Showing posts with label Email. Show all posts
Showing posts with label Email. Show all posts

Sunday, 18 October 2015

EFF Advises Against Eavesdropping HTTPS And VPN By NSA


This week, researchers presented information showing that the NSA may be able to store some encrypted connections, such as HTTPS, SSH and VPN, eavesdrop. Users can, however, take steps to prevent this, according to the American civil rights movement EFF.

The problem is that is used when an encrypted connection for instituting an algorithm for exchanging the key. In many cases, used for this purpose is the Diffie-Hellman algorithm. It forms the basis for modern cryptography and is used for VPNs, HTTPS, email, and other protocols. Because of the way the algorithm is implemented users run the risk of being bugged by the secret services, researchers said Alex Halderman and Nadia Heninger.

The problem is that a client, for example, a browser, and a server which use Diffie-Hellman must first agree on a prime number with a certain shape. Many applications thereby appear to use standardized 'hardcoded' primes. A secret service that any one particular prime number is able to "crack", then can eavesdrop all connections that use this particular prime number. It is in this case 1024-bit prime numbers.

NSA

"Based on the evidence we have, we can not prove that the NSA does. Our proposed way to crack Diffie-Hellman is better suited to the technical details of the large-scale decryption capabilities of the NSA than any other explanation," said the researchers. The documents from whistleblower Edward Snowden that the NSA have an infrastructure to monitor VPN connections. The system is designed to collect specific data that is required specifically to attack Diffie-Hellman.

"As the use of Diffie-Hellman in this feeble way is widespread in both standards and implementations, it may take years before the problems are resolved," as the researchers warn. They argue that all major governments can carry out similar attacks, if they do not do that.
Actions

Internet users who want to protect themselves against a possible attack may take various measures. Diffie-Hellman can be in the browser are so turned off, so that with it the setting up of an encrypted connection no use is made. Users of VPN have set their software to Diffie-Hellman is used only with 2048-bit prime., As the EFF in this article explains

Tuesday, 11 August 2015

Ransomware Focuses On Russia And Ukraine


Makers of ransomware is not only aimed at English speakers, also should beware of Internet users in Russia and the Ukraine. Microsoft saw earlier this year named a ransomware variant appear Troldesh mainly in June was very active. The malware spreads through exploit kits, which infect Internet via, for example vulnerabilities in Adobe Flash Player.

Once active Troldesh encrypts files on the computer and then asks for a fee to decrypt them. Unlike other ransomware which victims must make the payment in bitcoin, the maker of Troldesh communicate via email with his victims. On the infected computer is left a text file with instructions. These instructions enable the victim via e-mail contact with the author should include.

In June, a researcher contacted the maker, then successfully on the ransom amount to barter . Eighty percent of infections Troldesh took place in Russia, followed by Ukraine with 9%. Microsoft advises victims to not pay the requested ransom for decryption, as there is no guarantee that the victims referred to regain access to their files.

Monday, 11 May 2015

Mitnick: Almost 100% Success With Social Engineering



Social engineering is still one of the best ways for hackers to invade in organizations, since there is no patch for human stupidity, says security expert Kevin Mitnick. Mitnick was for years the most wanted hacker in the world and was eventually sentenced to a prison term of five years for breaking into several large companies, where he applied social engineering.

During his keynote address to the CeBIT business IT conference in Sydney Mitnick said that social engineering is particularly effective to penetrate into secure networks because existing problems are human error. "You can not download a patch for stupidity," he noted. "Social engineering bypasses all intrusion-detection systems. There is nothing on the market that can detect." In addition, free or relatively inexpensive to carry out, such as sending e-mail.

Mitnick himself conducts his own business penetration tests. If there should be social engineerg used, the success rate close to 100%. "It works on any platform, regardless of whether you're using Windows, Mac OS X or Linux. It is completely platform independent and the success rate is almost 100%." Mitnick told the audience that anti-virus software is dead and that most attacks that result from social engineering are able to bypass the virus, let Zdnet know.

They are, according to him than people who are the weakest link in security. "Users are the problem," said the ex-hacker. He also advises companies to strengthen "human firewall", something that can be done by repeated workouts. Additionally, organizations must ensure that all software on the computers of employees up-to-date and needs to incoming and outgoing traffic stringent be filtered through the firewall.

Tuesday, 31 March 2015

Researchers Reveal Solution For Mobile Malware


Researchers from the University of Alabama say they have developed a solution that should reduce the impact of mobile malware. The problem of mobile malware, according to the researchers is mainly caused by users who download applications from untrusted sites that offer infected apps. Once installed on the device has the malware free play.

"The Achilles heel of the security of mobile devices is that security decision depends on the user," says researcher and lecturer Nitesh Saxena. For example, when you install an Android app gets the user's demand that the app will have certain rights. Users can then be distracted or have hurry and so quick to allow these permissions. "Whatever the reason, it is a known problem that people do not look at these warnings and simply" yes "clicks."

Current operating systems provide the researchers not protect against this type of attack. Therefore there was a search for a solution to the important parts of the phone, namely the ability to call the camera and NFC, protect against malware. The result was a security that is based on three hand movements. If a user wants to call that instance must move the device or tap anywhere before the phone rings, while as malware service to telephone calls this movement will fail.

To demonstrate the effectiveness of the approach, the researchers collected data from several phone models and users in real or "almost real" scenarios, where both friendly and hostile scenarios were simulated. It emerged that detect hand movements are very accurate and other benign and malignant activities can be distinguished. "In this way, something as simple as human movement to solve a very complex problem," says Saxena. "It makes the weakest link, the user, the strong defender." The researchers plan to develop security for other smartphone services, such as SMS and email.

Tuesday, 24 March 2015

Many Computers Vulnerable To BIOS Leak


Estimated that millions of computers contain vulnerabilities in the BIOS (Basic Input / Output System) allowing attackers permanently infect a system and then steal all kinds of data. That researchers were LegbaCore Last week, during the CanSecWest conference in Vancouver. BIOS is a set of basic instructions for communication between the operating system and the hardware. It is essential for the operation of the computer and also the first major software that is being loaded.

During their demonstration ( pdf , pptx ), the researchers got different "incursion" vulnerabilities in the System Management Mode (SMM) see. SMM is a mode of Intel processors that firmware can perform certain functions. By using this mode, for example, the contents of the BIOS chip to be adapted or used for the installation of a "implant". Hence, it is possible to install and rootkits to steal passwords and other data from the system.

SMM malware also gives the opportunity to read all the data is in the machine's memory. The researchers therefore showed how they were able to access a BIOS through the incursion vulnerabilities, and then install the "Light Eater SMM implant" there. Via this malware they could GPG keys, passwords and steal decrypted messages from the Tails privacy operating system on an MSI computer.

Tails is a privacy and security-oriented operating system that can be loaded from DVD or USB stick. Tails removes even when closing all kinds of data from memory. Through the BIOS malware makes does not matter anymore, because all data from the memory of the computer can be stolen before cleanup occurs.

Attack

To install the BIOS malware attacker has two options, either through malware on your computer, for example, via an infected email or drive-by download. The second way is to have physical access to the system. The researchers would have already reported the problem to several manufacturers who are now working on a solution.

Even if released BIOS updates will probably have little effect. Most people install because no BIOS updates, the researchers said. According to the CERT / CC at Carnegie Mellon University are the vulnerabilities at least in systems from Dell and HP found. However, the status of many other suppliers is unknown.

Wednesday, 7 January 2015

New Variant of Emotet Malware - "Microsoft Warns of Malware That Steals Passwords"


Microsoft warned their users about malware that steals passwords for various programs and login details for online banking. The Emotet malware is distributed via a spam campaign that is aimed primarily at German Internet users, although 2.3% of the infections was observed in the Netherlands. The email contains a link to a zip file with a known deposit of the bank.



In reality, the zip file contains an .exe file that malware. Once active Emotet tries to steal login details for several German banks. In addition, the passwords for Eudora, Google Desktop, Google Talk, IncrediMail, Mozilla Thunderbird, MSN or Windows Live Messenger, Netscape 6 and Netscape 7, Outlook 2000, Outlook 2002 and Outlook Express, Windows Mail and Windows Live Mail and Yahoo! Messenger sent back to the attackers.

The linked website can download a .zip file that contains an executable file with a long file name to hide its .exe extension such as:

  • de_0000239029_rechnung_scan_hp_28_0000000904_page_2_10_01_05_id_00291002098.exe
  • E-Card_zu_Weichnachten_scan_foto_2834792347_12_2014_21093812_000129_001_004_002910.exe
  • Informationen_Kontobewegung_dezember_2014_de_20_8139_237_90109238_000129_000028_05.exe

According to the software giant let the malware show that it is important to keep security software up-to-date. To share in the event Microsoft's security software is used, users taking the advice to data with the Microsoft Active Protection Service Community (MAPS).


Friday, 12 December 2014

Microsoft - Beware of Payment Report Malware


Microsoft has warned Windows users to a malicious spam attack that attempts to infect recipients with malware. In the mail, with the subject "Payment Report - importan", it is stated that the recipient of the email received an amount of $ 35,000.

More details would be in the included zip find attached. The zip appendix contains a .scr file with a PDF icon. Because Windows default file extension does not display, users would have thought that it is a PDF document. Depending on the set display of folders, Windows will still show that it is a screensaver.


If the attachment is opened the computer becomes the Upatre downloader infected. This downloader can then again download other malicious software. According to Microsoft, the malware would be seen especially in consumer and business computers in North America.


MD5: 5a0e6a8f6d3afd811a109df2e1ee727b


 Virustotal Report

Wednesday, 30 April 2014

Russian Internet giant offers email service without a password

The Russian Internet giant Mail.Ru has a new e-mail service launched where users have no password.
My.com such as the e-mail service is called, is in fact only accessible via an app on the smartphone.Once users register they will receive a unique SMS code.
This registration code is used once, after which users never have to enter a password. The phone is namely as authentication."And you always have with you", so let the developers know. Our own research would show that often their email on their smartphone then check users on their desktop.
Furthermore, all sent and received e-mails should be encrypted, but specific details are not given. In addition, users of the free e-mail service to get 150 gigabytes of data storage, ten times as much as in the case of Gmail. 
My.com is only available for iOS and Android users. The developers say that they keep an eye on Windows Phone, but due to limited resources and expertise will now focus on iOS and Android.

Tuesday, 8 April 2014

Symantec: New era of mega-data leaks' has arrived

According to Symantec, a new era of "mega-data leaks' dawned. Cyber ​​attacks are becoming larger and cost tens of millions of dollars in damage.



At the end of 2013, the most damaging cyber attacks occurred in history, according to the annual Internet Security Threat Report (ISTR) from Symantec. The report shows a significant change seen in the way cybercriminals operate. Kept criminals rather mainly with fast attacks that had a small profit result, now they take months to prepare that generate a lot of money. Larger data leaks for
"A mega attack produces sometimes the same as 50 smaller attacks," said Tom Welling, Security Expert at Symantec Benelux. "Although the level of attacks continues to rise, more and more criminals have more patience and they wait until they can commit to deliver more money with a major attack."

Netherlands
The report also reveals that cyber criminals often use networks in the Netherlands to commit cyber attacks. If so-called "threat-source country rises Netherlands internationally from place to place 7 4. In the top ten of threat-source countries, only the Netherlands and Russia increased relatively strongly in 2013.



Increase
The number of data breaches in 2013 increased by 62 percent compared with 2012. As a result, more than 552 million online identities exposed to cyber criminals. So Cybercrime remains a real and damaging threat to both consumers and businesses. In the Netherlands, the favorite sector of cybercriminals each attack varies. The telecom industry is the biggest target for spam (77 percent), followed by the financial sector (64 percent). When it comes to malware, it is the largest retail target.



Compared to 2012, targeted attacks increased by 91 percent in 2013. Moreover, the attacks in 2013 lasted on average three times as long. Looking at occupations, personal assistants and PR staff are most attacked, because they are often a prelude to prominent figures such as celebrities or executives of large corporations.



Protect
According to Symantec, there are certain steps that businesses and consumers can take to protect against possible data leaks, targeted attacks, or general spam better.

Tips for Business
Know your data: information should be the focus of protection are not the devices or the data center. Knowing where sensitive information is located and where it is flowing, helps determine the best policy and the best procedures to protect the data.

Organization
Inform employees supervised workers in protecting their information. Give them an insight into the corporate policies and procedures for protecting sensitive data on personal and corporate devices.
Implement proper security infrastructure: strengthen the security infrastructure through prevention practices aimed at data loss, network security, endpoint security, encryption, strong authentication and defensive measures, such as reputation-based technologies.



Tips for consumers
Be smart in the field of security: Choose a strong password and update all your devices with the latest security software.
Pay attention: check bank and credit card statements for irregularities and be careful when responding to unsolicited or unexpected emails. Also be alert for online deals that seem too good to be true, because usually they are just that.
Know with whom you work, make sure you are familiar with the policies of retailers and online services that can retrieve bank or personal information. If this information should be shared, please do so via the official website of the company and not through an email link.

Detailed Report

Sunday, 16 March 2014

Phishing Attack on Google users hosted by Google

In a recent phishing attack on users of Google Docs and Google Drive cybercriminals have the phishing page where victims had to introduce hosted on the servers of Google. Their credentials Something the phishing attack is both refined and remarkable, says Symantec.

Google Docs phishing login page

The anti-virus company discovered the attack, which starts with an email subject "Documents" has. The email prompts the recipient to view an important document. The link does not point to Google Docs, but after a fake Google login page. The neppagina however hosted on Google's servers and then ran over an SSL-secured connection, which makes the attack seem more convincing.
In this case, the scammers a folder in a Google Drive account is created, placed it in a file and then put the public folder. The preview feature of Google Drive they got this way a publicly accessible URL that was added. To the phishing emails When users their information on the phishing page fill go directly to the criminals behind the attack, while the victim to the real Google Docs page is redirected and possibly nothing by it.