Showing posts with label Github. Show all posts
Showing posts with label Github. Show all posts

Wednesday, 5 September 2018

MEGA Warns Against An Infected Chrome Extension That Steals Data



The popular cloud storage service MEGA has warned users of an infected version of its own Chrome extension that was distributed through the official download channel and tried to steal all kinds of user data. According to MEGA, the cloud storage service of internet entrepreneur Kim Dotcom, an attacker has gained access to the official Chrome Web Store account of the company.

Then an infected version of the MEGA Chrome extension was placed in the Web Store and automatically offered to existing users. This version required permission to read data on all websites. As soon as users granted this permission, the extension tried to steal private keys for cryptocurrency wallets and user names and passwords for Amazon, GitHub, Google and Microsoft accounts.

After five hours, the infected Chrome extension was removed from the Chrome Web Store by Google. MEGA states that it has initiated an investigation to find out how the Web Store account could be taken over. The cloud storage service also gets to Google because it does not allow developers to sign their Chrome extensions. The extensions are now automatically signed after being uploaded to the Chrome Web Store. According to MEGA, this will remove an important measure that must protect against attackers.

Before MEGA gave the warning, Jeremy Nation of MetaCert already came up with an analysis of the infected extension. It is not the first time that attackers get access to the Web Store account of an extension developer and then distribute an infected update or version. At the end of last year, eight Chrome extensions were discovered that had been hacked and adware was installed by the 4.6 million users. The attackers had been able to trace the login data for the Web Store through these phishing attacks.

Sunday, 11 March 2018

Popular Privacy Plug-In Ghostery Made Open Source



The German software company Cliqz, owner of the popular privacy plug-in Ghostery , has decided to make the tool open source. Ghostery blocks ads and trackers and has millions of users. A year ago Ghostery was taken over by Cliqz .

In the interests of transparency and an open internet, Cliqz has made the choice to make Ghostery open source. By looking at the source code, users can see how Ghostery works and what kind of data it collects. In addition, other developers can now contribute to the privacy plug-in. "Only when people understand what data digital products collect can they make meaningful decisions about what information they want to share and with whom," says Jeremy Tillman , Ghostery's product director.

According to Cliqz, most Ghostery users share stats with which new trackers are found. The software company emphasizes that it is anonymous statistics that also assess the relevance and safety of websites. However, it is also possible to set Ghostery so that no data is shared. The source code of Ghostery can be found on GitHub .

Monday, 9 October 2017

WordPress Sites Vulnerable By Leak Into Postman SMTP Plug-In



Over 100,000 WordPress sites are vulnerable due to a vulnerability in the Postman SMTP plug-in, and a developer security update is not yet available. Postman is an SMTP mailer that helps send emails generated by the WordPress site.

The plug-in is vulnerable to reflected cross-site scripting, which allows an attacker to steal the content of cookies from, for example, the administrator, according to security company White Fir. Due to the unpatched vulnerability, WordPress decided to remove the plug-in from the database with available plug-ins on WordPress.org . Meanwhile, GitHub has published a patched version of Postman, but it has not been developed by the original author. The original developer would have been informed about the problem.

Sunday, 4 October 2015

GitHub Introduces Logging Via USB Key


The popular online platform for developers GitHub has a new method added to allow users to login securely and advises developers to also to add their own software to the login method. It is the Universal 2nd Factor (U2F) standard of FIDO Alliance.

It is an authentication standard that during the next logon password also checks the presence of a U2F USB key. This hardware key acts as a second security factor. The key works only on the real website of GitHub, which as phishing and man-in-the-middle attacks must be prevented. U2F standard supports several platforms and browsers and requires no installation of drivers or software.

There are several manufacturers that offer U2F USB keys, which can all be used, but GitHub has launched an action with Yubico, provider of the YubiKey. Before developers on GitHub can log in via the USB key they need to be first through their account register. Last year, decided Google already U2F in to Google Accounts and set in August did Dropbox so. U2F as said from the FIDO Alliance, an alliance of IT companies like Microsoft, ING, Google and Intel, who want an end to the password and therefore working on alternative solutions.

Tuesday, 28 July 2015

Handy Privacy Tips For Firefox Users


Firefox includes many extensions to block trackers on the Internet and to protect the privacy of users, but the browser also sends itself data to third parties. Reason for a GitHub user to a list to the privacy options that adapt themselves through the browser.

This concerns issues such as Safe Browsing, collect statistics by Mozilla, the built-DRM plug-in, Firefox Hello, Pocket-integration WebRTC and geolocation. Sometimes users need to balance security and privacy. As Firefox exchanges via Google Safe Browsing information with Google in order to protect users from phishing sites and malware. Disabling this option can also be a security risk.

It also appears that Firefox Hello, a tool for video calls via the browser, connect to the servers of ISP Telefonica, without asking for your permission. In the case of the Pocket-integration, it is a connection to a third party to manage a list of articles read. In addition, users advised to search suggestions from the search box from the switch, since everything that is sent is typed into the search box defaults to the preset engine.

Sunday, 19 July 2015

Hacker Develops Device To Surf The Internet Anonymously


A well-known hacker has developed a device that users can go online anonymously, without their actual location or IP address to give up. The ProxyGambit of Samy Kamkar is an "improvement and reincarnation" of the ProxyHam. The ProxyHam would be demonstrated at the Defcon hacking conference initially, but researcher Benjamin Caudill concluded his lecture for letting off unknown reasons.

Also destroyed it all prototypes of the ProxyHam and announced that the software and blueprints of the device would not be published. The ProxyHam was a device that consisted of a Raspberry Pi computer with Wi-Fi card and three antennas. An antenna connection made ​​with an open Wi-Fi network, for example at a Starbucks or library, and two antennas that sent the data to and from the user via a 900Mhz frequency. A user could be at a position of 4 kilometers.

ProxyGambit

Kamkar, which in recent months regularly with all kinds of hardware hacks in the news came out, decided to develop its own solution based on the idea of ProxyHam. The ProxyGambit however, leave more space between the user and the used Wi-Fi network. The device supports both a radio link as a mobile bridge to connect to a Wi-Fi network. In the case of the GSM network can bridge the thousands of kilometers away there. Is made ​​using a direct link, the distance 10 kilometers.

Like the ProxyHam assigns the IP address that is visible to the outside world to the Wi-Fi network that uses the ProxyGambit. To connect to the mobile bridge, which used 2G, can be used as Kamkar a prepaid SIM card, which can be obtained anonymously. "In both cases, your connection proxied by local Wi-Fi networks in the vicinity of the unit, making it difficult to determine your actual location, IP and identity," Kamkar says.

The hardware for the ProxyGambit consists of an Arduino Nano, Raspberry Pi, GSM Fona, USB hub, wifi adapter, Ubiquiti Nano Station and a Power over Ethernet injector. The cost of the parts amounts include 200 dollars. The software for the device, the hacker on GitHub placed while a Linux image via Dropbox is available for download. Kamkar warns that this is still a "proof of concept" goes and users for whom privacy and anonymity is important to do further research.

Tuesday, 14 July 2015

NSA Launches Open Source Security Tool On GitHub


The US National Security Agency has placed an open source security tool on GitHub that enables organizations to protect their networks. The Integrity Management Platform ( SIMP ), as the tool is called, must keep networks compliant with security standards.

In recent years, several governmental and industry organizations have developed similar technologies. By SIMP release the NSA hopes to avoid duplication and promote cooperation within the community. "The wheel does not by any organization to reinvent," said the intelligence service. According to the NSA open source is a very effective way of "government lab" to get the technology marketplace.

"The open source community can benefit from the work that the NSA has produced, and the government can benefit from the expertise of the community. Everyone wins this way," said Linda Burger, director of the NSA Techology Transfer Program.Through Transfer Program can share the NSA technologies with other parties, such as academics, government and industry.

Thursday, 18 June 2015

Favicon Bug Late Chrome, Firefox And Safari Crash


A bug in the way Google Chrome, Mozilla Firefox and Apple Safari handle the favicons of websites ensures that they can eventually crash. The problem was accidentally discovered by security analyst Andrea De Pasquale. He had a favicon 64MB download large that a full backup of a WordPress website turned out to be.

Programmer Benjamin Gruenbaum worked out the problem further into a demonstration on GitHub , which browsers without users have let this by downloading a large favicon. For his demonstration Gruenbaum created a favicon almost 10GB which ultimately caused a crash on his Macbook, so he lets on Hacker News know. Undetected downloads would especially be a problem for mobile users with a data limit. Gruenbaum then warned Mozilla and Google on the issue. The developers of Firefox came in three hours with a solution that will be present in the latest version of the browser. The problem is not with Internet Explorer.

Tuesday, 31 March 2015

GitHub Know Repel Chinese DDoS Attack After 113 hours



The popular online platform for developers GitHub has a DDoS attack that began on March 26 after 113 hours to successfully beat off, as the website shows through Twitter know. When the DDoS attack combining attack vectors used. It was well known attack techniques and new technologies used by the browsers of unsuspecting people who had nothing to do with the attack, large amounts of data direction github.com send.

"Based on reports we have received, we think that the aim of this attack is to remove certain content," said Jesse Newland from github in a blog posting . According to the company Insight Labs Internet in China was manipulated to harass GitHub website with traffic. Files of the Chinese search engine Baidu were thereby replaced with JavaScript against the GitHub pages of the Chinese New York Times and Great Fire was directed. Great Fire is an organization that monitors censorship in China.The added code caused the browsers of Chinese Internet users every two seconds clippings from the GitHub pages.

Even researchers Netresec say that the "Great Firewall of China" was used to perform a powerful DDoS attack on GitHub."Therefore the Great Firewall can not only be seen as a technology to censor the Internet of Chinese citizens, but also as a platform for conducting DDoS attacks against targets worldwide, with the help of innocent civilians deployed visit Chinese websites." The current measures taken by GitHub would however maintain.

Tuesday, 17 March 2015

Mozilla Launches Memory Scanner For Servers


Mozilla has released a tool that allows for real-time scan the memory of a great number of servers on any suspicious items. The open source developer manages thousands of servers for the development of products and offering services.

Developed to monitor the security of these servers was the Mozilla Investigator (MIG). MIG can the file system and network information on thousands of machines simultaneously monitors, which should provide more insight into the infrastructure.Until recently, however, it was not possible to isolate MIG to analyze the memory of running processes. Yet it would be for security investigation.

Masche

In recent months developed several students why a "memory forensics library" on Linux, Mac OS and Windows is running. Masche , as the tool is called, can scan the memory of running processes, without having impact on the system. It does not offer the same detail as advanced forensic software, but is focusing on " regexes "and" byte strings "in the processes of many systems.

This makes it possible to monitor the memory of such systems quickly and in real-time. The source code of Masche is completely open source and available on Github . Mozilla tool will integrate within MIG and deploy within their own infrastructure. This should ultimately improve scanning performance of the tool, which in turn Mozilla will share with the community.

Saturday, 21 February 2015

250,000 routers discovered with same SSH key


A researcher who wrote a program to include the "fingerprints" of collecting SSH keys watched curiously when he found one fingerprint on over 250,000 devices. It turned out to routers of the Spanish telecommunications provider Telefonica de Espana.

Some network would default SSH feature, which the manufacturer decides to roll out the same operating system image on all devices. Researcher John Matherly , founder of the Shodan search engine, also found two keys that 200,000 and 150,000 times were used, respectively.

"By analyzing these cases it is easy to get a picture of the systemic problems both hardware manufacturers and ISPs pests," said Matherly. He has a list of unique fingerprints collected offers now via Github to. "It would not surprise me if you find interesting security problems by analyzing why these things are configured incorrectly," he notes.

Tuesday, 3 February 2015

Firefox and Chrome Can Leak IP VPN Users

Firefox and Google Chrome have implemented a technology allowing the IP address of VPN users can be traced. Before Daniel Roesler warns on GitHub . The problem is caused by WebRTC , an open source project developed by Google that provides browsers Real-Time Communications (RTC).

Both Firefox and Chrome have implemented whereby the WebRTC technology called " STUN requests "can send to STUN servers. Through these requests, the local and public IP addresses of the user can be captured via JavaScript. This is especially a problem for VPN users, who often use VPNs to protect their identity. Roesler made ​​this demonstration to capture the IP addresses. Readers Reddit give different solutions to the problem, such as disabling WebRTC in Firefox and Chrome.

In Firefox, this can by in the address bar " about: config "to enter and then put" media.peerconnection.enabled "to" false ".Google Chrome users can do this in the address bar " chrome: // flags / "to enter and then" Disable WebRTC device enumeration "to turn. Other solutions have JavaScript disabled, using Firefox NoScript or Chrome extension WebRTC Block. Additionally, VPN users get TorGuard advised to set the VPN tunnel directly to their router.

Thursday, 15 January 2015

Gitrob - "This New Tool Crawls GitHub Sensitive Data"


For developers and organizations that work with GitHub is a new tool appeared which makes it possible to search the platform on sensitive data. GitHub is a popular online platform for software developers that code and files can be shared.

Also can work on projects together over the platform. Many companies and projects use GitHub to host both internal and public projects. Sometimes it happens that employees publish things that actually may not be published. This relates to sensitive data or business with which a system can be made ​​immediately. "This can happen by accident or because the employee does not realize the sensitivity of the information," said Michael Henriksen .


So it still happens regularly that developers publish things as private keys and credentials. Henriksen therefore developed Gitrob , enabling organizations and security professionals can find this kind of sensitive data. The tool collects all the public "repositories" of the organization, as well as all employees and their public repositories. Then all available files are collected and analyzed to see if they match patterns for sensitive files.

Henriksen works for SoundCloud and had to develop a system that monitors GitHub sensitive files. He notes that organizations can look through his tool or no sensitive files roam. In addition, penetration testers and more "offensive" security professionals can use the tool to collect information about a potential target.