Showing posts with label Sergey Lozhkin. Show all posts
Showing posts with label Sergey Lozhkin. Show all posts

Thursday, 11 February 2016

Russian Hospital Hacked Via Wifi And Old XP Flaw



A researcher has managed to hack a Russian hospital by a weak wifi password and a nearly 8-year-old vulnerability in Windows XP. The hack took place with the permission of the hospital in Moscow, let researcher Sergey Lozhkin know anti-virus company Kaspersky Lab.

He was using the Shodan search engine discovers a login portal of a CT scan machine hospital, which was only secured with a default password. Lozhkin had a friend who controlled the hospital and warned him. The hospital then agreed to an informal penetration test. The researcher decided to attack the hospital could do as a real attacker and began the Wi-Fi network of the hospital. He managed to retrieve the password through a brute force attack, let it faces Threat Post know.

After he had gained access to the wireless network he found a Windows XP machine that contained a vulnerability that Microsoft on October 23, 2008 had been patched. However, the update was not rolled out by the hospital. It was the vulnerability that also used the infamous Confickerworm to spread. Lozhkin then managed on the network to find the administrator panel of an MRI machine that was not password protected. Through the panel he had access to patient data and diagnoses were performed by the machine. According to the researcher shows his work that IT security too often forgotten by software developers, both in the medical industry and in other sectors.

Sunday, 19 July 2015

Voicemail Leads To Malware Attack Via OneDrive


A group of attackers used voicemail messages in combination with malware hosted at onedrive to attack organizations, as several security companies warn. The attack on the organizations begins with targeted phishing mails which contain a self-extracting archive file as an attachment. The attachment occurs when voice mail.

If a user opens the attachment is there as a distraction play a .wav file that looks like a real voice. In the background, however connection with OneDrive made the cloud service from Microsoft. The ultimate malware is then downloaded. Sergey Lozhkin of the Russian anti-virus firm Kaspersky Lab wonders whether this method will be applied by more cyber criminals.

"It is possible because it provides an easy way for attackers to hide malicious behavior. Detecting malicious traffic in legitimate cloud services is much more complex because it involves legitimate services to be blocked," said Lozhkin.Security company Palo Alto Networks has more details about the malware used, which was detected at the time of discovery by 3 of the 54 scanners on VirusTotal.