Showing posts with label Cyber Attackers. Show all posts
Showing posts with label Cyber Attackers. Show all posts

Wednesday, 14 March 2018

Researchers Let Malware Send Data Via Loudspeakers



Researchers at Ben-Gurion University have developed malware that can steal data from systems that are not connected to the internet via passive loudspeakers. Because of the risk of attacks, it is a lot of advice to not connect computers with confidential data to the internet.

This is also called an air gap. An offline computer can still be infected, for example via USB sticks or a malicious employee. In order to steal data from an infected offline computer, Ben-Gurion University researchers have developed various methods in the past, such as the use of speakers , air conditioning , sound from the hard disk , fans , radio waves , infrared cameras , scanners , heat emitted. , usb radiation , mobile phones , hard drive lights and router lights to return the data directly to the attacker or via an infected computer or smartphone connected to the Internet.


The researchers are now demonstrating a new method called Mosquito ( pdf ) in which "speaker-to-speaker" communication is used to steal data from a computer that is not connected to the internet. The scenario that the researchers sketch consists of a room with two computers, one of which is and one is not connected to the internet. Both computers are infected with malware and have passive speakers or headphones. The malware then exploits a feature of the audio chip that changes the connected speakers of output device into an input device (microphone).

Malware on one computer can then transmit information via the speakers and the use of ultrasonic waves that are collected by the speakers of the other computer, which have in fact become a microphone. In this way it is possible to send data at a speed of 10 - 166 bits / sec at a distance of 9 meters between the computers. If headphones are used instead of loudspeakers, a distance of 3 meters is possible.

The researchers state that in heavily guarded settings it is common to ban both active and passive loudspeakers, in order to create an air gap. Less stringent rules prohibit the use of microphones, but allow the use of "one-way" speakers. In many cases, the policy and security measures do not apply to modern headphones, which are basically non-powered and unenhanced loudspeakers. Mosquito could be effective in these situations.

To prevent such attacks, organizations can take various measures, such as prohibiting the use of speakers, headphones or earphones, using active speakers, disabling the audio codec in the bios, detecting ultrasonic transmissions, and using low-pass filters.

Sunday, 11 March 2018

Avast: Attackers CCleaner Also Wanted To Install keylogger



The attackers who hacked software company Piriform last year and added a backdoor to the popular CCleaner tool were also likely to install a keylogger on infected systems, according to anti-virus company Avast , which is the owner of CCleaner.

Last September, Avast announced that attackers had hacked CCleaner developer Piriform and added malware to the official version. This infected version was downloaded by 2.27 million users. The malware was added to the Piriform development platform between 11 March and 4 July 2017. The software company was acquired by Avast two weeks later on 18 July.

The first phase of the malware was to gather information about CCleaner users, such as the name of the computer, installed software and active processes. The second phase consisted of downloading additional malware. However, this was done with a select number of machines. Eventually, 40 computers received this additional malware. These included systems from major tech companies such as Intel, Samsung, Sony, Asus, NEC and the South Korean telecom provider Chunghwa Telecom.

There is no evidence that a third step has been carried out, but Avast has now found information indicating that it may have been planned. During the investigation into the hacked Piriform infrastructure, early versions of the first and second phase of the malware were discovered, as well as a tool called ShadowPad. ShadowPad is used by cyber criminals to control computers remotely. The tool was installed on four Piriform computers on April 12, while the second phase of the malware was already installed on March 12.

The older version of the second phase malware connected to a command & control server. The servers were no longer active at the time Avast analyzed the computers, so it is unknown what was downloaded, but given the time window it was probably ShadowPad. The Avast researchers also discovered ShadowPad log files with keystrokes from a keylogger installed on the computers. The keylogger had been active since 12 April and had stored keystrokes of all kinds of programs. The encountered version of ShadowPad appeared to have been specially made. Avast thinks that the attackers who had adapted especially for Piriform.

In addition to the keylogger, the attackers also installed a password builder and tools to install other software. According to Avast, there are no indications that ShadowPad is installed on the computers of CCleaner users. The virus fighter does state that it was the third phase of the attack. It is not known whether the attackers wanted to install the keylogger on all 40 attacked computers in the second phase, or just a few or not at all, this is still in under investigation.

Monday, 23 October 2017

Attack Via Office DDE Feature Also Works In Microsoft Outlook



The Microsoft Office DDE feature currently used to attack Internet users through Word documents also works in Microsoft Outlook, so researchers have shown. The attack can be performed by sending emails and calendar invitations set up in Rich Text Format (RTF).

The Dynamic Data Exchange (DDE) feature of Microsoft Office makes it possible to inject data from, for example, an Excel document into a Word document. This will add code to one document that points to the data in the other document. Instead of a document, malicious code may also be linked. Attackers now use this feature to infect internet users through Word documents with ransomware and other malware.

The attackers send emails that have attached a Word document. As soon as the recipient opens the document, he will see several dialog boxes asking for permission to run the code that is linked. However, it is not necessary to send Word documents, so researchers have shown . Researcher Kevin Beaumont found a way to use the DDE feature in Microsoft Outlook via e-mail. In this case, users get the same notification as with Word asking for permission to execute code.


In addition to a RTF-generated email, the attack can also be performed via a calendar invitation. According to anti-virus company Sophos , the attack is easy to stop, users need to click on no-click in the first window asking for code execution. If the user clicked yes in the first window, a second dialog will appear for permission. Only when yes is clicked is the code called through DDE executed. Another option that users can apply to protect themselves is to display emails in plain text.

Tuesday, 10 October 2017

ISC Warns Usb Cable With Built-In Sim Card


The Internet Storm Center (ISC) warns of usb cables that are sold and have a built-in sim card, mobile phone and microphone. Attackers could perform attacks or stolen data through such cables, according to Johannes Ullrich of the ISC.

For example, the $ 30-usb usb cable responds to text messages and can send those GPS coordinates. It is also possible to activate and listen to the microphone via a text message. "The main risk is to leave systems (and cables) left unattended in places with some public access," Ullrich notes. This applies, for example, to systems in hotel rooms or classrooms.

Users therefore get the advice to mark their cables so that they can not be replaced by other cables. In addition, the cables must be fastened. In conclusion, Ullrich states that the "usb spy cable" in question is easy to recognize when users know what to look for. "But I'm sure they can make a smaller cable and maybe a version that's a bit more expensive and not so easy to show the sim card."

Wednesday, 5 July 2017

Fourth Largest South Korean Bitcoin Stock Exchange Bithumb Hacked



Attackers have hacked the fourth largest South Korean bitcoin stock exchange Bithumb and data and money of users stolen. Bithumb is one of the largest exchanges where digital currency bitcoin and ethereum traded. The attackers were able to access the personal information of nearly 32,000 Bithumb users, including names, mobile phone numbers and email addresses, so let know Brave New Coin.

According to the exhibition is about three percent of the customers. Let customers know that converted stolen millions of euros to digital currency, but Bithumb suggests that the attackers had no direct access to client funds. According to the fair, the attackers managed to penetrate through the computer of an employee. The attackers would then use the stolen personal information to calling customers and to steal additional information which transactions could be carried out.

Bithumb discovered the data breach on June 29 and alerted the authorities on 30 June. More than 100 Bithumb users have been reported to the South Korean police. The exchange said the victims of the data breach will pay a fee of the equivalent of 76 euros. Users who have suffered Further damages will be compensated for as soon as the amount is confirmed, so notify South Korean media.

Wednesday, 10 February 2016

Adobe Close Critical Vulnerabilities In Flash Player And Photoshop



Adobe has patched critical vulnerabilities in Flash Player and Photoshop computers could allow an attacker to take complete. In the case of Flash Player is about 22 critical vulnerabilities which allowed an attacker to execute arbitrary code on the computer, such as installing malware by just visiting a hacked website or see it from an infected ad.

There was no further interaction required from users. As far as known vulnerabilities are not attacked on the Internet. Since attackers often develop after the release of Flash Player updates exploits to attack unpatched users, Adobe advises to update to Flash Player version 20.0.0.306 within 72 hours. This can be done via the automatic update function or Adobe.com. In the case of Google Chrome, Internet Explorer 10 and 11 on Windows 8 and 8.1 and Internet Explorer 11 and Microsoft Windows 10 Edge Embedded Flash Player will be updated using the browser. Through this Adobe page can be verified that the system version is installed.

There is also a security update for Adobe Photoshop CC and Adobe Bridge CC appeared. The update fixes three critical vulnerabilities that an attacker could take over your computer if opened a malicious file. Because Photoshop traditionally not been a target for attackers, Adobe advises users and administrators to install the update if it suits them. Updating via the built-in updater of drawing programs. In the case of Photoshop CC 02.04.2014 is the update to download only via Adobe.com.

Tuesday, 1 December 2015

Linux Ransomware Encrypts 3000 Websites



In recent weeks there have been the ransomware which it has provided encrypted hit 3,000 websites on Linux web servers. This places the Russian anti-virus company Doctor Web, which relies on weather data from Google. It is called ransomware Linux.encoder.

Attackers behind ransomware deliberately set WordPress websites and online stores using Magento. Through a still unknown vulnerability know the attackers to gain access to the Web server that hosts the website and then perform Linux.encoder.This ransomware, which additional duties require encrypts all kinds of files, and then asks one bitcoin, what with the current exchange rate is 349 euros. It is unknown how many webmasters have finally paid the ransom.

F-Secure reported in early November, about 36 people had paid, which at that time corresponded to an amount of 12,000 euros. Due to an error encrypted files can be decrypted without paying. The Romanian anti-virus company BitDefender has developed a free decryption tool for victims. From examination of the virus fighter shows that an early version of ransomware already was distributed on August 25 of this year and then seven people paid the ransom.

Saturday, 28 November 2015

Leak VPN Providers Can Reveal IP Address Users


A vulnerability in some VPN providers can ensure that the real IP address of users is revealed, warns VPN provider Perfect Privacy. A VPN (Virtual Private Network) is a secure connection between a computer and a server elsewhere on the Internet.

This connection is encrypted which others can not observe. All Internet traffic to and from the computer goes through this route shielded and can on this part will not be overheard. Additionally, VPN users can thus protect their IP address as websites visited only see the IP address of the VPN provider. According Perfect Privacy walk users of some VPN providers still risk their real IP address is known.

Port forwarding

The problem is with VPN providers offering port forwarding. It does not matter whether users of the VPN providers themselves use port forwarding, only the attacker must set it. To determine the IP address of a victim, there must be fulfilled several conditions. For example, the attacker must have an active account with the same VPN provider and the victim. The attacker must know the 'exit' IP address of the victim and the victim to open a file or page.

An attacker who port forwarding is activated can then request to see the image or website which the real IP address of the victim is from. In total, nine tested Perfect Privacy VPN providers, of which five were found vulnerable. These parties have been notified. The problem, however, with other VPN providers are not tested, warns Perfect Privacy.

BitTorrent

According to security expert Darren Martyn can leak be used to expose BitTorrent users who illegally download copyrighted material. To shield their IP address are BitTorrent users who use a VPN service. By leak holders can still see the IP addresses of illegal downloaders. Martyn expects that companies connected with suing copyright infringers concerned will use this vulnerability to sue BitTorrent users.

Hacked Site Reader's Digest Spread Malware


Attackers have managed to hack the website of Reader's Digest and use this now to spread malware. Before that anti-malware company cautions Malwarebytes. According to the company, there is an increase in the number of hacked WordPress websites and Reader's Digest is one of them.


On the hacked websites is placed code that visitors unnoticed to a page with the Angler-exploitkit forward. This exploitkit is using known vulnerabilities in Adobe Flash Player and Internet Explorer users have not patched. In case the attack is being installed Bedep Trojan on the computer successfully, which can install additional malware again.

Reader's Digest was a few days ago warned by Malwarebytes, but the security company and got no response when a blog posting about the infection appeared online yesterday distributed the website still malware.

Friday, 27 November 2015

IT Vendor LANDesk Warns staff After Hack


The American IT vendor LANDesk has staff warned that their data may have been stolen in a burglary on the network, but LANDesk employees to know that the hack goes much further and there may also be source code was stolen. LANDesk develops software for computer management.

The company has issued a warning recently that suspicious activity is detected on the IT systems. In addition, the data may be stolen by employees, the company said. Details will not, however, give the IT provider, but it does know that the environments of customers using the LANDesk software no risk. Across IT journalist Brian Krebs tell several employees that the attackers may have been since June 2014 had access to the systems. This is clear from the logs.

The burglary was discovered only after an employee complained about a slow internet connection. The survey also showed that the attackers passwords IT manager and system had been compromised. Lists also were found with source code and build evers who had compiled the attackers. Through the source code, it could be easier for attackers to find vulnerabilities in the software and allows companies to attack. However, a spokesman would not confirm or deny that the break-source code has been captured.

Thursday, 26 November 2015

Weather Teen Arrested For Attack On TalkTalk


The British authorities have arrested a teenager again because of the attack on the ISP TalkTalk. In the attack, the data were more than 156 000 customers stolen. In total there are now arrested five people, including four teenagers. The teenager who is now arrested a 18-year-old boy from Wales.

He is suspected of extortion. Shortly after the burglary last month at the British Internet service was announced the director said that the company was extorted by the assailants. Further details of the fifth suspect are not given. Besides the 18-year-old boy also be a 20-year-old man, two boys aged 16 and a boy of 15 suspected of involvement in the attack. Three of them will continue to be heard next March. Due to the burglary, which is still not known how that occurred, TalkTalk decided all subscribers a gift to give.

Wednesday, 25 November 2015

More Dangerous Certificates On Dell Computers Discovered



On Dell computers appear to present certificates are more dangerous than just eDellRoot root certificate which since yesterday is to warn and allowing users to be attacked. Reported that the security firm Duo Security on the basis of its own research.

Dell turns since August computers to install the same root certificate called eDellRoot, including associated private key.Something that, according to researchers at Duo Security is a pretty big mistake. " Using the certificate can be man-in-the-middle attacks against users are executed and it is for example possible to install malware or encrypted connections to eavesdrop. In addition, there appears to be a second eDellRoot certificate. The second license was found on 24 IP addresses. Which models are exactly is unknown.

"It suggests that Dell is deliberately identical keys in other models. This is a blatant disregard for basic cryptographic security," said the researchers. One of the systems used was accessible via the internet and certificate to offer Web services over HTTPS was a SCADA system. Such systems are used, among other vital infrastructure.

Finally an Atheros Authenticode certificate was also detected for the signing software. The password of the certificate was cracked within six hours. However, the certificate was found to have expired already, which restricts the possibility for abuse. However, it seems that the certificate was in use at the time that it was still valid.

Manufacturers Do Not Learn

According to the researchers, the discovery reveals a disturbing trend among manufacturers. Adding Trusted Certificates to a system, and especially root certificates can expose users to unnecessary risks. "Unfortunately it appears that manufacturers do not learn from past mistakes and keep them to keep repeating," the conclusion of the research (pdf). Dell has now indicated that it eDellRoot certificate via an update will be removed.

Dell Will Remove Dangerous Certificate Of Computers



Computer manufacturer Dell will begin today with the removal of a certificate that allows users to be attacked, as the company has announced. Since August this year, laptops and desktops from Dell comes with a certificate that contains the private key.

Attackers can use this key to sign malware for example, so it looks like that comes from Dell, and are also man-in-the-middle attacks on HTTPS sites possible. According to Dell, the certificate is no malware or adware. It was deliberately placed on systems to help customers. Through the certificate Dell's help desk can identify the service tag of the system and quickly identify the computer model, operating system and other components.

The computer manufacturer states in a blog posting that the certificate inadvertently introduces vulnerabilities. Something that Dell makes excuses for that. The company now has instructions (docx) put online how the certificate can be removed in question, and will also release an update starting today to remove the certificate. Also, all new systems will be delivered without a certificate. In the blog posting thanked Dell also researchers Hanno Böck, Joe Nord and Kevin Hicks who published about the security issue. Dell customers who want to know whether they are vulnerable to these via this website testing.

Update

"The security and privacy of our customers are of utmost importance to Dell. The recent situation relates to an" on-the-box "support certificate is intended to provide customers a better, faster and simpler support experience. Until Dells regrets the license shall carry an unintended security vulnerabilities along with it. To solve this problem we will provide our customers with instructions to remove this certificate permanently from their systems, "

"We go to the instructions via email on our support website and communicate via our technical support, we go the Certificate of all remove Dell systems that need to be made. Please note:. Business customer an image of their own Managing this issue does not affect systems. Dell does not install any adware or malware. The certificate will not reinstall itself if it is properly disposed of according to the process recommended by Dell. "

It also has CERT Coordination Center (CERT / CC) at Carnegie Mellon University, a warning issued to the certificate. It is also recommended to remove the certificate.

Saturday, 21 November 2015

XSS Vulnerability Addressed In LinkedIn



Business networking site LinkedIn has a cross site scripting (XSS) vulnerability fixed in the website. Security Expert Rohit Dua from India Wednesday posted a message about the leak on Full Disclosure. LinkedIn Help forum did not have adequate security, the profile pages of LinkedIn were not vulnerable.


To exploit the vulnerability must be a user logged in. When starting a discussion on the Help pages, it was possible for an attacker to execute code in the form fields. The code then implemented, was also open to non-visitors.

LinkedIn has vulnerability - with the help of Dua - rectified within three hours, writes Threat Mail. According been a spokesman for LinkedIn are private data of users at no time in danger and there is no abuse of the vulnerability.

Thursday, 19 November 2015

Amazon Makes Two-Factor Authentication


Amazon has quietly for the shop two-factor authentication enabled. The option is currently still stand out. Logging in Amazon normally goes with a username and password. But for added security, users can now also receive a code on their phone they have to fill in the login.

The introduction of two-factor authentication will the attackers more difficult for someone else to log on because they need to know in this case, both username and password, but also have access to the smartphone.

An employee of Engadget discovered the new option this week. According to reports on Twitter, Amazon would be the new two-factor identification introduced about two weeks ago.

Two-factor authentication is a widely used method to prevent abuse of login data. Other major Internet companies that offer this login method, include Google, Twitter and Facebook.

Who at Amazon wants to use the two-factor authentication, should go to their account settings and select it by changing the settings for 'advanced settings'.

Tuesday, 10 November 2015

Researchers Crack Linux Ransomware By Design Flaw


Researcher managed to crack the Linux.Encoder-ransomware for Linux so that victims without paying their files to recover. The ransomware was last week announced by the anti-virus company Doctor Web. At the time, it was unknown how the ransomware spreading.

It was known that it was mostly web servers that were infected. Now the Romanian anti-virus company said Bitdefender attackers use a vulnerability in the popular content management system magento to access servers. Then they install the ransomware, which looks a lot like Windows ransomware. Like Windows-based ransomware encrypts Linux.Encoder files with AES. The symmetric key is then encrypted with an asymmetric encryption algorithm (RSA).

When designing the ransomare the creators have made ​​a big mistake, allowing researchers Bitdefender can identify the AES key without that first with the RSA private key must be decrypted. The ransomware does not use any keys and initialisation vectors for encryption, but leads these two pieces of information on a specific feature in combination with the time of the encryption. This information is easily retrieved and, according to the researchers, a major design flaw. They now have a tool(zip) has been developed which automatically encrypted files can decrypt.

Sunday, 8 November 2015

NSA Would Most Zero-Day Vulnerabilities In Software Report


The NSA would be 91% of the most critical zero-day vulnerabilities it finds in software used in the United States or developed report, as the US Secret Service let the website know. How many software vulnerabilities and what exactly is going unreported.

The remaining 9% of the vulnerabilities found is resolved before the NSA, the supplier can inquire or is not reported due to national security reasons. Zero-day vulnerabilities are vulnerabilities for which no security update from the vendor is available.Through this kind of leak attackers have a greater chance of a successful attack, for example, to gain access to systems.

"The US government is committed to an open, interoperable, secure and reliable internet. In most cases, the reporting responsibility of a newly discovered vulnerability clearly in the national interest," according to the explanation of the NSA.Secret Service claims that there advantages and disadvantages to the decision to report a leak. This could cause the possibility of being lost to collect important foreign intelligence among other "terrorist attacks" may occur.

The NSA now uses a process to determine when it reports a vulnerability. "While these decisions may be complicated, the government tends to be a responsible and discreet reporting vulnerabilities." According to current and former government officials, the reassurances of the NSA, however, misleading, because the Secret Service vulnerabilities yourself first used to conduct attacks them before the companies inform that these problems can fix and patches to users can roll, reports news agency Reuters .

Saturday, 7 November 2015

CryptoWall-Ransomware Ransom Increases To 700 Euro


There is a new version of CryptoWall-surfaced ransomware that encrypts file names, victims speaks in a derogatory way and the ransom amount has increased to 700 euro, so researchers at the forum Bleeping Computer discovered.

CryptoWall is a form of ransomware which kinds of files on the computer encrypts. For decrypting victims must then pay. The first variant was last May discovered. This release early victims still 500 for decryption. If victims do not paid this amount was increased to 1,000 euros a time. With CryptoWall 4.0 that figure has now 1400 euros.

The new version also stands out because not only the contents of files are encrypted, but the file names. This is probably done to frustrate victims and make it difficult to determine which files need to be restored, says Lawrence Abrams Bleeping Computer. Like previous versions, removes all CryptoWall 4.0 Volume Shadow copies, turn off System Restore and Windows Startup Repair. Also makes use of the computer, on the basis of operating system and processor, a unique identification number.

Another change in Crypto 4.0 is the text to see victims of an encrypted computer get. Namely, that it has acquired a derogatory tone. So victims are addressed as "Congratulations !!! You have become part of the great CryptoWall community."It is also assumed that victims do not understand the explanations about encryption. Next, the creators which CryptoWall is not malicious and that together with the victims make the Internet safe. How the new version spreads exactly is unknown, but previous versions used mainly e-mail attachments and unpatched software.

1,56,000 UK Customer Data ISP TalkTalk Stolen


During the attack on the British ISP TalkTalk which took place on October 21 stolen the data of over 156,000 customers, according to company research. For a long time it was unclear whether the attackers had managed to steal customer data and how many people would go then.

For example, take into account that the dates of possible 4 million customers were captured. Two weeks after the incident TalkTalk now determined the true scope of the attack. Thus, the data of more than 156 000 customers are approached. Of these customers are then more than 15,000 account numbers and bank codes approached. Furthermore, 28 000 partially unrecognizable credit and debit card numbers seen by the attackers.

In a declaration, the provider that the size of the attack is much smaller than was assumed in the first instance. "And we can confirm that the sensitive personal data of only 4% of TalkTalk customers at risk." The provider calls it a difficult decision to warn all customers about the risk before the actual extent of the data loss was apparent. Meanwhile, all customers are informed whose financial data have been accessed. How the attackers were able to gain access to the data is still not disclosed. Because of the attack are four suspects arrested, including three teenagers.

Friday, 6 November 2015

Microsoft Is Considering SHA-1 Certificates To Block Previously



Microsoft is considering because of recent research to SSL certificates with the SHA-1 algorithm to block half a year earlier than planned. From the screening shows that it is much cheaper to attack SHA-1 certificates than previously assumed.

A hashing algorithm is considered safe if it is for any input has a unique output and that output is not turning back so that imports can be traced. Because the output should not manipulate, hashes are used to demonstrate the validity of certificates and files, for example. Since 2005, however, there are collision attacks on SHA-1 is known where various input gives the same output.

Recent research by Marc Stevens of the Mathematics and Computer Science (CWI) in Amsterdam, Pierre Karpman from the French INRIA and Thomas PEYRIN NTU of Singapore shows that performing such a collision attack can be much cheaper than previously thought. This would also criminals can perform these attacks. This would make it possible for attackers to forge certificates for example.

Microsoft had previously announced to SHA-1 certificates block from 2017, but is now considering to introduce in the block next June. Seven months earlier than planned. Last month, showed Mozilla already know that it is considering to implement the SHA-1 blockade earlier, giving a date of July 1, 2016 was mentioned. Microsoft is now with other browser developers discuss the impact of the new date proposed is based on use and the feasibility of SHA-1 attacks.