Showing posts with label Exploit Kit. Show all posts
Showing posts with label Exploit Kit. Show all posts

Wednesday, 4 November 2015

Hackers Would Have Earned $ 1 Million With iOS9 Leak


A contest where hackers could earn $ 1 million with a zero-day vulnerability in iOS9 allow an attacker to get permanent access to the unit has produced a winner. That Zerodium let through Twitter know, the company that organized the contest. Critics are skeptical.

Participants in the competition were until 1 November to submit their zero-day exploits. In order for the amount of money needed to qualify the vulnerability could be attacked without user interaction, except for visiting a malicious web page. Also attacks came via SMS or MMS to reward eligible. Now Zerodium argues that the contest has produced a winning team.

Critics are skeptical and say that without evidence ultimately a PR stunt is. Across Vice Magazine late founder Chaouki Bekrar know that performing a jailbreak remotely allowing permanent access to the device can be obtained at least two or three additional exploits required. Several teams went to this was fixed and Bekrar plan to extend the deadline until another team came a few hours before the expiry of a solution.

To which team it exactly goes and what kind of vulnerabilities not know there used to attack Bekrar late. He also will not say how much he will sell the exploit. Zerodium buys vulnerabilities from researchers to then resell these to government organizations.

Friday, 30 October 2015

Recent Poem Flash Leak In Crosshairs Of Cyber Criminals



A critical vulnerability in Adobe Flash Player which ten days ago an emergency patch rolled out is now being actively attacked by cyber criminals. At the time Adobe update rolled out the company claimed that the vulnerability was used only in targeted attacks on a limited scale.

Now reports researcher JuK of the blog Malware do not need Coffee that an exploit of the vulnerability using the Angler-exploitkit added. Consequently have less technical knowledge cybercriminals with the means to attack the Flash leak. The Angler exploitkit was in recent months in large-scale advertising campaigns on popular websites used.

Criminals use this ad network of popular websites to spread infected ads. These ads send visitors unnoticed to a page with the Angler-exploitkit. In case users have their Flash Player or other software is not up-to-date, they can become infected with malware. Now the recent poems Flash leak also been added to the Angler-exploitkit cyber criminals have a greater opportunity to infect internet users, since the update of October 16 may not yet installed anywhere.

In case the attack is successful, the Bedep Trojan is installed on computers. This Trojan can install additional malware, including malware for advertising fraud and ransomware, and the computer part of a botnet. The Flash vulnerability was two weeks before the attack on the 'wild' was discovered already by Google to Adobe reported. Through this page to monitor Internet users whether they are using Flash version.

Saturday, 26 September 2015

Porn XHamster Spread Malware Weather


For the third time in a year there are again infected ads on the most popular porn xHamster published that attempted to infect visitors with malware. XHamster receives nearly half a billion monthly visitors and is on the 71st place of most visited websites on the internet.

The infected ads first carried out various checks. Thus, it ensures that the visitor Internet Explorer and certain security tools such as Wireshark and Fiddler active, said anti-malware company Malwarebytes. In case it IE users without said security tools went unnoticed was a page loaded with the Nuclear-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer users have not patched.

In the case the attack was successful was ransomware and other malware installed. After being informed removed the ad network TrafficHaus infected ads. A few days later appeared again malicious ads on xHamster. This time the browser was based Brow lock ransomware spread. This ransomware is not on the computer, but locks the browser via a special JavaScript and states that the user must pay to get access again.

Again TrafficHaus was informed. Malwarebytes but does not know if the second round with malicious ads has been removed. In January and April also appeared already contaminated ads on xHamster.

Thursday, 24 September 2015

American 'Funda' Spread Malware Via Infected Ads


Cyber criminals are again managed to place infected ads on a very popular website with tens of millions of visitors who attempted to install malware. It is Realtor.com, the US counterpart of Funda which all kinds of real estate is offered.

The website is according to market researcher Alexa at the 101st place of most visited websites in the United States and a 485ste place worldwide. It is estimated that Realtor.com monthly 28 million visitors. The attackers previously infected ads on the English website of eBay, Drudge Report and other major websites were seated according to anti-malware company Malwarebytes also behind this attack. Through advertising network Adspirit.net the affected ads were posted on the website.

The ads sent visitors without being noticed this through to a website with the Angler-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer to install malware. For whatever it's malware was not disclosed. After being informed, the publisher of Realtor.com and Adspirit off the ads. Internet users whose software was up-to-date were no known risk. Yesterday it became known that criminals a week infected ads on Forbes.com have shown.

Wednesday, 23 September 2015

Forbes.com Spread Malware Via Infected Adverts


On the very popular website of business magazine Forbes have been infected for some time ads shown to infect visitors with malware tried. Forbes.com state according to market researcher Alexa on the 74th spot of most visited websites in the United States and the 154th place worldwide.

The website is monthly by more than 31 million visited visitors. Those visitors were from 8 to 15 September dished ads so they were undetected to a website with the Angler- and Neutrino-exploit kits. This exploit kits exploit known vulnerabilities include Adobe Flash Player. In case there is no up-to-date software was used silently malware could be installed on the computer, says security firm FireEye.

For what exactly will the malware was not disclosed. The ads were via an advertising service from a third party displayed on the Forbes website. According FireEye use of contaminated advertising remains a popular attack method for criminals.Via advertising platforms, especially those that hold real-time auctions for ad space, attackers can choose exactly where their malicious content is displayed.

In case the infected appear ads on popular websites the chance of massive infection is significantly increased, allowing both users and businesses at risk, according to the security company. After being informed Forbes has removed the infected ads. Last year, even though malware via Forbes.com spread. When attackers used a widget on the website that zero-day vulnerabilities in Internet Explorer and Adobe Flash Player attacked.

Tuesday, 22 September 2015

Adobe Fixes Numerous Flash Player Vulnerabilities


Adobe today released a new version of Flash Player that 23 vulnerabilities are fixed. Through the vulnerabilities an attacker would at worst systems can take over completely. Eighteen of the vulnerabilities allow an attacker to execute arbitrary code on the computer, such as installing malware.

Simply select visiting a hacked or malicious Web site or see getting an infected ad. Through the remaining vulnerabilities were able to retrieve information. In addition, protection against so-called "vector length corruptions" improved. Adobe recommends because of attacks from the past that both Mac and Windows users the update within 72 hours of installation.

It is common for cyber criminals following the appearance of Adobe Updates develop exploits to attack users who have installed the updates yet. In the case of Google Chrome and Internet Explorer 10 and Edge 11 and Microsoft Windows 8, 8.1 and Windows 10 the embedded Flash Player will be updated automatically via the browser. The vulnerabilities have been fixed in Adobe Flash Player version 18.0.0.241 (Extended Support Release) and 19.0.0.185. Through this page,see what version is installed on the computer.

Saturday, 19 September 2015

Thousands Of Hacked WordPress Sites Spread Malware


Attackers have managed to hack thousands of WordPress sites and use them for distributing malware, including the website of a US security. Before that warns security firm Sucuri. It would now go to 6,000 contaminated sites.

The attacks on the WordPress websites began two weeks ago. The hacked sites placed code that visitors unnoticed a page with the Nuclear-exploitkit late charge. This exploitkit is using known vulnerabilities in Adobe Flash Player and Internet Explorer users have not patched. Among the hacked WordPress sites are among other Coverity's website, a company dealing with security software.

How the attackers access to the WordPress sites managed to get has not been determined yet, but the attackers seem to create vulnerabilities in WordPress plugins use. Not just forget owners of WordPress flocking to update the software on their website, including updates to installed plug-ins will be forgotten. According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use.

Wednesday, 16 September 2015

WordPress Vulnerabilities Take Over Attacker's Website


The administrators of WordPress have released a security update for the content management system which fixes three vulnerabilities. Through the vulnerabilities an attacker could take over the website, as reported to the Computer Emergency Readiness Team of the US government.

These include two cross-site scripting vulnerabilities and a leak that allows users without sufficient rights privépostings could publish and could make sticky. Furthermore there are 26 non-security-related bug fixes. Users are advised to go to WordPress 4.3.1 upgrade. According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use.Recently, it was revealed that millions of websites who use WordPress running a vulnerable version. This means they can be hacked and used to spread malware.

Monday, 7 September 2015

Millions Of WordPress Websites Vulnerable To Hackers


WordPress is by far the most popular content management system (CMS) on the Internet, but many administrators forget to update the software or use vulnerable plug-ins, allowing millions of websites are at risk of being taken over. The Danish security Heimdal Security warns that the looks of hacked WordPress websites that distribute ransomware on the rise.

The websites are malicious code placed that visitors unnoticed to a page with the Neutrino-exploitkit. This exploitkit uses known vulnerabilities in Adobe Flash Player, Adobe Reader and Internet Explorer users have not patched. In case the attack is successful, the Tesla Crypt-ransomware placed on the computer, mainly computer games-related data encrypted. Next, there to decrypt the files to be paid.

According to figures from W3Techs is WordPress by 24.4% of all websites on the Internet use. The latest WordPress version 4. This version is used by 79.9% of WordPress sites. 20.1% running on WordPress version 3 or older. The latest version of WordPress 3 appeared on November 20, 2014 and fixed it several security vulnerabilities. Also, version 4 have been different versions appeared, in part because of vulnerabilities.

In the 79.9% which WordPress uses 4 can therefore which users are still running a vulnerable version. Each month WordPress websites are 409 million people read. According Heimdal Security is therefore important that WordPress administrators to install available updates, both for their own website as the safety of their visitors.

Friday, 28 August 2015

Infected Ads On MSN.com Spread Malware


Cyber ​​criminals have managed to infected ads on MSN.com get, the web portal of Microsoft, who then attempted to install malware on visitors. It is the same group of criminals who had previously been infected ads on the websites of Yahoo got.

Reported anti-virus company Malwarebytes. The ads redirect users to a page with the Angler-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player that users are not patched. What was there for malware through compromised advertisements installed is unknown, but through the Angler-exploitkit often ransomware malware and distributed for advertising fraud.

The infected ads came from the ad network AdSpirit.de, already described for the display of advertisements was infected on many popular websites responsible, including Yahoo. Picked up in the case of MSN advertising was via AppNexus at AdSpirit. AppNexus in June was also involved in infectious ads on the website of The Telegraph. Meanwhile the infected ads MSN.com removed.

Wednesday, 5 August 2015

Exploit Kit Infects 1.3 Million Computers Through Advertisements


The past six weeks have been about 1.3 million Internet users become infected because they are contaminated classifieds websites visited and had not patched their software. That leaves security firm Trustwave know . The ads redirect users to a new version of the RIG 3.0 exploitkit. This exploitkit uses vulnerabilities in Adobe Flash Player and Windows to infect users with malware. Especially vulnerabilities in Flash Player resulted in a lot of infections.

It is in this case for known vulnerabilities for which updates are available. In total, users would through compromised 3.5 million times ads have been forwarded to the exploitkit, resulting to 1.25 million infections. That equates to an average of 27,000 infections each day and a success rate of 34%. In addition, only traffic from Internet Explorer users redirected to the exploitkit.

Traffic originating from other operating systems and browsers is filtered by the cyber criminals. Once infected computers are then equipped with additional malware such as spambots and ransomware. To protect themselves against this type of attack Trustwave recommends users update their software, and specifically their browser and plug-ins. In addition, the use of click-to-play recommended browsers.

Tuesday, 4 August 2015

Great Campaign With Infected Ads On Yahoo


Cyber criminals have used the Yahoo ad network to spread contagious among Internet ads. According to anti-virus firm Malwarebytes involved a large-scale attack that began on July 28. The advertisements appeared on various Yahoo sites.

It was among other things, yahoo.com , news.yahoo.com and games.yahoo.com . The websites get together about 6.9 billion visitors per month. The ads showed visitors from Yahoo unnoticed load a page with the Angler exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player that users are not patched.

It is unknown what type of malware is installed on a successful attack on computers, but in the past Angler's exploitkit used to infect computers with malware and ransomware committing click fraud. After being informed Yahoo pulled the ad campaign from the air. The Internet giant states in response that it and other Internet companies working on a secure "advertising experience."

Saturday, 23 May 2015

Leaks In Routers Belkin, TP-Link D-Link Active Attacked



Focus cyber criminals in attacking vulnerabilities especially on browsers and browser plug-ins, however, are also an interesting target routers. A well-known researcher has discovered a exploit kit namely that leaks into the routers include Belkin, TP-Link D-Link attacks.

These are vulnerabilities that are disclosed in 2008, 2013 and 2015 and patched. Because routers are not automatically updated and many consumers do not own install available updates, it can indeed prevent further routers in circulation with vulnerabilities of seven years ago. In addition, the exploit kit also performs brute force attacks on all other models, including those from Microsoft and Linksys. In case the attacks are successful adjusts the DNS of the router. This allows attackers to traffic from the attacked router by running their own servers, or users of the attacked router forwarding to phishing sites.

Security Researcher 'JuK' of the blog Malware Do not Need Coffee discovered the exploitkit. That appears to work only from certain IP ranges. Once a router has changed the IP addresses of the DNS servers are changed and then reboot the router.As a secondary DNS server defaults DNS server of Google. This should prevent the investigator users suspect something when there are problems with the IP address of the first DNS server arise.

Tuesday, 21 April 2015

Flash Player Vulnerabilities Ever Attacked Quickly After Patch



Vulnerabilities in Adobe Flash Player are getting faster attacked after the release of a patch, which increases the pressure on users to install available updates as soon as possible. On April 14, patched a critical vulnerability in Adobe Flash Player that could allow attackers the underlying computer in the worst case can take over completely if a malicious or hacked website is visited or appear infected ads.

Only three days later, on April 17, there appeared an exploit that allows the vulnerability abuse. The exploit was added to the Angler-exploit kit, making all kinds of cyber criminals have access. By cyber criminals exploit kits can easily Internet attacks by placing on hacked websites iframes and JavaScript, pointing to the exploit kit. In case users do not patched malware can be installed on the computer.

There has been a trend in which leaks in Flash Player, after the release of an update, still attacked quickly. On the basis of the updates, the attackers can find out where exactly is the vulnerability and develop an exploit here. A development that reveals security experts worry, says security firm FireEye . The observed now operates first look at the user's system and then determines whether a parent or Tuesday patched vulnerability to be attacked. What kind of malware is distributed via the new exploit is unknown.

Thursday, 19 February 2015

Popular Porn RedTube Spread Malware


On the popular porn RedTube researchers have found malicious code that tried to infect visitors with malware. That leaves anti-virus company Malwarebytes know today. Unlike several other porn sites that for "drive-by downloads" were used, there were no infectious ads used in this case. The attackers had direct access to the code of the website.

The malicious code was executed inside an iframe and pointed to the Angler Exploitkit on another page. This exploitkit uses a recently patched vulnerability in Adobe Flash Player. In case users do not use the latest version of Flash Player, they can become infected with a Trojan horse. This malware steals personal information and installs browser helper objects showing ads. Some of these ads pointing again to other operating pages can infect your computer with malware so on.

RedTube leaves in front Malwarebytes know that last Sunday was attacked and the problem was resolved within a few hours.Meanwhile RedTube the malicious code would be removed . The porn is according to measurement agency Alexa on the 128th place of most visited websites on the internet. Earlier today, the anti-virus company warned that the website of chef Jamie Oliver malware spread . Also, this problem has now been resolved.

Hash:
1e0134d9b5b51d9ad233b0a2ecb7cf83

Thursday, 8 January 2015

Malicious Ads Distribute By AOL Advertisement's Network



Criminals have AOL's advertising network used to show ads on the infected websites of the Huffington Post, and many other sites. The ads pointed to a website where a exploit kit (Neutrino Exploit Kit or Sweet Orange Exploit Kit) turned that made abuse of a leak in Adobe Flash Player.

In case users were using an outdated version of Flash Player they could become infected with the Kovter-ransomware. This ransomware locks the computer and that the user has committed a crime and then to pay a fine to get access again.According to security firm Cyphort discovered that the attack is striking that the attackers used a combination of HTTP and HTTPS redirects to the servers that were used to hide in the attack.

Both Huffingtonpost.com as the Canadian website of the popular news were found infected ads according Cyphort.Huffingtonpost.com gets 51 million monthly visitors. Also FHM.com, gamezone.com and weatherbug.com included the target of this' malvertising campaign. Further investigation revealed that the ads were distributed via the AOL ad network.