Showing posts with label Sensitive Data. Show all posts
Showing posts with label Sensitive Data. Show all posts

Wednesday, 9 September 2015

Avira Tool For Lost iPhone Logins Sent Over HTTP



A free tool from antivirus company Avira for finding stolen or lost iPhones appeared to send unencrypted passwords over HTTP. This would allow an attacker who get the network traffic could eavesdrop usernames, passwords and other sensitive information.

It discovered security researcher David Coomber. According Coomber were the passwords that the Avira Mobile Security iOS app sent well protected by the weak MD5 algorithm, but would offer no protection against an attacker could sniff network traffic. Mobile Security is an app that allows users to trace five lost or stolen iPhones. Also, users can check via the tool or their e-mail was hacked, the address book or safe and iOS is up to date. Avira was informed on July 17 and published on September 3 version 1.5.11 in which the issue is resolved.

Thursday, 9 April 2015

Network White House Probably Hacked Phishing Mail


An unclassified network of the White House last year probably hacked by a phishing email, so let anonymous government officials across CNN know. In the attack were the attackers access to sensitive information, such as the planning of President Obama.

While this information is not classified according to the officials who would still be valuable for foreign intelligence services.To the White House to attack the attackers would first the Ministry of Interior have attacked. The officials say that a hacked email account from the ministry was used to send a phishing email to the White House. Details about this email, as used malware or exploits, are not given. According to Ben Rhodes, the national security adviser to Obama, there are no classified hacked systems in the attack.

Thursday, 15 January 2015

Gitrob - "This New Tool Crawls GitHub Sensitive Data"


For developers and organizations that work with GitHub is a new tool appeared which makes it possible to search the platform on sensitive data. GitHub is a popular online platform for software developers that code and files can be shared.

Also can work on projects together over the platform. Many companies and projects use GitHub to host both internal and public projects. Sometimes it happens that employees publish things that actually may not be published. This relates to sensitive data or business with which a system can be made ​​immediately. "This can happen by accident or because the employee does not realize the sensitivity of the information," said Michael Henriksen .


So it still happens regularly that developers publish things as private keys and credentials. Henriksen therefore developed Gitrob , enabling organizations and security professionals can find this kind of sensitive data. The tool collects all the public "repositories" of the organization, as well as all employees and their public repositories. Then all available files are collected and analyzed to see if they match patterns for sensitive files.

Henriksen works for SoundCloud and had to develop a system that monitors GitHub sensitive files. He notes that organizations can look through his tool or no sensitive files roam. In addition, penetration testers and more "offensive" security professionals can use the tool to collect information about a potential target.