Showing posts with label DNS Hijacking. Show all posts
Showing posts with label DNS Hijacking. Show all posts

Wednesday, 1 July 2015

Survey: Most VPN Services Leak IPv6 Traffic


Twenty percent of European Internet users use a VPN service to encrypt its Internet or IP address to foreclose, but many of these services leakage data users, say researchers at Queen Mary University of London (QMUL).

VPN services are among others used to visit for example censored or domestically not accessible websites, but also to encrypt traffic so for example, the home network can not monitor this. The researchers looked at the services of the 14 most popular VPN providers and found that there are 11 user information leaked, so leave them in their research report ( pdf know).This involves things like websites visited and the content of comments posted online. The problem is not with websites visited via HTTPS.

IPv6


The problem is caused by the leakage of IPv6 traffic, also referred to as "IPv6 leakage". IPv6 is the successor to IPv4, which is the standard now. The Internet Protocol is the communications protocol that is used to identify hosts on networks, and to determine their location. The advantage of IPv6 is that many more addresses are available, and provides the protocol features that are not present in IPv4. Many network operators steps now to IPv6, but many VPN services protect only IPv4 traffic.

For the study the fourteen most popular VPN providers were used and made from different devices with a Wi-Fi network connection. Attacks were carried out from this access point that could perform attackers. There was passive monitoring place where unencrypted data was stored, and "DNS hijacking, in which the users' browser was redirected to another location.

The researchers also looked at the safety of different mobile platforms when using VPN services and discovered that Apple's iOS offers more protection, but data from Android users can leak. "There are several reasons why someone wants to hide his identity and it is worrying that they are at risk, even though they use a service that is precisely designed to protect them," said QMUL researcher Gareth Tyson. He is particularly concerned about people living in repressive regimes and surfing via a VPN.

Tuesday, 31 March 2015

Infected Updates Distributed For Puush And FlashFXP


Users of programs Puush and FlashFXP has become the target of an attack in which infected updates were presented and distributed. Puush is a program for sharing screenshots. Via Twitter , the service says that malware was sent in the form of a Puush update for the Windows version. After the discovery Puush advised to close the app and scan the computer.

From unconfirmed investigation would show that the malware was designed to steal passwords from browsers. In our own research Puush saw however that passwords were sent to the attackers. There is now released an update for Puush that the malware removed and lets users know if they are or are not infected. In addition, users are advised to change all their passwords. Through a blog posting late Puush know that the server was hacked.

FlashFXP

A similar incident took place last week, only with the FTP program FlashFXP. At the forum FlashFXP users complained that they were offered an update that was not on the website. Attackers had the DNS of the domain using the automatic updater, liveupdate.flashfxp.com adapted and were able to spread infectious updates. According to the developer of the FTP program impact would be limited because FlashFXP first checks the digital signature updates before being installed.

In case the file does not have a valid signature features will be removed. Last week the developer published an update(5.1.0.3824) that users need better protection against DNS hijackings. So is now requesting updates controlled digitally. If the server does not respond with a valid digital signature, the server's response is ignored. Furthermore performed additional checks to verify that the signatures of downloaded files is really FlashFXP.

Friday, 27 March 2015

Malware Late Router Advertisements And Porn Websites Show



Researchers have discovered malware that attacks routers and then injects ads and pornography on websites that the user visits. Once the malware has been given access to the router, which is done by default usernames and passwords, the DNS settings are changed.

The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses. By adjusting the DNS of the router can fit criminals traffic from users via their server running. Most operating systems are configured to use the DNS settings of the router. Once a computer or other device to connect to the router, the custom DNS settings will be used.

With this modified DNS settings, it is possible for users to send by other websites, even if they tap the correct address in the address bar of the browser. In the case of custom DNS settings are requests to google-analytics.com intercepted. When users visit a website that used Google Analytics she redirected to a fake Google Analytics site.

Google Analytics is a service that allows websites to gain insight into the use of their website. If a website is viewed with Google Analytics, Google Analytics Javascript code which will download and run, after which the user's view is counted in the survey. Once the user to the fake Google Analytics site is redirected he gets malicious Javascript code which is then presented with advertisements and pornography on the website visited then injects.

Researchers from Ara Labs , which the malware discovered , argue that it is not a vulnerability in Google Analytics, but that the service because of the great popularity is the target. The makers of the malware get paid again to generate traffic to the websites and ads shown. To prevent the attack Internet users are advised to update the firmware on their router and change the default password.

Tuesday, 3 February 2015

D-Link Routers Vulnerable To DNS Hijacking


Different routers network manufacturer D-Link contains a vulnerability which can modify a remote attacker without credentials the DNS settings of the devices. This allows the attacker to the movement of the hacked router running through its servers, reports PC World .

The vulnerability is in the ZyNOS router firmware, developed by manufacturer ZyXEL. In addition to D-Link's firmware is also used by other manufacturers, including TP-Link and ZTE. Through the leak is possible to get without a valid username and password to access the administration interface. The problem is both an administrative interface that is directly accessible via the Internet as an interface that is only accessible locally. In the latter case an attacker to perform a CSRF attack.

Once access to the interface, the attacker could change the DNS settings. The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses. The DNS hijacking an attacker can manipulate the movement of users. It is believed that the leak in the D-Link DSL-2740R and the D-Link DLS 320B. Both models are sold in the Netherlands, where the DLS 320B still being offered.

Researcher Todor Donev, who noticed the problem reported this to manufacturer D-Link, so there is no update available yet.Moreover, the DSL-2740R is a phased model. Donev opposes Threat Post that other models are vulnerable, but he does not have the resources to test all affected devices. Meanwhile, he has also put an exploit online to demonstrate the attack.