Showing posts with label Devices. Show all posts
Showing posts with label Devices. Show all posts

Wednesday, 11 March 2015

Malware Explores Home Network Via Router Attack


Researchers have discovered a mysterious instance of malware that attacks the router from infected computers, then bring it home network card and the malware is removed again. It is the Vice Pass Trojan, which occurs at sites like Flash Player update.

When users download the so-called update and open the Trojan is installed. Once active attempts Vice Pass to log in via a list of predefined user names and passwords and a specific range of IP addresses on the router. Then looks malware or other devices are connected to the router, such as iPhones, iPads, LaserJet and Xbox consoles. Once the scan is performed, the malware sends the results back to the attackers and then deletes itself.

Researchers at antivirus company Trend Micro think the Trojan probably "scout" is used for larger campaigns. "The collection of information may be the first step of larger attacks," said analyst Lu Kenney. The collected information could for example be used for cross-site request forgery attacks. "What is the real purpose, this malware shows how important it is to protect devices, even those not obvious target," said Lu. Users will also be advised to change the standard nature credentials of their router.

Tuesday, 20 January 2015

According To Researchers Avoid Chrome And Skype


Security researchers who work with sensitive information can better avoid Google Chrome and Skype, as recommended two researchers. According to Dani Creus and Vicente Diaz Kaspersky Lab happens that investigators are approached by criminal gangs and intelligence.

It also happens that researchers be bugged or that their devices while traveling is compromised. Operational security (OPSEC) is therefore essential, say Creus and Diaz. The main rule here is to remain silent. "If you do not have to say do not do anything. If you need to communicate with someone do it safely so you're not the contents of your message in danger and if possible also leave no metadata."

In the case of communication should be used such as email, instant messaging and phone the researchers several tips. So can only chat services that are trusted Off-the-Record (OTR) offering and Skype should never be used for discussing sensitive issues. Also, wherever possible, disposable phones are used. Furthermore, researchers are advised to use TrueCrypt to encrypt data.

To the Internet, according Creus and Diaz wise to use an 'air gap', which is created by an anonymous obtained 3G / 4G modem connection. Also have no cookies in the browser must be accepted and the execution of JavaScript can be prevented. Furthermore, users can not log on to an account and use Google Chrome is not recommended.

"OPSEC must be quickly part of the daily routine of security researchers," note the two researchers. "Given the kind of operation that is detected, and the parties concerned, the lack of knowledge and discipline in this area can have devastating consequences for researchers who do their work," concludes the pair. Earlier also gave a researcher called The Grugq sorts of tips for improving operational safety.

Wednesday, 7 January 2015

AVG: Login Via Fingerprint Positive Development


In late December showed a German hacker still see him with a picture fingerprint had copied the German Minister of Defence, but according to Tony Anscombe anti-virus company AVG login via fingerprint correct a positive development. Anscombe also criticizes the negative coverage of biometric authentication, which would let users believe that fingerprint logon is not safe.

"The process to copy someone's fingerprint in this way is difficult and time-consuming, and it is therefore unlikely that the masses will be a problem," says AVG security evangelist. "I think we just have to celebrate that authentication mechanisms that initially only used by companies and governments have now found a place in our daily lives."

Anscombe notes that as biometric security ensures that more people lock their phone, this is a positive development. "It shows that more consumers than ever protect their devices in a certain way in order to prevent their information being stolen." The security evangelist says he understands that research into this type of security is necessary, but he would prefer to see that people are encouraged to use the security on their phone than that they are trying to undermine the systems that can protect them.

Tuesday, 23 December 2014

Researcher demonstrates firmware attack on Macbook


In late December, a researcher showed how it is possible to install on an Apple Macbook a bootkit that reinstalling the operating system and replace the hard drive can survive. The bootkit can be installed by someone with physical access to the laptop. For this, the externally accessible Thunderbolt port is used. Once the bootkit is running that can spread virally by infecting other Thunderbolt devices.



According to researcher Trammell Hudson is possible to bypass the control that uses Apple EFI (Extensible Firmware Interface) firmware updates. This can add an attacker with physical access of malicious code to the firmware on the ROM of the motherboard, creating a new class of firmware boat kits for Macbooks. The firmware is not cryptographically checked during boot, so the malicious code from the beginning has full control over the system.


Hudson developed a "proof of concept" bootkit Apple's public RSA key in replacing the firmware and prevents attempts to replace the malicious code. Since the boot firmware is independent of the operating system, the bootkit continues after a reinstallation of the operating system to exist. Replacing the hard drive also has no effect. Only through a programming device, the original firmware can be restored.

The researcher notes that can be adjusted by the bootkit and can spread further as the firmware of other Thunderbolt devices. "Although the two year old Thunderbolt firmware leak that this attack used a firmware patch to remedy is the bigger problem of Apple's EFI firmware security and secure booting without solving difficult trusted hardware." Hudson will during his presentation at the CCC conference give more details.

Saturday, 6 December 2014

Preinstalled Malware on Cheap Android Devices - Death Ring


Researchers have found in several Android phones malware advance was already installed. It comes to phones that are sold mainly in Africa and Asia, such as Vietnam, Indonesia, India, Nigeria, Taiwan and China. The phones are standard Trojan horse called "Death Ring" that occurs as a ringtone app.

In reality, the app SMS and wapcontent of the Command & Control server to download to the phone, says security firm Lookout . The malware is activated in two ways, depending on how the user uses his phone. The malware is activated when the phone is restarted five times. In addition, start the malicious service if the victim fifty times are unlocked device.

Lookout has described various scenarios malware can do on a phone, but has no concrete examples. However, the company warns that the malware can not be removed by a virus app, as it is in the system directory. Which is added in the supply chain the malware is unknown. Consumers also are advised to pay attention to where the equipment they buy comes from.

The infections were detected forged Counterfeit Samsung GS4/Note II Various TECNO devices Gionee Gpad G1 Gionee GN708W Gionee GN800 Polytron Rocket S2350 Hi-Tech Amaze Tab Karbonn TA-FONE A34/A37 Jiayu G4S – Galaxy S4 Clone Haier H7 No manufacturer specified i9502+ Samsung Clone

It is not the first time that pre-installed malware on Android devices found .

Wednesday, 19 March 2014

Windows Spyware WinSpy and GimmeRAT monitors Android devices

If you are using Android Phone and syncing with the Windows Operating System for backup and transferring files, Then Be Careful.
Mechanism of attack on financial institution employing WinSpy

Researchers have found by analysis of an attack on a U.S. financial institution Windows spyware that is also able to monitor. Android devices The institution was attacked by a spear phishing email, which had a large NSIS file as an attachment.
Once the file was opened, the recipient was a picture of a payslip to see while installed in the background. WinSpy This is commercially available Windows-spyware which makes it possible to monitor, according to the authors. Computers but also Android devices In a second attack on the institution was again used WinSpy, only the malware was now hiding in an Excel document with a macro.
Once the malware on your computer is active, the attacker can control the webcam, capture screenshots, saving keystrokes, disable security software, downloading and surfing habits chat conversations via the microphone shoot, upload and download files and send messages to the computer.

Android



During the analysis of the malware security company FireEye also discovered various Android components that can be used to monitor the victim. It involves three different applications, one of which only works when the device is connected to the Windows computer while the other two make it possible to control. Android device via SMS
Deployment Scenarios for Android Components

To install the Android spyware must be connected, then the installation takes place. On the infected computer Windows phone Through the Android spyware screenshots can be stolen and it is possible to find out. The location of the target
"These attacks and tools to confirm that we live in an age of digital surveillance and theft of intellectual property. Commercial Remote Administration Tools (RATs) continue to proliferate and are increasingly being used by attackers," said analyst Thoufique HaqHe notes that the rise of mobile platforms like Android, a new market has emerged which also asked about RATs that support these platforms.