Showing posts with label Internet Storm Center. Show all posts
Showing posts with label Internet Storm Center. Show all posts

Tuesday, 10 October 2017

ISC Warns Usb Cable With Built-In Sim Card


The Internet Storm Center (ISC) warns of usb cables that are sold and have a built-in sim card, mobile phone and microphone. Attackers could perform attacks or stolen data through such cables, according to Johannes Ullrich of the ISC.

For example, the $ 30-usb usb cable responds to text messages and can send those GPS coordinates. It is also possible to activate and listen to the microphone via a text message. "The main risk is to leave systems (and cables) left unattended in places with some public access," Ullrich notes. This applies, for example, to systems in hotel rooms or classrooms.

Users therefore get the advice to mark their cables so that they can not be replaced by other cables. In addition, the cables must be fastened. In conclusion, Ullrich states that the "usb spy cable" in question is easy to recognize when users know what to look for. "But I'm sure they can make a smaller cable and maybe a version that's a bit more expensive and not so easy to show the sim card."

Sunday, 20 September 2015

Tip: Adobe Reader Lets You Open Any Embedded Files




In recent weeks, cyber criminals several times PDF files sent which was hiding a malicious Word document. Once users opened the PDF file they were asked if they wanted to open the embedded Word document.

The Word document contains another macro that installed malware on the computer. The macro is executed only if users set it, but in practice this is an effective method of attack. Users and administrators can easily avoid, however, Adobe Reader opens these embedded documents, says Didier Stevens, handler at the Internet Storm Center. Through the Trust Manager, available via the settings of the PDF reader option can be switched off, as Stevens Also in this video shows.

Wednesday, 20 May 2015

Safari Flaw Allows Malware And Phishing Attacks Possible



A vulnerability in Safari allows you to execute malware and phishing attacks. The vulnerability can any URL displayed in the address bar, while another site is loaded. The vulnerability was revealed by the UK security Deusen.

As evidence it put a proof-of-concept online. This test looks like the website of the Daily Mail is open, while this is not so."While this proof-of-concept is not perfect, it can be certainly improved and is then very easy to use for phishing attacks," said Manuel Humberto Santander Pelaez of the Internet Storm Center . The attack may not work if cookies only from the currently open website are allowed.

Saturday, 18 April 2015

Alarmfase Internet Increased Due To Leak In HTTP.sys


The Internet Storm Center (ISC) has raised the alert for internet to color code yellow, now that attacks have been observed on a vulnerability in Windows which on Tuesday published a patch. Through the vulnerability in the HTTP.sys file to send attacker at worst systems take over completely by only a single HTTP request.

The attacks, which now has the ISC observed , however, cause a Denial of Service. Something that is still a problem, since the vulnerability especially playing at web servers. According to an estimate by Netcraft Internet company would be 70 million websites run risk. A denial of service of a web server means that a web application or website temporarily not working or is accessible.

The attackers who are behind the attacks now perform "wide web" scans. In addition to a Denial of Service, an attacker through the leak also can steal information systems. In addition to installing the patch can also be chosen to "kernel caching" off, but this may adversely affect the performance of the server.

Color codes

In total, the ISC uses four color codes, green is the lowest level, followed by yellow, orange and red color code as the highest level. Yellow means that there is a new threat is followed whose impact on the infrastructure remains unknown or bad.However, the local impact can be pretty. Users and administrators also are advised to immediately install the available updates. Red color code only applies to situations where a large part of the internet no longer works. Early this year, the color code has also been increased to yellow, then because of a vulnerability in Adobe Flash Player.

Tuesday, 10 March 2015

Attack With Malicious Macros In XML Files


Cyber ​​criminals use to spread again some time macros in documents to malware, but now there are also attacks observed with XML files were deployed. Macros allow users to automate various tasks and were used years back on a large scale by malware. Because of the security risks, Microsoft decided therefore to block macros by default in Office.

A year ago, appeared more and more .doc and .xls documents containing macros were hidden. The documents users were summoned to enable macros. Once the user the macro switch is downloaded and installed malware instance in the background. One tactic that seems to be successful, because the beginning of this year, Microsoft already gave a warning off for macro malware. Now warns security firm Trustwave for a new attack in which malicious macros are used via XML files.

XML stands for Extensible Markup Language and XML-based formats have become the standard for various office tools, including Microsoft Office. When a user loads the XML file opens Office and will appear again indicating that macros must be enabled. After switching a malicious script is executed that downloads and installs a Trojan horse. It is the Dridex banking Trojan, malware specifically designed to steal money from online bank accounts. The Internet Storm Center (ISC) gives organizations advice how this kind of XML files can be filtered.

Wednesday, 7 January 2015

ISC: Another Port For SSH Is Not Meaningless



Who SSH (Secure Shell) to log on to remote computers and servers will benefit from it to change the default port 22, as late as a handler of the Internet Storm Center (ISC) know. SSH is a popular protocol for managing computers. Standard protocol listens on port 22.

This will also be a lot of scans and attacks on this port. At present, there Reddit , in response to this article , a discussion or change the default port is wise. One of the criticisms is that " security through obscurity "is not a security measure, but only one way to slow an attacker and therefore offers little value. "While it is true that it is difficult to stop a determined attacker to cause you provide, any measure that prevents arbitrary script kiddies and scanners to your SSH look not entirely meaningless," says ISC handler Rick Wanner.

Wanner says more than 15 years SSH on a non-standard port to run, such as port 52222. "Of course this is not the only security measure that I use. I patch daily use hosts.allow where possible, keys and passphrases instead passwords and use Deny Hosts ", he tells. ISC handler notes that he does not use port 22 because of "security through obscurity" benefits, but because it eliminates all noise on port 22.

Port 22 is a favorite target of brute force attacks and port scans rising every year. These activities cause Wanner as much noise in the logs. "Why would you tolerate it if it is not needed?", He notes. The default port change he would attack traffic are much diminished that he occasionally his defense test to see if it still works.