Showing posts with label Network Security. Show all posts
Showing posts with label Network Security. Show all posts

Thursday, 5 May 2016

German Government Launches Test Plan For Security Routers


In order to ensure that routers that individuals and small businesses purchase are safe, the Bundesamtes für Sicherheit in der Informationstechnik (BSI), part of the German Ministry of the Interior, today a comprehensive test plan ( pdf ) launched broadband routers.

The test plan, especially for Internet service providers and manufacturers intended, which describes a secure router to meet.In this way, potential buyers can more easily compare models in the field of security with each other. According to the BSI, the security of a router, an important factor when choosing a particular manufacturer or type. The German federal government has recently abolished the so-called router obligation. Thereby German internet users can choose yourself which soon modem and router that they want to use their broadband connection.

"Routers are a central part in the digitalization and networking. They are the heart of the home network, but protect at the same time against Internet threats. The abolition of the router obligation have internet August this this year more choice in choosing their router. users should make use of this by looking at the safety when choosing a router, "said Arne Schönbohm, head of the BSI.

In the test plan different parts are discussed, such as the presence of security measures. Thus, each router must sort the BSI have a firewall and there should be no default port forwarding enabled. In addition, made several recommendations, such as the presence of an automatic update feature. Furthermore, the test plan contains examples of common vulnerabilities and attack scenarios.

Thursday, 11 February 2016

Google Stops From 2017 With Flash Ads


From January 2017 Google stops displaying Flash ads on their own ad networks, such as the Google Display Network and DoubleClick, as the Internet giant has over Google Plus disclosed. According to Google, it's important for advertisers to switch to HTML5 ads, so many people can be reached.

To accelerate this process will AdWords and DoubleClick Digital Marketing from June 30 to accept new Flash ads this year.From January 2, 2017 Flash ads will no longer be on the Google Display Network are displayed via DoubleClick. Google warns advertisers that they should have converted their ads to HTML5 for these dates. For now, the new measure does not affect video ads created in Flash.

Google has long been working to make Flash unnecessary. As YouTube videos are automatically played through HTML5. In the case of Flash ads that are distributed through AdWords, which are automatically converted to HTML5 since February last year. Since September 1st of last year, most Flash ads automatically in Google Chrome paused .

Last year, also called Alex Stamos, the new Chief Security Officer (CSO) of Facebook, which with Adobe Flash technology to stop , so that it can be switched completely on HTML5. HTML5 is natively supported by modern browsers and allows playback of videos and other "rich content" without installing additional plug-ins possible.

Wednesday, 18 November 2015

Public Wifi Especially Risky In Airports And Hotels



Most of unsafe open Wi-Fi networks can be found in airports and hotels. There is the chance that you log in to a hotspot of a malicious greatest. That's Janne Pirttilahti, Director of Product Management Next Gen Security at F-Secure, said Tuesday.

Pirttilahti demonstrated during Wifi Now in Amsterdam how easy it is to create a fake hotspot and people in the area to let the network use with the aim to steal private information from them.

Hotels And Airports

Hotels and airports are the easiest locations to set up fake hotspots around because there are a lot of businessmen or people who have to spend money, says Pirttilahti talking. "There are interesting targets, while falls in those locations do not like someone pops open a laptop with antennas. Sometimes it can even from a hotel room. But in a coffee shop is much faster suspicious."

Research by F-Secure among UK consumers also shows that many consumers are well aware of the risks they run if they use public Wi-Fi networks. A whopping 52 percent of consumers surveyed avoid using public Wi-Fi networks because they are afraid that their personal information into the hands of hackers.

VPN Connection

59 percent says open Wi-Fi networks not to use it because they are afraid of viruses or malware. Still, says nearly one in every three month to use at least once and sometimes daily public wifi networks. The advice is to at public Wi-Fi networks in any event using a VPN connection.

Sunday, 8 November 2015

American Library Will Distribute USB Sticks With Privacy OS


The American library that previously defied all the Department of Homeland Security to run a Tor server does again of himself speaking, there is in fact decided to show a film about Snowden and USB sticks with the privacy operating system Tails to distribute to library visitors.

It is the Kilton Public Library in West Lebanon (New Hampshire), a community with 3500 inhabitants. The library was in the news because it had decided to set up a Tor server. The Tor network allows users to hide their IP address and visit censored websites. After an e-mail from the Department of Homeland Security and concerns of the police and the local administration, the library decided to temporarily stop the Tor server, but came back to that later turned server back on.

Among other things Edward Snowden responded to the decision by the library. Due to the positive reactions and tweet Snowden, the library authorities now decided next Tuesday Citizenfour, to show the documentary about Snowden, reports Valley News. In addition, USB sticks will be distributed to the privacy OS Tails. Tails (The Amnesic Incognito Live System) is a complete operating system that can be used from a DVD or USB stick. It is based on Debian and contains various tools to access the Internet anonymously. For example, among other things, made ​​use of the Tor-network.

Thursday, 5 November 2015

Firefox 42 Display Changes Some SSL Certificates


In the latest version of Firefox, Mozilla has decided to offer some SSL certificates for different weather and the warning for HTTPS sites that have content via HTTP. In total, the four visual customization that users via the address should inform the HTTPS status.

The first concerns the so-called "domain-validated 'certificates. When domain-validated (DV) certificate, only the control checks on a particular domain. Firefox gave this SSL certificates previously via a gray lock icon in the address bar. Now this lock icon turned green. In addition, Firefox used for websites with mixed content two icons. In the case of mixed content display HTTPS websites also content over HTTP, which is a security risk. Firefox 42 now uses one icon that warns of mixed content. In addition, there are three different states for the display of mixed content.

Vulnerabilities

Yesterday reported all about the new Firefox version and reported that no vulnerabilities were fixed in the browser. At the time of writing, the Mozilla Security Advisories for Firefox are not updated and also made ​​no mention of the security fixes. Which are now published online. It appears that Firefox 42 in total 23 vulnerability fixes, including eight critical holes. Through this critical vulnerabilities an attacker can install malware on computers where only visiting a hacked or malicious website is enough. The latest version is basically updated automatically.

Wednesday, 4 November 2015

British Government Would Want To Prohibit End-To-End Encryption



The British government should IT companies to commit to no longer offer encryption services even where they have no access to the data. The bill will be presented tomorrow, as claims the Daily Telegraph. According to British newspaper allowed companies like Apple and Google will soon no longer offer advanced encryption which even they can not decrypt.

The UK government is not going to ban encryption in its entirety, because it plays an important role in protecting data. It is especially end-to-end encryption, where only the sender and recipient can read the message that the authorities concern. The bill would require IT companies soon to always be able to access the customer data.

"The government is clear that we must find a way to collaborate with industry and ensure that with clear monitoring and a robust legal framework, the police and intelligence services access to the content of the communications of terrorists and criminals can get, to resolve such matters and police to prevent crime, "said a ministry spokesman. He says that this means that companies communicate on their networks should be able to approach if they get a warrant.

Researchers Bypass Microsoft's EMET Security


Researchers have succeeded in the EMET security tool to circumvent Microsoft by a Windows Component are used to make 32-bit software on a 64-bit operating system running. EMET stands for Enhanced Mitigation Experience Toolkit (EMET) and provides Windows and applications from an additional layer of security.

This extra layer to make it harder for attackers to attack both known and unknown vulnerabilities in the operating system or installed programs or plug-ins. Researchers at Duo Security, however, found a way (pdf) to bypass the security of EMET.The attack is possible by WoW64 subsystem of Windows.

This system acts as a compatibility layer between 32-bit software and 64-bit Windows versions. While most Windows versions are now 64-bit, most Internet users still use 32-bit browsers. Research by Duo Security found that 80% of browsers on 64-bit Windows versions is a 32-bit process. For these browsers on a 64-bit system to use the "Windows on Windows" (WoW) used low.

The security measures EMET offers in WoW64 subsystem less effective. In the case of the attack Duo Security developed there may eventually be a 64-bit version will be attacked by a DLL, while WoW64 ensures that EMET only protects the 32-bit version of the file. To remedy this problem, Microsoft would have to make major changes to the operation of EMET.

Advice

Despite the successful attack the researchers state that EMET is still an important part of any security strategy. They also recommend the use of 64-bit software, because some parts of this abuse makes little trickier and other offers security advantages. Users and administrators also be advised where possible, true 64-bit software to run on 64-bit Windows versions.

Sunday, 25 October 2015

Students Accused Of Hacking Into US School System



Three pupils have been indicted in the United States for hacking into the system of their school. The boys would have adapted their own figures and the roster of some 300 students have changed. The arrest of the three came after months of police investigation.

The study, which began in July, showed that the timetables were revised and numbers of two students. However, the three students denied being guilty. Police suspect that one of the now detained students had joined a hardware keylogger on a computer keystrokes which were stored. The student would have won if the passwords and user names of dozens of teachers and administrators.

During a search at one of the students, the keylogger was found, and reporting Newsday and NY Daily News. On the device were the credentials of the school staff. The school late in a statement on its website that the changes to the figures and schedules, after being discovered, have been immediately canceled.

Botnet Security Cameras Used For DDoS Attack


It is not just routers and computers that need to be secured, because researchers have identified a botnet of hacked about 900 security cameras discovered that was used to carry out DDoS attacks on a cloud service. This was reported by security firm Imperva.


The cameras are located in various countries, but were concentrated primarily in India. Investigators found the cameras malware that searches for certain devices via Telnet and SSH. This relates to devices on BusyBox run a Linux distribution for embedded systems, and are vulnerable to brute force attacks. In this case it appeared that all hacked cameras were accessible via the default login password. The researchers therefore call on administrators to always change default passwords, whether it's a router, access point or security.

German Government Gives Safety Tips For Cloud Use


More and more people are making use of cloud services, which both benefits and risks entails. The reason for the German Federal Office for Information Security (BSI), part of the German Ministry of the Interior, to various tips to give.

While cloud providers are responsible for the safety and the use of cloud services is easy, data should not simply be placed in the cloud, says the BSI. So data can be sent unencrypted through which others can intercept and it is not always clear where the data is stored. Following several recommendations, however, can be made safely use the cloud, says the BSI. The department recommends that only access the cloud via a secure system.

It should be a secure password for cloud services and set login to the cloud via an unsecured Wi-Fi network can be avoided. In addition, operators must read the terms and conditions of the cloud service and figure out the location of the data centers used. In the case of sensitive or important information which should only be stored encrypted in the cloud.Finally, users must check how their data is deleted from the cloud. Some cloud providers store backups namely in different data centers.

Tuesday, 20 October 2015

Smart Kettle iKettle 2.0 Leaking WiFi Key


A smart kettle which it is possible to cook over the local Wi-Fi network water seems to leak the WiFi key. This has security researcher Ken Munro of the British Pen Test Partners discovered. The iKettle 2.0 is developed by Smarter kettle which is operated via the smartphone.

In the first version of the kettle was found that the device is vulnerable to an attack where the malicious attacker a Wi-Fi network setup. The kettle simply showed the SSID to use for authentication. Once the kettle with the malicious Wi-Fi network connection allows an attacker can retrieve via Telnet the WPA key of the original Wi-Fi network in plain text and connect with this.

Munro since the problems with the first iKettle in June demonstrated there is a new version appeared on the market, the iKettle 2.0. This version, despite the new version number with the same problems to worry, says Munro. Ascertaining the WiFi key would be especially easy when the Android app is used for operating the kettle, but the attack is also to perform in users of the iPhone app.

The researcher advises owners of smart kettle to turn it on only when water should be boiled and then off again.Furthermore, any update from the manufacturer must be installed directly. Also advised is not nonsensical 'Internet of Things' devices being connected to the home network, unless the security of the manufacturer has been tested and proven.

Friday, 16 October 2015

Experts Unveil Plan For Secure Wi-Fi Routers



A group of more than 260 experts, including TCP / IP inventor Vinton Cerf, have unveiled a plan for secure Wi-Fi routers, which ultimately should lead to a faster, better and safer Internet. "Right now there are hundreds of millions of routers with serious leaks," said Dave Farber.

Farber was the former chief technology officer at the Federal Communication Commission (FCC), the US telecoms regulator. He responded with the large group of experts on plans of the FCC. The regulator wants to use to adjust the rules for Wi-Fi equipment and other devices using radio frequencies. According to experts, these plans do not go far enough and they ensure that manufacturers can evade their responsibilities.

The experts therefore have a personal plan (pdf drafted) consisting of four points. Firstly, the source of Wi-Fi routers, open-source and are open to everyone. In addition, routers can be safely updated and the owner of the router must have control over them. Furthermore, manufacturers must within 45 days after being notified of updates for vulnerabilities come over the lifetime of the product, or five years after the router was last delivered.

Finally, the FCC must violating these rules can punish severely. So should be revoked for violations certification of the existing product and may be decided to certify products manufacturer no longer in severe cases. Additional questions to the experts that the FCC waive rules that conflict with open source best practices or ensure that manufacturers add undocumented code or use mechanisms through which users can not patch.

"We can not afford to let rot part of the infrastructure of the Internet. We have this proposal was made ​​because the wireless spectrum should not only be justified granted but must be used responsibly. By setting a minimum of openness which is used in the technology at the edge of the Internet, we can find any mistakes or cheating and quick fix, "said Vint Cerf, co-inventor of the TCP / IP protocol and therefore founder of the Internet.

Friday, 25 September 2015

Cisco Launches Scanner For Finding Hacked Routers


Cisco has a scanner launched enabling organizations hacked routers can be found on their network where the firmware is updated. Attackers appear to hack through stolen passwords or physical access Cisco routers and install a custom operating system.

This custom operating system is called the SYNFUL Knock-malware. Through the malware continue to keep the attackers access to the corporate network, even resetting the router. Cisco recently conducted a scan on the internet and discovered 199 IP addresses that were infected with the SYNFUL Knock-malware. Now, Cisco has developed a tool that allows customers hacked routers can find on their own network. It is in this case only routers that are infected with the SYNFUL Knock-malware.

The tool does come with a manual. The rotation of the tool via network address translation (NAT) can affect the accuracy of the tool and make sure the tool hacked routers can not detect. Cisco advises to carry out the tool from a network location where there is no NAT between the scanning system and the routers.

Monday, 21 September 2015

Cisco Scans The Internet On Hacked Routers


Cisco has teamed up with the Shadow Server Foundation the past few days the Internet scans on hacked Cisco routers, which eventually yielded 199 suspicious IP addresses. Recently warned both Cisco and security for the SYNFUL Knock-malware.

Attackers appear to hack through stolen passwords or physical access Cisco routers and install a customized version of the operating system; the SYNFUL Knock-malware. Through the malware continue to keep the attackers access to the corporate network, even resetting the router. By scanning the Internet Cisco affected customers can now warn. The scan yielded 199 IP addresses that behavior that matches the SYNFUL Knock-malware.

The number of IP addresses varies, as found in a scan yesterday there 163 IP addresses. Perhaps the 'disappeared' 36 routers were cleaned or online. Most of the infected routers are located in the United States. It involves a total of 65 IP addresses. Remote tracking India (12), Russia (11) and Poland (9). Organizations are advised to identify hacked routers and the infection as quickly as possible to remove. Cisco recently published explanation how the infected routers can be found and cleaned up.

Friday, 18 September 2015

Cisco: Routers Hacked Via Stolen Passwords




In recent days, much has been written about attacks on Cisco routers with the firmware of the device was replaced so that attackers had permanent access to the corporate network. In total, worldwide, 79 found such hacked routers.

Cisco had already before the attack warning, but now has shown again that the attackers do not use vulnerabilities in the products of the manufacturer's network. To access the routers are used stolen credentials, says Omar Santos Cisco. Another possibility is that the attackers have physical access to the equipment, and thus the control system may be replaced by a modified version.

"As the technology evolves, so does the nature and complexity of attacks," Santos notes. According to him, this is an example of the "evolution of attacks" in which attackers try to steal login details and then unnoticed to carry out an attack so they keep longer time access to the area surrounding the target. Cisco made ​​the following video explaining how this particular attack is to detect and prevent.

Thursday, 17 September 2015

Researchers Found 79 Cisco Routers With Custom Firmware


Worldwide, there appear to have been hacked 79 Cisco routers whose firmware is modified so that the attackers can still access the network. Which allow researchers from the University of Michigan, UC Berkeley and the International Computer Science Institute know.

This week security firm FireEye announced that it had discovered 14 routers where attackers replaced the firmware. How the attackers access to the routers were able to get is unknown, but according to FireEye is probably not using a zero day attack. Earlier also warned Cisco for these attacks and suggested that the attackers with valid credentials to gain access to the routers know.

Once the custom firmware is active can be accessed using special TCP SYN packets. The researchers used ZMap scanner to go through all the public IPv4 addresses on the Internet and to send these packets. A total of 79 routers discovered that responded to the packets, such as would be the case with the custom firmware. 25 of the routers are in the United States. Lebanon (12) and Russia (8) follow at a distance. The researchers are now working to notify all affected organizations.

Wednesday, 16 September 2015

Hacked Cisco Routers Equipped With Infected Firmware



Worldwide, several hacked Cisco routers discovered that the firmware was modified so that the attackers held permanent access to the network. That leaves the US security firm FireEye know. Recently warned even though Cisco for attacks through custom firmware.

The routers are detected hacked custom firmware in Ukraine, Philippines, Mexico and India. It involves a total of 14 devices. How the attackers access to the routers were able to get is unknown, but according to FireEye is probably not using a zero day attack. "It is believed that were the default login data set or to be discovered by the attacker to install the backdoor," said the security guard. The router would be an ideal target for further attacks because of its position in the network.

Once active it can through the backdoor different modules are placed on the router. For now goes to the Cisco 1841, 2811 and 3825 routers, but FireEye warns that other models are or will be attacked. Also expects the security guard that this attack method popular among attackers will be. Because the firmware is updated, the attackers retain, maintain access to the router, even though the device will restart. In addition, to detect the custom router-firmware difficult.

Thursday, 3 September 2015

Expert: Trackers Create Websites Painfully Slow


Trackers for ads and analyzing visitors are not only a privacy issue, they make websites also painfully slow which makes it sometimes seems that the time of the dial is back. This enables security expert Sean Sullivan of the Finnish anti-virus firm F-Secure.

As an example, Sullivan, the American site of Ikea, when nine different trackers rotate, according to data from Ghostery. In this case were authorized third party cookies. Sullivan then went to the Finnish website of Ikea, but did not allow cookies from third parties. In this case there were 11 trackers ago. In the case of third-party cookies had been granted, were charged a total of 49 trackers.

"If the trackers are allowed to place their cookies, they often charge more resources and slows down the browsing," Sullivan noted. "It is 2015, but many websites load as if it was 1999". The expert also advises to block third-party cookies in your browser. "The earlier trackers are disabled better Internet experience."

Friday, 28 August 2015

Google Chrome Will Pause Flash Ads


From September 1, Google Chrome will automatically pause most Flash ads, so has Google via Google Plus disclosed. In June, Internet giant had already announced that it wanted to pause certain plug-ins, including Adobe Flash Player, in order to reduce power consumption and load times.

Google has long been trying to make Flash redundant. As YouTube videos are automatically played through HTML5. In the case of Flash ads that are distributed via AdWords, which are since February this year automatically converted to HTML5.Google argues that advertisers with Flash ads are working have several options to ensure that their ads are still shown to Chrome users, such as automatically to HTML5 to put out or to do it yourself.

Last month, also called Alex Stamos, the new Chief Security Officer (CSO) of Facebook, which with Adobe Flash technology to stop so completely on HTML5 can be switched. HTML5 is natively supported by modern browsers and allows playback of videos and other "rich content" without installing additional plug-ins.

Friday, 14 August 2015

Cisco Warns Of Attacks Via Infected IOS Images


Cisco has warned businesses to sophisticated attacks against customers using the Cisco IOS software. The Cisco Internetwork Operating System (IOS) is the operating system installed on most network equipment from Cisco.

The attacks that are now observed know an attacker with physical access or administrator to get access to an IOS device.Then, the Cisco ISO is ROMMON image (IOS bootstrap) by a malicious image, so that the attacker maintains full control of the network device. In all cases, the attackers managed to sign with valid credentials of the administrator.

Through the upgrade mechanism they installed the malicious ROMMON image, after which the device was restarted. The advantage of this method of attack is that the attacker retain control of the device, even if it is restarted. Since upgrading the ROMMON image is a standard feature of IOS, there is according to Cisco not a vulnerability. Cisco has several documents about the attack and secure IOS put online and advises clients to go through it.