Showing posts with label Microsoft EMET. Show all posts
Showing posts with label Microsoft EMET. Show all posts

Wednesday, 8 July 2015

Office Component Allows Attacker's Code Without Executing Macros


A researcher warns Office users a feature allowing attackers to execute malicious code through documents, even if macros are turned off and the part is not off. Every Windows version of Microsoft Office contains a feature that makes it possible to embed content in documents.

These include the executable content, such as .exe and JavaScript files, so let investigator Kevin Beaumont on the Full Disclosure mailing list know. OLE Packager, as the feature is called, since the early 1990s in the Microsoft software is present. The feauture, which allows the embedding of content, was introduced in Windows 3.1 and was supported until Windows XP. All versions of Office support the feature yet. To prevent any abuse of the feature made ​​Microsoft uses a list of risky file types.

Once a risky file type to a document is added to the list view shows a warning to the user. This warning can be ignored, but users can at least see that the document contains risky content. According to Beaumont the static list is not, however, up-to-date. For example, PowerShell and other executable files not recognized and therefore users get no warning. Thus, it is possible to carry out through the opening of Office files code on the computer. It does not stand out or macros off, or that of High Security templates are used.

Solution

Microsoft was informed in March of this year about the problem and was told that attackers were experimenting with the feature. To not know what is exactly the attackers and attacks Beaumont late. However, Microsoft then would have asked him not to publish information about the issue. Eventually told the researcher that it is and the problem is still not resolved to a feature of Office. For Windows users, Microsoft EMET installed, a free tool for Windows with secure, to assume control for Excel, Word and PowerPoint that prevents the feature can be implemented. However, this also prevents legitimate use of the feature

Tuesday, 7 July 2015

Hacking Team Had Zero Day Vulnerabilities For Windows And Flash



The Italian developer of government spyware Hacking Team had zero day vulnerabilities for Windows and Adobe Flash Player, according to the files that were stolen from the company. Yesterday published attackers a file of about 400GB with all sorts of information that was captured by Hacking Team.

The files have now discovered two vulnerabilities for which no security update available yet, says security researcher The Grugq . It is a vulnerability in Windows that allows an attacker can increase his rights on the system. In this case, the attacker must already have access to the computer in order to use the leak. The second vulnerability is in Adobe Flash Player. Through this vulnerability, an attacker computers or completely take over, for example, when users visit a hacked or malicious website.

The embedded Flash Player in Google Chrome is vulnerable. According to security researcher Kevin Beaumont makes the leak is possible to escape from the sandbox of Chrome. Researcher Rik van Duijn of security Dear Bytes however, leaves know that a sandbox escape "through the published code is not possible and therefore a second exploit is required. Hacking Team, which develops spyware for government agencies, has in statement confirming that it has been hacked. "We think there are documents of the company have been stolen. We have launched an investigation to determine the extent of the attack and to determine what exactly is captured," said a spokesman. The company's website has been offline since yesterday.

Update

The National Cyber ​​Security Center (NCSC) government has a warning issued for the flaw in Flash Player. Through the leak, an attacker execute arbitrary code on the computer with the rights of the logged in user. The NCSC states that there is no update available for the leak yet.

Update 13:48

The attack on Hacking Team is claimed by the hacker who last year by spyware developer Gamma International managed to break in and there gigabytes of data was captured, says Vice Magazine . The hacker says soon come up with the details of how he managed to break into Hacking Team.

Update 15:09

Anti-virus company Symantec confirms that this is a zero-day vulnerability in the latest version of Flash Player. The virus firefighter expects that attackers will probably make use of the vulnerability.

Update 15:19

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns also the vulnerability and says that users can protect themselves by installing Microsoft EMET unreliable or not Flash content to perform.

Thursday, 5 March 2015

NSA Provides Tips Against Destructive Malware


Attackers who have full access to a network to steal or destroy all data on the network. It is therefore important to prevent attackers able to access and can go about their business undisturbed, according to the US Secret Service NSA in a new document on destructive malware. The report follows the attack on Sony, where assailants sabotaged thousands of computers.

"While there may be tools which in some cases may prevent the complete destroying data at that time, is a better defense to prevent an attacker can get as much control over the network." The NSA recognizes that this can be difficult in practice, but several measures can be taken to make it much harder for an attacker to unseen to get as much control over the network."The sooner network defenders can detect an intrusion, the less damage can potentially cause the attacker."

In the advisory report ( pdf ) the NSA gives several recommendations that help prevent, detect and reduce attacks. For example, recommended network segregation, so an attacker can not gain access to other parts of the network. The use of administrator rights must be limited and it is recommended deploying application whitelisting, so that unauthorized or malicious software can not be installed.

Another measure that organizations can adopt according to the NSA is to install the free Microsoft Enhanced Mitigation Experience Toolkit (EMET) or other programs that perform exploits difficult. EMET is a free program that adds a layer of security applications and Windows. This protection should make it harder to exploit any vulnerabilities in the software. The advice is further supplemented with known measures, such as the timely installation of patches and making backups.