Showing posts with label Microsoft Silverlight. Show all posts
Showing posts with label Microsoft Silverlight. Show all posts

Tuesday, 10 November 2015

Adobe Flash Player Most Attacked Software


Adobe Flash Player is the most attacked software on the Internet, according to the US company Recorded Future, on the basis of its own research. For the study were analyzed for more than one hundred exploit kits. These are programs that use vulnerabilities in software to fully automated and without requiring users to install malware on computers this notice.

Of the 10 most attacked vulnerabilities exploitable by kits are there in Flash Player 8. The other two attacked vulnerabilities present in Internet Explorer and Microsoft Silverlight. Most popular among cybercriminals vulnerability involves a flaw that Adobe Flash Player on February 2 this year patched. The survey also shows that Java, which was a favorite target in the past, from the radar of cyber criminals has disappeared.

Where criminals often in the past for some time using old vulnerabilities made, dating all attacked vulnerabilities in the Top 10 this year. Recorded Future suggests that companies should decide themselves whether to install the continuous flow of Flash Player updates a viable is an option. Otherwise, click-to-play "be used as a solution to prevent attacks.

Monday, 2 November 2015

Flash Player And Internet Explorer Favorite Cyber Criminal



Internet users who do not update their software run mainly risk of becoming infected with malware if they use Adobe Flash Player and Microsoft Internet Explorer, according to figures from the Russian anti-virus firm Kaspersky Lab. This involves infections via so-called "drive-by downloads."

These cyber criminals use of exploit kits, which automatically infect Internet through unpatched vulnerabilities with malware.Most kits include attacks to exploit vulnerabilities in IE, Flash Player and Silverlight. It is in all of these cases vulnerabilities this year by Adobe and Microsoft were patched. We look at the attacked software, it is mainly Flash Player and Internet Explorer. Attacks on Java even took off. In recent exploit kits there are no exploits for Java included.

Kaspersky Lab also looked at attacks from "web resources" and where those resources are located. 

Saturday, 10 October 2015

Firefox Stops Java Support, But Flash Continues To Support


Like Google and Microsoft will also stop supporting Mozilla based on NPAPI plug-ins, but for Adobe Flash Player is an exception. According to Mozilla are plug-ins that the old Netscape Plug-in API (NPAPI) use responsible for performance issues, crashes and security incidents.

End 2016 Mozilla also wants to stop the support for most NPAPI plugins in Firefox. A process that was initiated some years ago, by letting users activate these plug-ins manually. In addition, the new 64-bit Firefox for Windows platform will be launched entirely without support plug-ins, because it is no longer needed by the browser developer.

Because Adobe Flash Player on so many websites use Mozilla continues this plug-in, as an exception to the rule, do support. "Mozilla and Adobe will continue to work to make improvements to the Flash experience within Firefox, among others in terms of stability and performance, and security features," said Mozilla's Benjamin Smedberg.

Java

He advises websites that use plugins such as Silverlight and Oracle Java to switch to web technologies. These plug-ins will be late next year would no longer supported. In the event websites can not be without, for example Java advised to develop the required features as a Firefox extension. In order to end of Java within Firefox run smoothly cooperates with Oracle there. So advises Oracle now on websites instead of Java applets, plug-in free solution such as Java Web Start to use.

Wednesday, 7 October 2015

Cisco Disrupts Extensive Network Of Cyber Criminals


Network manufacturer Cisco has disrupted an extensive exploit kit network that criminals tried to infect surfers with ransomware and other malware. How many people have been victimized and how many criminals have earned the ransomware is unknown.

The action was directed against the Cisco Angler-exploitkit, used by cyber criminals to infect Internet users via vulnerabilities in Adobe Flash Player, Silverlight and Internet Explorer with malware. Cisco researchers discovered that the Angler-exploitkit used a large number of proxy servers, which were located primarily in the provider Limestone Networks. The study showed that the Angler-exploitkit one party was used extensively. This party was for 50% of all activity of the Angler exploit responsible and tried every day 90,000 people to infect via the aforementioned vulnerabilities.

Infections can only occur when users are using vulnerable software, for example, because they have no security updates have been installed. By working with Limestone was extensive information about the Angler-exploitkit are collected.Eventually all hosting providers where the proxy servers were informed, who then Switch off servers. Therefore, the cyber criminals had no access to the Angler-exploitkit.

Juggling With Figures

Cisco sets the announcement about the operation that cyber criminals through the exploitkit $ 60 million per year earned by ransomware. It is important to mention that this is an assumption and not a fixed amount. There is no hard evidence how many criminals have earned through their ransomware. The estimate of Cisco is based on several assumptions. For example, pointed to previous research showing that 40% of Internet users being attacked via the Angler-exploitkit also touches actually infected.

Further, it would be installed in 62% of infections via Angler ransomware. In addition, the average ransomware amount would be $ 300. According to figures from Symantec would actually pay 2.9% of the victims. Because all that matters to multiply with each Cisco eventually comes to an amount of 60 million dollars. As stated, this is an unconfirmed amount based on certain assumptions.

Thus, researchers from Dell SecureWorks to 0.4% of the ransomware victims pay the demanded ransom. Other studies a percentage of 0.27% to the front. If Cisco with these percentages, the amount would have expected would be much lower outage, which includes fluctuations in the number of successful infections and the number of ransomware installations.

Wednesday, 12 August 2015

IE Vulnerability Used To Distribute Ransomware


A vulnerability in Internet Explorer that Microsoft only three weeks ago patched is now actively used to infect computers with ransomware. The vulnerability exists in IE6 to IE11. Visiting a malicious or hacked website or see getting an infected ad is enough for an attacker to install malware on the computer for example.

The exploit that uses the vulnerability has been developed by the creators of the Angler Exploitkit. According to security researcher ' JuK 'of the blog Malware do not need Coffee makers could possibly since July 24 with the development of the exploit have been busy, two days after the release of the update. The makers of Angler developed previously often very quickly just exploits for unpatched vulnerabilities in Adobe Flash Player. Many Internet users are slow to patch. Even though there are security updates available, there are still computers are not up-to-date and can be attacked.

Adobe

According to security firm FireEye is noteworthy that the creators of the Angler Exploitkit now suddenly focus on an IE vulnerability. In recent months, were in fact only developed exploits for Flash Player vulnerabilities, with an exploit for Microsoft Silverlight as an exception. One possible explanation, according to the security at the security measures Adobe has taken to prevent abuse of vulnerabilities.

Depending on the software installed Internet, try the Angler Exploitkit attacks through vulnerabilities in Flash Player, Silverlight and Internet Explorer. In case the attack is successful CryptoWall-ransomware is installed. This ransomware encrypts files on the computer and then asks for a fee to decrypt them.

Wednesday, 22 July 2015

Recent Silverlight Leak Targeted By Cyber Criminals


It is not only vulnerabilities in Adobe Flash Player cyber criminals to infect computers with malware, users also need to watch Microsoft Silverlight, according to a security researcher. A vulnerability in the video plug-in that Microsoft in May by Security Bulletin MS15-044 patched is now being actively attacked by exploit kits, according to researcher ' JuK 'of the blog Malware Do not Need Coffee.

Once users with a vulnerable version a hacked or malicious website or visit an infected ad get to see the computer can become infected with malware. However, the question is how effective is attacking outdated Silverlight versions. Both Internet Explorer and Google Chrome Block obsolete video plug-in fact. In addition, Microsoft announced that Silverlight in the new Edge browser in Windows 10 will not support .

On the other hand, there are still users who do not install Windows Updates and therefore at risk of being attacked. Anti-virus company Trend Micro stated that Internet users last year, most via Adobe Flash Player, Internet Explorer and Silverlight were attacked and this year there have been several attacks discovered that unpatched Silverlight versions were targeted.

Wednesday, 13 May 2015

Website Chef Jamie Oliver Hacked For Third Time


Attackers are there for the third time succeeded in hacking the website of the British chef Jamie Oliver and use for distributing malware. Previously it had been hit in February and March . As with these incidents the attackers malicious code added to jamieoliver.com.

This code sends visitors unnoticed to another website through which uses known vulnerabilities in Adobe Flash Player and Java to infect visitors with malware. It is malware that attempts to steal passwords. In case the software of visitors up-to-date, they are not at risk. The team that know the website of Oliver would be responsible of the incident and take measures to solve the "once and for all", says anti-virus company Malwarebytes . How the attackers were able to gain access to site is unknown.

Sunday, 19 April 2015

Ransomware Allows Victims To Recover From Error Files



A new ransomware variant that first appeared in late January and make the last month was increasingly active shows an error causing casualties without paying their files can be recovered. It is the Threat Finder ransomware which spreads through vulnerabilities in Java, Adobe Flash Player and Microsoft Silverlight that Internet users are not patched.

Once the ransomware encrypts which operates numerous files and asks here for 1.25 bitcoins, what with the current exchange rate is 259 euros. A researcher from Bleeping Computer discovered that the ransomware the Volume Shadow Copies are not removed from the computer, making it possible to access the files using the " Previous options can restore "of Windows, or a tool like Shadow Explorer .

Wednesday, 8 April 2015

Scale Attack Through Infected Google Ads


Last night there was a large-scale attack on Internet via infected Google ads place. Advertisements and the website of Engage Lab, a Bulgarian company that clients advertising space offered by Google, including through DoubleClick, were found to contain malicious code, as discovered the Delft security firm Fox-IT .

The malicious code sent visitors who see the ads were unnoticed through to another website. This website was exploitkit placed that visitors through known vulnerabilities in Adobe Flash Player, Java Oracle and Microsoft Silverlight tried to infect.In case users up-to-date were unsuccessful attack. Users who had forgotten to install the available security updates could become infected with malware.

After about two hours there were no ads found infected through the ad network Engage Lab. To prevent attacks via infected ads advises Fox-IT updating software like Java, Silverlight and Flash Player and the use of a AdBlocker.

Sunday, 15 March 2015

Website Chef Jamie Oliver Spreading Malware Again


The website of the British chef Jamie Oliver has been hacked again and again spreading malware. The site places attackers malicious code that visitors unnoticed forward to another site. This site contains the Fiesta exploitkit which makes abuse of vulnerabilities in Flash Player, Silverlight and Java.

These are vulnerabilities where all updates to be available. Users who are up-to-date are therefore not at risk. In case users are not up-to-date, it will install a Trojan horse, which is recognized by few virus scanners on VirusTotal. In addition, the malware is signed, even though the certificate used now no longer valid, as reported anti-virus company Malwarebytes. The virus fighter discovered the first hack the website and then warned webmasters that it fixed the problem. Or so it seemed.

The structure used by the attackers to now placed malicious code is very similar to that of the first attack. "That's why we think this is the same infection that was not completely removed or perhaps that a vulnerability in the server or content management system (CMS) is still present," said the researchers. Oliver's website is on the 536ste place of most visited websites in Britain and would attract 10 million visitors each month.

Thursday, 19 February 2015

Popular Porn RedTube Spread Malware


On the popular porn RedTube researchers have found malicious code that tried to infect visitors with malware. That leaves anti-virus company Malwarebytes know today. Unlike several other porn sites that for "drive-by downloads" were used, there were no infectious ads used in this case. The attackers had direct access to the code of the website.

The malicious code was executed inside an iframe and pointed to the Angler Exploitkit on another page. This exploitkit uses a recently patched vulnerability in Adobe Flash Player. In case users do not use the latest version of Flash Player, they can become infected with a Trojan horse. This malware steals personal information and installs browser helper objects showing ads. Some of these ads pointing again to other operating pages can infect your computer with malware so on.

RedTube leaves in front Malwarebytes know that last Sunday was attacked and the problem was resolved within a few hours.Meanwhile RedTube the malicious code would be removed . The porn is according to measurement agency Alexa on the 128th place of most visited websites on the internet. Earlier today, the anti-virus company warned that the website of chef Jamie Oliver malware spread . Also, this problem has now been resolved.

Hash:
1e0134d9b5b51d9ad233b0a2ecb7cf83

Wednesday, 18 February 2015

Vulnerability: "Website Chef Jamie Oliver Spreading Malware"


Attackers have managed to hack the website of the British chef Jamie Oliver and provide malicious code that attempts to infect visitors with malware. Researchers at anti-virus company Malwarebytes found on the website that visitors JavaScript invisible sends to a exploitkit on another hacked website. This makes exploitkit abuse leaks in Flash Player, Silverlight and Java.

These are vulnerabilities where all updates to be available. Users who are up-to-date are therefore not at risk. In case users are not up-to-date, it will install a Trojan horse, which is recognized by few virus scanners on VirusTotal. "Unlike most web exploits that we have seen recently, this is not the result of contaminated ads, but a well-hidden injection at the site itself,"says analyst Jerome Segura. He notes that the problem lies in the compromised JavaScript on the website.

It may be possible to go a legitimate script adapted or an entirely malicious script. The webmaster will also receive the advice to look for other signs of infection, then just remove the script in question or modify. "Usually the stolen credentials or a vulnerable plug-in allowing an attacker gets access to a server," said Segura. Oliver's website is on the 536ste place of most visited websites in Britain and would attract 10 million visitors each month.

Hash:
f93f39f39dc5162f9e310648022d6f40

Sunday, 8 February 2015

Contaminated Advertisements For Months On Popular Sites


A group of cyber criminals has been struggling for months with showing infected ads on popular websites including Photobucket, Huffington Post and several webmail providers. Once visitors of these websites get to see the ads, they can become infected with malware.

The group would include used a zero-day vulnerability in Adobe Flash Player to infect computers. Before warns security firm Invincea . The company has a list of domains and data put online showing that the group since October 17 last year, "malvertising" is in progress. Offered to the infected ads on the websites show is include in "real time" on the available ad space.

According Invincea would malicious ads on CBS Sports, Russia Today, answers.com , Jerusalem Post, Match.comNews.com.au , search.aol.com and thesaurus.com have appeared. Furthermore, also webmail domains such webmail.nc.rr.com , webmail.windstream.net , mail.twc.com and webmail.earthlink.net for the overview. In total there are 51 different domain names.

"It is important to mention that the sites where the infected ads appear not know that their sites are used for distributing malware and largely also can not do anything," said the security company.

Wednesday, 28 January 2015

Visitors Porn Sites Attacked By Flash Player Leak


Visitors from different porn sites, including one that is on the Internet in the Top 1000 most visited sites are attacked by a leak in Adobe Flash Player which published an update until recent days. The attack took place through ads displayed on porn sites.

That says security firm FireEye. Once the ads were shown malware could be installed on the system in a vulnerable browser.To which websites are just the IT security officer does not know. However, the advertisements used a variant of the attack which was observed in the first instance. That first attack was carried out by the Angler Exploitkit while the new attack does not use this exploitkit.

The original Angler attack used some JavaScript and try to detect the presence of virtual machines and scanners, while the new variant no obfuscation used or analyzes the environment. The exploit for Flash Player in this case is loaded via normal JavaScript. The attack is successful then a variant of the Reveton ransomware-installed. Reveton locks the computer and that the user has committed a crime. In order to prevent criminal prosecution and to regain access to the system must be an amount of money to be paid.

Meanwhile, there is for all users released an update that fixes the leak. Through this page can be checked which version of Flash Player installed on your computer. The Finnish F-Secure let know that the Angler Exploitkit last week was the most popular exploitkit among cybercriminals. The virus fighter advises Internet users in addition to installing the update also to set click-to-play. In this case, the user must first click on a Flash object before it is loaded. In this way it can automatically be prevented infecting the computer via browser plug-ins.

Monday, 26 January 2015

Flash Users Attacked By Infected Ads


The zero-day vulnerability in Adobe Flash Player that this week was discovered and which is expected next week an emergency patch will be deployed against Internet via infected ads. Visiting a website that shows the infected ads with Internet Explorer or Firefox on any Windows version is basically enough to get infected with malware.

It does not matter whether a 32- or 64-bit Windows version used, as reported security firm Zscaler. The malicious ads would be distributed through ad networks and Adcash Oneclickads. As previously noted already infected computers part of a botnet, that the machine for advertising and click fraud efforts. "This is the first zero-day exploit for Adobe Flash Player this year and it's no surprise that it is spread via infected ads," said John Mancuso of Zscaler. Pending to update users get the advice to temporarily disable Flash Player.