Showing posts with label Hacker News. Show all posts
Showing posts with label Hacker News. Show all posts

Thursday, 5 May 2016

German Government Launches Test Plan For Security Routers


In order to ensure that routers that individuals and small businesses purchase are safe, the Bundesamtes für Sicherheit in der Informationstechnik (BSI), part of the German Ministry of the Interior, today a comprehensive test plan ( pdf ) launched broadband routers.

The test plan, especially for Internet service providers and manufacturers intended, which describes a secure router to meet.In this way, potential buyers can more easily compare models in the field of security with each other. According to the BSI, the security of a router, an important factor when choosing a particular manufacturer or type. The German federal government has recently abolished the so-called router obligation. Thereby German internet users can choose yourself which soon modem and router that they want to use their broadband connection.

"Routers are a central part in the digitalization and networking. They are the heart of the home network, but protect at the same time against Internet threats. The abolition of the router obligation have internet August this this year more choice in choosing their router. users should make use of this by looking at the safety when choosing a router, "said Arne Schönbohm, head of the BSI.

In the test plan different parts are discussed, such as the presence of security measures. Thus, each router must sort the BSI have a firewall and there should be no default port forwarding enabled. In addition, made several recommendations, such as the presence of an automatic update feature. Furthermore, the test plan contains examples of common vulnerabilities and attack scenarios.

Wednesday, 4 May 2016

Virus Crashes Medical Equipment During Heart Procedure


A medical system that monitors patients crashed during cardiac procedures because the virus carried a specified virus. Reported that the US regulator FDA. It concerns the Merge Hemo, a programmable diagnostic computer of Merge Healthcare.

The system consists of a data module and the patient Hemo-monitor computer. The two units are connected via a serial interface connected with each other. During a heart procedure, the Hemo-monitor computer lost contact with the client and Hemo was the image black. While the patient was anaesthetized, this caused a delay of five minutes because the system had to be restarted. Research showed that the virus was to perform a scheduled virus scan.

According to the FDA this may compromise the patient at risk. In the case of the incident was the heart procedure, after the system was restarted, been successfully completed. The manufacturer states in response that the hospital has not followed the instructions regarding the installation of anti-virus software. These guidelines establish how the virus must be set so that there are no consequences for treatments. As patient data and medical images must be scanned. There, according Merge Healthcare therefore no problem lie with the medical system.

Monday, 6 July 2015

Italian Spyware Developer Hacked Hacking Team



Attackers have managed the controversial Italian surveillance operation and spyware developer Hacking Team to hack and thereby some have 400GB to 500GB of data captured, including financial data, software source code, e-mail and much more sensitive matters.

Hacking Team is a company that develops spyware for governments in recent years and was regularly in the news . The company's spyware would include being deployed by totalitarian regimes against activists. As Amnesty International showed a tool developed to detect the spyware Hacking Team. How the attackers, calling themselves Team Hacked call, access the data received is unknown. The stolen data is now distributed via .torrent files.

Evidenced by the now leaked information that the company customers in countries like Ethiopia, Sudan, Azerbaijan, Bahrain, Oman, Saudi Arabia has and the United Arab Emirates, but also Switzerland, Spain, Poland, Luxembourg, Germany and the United States found in the customer base, as on Hacker News reported, and would from a post on Pastebin appear. An anonymous source leaves in front of Vice Magazine that the attackers have managed to steal all company.

Last year was the German-British Gamma International, developer of the FinFisher spyware same. The website was hacked and then published attackers database, ultimately to parliamentary questions resulted in Netherlands. In an e-mail now to Hacking Team was captured late CEO and founder of the Italian surveillance company David Vincenzetti, bending over his rival hacked off. "A wannabe competitor of ours is severely compromised," he writes. Hacking Team has not yet responded to the burglary, which about nine days ago was announced.

Update

By now appear more and more details about the stolen data. There is an overview of the contents of the torrent file online appeared. Privacy activist Christopher Soghoian reports that the Italian company used illegal software, as there was a cracked version of a popular analysis tool found in the download. Another Twitter announced that the software Hacking Team vulnerable for SQL Injection.

Sunday, 28 June 2015

Researcher: Root Certificates Added Quietly Windows


Microsoft has quietly 18 new root certificates to Windows without notice has been here somewhere. So says a researcher with the alias " Hexatomium ". Root Certificates determine which SSL certificates are trusted by the operating system.

It is therefore important to know which organizations and certificate authority's root certificate is added. The researcher reports that he is the new root certificates through the RCC-auditing tool has discovered. Through the program, users can control which root certificates are heard in the Windows root CA to store and which have been added quietly.

In addition to the SHA1 hash of the license and the name of the associated certificate authority is no additional information is available. On Hacker News lets a user know that the certificate authority named RXC C2 is actually Cisco. Remarkably Cisco sets its own documentation Cisco RXC certificate policy ( pdf ) which certificate authorities should always use meaningful names. Feather in the list of additional root certificates include certificates of Swedish, Tunisian and Indian authorities.

Thursday, 18 June 2015

Favicon Bug Late Chrome, Firefox And Safari Crash


A bug in the way Google Chrome, Mozilla Firefox and Apple Safari handle the favicons of websites ensures that they can eventually crash. The problem was accidentally discovered by security analyst Andrea De Pasquale. He had a favicon 64MB download large that a full backup of a WordPress website turned out to be.

Programmer Benjamin Gruenbaum worked out the problem further into a demonstration on GitHub , which browsers without users have let this by downloading a large favicon. For his demonstration Gruenbaum created a favicon almost 10GB which ultimately caused a crash on his Macbook, so he lets on Hacker News know. Undetected downloads would especially be a problem for mobile users with a data limit. Gruenbaum then warned Mozilla and Google on the issue. The developers of Firefox came in three hours with a solution that will be present in the latest version of the browser. The problem is not with Internet Explorer.

Monday, 11 May 2015

Mitnick: Almost 100% Success With Social Engineering



Social engineering is still one of the best ways for hackers to invade in organizations, since there is no patch for human stupidity, says security expert Kevin Mitnick. Mitnick was for years the most wanted hacker in the world and was eventually sentenced to a prison term of five years for breaking into several large companies, where he applied social engineering.

During his keynote address to the CeBIT business IT conference in Sydney Mitnick said that social engineering is particularly effective to penetrate into secure networks because existing problems are human error. "You can not download a patch for stupidity," he noted. "Social engineering bypasses all intrusion-detection systems. There is nothing on the market that can detect." In addition, free or relatively inexpensive to carry out, such as sending e-mail.

Mitnick himself conducts his own business penetration tests. If there should be social engineerg used, the success rate close to 100%. "It works on any platform, regardless of whether you're using Windows, Mac OS X or Linux. It is completely platform independent and the success rate is almost 100%." Mitnick told the audience that anti-virus software is dead and that most attacks that result from social engineering are able to bypass the virus, let Zdnet know.

They are, according to him than people who are the weakest link in security. "Users are the problem," said the ex-hacker. He also advises companies to strengthen "human firewall", something that can be done by repeated workouts. Additionally, organizations must ensure that all software on the computers of employees up-to-date and needs to incoming and outgoing traffic stringent be filtered through the firewall.

Friday, 27 February 2015

Facebook 1.3 Million Paid Researchers For Bug Reports


Facebook last year, $ 1.3 million paid for bug reports were submitted by researchers. Since the "bug bounty" program began in 2011 is more than $ 3 million disbursed. In 2014, Facebook received 17,000 bug reports, an increase of 16% compared to 2013.

Eventually, 321 researchers rewarded for their entries, which equates to an average reward of 1788 dollars per bugmelding.The five most active researchers earned last year together $ 256,000. Furthermore, according to figures from Facebook that most bugs last year were sent by Indian researchers, namely 196. Average yielded investigators USD 1,343 per bugmelding on.

The number of bug reports from Great Britain is 28 much lower, but average paid Facebook British researchers dollar 2,768 per bugmelding. A total of researchers from 65 countries paid by the social networking site. For this year expects Facebook again the necessary bug reports. Since the new year were already more than 100 valid reports are received.

Thursday, 26 February 2015

Hacked Insurer Fined For Missing Patches


A British insurance company has been fined 175,000 pounds (239,000 euros) because the security updates forgot to install which customer data could be stolen. During the attack on Stay Sure attackers had access data from more than 100,000 credit cards, as well as medical data. The security of the credit cards, which is the back of the card, was also accessible.

However, this is in violation of industry rules, which state that they may not be saved. Eventually tampered with the credit cards of more than 5,000 people. It emerged that the company had no policies or procedures for checking and updating of IT security systems. In addition, the insurer password twice to update the database, so the intruder could have been prevented.

"It is inconceivable that a company with three million customer data had no procedures in place to protect that information,"says Steve Eckersley, head of enforcement at the UK Information Commissioner's Office. Eckersley hopes that the penalty as a warning to other companies will need to keep their IT security in order.

Wednesday, 25 February 2015

PrivDog: Only 57,000 Users At Risk


Adware PrivDog developer has released a security update after there was a vulnerability in the software detects allowing users targeted by Man-in-the-middle attack could be. In total, this "only" 57,000 users have run risk, says the developer. However, this is not the PrivDog software that comes with the programs of security provider and Certificate Authority Comodo. PrivDog makes adware that SSL connections are intercepted and software advertisements of "reliable partners" can inject.

Researchers discovered that PrivDog install a root certificate and thus intercepted each SSL certificate of websites using a self-signed certificate, even when it comes to SSL certificates that are not valid. As a result, the browser will accept HTTPS each certificate that is, whether by a Certificate Authority (CA) is signed or not. For example, users of public Wi-Fi networks could thus be the victim of a Man-in-the-middle attack. The vulnerability is present in versions 3.0.96.0 and 3.0.97.0 PrivDog.

These versions intercept SSL traffic and were downloaded from the website of PrivDog. Contrary to what was thought yesterday is Comodo Internet Security with an earlier version of PrivDog bundled working with a browser extension and thus is not directly vulnerable to this threat. That says researcher Hanno Boeck in addition to his research. PrivDog also confirms that the PrivDogplug-in that comes with the Comodo Browsers problem has not.

Globally, more than 57,000 people have downloaded the vulnerable PrivDog versions. According adware developer made ​​sure that the problem with some sites that use a self-signed certificate no certificate warning was given. However, the encryption was offered to the end user would remain intact, says PrivDog. Tonight there is rolled out an automatic update that fixes the problem by users.

Tuesday, 24 February 2015

Privdog Software Worse Than Superfish Adware


After computer manufacturer Lenovo appears to combine security provider Comodo adware with its own software SSL traffic intercepted, only the impact is much greater than with Lenovo's Superfish was. That says researcher Hanno Bock . Comodo is known software like Comodo Internet Security and Comodo Dragon Browser. With some of the programs PrivDog-adware is included.

Like Superfish intercepted PrivDog HTTPS traffic to inject ads from "reliable partners". Late last year, the ability to filter HTTPS traffic was already on the forum Comodo discussed . The software is after Superfish scandal now in the spotlight. A user decided because Superfish a test page to do, which warns users if their HTTPS connection is manipulated. Although the user is not used Superfish he got a warning. Then this user reported on Hacker News that the possible was the PrivDog-adware.

PrivDog not have the same vulnerability as Superfish, using a weak certificate and a weak password to protect the private key of the certificate, but one which is many times as possible according to Bock. Although Superfish same certificate and key used for all installations, PrivDog makes for each installation a separate key and certificate. The biggest problem is that each certificate PrivDog intercepted and replaced by a self-signed certificate.

It is also about certificates that were not valid in the first place. As a result, the browser will accept HTTPS each certificate that is, whether by a Certificate Authority (CA) is signed or not. "We are still trying to find out the details, but it looks bad," Bock says. The researcher also finds it strange that Comodo, which is itself a CA bundle adware with their own software. "If the CA would be their job to protect HTTPS, not break," the researcher concludes.

Meanwhile warns also the CERT Coordination Center (CERT / CC) at Carnegie Mellon University for PrivDog. An attacker could according to the CERT / CC HTTPS sites spoof and intercept HTTPS traffic without users see a certificate warning.Users will also be advised to remove PrivDog. This would also be the root certificate in question to be removed.

US-CERT writes: "Adtrustmedia PrivDog is promoted by the Comodo Group, which is an organization that offers SSL certificates and authentication solutions." A variant of PrivDog that is not affected by this issue is shipped with products produced by Comodo (see below). This makes this case especially interesting because Comodo itself is a certificate authority (they had issues before). As ACLU technologist Christopher Soghoian points out on Twitter the founder of PrivDog is the CEO of Comodo. (See this blog post.)

Update/Clarification: The dangerous TLS interception behaviour is part of the latest version of PrivDog 3.0.96.0, which can be downloaded from the PrivDog webpage. Comodo Internet Security bundles an earlier version of PrivDog that works with a browser extension, so it is not directly vulnerable to this threat. According to online sources PrivDog 3.0.96.0 was released in December 2014 and changed the TLS interception technology.

Update 2: Privdog published an Advisory.

Professor: Cyber Criminal Is Not A Full Hacker


Hackers are often portrayed as evil geniuses, but a better description of who is talented, albeit sometimes mischievous, craftsman. They also play a key role in society by things safer else to think about problems and systems. That suggests Kevin Steinmetz , professor of sociology, anthropology and social work at Kansas State University.

Hacking is according to him, more than breaking into computer networks and security systems. "Hackers are often portrayed as criminals who steal in the dark money. Hacking is much more than that. It can also consist of the development of free and open source software." The professor is concerned with the study of the hacker culture and digital crime. In his latest research on the question of what is a hacker and what it means to hack.

"If there's one thing that they have taught me is to not be afraid to bend the rules or an idea on its head and put things challenging," said the professor in an interview about his research the Wichita Eagle . "We need to encourage people to think differently and to draw the status quo in doubt." Part of both hacking and craftsmanship consists of finding and solving problems. Hacking also has many similarities with craftsmanship. Steinmetz designates the self as a technological craft passing boundaries.

Hacking has evolved over the years. Yet hackers engaged in security currently getting all the attention, according to the research of the professor. The reason that security at the moment is so popular is because here play all interesting problems, says a hacker who spoke Steinmetz. The research also shows that hacking is no longer associated with the subculture where it originally came from. Namely people who are interested in technology and computers. Hacking is now used in a variety of domains. The media usually about hackers who are guilty of cyber crime, breaking into networks and steal credit card information.

However, this stereotyping fog that hacking is more to the process than the end result. Without craftsmanship is someone who commits crimes with digital may therefore not a hacker. "If people are engaged in this type of behavior because they want only final results, my research shows that they can not be regarded as a complete hacker" said Steinmetz. "They need to embrace the qualities of a professional, someone who loves his job and goes up here." The research of the professor was published in the British Journal of Criminology.

Wednesday, 18 February 2015

Server Programming Language Haskell Hacked


Attackers have been there last week managed to hack a server programming language Haskell. Haskell is a functional programming language named after the mathematician Haskell Brooks Curry. Via Haskell.org it is possible to download the "Glasgow Haskell Compiler". These include the versions of the compiler made ​​for Debian.

The attackers managed to gain access to the server where the Debian packages are offered, according to a status report on the website of Haskell.org . Last Saturday it was reported that the download location was taken off the air after the hosting provider had observed suspicious traffic. Further investigation revealed that the server with "Debian builds" since February 12 was compromised.

According to the organization behind Haskell was deb.haskell.org briefly taken offline after the discovery of the suspicious times. The attackers would have had little time to provide the offered packages of any backdoor. The investigation into the attack and whether there are other machines are affected is still running. On Hacker News , however, ask users whether the attackers have managed to get the key with which packages are signed. Haskell of the explanation is not clear.