One of the US IRS Tax system last month attacked by identity thieves who attempted to retrieve PINs that tax could be committed. The attacks were aimed at a web application that allows taxpayers, after entering their name, social security number, address and date of birth, their Electronic Filing (E-File) PIN to retrieve.
This PIN can then be used to apply for the tax refund. The identity thieves used the information to other parties was stolen to retrieve the PIN. In total, with 464,000 unique social security numbers tried to grab the code, which was successful at 101 000 social security numbers. According to the IRS , there was an automated attack. The Tax Administration claims that no taxpayers' data through IRS systems are won. In addition, the IRS will notify all individuals whose data were stolen by other parties.
The well-known hacker Starbug During a conference on biometrics demonstrated how through 'selfies' PIN smartphone and other passwords can be retrieved. The reflection of the Phone screen in the person's eyes provides sufficient detail to check out the credentials.
The 'corneal (corneal) keylogger "(pdf) last year was already demonstrated by the research team of Starbug. An attacker who use a malicious app to access only the camera can be so many pictures of the user, for example, enters the password. Another possibility is that an attacker via a good camera remotely pictures of the eyes makes when the user is busy with his smartphone.
The method of attack was one of many who showed Starbug, reports Planet Biometrics. "Everything is for spoofing," as he announced. "I can fool all fingerprint sensors within two hours," says the researcher who earlier world was to circumvent Apple Touch ID. Despite the sensitivity of fingerprints known Starbug, in daily life also known as Tobias Fiebig, he also uses a fingerprint instead of a password for its own smartphone.
Chip manufacturer Qualcomm has developed a kill switch for smartphones that can lock the device at the chip level and will be applied by the software of the Czech anti-virus company AVG. The measure to protect consumers and their data in the event of a lost or stolen smartphone.
Safe Switch, as the technology is called, the device locks on the chip level. In addition, it protects users by encrypting data on the device. Any attempt to replace the SIM card, perform a factory reset or PIN to brute force makes the device temporarily unusable. After locking only the owner via a "master" PIN to unlock the device.
The technology will now be used in the applications of AVG and works on a select number of smartphones with Snapdragon chipsets. This week both companies demonstrated their solution. The cooperation should ensure that later this year an "end-to-end" business solution can be offered, says AVG .
Researchers have discovered a device that makes it possible to brute forcing the lock screen of iPhones and iPads. IP Box, as the device is called, would be used by telephone repairmen to bypass the screen lock of iOS. "This obviously has major implications for the safety and of course was something that we wanted to investigate and validate" said researchers MDSec .
They did eventually get to 200 pounds one of the devices. The IP Box appears to simulate via the USB connection to enter the PIN and also tries all possible pin combinations. According to the researchers, this has been known, but the device also works if the option is enabled to delete the data after 10 attempts.
"Our initial analysis indicates that the IP Box to circumvent the restrictions by making direct with the power of the iPhone connection and aggressively to break the flow after each unsuccessful PIN, but before the attempt is synchronized in the Flash memory." Entering a PIN would therefore take about 40 seconds. A four-digit PIN can therefore be outdated in some 111 hours.
The attack has been tested on iOS 8.1. An attack on iOS 8.2 will follow. The research would show that it is possible to have a leak was discovered last year, but this has yet to be confirmed. The researchers made the following video on YouTube in which the device and the attack will be demonstrated.
Programmers create code and hackers find errors in it and use them. Discovered a hole in the most widespread cryptographic the OpenSSL could potentially lead to data theft almost all Internet users.
Seventh of April came security bulletin CVE-2014-0160, from which it became aware of the continued existence of a critical vulnerability in the cryptographic package OpenSSL.
Found that implementation algorithms TLS and SSL are used today in most versions of OpenSSL properly handle expansion packs Heartbeat (because of what the error was called HeartBleed). This allows hackers to gain remote access to confidential information from RAM active network process outside the buffer.
An error in the system has learned the Finnish-American company Codenomicon, what hastened to inform the world through a special website heartbleed.com. Heart Bleed - is the name given error experts, loosely translated it means "bleeding heart."
Such dramatic name was not chosen randomly. An error was detected in the package heartbeat (heart beat, heart rate) used for fault detection and resource management server cluster. The result was a play on words in the heart of the leak occurred.
Surprisingly, the critical vulnerability did not notice for two years. It affects all versions from 1.0.1 to OpenSSL 1.0.1f inclusive and 1.0.2-beta1.
As a result of that error in them is not checked in the recording of the actual length of SSLv3. This allows you to read without authorization to 64 Kbytes of RAM process on the connected client or server for each request. In many cases this is enough to get the keys, passwords or other sensitive data. Vulnerable versions of OpenSSL cryptographic package from March 2012 are included in many distributions and BSD OS family of almost all branches of the Linux Debian, RedHat and Slackware.
The first error affects servers Apache, nginx, project Tor (via the web server https://www.torproject.org), as well as many websites that use the HTTPS, even if access to them is carried out by VPN.
Unlike all the other "helpers hackers» Heart Bleed intercepts encryption keys - the cornerstone of secure connections, which encrypts the data transmission between servers. By themselves, the captured data is not worth anything, because the same encrypted PIN bank card might look like, «dkgh # k87u». Without the key, which will allow to decipher the code, it's just a set of symbols. But if the key will be in the hands of criminals, then get the raw data for them there is no trouble.
The greatest danger lies in the fact that this hack does not leave absolutely no trace in the case of data theft is not possible to know about this.
It would seem, what's this, because such errors are almost every day. However encryption package OpenSSL - the most widespread in the world. It is used mostly in the Apache web server and nginx. According to research company Netcraft, on these architectures employ about 66% of all sites on the Internet. Thus, only every third site does not represent a potential threat in terms of data theft. Among the endangered sites include such popular services like Twitter, Dropbox, Yahoo!, Steam and others. OpenSSL packages are used to everything else for the operation of e-mail servers and diverse client software.
To determine the degree of risk of error Codenomicon tried to kidnap their own data as it would make professional hackers.
As a result, they managed to make an attack on their own servers, without leaving any traces. Using only a hole in the system, Codenomicon received encryption keys. Using them, experts have collected from servers usernames and passwords, correspondence employees through messengers and email, as well as confidential company records stored on your computer.
Of course, such a dangerous hole could not remain uncovered. As a result, on April 7 was released a new version of OpenSSL, in which the error is no longer present. However, a simple upgrade package is not enough. If criminals have stolen encryption keys, they can use them in the same way as in the previous version, and for security administrators need to get a new security certificates and to generate new keys.
Of course, for large projects should not worry, because the price of their negligence administrators too great. It can be assumed that the relevant work already done on the servers.
In Codenomicon even see the positive side of Heart Bleed: because administrators can not ignore the fact that hole detection, they have to update the system data encryption on their servers. Along with them are likely to be installed, and other updates that have been postponed for a certain period.
While common in the bulletin and news reports officially recommend the following steps:
Install a patched version of OpenSSL 1.0.1g or 1.0.2-beta2 or recompile OpenSSL package with key OPENSSL_NO_HEARTBEATS;
reissue the SSL-certificate;
lures (honeypot), simulating the presence of a vulnerable server package OpenSSL, and check to connect to them.
We recommend that if you do not use in public places WiFi network, then try to put this kind of functionality is temporarily closed. Personal use of computers when not readily allow strangers remote control of their computer to prevent personal information from being stolen. Once the leakage of information to remind consumers to timely remedy, keep relevant evidence, take the initiative to safeguard their rights.