Showing posts with label Discovered. Show all posts
Showing posts with label Discovered. Show all posts

Thursday, 1 January 2015

Security Researcher Hijacks PayPal Accounts via Flash File


A security researcher has discovered a flaw in the PayPal website so he could take over users' accounts. The vulnerability was in the page to generate invoices. The page allows users to upload different types of files. PayPal turned out only to check the extension of the uploaded files, not the content, so the researcher discovered.



This allowed him to a Flash file with full read on www.paypal.com upload. Then, to take account of a user, the user must visit a Web site of the researcher. The researcher can then execute arbitrary commands with the PayPal account, such as the transfer of money and steal data.



The researcher reported the problem with us that rewards bug reports through a special program. However, eight days after he was told that another researcher had already reported the problem and, therefore, no compensation was paid. "I know that researchers sometimes find the same bugs, but I think that PayPal better to deal with this double bug reports," said the disappointed researcher.

Monday, 8 December 2014

"More openness required --> Antivirus companies on government spyware"

Regin Malware

Anti-virus companies have to be more open about the government spyware that they find, says security expert Bruce Schneier . Schneier reigns on the discovery of the highly advanced Regin malware , which would be by the US and British intelligence developed .

Anti-virus companies have known for some time of the malware, but made ​​the existence of Regin until the end of November to the public. It was the first that Symantec came out with a publication because it knew that another party would reveal the malware. This party was news The Intercept. After the report, Symantec also followed F-Secure and Kaspersky Lab with their own findings. All three follow the anti-virus companies said Regin years, where she copies of years ago found.

"Why were all these companies Regin long secret and why they showed us all this time vulnerable?" Schneider asked. Self thinks the expert that the anti-virus companies no incomplete picture wanted to express. Unlike malware cybercriminals is the effect of government spyware much more complex. In addition, Regin was only used against specific targets, which makes it difficult to obtain copies.

"If you're big in the press comes with a newly discovered malware copy you want to have the whole story. Apparently no one thought they had it with Regin," said Schneier. The expert, however, find this no excuse. "Now government malware more often will come we will often not have the whole story." As long as nations will fight each other over the internet, according to the expert, some individuals or organizations are the target and the residual risk to be hit inadvertently by this type of malware.

Even more

Schneier believes that anti-virus companies are at the moment even more incomplete stories on all government malware. "But they should not do. We want and need that our anti-virus companies us all about these threats tell as soon as they can, and not wait for the appearance of a political story so they can no longer remain silent."

Tuesday, 25 March 2014

XP malware allows criminals ATM emptying via SMS

ATM malware infects a Windows XP installation makes it possible for criminals by sending a single SMS message to retrieve the dispenser. Empty It involves the Ploutus malware last October for the first time in Mexico was discovered, but is now active in more countries.

Two weeks after the discovery of a new variant Ploutus was found . This version was translated not only in English but also had a modular architecture. Anti-virus company Symantec has this version further analyzed and discovered that criminals now the ATM to clean out. via sending text messages.

Attack
To attack the ATM criminals first need to have physical access to it. Then the ATM machine booted from a boot CD. This boot CD contains the Ploutus malware that infects the operating system of the ATM during startup. In addition, the virus may be present, the malware also switches off.

After installation, it is possible to activate Ploutus via a special key combination can be spent on command. Money Criminals straw men gave the command to retrieve the money had to share this key. If the straw men knew what could be done with the key they can light up their client, says Symantec.
Ploutus ATM attack overview


Smartphone
To solve this problem, the criminals can also link a smartphone to the ATM. The already installed malware ensures that the criminal can communicate. Using the smartphone with the ATM This avoids key shared. Lake with the straw man The criminal can now send an SMS to the ATM which then spends the money that is being recorded. Straw man by himself The attacks would have been observed. Different places in the world.

Symantec notes that as encrypted hard drives, which installed the malware may occur. Modern ATMs have better security, Older ATMs, however, would run on XP and are therefore more vulnerable. Ploutus example works only on Windows XP. Banks also get the advice to Windows 7 or 8 upgrade. In addition, the BIOS must be locked so that it can not be booted. From other media.

MD5:
488acf3e6ba215edef77fd900e6eb33b
b9f5bd514485fb06da39beff051b9fdc

Virus Total Link:
https://www.virustotal.com/en/file/0106757fac9d10a8e2a22dce5337f404bfa1c44d3cc0c53af3c7539888bc4025/analysis/

https://www.virustotal.com/en/file/34acc4c0b61b5ce0b37c3589f97d1f23e6d84011a241e6f85683ee517ce786f1/analysis/