Showing posts with label Proxy. Show all posts
Showing posts with label Proxy. Show all posts

Thursday, 23 April 2015

Adobe Distributes Emergency Patch Attacked Flash Leak



A comprehensive attack on users of Adobe Flash Player remained hidden for two months before it was discovered by security researchers. Before the attack, the attackers were using an unknown vulnerability in Adobe Flash Player which on February 4 this year came with an update. Anti-virus company Malwarebytes, however, that the leak since December 10, 2014 was attacked.

Unlike many zero days, vulnerabilities for which an update is missing, it was not a question of targeted attacks against specific organizations or institutions. Just ad networks were used to attack ordinary Internet users and infect with ransomware and click fraud malware. Once an infected ad was shown a Flash Player user's computer could be infected with the malware.

For the spread of infectious ads used the attackers an ad network that reaches more than 500 million users in their own words. To prevent the attack would stand each visitor got infected ad only see once and were users with a VPN or proxy not infected. According Malwarebytes attackers tried in this way to hide the attack for security researchers and security.

Furthermore discovered the virus fighter that the attackers simply paid for the ads and there was no hacked ad networks. 0.75 cents was paid for 1,000 impressions, but this figure fell to 0.06 cents at less busy times. The ads appeared on separate popular websites, Malwarebytes states that, judging by the use of a zero-day and the execution of the attack, we were dealing with a professional operation. The attacks stopped in the end on February 3, a day after Adobe an emergency patch was announced for the leak.

Thursday, 2 April 2015

Google Says Trust Certificates In Chinese CNNIC CA


Due to a recent incident with wrongly issued SSL certificates for Google sites Google has confidence in the Chinese certificate authority (CA) CNNIC terminated, which Google products such as Chrome will no longer recognize the certificates of CNNIC. Something that will be implemented through a future update for Chrome. Since this is very big impact, particularly Chinese Chrome users will have Google has decided to permit temporarily issued SSL certificates under CNNIC even by placing them on a public whitelist.

The reason for the measure is the recent discovery of rogue SSL certificates for various Google domains that were created by the Egyptian company MCS Holding. The company had been given the opportunity of CNNIC, which is a root CA. As root CA is CNNIC trusted by all major browsers. CNNIC had spent an intermediate certificate for MCS Holding, which the company for arbitrary domains could create SSL certificates. Because the intermediate certificate of CNNIC came, they were created SSL certificates also trusted by browsers.

According MCS Holding made ​​a human error sure that the existence of the rogue Google certificate was discovered. Google, Microsoft and Mozilla therefore decided to block these certificates. In addition, the CNNIC was heavily charged that MCS Holding gave an intermedia certificate, which the Chinese company had violated all sorts of rules. After further investigation, Google has now decided to tell all the confidence in CNNIC.
Certificate Transparency

Google argues in a statement that it believes that no other unauthorized SSL certificates have been issued or that the rogue Google certificates are used outside the test environment of MCS Holding. Regarding the Chinese certificate authority that Google must "Certificate Transparency" before implementing any request about the renewed confidence of CNNIC is considered.

Certificate Transparency is a technology developed by Google and is intended to address several structural flaws in the SSL certificate system. Thereby to unjustifiably spent and rogue SSL certificates are detected earlier. Mozilla has also decided to Certificate Transparency support .
Update

CNNIC called Google's decision unacceptable and unwise. The Chinese CA Google also calls to take the interests and rights of users into consideration. CNNIC let customers know their rights and interests will not be compromised.

Friday, 27 March 2015

Egyptian Company: Google Rogue Certificates Were Mistake


The Egyptian company that had generated rogue SSL certificates for different websites from Google calls it a mistake that Google eventually discovered the certificates and hit alarm . Indeed, it was not intended that the certificates were discovered. This week, Google warned Internet users to rogue Google certificates generated by the Egyptian MCS Holding. Through the certificates could allow an attacker to Man-in-the-middle and phishing attacks on Internet users to intercept passwords and the contents of encrypted traffic.

MCS Holding is an Egyptian security company that delivers business networking. However, it had become a so-called "intermediate" certificate authority (CA), which was linked to the Chinese certificate authority CNNIC. SSL certificates from an intermediate certificate authority originate have the full authority of the CA under which they fall. In particular, Mozilla had great criticism of CNNIC that MCS Holding had given permission to the intermediate CA to generate SSL certificates.

The Egyptian company said in a statement that it had signed an agreement with CNNIC to a two-week period intermediate CA to act. This would be necessary for the testing of a new roll from cloud service. The test took place in a secure lab where the private key of the CA certifcate, to generate SSL certificates, stored in a firewall.

However, the firewall was set to automatically generate certificates for websites that were visited on the Internet. During an unguarded moment at the weekend would be one of the IT engineers decided to use the internet with Google Chrome. Chrome offers certificate pinning, which websites can indicate what their CA SSL certificate has been issued. The browser will then put these certificates on a whitelist.

Is the website for an SSL certificate that is issued by a different CA, then turn the alarm browser. After MCS Holding by CNNIC had informed the certificate was immediately removed from the firewall and warned all parties involved. According to the Egyptian company, it is a human error which inadvertently took place. "We have no evidence of abuse, and we therefore recommend that people will not change their password or other action," said a company spokesman.

Measures

Meanwhile, Google has revoked the intermediate certificate of MCS Holding and also a Microsoft update released under Windows Users. From the description of the software giant appears that certificates for domains *. google.com , *.google.com.eg , *. g.doubleclick.net , *. gstatic.com , www.google.com , www.gmail .com and *. googleapis.com were created. Firefox comes next week with an update to revoke the certificate.

On the mailing list of Mozilla developers after the incident a heated debate erupted or CNNIC is not guilty because it would have violated all sorts of rules. While some want CNNIC is removed from the root store of Firefox. Mozilla could do this then this can have very serious consequences, especially for Chinese Firefox users, thereby HTTPS sites with SSL certificates of CNNIC and suspended beneath intermediate CAs can not visit. The Chinese CA Mozilla has therefore asked not to remove it from the root store CNNIC.

Tuesday, 24 March 2015

Google Sounds Alarm On Rogue Google certificate



Google warns Internet users to rogue Google certificate issued by a company from the United Arab Emirates and could be used to perform man-in-the-middle and phishing attacks on Internet users, so as passwords and the contents of encrypted traffic intercept. SSL certificates are used inter alia for encrypting traffic between websites and visitors and identifying websites.

The company that rogue SSL certificates issued is MCS Holdings , a so-called "intermediate" certificate authority (CA), which is linked to the Chinese CNNIC certificate authority. SSL certificates from an intermediate certificate authority originate have the full authority of the CA under which they fall. CNNIC is in all major "root certificate stores" so the Google unfairly issued certificates would be trusted by most browsers and operating systems.

Chrome on Windows, OS X and Linux, ChromeOS and Firefox 33 and newer would have refused the certificate because certificate-pinning. According to Google, there are probably also issued certificates for other websites that may not be recognized by certificate-pinning. Certificate-pinning sites may indicate by what their CA SSL certificate has been issued. The browser will then put these certificates on a whitelist. Is the website for an SSL certificate that is issued by a different CA, then turn the alarm browser. Browsers like Chrome and Firefox currently support only pinning for some great websites.

Proxy

Following the fraudulent certificates, which were discovered on 20 March, Google CNNIC approached and was told that MCS Holdings only if issued certificates for domains they had registered themselves. That turned the company does not have done. MCS Holdings provides proxy appliances and firewall solutions that enable organizations of workers through the encrypted traffic can intercept self signed certificates. Should normally be set to the office computers to trust the proxy, but in this case it was not required by the wrongly issued certificates.

Google sees similarities with previously unduly certificates issued in 2013 by the French CA ANSSI . The Internet giant also denounces that CNNIC the power to create SSL certificates awarded to a company that was not suitable here. Chrome users do not have to do to be protected from rogue certificates, while Firefox users will have to wait for the arrival of Firefox 37 in which the certificate has been revoked. This version on March 31 appear.

Saturday, 10 January 2015

Sony Hackers Were Deliberately Left Possible Traces


The hackers managed to break into Sony may have deliberately discarded tracks and were not sloppy like the FBI this week claimed. So say a former North Korean official and a South Korean security expert versus the Wall Street Journal.

"While it is impossible to prove whether the hackers proof accidentally or deliberately left behind, it can not completely hide their tracks also mean that North Korea wanted it known," said Choi Sang-myung, advisor to the South Korean cyberwarfare commands. The theory is supported by Jang Jin-sung, a former officer of a North Korean propaganda unit.

He argues that North Korean hackers have an incentive to leave evidence behind, because successful attacks against the enemy will be rewarded with promotions. "People compete fiercely to prove their loyalty. They must leave behind evidence that they have done it," Jin-sung says.

In an attack on South Korean television companies and banks in 2013 would have been visible a short time a North Korean IP address, because the Chinese servers that were used as a proxy temporarily not working. According to security expert Richard Bejtlich let this story shows that technical features are just one part of the grant of an attack. "There should therefore be taken into account not only national but also personal incentives to solve the attribution question," he notes.

Thursday, 9 October 2014

Botnet of 500,000 computers - Qakbot Malware

The Attack Chain


Researchers have identified a botnet of 500,000 computers discovered that 52% of machinery exists that run on Windows XP. A comparatively very high percentage, since it no longer supported by Microsoft operating system worldwide share of between 14% and 24%.

The computers have been infected with qbot via known vulnerabilities in Adobe Flash Player, Java, Adobe Reader and Internet Explorer, also known as Qakbot. On infected computers qbot steals all kinds of data for Internet banking. Researchers from Proofpoint found that the login data of 800,000 accounts online banking were intercepted. In 59% of these cases involved one of the five largest American banks.

Further figures ( PDF ) show that the malware on the American Internet has provided, since 75% of the infected computers over an American IP address available. especially In addition to steal login details infected machines are also offered for other cybercriminals. Paid as proxy These criminals can the infected computers as a springboard for other attacks use or for storage or transportation of stolen data.

Following are the steps How It works:

1. Infecting Legitimate Websites

Infecting Legitimate Websites

2. Filtering Targets- Traffic Distribution Systems.

Filtering Targets- Traffic Distribution Systems

3. Getting Into The User's Machines -Exploits

Getting Into The User's Machines -Exploits

4. Stealing User Banking Credentials - Malware

Stealing User Banking Credentials - Malware