Showing posts with label Man In The Middle Attack. Show all posts
Showing posts with label Man In The Middle Attack. Show all posts

Wednesday, 25 November 2015

Dell Will Remove Dangerous Certificate Of Computers



Computer manufacturer Dell will begin today with the removal of a certificate that allows users to be attacked, as the company has announced. Since August this year, laptops and desktops from Dell comes with a certificate that contains the private key.

Attackers can use this key to sign malware for example, so it looks like that comes from Dell, and are also man-in-the-middle attacks on HTTPS sites possible. According to Dell, the certificate is no malware or adware. It was deliberately placed on systems to help customers. Through the certificate Dell's help desk can identify the service tag of the system and quickly identify the computer model, operating system and other components.

The computer manufacturer states in a blog posting that the certificate inadvertently introduces vulnerabilities. Something that Dell makes excuses for that. The company now has instructions (docx) put online how the certificate can be removed in question, and will also release an update starting today to remove the certificate. Also, all new systems will be delivered without a certificate. In the blog posting thanked Dell also researchers Hanno Böck, Joe Nord and Kevin Hicks who published about the security issue. Dell customers who want to know whether they are vulnerable to these via this website testing.

Update

"The security and privacy of our customers are of utmost importance to Dell. The recent situation relates to an" on-the-box "support certificate is intended to provide customers a better, faster and simpler support experience. Until Dells regrets the license shall carry an unintended security vulnerabilities along with it. To solve this problem we will provide our customers with instructions to remove this certificate permanently from their systems, "

"We go to the instructions via email on our support website and communicate via our technical support, we go the Certificate of all remove Dell systems that need to be made. Please note:. Business customer an image of their own Managing this issue does not affect systems. Dell does not install any adware or malware. The certificate will not reinstall itself if it is properly disposed of according to the process recommended by Dell. "

It also has CERT Coordination Center (CERT / CC) at Carnegie Mellon University, a warning issued to the certificate. It is also recommended to remove the certificate.

Thursday, 22 October 2015

Leaks In Hard Disk Drives Seagate And Western Digital Unveiled


Researchers have identified vulnerabilities in the hard drives of both Seagate and Western Digital unveiled which no updates are available. Eric Windisch found multiple vulnerabilities in the Central Seagate NAS solutions for networked storage.

It appears that firmware updates are vulnerable to a man-in-the-middle attack, as they are offered over HTTP and are not signed. This allows an attacker located between the user and the Internet is install malicious firmware. Furthermore, the device appears to leak via a phpinfo page information to any unauthorized user information.

Users can also adjust each other's files, there is a general root password used to world-readable, the web application allows unauthorized modification of IP address and host name possible and local users can increase their rights to the NAS. Windisch Seagate inquired twice but got no response. That's why he decided to publish his findings.

Western Digital

In the case of Western Digital were examined different models in the My Passport series that can encrypt themselves. The Western Digital My Passport external hard drive that offers hardware encryption on certain models. Problems with the leaking of information from memory, weak encryption keys and even backdoors on some drives make it possible for an attacker to decrypting user data without a password, the researchers said in their report (pdf).

Thus it appears the hard drives come with a default password. In case the user changes the password and do this once, the key of the default password remains on the hard drive behind. This makes it easy for an attacker to decrypt the hard drive. The problem can be remedied by the password reset a second time, but this is probably not familiar to users.Western Digital has been informed by the researchers, but no solution has yet released.

Tuesday, 30 June 2015

Software Update LG Phones Vulnerable To MITM Attack



The software electronics manufacturer LG used to update smartphone apps not check the server's SSL certificate that provides the updates, allowing users vulnerable to man-in-the-middle attacks and silently apps can be on the phone installed.

It reports the Hungarian security Search Labs . The problem is in the LG Update Center app. This app acts as an app store and allows users to download all kinds of apps. These apps are managed through the Update Center app, which also checks for available updates. To see if any updates are available makes the app via HTTPS connection www.lgcpm.com . However, the SSL certificate is not checked.

An attacker who is between the user and the Internet is just to catch the request of the Update Center app, and can then specify a different location to download the update. Since updating via APK files is done which there is no further permission or user interaction is required, an attacker can thus silently install malicious APK files on the phone of the target. These malicious apps can use any permission except the permissions must be signed with the key system.

According to the researchers, the entire process can take place in the background without the user suspecting anything. LG smartphones have also been configured to automatically install updates as they become available. The problem was reported to LG last November. The company said researchers know that for newer models with Android Lollipop, an update would consider. However, the updates must still appear.

"At the moment all LG Android-based smartphones are vulnerable to this attack and will continue to plans by LG," write the researchers. They argue that because LG "business interests" No updates will bring. LG users who want to protect themselves are advised to "Auto app update" disable and use the Update Center app only reliable Wi-Fi networks to install apps or update.

Wednesday, 24 June 2015

Kodi Media Center (XBMC) Vulnerable To MITM Attacks



The popular media center Kodi, formerly known as XBMC, contains a vulnerability which attackers between a user and the Internet are able to attack the system. Through Kodi allows users movies, music and other media, for example playback on their TV or sound system.

The software contains a collection of add-ons that allow users popular services like YouTube, Grooveshark and Dropbox can access. Each time Kodi is started watching the software or pre-installed add-ons updates. In the case of a new version is automatically downloaded and installed. The update check takes place entirely over HTTP without encryption, as discovered the Romanian antivirus company BitDefender .

The software asks during the update check to a MD5 hash for the last addons.xml file, which contains information about add-ons. An attacker can send back, in this case a random MD5 hash, which does not have to correspond to the file that is then presented. The attacker could send a specially prepared following addons.xml file indicating that a new version for a particular add-on is available. Then, the attacker must send the correct MD5 hash for his malicious add-on. Once Kodi this add-on installs the malicious Python code running in the add-on to the system.

For their demonstration, the researchers succeeded to download an executable file and place it in the startup directory of the system. It should be noted that an attacker the same privileges as the user running Kodi. Eventually they managed also to steal login details for YouTube and could Dropbox add-on change, so when starting or synchronizing files all content from the local Dropbox directory to a specified FTP server was sent. The Kodi developers are informed by Bitdefender and working on an update. When that appears is unknown.

Thursday, 18 June 2015

Serious Leak In Keyboard Software Samsung Smartphones


Researchers at the keyboard software installed on many Samsung smartphones found a vulnerability that could allow an attacker who between users and the Internet is to execute arbitrary code with system privileges on the device. Samsung Galaxy S phones, including the Mini S4, S4, S5 and S6 are standard version of Swiftkey keyboard.

This software runs with standard system privileges and regularly checks for updates. However, monitoring will take place over HTTP, which means that it is vulnerable to man-in-the-middle attacks. An attacker who can intercept this update checks and then offering a malicious update can execute arbitrary code as the camera with system privileges. Even if the software is used can not still be attacked, according to researchers from NowSecure . Who published a web page where users can check whether they are vulnerable. According to the researchers, the problem is present at about 600 million sets.

The CERT Coordination Center ( CERT / CC ) at Carnegie Mellon University suggests that the probability of an attack, depending on how often the software checks for updates, it is possible small. Samsung has now released a firmware update for telecom providers. In case users do not receive over-the-air update is still advised to avoid unreliable networks including open Wi-Fi networks. The use of unreliable networks increases the chance of becoming a victim of a man-in-the-middle attack, according to the CERT / CC.

Wednesday, 29 April 2015

Lenovo Provides Free Recovery Media Without Superfish


Owners of a Lenovo laptop can now apply for recovery media to install Windows and additional software without even the Super Fish-adware is installed together, so has let the computer manufacturer on the private forum know. Super Fish is a program that intercepted SSL connections to inject ads. The adware used for this purpose its own root certificate. Researchers managed to crack the password using the private key of the Superfish certificate.

This makes it possible in certain cases to Man-in-the-middle attacks against systems that perform Superfish and the certificate installed. In total Superfish appeared on more than 40 different types of laptops to be installed. Because of the Superfish debacle Lenovo announced several measures. For example, published a removal tool and put the manufacturer's promise that it will provide cleaner machines with less pre-installed software in the future. Also followed a free subscription of six months on the McAfee virus scanner.

Current owners of a laptop sit with the problem on their recovery media, such as a special recovery partition, Superfish is still present. If the computer is reinstalled using the recovery media is also Superfish replaced. Last month, Lenovo's own forum know that they worked to restore clean media without Superfish which can be requested via the support department. An employee of Lenovo claims that the recovery media will not be sent in bulk. "But if you need due to specific circumstances recovery media, please contact the service desk." Whether the media via CD or USB stick will be offered the employee does not know. We have asked for clarification about Lenovo.

Saturday, 18 April 2015

Google Warns SSL Kapende Adware



Adware is not only annoying because it shows everywhere ads, it also poses a serious security risk.Before warns Google. The Internet giant is facing various forms of adware that are able to hijack SSL connections, such as with Superfish Lenovo was the case.

The adware runs through hijacking SSL connections actually a man-in-the-middle attack from users, allowing access to personal information can be obtained and the computer is vulnerable. In the case of Superfish and Komodia attackers could for example host phishing sites that caused no warning and decrypt encrypted traffic.

To avoid this kind of risk Google advises users to be careful when downloading software from the Internet. When a secure site visited, for example online banking, extra attention should be given to strange changes to the website, such as additional ads, coupons or investigations. "This may be an indication that your computer with this kind of unwanted software is infected," says Google software engineer Eric Severance.

Saturday, 28 March 2015

Researchers Reveal SSL Attack By 13-Year-Old RC4 Leak


Researchers have demonstrated an attack with which it is possible to be a part of the information that is to intercept encrypted via SSL / TLS. Unlike several other attacks on the encryption protocol is when attacked by security company Imperva ( pdf ) no need to sit through a man-in-the-middle attack between the user and the Internet. The passive eavesdropping of data, for example, would suffice received by a web application.

The attack is aimed at a thirteen year old vulnerability in the RC4 encryption algorithm, which is used in setting up an SSL / TLS connection. The vulnerability has already been described in 2001, and makes it possible to carry out a "plain text recovery attack" on SSL traffic as RC4 is the used encryption algorithm. Then an attacker can retrieve portions of session cookies, passwords and credit card numbers. The vulnerability is caused by the weak keys that uses RC4.

If an attacker enough SSL / TLS connections can be intercepted found such a weak key, which can then be read the first 100 bytes of the encrypted data. If an attacker tries to steal a session cookie can reduce the effective size of the cookie using this attack, which can be accelerated a brute force attack on the session cookie. Via session cookies, it is possible to take over the session of a user and so as to gain access to online accounts.

The problems with RC4 have long been known , and in 2013, Microsoft released an update for Windows to disable the algorithm. Most browsers would still support RC4, as well as more than half of the servers. According to the researchers such would be 30% of the TLS sessions are still using RC4, even if it is stronger AES algorithm available for quite some time.

Tuesday, 10 March 2015

Lenovo Provides Customers With Superfish-Adware 6 Months McAfee


Customers of computer manufacturer Lenovo laptop with the Superfish-adware can receive from next week try a virus McAfee for a period of six months without charge, as the company has let know .Because of the Superfish debacle Lenovo announced several measures. Was published as a removal tool and put the manufacturer's promise that it will provide cleaner machines with less pre-installed software in the future.

In addition, the customers a free subscription offer of a half years at McAfee Live Safe. The security software can be used on multiple devices and to protect systems against malware and other online threats. Duped consumers can already download the trial version of the software, to activate it, then next week on 16 March. In case users the security itself already bought their existing subscription will be extended by six months.

In total, more than 40 different types of laptops that Superfish standard was installed qualify for the program. Super Fish is a program that intercepted SSL connections to inject ads. The adware used for this purpose its own root certificate.Researchers managed to crack the password using the private key of the Superfish certificate. This makes it possible in some cases to Man-in-the-middle attacks against systems that perform Superfish and the certificate installed.