Showing posts with label Javascript. Show all posts
Showing posts with label Javascript. Show all posts

Friday, 6 November 2015

Extra Secure Tor Browser For Linux Launched



The creators of Tor Browser, the software for browsing through the Tor network, have released a security-enhanced version of Linux. It is the first time that the Tor Project offers a "hardened" version of Tor Browser. This browser includes a customized version of Firefox and Tor software.

The extra secure Tor Browser is based on the Tor Browser Alpha series. These are test versions of the browser that appear in the final versions. In addition, extra protection is added which should offer protection against memory exploits. For this are both the Tor software, and Firefox version Address Sanitizer compiled. This should give users a safer Tor Browser, especially if JavaScript is partially or completely disabled. It also helps to find problems earlier and to remedy them in the alpha and stable versions.

The additional security does have several disadvantages. Thus, this version is slower, consumes more memory and is slightly larger than the normal version. In addition, the added security of Address Sanitizer not perfect. An attacker who successfully back halls which it is practiced can still via JavaScript certain types of attack vulnerabilities. To date, the high-security Tor Browser only for Linux available, but is being given to versions for Mac OS X and Windows.

Tor Browser lets Internet users hide their IP address and visit censored websites. Every day, over two million people from all over the world using the Tor network, such as activists, people in totalitarian regimes and Internet users who value their privacy. The software is also used by criminals. Two years ago, users of legacy Tor Browser still the target of an attack allegedly by the FBI conducted. The attack users of the real IP address could be traced. To avoid Tor Browser Users with outdated versions meanwhile continue surfing is an automatic updater added to the browser.

Tuesday, 8 September 2015

Security Experts Swear By 20-Year-Old Mail Client Mutt


Regular Internet users are advised to use the latest software, but in the case of e-mail clients swear some security experts at the 20-year-old Mutt. Mutt is a small text-based mail client for Unix systems.The latest stable release dated June 9, 2007, although there last week released a new preview version.

Mutt is characterized by its simplicity. The software does not support HTML or emails with JavaScript. It is also for this reason that security for Mutt choose. "Simplicity is security," says Marek Tuszynski of the Tactical Technology Collective in front of Vice Magazine. Tools that run from the command line are characterized by a simpler design, fewer lines of code and the absence of vulnerable code such as Java or Flash. Therefore these types of programs will generally contain fewer bugs and be more stable.

Security researcher Christopher Soghoian says that he does not want his email client also contains the rendering engine of a web browser or JavaScript can handle. "The smaller the attack surface, the better," he tells. Mutt consists of "only" 100,000 lines code. Much less than the 14 million lines of Firefox and the 17.4 million of Chromium, the open source browser, which is the basis for Google Chrome. Due to the spartan look and feel is to use command line tools like Mutt mostly limited to technical users, even if they offer more safety than the programs in which the masses participate.

Wednesday, 2 September 2015

UPnP Routers Lets You Customize Firewall Attacker



The Universal Plug and Play (UPnP) protocol to make it easier for devices to communicate with each other and connect, but an unknown number of routers, the security is not well regulated, so an attacker can open quietly ports in the firewall or access to the router can get.

Before that warns the CERT Coordination Center (CERT / CC) at Carnegie Mellon University. The UPnP protocol was originally developed for private networks and uses standard therefore no authentication. Later it was decided to draw up a UPnP security standard set yet, but this support is very limited. Because of the lack of security could allow an attacker with access to the private network via UPnP access to the router and to prepare for open ports or services that enable the network to be attacked further.

Although the UPnP problems that the CERT / CC warns alone can be attacked via private networks, it is also possible from the internet here to access it. Via a dedicated website, an attacker, with Chrome and Firefox users who have enabled JavaScript, that any UPnP requests sent to the firewall and thus the network further attacks. The "Filet-O-Firewall"vulnerability has already been demonstrated in early August, but now the CERT / CC decided to issue a warning.

As a solution, users advised to not open unknown links, UPnP off, implement the latest UPnP standards or to the UPnP control arbitrary URL, so that can not be guessed by an attacker. Which models and manufacturers are vulnerable is unknown, but according to the discoverer of the problem involves a "vendor independent vulnerability".

Thursday, 6 August 2015

Developer: Mozilla Threaten Windows Users


Since the launch of Thunderbird 38 Mozilla e-mail client of the Lightning extension provided, but how the extension is implemented is a security risk for Windows users. The German software developer Stefan Kanthak even calls it a "security nightmare".

Lightning provides Thunderbird with an agenda. The extension is enabled by default, although users can turn off or Lightning.Mozilla install the extension in the profile of users and not in the Program Files directory. Mozilla thus violating the mandatory development guidelines for Windows, according Kanthak. It also introduces a security risk.

Applications in the Program Files directory can only be changed by users with appropriate privileges. That does not apply to files in the AppData directory. It is in this directory where the Thunderbird profile of users is stored and the Lightning extension is located. "This is a fundamental vulnerability in Mozilla's extensions and a security nightmare," writes Kanthak the Buggtraq mailing list .

According to the developer, users perform for safety reasons no code in their user profile. That does not apply to Lightning, which is being carried out from here. An attacker with access to the system can therefore replace the DLL files and JavaScript of the extension. Kanthak Mozilla advises to turn off local installation of extensions in Mozilla products and only global installations to allow extensions.

Friday, 17 July 2015

IPhone Users Target Fraudulent Crash Message



Owners of an iPhone are still the target of popups fraudulent crash reports and scammers have already moved their operations to the UK. The last few months, especially American iOS users got to see the message on their device.

Meanwhile, there are also reports that British users see the messages, so let the Daily Mail know. The pop-ups using JavaScript, so it is impossible to close the browser in the normal way. According to the report in the pop-up iOS crashed and should be contacted directly with the "support staff." The telephone number of scammers who argue that there needs to be paid to fix it. It is a sum of 43 euros to British victims must deal and 73 euro prompted to Americans.

In addition, the scammers ask for the credit card information of their victims. On the Apple forum in recent months dozens of topics and responses to find people who report to you got . Users who have to deal with the pop-up to close Safari by tapping twice on the home button and then clear the browser history, as Apple on this page explains. What kind of websites users come into contact with the pop-ups is unknown.

Saturday, 23 May 2015

CryptoWall-Ransomware Spreading Through SVG Files


Cyber ​​criminals have found a new way to distribute ransomware, namely the use of SVG files, so says security firm AppRiver. Scalable Vector Graphics (SVG) is a graphics format that supports interactive features and animations.

Thus, it is possible to add scripts to an SVG image. The now discovered attack starts with an e-mail claiming to contain a resume. It is a ZIP file that contains an SVG file again. At the SVG is a piece of JavaScript added again downloads a ZIP file. This .zip file contains CryptoWall-ransomware. It is an EXE file that the user has to extract and open. Once opened encrypts CryptoWall kinds of files and then ask hundreds of dollars ransom to decrypt them.

Friday, 8 May 2015

Australia Warns Of CVs Ransomware

The Australian government has warned companies to resumes that are currently scattered through e-mail and try to infect computers with ransomware. The e-mail suggests someone and says that he has attached his job. It is a zip file that contains a JavaScript file again. Once this .js file is opened, the computer becomes CryptoWall-ransomware infected.

It is the same attack in the April 21 news came. The Stay Smart Online campaign by the Australian government suggests that the attack focuses on Australian companies and a new campaign is active since last week. CryptoWall encrypts files on the computer and then asks for a ransom here. The Australian government warns that many victims recover their files if they pay the ransom, but there is no guarantee, since users have to deal with criminals. "Prevention is therefore the best medicine for ransomware and other malware attacks," the campaign.

Monday, 27 April 2015

Malicious Word Document Hidden In A PDF File


Frequently happens that attackers use DOC and PDF files to infect internet users with malware, but recently a researcher found a PDF file called "Sales Invoice" that contained a malicious Word document.When opening the PDF file is via Javascript tried to open an embedded Word document. Standard warns Adobe Reader to open these embedded files.

If users ignore the warning and still choose to open the DOC file in Microsoft Word, then get them whether they want to run the macro in the document. In recent months, regular Word documents with macros used , which once carried download malware. Also in this case, it is after the execution of the macro malware downloaded. It is a variant of the Dridex banking Trojan, a Trojan horse that steals money from online bank accounts.

According to researcher Steve Basford the malicious Office documents at the time only against Windows users. "Apple and Android software to open these attachments and might even run the macros embedded in the annex," he tells his own blog.Belgian researcher and ISC handler Didier Stevens made ​​this demonstration video in which he analyzes the PDF file.

Tuesday, 21 April 2015

JavaScript Annex Spreads CryptoWall-Ransomware


In many email attacks are used executables and Office documents, but there are spammers that use JavaScript attachments. Before warns Trustwave. The security company recently discovered a spam campaign where emails were sent that contain supposedly a resume laity.

There was a zip file as an attachment sent with it a Javascript file, ending .js. Once the recipient opened the file the script tried to download an executable, which turned out to be a variant of the CryptoWall-ransomware. This ransomware encrypts all kinds of files on the computer and then asks hundreds of dollars for decrypting it.

On another spam campaign Trustwave discovered a phishing attack that also made ​​use of JavaScript. In this case, an HTML file was sent to JavaScript which recipients must enter their account details. "If an e-mail telling you to enable JavaScript that you should not really do," says analyst Brian Bebeau. "Despite the use of executable files and other exploits you can not ignore JavaScript attachments in your e-mail traffic. They can both your users and yourself cause problems."

Saturday, 7 March 2015

Ransomware Spreads Via Malicious Help Files


Cyber ​​criminals have been distributed in the Netherlands emails containing malicious help files that contain the CryptoWall-ransomware. Before that warns the Romanian antivirus company BitDefender. The e-mails contain a .chm file as an attachment. This stands for Microsoft Compressed HTML Help, and is the successor to the help files in Windows.

Chm files are highly interactive and can contain various technologies, such as JavaScript. This makes it possible to automatically download a file when the .chm file is opened. According to analyst Catalin Cosoi is a logical choice for cybercriminals to use chm files. "The less user interactions, the greater the risk of infection." In addition, users will these files may not be regarded as suspect.

The e-mails in question occur among others as e-mail messages from a fax machine. Once opened the ransomware can encrypt files on the computer and then asks for a certain amount of users to decrypt them. According Bitdefender however the attackers with this spam run would have to provide companies and attempting to infiltrate corporate networks. Over the past several months, let companies know that they are the victim of ransomware became.

Wednesday, 18 February 2015

Vulnerability: "Website Chef Jamie Oliver Spreading Malware"


Attackers have managed to hack the website of the British chef Jamie Oliver and provide malicious code that attempts to infect visitors with malware. Researchers at anti-virus company Malwarebytes found on the website that visitors JavaScript invisible sends to a exploitkit on another hacked website. This makes exploitkit abuse leaks in Flash Player, Silverlight and Java.

These are vulnerabilities where all updates to be available. Users who are up-to-date are therefore not at risk. In case users are not up-to-date, it will install a Trojan horse, which is recognized by few virus scanners on VirusTotal. "Unlike most web exploits that we have seen recently, this is not the result of contaminated ads, but a well-hidden injection at the site itself,"says analyst Jerome Segura. He notes that the problem lies in the compromised JavaScript on the website.

It may be possible to go a legitimate script adapted or an entirely malicious script. The webmaster will also receive the advice to look for other signs of infection, then just remove the script in question or modify. "Usually the stolen credentials or a vulnerable plug-in allowing an attacker gets access to a server," said Segura. Oliver's website is on the 536ste place of most visited websites in Britain and would attract 10 million visitors each month.

Hash:
f93f39f39dc5162f9e310648022d6f40

Tuesday, 3 February 2015

Firefox and Chrome Can Leak IP VPN Users

Firefox and Google Chrome have implemented a technology allowing the IP address of VPN users can be traced. Before Daniel Roesler warns on GitHub . The problem is caused by WebRTC , an open source project developed by Google that provides browsers Real-Time Communications (RTC).

Both Firefox and Chrome have implemented whereby the WebRTC technology called " STUN requests "can send to STUN servers. Through these requests, the local and public IP addresses of the user can be captured via JavaScript. This is especially a problem for VPN users, who often use VPNs to protect their identity. Roesler made ​​this demonstration to capture the IP addresses. Readers Reddit give different solutions to the problem, such as disabling WebRTC in Firefox and Chrome.

In Firefox, this can by in the address bar " about: config "to enter and then put" media.peerconnection.enabled "to" false ".Google Chrome users can do this in the address bar " chrome: // flags / "to enter and then" Disable WebRTC device enumeration "to turn. Other solutions have JavaScript disabled, using Firefox NoScript or Chrome extension WebRTC Block. Additionally, VPN users get TorGuard advised to set the VPN tunnel directly to their router.