about the type and location of logical partitions on the hard drive. It is essential for the computer to be able to start. The now discovered Rombertik-malware focuses on the MBR in the case of analysis. The malware spreads via email attachments and poses as a PDF file. In reality it is a SCR file the malware.

Once users open the attachment Rombertik first check whether it is running in a sandbox. Sandboxes are often used by researchers to analyze malware and is regularly checks for malware on the presence of this type of analysis environments. In case there is no sandbox is found, the installation continues. Rombertik is designed to steal passwords from browsers.

Before it does this is a final check there is still carried out in order to check that the malware is not analyzed via the memory.If this check fails to Rombertik strikes and destroys the MBR and overwrites partitions with "null byte", so recovering data from these partitions is difficult. The MBR is further adjusted so that the computer enters an infinite reboot loop. If the malware does not have permissions to overwrite the MBR will overwrite all the user's files in the home directory and encrypt.

Saturday, 11 April 2015

Group bombarded SSH Servers With 300,000 Passwords



A group of cyber criminals that has been active since June last year conducts large-scale attacks against SSH servers, whereby through more than 300,000 unique passwords attempting to log in. Once access to the server is obtained finally installed a DDoS rootkit.

Through this rootkit can execute the attackers acquired server DDoS attacks. The cyber criminals by Cisco and Level 3 as "SSHPsychos" and "Group 93" indicated. The group would generate as much traffic with the login attempts that all joint attacks on SSH from other parties combined into nothing fall. The attacks appeared from different netblocks (ranges of IP addresses) to arise. In cooperation with backbone provider Level 3 was decided that the group netblocks disabling used.


As part of the process, Level 3 warned the responsible providers, which the group cybercriminals suddenly used a new network for their scans and attacks. Because of this sudden transition decided Cisco and Level 3 to remove the routing options for both the old and new netblock. According to Cisco, this will "hopefully" slow down the activities of the group for a certain time.

The networking giant notes that "detectors and protectors" can no longer sit on the side as cybercriminals in such flagrant attack systems. However, the measures affect only the part of the Internet that is provided by Level 3. Cisco calls than other parties in order to block malicious traffic from this group on the Internet. "By working together, we can eliminate a group that makes no effort to hide their malicious activities," the company said.

Monday, 23 March 2015

Leak In Cisco IP Phones Allows Eavesdropping Possible


Networking giant Cisco warns of vulnerability in the SPA300 and SPA500 IP phones allowing attackers without credentials distance calls can eavesdrop or to gain access to the phone to call then himself. However, an update is not yet available.

Also could be used for a successful attack further attacks, said the advisory . The vulnerability is caused by authentication settings in the default configuration. An attacker would through a specially prepared XML request to send here to abuse a vulnerable device.

Cisco says that in order to exploit this vulnerability, an attacker allowing access to a trusted internal network behind a firewall should be to send the XML request. This requirement would reduce the possibility of a successful attack. Since there is no update available system get the advice to turn XML Execution authentication in the configuration settings.Furthermore, could protect a "solid firewall strategy" systems and can be considered to give only trusted IP addresses access.

Sunday, 22 March 2015

Companies Change Delivery Address Cisco Equipment Due To NSA


Some companies use other delivery addresses when ordering equipment from Cisco in order to evade the NSA, so, Cisco CEO John Stewart at a conference to know. Following his revelations of whistleblower Edward Snowden, showing that the NSA intercepted orders such as routers and then provides a backdoor. On one of the photos that were shown publicly through Snowden how NSA staff a box of Cisco equipment opens.

Stewart, chief security and trust officer at the networking giant says that it prevents companies specify delivery addresses that have nothing to do with the client, reports PC World . This should make it theoretically difficult for the NSA to focus on a particular company. Stewart did know, however, that once Cisco provides the equipment to a shipping company, it has no control anymore. However, Cisco could collaborate with customers to better control the integrity of delivered systems.

Yet then Stewart will always be risks that can not be avoided. "As a truly motivated team it has provided you, and they do this for a long period of time, this increases the chance that they will succeed again." Stewart was at the conference whether Cisco has ever encountered strange hardware in its own products which was placed there. "No, and that we could not know, because the only people who know for sure that the NSA," the CEO said.

Friday, 20 February 2015

Cisco Warns Of Attacks On The ASA VPN Software


Cisco warns organizations for attacks on the ASA software allowing attackers credentials can get their hands on for VPN connections or malware can spread. The vulnerability is in the Clientless SSL VPN software. The software provides ASA-administrators the ability to customize the appearance of the Client SSL VPN portal.

A vulnerability in the "customization framework" which the adjustments are made allow a remote attacker without login details the contents of the Clientless SSL VPN portal adjust. This makes it possible to steal login details, cross-site scripting (XSS) and other web attacks to perform and distribute malware instance. Once a VPN portal is compromised adaptations of the persistent attacker.

Restarting the server or changing the ASA Software custom objects will does not remove. The leak was unveiled late last year and patched. Yet who now find attacks rather abuse the vulnerability. In addition, on the Internet also exploit code appeared. Cisco has in the warning information also given how compromised VPN portal can be recognized.

Wednesday, 11 February 2015

Chanitor Trojan: "Maleficent Microsoft Volume Licensing Spreading Malware"


Several companies have recently received an email from the Microsoft Volume Licensing Service Center (VLSC) comes appeared and attempts to spread via a clever trick JavaScript malware. Through the VLSC companies to manage their Microsoft licenses. The message that goes around is very similar to the emails that sends Microsoft normally on the VLSC and a personalized salutation. According to the e-mail recipients may register via the attached link for the VLSC.

The link actually points to a hacked WordPress server. Using JavaScript, however, the real-VLSC Microsoft Web site shown where users can log in. However, there is simultaneously a zip file provided that the hacked WordPress server originates.This seems like the file from the Microsoft Web sites originates, although the hacked WordPress server is listed at the download location.

Offered zip file contains another .scr file is a Trojan horse. This "Chanitor Trojan" then connects to the Tor network. According to Cisco, the malware at the time was that the e-mails were detected around 9 out of 57 virus scanners on VirusTotal.

Hashesh:

1b147fc9d5342ca0fa59207d366ec4fb  (VLSC Microsoft.zip)

6266dc7f68e98b3a52908a7e2b5fe4eb (Volume_Licensing_Service_Center_details_7834892334.scr)

Sunday, 23 March 2014

NSA spying on Chinese networking giant Huawei


The NSA has a widespread espionage attack against China conducted in which both the Chinese government and Chinese companies were targeted. Reports that the German newspaper Der Spiegel on the basis of documents received from the whistleblower Edward Snowden.
Among the attacked companies are banks and telecommunication companies. However, the NSA focused in particular on the Chinese networking giant Huawei, the second largest network provider in the world and a competitor of the U.S. Cisco. In 2009, the U.S. Secret Service began an operation that internal "Shot Giant" was mentioned. A special NSA unit managed to break into the corporate network from Huawei and copied a list of 1,400 customers, as well as internal documents on training were engineers on the use of Huawei products.

Source

From a secret NSA presentation shows that the NSA also managed to gain access to the internal e-mail archive and the secret source of Huawei products. The network where the U.S. Secret Service had broken up generated as many e-mail and data that the NSA did not know what to do with it. The reason for the break-in at the company let the NSA in the documents know that many of the targets via Huawei products communicate. "We want to make sure that we can attack these products," said an official in one of the secret documents.
In a statement, says a spokesperson from the network giant that if the reports are correct it is very ironic, since the United States Huawei always have accused the Chinese government would help in espionage. More details about the espionage attack by the NSA will Der Spiegel published tomorrow.