Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Monday, 25 May 2015

Stallman: Windows And Mac OS Are Malware


Much of the software in circulation today is malware. It are programs that treat their users bad, says Richard Stallman, which is Windows, Mac OS and iOS gives specific examples. Stallman is the creator of the GNU operating system.

He uses the definition of malware not only for viruses and Trojans, but for programs that users are treated badly. Stallman Something that has become commonplace, writes in a column for The Guardian. "There are so many cases of proprietary malware reported that we should consider any closed program as suspicious and dangerous." Some of these programs closed spy on users, while others are made ​​to chain users through DRM solutions. Other programs impose censorship on weather and some software is specially designed to sabotage users, Stallman continues.

As an example he mentions malware operating systems like Windows, Mac OS and iOS. This is software that users chains, spies and censors. An Internet that closed out all kinds of software solutions exist is not to be trusted. Stallman calls therefore users to take action. So should software and Web services that spy on users or follow avoided.

It should be collectively invested in free solutions that users do not follow the web. Thirdly legislation must come through democratic ways which prohibits several "malware practices." It is also necessary that there be a democracy, says Stallman.Something which according to him is not the case with trade agreements such as TTP and TTIP those companies actually offer the ability to suppress democracy.

Thursday, 30 April 2015

Microsoft Is Addressing Misleading Advertising


According to Microsoft, there is an increase in the number of misleading advertisements on the Internet, allowing users with malware or unwanted software come into contact. Reason for the software giant to tackle this kind of advertising. The deliberately misleading ads trick users usually have to do something whose consequences are not immediately obvious, such as visiting an infected website or downloading a program that has a "negative impact" on the Internet.

Therefore, Microsoft has a number of requirements established where ads from June 1, 2015 must meet. So ads can not be fooled, they should be distinguished from the website, they may not contain malicious code and may not lead to downloading files. In the event ads do not meet these requirements, Internet Explorer will soon give a warning and the website which can be seen blocking the ads.

Tuesday, 20 January 2015

According To Researchers Avoid Chrome And Skype


Security researchers who work with sensitive information can better avoid Google Chrome and Skype, as recommended two researchers. According to Dani Creus and Vicente Diaz Kaspersky Lab happens that investigators are approached by criminal gangs and intelligence.

It also happens that researchers be bugged or that their devices while traveling is compromised. Operational security (OPSEC) is therefore essential, say Creus and Diaz. The main rule here is to remain silent. "If you do not have to say do not do anything. If you need to communicate with someone do it safely so you're not the contents of your message in danger and if possible also leave no metadata."

In the case of communication should be used such as email, instant messaging and phone the researchers several tips. So can only chat services that are trusted Off-the-Record (OTR) offering and Skype should never be used for discussing sensitive issues. Also, wherever possible, disposable phones are used. Furthermore, researchers are advised to use TrueCrypt to encrypt data.

To the Internet, according Creus and Diaz wise to use an 'air gap', which is created by an anonymous obtained 3G / 4G modem connection. Also have no cookies in the browser must be accepted and the execution of JavaScript can be prevented. Furthermore, users can not log on to an account and use Google Chrome is not recommended.

"OPSEC must be quickly part of the daily routine of security researchers," note the two researchers. "Given the kind of operation that is detected, and the parties concerned, the lack of knowledge and discipline in this area can have devastating consequences for researchers who do their work," concludes the pair. Earlier also gave a researcher called The Grugq sorts of tips for improving operational safety.

Friday, 26 December 2014

Google disables 39,000 WordPress sites for malware



Google has already put more than 39,000 Wordpress websites on a blacklist because they are infected with malware. Attackers use a leak in the WordPress Slider Revolution Premium plug-in attempts to infect to get access to the sites and then add malicious code that visitors with malware. The leak in the plug-in has long been known, and a patch is available. Many sites that have not been installed.

According to security firm Sucuri involves three different campaigns where the SoakSoak campaign is responsible for most infections. According to Google, the malware of this website to over 17,000 detected domains. Through the wpcache blogger campaign are spacious 12,000 sites have come to the blacklist of the search giant. Finally, there is an IP address that the attackers and code to 8500 was found websites.

Once Internet users to visit these Web sites via eg Google Chrome or Firefox they'll see a warning. Sucuri Commission on the basis of own research that more than 50,000 websites have been infected, but they have not all been indexed by Google.

Affected websites are advised to do a "complete cleaning" of the website, since installing WordPress alone is not enough again. The attackers would in fact leave too many backdoors. Additionally WordPress administrators are urged to update their plugins. With over 74 million websites WordPress is the most popular online content management system.

Tuesday, 23 December 2014

The Tor Network Is Under Attack



Tor users in the coming days may have problems with the use of its services. As representatives warn Tor, detected an attempt to take control of specialized servers, referred to as directory Authorities that support this network. They did not disclose what the hacker group or organization is behind this attack. "We have taken steps to ensure the safety of users of our services. Tor already uses redundancy mechanisms that will keep their anonymity, even if the planned attack will be executed. Tor is safe "provides" arma "on the blog associated with the project . "Arma" is a nickname associated with the project leader Roger Dingledine.

The Tor network packets are exchanged directly between the source and the receiver, and pass through several randomly selected relay servers, which mask the path of the flow of information and thus allow the anonymity of the users of the network. "Even if the attacker take control of the majority of servers, they will not be able to force the Tor client software to resign from the other relays communication and as a result will still be safe and anonymous "provides" arma ".

If you use Tor - you may want to note down and temporarily avoid these affected mirrors in a below pic

Affected Mirrors

Currently, Tor uses 9 servers to manage traffic in the network. They are located in the USA and Europe. At the moment (Monday 22/12/2014) there was no information about the planned attack on Tor. Representatives of the project promise that all information on the current situation will be immediately posted on the blog design . -providing anonymity on the Internet.

Tor network is used by users who want to avoid censorship and track their content published by the secret services, especially in non-democratic countries. Representatives say the Tor project, the network is also used by millions of people who want to ensure the security of the communication itself when connecting to the Internet in public areas. Unfortunately, it is also used by criminals, such as drug trafficking network Silk Road. It was closed down in October 2013 years by the US police, but there is another version - Silk Road 2.0. Despite these controversies, Tor network is one of the symbols of freedom and privacy of Internet communication and any attempt to attack this system probably will lead to big stir among users global network.

Sunday, 21 December 2014

Critical vulnerabilities Found in Network Time Protocol (NTP)



Researchers at Google have critical vulnerabilities in the Network Time Protocol (NTP) allowing attackers discovered on systems that use NTP can execute code. NTP is a protocol that allows systems to synchronize the time for different services and applications.

It is used among other things on a large scale industrial systems. Neel Mehta and Stephen Roettger of the Google Security Team discovered several vulnerabilities in the protocol. In the worst case, an attacker by sending a single packet to cause a buffer overflow, and it is now possible to carry out on the attacked system code with the rights of the NAP-process. This vulnerability is present in all versions of NTP NTP-4.2.8.

Before warn the the Industrial Control Systems Cyber ​​Emergency Response Team (ICS-CERT) of the US Government, the US Computer Emergency Readiness Team ( US-CERT ) and the CERT Coordination Center ( CERT-CC ) at Carnegie Mellon University. Administrators also are advised to upgrade to NTP 4.2.8. Furthermore, this version fixes vulnerabilities in the random number generator allow an attacker to retrieve certain information. Exploits that make the leak abuse have been found on the Internet, according to the ICS-CERT

Friday, 12 December 2014

OphionLocker Ransomware Forget To Remove Files Thoroughly


Researchers have discovered a new ransomware variant that uses strong encryption to encrypt files, but because the original file could not be thoroughly erased victims recover their data without having to pay the ransom.


OphionLocker Message

OphionLocker, such as the ransomware by Trojan7Malware is called, spreads via hacked websites and makes use of known vulnerabilities that are not by Internet users are patched to infect their computer. Once active makes ransomware a unique hardware identifier to, based on the serial number of the first hard disk, the serial number of the motherboard and other information.

Asking For Hardware ID - Tor Link

Then it will create a Tor website link to check the specific hardware ID is already encrypted. Hereafter OphionLocker looking for all kinds of files. However it is only for files with file extensions sought in lowercase. A file as photo.jpg will encrypt the ransomware while foto.jpg is about beaten.

Encryption

To encrypt used OphionLocker elliptic-curve encryption (ECC). As far as known, it is only the second ransomware that uses this encryption method. Most ransomware uses a combination of AES and RSA encryption to encrypt the files of victims. Here, the server generates a key pair, RSA public and private, for RSA. The private key remains on the server, while the public key is sent to the ransomware. In OphionLocker is the public key already in the malware. As a result, can also on computers which are not encrypted are files connected to the Internet.

The malware after encryption displays a message indicating the amount of 1 bitcoin is asked, what with the current exchange rate is 290 euros. Victims, however, do not have to pay to get their files, reports the forum Bleeping Computer . The ransomware shows the original of the files not erase the encrypted safe and also allows the volume shadow copies alone. As a result, it is possible to access the files through a program as ShadowExplorer to recover.

Wednesday, 26 November 2014

DroidJack RAT Android App Malware



Software developers who first made ​​apps for Android now versatile malware developed for the platform that it include possible to eavesdrop on conversations, intercept WhatsApp messages, looking into the camera or the microphone to listen to the environment. It is a remote administration tool (RAT) called DroidJack.

DroidJack website homepage


In a report issued late last year on Facebook developers claimed that they were novice entrepreneurs. They published at the same time on Google Play app that allows to control a remote computer. Symantec had the legitimate app developers with little success and they then directed their attention to the development of Android malware. DroidJack is now openly available over the internet. The malware will cost $ 210, which buyers also get lifetime support.

In order to carry out the RAT are no root rights are required. Once activated, it is possible to steal files, read WhatsApp messages, calls and eavesdrop on the microphone, see the address book, to operate the camera and the last GPS location to retrieve the device and Google Maps to display. The malware is equipped with a disclaimer, but they come before a judge not get away with, says analyst Peter Coogan.

Some of the Features of DroidJack:
  • No root access required 
  • Bind the DroidJack server APK with any other game or app 
  • Install any APK and update server 
  • Copy files from device to computer 
  • View all messages on the device 
  • Listen to call conversations made on the device 
  • List all the contacts on the device 
  • Listen live or record audio from the device's microphone 
  • Gain control of the camera on the device 
  • Get IMEI number, Wi-Fi MAC address, and cellphone carrier details 
  • Get the device’s last GPS location check in and show it in Google Maps

There are many more features which the App offers.

Disclaimer:

Disclaimer used in DroidJack marketing

Wednesday, 30 April 2014

Russian Internet giant offers email service without a password

The Russian Internet giant Mail.Ru has a new e-mail service launched where users have no password.
My.com such as the e-mail service is called, is in fact only accessible via an app on the smartphone.Once users register they will receive a unique SMS code.
This registration code is used once, after which users never have to enter a password. The phone is namely as authentication."And you always have with you", so let the developers know. Our own research would show that often their email on their smartphone then check users on their desktop.
Furthermore, all sent and received e-mails should be encrypted, but specific details are not given. In addition, users of the free e-mail service to get 150 gigabytes of data storage, ten times as much as in the case of Gmail. 
My.com is only available for iOS and Android users. The developers say that they keep an eye on Windows Phone, but due to limited resources and expertise will now focus on iOS and Android.

Spammers bypass spam filters with non-Latin characters

Spammers use a variety of ways, such as images and ASCII text, to bypass spam filters and get. As phishing emails and other messages delivered to the mailbox of Internet users but recently the use of non-Latin characters, a trend to be.
This allows anti-virus firm Kaspersky Lab. It concerns in particular Italian phishing emails, which spammers use certain non-Latin characters to replace. Latin characters This is possible thanks to the UTF-8 encoding system, in which characters from different writing systems can be combined in the same e-mails said analyst Maria Rubinstein. In the image below, several of the non-Latin characters underlined in red.

Monday, 28 April 2014

XP users should avoid Internet Explorer


Windows XP users should not use Internet Explorer now there is a new leak was discovered in the browser. That suggests Mikko Hypponen of the Finnish F-Secure. This weekend it was announced that a new leak in IE is present that is deployed. Limited extent in targeted attacks
The vulnerability in Internet Explorer 6 to 11 present, although the attacks were directed only. Against users of IE9, IE10 and IE11 Since Microsoft no longer supports Windows XP, except for organizations with an extended service contract available, run IE users on the platform risk because there is no patch will be released which fixes the leak more.
Symantec also recommends that XP users to use another browser, but notes that this is a temporary measure until Microsoft has released a patch. A notable addition, because most XP users will receive. No more updates For XP users that IE can not do without the use of Microsoft's free Enhanced Mitigation Experience Toolkit (EMET) 4.1 option.
This program adds additional security to the system and also works on Windows XP. The tool prevents attackers newly discovered IE vulnerability to exploit, according to Symantec. Besides XP users also users of other Windows versions can protect themselves through EMET against the vulnerability.

Monday, 24 March 2014

White Hat Security company launches "secure browser" on Internet


An American security company claims to have the "most secure browser" launched on the Internet that users must protect. Against both malware and parties who want to violate the privacy Aviator, such as the browser is called, was published last year, the Mac version and now there is also a Windows version.

Aviator has been developed by white hat security and based on Chromium, the open-source browser that is used. Google Chrome The reason it was chosen Chromium is that it has several unique security features, such as a sandbox. White Hat found that Chromium is not safe enough and made ​​an adapted version with more security and privacy settings.

"Google and Microsoft make a lot of money on online ads. Unfortunately, very intrusive online advertising, because you basically follow anywhere on the Internet. Even Mozilla receives most of the revenue through advertisements. Implementing truly effective security and privacy could adversely for their business operations, " said the security company

For example, the default search engine DuckDuckGo instead of Google and integrates the browser Disconnect. An extension that ads and tracking on the Internet blocking. In addition, the browsing history, cache, cookies, auto-complete, and local storage after restarting the browser removed. Standard third party cookies are blocked, plug-ins require an additional mouse to work state Do-Not-Track is enabled by default and minimum data is sent to Google.

Earnings
Although there is little advertising for the Mac version was made, was downloaded thousands of times in recent months. The browser is free to download, but still is underway on a revenue model, allows product management director Robert Hansen know . He gives the guarantee that no money will be earned on the information provided by users, as do many other browsers.
Current users of the browser, however, would be no need to worry, because the browser can always use for free. "Once we have determined how we can make money on new users will only have to pay for a license." In the future, other operating systems are supported. Alongside Mac and Windows

Sunday, 23 March 2014

India is fighting botnets computers with cleaning center


The Indian government is planning to establish that engages in the fight against botnets. A special "cleaning center" In recent years, the number of Indian computers part of a botnet has exploded. In 2007 it went to some 26,000 systems.
In the first half of 2013 the number of bots, however, rose to 4.2 million systems . The increase is explained by the growing Internet usage in India. In addition, it is not just computers that become infected, more and more smart phones would become part of a botnet. Therefore, the government now wants to start a center to end the infection must, along with internet providers said the Deccan Herald.

Tuesday, 18 March 2014

Intruders attacked Google public DNS server


Traffic to the free DNS service provided by Google last Saturday was hijacked 22 minutes so that the commands and traffic to Google's servers temporarily came out at a Venezuelan network, as claimed BGPmon, a company that monitors network and internet traffic.
Internet, the DNS servers of their own provider replaced by that of Google. The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses. By setting up Google's the DNS servers (8.8.4.4 and 8.8.8.8) Internet users do not ask their provider where the IP address of a given domain name is found, but at Google.

Last Saturday was the traffic to the DNS servers of Google redirected to a network in Venezuela 22 minutes. According BGPmon there was a BGP (Border Gateway Protocol) hijacking. Had implications for both the transmission networks in Venezuela and Brazil. How the hijacking could occur late BGPmon not know, but the possibility of abuse was enormous, the company said on Twitter .