Showing posts with label IP addresses. Show all posts
Showing posts with label IP addresses. Show all posts

Friday, 13 November 2015

FBI Would Have Paid For College Attack On Tor


The FBI would have last year an American university paid $ 1 million for attacking Tor users in order to find people that they could accuse of crimes, reports the Tor Project, the organization that maintains the Tor network.

Every day, 2.5 million people use the Tor network to protect their IP addresses and online privacy. In July last year there were several Tor servers discovered that had been put down to identify Tor users. Eventually, it turned to a study conducted by Carnegie Mellon University. According to the Tor Project were likely to be a dragnet that investigators throw out, to gather as much information about users which could then be used by the FBI.

In addition, the action was aimed not only against criminal users of the Tor network, but for all users. "This attack exceeds the critical line between research and endangerment of users," said Roger Dingledine, co-developer of Tor. He argues that the attack also sets a precedent where civil liberties are under attack by law enforcement agencies that outsource their police work in universities.

"As such an FBI-attack is accepted via a university proxy, no one has on the Internet, the protection of the amendment and 4th runs anyone risk." Dingledine argues that investigative agencies Tor can use for their police work, but that police investigation is not complete violation of people justifying their privacy and certainly not as legitimate research 'can be labeled. The vulnerability that the researchers used was already addressed last year. In addition, the Tor Project has a number of rules for ethical research published to the Tor network.

Wired approached the university, who denied the allegations, but said that there was a lack of evidence. "I would like to see a substantiation of their claim," said a PR staff. "I'm not familiar with any payment," as he announced. The employee declined to comment further.

Sunday, 16 August 2015

The Seven Deadly Sins Of System


System administrators play an important role in the prevention of attacks on their organization. However, there are arranged attacks in the news in which there is, for example, vulnerabilities have been used to infiltrate the corporate network for which for many years were available updates.

However, the security updates were not installed so employees by opening a document or visit a Web site became infected.This relates to old vulnerabilities in, for example Microsoft Office and Java regularly targeted. Among other targeted espionage attacks. Something recently the FBI warned . There are also other things that should have a system in place, or else run the risk organization. Reason for security GFI Software to a list of seven deadly sins to create system in which not installing security updates is called first.

The other mortal sins are using default configurations and passwords, working with admin rights, not documenting changes, IP addresses and license keys, no viewing log files, password sharing and finally the question of passwords. Often alerting system administrators and end users to phishing attacks say that they should never share their passwords, then himself to the user asking his password if there is a problem. End users should also never be asked for their password, according to the explanation of the last mortal sin.

Friday, 7 August 2015

American And British Companies Hacked Through Very Old Java Flaw



In recent years, American and British companies hacked a vulnerability in Java in 2011 has already been patched by Oracle. The attackers behind the attacks also are sent out zip files containing malware to their victims. That Dell SecureWorks announced.

To the companies through the old Java vulnerability to attack the attackers hacked some 100 sites that were visited by employees. It then went to websites of major production companies, embassies of countries in the Middle East, Europe and Asia in Washington DC and non-governmental organizations (NGOs). To ensure that only the right companies were attacked, the attackers used a whitelist. Based on IP address was determined whether users were attacked via the Java leak.

The group would also be other known vulnerabilities for which patches have been attacked available, but the Java vulnerability would have been particularly popular. Once access to the machine of a worker obtained a vulnerability in JBoss was used from 2010 to redirect the browser to other users to the attack code, so that the attackers gained access to other systems.

Social Engineering

Besides attacking known vulnerabilities, the attackers also used social engineering. So were targeted emails sent to targets with a zip file. The zip file contains both legitimate files as malware. As contained one of the zip files a PDF file, an image, and the malware was disguised as a file. Because no standard Windows file extensions display saw users in this case that the "picture" for instance ended in .exe.

According to Dell, the attackers had to cater for defense companies and were looking for information on US defense projects.Companies and organizations in other sectors, however, were also targeted. How many companies the attackers were able to compromise was not disclosed.

Thursday, 30 July 2015

Chrome Extension Prevents Profiling By Type Of Behavior



Websites, Internet users nowadays not only to follow based on their IP address or browser features, including the way one type provides companies with sufficient information to draw up a profile. Two researchers, Paul Moore and Per Thorsheim therefore have developed an extension for Google Chrome called " Keyboard Privacy "that prevents profiling by type of behavior.

Several banks were already using the technology. The technology according to the researchers, also interesting for totalitarian regimes, as well as advertisers. Even when using an Internet user or a Tor proxy, he would still be recognized by the use of his type of behavior. In order to counter this form of tracking and profiling Keyboard Privacy changes the rate at which typed characters arriving at the website.

Moore argues that the extension reduces security, but this is not a bad thing necessarily. "It's important to find a good balance between security and privacy. It is very difficult to raise one without the other measurable decrease," he notes.Internet users who like their type of behavior on websites "leak" or their bank will be forced to, according to Moore extension per website on or off. Soon there will appear a Firefox version of the extension.

Sunday, 5 July 2015

Critical Vulnerabilities In Tor And Tails Corrected


There are new versions of Tor Browser and Tails appeared, two programs for people who want to protect their privacy and anonymity on the Internet, where critical vulnerabilities are fixed. Users also have strongly advised to upgrade, since users of Tor Browser still using an old version surfed in the past been the target of attacks, their actual IP address was traced .

Via Tor Browser, users can easily hide their IP address. The browser consists of a modified version Firefox and software to connect to the network-Tor. This week a new version of Firefox, allowing the developers of Tor Browser also had to release a new version. Tor Browser 4.5.3 also includes a new version of OpenSSL and NoScript Torbutton, as well as a fix for a bug that allowed the browser crash and a patch to improve the usability of Tor Browser on websites. Updating via Torproject.org if the update function of the browser.

Tails

Users of Tails get urgent advice to Tails 1.4.1 upgrade. Tails is a complete operating system from a DVD or USB stick to use and is totally focused on privacy. It is based on Debian and contains various tools to access the Internet anonymously, including Tor Browser. In the past, for which the new versions of Tor Browser and Tails were not coordinated.

Therefore Tails users could sometimes several weeks stuck with an outdated Tor Browser. Now Tails development team has been waiting for the new Tor Browser, which added to the operating system. In addition, several Debian-related vulnerabilities are resolved. Updating via the Tails website .

Saturday, 13 June 2015

IBM Sees Weather DDoS Attacks From Bill Gates Linux Botnet


A botnet that infects Linux computers and used to carry out DDoS attacks is active again, says IBM. It's the "Bill Gates botnet" which last year was first detected, reports IBM . The bot-amplification uses DNS to carry out the DDoS attacks.

With DNS amplification open DNS servers are used to enhance the traffic to the attacked websites or services. An interesting feature of this malware, according to the Russian anti-virus company Dr. Web together with the Finnish F-Secure paid attention to the last year malware. According to the Russian virus fighter is the Gates-malware also allegedly found because of a sophisticated modular structure that never experienced Linux malware.

At the time, it was unknown how the malware was spreading. Something where IBM still has no answer. It is not known who is behind the botnet. However, the company argues that there has been observed a significant increase in traffic, which are used forged packets and the destination IP address in China.

Tuesday, 26 May 2015

Server Digital Bank Robbery Points To Russian Secret Service


Researchers from the Japanese anti-virus company Trend Micro were strange to look at when a server that was used in a bank robbery comprehensive digital suddenly pointed to an IP address of the Russian secret service FSB. Late last and early this year warned security for a group of attackers, called "Anunak "or" Carbanak "who knew to break through malware with banks and tens of millions of euros booty made.

The malware was driven by the gang used several domain names, as Command & Control (C & C) server functioned. Since the revelations infrastructure Carbanak monitored. Last week was the IP address of one of the C & C domains suddenly turned and pointed to an IP address of the FSB, let analyst Maxim Goncharov know. He does not think the FSB of adjustment and is therefore suspect that it is a joke of the domain owner, though a blunder also not excluded.

Saturday, 23 May 2015

Leaks In Routers Belkin, TP-Link D-Link Active Attacked



Focus cyber criminals in attacking vulnerabilities especially on browsers and browser plug-ins, however, are also an interesting target routers. A well-known researcher has discovered a exploit kit namely that leaks into the routers include Belkin, TP-Link D-Link attacks.

These are vulnerabilities that are disclosed in 2008, 2013 and 2015 and patched. Because routers are not automatically updated and many consumers do not own install available updates, it can indeed prevent further routers in circulation with vulnerabilities of seven years ago. In addition, the exploit kit also performs brute force attacks on all other models, including those from Microsoft and Linksys. In case the attacks are successful adjusts the DNS of the router. This allows attackers to traffic from the attacked router by running their own servers, or users of the attacked router forwarding to phishing sites.

Security Researcher 'JuK' of the blog Malware Do not Need Coffee discovered the exploitkit. That appears to work only from certain IP ranges. Once a router has changed the IP addresses of the DNS servers are changed and then reboot the router.As a secondary DNS server defaults DNS server of Google. This should prevent the investigator users suspect something when there are problems with the IP address of the first DNS server arise.

Friday, 1 May 2015

Increase DDoS Attacks Hacked Routers And Printers



Hacked printers and routers are responsible for an increase in the number and size of DDoS attacks.Other devices connected to the web and part of the "Internet of Things" are play a role, claims the security NSFocus.

In the attacks, the attackers use the Simple Service Discovery Protocol (SSDP), which is part of the UPnP protocol. This protocol is enabled on millions of devices, including routers, media servers, webcams, smart TVs and printers. Via SSDP devices can find each other easily networks and connect with each other. Through the SSDP protocol on these devices strengthen their criminals DDoS attacks.

The criminals in this spoof the IP address of the attack site and send packets to the router or other devices. Which then react with response packets that are sent to the spoofed IP address. According NSFocus attacks can in this way by a factor of 75 to be reinforced. The company further states that there are more than 7 million SSDP devices that can be used for DDoS attacks. As soon the Internet of Things becomes reality, whereby billions of devices coming online, expects IT security exponential growth of SSDP-like attacks.

"Recently more attacks were seen being launched from smart devices", say the researchers from the security company in this report . The reason is that smart devices have a relatively high bandwidth, often not be updated 24 hours a day online."As smart devices have weak passwords or other vulnerabilities, attackers can use them to carry out DDoS attacks."Recently warned also security company Arbor Networks to use SSDP for strengthening DDoS attacks.

Tuesday, 28 April 2015

Branding Biggest Challenge DuckDuckGo


Various studies have shown that people on Internet privacy is important, yet awareness is the biggest challenge for privacy search engine DuckDuckGo. The search engine focuses entirely on online privacy and says that the IP addresses of users or other personal information store and does not create user profiles.

Late last year decided both Apple and Mozilla DuckDuckGo optional respectively Safari and Firefox add . Meanwhile, the search engine privacy will be affected more than 9 million searches per day. This number is not proportionate to the 3.5 billion searches Google processes daily.

Yet DuckDuckGo founder Gabriel Weinberg is positive. He points to a recent survey by the Pew Research Institute, which shows that people are looking for privacy-friendly alternatives. "While it is difficult to predict future growth, it looks good. Our biggest problem is to know that we exist," says Weinberg opposite Network World . He noted that DuckDuckGo has no plans to also start offering other services and will focus only on the search engine.

Saturday, 11 April 2015

Group bombarded SSH Servers With 300,000 Passwords



A group of cyber criminals that has been active since June last year conducts large-scale attacks against SSH servers, whereby through more than 300,000 unique passwords attempting to log in. Once access to the server is obtained finally installed a DDoS rootkit.

Through this rootkit can execute the attackers acquired server DDoS attacks. The cyber criminals by Cisco and Level 3 as "SSHPsychos" and "Group 93" indicated. The group would generate as much traffic with the login attempts that all joint attacks on SSH from other parties combined into nothing fall. The attacks appeared from different netblocks (ranges of IP addresses) to arise. In cooperation with backbone provider Level 3 was decided that the group netblocks disabling used.


As part of the process, Level 3 warned the responsible providers, which the group cybercriminals suddenly used a new network for their scans and attacks. Because of this sudden transition decided Cisco and Level 3 to remove the routing options for both the old and new netblock. According to Cisco, this will "hopefully" slow down the activities of the group for a certain time.

The networking giant notes that "detectors and protectors" can no longer sit on the side as cybercriminals in such flagrant attack systems. However, the measures affect only the part of the Internet that is provided by Level 3. Cisco calls than other parties in order to block malicious traffic from this group on the Internet. "By working together, we can eliminate a group that makes no effort to hide their malicious activities," the company said.

Thursday, 26 March 2015

Site Checks Hijacked DNS Settings Router


The past year has regularly occurred cybercriminals adapted the DNS settings of routers so that they could direct users to malicious Web sites without direct user was clear. The Finnish anti-virus firm F-Secure says it has discovered more than 300,000 residential and business routers in 2014 of which were adapted to the DNS settings.

The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses.By adjusting the DNS of the router can criminals traffic from users via their servers run or redirect user to as phishing sites, even though they have stated in their browser the correct URL.

The anti-virus company therefore has a website launched that can be easily verified that the DNS settings on the router or the system are hijacked. In case the DNS hijacked, users advised to disconnect their router from the Internet and reset, change the password, disable remote management and updating the firmware. In the case of custom DNS settings on the computer that can be restarted in order to empty the DNS cache and is advised to perform a virus scan.

Tuesday, 24 March 2015

Chinese Phishing Sites Doubled To 93,000


With an online population of 649 million people, cyber criminals are increasingly turning to the Chinese market, according to a new report from the Chinese Computer Network Emergency Response Technical Team / Coordination Center (CNCERT / CC). Last year there were observed more than 93,000 phishing sites in China, a doubling from the previous year.

Furthermore, the Chinese authorities discovered 37,000 sites that were adapted, while 40,000 websites were equipped with a backdoor. Nearly 6,000 of the websites with a backdoor were controlled by American IP addresses, reports the Chinese state press agency Xinhua .

Monday, 23 March 2015

Leak In Cisco IP Phones Allows Eavesdropping Possible


Networking giant Cisco warns of vulnerability in the SPA300 and SPA500 IP phones allowing attackers without credentials distance calls can eavesdrop or to gain access to the phone to call then himself. However, an update is not yet available.

Also could be used for a successful attack further attacks, said the advisory . The vulnerability is caused by authentication settings in the default configuration. An attacker would through a specially prepared XML request to send here to abuse a vulnerable device.

Cisco says that in order to exploit this vulnerability, an attacker allowing access to a trusted internal network behind a firewall should be to send the XML request. This requirement would reduce the possibility of a successful attack. Since there is no update available system get the advice to turn XML Execution authentication in the configuration settings.Furthermore, could protect a "solid firewall strategy" systems and can be considered to give only trusted IP addresses access.

Wednesday, 11 March 2015

Malware Explores Home Network Via Router Attack


Researchers have discovered a mysterious instance of malware that attacks the router from infected computers, then bring it home network card and the malware is removed again. It is the Vice Pass Trojan, which occurs at sites like Flash Player update.

When users download the so-called update and open the Trojan is installed. Once active attempts Vice Pass to log in via a list of predefined user names and passwords and a specific range of IP addresses on the router. Then looks malware or other devices are connected to the router, such as iPhones, iPads, LaserJet and Xbox consoles. Once the scan is performed, the malware sends the results back to the attackers and then deletes itself.

Researchers at antivirus company Trend Micro think the Trojan probably "scout" is used for larger campaigns. "The collection of information may be the first step of larger attacks," said analyst Lu Kenney. The collected information could for example be used for cross-site request forgery attacks. "What is the real purpose, this malware shows how important it is to protect devices, even those not obvious target," said Lu. Users will also be advised to change the standard nature credentials of their router.

Friday, 2 January 2015

Spamhaus Sees Increase In Botnet Servers In 2014


The past year were more servers detected that were used by botnets to control infected computers, according to Spamhaus in a new survey published. According to the anti-spam organization comes as no surprise that there are more botnet activity was observed.


Most botnet servers are located at providers with undermanned abuse departments, inadequate abuse policy or who are not able to detect abuse on their network efficiently and fight. The areas used by cyber criminals for their botnet servers are mainly registered with registrars in countries with lax laws and enforcement against cyber crime.



Last year saw Spamhaus 7182 unique IP addresses when a botnet server was hosted. An increase of IP addresses 525 (7.88%) relative to 2013. In 48% of cases, however, it was a hacked web server. The botnet servers were hosted on different network in 1183. Most botnet servers were found in the French OVH, German and Dutch Hetzner Leaseweb. Spamhaus notes that this is just about the raw numbers and the numbers say nothing about how long a botnet server is active, or the provider responds quickly to takedown requests.


When it comes to registrars where cyber criminals domain names for their botnet server register the top 5 consists only of Russian and Chinese registrars. Furthermore, are also American registrars extended in the overview. Regarding the tld who choose the cyber criminals is most likely to domains ending in .com and .ru. Further from the survey shows that most botnet servers are used for controlling banking Trojans, Trojans that are designed to steal money from online bank accounts. 4565 servers (63.5%) were used for this type of malware.