Showing posts with label Root. Show all posts
Showing posts with label Root. Show all posts

Monday, 2 March 2015

Criticism Leak Discovered In Seagate NAS Systems

Seagate

A researcher has a critical vulnerability in several NAS hard drive manufacturer Seagate discovered that an attacker can potentially thousands of these devices on the internet can take over, but despite months of communication about the problem, there is still no update for affected users are available.

The problem is in the Seagate Business NAS systems, according to the researcher Beyond Binary be used by both consumers and businesses. Through the systems, it is possible to store data and to share. To create users, set access rights, file management and other issues are the NAS systems provide a web management application.

The researcher discovered that this application is based on three outdated technologies, namely PHP version 5.2.13 (2010), CodeIgniter 2.1.0 (2011) and Lighttpd 4.1.28 (2010). The versions of PHP and CodeIgniter contain several vulnerabilities. In addition, also found problems in the application developed by Seagate. An attacker who adapts the session cookie can therefore eventually execute code as the user "root".

Meanwhile, there are a Metasploit module and a Python script developed to vulnerable systems can be attacked. The requirement is that the NAS can be accessed via the internet. A search via the search engine Shodan yielded more than 2,500 potentially vulnerable NAS systems. The problem has been confirmed on NAS systems with firmware 2014.00319 and 2013.60311, but the researcher suggests that basically all firmware versions are vulnerable.

In addition to the access data to attack the NAS systems within an organization can have far greater consequences. The NAS does not work with Active Directory or LDAP. Therefore they need the password for each user who needs access locally. These passwords are vulnerable through the MD5 hashing algorithm hashed. According to the researcher NAS systems at companies are undoubtedly contain passwords that are reused by domain users. An attacker who has access to the NAS can thus steal the MD5 hashes and crack, and discover the domain data.

Despite the severity of the problem, there is no update available, and the question is whether that will come. On 7 October 2014, the researcher reported the problem to Seagate. Then followed sorts messages where it appeared difficult for the investigation to catch the right person. Late January a Seagate employee could reproduce the problem using the supplied exploit. The researcher stated on January 17 that he wanted to publish the issue on 1 March.

However, this did not lead to an update since last Thursday Seagate said that there is no solution yet available. Users who want to protect themselves get therefore advised to make the NAS not accessible from the public Internet and placing the devices behind a firewall and only give several reliable IP addresses access.

Monday, 5 January 2015

CyanogenMod 12 Manages Root Privileges via Privacy Guard


The popular Android ROM CyanogenMod will in the latest version no longer use a separate app for managing root privileges. This will namely be done via the built Privacy Guard System, reports Android Police. CyanogenMod is a customized version of the Android operating system that can install owners of get rooted smartphone.


At this time the developers work on CyanogenMod 12 based on Android Lollipop. From modifications to the code that the Superuser access no longer requires a separate app, but through Privacy Guard will be arranged. Privacy Guard, formerly known yet if Incognito Mode is part of the operating system that allows users to set permissions important apps. When CyanogenMod 12 appears is still unknown.

Tuesday, 9 December 2014

"Turla Linux Malware" - Researchers discover espionage virus for Linux


Researchers from the Russian anti-virus firm Kaspersky Lab have discovered a spy virus for Linux that may go unnoticed for years, although for the latter is no proof yet. It is a variant of the Turla malware, also known as Snake or Urburos which all other known specimens have been developed only for Windows.

The researchers knew that there are Linux versions of Turla existed but had never yet found in the "wild" so far. Turla according to Kaspersky Lab is one of the most sophisticated espionage campaigns ever discovered . Among others, the Belgian Ministry of Foreign Affairs would have become the victim of the campaign. The now discovered Turla variant supports Linux so that there can be infected with more systems attacked organizations.

"We suspect that this part years was active in an organization attacked, but have no concrete evidence to prove it," said Costin Raiu of Kaspersky Lab. Through the malware an attacker can communicate with infected systems and execute arbitrary code. Thereby Turla do not need elevated privileges. Also, the malware can not be found via netstat, a tool that system administrators use to get an overview of open network connections.

"It uses techniques that do not require root access, so it can move freely on the system of a victim. Even if it's a regular limited user launches can continue to intercept the incoming packets and execute commands on the system," says Raiu . He notes that the Linux malware especially in other public source code is based, in which the attackers a number of things have been added. How the malware spreads exactly is not reported.

Wednesday, 26 November 2014

DroidJack RAT Android App Malware



Software developers who first made ​​apps for Android now versatile malware developed for the platform that it include possible to eavesdrop on conversations, intercept WhatsApp messages, looking into the camera or the microphone to listen to the environment. It is a remote administration tool (RAT) called DroidJack.

DroidJack website homepage


In a report issued late last year on Facebook developers claimed that they were novice entrepreneurs. They published at the same time on Google Play app that allows to control a remote computer. Symantec had the legitimate app developers with little success and they then directed their attention to the development of Android malware. DroidJack is now openly available over the internet. The malware will cost $ 210, which buyers also get lifetime support.

In order to carry out the RAT are no root rights are required. Once activated, it is possible to steal files, read WhatsApp messages, calls and eavesdrop on the microphone, see the address book, to operate the camera and the last GPS location to retrieve the device and Google Maps to display. The malware is equipped with a disclaimer, but they come before a judge not get away with, says analyst Peter Coogan.

Some of the Features of DroidJack:
  • No root access required 
  • Bind the DroidJack server APK with any other game or app 
  • Install any APK and update server 
  • Copy files from device to computer 
  • View all messages on the device 
  • Listen to call conversations made on the device 
  • List all the contacts on the device 
  • Listen live or record audio from the device's microphone 
  • Gain control of the camera on the device 
  • Get IMEI number, Wi-Fi MAC address, and cellphone carrier details 
  • Get the device’s last GPS location check in and show it in Google Maps

There are many more features which the App offers.

Disclaimer:

Disclaimer used in DroidJack marketing