Showing posts with label Java. Show all posts
Showing posts with label Java. Show all posts

Monday, 2 November 2015

Flash Player And Internet Explorer Favorite Cyber Criminal



Internet users who do not update their software run mainly risk of becoming infected with malware if they use Adobe Flash Player and Microsoft Internet Explorer, according to figures from the Russian anti-virus firm Kaspersky Lab. This involves infections via so-called "drive-by downloads."

These cyber criminals use of exploit kits, which automatically infect Internet through unpatched vulnerabilities with malware.Most kits include attacks to exploit vulnerabilities in IE, Flash Player and Silverlight. It is in all of these cases vulnerabilities this year by Adobe and Microsoft were patched. We look at the attacked software, it is mainly Flash Player and Internet Explorer. Attacks on Java even took off. In recent exploit kits there are no exploits for Java included.

Kaspersky Lab also looked at attacks from "web resources" and where those resources are located. 

Sunday, 21 June 2015

New ExploitKit Focuses Almost Entirely On Flash Player


Adobe Flash Player is the favorite target of cyber criminals has become instead of Java was the last few months several times already demonstrated , but a new trend exploitkit makes this clear again. The Beta Exploitkit, also known as Sundown, is a recently launched exploitkit which is still in the testing phase.

Through exploit kits can cyber criminals Internet users who miss security updates easily infect by example code on a compromised website or to hide in an advertisement. This code then sends visitors to the exploitkit. In the case of Sundown trying to infect the exploitkit Internet via six different vulnerabilities with malware.

This is according to researcher JuK of the blog Malware Do not Need Coffee to four vulnerabilities in Adobe Flash Player and two Windows. Researchers Aditya Sood and Rohit Bansal analyzed a different version in which a Windows vulnerability for IE vulnerability had made. Java, which was a favorite target in the past, is missing. A trend that is also seen in many other recent exploit kits.

The Windows leaks Sundown attacks dating back to 2013 and 2014, while the Flash Player vulnerabilities last year and this year. The IE vulnerability that Sood and Bansal saw was discovered in 2012 and patched. For all vulnerabilities are updates available. Yet there are still internet users who do not install these patches and so risk.

However, the Beta Exploitkit is itself not without faults. Sood and Bansal discovered errors in the administrator panel exploitkit, allowing them to log on and managed to retrieve all kinds of information, such as used server domains, users, domains, location of the victims and what kind of browser that surfing. The exploitkit is still in the testing phase, but the researchers expect that the coming months will be used by cyber criminals.

Saturday, 13 June 2015

Microsoft Sees Old Ask Toolbar As Unwanted Software


Microsoft security software sees old versions of the Ask Toolbar, which include the installation of Java is included, henceforth as unwanted software. Late last year, the software giant announced that measures would be taken against toolbars and other programs that change browser settings, unsolicited.

Toolbars for many users is a major source of annoyance. It also happens often that the default search engine users is adjusted and it is very difficult to change back the original engine. In late May Microsoft let them know that it was also customize this software. The new measures would take effect on June 1, and it seems that the software giant has kept his promise.

Old versions of the Ask Toolbar, given the large number of topics on its removal for many users a real plague , is now classified as unwanted software. This allows a user on Slashdot know, taking to an article in the malware encyclopedia indicates Microsoft. According to the description the Ask Toolbar Microsoft considers a "high threat" that can be removed by Windows Defender, Microsoft Security Essentials and Microsoft Safety Scanner.

Since the message on Slashdot the news was taken up by other media, which again for a response from Ask.com and Microsoft seems to have created. Indeed, there is an update posted in the encyclopedia, which now reported that the most recent version of the Ask Toolbar is not considered unwanted software.

Tuesday, 14 April 2015

Apple OS X Designed To Help Against Adware


Apple has taken further steps against adware, reinforced free Mac apps settled in Download and changes among other browser settings.

OS X 10.10.3 should also remove unwanted adware, such as Apple tells in a support document . When browsing suddenly pop-up window and graphics appear with advertising or search engine and homepage has been changed unexpectedly, adware has come to the Mac, says the manufacturer. Some download portals insert the advertising software in the offered there free programs - the user installs this then perhaps unintentionally. Even software such as Oracle's Java brings now Adware for OS X with .

What are the steps to initiate the update opposite already installed Adware, Apple does not execute. Apparently the import of 10.10.3 does not always help but long to sudden commercials, as the company continues to point to a longer instructions to remove certain adware manually.

This Apple recommends that you check the Safari Extensions and delete unknown specimens. For removal of other "Ad-injection software" but deeper trip to the library system of OS X are required - specifically, the Group carries it Down Lite, VSearch, Conduit, trovi, MyBrand Search and Protect on.

Specifically, Apple also addresses the adware Genieo respectively InstallMac, the deep hooks into the system and fades among others own promotional items on visited web pages. A Genieo variant blocked the built in OS X anti-malware tool XProtect since February - but the manufacturer should offer more long versions.10.10.3 OS X also includes a long list of vulnerabilities .

Wednesday, 8 April 2015

Scale Attack Through Infected Google Ads


Last night there was a large-scale attack on Internet via infected Google ads place. Advertisements and the website of Engage Lab, a Bulgarian company that clients advertising space offered by Google, including through DoubleClick, were found to contain malicious code, as discovered the Delft security firm Fox-IT .

The malicious code sent visitors who see the ads were unnoticed through to another website. This website was exploitkit placed that visitors through known vulnerabilities in Adobe Flash Player, Java Oracle and Microsoft Silverlight tried to infect.In case users up-to-date were unsuccessful attack. Users who had forgotten to install the available security updates could become infected with malware.

After about two hours there were no ads found infected through the ad network Engage Lab. To prevent attacks via infected ads advises Fox-IT updating software like Java, Silverlight and Flash Player and the use of a AdBlocker.

Friday, 27 March 2015

Xtube Porn Spreading Malware Via Flash Attack


Visitors to the porn xtube are now warned cyber criminals have hacked the website and use it for distributing malware. Xtube 780 ranked of most visited websites in the United States and would have to deal with 25 million visitors every month.

Unlike other recent attacks are widely used in the case of infectious xtube no ads, but the attackers have malicious code placed directly on the website itself. Something which is possible only if the attackers have access to the website. The code sends users unnoticed through to another website which then tries to put through a known vulnerability in Adobe Flash Player malware on the computer.

It is a vulnerability that already has a security update has been released. Users who have the latest Flash Player version available are therefore not at risk. In case the attack was successfully placed a Trojan horse on the computer. The malware was detected at the time of the attack by 12 of the 57 scanners on VirusTotal, says anti-virus company Malwarebytes .

It is not just porn sites that are victims of these attacks. This week, the Dutch security researcher warned Yonathan Klijnsma that the website nummeriban.nl where users can convert to an IBAN account number, also malicious code was detected. The malicious code sent by visitors to a website that users via known vulnerabilities in Adobe Flash Player, Java and Adobe Reader tried to attack.

Wednesday, 25 March 2015

Oracle Provides Mac Version Of Java Again With "Adware"


Oracle has started with the delivery of the Java installation for Mac with the infamous Ask Toolbar. Also users get back to whether they have their home in Ask.com want to change. In early March showed that Oracle had the setup of Java for Mac bundled with the Ask Toolbar.

The software does this for some time for the Windows version, but it's the first time it does this for the Mac version. The Ask Toolbar is labeled as adware by different parties. The toolbar uses the Ask search engine, which would be full of bad classified ads. Advertisements that are not of the "organic" results would be distinguished in most cases.

There was considerable controversy because of bundling the Ask Toolbar and after a week seemed Oracle thus stopped to be. Several parties indicated they when installing Java to see the toolbar no longer received. Security firm Intego reports that Oracle now controls the location of users first before it is decided to activate the installation of the Ask Toolbar. Thus, French users will not see the toolbar, while US users will be asked if they want to install.

Regardless of the country of the user is always installed the "Sponsors.framework" when installing Java on the Mac, which again to install the Ask Toolbar is responsible. Intego suspects that the Ask Toolbar can be enabled with future updates , without the need for Java to be installed. The framework would say, if it is already installed, can be updated silently.

Saturday, 21 March 2015

Oracle Stops Security Updates For Java 7


Oracle Java users warned that after April no more security updates are offered for Java 7, unless a special agreement is concluded. This runs the risk of a large number of users to sit with an unsupported version, unless they upgrade to Java 8.

In January PaaS provider Jelastic published an overview of the various Java versions that are in use. Then it turns out that 83% of users still using the Java version 7. Java 6 is already installed in 14% of users, while the latest version of Java, Java 8, was found in only 3% of the Java Users. Like Microsoft Windows XP organizations the opportunity to continue receiving updates while supporting stopped for consumers, Oracle also does this.

"As described in the Oracle JDK Support roadmap, Oracle will after April 2015 no updates for Java SE7 to publish public download site. Customers who need access to critical bug fixes and security updates as well as general support for Java SE 7 or older versions may have a long-term contract support for close, " said the software giant on its own website.

Monday, 16 March 2015

Oracle Removes "Adware" From Java Installation On Mac


Recently there was great controversy when it became known that Oracle is the Ask Toolbar was bundled with the installation of Java for Mac OS X, but now the company seems to have stopped here quietly along. The Ask Toolbar is labeled as "adware" by various parties.

The toolbar uses the Ask search engine, which would be full of bad classified ads. Advertisements that are not of the "organic" results would be distinguished in most cases. In addition to installing the toolbar were Mac users with the Java installation also asked whether they wanted to change their home page in Ask.com. Both options were selected by default.

Oracle Java installer now delivers without Ask Toolbar this is now confirmed by both The Safe Mac as security Intego . The virus of the company blocked the toolbar. Report Although various parties that the Ask Toolbar is no longer installed, Oracle late own site know that the toolbar is also installed on Mac OS X. However, it may be that the website has not yet been adjusted.

Friday, 6 March 2015

Oracle Adds "Adware" To Java Installation On Mac


For years, the installer for Java on Windows bundled with additional software, such as the Ask Toolbar, but now Oracle applies this practice also allows for the Java installer on Mac OS X. The Ask Toolbar is labeled by various parties as "adware." Under Windows Follower Ed Bott shows the Ask search engine bad results that are filled with advertisements that do not "organic" results can be distinguished in most cases.

In the case of Mac OS X is about 8 Java Update 40 whereby the Ask Toolbar is installed and the home page is changed. This version came out the week. The option to install the Ask Toolbar and change home is checked by default. Anyone who does not pay attention during installation has also a toolbar at. Bott discovered the new bundle of Oracle policy. He also discovered that the Ask developers in the Chrome Web Store does not use their own name, but "chromewebstore12".

Developers do when two other apps the same, allowing users might think that it is official Chrome apps. Oracle website now also makes mention that cooperation with certain parties that offer different products, but provides no further explanation or lets you know what people can do to remove Ask their system. Oracle's decision to join the toolbar follows the Lenovo Superfish debacle. Lenovo did this knowing that in the future cleaner machines will offer without much preinstalled software.

Sunday, 15 February 2015

Prize For Hacking Chrome During Pwn2Own


During a hacker contest next month in Vancouver held hackers and researchers can win the grand prize by hacking Google Chrome. Who a vulnerability in Google's browser on Windows 8.1 knows how to find can earn $ 75,000.

This is more than for leaks is offered in other browsers. The game in question is the annual Pwn2Own contest, which takes place during the CanSecWest conference. Every year, researchers and hackers at the event to test the security of browsers.After the prize for Google Chrome follows Internet Explore 11 where a reward of $ 65,000 to be offered. Apple Safari on Mac OS X Yosemite follows with $ 50,000 in the third. Finally provides a successful hack of Mozilla Firefox at $ 30,000.

Besides the four browsers will be tested also the security of Adobe Reader and Adobe Flash Player. A successful attack on both programs make $ 60,000 on. This year, the difficulty for participants is much higher than previous years because the exploits that should be developed with Microsoft's free security tool EMET works.

The Enhanced Mitigation Experience Toolkit (EMET) is precisely designed to neutralize the effect of exploits. As a result, researchers now take two hurdles. Researchers who through their exploits on a Windows computer code with SYSTEM privileges can perform get an extra $ 25,000 reward. In addition, Google will in the case of a Chrome hack pay an additional reward of $ 10,000. Pwn2Own will take place on 18th and 19th March.

Wednesday, 21 January 2015

Oracle Java SSL 3.0 Switches Off


To protect users from attack Java, Oracle SSL 3.0 disabled in the software. The measure is part of the security update that appeared Tuesday. "This Critical Patch Update disables the standard use of SSL 3.0. SSL 3.0 will be considered an obsolete protocol and this situation is exacerbated by the POODLE-leak. As a result, this protocol widely attacked by malicious hackers," says Eric Maurice Oracle.

The POODLE-vulnerability in SSL 3.0 ensures that an attacker who between a user and the Internet to know places, for example in an open Wi-Fi network, can steal information from encrypted connections, such as session cookies. Maurice gives organizations advised to discontinue use of all SSL versions, as it is no longer the safe communication between systems can be trusted.

Also Oracle customers have to change their code and switch to a more secure protocol such as TLS 1.2. Oracle employee further notes that Oracle in the future SSL in all Oracle software will turn off. Besides disabling SSL 3.0 update also fixes 19 vulnerabilities in Java, which in the worst case, an attacker can give full control over the system.

Thursday, 9 October 2014

Botnet of 500,000 computers - Qakbot Malware

The Attack Chain


Researchers have identified a botnet of 500,000 computers discovered that 52% of machinery exists that run on Windows XP. A comparatively very high percentage, since it no longer supported by Microsoft operating system worldwide share of between 14% and 24%.

The computers have been infected with qbot via known vulnerabilities in Adobe Flash Player, Java, Adobe Reader and Internet Explorer, also known as Qakbot. On infected computers qbot steals all kinds of data for Internet banking. Researchers from Proofpoint found that the login data of 800,000 accounts online banking were intercepted. In 59% of these cases involved one of the five largest American banks.

Further figures ( PDF ) show that the malware on the American Internet has provided, since 75% of the infected computers over an American IP address available. especially In addition to steal login details infected machines are also offered for other cybercriminals. Paid as proxy These criminals can the infected computers as a springboard for other attacks use or for storage or transportation of stolen data.

Following are the steps How It works:

1. Infecting Legitimate Websites

Infecting Legitimate Websites

2. Filtering Targets- Traffic Distribution Systems.

Filtering Targets- Traffic Distribution Systems

3. Getting Into The User's Machines -Exploits

Getting Into The User's Machines -Exploits

4. Stealing User Banking Credentials - Malware

Stealing User Banking Credentials - Malware






Friday, 11 April 2014

The Ins and Outs of ransomware


Malware researcher Bart Blaze has published an extensive article about ransomware on his blog. In the article he interviews a number of anti-malware experts who give their opinion on the current trends and the evolution of ransomware.
The following experts shared their insights:
  • Malware researcher Malekal
  • Adam Kujawa - Malwarebytes Head of Malware Intelligence
  • Fabio Assolini - Kaspersky Senior Security Researcher
  • Fabian Wosar - Emsisoft GmbH Administration / Development
  • Hendrik Adrian - MalwareMustDie Security Research Group

Experts

The experts will discuss, among other things: their first acquaintance with ransomware, the psychological aspect of ransomware, how ransomware spreads, how effective it is in practice, and last but not least, how can one protect against this specific type of malware.
The experts agree on one thing: the first versions of ransomware were quite primitive but very effective. Over the years it has evolved greatly ransomware and cybercriminals are earning millions of dollars with it. The reason that this type of malware is so fast becoming popular is the fact that ransomware savings than "rogueware" (fake antivirus software), and in particular the variants encrypt files, such as Crypto Locker more money.
"Ransomware as Crypto Locker is currently more efficient than the FBI called Ransomware because almost everyone knows this form now. When the FBI was everyone thought it was legitimate, variant first spotted" explains Adam Kujawa out. "I can not give you exact percentages because I do not have it, but the golden rule is that when a particular attack vector of attack strategy is reused, meaning that the tactic is effective and therefore works. We now identify malware like Prison Locker (or Power Locker ) due to the success of Crypto Locker, just as we saw hundreds of variants and families of the FBI Ransomware in 2012. "

Recommendations

The article also contains several recommendations for both end users and companies. How can one protect against ransomware and what can one do when a computer is infected.

End users

For end users, it comes down to the following: keep all your software up to date, install an antivirus program, remove unused software (eg Java), install security add-ons such as NoScript in the browser (and update it also ), no download applications via spam or suspicious or unknown websites and make backups (and disconnect the external drive after taking the backup).

Companies

For companies, the recommendations are as follows: Use strong passwords for servers, RDP switch off if possible, use a spam filter, using group policies, limit the rights of users, instruct your users and also applies here: make backups.

Never pay

Victims of ransomware should certainly never proceed to payment. There is no guarantee that the cyber criminals the files or accessing the computer will recover. Maybe you even more vulnerable to a new attack, the cyber criminals will know after all that you will pay. By following the recommendations, however, you reduce the chance of becoming a victim already drastically.
Do you want more information, detailed advice and tips, then read the article at Blaze's Security Blog.