Showing posts with label Kevin Beaumont. Show all posts
Showing posts with label Kevin Beaumont. Show all posts

Friday, 21 April 2017

Cybercriminals Use NSA Exploits To Attack Servers


Cyber criminals are currently actively using the NSA exploits last week by the hacker group Shadow Brokers were made public to provide servers backdoors and possibly spreading ransomware. Let know several security researchers.

Thus Double Pulsar tool found on the various servers. The NSA would use this tool after it has been through an exploit access to a server. In addition, security reports SenseCy that there is currently a "trend" going where the leaked NSA exploits used to infect Windows Servers with ransomware. The attackers were using either a vulnerability in Windows SMB Server make that Microsoft patched in March.

Further details are not given, however, about this ransomware attacks. Earlier researcher Kevin Beaumont predicted that the NSA exploits a ransomware worm would be used. "It's the next logical step yields for worms and criminals, because the money and is easy to do," says the researcher. Beaumont says that if known exploits are currently being used to servers a backdoor provide.

Wednesday, 8 July 2015

Office Component Allows Attacker's Code Without Executing Macros


A researcher warns Office users a feature allowing attackers to execute malicious code through documents, even if macros are turned off and the part is not off. Every Windows version of Microsoft Office contains a feature that makes it possible to embed content in documents.

These include the executable content, such as .exe and JavaScript files, so let investigator Kevin Beaumont on the Full Disclosure mailing list know. OLE Packager, as the feature is called, since the early 1990s in the Microsoft software is present. The feauture, which allows the embedding of content, was introduced in Windows 3.1 and was supported until Windows XP. All versions of Office support the feature yet. To prevent any abuse of the feature made ​​Microsoft uses a list of risky file types.

Once a risky file type to a document is added to the list view shows a warning to the user. This warning can be ignored, but users can at least see that the document contains risky content. According to Beaumont the static list is not, however, up-to-date. For example, PowerShell and other executable files not recognized and therefore users get no warning. Thus, it is possible to carry out through the opening of Office files code on the computer. It does not stand out or macros off, or that of High Security templates are used.

Solution

Microsoft was informed in March of this year about the problem and was told that attackers were experimenting with the feature. To not know what is exactly the attackers and attacks Beaumont late. However, Microsoft then would have asked him not to publish information about the issue. Eventually told the researcher that it is and the problem is still not resolved to a feature of Office. For Windows users, Microsoft EMET installed, a free tool for Windows with secure, to assume control for Excel, Word and PowerPoint that prevents the feature can be implemented. However, this also prevents legitimate use of the feature

Tuesday, 7 July 2015

Hacking Team Had Zero Day Vulnerabilities For Windows And Flash



The Italian developer of government spyware Hacking Team had zero day vulnerabilities for Windows and Adobe Flash Player, according to the files that were stolen from the company. Yesterday published attackers a file of about 400GB with all sorts of information that was captured by Hacking Team.

The files have now discovered two vulnerabilities for which no security update available yet, says security researcher The Grugq . It is a vulnerability in Windows that allows an attacker can increase his rights on the system. In this case, the attacker must already have access to the computer in order to use the leak. The second vulnerability is in Adobe Flash Player. Through this vulnerability, an attacker computers or completely take over, for example, when users visit a hacked or malicious website.

The embedded Flash Player in Google Chrome is vulnerable. According to security researcher Kevin Beaumont makes the leak is possible to escape from the sandbox of Chrome. Researcher Rik van Duijn of security Dear Bytes however, leaves know that a sandbox escape "through the published code is not possible and therefore a second exploit is required. Hacking Team, which develops spyware for government agencies, has in statement confirming that it has been hacked. "We think there are documents of the company have been stolen. We have launched an investigation to determine the extent of the attack and to determine what exactly is captured," said a spokesman. The company's website has been offline since yesterday.

Update

The National Cyber ​​Security Center (NCSC) government has a warning issued for the flaw in Flash Player. Through the leak, an attacker execute arbitrary code on the computer with the rights of the logged in user. The NCSC states that there is no update available for the leak yet.

Update 13:48

The attack on Hacking Team is claimed by the hacker who last year by spyware developer Gamma International managed to break in and there gigabytes of data was captured, says Vice Magazine . The hacker says soon come up with the details of how he managed to break into Hacking Team.

Update 15:09

Anti-virus company Symantec confirms that this is a zero-day vulnerability in the latest version of Flash Player. The virus firefighter expects that attackers will probably make use of the vulnerability.

Update 15:19

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns also the vulnerability and says that users can protect themselves by installing Microsoft EMET unreliable or not Flash content to perform.