Showing posts with label SMS. Show all posts
Showing posts with label SMS. Show all posts

Friday, 4 September 2015

Two-Factor Authentication Frustrates Phishers


Turning on two-factor authentication for email accounts appears to be a difficult problem for phishers, let examination of Canadian Citizen Lab see. The organization writes a sizeable phishing campaign against Iranian people and a director of the American civil rights organization EFF.

Two-factor authentication ensures that must be entered when logging an additional code. This code is received via SMS or can be generated via an app. However, the code has a limited validity. This allows phishers to try in real-time to get both the password of the account if the two-factor code. During the phishing campaign Citizen Lab describes using various tactics.Thus users received a text message which seemed to come from Google and suggested that there was someone else at the account login.

Shortly after the SMS was sent a phishing mail that warned of the accused login attempt. The message was a link to enable users to reset their password. The link pointed to a phishing site where the password must be entered as a two-factor code.The attack failed when the attackers in a short time more than ten text messages sent out to the target to increase the pressure.

Journalist

In the case of the EFF headmistress she got a call from someone posing as a journalist and wanted to interview her. Then the director received an e-mail with a link to a document on the phishing page. Since the link has not been opened to the phisher was frustrated and sent a new message. Eventually he called the director frustrated and asked if she wanted to open the link, since the mail was now sent from his personal account.

According to Citizen Lab shows the campaign that two-factor authentication, and the attention of users, ensures that attackers need to do much more effort to gain access to an account. In addition, users are advised to use an app to generate the two-factor code, as it offers more security than a text message.

Friday, 22 May 2015

Dozens Minecraft Apps On Google Play Prove Scareware


On Google Play, researchers from the Slovak anti-virus company ESET found dozens of apps that occur as cheats for the popular computer game Minecraft, but in reality scareware. It involves a total of 33 applications that were placed on Google Play over a period of nine months and have been downloaded between 660,000 and 2,800,000 times.

The apps do not do what they promise and show after starting only banners claiming that the Android device with a "dangerous virus" infected. Then offered to remove the virus, for which there should be a "virus" via SMS enabled. However, it is an SMS user subscription costs 4.80 euro per week. ESET recommends that Android users to still only download apps from official app stores, to check what permissions the app asks and be read reviews from users.

Friday, 3 April 2015

Tool Protects WiFi Networks Against Malicious Access Points


To prevent employees and other Wi-Fi users with hostile access points to connect to a programmer has developed a tool that offers protection against this. Through EvilAP_Defender like tool called Mohamed Idris, network administrators can discover so-called evil or rogue access points and prevent them from WiFi users attacks. A rogue access point is a Wi-Fi network as another Wi-Fi network to make do with the ultimate goal that employees through this network connection. Then the attacker could intercept and perform other attacks.

Once active EvilAP_Defender can send an e-mail to the administrator when a rogue access point detected. Soon there will also appear for SMS support. The tool can also be set to perform a Denial of Service attack on the rogue access point, so that the network administrator has time to take action.

The tool will only perform against rogue access points with the same network name the DoS attack, but a different BSSID (the MAC address of an access point), or if they are running on a different channel. This should prevent a DoS attack is performed on the legitimate network. On Reddit , where Idris tool announced yesterday, let him know that there is also a control signal. He also has plans to later develop a client-server version in which there are arranged at various places sensors that look for rogue access points.

Tuesday, 31 March 2015

Researchers Reveal Solution For Mobile Malware


Researchers from the University of Alabama say they have developed a solution that should reduce the impact of mobile malware. The problem of mobile malware, according to the researchers is mainly caused by users who download applications from untrusted sites that offer infected apps. Once installed on the device has the malware free play.

"The Achilles heel of the security of mobile devices is that security decision depends on the user," says researcher and lecturer Nitesh Saxena. For example, when you install an Android app gets the user's demand that the app will have certain rights. Users can then be distracted or have hurry and so quick to allow these permissions. "Whatever the reason, it is a known problem that people do not look at these warnings and simply" yes "clicks."

Current operating systems provide the researchers not protect against this type of attack. Therefore there was a search for a solution to the important parts of the phone, namely the ability to call the camera and NFC, protect against malware. The result was a security that is based on three hand movements. If a user wants to call that instance must move the device or tap anywhere before the phone rings, while as malware service to telephone calls this movement will fail.

To demonstrate the effectiveness of the approach, the researchers collected data from several phone models and users in real or "almost real" scenarios, where both friendly and hostile scenarios were simulated. It emerged that detect hand movements are very accurate and other benign and malignant activities can be distinguished. "In this way, something as simple as human movement to solve a very complex problem," says Saxena. "It makes the weakest link, the user, the strong defender." The researchers plan to develop security for other smartphone services, such as SMS and email.

Monday, 23 March 2015

Encrypted SMS With Android App SMSSecure


Announced a new app for Android should make it possible again to send encrypted text messages, now another popular Android app that made ​​this possible is stopped. Recently showed Open Whisper Systems , the developer of Secure Text, know that the support of encrypted SMS / MMS is stopped.

According to the developer will be encrypted SMS / MMS never easy to use as encrypted text messages, because users in encrypted SMS manual should exchange the encryption keys before it can be communicated. "We believe that people should not even know what a" key "is, so this obstacle always felt wrong," said the developers.

Also mentions Open WhisperSysms SMS and MMS a "security disaster", because metadata is continuously leaked. SMS messages pass through the servers of telecom companies. The developers do not want the state-run telecom companies like Saudi Arabia, Iran or China can access the metadata Text Secure users. Finally, the support of SMS / MMS make it more difficult for the developers in order to improve the app.

SMSSecure

On GitHub is a new app called appeared SMSSecure , a fork of Text Secure. It is a spin-off based on the source code of Text Secure and focuses on encrypted SMS messages. To go with the app to work there needs to be an unencrypted backup Text Secure, which can then be imported by SMSSecure. SMSSecure developed by the Frenchman Bastien Le Querrec.

Tuesday, 17 March 2015

Yahoo Unveils Own Login Without Password


Yahoo has unveiled a new service allowing users without their password on their account login. Instead of getting the own Yahoo password to remember, users of the new "on-demand" service sent an SMS with a short password, which must be completed.

To use the service, users must first log in using their own password and then register their phone. If the service is enabled, the user gets the next time he wants to login to see no password field, but a button that the password code of four characters is sent to his unit.

"This is the first step in eliminating passwords", said Yahoo CEO Dylan Casey while Southwest festival in Texas know. The process resembles that of two-factor authentication, only without the first factor, the password of the user. The new service is now available for US users, according to Yahoo . When it appears for other users is unknown.

Wednesday, 11 February 2015

Anti-virus Company G Data Is Encrypted Chat App


The German anti-virus company G Data will in April an application for encrypted instant launch , based on the protocol of Axolotl Text Secure . The app allows users besides conducting individual interviews and group discussions also encrypted exchange pictures and files.

Meanwhile, there would be more than 10 million users that communicate via the Axolotl protocol Text Secure. Through apps that support the protocol, as the app from G Data or Secure Text of Open Whisper Systems can either via SMS or via the messaging app itself communicate safely. The app will appear in a free and paid version.

The free version offers not only encrypted chat and file also backing up their own chat history to the SD card and encrypt the private chat history and lock with a password. The paid version offers a phishing filter URLs in instant messages and filter incoming and outgoing messages and text messages.

Saturday, 6 December 2014

Preinstalled Malware on Cheap Android Devices - Death Ring


Researchers have found in several Android phones malware advance was already installed. It comes to phones that are sold mainly in Africa and Asia, such as Vietnam, Indonesia, India, Nigeria, Taiwan and China. The phones are standard Trojan horse called "Death Ring" that occurs as a ringtone app.

In reality, the app SMS and wapcontent of the Command & Control server to download to the phone, says security firm Lookout . The malware is activated in two ways, depending on how the user uses his phone. The malware is activated when the phone is restarted five times. In addition, start the malicious service if the victim fifty times are unlocked device.

Lookout has described various scenarios malware can do on a phone, but has no concrete examples. However, the company warns that the malware can not be removed by a virus app, as it is in the system directory. Which is added in the supply chain the malware is unknown. Consumers also are advised to pay attention to where the equipment they buy comes from.

The infections were detected forged Counterfeit Samsung GS4/Note II Various TECNO devices Gionee Gpad G1 Gionee GN708W Gionee GN800 Polytron Rocket S2350 Hi-Tech Amaze Tab Karbonn TA-FONE A34/A37 Jiayu G4S – Galaxy S4 Clone Haier H7 No manufacturer specified i9502+ Samsung Clone

It is not the first time that pre-installed malware on Android devices found .

Tuesday, 25 March 2014

XP malware allows criminals ATM emptying via SMS

ATM malware infects a Windows XP installation makes it possible for criminals by sending a single SMS message to retrieve the dispenser. Empty It involves the Ploutus malware last October for the first time in Mexico was discovered, but is now active in more countries.

Two weeks after the discovery of a new variant Ploutus was found . This version was translated not only in English but also had a modular architecture. Anti-virus company Symantec has this version further analyzed and discovered that criminals now the ATM to clean out. via sending text messages.

Attack
To attack the ATM criminals first need to have physical access to it. Then the ATM machine booted from a boot CD. This boot CD contains the Ploutus malware that infects the operating system of the ATM during startup. In addition, the virus may be present, the malware also switches off.

After installation, it is possible to activate Ploutus via a special key combination can be spent on command. Money Criminals straw men gave the command to retrieve the money had to share this key. If the straw men knew what could be done with the key they can light up their client, says Symantec.
Ploutus ATM attack overview


Smartphone
To solve this problem, the criminals can also link a smartphone to the ATM. The already installed malware ensures that the criminal can communicate. Using the smartphone with the ATM This avoids key shared. Lake with the straw man The criminal can now send an SMS to the ATM which then spends the money that is being recorded. Straw man by himself The attacks would have been observed. Different places in the world.

Symantec notes that as encrypted hard drives, which installed the malware may occur. Modern ATMs have better security, Older ATMs, however, would run on XP and are therefore more vulnerable. Ploutus example works only on Windows XP. Banks also get the advice to Windows 7 or 8 upgrade. In addition, the BIOS must be locked so that it can not be booted. From other media.

MD5:
488acf3e6ba215edef77fd900e6eb33b
b9f5bd514485fb06da39beff051b9fdc

Virus Total Link:
https://www.virustotal.com/en/file/0106757fac9d10a8e2a22dce5337f404bfa1c44d3cc0c53af3c7539888bc4025/analysis/

https://www.virustotal.com/en/file/34acc4c0b61b5ce0b37c3589f97d1f23e6d84011a241e6f85683ee517ce786f1/analysis/