Showing posts with label Putty. Show all posts
Showing posts with label Putty. Show all posts

Tuesday, 10 November 2015

Vulnerability In Popular SSH Client PuTTY Poem


There is a new version of the popular SSH client PuTTY appeared in which a vulnerability is closed through which attackers could execute at worst arbitrary code with the rights of the logged on user systems.

For this, a user had to connect to the server of the attacker. The cause of the problem in the terminal emulator was an escape sequence whereby the terminal code of PuTTY read the wrong memory and possibly could describe well, which could lead to an integer overflow. PuTTY and pterm version 0:54 to 0.65 are vulnerable. Users therefore be advised to version 0.66 to upgrade.

Wednesday, 20 May 2015

Infected Version Of PuTTY Steals Passwords


Cyber criminals are spreading on the Internet an infectious variant of the popular SSH client PuTTY, which is designed to steal passwords. PuTTY is a free open source terminal emulator application as a client for SSH, Telnet, rlogin, and raw TCP protocols can serve.

The now discovered version is not on the official PuTTY download site spreads, but via a hacked another page. The infected version would have been the end of 2013 and then already been distributed over the Internet. Recently, anti-virus company Symantec observed more infections. The infection starts with a user searching through a search engine to PuTTY.

Instead of choosing the official website, the user selects a hacked website. The hacked website sends the user several times and let him finally downloading an infected version. When the user logs in via the infected version on a system, the login information can be sent to the attacker. Users also are advised to check that they only download software from the official website of the supplier or developer.

Sunday, 17 May 2015

Check Point: Microsoft Needs To Create Help Files Harmless


Cyber criminals use Microsoft help files that Windows users just provide information on various subjects, in order to spread malware. The software giant should therefore take measures to defuse this threat, as advocates security company Check Point.

The problem is present with chm files, which stands for Microsoft Compressed HTML Help. This format is the successor of the famous .hlp file in Windows. CHM files are highly interactive and can contain various technologies, such as JavaScript and PowerShell commands. This makes it possible to automatically download a file when the CHM file is opened.

There have been several attacks in which malicious observed chm files are distributed via e-mail. Many users would not know that this is a potentially dangerous file. "The .chm help files are often used as software documentation and help manual. As the use is so common, we find the use of the help files is usually not suspected," says analyst Oded Vanunu Check Point.

He recently discovered a CHM file that the program Putty downloaded and executed on the computer, which then further commands could be executed on the computer. Many virus scanners, however, would not detect the malicious CHM files."Microsoft has not yet developed a patch to prevent this attack method. Therefore, it is still used by attackers as not be noticed by virus," said Vanunu.