Showing posts with label Security Researchers. Show all posts
Showing posts with label Security Researchers. Show all posts

Sunday, 11 March 2018

Leaked Source Code Ammyy Admin Uses For Malware



Source code of the remote desktop software Ammyy Admin has been used for malware that has been used for both targeted and large-scale attacks, according to security firm Proofpoint. Ammyy Admin is a program that allows remote access to computers.

Some time ago the source code of Ammyy Admin version 3 appeared on the Internet and cyber criminals have used it to develop malware called "FlawedAmmyy". This malicious version has been used in attacks since the beginning of 2016, but only recently discovered, Proofpoint says. Among other things, the automotive industry would be the target of the attacks.

To spread the malware, the attackers use e-mails that contain Word or ZIP files as an attachment. The Word files have a malicious macro that, when enabled by the user, downloads the malware on the system. Once active on a system, FlawedAmmyy can be used to steal trade secrets, customer data and other information from companies, according to the researchers.

Thursday, 26 November 2015

Millions Of Vulnerable Devices By The Same Encryption Keys


Researchers warn that millions of devices such as Internet routers, IP cameras and modems are vulnerable because they use the same encryption keys. Attackers can therefore perform man-in-the-middle attacks and eavesdropping and decrypt encrypted traffic.

Therefore might enter sensitive information into the wrong hands. The problem is with so-called embedded devices, including routers, modems, IP cameras and VoIP phones. Researchers from security firm SEC Consult watched for their research firmware more than 4,000 such devices from more than 70 manufacturers.

They mainly looked at cryptographic keys in firmware, such as public keys, private keys and certificates. It mainly involves keys that are used to connect through SSH and X.509 certificates used for HTTPS. In total, were found more than 580 unique private keys in the 4,000 studied devices.

This information was then correlated with data from large-scale Internet scans. It emerged that the dataset with the 580 unique keys contains the private keys of 9% of the HTTPS web hosts and the private keys of more than 6% of all SSH hosts.At least 230 of the 580 keys were actively used and seen by millions of hosts.

The keys are added by manufacturers to provide connection via HTTPS and SSH. The problem is that all devices with the appropriate firmware using the same keys. It was remarkable that the same keys were found in the products of different manufacturers. For example, a certificate of Broadcom were found on the Internet at more than 480,000 units, including Linksys and ZyXEL. The problem also arises in Cisco, Huawei, Ubiquiti Networks and other vendors. The devices are especially vulnerable in the United States (26.3%) and Mexico (16.5%).

Solution

SEC Consult has worked with the CERT Coordination Center (CERT / CC) at Carnegie Mellon University to warn the manufacturers involved and browser developers. Meanwhile, some parties have released updates. Manufacturers also are advised to use unique cryptographic keys for each device. In addition, Internet service providers to ensure that remote access over the WAN port to the equipment of their subscribers is not possible. Finally end users are advised to generic SSH keys and X.509 certificates on their devices to replace unique versions. However, the CERT / CC states that in many cases, there is no practical solution is available.

Tuesday, 24 November 2015

New Ransomware Variant Linux Uses OpenSSL



Researchers have discovered a new variant of ransomware that encrypts Linux web servers.Linux.Encoder.2, as this variant is called, however, appeared earlier than Linux.Encoder.1 where early November was warned. The second would be used in September and October.

The attackers deliberately set WordPress websites and web shops running on Magento. The attackers know exactly how to enter, according to the Russian anti-virus company Doctor Web is not yet known. Once access to the server is obtained encrypted files and victims get a message that they have to pay. A difference between the first and second variant is the use of OpenSSL instead of PolarSSL. Why the creators of the ransomware SSL library has changed is unknown.

Like the first variant the second variant can also be decrypted so that victims do not have to pay. However, the decryption tools are not removing the infected server to the shell script. Thus, the attackers can infect the server. Victims are advised to call the police, do not change the contents of encrypted directories and not to delete files from the server.

Friday, 13 November 2015

Adware Disables Updates For Chrome And Firefox


Adware is limited not only to the display of advertisements, aggressive adware variant fact also brings the systems of users at risk, so warn researchers. Where most adware is only nests in the browser, the DynamicPricer-adware first switches off the automatic updates for Chrome and Firefox, and then install an older version of Chrome.

In this old Chrome version, which dates from February 2014, the adware displays all kinds of ads, reports anti-malware company Malwarebytes. The adware is installed via so-called software bundles, which besides the desired program to install all kinds of additional software. Recently warned researchers also adware already installed browsers on the computer trying to replace.

This trojan was hosted at cdn[dot]searchbook[dot]me. Which currently resides at an IP-address that has quite the history (198.232.127.32). If you know where to look you will be able to find other and more recent installers, but they are password protected zip files which will be unpacked by the bundle installer under “normal” circumstances.

VirusTotal Report

Friday, 6 November 2015

Researcher Unveils First Ransomware For Mac


A Brazilian researcher is the first ransomware developed for Mac OS X, in his own words to break the myth that there is no malware for the Mac. Rafael Marques calls his creation "Mabouia 'and this is a so-called" proof-of- concept. "

A creation which is intended purely for demonstration purposes and the investigator wrote in two days. He will therefore not publish the source code of the malware. Although there are already 'ransomware' for Mac was released in these cases to Javascript code that the browser unlocked and a warning that supposedly showed the FBI or Europol originated. Files on the computer remained unaffected.

The Marques of ransomware encrypts files and actually uses the eXtended Tiny Encryption Algorithm (XTEA) and then sends the key to a server. The researchers developed a way to decrypt the files. Critics argue that the ransomware is not as complex as the ransomware for Windows. "I never said that [the ransomware] is complex. I made ​​it in two days. But it's still the first Mac OS X ransomware", as the researcher leaves via Twitter know. He also made ​​this demonstration video.

Thursday, 5 November 2015

New XcodeGhost-Malware For iOS Developers Discovered


Researchers have identified a new variant of the XcodeGhost malware discovered trying to infect iOS developers so they put infected apps in the official Apple App Store. There are more than 200 companies worldwide, which infected iOS users roam.

XcodeGhost is spread via infected versions of Xcode, Apple's official tool for developing iOS applications. Because of its size, the program is 4GB in size, some developers in China choose not Xcode via Apple's website, but can be downloaded via unofficial download sites. The Xcode on these websites provide the XcodeGhost malware. The apps that developers were thus also became infected.

After the discovery of the infected apps in the App Store, Apple decided to remove and arranged so that Chinese iOS developers can program easier downloading. Although the hit iOS developers new clean apps have provided, there are still users who continue to use the affected versions. These include to the popular chat app WeChat.

It also notes that users with infected iOS apps also walk around within companies. Security firm FireEye discovered 210 enterprises which infected apps were trying to communicate to the outside. However, most companies are located in Germany and the United States.

New version

There is also a new version of XcodeGhost discovered in unofficial versions of Xcode 7. This is the Xcode iOS version 9. In this version added new features to iOS infect 9 and bypass static detection by Apple. Also, there is one app is discovered which had become infected via the new XcodeGhost malware and ended up in the Apple App Store. It is a Chinese shopping app that also was offered in the US store. Apple has the app been removed.

Wednesday, 4 November 2015

Researchers Bypass Microsoft's EMET Security


Researchers have succeeded in the EMET security tool to circumvent Microsoft by a Windows Component are used to make 32-bit software on a 64-bit operating system running. EMET stands for Enhanced Mitigation Experience Toolkit (EMET) and provides Windows and applications from an additional layer of security.

This extra layer to make it harder for attackers to attack both known and unknown vulnerabilities in the operating system or installed programs or plug-ins. Researchers at Duo Security, however, found a way (pdf) to bypass the security of EMET.The attack is possible by WoW64 subsystem of Windows.

This system acts as a compatibility layer between 32-bit software and 64-bit Windows versions. While most Windows versions are now 64-bit, most Internet users still use 32-bit browsers. Research by Duo Security found that 80% of browsers on 64-bit Windows versions is a 32-bit process. For these browsers on a 64-bit system to use the "Windows on Windows" (WoW) used low.

The security measures EMET offers in WoW64 subsystem less effective. In the case of the attack Duo Security developed there may eventually be a 64-bit version will be attacked by a DLL, while WoW64 ensures that EMET only protects the 32-bit version of the file. To remedy this problem, Microsoft would have to make major changes to the operation of EMET.

Advice

Despite the successful attack the researchers state that EMET is still an important part of any security strategy. They also recommend the use of 64-bit software, because some parts of this abuse makes little trickier and other offers security advantages. Users and administrators also be advised where possible, true 64-bit software to run on 64-bit Windows versions.

Monday, 2 November 2015

Forgotten Explorer Vulnerability In Windows 10 Still Patched


Microsoft has previously forgotten vulnerability in Internet Explorer for Windows 10 yet patched. On October 13 released Microsoft Security Bulletin MS15-106 for several critical vulnerabilities in Internet Explorer that could allow an attacker the underlying system could take over completely.

Several of the vulnerabilities were corrected by the Zero Day Initiative (ZDI) of security firm TippingPoint reported to Microsoft. Researchers can at ZDI sell vulnerabilities fee, and TippingPoint notifies the responsible supplier. Next, details of the vulnerability published as the supplier has solved the problem, or has not complied with the deadline of the ZDI.

In this case, made ​​after the publication of the TippingPoint Security Bulletin MS15-106 know that Microsoft is a critical vulnerability in Internet Explorer 11 for Windows 10 had composed, designated as CVE-2015-6045. The vulnerability, however, was not mentioned in the Microsoft Security Bulletin itself, what questions on Twitter made. TippingPoint then pulled the own publication about the vulnerability away.

It now appears that Microsoft had not patched the vulnerability. Thursday appeared namely a new version of the Microsoft Security Bulletin which announces that a new cumulative update was released CVE-2015-6045 in which it is resolved. The update is only for Windows 10, which also need to install the new update. On most systems, however, this happens automatically.

Thursday, 22 October 2015

Criminals Fraud Were For Tons Of EMV Credit Cards


Criminals are in a very smart way managed to defraud for tons of credit cards that are equipped with an EMV chip. The EMV chip is the successor to the magnetic strip and make it harder for criminals to defraud, for example through the skimming of debit cards.

However, the chip is also not immune to attacks, according to research (pdf) by French researchers that Wired notified.Four years ago, a dozen credit cards stolen in France, which were then used in Belgium. Something that would be impossible without the PIN of the card holders. This led to police investigations and finally the arrest of several gang members.

The research that followed and which the researchers used X-rays revealed that the criminals had made a second chip in the EMV chip of the stolen credit cards. Through this chip, they could bypass the authentication of the PIN code, since any PIN you entered was accepted. In addition, the criminals took advantage of the fact that the authentication of the PIN code then was disconnected from the transaction authentication of EMV payment cards.

Transaction

A normal EMV transaction consists of three steps. Authentication payment, verification of the cardholder and finally the authorization of the transaction. During the transaction if the original chip on the custom payment simply responding to the authentication control. The verification of the cardholder asked the payment to the user's PIN. The criminal then filled in an arbitrary code.

At that time, the applied chip was active and the ticket said that the PIN was correct, which accepted it. During the last transaction authorization gave the second chip, the data between the terminal and the first original chip. In this way, managed to steal the gang for about 600,000 euros with the custom cards. Eventually, the criminals ran into trouble because they always used the stolen credit cards on the same spots.

Tuesday, 20 October 2015

Nearly One Million Websites With "Unsafe" SHA-1 Algorithm


Recently demonstrated researchers that it is much cheaper to attack SSL certificates with the SHA-1 algorithm than previously thought. The Centre for Mathematics and Computer Science (CWI) in Amsterdam pleaded therefore for the SHA-1 algorithm rather to phase out.

Google Chrome sees SSL certificates with the SHA-1 algorithm already unsafe. Research by internet company Netcraft shows that there are still nearly one million SSL certificates with this sensitive algorithm in use. The number of certificates is expected to decline from 2016. The CA / Browser Forum, a consortium of certificate authorities, the parties who issue SSL certificates, then do not allow new certificates with the SHA-1 algorithm.

Although SHA-1 by Google Chrome is now as weak or insecure is seen this year still spent more than 120,000 SHA-1 certificates. Some of these certificates are valid until 2020, but will need to be replaced sooner. From 2017 all browsers will display these certificates namely unsafe.

Tuesday, 13 October 2015

Canadian Arrmy Seeks Hacker Who Can Hack Truck


The Canadian Army is looking for a hacker to hack into a military truck, according to a tender that has appeared on the internet. For some truck involved is not disclosed as this information is confidential and only after award of the contract is told.

The research must be undertaken in a research center of the army and there may only be used software of the army. This software, the hacker must also develop further. For the main part is a reward of 139,000 euros offered. Possible that there are additional tasks, such as finding and developing defensive measures to prevent an attack on a vehicle.

For this part would be paid extra in total 420 000 euro. Recently, researchers demonstrated how to hack a Jeep remotely.One of these researchers Chris Valasek, leaves in front of CBC News that the price is reasonable, but is on the low side for this type of work.

Tuesday, 6 October 2015

Malicious Game: Retro Tetris In Google Play Could Rooting Android Devices



Researchers in Google Play two games have been discovered rooting Android devices. The first game Brain Test and was previously by researchers at Check Point noted. These malicious app was removed on September 24 by Google from the Google Play Store.

The second app which anti-virus company Trend Micro warns's Retro Tetris. This malicious application uses four vulnerabilities in 2013, 2014 and 2015 to rooting Android devices. Devices from Android 2.3 Gingerbread would this risk.What does the malicious app after obtaining root access is not listed. According to Trend Micro's Retro Tetris downloaded between 500 and 1,000 times, especially in China. After being informed Google has removed the app this weekend.



RetroTetris Hashes:


Brain Test:

Thursday, 1 October 2015

Research: Install Patches Costs Companies 100 Days


Companies have on average between 100 and 120 days to install patches for vulnerabilities, giving them some time vulnerable to attackers. Some vulnerabilities are not patched, however. According to research (pdf) of Kenna Security among 50,000 companies.

While companies need between 100 and 120 days to deploy available security updates, shows that attackers operate much faster. Most vulnerabilities are namely attacked in the first 60 days since the release of the patch. Between 40 and 60 days, there is a chance of 90% that a vulnerability is attacked.

The researchers argue that in the case of unpatched vulnerabilities that are attacked often for very famous and ancient leak is where patches have long been available, but not installed by organizations. "When evaluating the data we got this over and over against", so let them know. For example, last year 121 000 successful attacks on a vulnerability in phpMyAdmin measure that had already been patched in 2010. Another example is the vulnerability that uses the Slammer worm. This vulnerability dates from 2002, but last year there were still 156 000 successful attacks using the vulnerability instead.

Tuesday, 29 September 2015

Researchers Stop Malware In Shortened Links On Twitter



Researchers have developed a system that malicious shortened links on Twitter to identify and stop. The system will be tested next year during the European Football Championship, as reported in the Engineering and Physical Sciences Research Council (EPSRC).

Together with the Economic and Social Research Council (ESRC) the SPSRC has funded the research. For the study, the researchers collected links during the recent World Cup cricket and the Super Bowl were sent out and investigated the interaction between a website and the computer to determine whether there was an attack. In case occurred adjustments on the computer, such as new processes, custom registry files or modified files, there was malware.

Then the researchers used system activities, such as data exchanged between the computer and a remote server, processor utilization and status of the network to get to know the system to the signs of a malignant and benign link.Researchers from Cardiff University which conducted the study to determine knew within five seconds with an accuracy of 83% or it was an attack or not.

Within 30 seconds% accuracy to 98% were incurred as a user clicked on a shortened link and malware to the infected computer. "Because links on Twitter are always abbreviated due to character limitations in messages it is very difficult to determine which are legitimate," said Pete Burnap of the University and leader of the study. "We have the European Championship next summer, which will cause a large spike in Twitter traffic and we expect to test our system during this event."

Saturday, 19 September 2015

Chrysler Drivers Warned Of USB Sticks And Wifi



Owners of a Chrysler should not USB flash drives, connect memory cards or CDs from strangers on their car and ensure that the Wi-Fi network of the vehicle is secured with WPA2. It advises the Industrial Control Systems Cyber ​​Emergency Response Team (ICS-CERT), part of the US Department of Homeland Security.

The reason for the recommendation is a vulnerability in the UConnect infotainment system, which allows the operation of the vehicle can be controlled. An attacker could remotely login without credentials on the UConnect system.Subsequently, it is possible to control or information, such as to adjust the speedometer of the brake, the steering wheel and the air conditioning. Because of the vulnerability was demonstrated in July, Chrysler decided to 1.4 million cars to recall that a patch could be installed. For this, also USB sticks with the update sent to clients.

Network provider Sprint decided to block ports that attackers could communicate with the UConnect system. According to the ICS-CERT, it is difficult to develop a working attack that makes use of the leak abuse. In addition, the UConnect systems currently are unattainable because Sprint is blocking the ports, which reduces the likelihood of a successful attack.

Despite the measures adopted previously by Chrysler and Sprint advises the government organization Chrysler drivers to take protective measures. In addition to enabling WPA2 for the Wi-Fi network and avoiding unreliable media are also advised to ensure that all the connected devices and / or systems are not accessible from the Internet and remote access is still required there using a VPN must be made.

Sunday, 6 September 2015

Chrysler Calls 7800 SUVs Back Because Of Vulnerability



Chrysler has in the United States 7800 SUVs because of a vulnerability in the radios recalled. Using the vulnerability, an attacker can remotely the system "manipulate," the carmaker. Recently, scientists show how remote a Jeep could partially control.

Chrysler says it has already taken measures to prevent such attacks. Through these measures will be blocked access to certain vehicle systems. For this, customers or dealers do not have to do anything. The vulnerability which the 7800 SUVs are now being recalled is different from the problem that the two researchers demonstrated in July and which the carmaker 1.4 million vehicles called back.

As with the recall in this case goes to a voluntary recall. The problem is with Jeep Renegade SUVs of 2015 with a 6.5-inch touchscreen. Customers receive a USB stick which they can update the car software itself. Another option is to download the software or go through the dealer, who will perform the installation. For this purpose, no fee will be charged.

In the press release Chrysler also announced that it is not aware of any accidents or complaints were the result of attacks on the vulnerability. Below is a picture of the USB key that was sent recently to American car owners to patch the previously discovered vulnerability in Chrysler cars. An action where security experts much criticism had on.

Thursday, 3 September 2015

Leak In OS X Keychain Late Attacker Steal Passwords



A vulnerability in Keychain, the default password manager for Mac OS X makes it possible for attackers to steal passwords stored by users without much interaction. Via terminal commands it appears possible to retrieve passwords stored in the Keychain.

In this case, the password manager would not ask for a password, but a window to show the user which then must click on Allow. Two researchers from Beirut developed an exploit where they retrieve saved passwords, but then simulate the mouse click of the user. This happens in a few milliseconds, so that users do not see through. Once this automated action occurs are stored passwords via SMS sent to the researchers, as it turns out this demonstration video on YouTube.

In order to perform the attack, the code that performs terminal-and-click command simulates still be performed on the user's system. The code that the researchers developed, however, as "wrapper" to be added to innocent files. Once the user opens the file, such as an image, executes the code. According to the researchers security software will not detect the attack, because there is running legitimate code in principle.

Apple

As a solution, Apple should modify the way Keychain handles the terminal assignments and the user just need to ask for a password as it actually supposed to do. The researchers decided to inform Apple, but received no response from the software company. Because of the impact they decided their discovery through CSO disclose. "The vulnerability is very serious. Everyone can thus steal your passwords by just downloading a file that is not evil looks," said Antoine Vincent Jebara.

According to researchers, the attack can be carried out in various ways. So an attacker can a malicious file via e-mail to the user, spread malicious code through a torrent file or add in the event of a man-in-the-middle attack, the malicious code to download user .

Wednesday, 2 September 2015

Trojan Blocks Malware On Infected Computers


A Trojan horse is designed to steal money from online bank accounts show the spoils do not want to share with other cyber criminals. Once active blocking Trojan namely other malware on the infected computer. Let researchers at IBM know.

The Shifu Trojan, as malware is called, focuses on Japanese and European banks and for several months running. The malware steals all kinds of data required for online banking, such as passwords, personal certificates and tokens, as well as data from smart cards. Via VNC or Remote Desktop Protocol cyber criminals can directly from the infected computer to commit bank fraud. What stands out to Shifu, the steps taken to block other malware. The Trojan uses a type of virus-like feature, allowing files to be downloaded from the internet and malware are blocked.

It is in this case for executable files that are not signed and are downloaded via HTTP. These files will block the Trojan and sends it to its creators, presumably in order to keep the competition in mind. To let the user suspects nothing to see a message that the system has enough memory for the downloaded file. According to the researchers, it is the first time that malware draw up special rules for stopping suspicious files.

Sunday, 30 August 2015

Researchers Found 30 000 Infected Apps On Google Play


Researchers at Indiana University have developed a scanner that allows them to rapidly scan hundreds of thousands of Android apps, which ultimately resulted in 30 000 infected apps on the official Google Play store. MassVet (pdf) as the scanner is called, can determine within seconds whether an app is benign or malignant, without knowing how the malware looks or behaves.

Instead of analyzing the app MassVet compares it with apps that already exist in the relevant store. Most Android malware is in fact repackaged apps. When cybercriminals repacking apps add malicious components increasing. Therefore differs repackaged app of the original. The malicious components in applications can also be found who seem to have nothing to do with each other.

The researchers decided to test the scanner with 1.2 million apps from 33 different app markets. MassVet proved apps within 10 seconds, assess and outperformed 54 virus scanners on VirusTotal. Of the 1.2 million-controlled apps were found to be more than 127 000 malignant and 34 000 were missed by most malware scanners on VirusTotal. Some of the malware specimens were installed millions of times. It also found that 5000 malicious apps each had more than 10,000 installations.
Google Play

Also analyzed MassVet 400 000 apps on Google Play, of which 30 000 were found to be malignant. This equates to an infected rate of 7.6%. According to the researchers this different from earlier figures of Google. According to Google, was found on Android Users who only install apps from Google Play at less than 0.15% of the devices a "potentially malicious application" (PHA).

However, users of China's market places that are most likely to Android malware. In the market places of Anzhi, Yidong, yy138 and Anfen was 39%, 36%, 28% and 23% of all available apps malware. On the fifth of infected stores SlideMe comes back, 21% of the malware apps proved to be. The overview is also given to the store by Opera. This was 7.8% of the apps labeled as malicious.

Monday, 24 August 2015

Android User Chooses Predictable Lock Pattern




Android users who have secured their device with a screen lock often opt for predictable patterns, according to a survey of 3400 users by researcher Marte Loge. In early August she presented her research at the bsides 2015 conference in Las Vegas (video).

The examination of Loge shows that the most commonly used pattern consists of four dots. The average number of spots was five, so that there are fewer than 9,000 combinations. It also appears that people usually start at the top left. 77% of the dot patterns begins in one of the four corners and the patterns usually run from left to right and from top to bottom. It also appears that people often choose patterns in the form of a letter, such as their initials.

According Loge people choose dot patterns in the same way as passwords, which complex patterns are difficult to remember, like complex passwords. And like a weak password is easy to guess a weak lock pattern. "Full disk encryption will not save you if your pattern of the L loser is", warns the researcher.