Showing posts with label Linux. Show all posts
Showing posts with label Linux. Show all posts

Friday, 6 November 2015

Extra Secure Tor Browser For Linux Launched



The creators of Tor Browser, the software for browsing through the Tor network, have released a security-enhanced version of Linux. It is the first time that the Tor Project offers a "hardened" version of Tor Browser. This browser includes a customized version of Firefox and Tor software.

The extra secure Tor Browser is based on the Tor Browser Alpha series. These are test versions of the browser that appear in the final versions. In addition, extra protection is added which should offer protection against memory exploits. For this are both the Tor software, and Firefox version Address Sanitizer compiled. This should give users a safer Tor Browser, especially if JavaScript is partially or completely disabled. It also helps to find problems earlier and to remedy them in the alpha and stable versions.

The additional security does have several disadvantages. Thus, this version is slower, consumes more memory and is slightly larger than the normal version. In addition, the added security of Address Sanitizer not perfect. An attacker who successfully back halls which it is practiced can still via JavaScript certain types of attack vulnerabilities. To date, the high-security Tor Browser only for Linux available, but is being given to versions for Mac OS X and Windows.

Tor Browser lets Internet users hide their IP address and visit censored websites. Every day, over two million people from all over the world using the Tor network, such as activists, people in totalitarian regimes and Internet users who value their privacy. The software is also used by criminals. Two years ago, users of legacy Tor Browser still the target of an attack allegedly by the FBI conducted. The attack users of the real IP address could be traced. To avoid Tor Browser Users with outdated versions meanwhile continue surfing is an automatic updater added to the browser.

Monday, 5 October 2015

AV-Test Lab: Linux User Without Virus


The amount of malware for Linux is still very limited, especially compared to Windows. Nevertheless, even Linux systems with malware become infected. In addition, Linux systems are often used in Windows environments and thus come into contact with Windows Malware. Astute Linux users, however, need to install a virus scanner, according to the German test lab AV-Test.

AV-Test decided 16 different security packages for Linux with both Linux and Windows Malware to test an Ubuntu system.The results are disconcerting for some products, because they are by letting 85% of the Windows Malware and up to 75% of the Malware Linux. Eight of the sixteen security suites able to detect between 99.7% and 99.9% of the 12,000 common Windows Malware. Only Symantec scores 100%. McAfee and Comodo scoring with 85.1% and 83% respectively lower.Much worse are the results from Dr. Web (67.8%), F-Prot (22.1%) and ClamAV (15.3%).

Tested for the second part of the test was 900 malware instances for Linux. Kaspersky'm here solely to detect all malware, followed by ESET with 99.7%. AVG scores 99%, followed by the server versions of Kaspersky and Avast that detect more than 98% of malware. Symantec, which identified all Windows Malware recognizes 97.2% of Linux Malware. The other products scored less well, with ClamAV, McAfee, F-Prot Comodo and finish at the bottom. The detection rates lie between 66.1% and 23%.

Linux And Malware


The question remains to what extent it is necessary for Linux users to install a virus. According to AV-Test, the number of Trojans for Linux has increased recently, but they are of poor quality. This is according to the test lab because attackers are aware of good security practices that Linux offers. There is then also especially the ignorance of users use, for example, which become infected by operational errors.

The most common way to become infected by Malware Linux is by installing software updates or via third parties, according to AV-Test. The software will ask during the installation to temporary root privileges. If the user allows this software to the system will be manipulated and attackers can install a backdoor on the system and is it part of a botnet.

According to AV-Test, most Linux users believe that they are one of the safest systems available use. "This statement is true if you only look at the system and leave the rest aside." Insecure third-party software and user errors can ultimately ensure that a Linux system, like Windows and Mac with malware gets infected.

Research by anti-virus companies shows that many infected Linux servers that are part of a botnet. Linux-based botnets often remain even longer operational because the servers do not use security software, unlike Windows Servers where this is the case. And if there is already software installed are often the wrong products. "In many Linux Forums free Comodo products, ClamAV and F-Prot be recommended to home users. This is not good advice", says AV-Test.

The test shows that home better for the free versions of Sophos or Bitdefender can choose. For server systems, there is the free scanner from AVG. ESET is as a whole out on top, followed by Symantec and Kaspersky. For servers are Kaspersky, AVG and Avast recommended.

Virus Scanner Necessary?

Or Linux Users must install a virus is ultimately to their own behavior. AV-Test says that security suites are only a second line of defense. The main security is in fact the user. Anyone who loves his system up-to-date, no unnecessary ports opens, only install software from trusted sources, prevents the browser to run active content and not open just e-mail attachments will do when it comes to Linux Malware no worries make, according to the testing lab.

Wednesday, 8 July 2015

Zero-Day Vulnerability In Flash Player Active Attacked - Update


The vulnerability in Adobe Flash Player which the Italian developer of government spyware Hacking Team disposal is now actively used to infect internet users with malware. Recently, an attacker managed to break in Hacking Team in there and made some 400GB of data booty.

Among the files an exploit was discovered a vulnerability in Flash Player for which no security exists a so-called 'zero-day'.Anti-virus firm Malwarebytes and researcher JuK of the blog Malware Do not Need Coffee now now report that several exploit kits about the exploit to have discovered by Hacking Team Flash Player flaw.

Exploit kits are programs that cyber criminals can infect Internet users through unpatched vulnerabilities in popular software.Thereby running Internet using Adobe Flash Player now a high risk of becoming infected with malware. Visiting a hacked or malicious Web site or see getting an infected ad is sufficient to run an infection.

Emergency Patch

Adobe yesterday evening let know that there are expected today to emergency patch will appear. The notice is still no reports that the vulnerability is also actively attacked. Google Chrome users seem to be already protected against the vulnerability. Yesterday, Google published because a new version of Google Chrome. Details on changes Google is not announced, but discovered that the embedded Flash Player in the browser but was upgraded to a version that is not vulnerable according to Adobe.

Update 12:38

Adobe has released the emergency patch already released . This is version 18.0.0.203 for Windows and Mac users, while version 18.0.0.204 for the Linux version of Chrome is available. For the Linux version of Firefox, version 11.2.202.481 appeared. The update will be rolled out in most cases via the automatic update function, but can also be downloaded manually from Adobe.com .

Linux Developer Not Afraid Of Artificial Intelligence



The developer of the Linux kernel Linus Torvalds is not afraid of artificial intelligence (AI), he said in an interview with readers of the news site Slashdot let you know. In recent months, told several celebrities, including Bill Gates , Steve Wozniak and Elon Musk that they are very concerned about creating artificial intelligence.

Musk even called it the greatest threat to humanity. He therefore decided $ 10 million to allocate to hold artificial intelligence "useful". During the interview on Slashdot Torvalds was asked whether he was also worried about AI. "I just do not see why I should be afraid," he replied. According to Torvalds, the man will eventually create artificial intelligence, but it will need training. It will not be a rules-based program. In that regard, it will Artificial Intelligence, therefore, not as "reliable" as is the case with traditional computers, notes the Linux developer.

This makes it of interest to him, but also more difficult to use. Torvalds expects more targeted artificial intelligence, or AI that people will like. The " singularity , "where computers are getting smarter and create new models that are smarter again until they are more intelligent than humans, he designates as science fiction. "It's science fiction, and not even very good."Instead of infinite exponential growth, he expects more something that will resemble Moore's Law.

Monday, 8 June 2015

Special Linux Distribution For Analyzing Malware


There is a new version of REMnux appeared, the Linux distribution that is specially developed to analyze malware. REMnux is based on Ubuntu and contains a variety of tools for analyzing malicious files, documents and Web pages. Also, the distribution of various tools for memory forensics and reverse engineering of malware.

In REMnux version 6 added several tools who earlier were not part of the distribution, as oledump, vtTool, Docker, Yara Rules and pedump. In addition, several libraries have been added to allow software developers to develop new malware analysis tools. Another important adjustment is used Ubuntu version. REMnux used as a base because the 64-bit version of Ubuntu 14:04. Download via SourceForge .

Thursday, 28 May 2015

Linux Malware Allows Routers On Facebook And Twitter Defraud

Linux / Moose Overview
Researchers have discovered a new form of Linux malware that tries to take over routers subsequently on social networks like Facebook, Twitter, YouTube, Instagram and other sites to commit fraud with. The malware is called Moose ( pdf ) and scans the internet in search of Linux routers with an accessible Telnet service. Once found, will perform a brute force attack to gain Telnet access to the router.

Moose will modify the DNS in the event of a successful attack, steal the unencrypted network traffic to and from the router, perform man-in-the-middle attacks and offer proxy services for the malware creator. In practice, the malware will steal HTTP cookies from the aforementioned social networking sites to perform with fraudulent actions, such as "track", "view" and "like" of users and content on the websites.

In addition, the malware infected routers will also be used to scan for new vulnerable systems. According to researchers from the Slovak anti-virus company ESET malware is remarkable, because most Linux malware going around and it has developed features on routers to perform DDoS attacks. ESET also denounces the security of routers to be desired and allows this type of malware can strike.

"Witness the primitive techniques Moose used to access other devices, it is unfortunate that the security vendors of routers do not take seriously", say the researchers conclude. That also recommend IT experts to check the routers acquaintances on firmware updates and safe settings if they are nearby.

Monday, 11 May 2015

Mitnick: Almost 100% Success With Social Engineering



Social engineering is still one of the best ways for hackers to invade in organizations, since there is no patch for human stupidity, says security expert Kevin Mitnick. Mitnick was for years the most wanted hacker in the world and was eventually sentenced to a prison term of five years for breaking into several large companies, where he applied social engineering.

During his keynote address to the CeBIT business IT conference in Sydney Mitnick said that social engineering is particularly effective to penetrate into secure networks because existing problems are human error. "You can not download a patch for stupidity," he noted. "Social engineering bypasses all intrusion-detection systems. There is nothing on the market that can detect." In addition, free or relatively inexpensive to carry out, such as sending e-mail.

Mitnick himself conducts his own business penetration tests. If there should be social engineerg used, the success rate close to 100%. "It works on any platform, regardless of whether you're using Windows, Mac OS X or Linux. It is completely platform independent and the success rate is almost 100%." Mitnick told the audience that anti-virus software is dead and that most attacks that result from social engineering are able to bypass the virus, let Zdnet know.

They are, according to him than people who are the weakest link in security. "Users are the problem," said the ex-hacker. He also advises companies to strengthen "human firewall", something that can be done by repeated workouts. Additionally, organizations must ensure that all software on the computers of employees up-to-date and needs to incoming and outgoing traffic stringent be filtered through the firewall.

Thursday, 30 April 2015

Malware Infects Thousands Of Linux And BSD Servers


Researchers from the Slovak anti-virus company ESET have discovered thousands of Linux and BSD servers that are infected with malware and used to send large numbers of spam messages. Hard mumble, as the malware is called, would have been active since 2009.

It mainly involves Web servers that most likely through leaks in the popular content management systems Joomla and WordPress were hacked. Then the attackers Mumble Hard installed on the systems. In addition, the malware could also have spread via pirated versions of a program called Direct Mailer. The software normally costs $ 240, but on the Internet pirated versions were found with Mumble Hard backdoor.

Yell Soft

Direct Mailer is developed by the software company Yell Soft. Yell Soft sells software like Hard Mumble is written in the Perl programming language and is used to send bulk mail. Researchers from ESET suspect Yell Soft may be involved in the malware. It appears that the IP address of the C & C server that the infected Linux and BSD machines controls is in the same range as the Web server yellsoft.net .

The second link which the researchers point to the existence of the illegal versions of Direct Mailer where Mumble Hard backdoor hidden in. The first version of Mumble Hard dates from 2009. Yell Soft exists since 2004. "It is unclear whether they were involved between 2004 and 2009 in malicious activity," as the researchers in their report ( pdf ) about the malware.

Infections

Hard mumble was discovered after an administrator had complained that his server was ended because of a spam blacklist.During the research conducted ESET researchers knew to "sink holes" botnet server, where the movement of infected machines ran to a server of the anti-virus company. In this way, the researchers saw a period of seven months, nearly 8900 unique IP addresses passing by who were infected. Administrators who want to know if their server is compromised are advised to search for unsolicited cron jobs for all users.

Tuesday, 7 April 2015

Linux Server Australia Hacked Through Unknown Leak


The organization of Linux Australia, an Australian organization that organizes various Linux Conferences and commitment to the open source community in the country, has recently been faced with a hacked server, where possible personal data captured.

That the organization this weekend via its mailing list disclosed. On March 22, there was a large number of system messages sent from the conference management server. This server is used to host various conferences. The messages were generated automatically by the system. Further investigation on March 24 showed that the server on March 22, was hacked.

Under Linux Australia managed to cause the attacker to an unknown vulnerability a buffer overflow and then got root privileges on the server. The attacker installed below a remote access tool to control the remote server and installed software to the server part of a botnet. At the time of the attack, the attacker access to personal information including name, address, phone numbers, email addresses and hashed passwords.

However, the organization says it has found no evidence that there are data captured, but assumes the worst scenario.Because of the attack have been taken several measures, including the removal of all malicious software. In addition, the compromised server will be discarded and there is now set up a new server. The security of this server will be strengthened, including through a rigorous update schedule, duplicating logs and running of user accounts three months after the conference.

Thursday, 2 April 2015

Google Says Trust Certificates In Chinese CNNIC CA


Due to a recent incident with wrongly issued SSL certificates for Google sites Google has confidence in the Chinese certificate authority (CA) CNNIC terminated, which Google products such as Chrome will no longer recognize the certificates of CNNIC. Something that will be implemented through a future update for Chrome. Since this is very big impact, particularly Chinese Chrome users will have Google has decided to permit temporarily issued SSL certificates under CNNIC even by placing them on a public whitelist.

The reason for the measure is the recent discovery of rogue SSL certificates for various Google domains that were created by the Egyptian company MCS Holding. The company had been given the opportunity of CNNIC, which is a root CA. As root CA is CNNIC trusted by all major browsers. CNNIC had spent an intermediate certificate for MCS Holding, which the company for arbitrary domains could create SSL certificates. Because the intermediate certificate of CNNIC came, they were created SSL certificates also trusted by browsers.

According MCS Holding made ​​a human error sure that the existence of the rogue Google certificate was discovered. Google, Microsoft and Mozilla therefore decided to block these certificates. In addition, the CNNIC was heavily charged that MCS Holding gave an intermedia certificate, which the Chinese company had violated all sorts of rules. After further investigation, Google has now decided to tell all the confidence in CNNIC.
Certificate Transparency

Google argues in a statement that it believes that no other unauthorized SSL certificates have been issued or that the rogue Google certificates are used outside the test environment of MCS Holding. Regarding the Chinese certificate authority that Google must "Certificate Transparency" before implementing any request about the renewed confidence of CNNIC is considered.

Certificate Transparency is a technology developed by Google and is intended to address several structural flaws in the SSL certificate system. Thereby to unjustifiably spent and rogue SSL certificates are detected earlier. Mozilla has also decided to Certificate Transparency support .
Update

CNNIC called Google's decision unacceptable and unwise. The Chinese CA Google also calls to take the interests and rights of users into consideration. CNNIC let customers know their rights and interests will not be compromised.

Friday, 27 March 2015

Egyptian Company: Google Rogue Certificates Were Mistake


The Egyptian company that had generated rogue SSL certificates for different websites from Google calls it a mistake that Google eventually discovered the certificates and hit alarm . Indeed, it was not intended that the certificates were discovered. This week, Google warned Internet users to rogue Google certificates generated by the Egyptian MCS Holding. Through the certificates could allow an attacker to Man-in-the-middle and phishing attacks on Internet users to intercept passwords and the contents of encrypted traffic.

MCS Holding is an Egyptian security company that delivers business networking. However, it had become a so-called "intermediate" certificate authority (CA), which was linked to the Chinese certificate authority CNNIC. SSL certificates from an intermediate certificate authority originate have the full authority of the CA under which they fall. In particular, Mozilla had great criticism of CNNIC that MCS Holding had given permission to the intermediate CA to generate SSL certificates.

The Egyptian company said in a statement that it had signed an agreement with CNNIC to a two-week period intermediate CA to act. This would be necessary for the testing of a new roll from cloud service. The test took place in a secure lab where the private key of the CA certifcate, to generate SSL certificates, stored in a firewall.

However, the firewall was set to automatically generate certificates for websites that were visited on the Internet. During an unguarded moment at the weekend would be one of the IT engineers decided to use the internet with Google Chrome. Chrome offers certificate pinning, which websites can indicate what their CA SSL certificate has been issued. The browser will then put these certificates on a whitelist.

Is the website for an SSL certificate that is issued by a different CA, then turn the alarm browser. After MCS Holding by CNNIC had informed the certificate was immediately removed from the firewall and warned all parties involved. According to the Egyptian company, it is a human error which inadvertently took place. "We have no evidence of abuse, and we therefore recommend that people will not change their password or other action," said a company spokesman.

Measures

Meanwhile, Google has revoked the intermediate certificate of MCS Holding and also a Microsoft update released under Windows Users. From the description of the software giant appears that certificates for domains *. google.com , *.google.com.eg , *. g.doubleclick.net , *. gstatic.com , www.google.com , www.gmail .com and *. googleapis.com were created. Firefox comes next week with an update to revoke the certificate.

On the mailing list of Mozilla developers after the incident a heated debate erupted or CNNIC is not guilty because it would have violated all sorts of rules. While some want CNNIC is removed from the root store of Firefox. Mozilla could do this then this can have very serious consequences, especially for Chinese Firefox users, thereby HTTPS sites with SSL certificates of CNNIC and suspended beneath intermediate CAs can not visit. The Chinese CA Mozilla has therefore asked not to remove it from the root store CNNIC.

Tuesday, 24 March 2015

Google Sounds Alarm On Rogue Google certificate



Google warns Internet users to rogue Google certificate issued by a company from the United Arab Emirates and could be used to perform man-in-the-middle and phishing attacks on Internet users, so as passwords and the contents of encrypted traffic intercept. SSL certificates are used inter alia for encrypting traffic between websites and visitors and identifying websites.

The company that rogue SSL certificates issued is MCS Holdings , a so-called "intermediate" certificate authority (CA), which is linked to the Chinese CNNIC certificate authority. SSL certificates from an intermediate certificate authority originate have the full authority of the CA under which they fall. CNNIC is in all major "root certificate stores" so the Google unfairly issued certificates would be trusted by most browsers and operating systems.

Chrome on Windows, OS X and Linux, ChromeOS and Firefox 33 and newer would have refused the certificate because certificate-pinning. According to Google, there are probably also issued certificates for other websites that may not be recognized by certificate-pinning. Certificate-pinning sites may indicate by what their CA SSL certificate has been issued. The browser will then put these certificates on a whitelist. Is the website for an SSL certificate that is issued by a different CA, then turn the alarm browser. Browsers like Chrome and Firefox currently support only pinning for some great websites.

Proxy

Following the fraudulent certificates, which were discovered on 20 March, Google CNNIC approached and was told that MCS Holdings only if issued certificates for domains they had registered themselves. That turned the company does not have done. MCS Holdings provides proxy appliances and firewall solutions that enable organizations of workers through the encrypted traffic can intercept self signed certificates. Should normally be set to the office computers to trust the proxy, but in this case it was not required by the wrongly issued certificates.

Google sees similarities with previously unduly certificates issued in 2013 by the French CA ANSSI . The Internet giant also denounces that CNNIC the power to create SSL certificates awarded to a company that was not suitable here. Chrome users do not have to do to be protected from rogue certificates, while Firefox users will have to wait for the arrival of Firefox 37 in which the certificate has been revoked. This version on March 31 appear.

Saturday, 7 February 2015

GnuPG Developer Receives 130,000 Euros After Cry


The developer of the Gnu Privacy Guard (GnuPG), very popular software for encrypting e-mail, has received 130,000 euros in donations after a cry that he would go bankrupt. Werner Koch GnuPG developed in 1997. It is a free implementation of the OpenPGP standard that is used for encryption of the data and communication. Since launching Koch maintains software.

Yesterday appeared in ProPublica an interview with the 53-year-old German, who argued that his money was slowly running out. "It was in early 2013 that I realized I had to take a normal job," Koch said earlier already know. When the revelations of whistleblower Edward Snowden appeared in his own words, he realized that it was not the right time to stop.

Despite all the attention for encryption and secure e-mail traffic Koch was struggling to find enough money. Among others to realize his dream, hiring a full-time programmer. The German would have about $ 25,000 earned annually since 2001. Much less than he could earn in a company.

So he decided after the revelations Snowden start a fundraiser, where T-shirts and stickers could be purchased. It eventually yielded 18,000 euros. The campaign gave Koch, who is married and has a daughter of 8, some space. When asked what would happen if this amount was the programmer said that he would rather not think about it. "I am happy that for the next three months, money is," he says.

After the article appeared in ProPublica told the GnuPG developer that last week he had received a one-time scholarship of $ 60,000 from the Linux Foundation's Core Infrastructure Initiative. However, he could announce until after publication of the article the donation. In addition, the article missed its effect is not. In 2011, the German programmer 21 donations with a net worth of 465 euros.

A year later, there were 53 and went to nearly 5,000. In 2013, he received more donations, namely 148, but the donations were lower which he played at Euro 4145. In 2014, the situation improved with 801 donations, with a gross value of 35,000 euros. This year, Koch after the article all 3849 donations worth some 130,000 euros received.

Thursday, 29 January 2015

Experts: Linux system Reboot After Installation GHOST Patch


Tuesday released a patch for a critical vulnerability in Linux, but after installing the system must be restarted, as experts warn. Through the GHOST vulnerability an attacker can take over vulnerable systems in certain cases. Still, the leak can not be compared with other major vulnerabilities as Heartbleed and Shellshock.

Most systems are not vulnerable because, says security expert Robert Graham . Modern software would use a different function and even software that uses the function which the leak can be invoked does so in a way that can not be abused."Even if software will use the vulnerable function is not to say that it is also vulnerable," the expert notes. Also, most systems would not be attacked by the leak and many of the exploits used only locally. Graham says that users also do not have to panic.

He gets applause Jen Ellis security company Rapid7. "Unlike a leak as Heartbleed is not always exploit the problem. The general consensus is that the bug is not easy to abuse," Ellis says. Until now, there would be only one known case that is easy to abuse. Both experts suggest that users of their systems after installing the patch have to reboot. Without a reboot services that will use the vulnerable library not be restarted.

Wednesday, 28 January 2015

Linux Systems Vulnerable To Criticism GHOST Leak



There is a critical vulnerability in Linux discovered which virtually all systems since 2000 at risk. Through the leak can take over a remote attacker without valid credentials vulnerable computers. The vulnerability is since November 2000 in the GNU C library.

The GNU C Library, also known as glibc, is an implementation of the standard C library and an important part of Linux.Without this library would be a Linux system does not work. The leak has researchers named GHOST received because it through the gethostbyname function is to call. An attacker could then execute arbitrary code on the system.



On May 21, 2013 between the releases of glibc 2.17 and glibc 2:18 there appeared a solution to the leak. However, the fix was not classified as a security advisory, making the most stable distributions with long-term support remained exposed, according to security firm Qualys discovered that the vulnerability. This is Debian 7 (wheezy), Red Hat Enterprise Linux 6 and 7 and Ubuntu 12.04.

"GHOST is a remote code execution risk, which makes it very easy for an attacker to compromise a machine. Example, an attacker can send a simple e-mail from a Linux system and automatically get full access to that machine," says Wolfgang Kandek, CTO at Qualys. Administrators and users are advised to install the updates now available from their supplier.

Saturday, 13 December 2014

Linux espionage virus first made possible for Solaris


This week researchers announced that they had a spy virus for Linux discovered , but the Finnish anti-virus firm F-Secure says that the malware is possible first developed for Solaris. The Turla backdoor, also known as Snake or Urburos, was known only deployed against Windows.

Now Kaspersky Lab reported that it had discovered a Linux variant. The malware, according to researchers, a number of interesting features, with the ability to sniff the network interface is most striking. The malware can namely the Command & Control server, which controls the infected machine, adjust according to the network traffic. The attackers only need to send a special packet to the machine to activate the malware.

Furthermore, the malware acts as a normal "remote access trojan" (RAT) and allows attackers to download and upload files and execute commands. Researchers at F-Secure discovered in the code some remarkable system paths. It went to directories that are normally used in a Solaris environment.

Researchers have therefore questioned whether the backdoor is not first developed to attack Solaris servers. The code rates can be easily adjusted for other platforms. "It is no surprise if we malware the coming days also find on Solaris servers," says Jarkko Palviainen F-Secure.

Tuesday, 9 December 2014

"Turla Linux Malware" - Researchers discover espionage virus for Linux


Researchers from the Russian anti-virus firm Kaspersky Lab have discovered a spy virus for Linux that may go unnoticed for years, although for the latter is no proof yet. It is a variant of the Turla malware, also known as Snake or Urburos which all other known specimens have been developed only for Windows.

The researchers knew that there are Linux versions of Turla existed but had never yet found in the "wild" so far. Turla according to Kaspersky Lab is one of the most sophisticated espionage campaigns ever discovered . Among others, the Belgian Ministry of Foreign Affairs would have become the victim of the campaign. The now discovered Turla variant supports Linux so that there can be infected with more systems attacked organizations.

"We suspect that this part years was active in an organization attacked, but have no concrete evidence to prove it," said Costin Raiu of Kaspersky Lab. Through the malware an attacker can communicate with infected systems and execute arbitrary code. Thereby Turla do not need elevated privileges. Also, the malware can not be found via netstat, a tool that system administrators use to get an overview of open network connections.

"It uses techniques that do not require root access, so it can move freely on the system of a victim. Even if it's a regular limited user launches can continue to intercept the incoming packets and execute commands on the system," says Raiu . He notes that the Linux malware especially in other public source code is based, in which the attackers a number of things have been added. How the malware spreads exactly is not reported.

Monday, 13 October 2014

SEANux OS - A Linux Distribution OS Coming Soon By SEA (Syrian Electronic Army)



Hacktivists of the Syrian Electronic Army (SEA) on Twitter own Linux distribution called SEANux announced. One reason for the launch of its own distribution is not given, but the hacktivists announced that the source code will be, so users can check the operating system. Possible backdoors opensource When SEANux exactly will appear is still unknown, but according to the announcement it will "soon" be.

Previously advised the SEA already to use for security reasons. No American or Russian web services The hacktivists came last year in the news regularly because they managed to hijack. Twitter accounts and web services of all major media organizations

Thus, among other Skype , Microsoft , CNN , recommendation service Outbrain , hosting provider Melbourne IT , chat service Viber , the British newspaper The Guardian , media company Thomson Reuters , satirical website The Onion , business magazine Forbes , Wall Street Journal , advertisements on Reuters.com and Israeli army successfully attacked.

Wednesday, 19 March 2014

Operation Windigo: 25,000 Linux servers infected by malware


In cooperation with the CERT-Bund, the Swedish National Infrastructure for Computing and other institutes, ESET's malware researchers have uncovered an attack by cyber-criminals, currently more than 25,000 Unix monitored worldwide server.
High level perspective of Windigo’s components and their relationship

Due to the attack, the security experts "Operation Windigo" call servers are infected, which then send out millions of spam e-mails. But the criminals have developed a complex system of sophisticated malware components. This pirate servers, infect visiting computers and steal information. Among the victims of "Operation Windigo" include cPanel and kernel.org.
ESET released today under welivesecurity.com / windigo a detailed document that represents the results of the studies and an analysis of malware. A guide provides information about how users can check their own system for infection. In addition, ESET shows how the malicious code can be removed.
Operation Windigo: Over three years have gone unnoticed
While experts have encountered early on parts of Windigo, the full extent and complexity of these cyber criminal organization in the professional sector has remained undetected.


Flowchart of Windigo’s credential stealing scenario
"Windigo has largely won unnoticed by the security community in more than two and a half years in strength and taken control of over 10,000 servers," says ESET security researcher Marc-Etienne Leveille. "More than 35 million spam messages sent every day to the e-mail accounts of innocent users. These clog inboxes and compromise computer systems.'s Worse is that every day half a million computers are running the risk of becoming newly infected. Visiting a web page whose server has been infected by the 'Operation Windigo', ends on dangerous exploit kits or with unwanted advertising. "
Although sites were infected by Windigo Windows computers only contaminate an exploit kit with malware, even Mac users get advertisements for dating sites. iPhone owners will be redirected to pages with pornographic content.
Sysadmins are encouraged to take action against Windigo
About 60 percent of the world's websites run on a Linux server. ESET researchers ask webmasters and system administrators to review their systems to infection.
"Webmasters and IT professionals generally have much going on why we're sorry that we can make them even more work -.. However it is important it is to protect their opportunity and perhaps even duty, other Internet users," says Leveille. "Everyone should strive to prevent the spread of malware and spam. A few minutes can make a big difference and contribute to the solution."
Timeline of Events

Quick-Check for Server
The ESET experts advise Unix server administrators and webmasters, perform the following command. He is quick indication of whether the own server is compromised:
$ ssh-G 2> & 1 | grep-e-e illegally unknown> / dev / null && echo "System clean" | | echo "system infected"
In the case of an established infection ESET recommends to clean the affected computer completely and reinstall the operating system and the software. It is imperative to use new passwords and private keys. The existing credentials might be compromised.
Bitter medicine for Windigo victims
"The Ebury backdoor that was used by 'Operation Windigo', does not use the weaknesses of Linux or OpenSSH from" Leveille continues. "Instead, they will be installed manually by the attacker. It's scary that the cyber criminal group has done this successfully on thousands of different servers. During antivirus programs and two-factor authentication on clients are common, they are rarely on the protection of servers employed. This makes in relation to the theft of access and malware rankings quite vulnerable. "
Should therefore be message in the future about it for a greater degree of protection, also use technologies, such as two-factor authentication.
"We know that cleaning the server and the rebuilding of the systems is a very bitter pill. If attackers have but stolen or cracked administrators access data and were able to establish a remote access to the server, which is the only safe way," said Leveille. "Unfortunately, some of the victims, to whom we have contact, so far done nothing to clean up their systems - and thus bringing other Internet users at risk." All computer users should always remember never to use passwords that are easy to crack or have been used.
More information
A Detailed report on "Operation Windigo" is located here: Eset