Showing posts with label Crowd Strike. Show all posts
Showing posts with label Crowd Strike. Show all posts

Tuesday, 20 October 2015

American Company Claims Chinese Espionage Via SQL Injection


An American security company claims it has detected several cases of Chinese cyber espionage via SQL Injection, but concrete details and evidence are given. Does mention Crowd Strike in the blog posting about the cyber espionage frequent own security product.

About three weeks ago, China and the United States decided not to bother with the steal intellectual property via the internet. According Crowd Strike has seen the number of attacks in which the "high degree of certainty" could state that carried out by Chinese attackers. In which this assumption is based not reported by Crowd Strike.

Many of the attacks directed against companies in the technology and pharmaceutical sectors, Web servers via SQL Injection could be hacked. SQL Injection is a problem that has been known since the end of 1998, but is still found in many websites. Through SQL Injection attackers can communicate with the database behind a website and perform various tasks, which should not actually be executed.

In this way, it is possible, among other in order to steal the contents of databases, for example, user names, email addresses, and whether or not encrypted passwords. In this case the attacker SQL Injection eventually use to install a Webshell. Through this Webshell can be obtained access to the internal network of the victim. Despite the report hopes Crowd Strike which progress could be made, and norms and values ​​can be established countries.

Wednesday, 13 May 2015

Virtual Floppy Drive Creates Serious Leak In Virtual Machines


Researchers have discovered an eleven year old and serious vulnerability in various virtualization platforms, allowing an attacker to escape from virtual machines. The vulnerability has security Crowd Strike called " Venom got "and is located in the virtual floppy disk controller (FDC) of QEMU. QEMU, which stands for Quick Emulator, is free and open source virtualization software.

The vulnerable code is used by various appliances and virtualization platforms including Xen, KVM and QEMU client. Popular virtualization software such as VMware, Microsoft Hyper-V hypervisor and Bochs is not vulnerable. By using the vulnerability that may escape an attacker out of the virtual machine and then, whether or not to get over the other virtual machines, access to the network. While floppy disks no longer be used, would provide many standard virtualization solutions from a virtual floppy drive.

By attacking the Venom leak can get assailants as Crowd Strike access to intellectual property of companies, as well as sensitive and personally identifiable information. Possibly would be thousands of organizations and millions of users of sensitive virtual machines use risk. The leak would be present in the code since 2004. Yet there are no attacks observed in the wild. To carry out the attack must have an attacker or malware on root or administrator privileges on the host system.

For QEMU Project, Xen Project and Red Hat have now been released security updates. Another solution is to configure the virtual machine hypervisor in a certain way, the impact of the vulnerability can reduce or even prevent altogether. Something Crowd Strike in the advisory explains.