Showing posts with label Script. Show all posts
Showing posts with label Script. Show all posts

Wednesday, 18 November 2015

FireEye: Precision Attacks Possible Thanks Analytics


Webanalytics may be used to collect online information to let go then very targeted attacks on those visitors. Such practices to gather information would be even sponsored by certain governments. Claiming security company FireEye in the report pinpointing targets.

WITCHCOVEN

According FireEye is information about visitor behavior gathered through more than 100 websites that were hacked and manipulated. Anyone who visits such a site, imperceptibly redirected to a second site where the script WITCHCOVEN in is processed.

This script collects detailed information from the user's computer and install a "super cookie" to track the visitor. The information from the computer used according FireEye for later use very targeted exploits that work on those specific configuration and software of the user.

Friday, 26 June 2015

Man Mails More Than 97,000 People Their Password


With great regularity on websites like Pastebin stolen passwords and other credentials posted. The reason for a programmer named Julian alias' aTechDad 'to collect all kinds of stolen email addresses and passwords via a script and then warn the user.

For example, some Internet users use Google Alerts or other services to warn if their data appear anywhere on the internet.Most Internet users may not know such services exist and users who know there is much that their data would rather not leave you in this kind of party, said the programmer. He therefore decided to create a script, which he in a three-day period on Pastebin 97 931 combinations of email addresses and passwords collected.

Last month, he decided to warn users. Through a simple e-mail, he said that the account of the user probably was compromised, which he also co-stared the password. The nearly 98,000 sent emails yielded only nine thanked by. 100 e-mails could not be delivered, while 41 people sent back a request to be unsubscribed. Yet Julian considers the experiment a success. At this time he started a second experiment, in which he has already collected 300,000 passwords. "I might do it again," said the programmer.

Friday, 13 February 2015

Microsoft Publishes Script For Password Reset Krbtgt


Microsoft has published a script that enables organizations to reset the password of the so-called krbtgt account, what should prevent attackers with a stolen krbtgt account access to confidential data on the network. These researchers would focus increasingly on developing methods to attack the Kerberos authentication.

Kerberos is a standard authentication protocol that allows users to log on securely to the network and to prove their identity, without having to log in each time. Kerberos authentication works by assigning a ticket to a logged-in user. These tickets are encrypted with a symmetric key that is derived from the password of the server where the user logs on.

To request a session ticket must have a special ticket called the Ticket Granting Ticket (TGT), be presented to the Kerberos service. The TGT is as said encrypted with a key derived from the password of the krbtgt account, which is known only by the Kerberos service. A stolen account password can also have serious consequences, because an attacker this if other users can occur and thus gain access to sensitive data.

One way to reduce the risk of an attacker used a compromised krbtgt key to falsify user ticket is periodically reset the krbtgt account password. By doing this regularly to the useful life of the krbtgt keys is limited in case an attacker is able to access them. Microsoft now has a script and its advice is made ​​available to reset the password regularly.

"It is important to remember that resetting krbtgt is only one part of a recovery strategy alone will not prevent a previously successful attacker unauthorized access in the future to get a hacked environment," said Microsoft Tim Rains. He advises organizations therefore to draw up a comprehensive recovery plan.