Showing posts with label Decryption. Show all posts
Showing posts with label Decryption. Show all posts

Tuesday, 6 October 2015

Researchers Demonstrate Quantum Cryptography Over 100km



Researchers at Toshiba's Cambridge Research Lab have quantum cryptography secure data over a distance of 100 kilometers knowledge exchange, which is a new record. The exchange took place over a single cable with a speed of 200 gigabits per second.

Quantum cryptography is a technique in which the encryption of information is performed with the aid of light, or photons. A zero or one is represented by a single light particle. At the level of single particles governed by the laws of quantum mechanics. That means that if the encrypted message is tapped, the contents of the message changes automatically.

A problem with quantum cryptography is the so-called "cross-talk", which provides a signal on one channel for problems in a different channel. The normal encoded data bits are shown in quantum cryptography by millions of photons, while the bits of the quantum key are received through a single photon. Dispersion of light makes detecting these key photons difficult, says researcher Andrew Shields opposite Electronics Weekly.

Because of the light in certain ways to filter the researchers succeeded in order to identify the key. The next step in the research is to build a network in order to demonstrate end-to-end-quantum cryptography. Earlier this year, Toshiba already announced that it is in 2020 with a communication system is that makes use of quantum cryptography, and in theory, is not to eavesdrop.

Saturday, 27 June 2015

Cisco Fixes Problems Again With Standard SSH Keys


Cisco offers weather updates for different products released due to the use of standard SSH-keys. Using the default SSH keys, an attacker remotely without valid credentials on a login system with root privileges. The only thing that is required is that the attacker can connect to the platform.

According to Cisco, the problem is that all installations of the Web Security Virtual Appliance (WSAV), Email Security Virtual Appliance (Esau) and Content Security Management Virtual Appliance (SMAV) share the same authorized SSH key for the remote support functionality. Also, an attacker via the SSH host key can also all appliances is the same, and all communications between virtual appliances decrypt and mimic.

Cisco has released updates to fix the problems. Last October there appeared an update of a similar problem in the Cisco Unified Communications Manager Domain. The networking giant has announced that to their knowledge the newly discovered problems are not yet attacked or were previously known on the Internet.

Tuesday, 23 June 2015

Toshiba Promises Quantum Cryptography 2020


The Japanese electronics giant Toshiba says that in five years with a communication system is making use of quantum cryptography and in theory is not to eavesdrop. This was reported by the Asahi Shimbun . The testing of the quantum key distribution according to the company is located in the final stage. Earlier tests with long-distance communication would have been a success. In late August there will be a test of two years to test the resistance of the system before it goes to market.

At current encryption systems are working with secret keys. Once the key has been stolen, the data can be decrypted. Quantum Cryptography is a technique in which the encryption of information is performed with the aid of light, or photons. A zero or one is represented by a single light particle. At the level of single particles governed by the laws of quantum mechanics. That means that if the encrypted message is intercepted, the content of the message changes automatically.

The Toshiba system first sends the secret key and then the data. If it appears that the secret key is intercepted, the data will not be sent and intercepted key is turned off. Photons are, however, unstable and the development of a system to communicate over long distances has always been a major obstacle. Toshiba has improved the precision of the photo transmitter, where there is now photons over a distance of 45 kilometer may be sent. The test that begins shortly aims to solve the final obstacles so that the system, in practice, may be used.

Friday, 29 May 2015

"Dormant" Ransomware Makes Victims Worldwide


Main Locker Screen
This week, the world of computers with a new ransomware variant infected become infected systems which quietly and suddenly became active on 25 May. It is the locker-ransomware which like other kinds of ransomware specimens encrypts files on the system.

According Bleeping Computer is a large number of people worldwide affected by the malware. After the encryption users will see a notification that they have to pay 0.1 bitcoin. That comes with the current exchange rate equivalent to 22 euros. An amount that is one-tenth of what questions ransomware many other instances. In the warning that users get to see is further stated that they should not investigate Locker ransomware or remove, because the private key will be destroyed and the data is no longer decrypt.

Experts, however, that this is just a way to scare people so that they pay the amount requested. Besides the forum Bleeping Computer are also social news site Reddit been several reports of the victims appeared to have the amount paid. It is the low price of 22 euros given as a reason to watch or by paying the files are recoverable. Several victims have thereby know that after the pay could decrypt their files and so got back.

How Locker ransomware exactly spreads is not yet confirmed, but possibly it is a cracked version of Minecraft or sports streaming sites, although e-mail attachments and exploits are mentioned. The ransomware would just delete the Volume Shadow Copies on the C drive. This would be possible through the Volume Shadow Copies of other disks for files that have been encrypted there without paying retrieve .

Friday, 1 May 2015

New Ransomware Avoids US Computers


Researchers have discovered a new ransomware variant that strikes because the US does not infect computers intentional. Crypt0L0cker such as ransomware called, according to researchers from Bleeping Computer a version of the famous Torrent Locker ransomware.

Crypt0L0cker appears to use the same communication methods as Torrent Locker and encrypts all kinds of files, which then users hundreds of dollars can be decrypt. If victims do not ransom doubling pay on time.

Why Crypt0L0cker US avoids computers is unknown. In the past happened that Russian cyber criminals infecting computers no Russian, so as not to attract the attention of the Russian authorities. The new ransomware is now in Europe, Asia and Australia surfaced and spreads via emails posing as traffic violations or government posts.

Wednesday, 29 April 2015

Free Tool Provides Ransomware Victims Files Back


In March this year, there ransomware which focused specifically at gamers and files from popular computer games and gaming platforms like Steam encrypted and iTunes. Initially it was thought that it was a variant of the Crypto Locker ransomware, but the ransomware was eventually named "Tesla Crypt."

Like other ransomware victims must pay a fee to recover their files. Researchers from network giant Cisco, however, have discovered a vulnerability in the applied encryption, which makes it possible for the victims to decrypt without paying their files. The ransomware pretends to use asymmetric RSA-2048 encryption to encrypt files, but actually makes use of symmetric AES encryption.

The researchers also created a decryption utility to decrypt files free of charge. For this the "master key" must still be on the system. This file, called key.dat is in the user's application data directory stores. Users must copy this file to the directory of the decryption tool, and then run the tool, after all files are automatically decrypted. Using the tool is at your own risk, warns Cisco. Users also are advised to first back up their data.

Saturday, 25 April 2015

ESET: Ransomware Victims Should Not Pay



Computer users who are victims of ransomware and therefore no longer have access to their data should the ransom demand the criminals do not pay. This enables Raphael Labaca Castro of Slovak anti-virus company ESET. In recent months, several experts spoke out about paying ransomware and it was revealed that dozens of Dutch companies had the ransom paid after they were infected.

British anti-virus firm Sophos found that prevention is better than cure, but in the case of an infection the best " okay "is to pay the ransom. Labaca Castro has a different opinion. "If you pay your support cyber criminals by providing them with more money." In addition, according to the security expert would be no guarantee that the encrypted files are decrypted.Nevertheless, recent incidents where the ransom be paid to victims recovering their files.

Yet calls Labaca Castro paid a dangerous option. "Remember, this is not a service. The cyber criminals. Even if you pay, they do not on a" whitelist "position, so you can be infected again. So it is not a real solution for the future." Prevention according to the expert is the main weapon against ransomware. He also advises to make regular backups.

Tuesday, 21 April 2015

Hacker Tool Does Not Ask Americans To Additional Information


Due to legal obligations should users of the popular hacker tool Metasploit who are not from the United States or Canada now give more information about themselves. It involves users of Metasploit Pro or the Metasploit Community Edition and not the Metasploit Framework.

Metasploit is software to test with the security of networks and systems. It uses encryption and is therefore, like other similar products, subject to US export regulations. Additionally get Metasploit and other attack software with more and more American and international constraints make. Because of these rules is to offer Rapid7, the company that Metasploit, the way to customize how the free and trial versions of Metasploit Pro and community can be obtained.

Customers outside the US and Canada must now apply for a license and provide additional information about themselves or their organization. It must in this case to "reliable and accurate" going data. Rapid7 will then approve or reject the request. In some cases, however, provide the US Department of Commerce or users can use the software or not. According Rapid7 most users will simply receive a license key, only this can now let alone wait any longer, up to 48 hours. Users who already have a license need not be afraid that it will be withdrawn.

Saturday, 21 March 2015

Anti-virus Company Will Pay Ransomware Okay


British anti-virus firm Sophos finds it okay if victims of ransomware pay to pay their encrypted data, although it is better not to do this. Thus the virus fighter is partially against the advice of police and some experts in that just advise to never pay .

By paying criminals would continue with their practices. In addition, there is no guarantee that victims receive a decryption key or to decrypt the work files. Recently 25 Dutch companies had paid the creators of ransomware and recovering their files. There are also cases of American police agencies known to have been infected and eventually paid .

Sophos also states that it is easy to say that victims should not pay, but it's a different story if it were your own data. The anti-virus company says that it's okay to pay, but if it can be avoided. In addition, Internet users would be wise to take precautions, such as making backups. In the case of an infection can therefore be reduced and ultimately the damage is unavoidable that there is to be paid.

Friday, 20 March 2015

Multiple Vulnerabilities In OpenSSL Patched


As mentioned earlier this week announced for updates today OpenSSL true that address multiple vulnerabilities. In total, it comes to 14 vulnerabilities, two of which are labeled as "high." This is the highest level for vulnerabilities that uses OpenSSL. The first high-leak is present only in version 1.0.2, and makes it possible to perform a Denial of Service against a server.

The second high-leak was originally labeled as "low", the lowest category that uses OpenSSL. One of the OpenSSL developers had previously indicated that only one high-leak would be, which was in version 1.0.2. Still, it was decided the low-leakage to label as high. It involves "FREAK leak" that previously was revealed by researchers. Through the leak, an attacker who is between a target and the Internet is in some cases the encryption of the encrypted connection to downgrade to a weak encryption to crack then that and to see the encrypted traffic.

According to the OpenSSL developers was initially assumed that the problem would be small and it was not possible for many servers to downgrade to the weak encryption. Further investigation showed, however, that a significant number of servers supporting the weak encryption. The other vulnerabilities patched today were mainly possible to conduct denial of service attacks against servers. Administrators are advised, depending on which version is installed, upgrade to version 1.0.2a ,1.0.1m , 1.0.0r or 0.9.8zf .

Saturday, 14 March 2015

Forensic Tool Can Extract All Data From iCloud Drive


A forensic tool of Russian Elcomsoft in the last year news came because that would be used to steal nude photos of celebrities, is now able to extract all kinds of data from both Apple iCloud as iCloud Drive.It involves all the Apple data and data from third party applications.

In addition, the new version of Elcomsoft Phone Breaker can now also the keychain in iCloud backups decrypt. For this, it is required that the "securityd-key" of the device is physically removed. Russian software company would have spent almost half a year to write the new communication protocols iCloud Drive to reverse engineer and software to communicate with the iCloud Drive servers.

ICloud Drive

ICloud Drive is an upgrade from Apple iCloud and allows users to store all sorts of data in the cloud. Data are accessed via a Windows or Mac computer. Some data such as iOS backups and stored iOS appdata however stored separately. These data are only accessible by a backup on a new iOS device to replace. Elcomsoft's software is now able to access application data from user accounts that have been upgraded to iCloud Drive. In addition, the software also offers access to iOS backups.

Keychain

Another major adjustment is the ability to decrypt the keychain from iCloudback-ups. The keychain contains all kinds of sensitive information such as account passwords and certificates. On the device itself, the keychain is encrypted by a combination of hardware and software. As soon as the keychain is stored in a back-up change the security level depending on the type of backup. If the user makes a local password-protected backup through iTunes, the keychain is encrypted with a key that is dependent on the backup password.

Through the backup password most things in the keychain can be decrypted. If the local backup is created without a password, the keychain will be encrypted with a hardware-dependent key, which is unique for each device. This device will probably not change over the lifetime of the device. Once the key is superseded that can be used for future backups.

These keychains however, can only be put back on the same physical device, and to decrypt with the same hardware-dependent decryption key. If this key is retrieved from the physical device, it is then possible to decrypt all of the data from the outside of the keychain device. Finally there is the possibility to have a iCloudback up where the keychain is secured with the device password. This is similar to the iTunes backups without a password. All three kinds of keychains are according to decrypt Elcomsoft now, provided that the hardware-dependent key is present.

Friday, 16 January 2015

Cryptowall 3.0 - "Microsoft Sees Hundreds Of New Infections By CryptoWall"


After two months of silence, there is a new version of the CryptoWall-ransomware appeared that managed to infect one day 288 Windows computers, says Microsoft. CryptoWall 3.0 spreads the same way as previous versions, namely via drive-by downloads and installation by malware already present on computers. Once active encrypts CryptoWall kinds of files and then asks for an amount of 500 euros in bitcoin. Victims receive 167 hours to pay, and the price is increased. In previous versions it was then a sum of 1,000 euros.

Cryptowall Decrypt Service.

Communicated the older versions of CryptoWall still using the Tor network, CryptoWall 3.0 uses I2P, which stands for Invisible Internet Project (I2P), says researcher JuK of the blog Malware Do not Need Coffee . I2P is a network layer allowing application messages safely and pseudo-anonymous can exchange. 

Cryptowall 3.0 communications with C&C

The earlier versions of CryptoWall would be more than 830,000 computers have been infected, making it the most "successful" ransomware until now.

VirusTotal Report Zip File: c77a463c5f6481efee38bba2bc8bf085

VirusTotal Report: 6c3e6143ab699d6b78551d417c0a1a45

VirusTotal Report: 47363b94cee907e2b8926c1be61150c7