Showing posts with label Reddit. Show all posts
Showing posts with label Reddit. Show all posts

Friday, 13 November 2015

Microsoft Patches Update Outlook To Crash


Microsoft has released a new update for Windows 7, because the previous in some users Outlook to crash. Last Tuesday, Microsoft issued a critical security update (MS15-115) for multiple Windows computers leaks through which attackers could take over completely.

The 3097877 update caused some users of Outlook 2010 and 2013 ensure that the email program crashed when opening HTML emails, as evidenced by numerous complaints on the forum Microsoft and Reddit. The problems disappeared if the relevant update was removed. Microsoft allows now in the Security Bulletin MS15-115 know that the update has been re-released to fix the problem that caused crashes when viewing certain emails. Users also are advised to install the update again.

Monday, 17 August 2015

New Zero-Day Vulnerability Revealed In Mac OS X



On the Internet, details of a new vulnerability in Mac OS X appeared which there is no update available from Apple. Through the vulnerability can allow a local attacker who already has access to a system or a malicious app already installed enhance the rights.

It is reported via Hacker News and Reddit . An attacker can not take away or run this code on the system via the zero-day vulnerability. In this case, there is first requires an additional vulnerability. For users of Mac OS X Yosemite, there is no update available. The problem would by now have been addressed in Mac OS X 10:11 El Capitan, but this version is not yet rolled out to the general public.

Recently, a similar vulnerability in Mac OS X was revealed which at that time was still no update available from Apple. This zero-day vulnerability was finally an adware installer to install additional software with root privileges. This week Apple issued an update for Mac OS X that leak 133 fixed it in the operating system, including this vulnerability.

Thursday, 13 August 2015

T-Mobile Customers Targeted By SMS Phishing Attack


US customers of telecom provider T-Mobile have become the target of a sophisticated SMS phishing attack. The customers received a text message in which she was promised a discount of $ 20 when they opened the attached link.

The link pointed to a phishing page where to set the phone and the user's password is requested, and the last four digits of the social security number and PIN. After the data were completed, they got to see a message that the discount was processed and the official website of T-Mobile was loaded, reports anti-virus company Malwarebytes .


On Reddit allows an employee of T-Mobile know that the criminals behind the attack trying to get online access. Then they change the sim and let those expensive calls to premium numbers. Depending on how fast the scam is noted shin injury to the user in the hundreds or thousands of dollars. According to the employee gets them to deal with this every day.

Thursday, 23 July 2015

Bug In OpenSSH Makes Brute-Force Attacks Possible


A bug in the popular OpenSSH allows attackers to try thousands of passwords, while the software actually after six failed logins should disconnect. The vulnerability was by a security researcher with the alias " Kingcope announced. "

OpenSSH, also known as OpenBSD Secure Shell, is a set of network tools based on the SSH protocol, and allows users to securely log on to servers for instance, or remotely manage machines. Servers that allow login via SSH are regularly targeted by brute force attacks. In the case of OpenSSH, this is limited by after six unsuccessful attempts to disconnect. By using the vulnerability, it is possible to try to open thousands of passwords via a log-in window, that by default a two minute open state.

The problem is in the latest version of OpenSSH present, the researcher says. Which warns it especially FreeBSD systems at risk, because that keyboard-interactive authentication is enabled by default. On Reddit let a reader know that the "Challenge Response Authentication no" protects against the attack and was involved in its installation standard.

Friday, 29 May 2015

"Dormant" Ransomware Makes Victims Worldwide


Main Locker Screen
This week, the world of computers with a new ransomware variant infected become infected systems which quietly and suddenly became active on 25 May. It is the locker-ransomware which like other kinds of ransomware specimens encrypts files on the system.

According Bleeping Computer is a large number of people worldwide affected by the malware. After the encryption users will see a notification that they have to pay 0.1 bitcoin. That comes with the current exchange rate equivalent to 22 euros. An amount that is one-tenth of what questions ransomware many other instances. In the warning that users get to see is further stated that they should not investigate Locker ransomware or remove, because the private key will be destroyed and the data is no longer decrypt.

Experts, however, that this is just a way to scare people so that they pay the amount requested. Besides the forum Bleeping Computer are also social news site Reddit been several reports of the victims appeared to have the amount paid. It is the low price of 22 euros given as a reason to watch or by paying the files are recoverable. Several victims have thereby know that after the pay could decrypt their files and so got back.

How Locker ransomware exactly spreads is not yet confirmed, but possibly it is a cracked version of Minecraft or sports streaming sites, although e-mail attachments and exploits are mentioned. The ransomware would just delete the Volume Shadow Copies on the C drive. This would be possible through the Volume Shadow Copies of other disks for files that have been encrypted there without paying retrieve .

Monday, 27 April 2015

Still 88,000 Shops Vulnerable Magento Leak



A critical vulnerability in the popular shopping cart software Magento allow an attacker to completely take over the shop is still in 88,000 merchants present, even though the update since early February. The vulnerability is now being used to attack shops.

In addition, security company Check Point has released details about the leak. Researchers from the company warned Magento on 14 January this year about the problem they had found. A few weeks later, a security Magento. Still, many merchants decided not to install it. The Dutch hosting company Byte warned a week ago that still 140,000 merchants risked because they were not patched. Meanwhile, a significant portion of the vulnerable Magento shops install the update, but are still vulnerable 88,000 shops, according to the last census of Byte.

That census took place last Friday, the same day that the Magento developers a warning afgaven for the leak. Security firm Sucuri reported Friday that it had now perceived attacks that made ​​abuse of the leak. In addition, the company claimed that merchants who had rolled the patch not yet been hacked or that would be only a matter of time. Below is a video demonstration of Check Point which shows how online stores can be robbed by setting the price of goods at zero through the leak.

Sunday, 19 April 2015

140,000 Merchants Vulnerable Magento Leak



A serious vulnerability in the shopping cart software Magento enables merchants 140,000 at risk of being hacked, warns the Dutch hosting company Byte. The vulnerability was in February by the developers patched but examining Byte April 14 shows that 60% of merchants who still uses a vulnerable version running on Magento. That equates to 140,000 shops.

There are no observed attacks yet, but if there is an exploit appears Byte expects all vulnerable web shops will be hacked within 48 hours. To help, there is a merchants website appeared online that reports whether the shop is vulnerable or not. In addition, administrators are advised to install the update. According to an employee of security firm Check Point on Reddit , the company will next week more details about the vulnerability publicly, but no exploit code. Or the employee states that it is a very serious leak.

Friday, 3 April 2015

Tool Protects WiFi Networks Against Malicious Access Points


To prevent employees and other Wi-Fi users with hostile access points to connect to a programmer has developed a tool that offers protection against this. Through EvilAP_Defender like tool called Mohamed Idris, network administrators can discover so-called evil or rogue access points and prevent them from WiFi users attacks. A rogue access point is a Wi-Fi network as another Wi-Fi network to make do with the ultimate goal that employees through this network connection. Then the attacker could intercept and perform other attacks.

Once active EvilAP_Defender can send an e-mail to the administrator when a rogue access point detected. Soon there will also appear for SMS support. The tool can also be set to perform a Denial of Service attack on the rogue access point, so that the network administrator has time to take action.

The tool will only perform against rogue access points with the same network name the DoS attack, but a different BSSID (the MAC address of an access point), or if they are running on a different channel. This should prevent a DoS attack is performed on the legitimate network. On Reddit , where Idris tool announced yesterday, let him know that there is also a control signal. He also has plans to later develop a client-server version in which there are arranged at various places sensors that look for rogue access points.

Wednesday, 1 April 2015

Tor Is Promoting Use Of Hidden Websites


The Tor network not only provides users the ability to hide their IP address, even turning and visiting hidden sites and services is possible. And it is this feature of Tor developers who now want to bring wider attention.

Through the hidden sites and services, on the Tor network if hidden services identified, people can share information anonymously and safely. So bloggers, activists, journalists and organizations under other totalitarian regimes use it.Newspapers like the Washington Post and Human Rights organizations like Amnesty International use them again to receive leaked information. "The potential of hidden services is huge and much still needs to be explored there," said Tor developers.They want to make the technology therefore accessible to a larger audience.

The Tor developers look for hidden services namely an important role when it comes to the future of secure communication.To realize this, the uses of hidden services will have to be increased, there must be mobile support for mobile applications and will eventually also the number of people that have to grow hidden services used. At this time, approximately 4% of the Tor-traffic originating from hidden services. To determine where the emphasis will be launched a crowd funding campaign on.

While looking for the Tor Project ideas for hidden services to crowd funded. Meanwhile, there are three ideas conceived, including an information for administrators of hidden services and hidden services where anonymity is paramount but speed.In this case, the hidden service will not care about their own anonymity, but that visitors anonymously and securely connect through the Tor network. It involves, for example initiatives of Facebook and Reddit to also be active in the Tor network.Other ideas via this page to reach out to.

Monday, 30 March 2015

Tens Of Thousands Of Frequent Flyer Accounts Hacked British Airways


Attackers have managed to gain access to thousands of frequent flyer accounts of British Airways and steal all kinds of bonus because users had used their password for the service also for one or more other websites, according to the British airline.

In an email to customers affected British Airways announces that the "unauthorized activities" has discovered regarding the "Executive Club account" of the user. It is an automated attack that happened to other places stolen credentials was tried to login. The Guardian reports that for tens of thousands of users are affected. To protect users, it was decided to close all accounts and change the password. Before users can log in again they must first create a new password.

On Reddit and Twitter are all kinds of angry messages from customers who reported that their Avois points are all stolen, formerly known as Air miles. It is a reward program where consumers when shopping sorts can earn bonus points which can then be used for travel. According to British Airways, there would be no personal information captured and is working to resolve the situation.

Monday, 16 March 2015

Sony Compensate Damage Of Hacked PSN Gamer


A gamer who the Sony PlayStation Network account was hacked and used to reimburse hundreds of dollars in fraudulent purchases gets the damage from Sony. The player with the alias "Kadjar" on social news site Reddit message that last week he suddenly got all kinds of confirmations of purchases that he had not done. It would be an amount of more than $ 600.

The gamer logged onto his PSN account and removed the credit card that was linked to the account. By linking a credit to the account it is possible to buy all sorts of games and expansions through the PSN store from Sony. The attacker used this to yourself to purchase any games at the expense of Kadjar. After the card was removed took gamer contact Sony. An employee said that the company is an amount up to $ 150 would compensate.

Kadjar did have the option to cast doubt on the transactions at his bank, but warned the employee that his PSN account banned would be in this case. Therefore, the gamer would lose all his previous purchases. The attacker who had hacked the account of the gamer had deactivated the PlayStation 4 of Kadjar and activated its own console. The Sony Helpdesk allows one activation every six months. Therefore, the gamer would half a year without access to his own account.

Solution

The story was widely picked up by the media and made ​​sure Sony On contacting Kadjar and told to investigate the matter.The gamer is now reporting on Reddit that the investigation showed that his account was indeed hacked and Sony will arrange everything. Also told the employee that the Sony headquarters knew his situation and that there will be now examined whether the policy should be adjusted.

Tuesday, 3 February 2015

Firefox and Chrome Can Leak IP VPN Users

Firefox and Google Chrome have implemented a technology allowing the IP address of VPN users can be traced. Before Daniel Roesler warns on GitHub . The problem is caused by WebRTC , an open source project developed by Google that provides browsers Real-Time Communications (RTC).

Both Firefox and Chrome have implemented whereby the WebRTC technology called " STUN requests "can send to STUN servers. Through these requests, the local and public IP addresses of the user can be captured via JavaScript. This is especially a problem for VPN users, who often use VPNs to protect their identity. Roesler made ​​this demonstration to capture the IP addresses. Readers Reddit give different solutions to the problem, such as disabling WebRTC in Firefox and Chrome.

In Firefox, this can by in the address bar " about: config "to enter and then put" media.peerconnection.enabled "to" false ".Google Chrome users can do this in the address bar " chrome: // flags / "to enter and then" Disable WebRTC device enumeration "to turn. Other solutions have JavaScript disabled, using Firefox NoScript or Chrome extension WebRTC Block. Additionally, VPN users get TorGuard advised to set the VPN tunnel directly to their router.

Wednesday, 7 January 2015

ISC: Another Port For SSH Is Not Meaningless



Who SSH (Secure Shell) to log on to remote computers and servers will benefit from it to change the default port 22, as late as a handler of the Internet Storm Center (ISC) know. SSH is a popular protocol for managing computers. Standard protocol listens on port 22.

This will also be a lot of scans and attacks on this port. At present, there Reddit , in response to this article , a discussion or change the default port is wise. One of the criticisms is that " security through obscurity "is not a security measure, but only one way to slow an attacker and therefore offers little value. "While it is true that it is difficult to stop a determined attacker to cause you provide, any measure that prevents arbitrary script kiddies and scanners to your SSH look not entirely meaningless," says ISC handler Rick Wanner.

Wanner says more than 15 years SSH on a non-standard port to run, such as port 52222. "Of course this is not the only security measure that I use. I patch daily use hosts.allow where possible, keys and passphrases instead passwords and use Deny Hosts ", he tells. ISC handler notes that he does not use port 22 because of "security through obscurity" benefits, but because it eliminates all noise on port 22.

Port 22 is a favorite target of brute force attacks and port scans rising every year. These activities cause Wanner as much noise in the logs. "Why would you tolerate it if it is not needed?", He notes. The default port change he would attack traffic are much diminished that he occasionally his defense test to see if it still works.

Tuesday, 25 November 2014

USB Charger E-Cigarette Spreading Malwares.






Companies must not only pay attention to e-mail attachments and web traffic, even USB chargers can be used for electronic cigarettes to infect computers with malware. That leaves a self-proclaimed IT guy on the popular social news site Reddit know. The IT person tells how a not got closer to said large company with malware. It was the director of the computer where the infection was found.

The system was fully up to date and had up-to-date anti-virus. Seeking a declaration asked the IT department or the director for the past two weeks, maybe something had changed in his life. The man appeared to have switched to e-cigarettes. Further investigation revealed that contained the used USB charger for charging the e-cigarette malware. Once the charger was plugged touched the infected computer malware and made the connection to a remote server.

Boot-Sector Virus


While no further details are shared, let Rik Ferguson of Trend Micro anti-virus company opposite the Guardian know that it is a plausible scenario. "Malware in product lines has existed for years," he notes. There are several examples of MP3 players and digital photo frames that are already in the plant malware infection incur and it then passed on to the consumers who used the equipment. Thus warned consumer electronics giant Samsung still in 2008 that included the installation CD for a digital photo frame malware.

If you want to protect yourself from USB Malware start using USB Condoms by Sync Stop.

More Details by Srlabs : PDF & Video 


Wednesday, 2 April 2014

Tinder plagued by spam bots


A number of users of dating app Tinder reports that they are matched a fake profile of an attractive woman.In reality the automated bots that users want to download. Mobile game "Castle Clash"
The bots display a link to the game via the URL "Tinderverified.com", making it seem like Tinder is the owner of the URL, or is involved in any case in one way or another to the action. This is not the case.
A Reddit user realized what was happening and posted a screenshot. This post now has a handful of responses from others who say they have experienced the same. Also on Twitter More and more reports from people who claim they are matched with a fake profile.
The bot first sends innocent messages like "hey" and "how are you?" then they tell the unsuspecting user that they have such a fun game on their phone, "Castle Clash, have you heard of?" The bot then informs the URL, no matter what was the response of the user.
It is still unclear who exactly is behind the fake accounts, even though the app developer IGG.com course obvious. The company offers dozens of games on the App Store and Google Play. However, it is also possible that the developer himself the victim of an aggressive promotional network as previously happened with the on-demand ride service Uber .
Tinder shows himself to be aware of the problem and said the necessary steps to remove the spam.

Symantec Detailed Report

Monday, 10 March 2014

Bitcoin trading platform Mt. Gox security issue is a fraud? Hackers say!

Last month, Tokyo-based trading platform Bitcoin Mt. Gox claims to have lost because of security vulnerabilities worth nearly $ 500 million in customer bitcoins, but many users do not trust the platform to explain this Bitcoin trading platform.

Bitcoin trading platform Mt. Gox did not provide further information they are black, according to reports hackers use the trading system software vulnerabilities to steal, eventually led Mt.Gox crash. On Sunday, a group of hackers have claimed that black into Mt. Gox CEO Capet DeGeneres (Mark Karpeles) personal blog and found the number of bits stored coins and Mt. Gox claimed the number was stolen inconsistent.

According to Forbes, the hacker entered the Capet DeGeneres personal blog and Reddit account and posted a message claiming Bitcoin trading platform Mt.Gox still claiming the right to use some of Capet DeGeneres stolen bitcoins.

These hackers uploaded a series of documents, including a spreadsheet containing the anonymous user Bitcoin balances, as well as proof of residence Capet DeGeneres screenshot hacker access these data. In addition, hackers also released a file size of 716MB, saying the file containing the stolen data from the Mt. Gox server. Here is the link to the data address .

List of files
$ Tree
.
├ ─ ─ backoffice
│ ├ ─ ─ Bin
│ │ ├ ─ ─ TibanneBackOffice
│ │ │ ├ ─ ─ MacOSX
│ │ │ │ └ ─ ─ TibanneBackOffice.app
│ │ │ └ ─ ─ Windows
│ │ │ └ ─ ─ TibanneBackOffice.exe
│ │ └ ─ ─ screenshot.png
│ ├ ─ ─ Docs
│ │ ├ ─ ─ CV-Mark_Karpeles_20100325.pdf
│ │ ├ ─ ─ btc_xfer_total_summary.txt
│ │ ├ ─ ─ home_addresses.txt
│ │ └ ─ ─ trades_summary.txt
│ └ ─ ─ Exports
│ ├ ─ ─ btc_xfer_report.csv
│ └ ─ ─ mtgox_balances
└ ─ ─ trades
    ├ ─ ─ 2011-04.csv
    ├ ─ ─ 2011-04_mtgox_japan.csv
    ├ ─ ─ 2011-05.csv
    ├ ─ ─ 2011-06.csv
    ├ ─ ─ 2011-07.csv
    ├ ─ ─ 2011-08.csv
    ├ ─ ─ 2011-09.csv
    ├ ─ ─ 2011-10.csv
    ├ ─ ─ 2011-11.csv
    ├ ─ ─ 2011-12.csv
    ├ ─ ─ 2012-01.csv
    ├ ─ ─ 2012-02.csv
    ├ ─ ─ 2012-03.csv
    ├ ─ ─ 2012-04.csv
    ├ ─ ─ 2012-05.csv
    ├ ─ ─ 2012-06.csv
    ├ ─ ─ 2012-07.csv
    ├ ─ ─ 2012-08.csv
    ├ ─ ─ 2012-09.csv
    ├ ─ ─ 2012-10.csv
    ├ ─ ─ 2012-11_coinlab.csv
    ├ ─ ─ 2012-11_mtgox_japan.csv
    ├ ─ ─ 2012-12_coinlab.csv
    ├ ─ ─ 2012-12_mtgox_japan.csv
    ├ ─ ─ 2013-01_coinlab.csv
    ├ ─ ─ 2013-01_mtgox_japan.csv
    ├ ─ ─ 2013-02-12_coinlab.csv
    ├ ─ ─ 2013-02-12_mtgox_japan.csv
    ├ ─ ─ 2013-02-19_coinlab.csv
    ├ ─ ─ 2013-02-19_mtgox_japan.csv
    ├ ─ ─ 2013-02-26_coinlab.csv
    ├ ─ ─ 2013-02-26_mtgox_japan.csv
    ├ ─ ─ 2013-02_coinlab.csv
    ├ ─ ─ 2013-02_mtgox_japan.csv
    ├ ─ ─ 2013-03-05_coinlab.csv
    ├ ─ ─ 2013-03-05_mtgox_japan.csv
    ├ ─ ─ 2013-03-12_coinlab.csv
    ├ ─ ─ 2013-03-12_mtgox_japan.csv
    ├ ─ ─ 2013-03-19_coinlab.csv
    ├ ─ ─ 2013-03-19_mtgox_japan.csv
    ├ ─ ─ 2013-03-26_coinlab.csv
    ├ ─ ─ 2013-03-26_mtgox_japan.csv
    ├ ─ ─ 2013-03_coinlab.csv
    ├ ─ ─ 2013-03_mtgox_japan.csv
    ├ ─ ─ 2013-04_coinlab.csv
    ├ ─ ─ 2013-04_mtgox_japan.csv
    ├ ─ ─ 2013-05_coinlab.csv
    ├ ─ ─ 2013-05_mtgox_japan.csv
    ├ ─ ─ 2013-06_coinlab.csv
    ├ ─ ─ 2013-06_mtgox_japan.csv
    ├ ─ ─ 2013-07_coinlab.csv
    ├ ─ ─ 2013-07_mtgox_japan.csv
    ├ ─ ─ 2013-08_coinlab.csv
    ├ ─ ─ 2013-08_mtgox_japan.csv
    ├ ─ ─ 2013-09_coinlab.csv
    ├ ─ ─ 2013-09_mtgox_japan.csv
    ├ ─ ─ 2013-10_coinlab.csv
    ├ ─ ─ 2013-10_mtgox_japan.csv
    ├ ─ ─ 2013-11_coinlab.csv
    └ ─ ─ 2013-11_mtgox_japan.csv

33 directories, 80 files








Dump contains information about all the trades took place, exchange management utility, summary statistics, the authors computed hacking (archive formed by attackers to avoid the leakage of personal data of customers MtGox).

Currency: AUD Balance: 924,124.65121
Currency: BTC Balance: 951,116.21905382 <- This fat fucker lied to us! (Sic)
Currency: CAD Balance: 320,184.36558
Currency: CHF Balance: 99,487.07308
Currency: CNY Balance: 297,775.78994
Currency: DKK Balance: 112,264.56207
Currency: EUR Balance: 5,634,625.59531
Currency: GBP Balance: 921,892.96793
Currency: HKD Balance: 740,519.14894
Currency: JPY Balance: 384,885,150.13700
Currency: NOK Balance: 91,346.00305
Currency: NZD Balance: 58,224.95320
Currency: PLN Balance: 1,645,194.67364
Currency: RUB Balance: 551,162.54477
Currency: SEK Balance: 15,335.84383
Currency: SGD Balance: 43,193.59706
Currency: THB Balance: 666,464.33497
Currency: USD Balance: 30,611,805.67481
Total BTC Deposits: 19,065,241.307202
Total BTC Withdrawl: 18,563,466.149383
------------
BTC Difference: 501,775.157819


Hackers also said, saying the company's balance there bitcoin 951,116 BTC, based on current dollar terms, worth more than 600 million U.S. dollars. MtGox claiming that it lost a total of 850,000 bitcoins In announcing the bankruptcy filing, where 100,000 is the trading platform they own.

It CENT was reported that hackers published these data have not been confirmed, but some Reddit users said their personal account balances and hackers released data match.

As of press time, Capet DeGeneres and special currency trading platform Mt.Gox not yet issued a statement on the matter.