Showing posts with label Google Security Researcher. Show all posts
Showing posts with label Google Security Researcher. Show all posts

Wednesday, 18 November 2015

Gmail App Allows Spoofing


The Gmail app for Android installed already standard on many smart phones, enables users to send spoof emails. Google acknowledges the findings, but still taking no steps to remedy it.

Security Researcher Yan Zhu discovered that it is possible in the Gmail app to send emails from a fake sender address. The trick is very simple and will only work with the Gmail app for Android.


If the display name is changed in the settings, the app itself removes the real address from which the message is sent. For the receiver it is therefore difficult to check the sender via the headers. For demonstration Zhu sent a mail from the account security@google.com.

Although not found bug is serious, it can easily be abused. Spoofing is a technique widely used by cyber criminals to lure potential victims to a particular site.

Yan Zhu its findings in late October when Google reported, writes Motherboard, but who denies that this is a vulnerability.

Friday, 2 October 2015

Avast Close Criticism SSL Vulnerability In Anti-Virus Software



The Czech anti-virus company Avast has a critical vulnerability in the anti-virus software patched it was discovered by a researcher from Google and which allowed an attacker to execute arbitrary code by users. The problem arose in Web Shield, part of the anti-virus software.

The virus Avast scans the contents of this web traffic. To be able to check via HTTPS encrypted traffic install the anti-virus software an own root certificate. A controversial practice that was also used by the Super Fish-adware. The way Avast this had been implemented made ​​it possible for websites to execute arbitrary code on the system remotely via a specially crafted SSL certificate.

The vulnerability was discovered by Google researcher Tavis Ormandy, who also significant problems in the anti-virus software from Sophos, ESET and Kaspersky Lab discovered. Ormandy warned Avast on September 25 and yesterday evening the virus fighter rolled an update for the problem. The researcher shows via Twitter, however, know that there are still more arrive.

Monday, 28 September 2015

Vulnerabilities In Windows Version TrueCrypt Discovered


In the Windows version of the ever popular encryption program TrueCrypt and the derivative Vera Crypt has a Google security researcher found leaking. It involves two different vulnerabilities allow a local attacker's rights on the system could increase.

The problems are caused by the way the encryption programs deal with drive letters and tokens. According to Mounir Idrassi, the developer of Vera Crypt, the problem with the drive letters a critical problem. In the case of Vera Crypt vulnerability is now patched in version 1.15, which will be released soon. TrueCrypt however, is no longer supported,allowing users of this software remain vulnerable.

Last year the developers of TrueCrypt indicated that they stopped supporting the software and it was unsafe to continue using the program. In response, decided to Idrassi Vera Crypt develop. It involves a fork, a spin-off on the original TrueCrypt source code is based. Idrassi however has made ​​several improvements to provide more protection. In addition, Vera Crypt actively supported.