Showing posts with label Proof-of-concept. Show all posts
Showing posts with label Proof-of-concept. Show all posts

Wednesday, 25 November 2015

Lenovo Used Insecure Password For Admin Account


Computer manufacturer Lenovo has released an update to the System Update tool that fixes two critical vulnerabilities could allow a local attacker to gain system or administrator rights. The software is installed on most Lenovo computers and checks for new versions of drivers and other software. Using the software, users can also download and install updates.

The first issue (pdf) in the System Update tool concerned the temporary system administrator account that Lenovo created.This account was generated in a predictable name and insecure password, which allows a local user could then gain admin privileges. The second problem (pdf) concerned a legal problem which allows a local unprivileged user could execute Windows commands with system privileges.

Both vulnerabilities were discovered by security firm IOActive in October and early November reported to Lenovo. The computer manufacturer came last week, 17 days after the notification, with an update to the System Update tool. Then are the details of the vulnerabilities now publicly made, including a proof-of-concept that shows one of the attacks. Lenovo users are advised to install version 5.07.0019 or later of the System Update tool.

Friday, 6 November 2015

Researcher Unveils First Ransomware For Mac


A Brazilian researcher is the first ransomware developed for Mac OS X, in his own words to break the myth that there is no malware for the Mac. Rafael Marques calls his creation "Mabouia 'and this is a so-called" proof-of- concept. "

A creation which is intended purely for demonstration purposes and the investigator wrote in two days. He will therefore not publish the source code of the malware. Although there are already 'ransomware' for Mac was released in these cases to Javascript code that the browser unlocked and a warning that supposedly showed the FBI or Europol originated. Files on the computer remained unaffected.

The Marques of ransomware encrypts files and actually uses the eXtended Tiny Encryption Algorithm (XTEA) and then sends the key to a server. The researchers developed a way to decrypt the files. Critics argue that the ransomware is not as complex as the ransomware for Windows. "I never said that [the ransomware] is complex. I made ​​it in two days. But it's still the first Mac OS X ransomware", as the researcher leaves via Twitter know. He also made ​​this demonstration video.

Tuesday, 9 June 2015

Leak in iOS Mail App Allows Remote Attacker HTML Charge


A researcher has revealed a leak in the iOS Mail app which allows an attacker to load external HTML e-mail messages, which it is then possible to perform very convincing phishing attacks. The vulnerability was in January this year by researcher Jan Soucek discovered.

The iOS mail client shows a particular HTML tag in email messages can not be ignored. As a result, HTML content can be loaded which replaces the contents of the original e-mail message. Sourcek reported the problem to Apple in January, but because there is still no solution has appeared Soucek decided now a proof-of-concept to publish his attack. Thus, it is possible to display a pop-up to the user through the e-mail that looks like a legitimate logon window. In reality it is a malicious pop-up completed the password sends to the attacker, according to a demonstration video below.

Saturday, 6 June 2015

Malware Is Mac Users Via Leak In MacKeeper


Mac users who have installed warned the MacKeeper program for malware that attempts to spread via a flaw in the software that an update was published in May. Last month, a vulnerability in MacKeeper discovered that an attacker could execute arbitrary code with root privileges without much user interaction. The problem was caused by the way MacKeeper with "custom URLs" deal.

Braden Thomas researcher who discovered was a proof-of-concept that ensures that carried when visiting a specially prepared page with Safari arbitrary commands on the system problem. A few days after the proof-of-concept appeared online are also the first malicious MacKeeper URLs appear, discovered researcher Sergei Shevchenko of security company BAE Systems.

Phishing Mail

The URLs can for example be spread through phishing emails. When users click on the link, a pop-up warning that malware was found on the computer that must be removed. For this, the user must enter his password. Fills the user password, the malware is downloaded and installed. According to Shevchenko, it is a backdoor which receives an attacker remote access to the computer.

The malware collects all sorts of data on the system, including running processes, operating system name and version, user name, and the presence of VPN connections. According to the researcher, it is interesting to see how quickly attackers made use of the leak. To carry out the attack, a user must have installed a vulnerable version of MacKeeper. The developers of the software claim that MacKeeper has been downloaded over 20 million times.

Shevchenko also does not exclude that the attackers bombard their targets with phishing emails in the hope that one MacKeeper installed. After the leak last month became known MacKeeper came quickly but with an update that is installed automatically in most cases. It is also the question of how successful this attack campaign is or was.

Wednesday, 20 May 2015

Safari Flaw Allows Malware And Phishing Attacks Possible



A vulnerability in Safari allows you to execute malware and phishing attacks. The vulnerability can any URL displayed in the address bar, while another site is loaded. The vulnerability was revealed by the UK security Deusen.

As evidence it put a proof-of-concept online. This test looks like the website of the Daily Mail is open, while this is not so."While this proof-of-concept is not perfect, it can be certainly improved and is then very easy to use for phishing attacks," said Manuel Humberto Santander Pelaez of the Internet Storm Center . The attack may not work if cookies only from the currently open website are allowed.