Showing posts with label Network Attack. Show all posts
Showing posts with label Network Attack. Show all posts

Wednesday, 18 November 2015

Public Wifi Especially Risky In Airports And Hotels



Most of unsafe open Wi-Fi networks can be found in airports and hotels. There is the chance that you log in to a hotspot of a malicious greatest. That's Janne Pirttilahti, Director of Product Management Next Gen Security at F-Secure, said Tuesday.

Pirttilahti demonstrated during Wifi Now in Amsterdam how easy it is to create a fake hotspot and people in the area to let the network use with the aim to steal private information from them.

Hotels And Airports

Hotels and airports are the easiest locations to set up fake hotspots around because there are a lot of businessmen or people who have to spend money, says Pirttilahti talking. "There are interesting targets, while falls in those locations do not like someone pops open a laptop with antennas. Sometimes it can even from a hotel room. But in a coffee shop is much faster suspicious."

Research by F-Secure among UK consumers also shows that many consumers are well aware of the risks they run if they use public Wi-Fi networks. A whopping 52 percent of consumers surveyed avoid using public Wi-Fi networks because they are afraid that their personal information into the hands of hackers.

VPN Connection

59 percent says open Wi-Fi networks not to use it because they are afraid of viruses or malware. Still, says nearly one in every three month to use at least once and sometimes daily public wifi networks. The advice is to at public Wi-Fi networks in any event using a VPN connection.

Saturday, 14 November 2015

Leak In Smart TVs Vizio Gave Attacker Access To Home Network


More and more TVs equipped with so-called 'smart' functionality, but sometimes at the expense of security and privacy, so researchers at anti-virus company Avast investigated. The researchers looked at a smart television manufacturer Vizio, which recently due to transmission of the viewing habits came from users in the news.

During the study, there are several security issues with the television discovered. So the TV will connect to the domain control.tvinteractive.tv, but in doing so does not check the offered certificate. The researchers were thus able to perform a man-in-the-middle attack. Ultimately, they know how to physically examine the device to gain root access.

This ultimately gives enough information to send via the man-in-the-middle-server commands to the television, which then the home network can be attacked. It also appears that the television transmits information on viewer behavior, regardless of whether users with the terms of use and privacy policies are agreed at the time that the television was first established. After being informed by Avast Vizio has corrected the vulnerability. In addition, users can transmit their viewing via an option in the menu off.

Thursday, 12 November 2015

US Warns Of 'Cyber Incidents' By Webshells


The Computer Emergency Readiness Team of the US Government (US-CERT) organizations warned of "cyber incident" caused by webshells. A Webshell is a script that sets an attacker on a Web server, so that he can control the machine remotely.

Through the infected Web server can then be attempted to attack systems on the internal network of an organization. Using webshells by Advanced Persistent Threat (APT) and criminal groups has led to major cyber incidents, according to the US-CERT. Webshells can be written in different languages, such as PHP and ASP. Perl, Ruby, Python and Unix shell scripts are also used.

To install the Webshell an attacker must first find already existing vulnerabilities, such as the content management system (CMS) or the Web server software. Once the Webshell is uploaded it can be used for various purposes, such as to steal login credentials, install additional malware, as a communication channel to control systems on internal networks which are not connected to the Internet and as a command and control infrastructure, for instance in the shape of a botnet.

To avoid installing a Webshell advises the US-CERT to keep applications and operating system up-to-date, use reduced duties on the Web server, a demilitarized zone (DMZ) between applying the corporate network and online systems, a reverse proxy to use, scanning systems and applications for vulnerabilities and validating user input.

Wednesday, 4 November 2015

Forum Software vBulletin Close After Hacking Vulnerability


The makers of the popular forum software vBulletin released a security update for a vulnerability in the software and reset the passwords of almost 345 000 users forum yesterday after an attacker managed to hack the vBulletin.com website.

According to the developers has a "sophisticated attack" occurred on the network. In addition, the attacker may have access to customer IDs and received encrypted passwords. As a precaution, it is now decided by all users on the official support forum of vBulletin to reset the passwords. According to the company's statistics, the forum has nearly 345 000 users.

Further details of the attack are not shared. Ten minutes after the news about the attack and password reset vBulletin installed a new communication line, this time on a vulnerability in the software. The Communication put the developers that they have been notified of a vulnerability in vBulletin 5 Connect 5:14 version to 5.1.9 and therefore a security update has been rolled out. Administrators are advised to install the update. Whether the update fixes the leak which has attacked the vBulletin forum software developer does not know.

Saturday, 31 October 2015

New Pineapple For Wifi Hacking Announced



A tool that researchers use frequently on television and in workshops to demonstrate the risks of Wi-Fi networks, the WiFi Pineapple and will be releasing a new version of the versatile device. That the developer via Twitter announced.

The WiFi Pineapple is a small device that has multiple Ethernet ports, a Wi-Fi and a USB connection and runs on the Jasager firmware. This firmware is based on OpenWRT, a popular alternative for many router operating systems. What the pineapple makes it ideal for testing applications, Wi-Fi networks and WiFi users is how it occurs as an access point.

Many smartphones, laptops and tablets have network software that automatically connect to access points which was signed earlier. The pineapple says these devices against which it is one of these access points, after which the victim of the device connects automatically. Then all WiFi traffic passes through the pineapple and can be stored, analyzed and manipulated.

Besides demonstrations of the tool is also used by penetration testers, law enforcement agencies, the military and government, so let Hak5 know, the company that develops the pineapple. The WiFi Pineapple Mark V is the latest model, but is no longer offered by Hak5. Namely the reason is a new model. Details are still missing, except that the new Pineapple "soon" appears.

Thursday, 29 October 2015

New Browser-Attack Reveals Surfing Behavior On Websites



One researcher has demonstrated a new browser attack that websites can retrieve the browsing habits of visitors, as well as the browsing history before the user is deleted. The attack uses HTTP Strict Transport Security (HTST) and Content Security Policy (CSP).

HSTS allows websites visited to visit via HTTPS only over HTTPS, even though HTTP is introduced into the address bar.The browser in this case captures the user's command and turns off automatically in HTTPS. CSP is a measure to prevent cross-site scripting. The attack this weekend during the ToorCon conference was demonstrated by researcher Yan Zhu(pdf).

Attack

In order to carry out the attack must embed a malicious page images from a website-HSTS. However, the browser will attempt to load the images via HTTP. CSP is then used to prevent HSTS ensures that they are loaded via HTTPS. In the case CSP an image block this causes an error message. Based on the time it takes for the error message can be determined whether the Internet user HSTS the website from which the image was attempted to load previously visited.

Besides the explanation in her own weblog has Yan Zhu also a demonstration page put online that only works with Chrome and Firefox. Additionally, the HTTPS Everywhere browser plug-in must be disabled. Could be found only previously visited websites that make use HSTS. On Hacker News suggested that websites can avoid the attack by their domain to the HSTS preload ruse to add like. In this case the hardcoded domain name included in the browser so that is visited only via HTTPS. An employee of Mozilla calls it on Reddit a "smart attack" and states that the browser developer looking for a solution.

Tuesday, 27 October 2015

Ransomware Threatens With Publishing Encrypted Data


In Germany, new ransomware surfaced that not only encrypts files, but the system locks and threatens private data, to publish photos and videos on the Web. Chimera as the ransomware is called, focuses on companies.

Via so-called vacancies, job applications, contracts and applications are businesses approached. In the e-mails reference is made to a file on Dropbox for further information. This file is the ransomware which kinds of files on the computer encrypts. Furthermore Chimera searches for files on network drives to encrypt. The system then also be locked and a message appears with instructions.

The instructions let victims know that they have to pay almost 2.5 bitcoin, what with the current exchange rate is about 635 euros. The report furthermore states that if there is no paid personal data, photos and videos will appear with the victim's name on the Internet. Traditional ransomware encrypts files often alone. Threatening to steal and publishing of data is therefore not new. Chimera or eventually the data put online as claimed is unknown, said Botfrei.

Sunday, 25 October 2015

Students Accused Of Hacking Into US School System



Three pupils have been indicted in the United States for hacking into the system of their school. The boys would have adapted their own figures and the roster of some 300 students have changed. The arrest of the three came after months of police investigation.

The study, which began in July, showed that the timetables were revised and numbers of two students. However, the three students denied being guilty. Police suspect that one of the now detained students had joined a hardware keylogger on a computer keystrokes which were stored. The student would have won if the passwords and user names of dozens of teachers and administrators.

During a search at one of the students, the keylogger was found, and reporting Newsday and NY Daily News. On the device were the credentials of the school staff. The school late in a statement on its website that the changes to the figures and schedules, after being discovered, have been immediately canceled.

Botnet Security Cameras Used For DDoS Attack


It is not just routers and computers that need to be secured, because researchers have identified a botnet of hacked about 900 security cameras discovered that was used to carry out DDoS attacks on a cloud service. This was reported by security firm Imperva.


The cameras are located in various countries, but were concentrated primarily in India. Investigators found the cameras malware that searches for certain devices via Telnet and SSH. This relates to devices on BusyBox run a Linux distribution for embedded systems, and are vulnerable to brute force attacks. In this case it appeared that all hacked cameras were accessible via the default login password. The researchers therefore call on administrators to always change default passwords, whether it's a router, access point or security.

Friday, 23 October 2015

Infected Ads With T-Online And eBay Germany


On the website of the German ISP T-Online and eBay Germany are infected ads appeared which attempted to infect visitors with malware. Also received several other German sites to do with the infected ads but eBay.de and T-Online.de are respectively 131 million and 79 million monthly visitors by far the biggest websites were affected.

Through the ads were visitors silently redirected to pages with the Angler- and Neutrino-exploit kits. This exploit kits do include using known vulnerabilities in Internet Explorer and Adobe Flash Player. These are known vulnerabilities. Users whose software was up-to-date therefore were not at risk.

What malware was installed on the attack late anti-malware company Malwarebytes not know. The ad network which spread the infected ads would meanwhile have intervened, but analyst Jerome Segura does not rule out that the attack campaign through other ad networks will continue.

Monday, 12 October 2015

Companies Hacked Via Leak In Cisco Web VPN


Attackers abuse a vulnerability in the Cisco Clientless SSL VPN to hack into companies and organizations, warns security firm Volexity. The Cisco SSL VPN Service, also referred to as Cisco Web VPN, is a web-based Virtual Private Network (VPN) to employees via their browser to access the corporate network and servers can get.

To log in to the VPN, users must enter a user name and password. A vulnerability in the Cisco Web VPN, which was patched in October 8, 2014, makes it possible to add malicious code to the login page. Remote attackers can do this and have developed a password or other credentials required. Through the malicious code that is placed on the login page it possible to store the credentials of users, which the attackers themselves can then login.

Cisco warned in February this year for attacks where the vulnerability was used, but that still take place, according Volexity. Medical companies, universities, academic institutions, manufacturing companies and think tanks could now be attacked using this method worldwide.

According to the security company, it is not clear whether the vulnerability has been used for all attacks. It is not excluded that some other attacks observed the attackers themselves already had access to the login page and so could add malicious code. It does not matter if companies use two-factor authentication since the second code to be entered when logging can be intercepted using the custom login page.

Kaspersky Close Leak That Windows Update Attacker Left Block



The Russian anti-virus firm Kaspersky Lab has closed a vulnerability in Kaspersky Internet Security poem through which attackers could simply block users' access to Windows Update, the Kaspersky website and other websites, as well as the servers of e-mail provider.

The vulnerability was discovered by Google researcher Tavis Ormandy, who earlier other serious problems in the security of Kaspersky Lab laid bare. Earlier Ormandy also found all vulnerabilities in the software from Sophos, ESET and Avast.The problem with the Internet Security package has been caused by a component called the "Network Attack Blocker".This component aims to protect the computer from malicious network activity. Ormandy discovered that it is actually nothing more than a simple stateless packet filter 'that in the event of an attack on the IP address put on a blacklist.

This design made ​​abuse possible, according to Ormandy. For example, the component was found to recognize a forged TCP packets. Also, the filter did not appear to understand the status of the application layer if there is a packet was received. An attacker could create simple abuse of this by sending the signature of an attack to a Kaspersky user, the IP address was falsified. According to Ormandy, the attacker could, for example windowsupdate.microsoft.com can specify as the sender. The Network Attack Blocker could then access to Windows Update are blocked, preventing users from Windows updates would receive more.

The second problem is a possible such scenario, then only via e-mail. In this case, the security component would have blocked user access to its server. Ormandy warned Kaspersky Lab on September 11, after the update was released last Thursday. Then the Google researcher has decided to details of the vulnerabilities disclose.

Saturday, 10 October 2015

10,000 Netgear Routers Hacked Via Zero-Day Flaw


More than 10,000 routers network manufacturer Netgear been hacked via a zero-day vulnerability for which no security update is made ​​available. That says Alexandre Herzog of the Swiss security company Compass Security. Through the vulnerability could allow an attacker without a valid password or user access to the admin panel.

The problem was reported to Netgear in July. In September, the network manufacturer announced that it had developed firmware for routers in which the problem was solved. It was, however, this is a beta version. Netgear did however not know when the final version would appear. On September 29, however, made another investigator same security issue known.Then Herzog decided Tuesday to place the vulnerability of details on the company website and Full Disclosure mailing list. Netgear user then let the mailing list know that he was hacked by the leak.

Herzog then asked for information from the victim, to step up the pressure on the Netgear. From the user's information appeared that his router was adapted so that all DNS requests were forwarded to the server of the attacker. The attacker would the user will have to send them to phishing sites or sites containing malware. Researchers from the Swiss security managed with a server that is to make up for the control of the infected routers compound was used. Then they found data indicating that more than 10,000 routers via the vulnerability were hacked, Herzog as late as compared Threat Post know.

The Swiss government GOVCERT would now be trying to get the server from the air and warned the providers of most victims. Which would are located mainly in the United States. To attack the vulnerability, the attack must be run from the internal network. In case the remote management is enabled, this can also be done directly from the Internet. Remote administration is not enabled by default. The problem is present in Netgear routers with the router firmware: N300_1.1.0.31_1.0.1.img and N300-1.1.0.28_1.0.1.img. This firmware is used among others in the WNR1000v4 Router.

Friday, 9 October 2015

Serious Leak Showed Hacker Outlook.com Account-Hijacking



Microsoft has a vulnerability in the login mechanism for Outlook.com poem allow an attacker accounts of the webmail service, and possibly other Microsoft services could hijack. Just visiting a malicious website or see getting a malicious ad with a login account for this was sufficient, says researcher Wesley Wineberg of security SYNACK.



He discovered on August 23, the vulnerability in the login mechanism of Live.com and now has his research made ​​public.Login.live.com the authentication system that Microsoft uses to allow users to Outlook.com to log in and let other Microsoft services. The problem Wineberg encountered is called cross-site request forgery (CSRF). These are performed in a user's name unauthorized actions.

Owners of a Microsoft account, that Outlook.com is used, apps give access to certain things, such as the address book or profile information. The user must confirm this entry itself and also get to see exactly clear what the app will access it. Wine Berg developed an attack in which CSRF is used to carry out this operation in the user's name.

In this case, the user would grant permission to an app that was given full access to the account. The CSRF code would thereby be executed automatically when a user visits a malicious website logged by Microsoft or view a malicious ad got.After being informed three weeks, the vulnerability was later closed by Microsoft and Wineberg received a reward of $ 24,000.

Tuesday, 29 September 2015

Hilton Investigates Possible Credit Card Theft In Hotels


The famous Hilton hotel chain has launched an investigation after attackers may have stolen the credit card details of customers. IT journalist Brian Krebs was tipped by sources with five banks that fraud pattern with stolen credit card information to different hotels from the Hilton was traceable.

According to the sources involves various chains of Hilton in the United States, including the luxury Waldorf Astoria Hotels & Resorts, as well as Embassy Suites, Doubletree and Hampton Inn and Suites. How many hotels there may be hacked is unknown. The sources also stated that the incident possibly dating back to November 2014 and may still be going on.

In the past, criminals have often at hotels struck, for example, through gift shops and restaurants. By hacking the POS systems of these spots can be installed malware to steal credit card information along. The stolen data is then fraudulently. In May, it appeared that the Hard Rock Hotel and Casino in Las Vegas in a similar way to credit card information was stolen.

Monday, 28 September 2015

Man Charged Steal $ 600,000 Via E-mail


In the United States a 28-year-old man charged with steal more than $ 600,000 through e-mail and an attempt to similarly $ 1.3 million prize. The man is suspected to have emails sent to companies with payment orders for the finance department.

The emails seem to stop coming to the company and include a PDF document with instructions for payment. To the e-mail appear to have legitimate domain names were registered that looked very much like the domain names of the attacked companies. This type of fraud is called "Business E-Mail Compromise" scam. The suspect was in the crosshairs of the FBI after two businesses were defrauded in this way. Both companies made ​​over $ 100,000. The used PDF files were sent to the accused traced suspect. The suspect is guilty, if to a prison term of up to 30 years and a fine of $ 1 million will be condemned.

Worldwide, there are, according to the FBI by now more than 8,000 companies ripped off in this way, of which 7,000 in the United States. The damage amounted to $ 800 million, again the majority, $ 750 million in the US In addition to the 800 million dollars that the FBI recorded in the first eight months of this year, other investigative agencies have a loss amount of $ 400 million observed, causing total damage at $ 1.2 billion comes out.

US Navy Ships Will Protect Against Cyber Attacks


The US Navy is working on a system to protect ships against cyber attacks, as more and more physical systems accessible via the Internet. The system is called Resilient Hull, Mechanical and Electrical Security (Rhimes) and to prevent malicious attackers to take over or turn off the mechanical and electrical control systems.

"The purpose of Rhimes is to repel cyber attacks," said Rear-Admiral Mat Winter. "This technology helps the Navy to protect the ship's physical systems, but it can also have important applications in the protection of the physical infrastructure of our country." The system must eventually prevent attackers from accessing the programmable logic controllers (PLCs), which are in communication with the physical systems of the ship.

To protect the ship systems used different techniques Rhimes to stop entire classes of attacks. In addition, the security system ensures that every controller just slightly different. An exploit for one controller will then no longer work for the other controllers. This technique can be used according to the Navy also, for example, factories, automobiles and airplanes. When Rhimes will be launched was not disclosed.

Friday, 25 September 2015

Cisco Launches Scanner For Finding Hacked Routers


Cisco has a scanner launched enabling organizations hacked routers can be found on their network where the firmware is updated. Attackers appear to hack through stolen passwords or physical access Cisco routers and install a custom operating system.

This custom operating system is called the SYNFUL Knock-malware. Through the malware continue to keep the attackers access to the corporate network, even resetting the router. Cisco recently conducted a scan on the internet and discovered 199 IP addresses that were infected with the SYNFUL Knock-malware. Now, Cisco has developed a tool that allows customers hacked routers can find on their own network. It is in this case only routers that are infected with the SYNFUL Knock-malware.

The tool does come with a manual. The rotation of the tool via network address translation (NAT) can affect the accuracy of the tool and make sure the tool hacked routers can not detect. Cisco advises to carry out the tool from a network location where there is no NAT between the scanning system and the routers.

Monday, 21 September 2015

Cisco Scans The Internet On Hacked Routers


Cisco has teamed up with the Shadow Server Foundation the past few days the Internet scans on hacked Cisco routers, which eventually yielded 199 suspicious IP addresses. Recently warned both Cisco and security for the SYNFUL Knock-malware.

Attackers appear to hack through stolen passwords or physical access Cisco routers and install a customized version of the operating system; the SYNFUL Knock-malware. Through the malware continue to keep the attackers access to the corporate network, even resetting the router. By scanning the Internet Cisco affected customers can now warn. The scan yielded 199 IP addresses that behavior that matches the SYNFUL Knock-malware.

The number of IP addresses varies, as found in a scan yesterday there 163 IP addresses. Perhaps the 'disappeared' 36 routers were cleaned or online. Most of the infected routers are located in the United States. It involves a total of 65 IP addresses. Remote tracking India (12), Russia (11) and Poland (9). Organizations are advised to identify hacked routers and the infection as quickly as possible to remove. Cisco recently published explanation how the infected routers can be found and cleaned up.

Friday, 18 September 2015

Cisco: Routers Hacked Via Stolen Passwords




In recent days, much has been written about attacks on Cisco routers with the firmware of the device was replaced so that attackers had permanent access to the corporate network. In total, worldwide, 79 found such hacked routers.

Cisco had already before the attack warning, but now has shown again that the attackers do not use vulnerabilities in the products of the manufacturer's network. To access the routers are used stolen credentials, says Omar Santos Cisco. Another possibility is that the attackers have physical access to the equipment, and thus the control system may be replaced by a modified version.

"As the technology evolves, so does the nature and complexity of attacks," Santos notes. According to him, this is an example of the "evolution of attacks" in which attackers try to steal login details and then unnoticed to carry out an attack so they keep longer time access to the area surrounding the target. Cisco made ​​the following video explaining how this particular attack is to detect and prevent.