Showing posts with label Pre-Installed Malware. Show all posts
Showing posts with label Pre-Installed Malware. Show all posts

Monday, 23 February 2015

Mozilla Is Considering Blacklist For Superfish Certificate


Mozilla is considering to put the Superfish certificate was installed on laptops from Lenovo on a blacklist.According to a discussion on Mozilla's Bugzilla where developers discuss issues and bugs in Mozilla software. By putting the certificate on a blacklist would user certificate warnings that are displayed when using the Superfish certificate can not ignore.

Through the root certificate that installs Superfish on the root store of computers, where all root certificates are stored, SSL connections can be intercepted. Superfish late because all SSL connections run through its own certificate. Researchers managed to crack the password using the private key of the Superfish certificate. This makes it possible in some cases to Man-in-the-middle attacks against systems that perform Superfish and certificate are active.

"Every certificate that is added to root stores by commonly used software and whose private key is known, is a risk," said Gervase Markham on Bugzilla. He notes that the behavior of software installation certificates or not install on computers can change. A program can one week show no suspicious behavior and that a week later do it again. "Without extensive research, we do not know exactly how they work, and in what cases can modify software root lists and also what root lists."

Although Mozilla employees were initially quite hesitant to put the certificate on the blacklist, the decision by Microsoft to the Superfish application and the certificate by using Windows Defender and Security Essentials to remove changed this. "This paves the way for us free to revoke the certificate," said Mozilla's Richard Barnes . Since Microsoft already has the certificate on many computers removed the impact of any blacklisting will therefore be easy. "It just adds to the disinfection," Barnes continues. However, if and when the certificate on the blacklist will not yet decided.

Weak "Superfish Certificate" Found In More Software


It is not just the owners of a Lenovo laptop that ran through the Super Fish-adware risk that their SSL traffic was intercepted, also all kinds of other programs using the same kind of certificate. That security researchers discovered Marc Rogers and Filippo Valsorda , both working for CloudFlare. The certificate used Superfish was from Komodia, an Israeli company.

The company shows the framework that for Superfish also used to have used other software. This relates to Keep My Family Secure, Easy hide IP Classic, Lavasoft Ad-aware Web Companion, Staffcop version 5.6 and 5.8, Kurupira Webfilter and Qustodio's parental control software. Also hide-my-ip is called by Rogers, only this software does not use SSL man-in-the-Middle and the certificate used is slightly different with the other programs. Yet it still uses an unrestricted root certificate with a simple password in plain text. Furthermore, the certificates Komodia for these programs used weak and the password is always Komodia.

"I think it's safe to assume that every SSL interception product sold by Komodia or Komodia SDK is based on the same method will be used," said Rogers. This means that the dangerous certificates are not only restricted to the laptops from Lenovo. Everyone who has come into contact with a product or Komodia parental control software installed check that it is not at risk.

"This problem is much bigger than we thought," warns Rogers. By using weak certificates, an attacker can eavesdrop on traffic or manipulate, without requiring users to see this. Even if the SSL connection is checked, the user sees only the strength of the connection between the Komodia software and its browser, and not the connection which goes over the internet. Users can use this page to check if it is installed on their computer, one of the Komodia certificates.
Superfish

Meanwhile Superfish puts the blame down to Komodia. The company leaves opposite the Associated Press that the vulnerability was inadvertently caused by a third party in the software. Superfish CEO Adi Pinhas also denounces the "false and misleading messages" in the media.

Researcher Late MITM Attack With Superfish Certificate See


An American security researcher demonstrated how he set up via a malicious WiFi network and the Superfish certificate Lenovo users may attack. Previously showed researcher Robert Graham already see how the password cracked that the private key of the Superfish certificate used.

Something for which he needed about three hours. Then he wanted to demonstrate that an attack with the obtained certificate would not only theoretically, as the CTO of Lenovo claimed, but also practical. For this, Graham chose as a hardware Raspberry Pi2 combined with Alpha-WiFi adapter. Through " RPI Wireless Hotspot "he changed the Raspberry Pi2 into a wifi hotspot, while sslsplit to perform the Man-in-the-middle attack used. In total, cost of setting up the hotspot also three hours.

Graham leaves on his blog how a simulated user via its Wi-Fi hotspot is internet banking can be intercepted, even though the user gets when visiting his bank site to see a valid SSL icon. According to Graham he used for performing the attack only commonly available tools. "The only special feature is sslplit, but it is a tool that companies use often for security purposes, and does not have a special hacking purpose. '" The researcher therefore concludes that this attack is really practical and not just theoretical.

Saturday, 21 February 2015

Lenovo Warns Customers For Super Fish-Adware


Lenovo has a security bulletin released which warns customers for the Super Fish-adware that was installed previously on laptops. According to the manufacturer discovered several vulnerabilities in Superfish, including the installation of a self-signed root certificate.

Consumers can remove Superfish, but Superfish certificate but will remain on the system. Since Superfish according Lenovo SSL traffic intercepted this is a "security concern". Therefore, the manufacturer removal instructions put online, and a list of vulnerable laptops. These laptops in E, Flex, G, M, S, U, Y Yoga and Z-series that are delivered between September 2014 and February 2015. Together account for more than 40 models.

Customers who leave running the certificate in certain scenarios, for example when an open Wi-Fi network, the risk of being attacked by a man-in-the-Middle. Users will also be advised to remove the certificate. Furthermore Superfish would be asked to turn off all server activity of the software. Via Twitter Lenovo announces that it is busy working to rectify the problem and regain the trust of customers.

The CERT Coordination Center (CERT / CC) at Carnegie Mellon University now has a warning issued for the certificate and advises users to delete it. There are EFF by the American civil rights movement removal instructions put online, including for Firefox users.

Superfish-Adware Is Lenovo Customers Cost


The Super Fish-adware that Lenovo laptops installed and making SSL connections risk reminiscent of the Sony rootkit scandal a few years ago and the computer manufacturer will ultimately cost customers.That says Adam Winn software company OPSWAT.

"Although the intentions may not be malicious, the implementation is certainly is. Superfish is more than just adware, it's a man-in-the-middle attack that occurs as adware. In an era of continuous security-related news it is shocking that Lenovo software installs the SSL chain breaks on in such a fundamental way. " Winn sees similarities with the Sony rootkit scandal in 2005, only this time the consequences are much greater.

"It touches both privacy as the fundamental trust that consumers have SSL-protected Web sites." He also predicts that this action Lenovo customers will cost. "Lenovo has a loyal following among IT professionals, as evidenced by the present Thinkpads anywhere within companies. There is no doubt that this incident will have a severe drain on the balance of Lenovo. No system tolerates a Man-in the-middle attack on proprietary or BYOD devices. "

The American civil rights movement EFF calls it an amateurish design choice of Superfish to inject ads through a self-signed certificate. "Lenovo's decision to provide this software was incredibly irresponsible and a great abuse of the trust that they received from customers." Lenovo late by Bloomberg know it was a mistake to install the software standard on laptops and that the only purpose was to improve the customer experience.

Thursday, 19 February 2015

Adware Lenovo Laptops Brings SSL Connection In Danger


Chinese computer maker Lenovo installs default very aggressive adware on the laptops that sells to the customer, allowing all users to set up SSL connections that are at risk. It was some time known that Lenovo installs the Superfish-adware on laptops, only now its impact appears to be much greater than was assumed initially.


According to researcher Marc Rogers adware performs a "Man-in-the-middle attack" to gain access to sensitive data running over SSL connections and inject ads. In addition, Lenovo also installs a weak certificate on the system, so users no SSL connection that they can set up more confidence.


The problem was already on 21 January by a user on the Lenovo forum reported. According to the user hijacks Superfish, also known as Visual Discovery and Similar Products, all SSL / TLS connections using a self-signed root certificate authority that is trusted by the browser. The user in question has returned to his laptop and asked for his money back.

Through Superfish ads are displayed on the computer. Rogers calls it an infamous piece of adware that hijacks legitimate connections, user activity monitors, collects personal information and upload to servers, pop-up displays with adware and another attacking users of SSL connections and uses a self-signed certificate. Superfish used also a weak SHA1 certificate.SHA-1, however, has been replaced by SHA-256, SHA-1 as attacks on can now be carried out using standard computers. It also appears that there is a 1024-bit RSA key is used which is to crack.

The researcher suggests that Lenovo is therefore ignorant and reckless busy. "It's probably the worst I've seen put on a supplier customers." In a reaction that enables Lenovo Superfish temporarily of laptops has been removed. In addition, the manufacturer notes that the plug-in can not hurt.

Or the plug-in is removed only on new laptops and Lenovo can do this on existing computers is unclear. It is also unclear whether in this case the self-signed root certificate authority is removed. The Next Web reports that Firefox users are not at risk, because the open source browser uses its own certificate store. Furthermore, virus scanners would Superfish detect adware and recommend to remove.

Lenovo said in a statement that Superfish from January 2015 not installed on new systems. Furthermore Superfish would already sold Lenovo machines are turned off. According to the manufacturer the adware on only a "select few" consumer models installed.

Superfish Domains & IP Addresses
Security Researcher Conrad Longmore has published a list of IP addresses and domain names used by Superfish. He notes that the information is sent to US IP addresses. Superfish itself is Israeli. "What seems to be a popular place to develop adware," he notes.


Owners of a Lenovo laptop can through this page, check the Superfish Certificate Authority trusted by their browser and they are therefore at risk.


Several researchers have meanwhile managed to crack the password that the private key of the Superfish certificate used.The password proved "komodia" to be, according to an analysis by researcher Robert Graham . In theory it would be possible thus to perform man-in-the-middle attacks and encrypted traffic to intercept Lenovo users. For this, an attacker would have to place between the user and the Internet. Further says researcher Erik Loman that contrary to what was first reported Firefox users be vulnerable.


Lenovo showed earlier know Superfish is no longer installed in new laptops and existing installations were off.Whether this also the self-signed certificate is removed is unclear. Lenovo has asked for clarification but received no reply.

Lenovo late know that it completely stops Superfish and not on machines will install the software. Additionally, the software off in January of this year on the server side of Lenovo. Thereby Superfish would no longer be active. Or users themselves must remove the self-signed certificate is unclear. This question is still open at Lenovo.

The computer manufacturer also states that it has extensively researched the technology, but has found no evidence to justify the resulting safety concerns. "But we know that users are concerned about this problem and therefore immediate action taken by products with this software to deliver any more.