Showing posts with label Tavis Ormandy. Show all posts
Showing posts with label Tavis Ormandy. Show all posts

Monday, 12 October 2015

Kaspersky Close Leak That Windows Update Attacker Left Block



The Russian anti-virus firm Kaspersky Lab has closed a vulnerability in Kaspersky Internet Security poem through which attackers could simply block users' access to Windows Update, the Kaspersky website and other websites, as well as the servers of e-mail provider.

The vulnerability was discovered by Google researcher Tavis Ormandy, who earlier other serious problems in the security of Kaspersky Lab laid bare. Earlier Ormandy also found all vulnerabilities in the software from Sophos, ESET and Avast.The problem with the Internet Security package has been caused by a component called the "Network Attack Blocker".This component aims to protect the computer from malicious network activity. Ormandy discovered that it is actually nothing more than a simple stateless packet filter 'that in the event of an attack on the IP address put on a blacklist.

This design made ​​abuse possible, according to Ormandy. For example, the component was found to recognize a forged TCP packets. Also, the filter did not appear to understand the status of the application layer if there is a packet was received. An attacker could create simple abuse of this by sending the signature of an attack to a Kaspersky user, the IP address was falsified. According to Ormandy, the attacker could, for example windowsupdate.microsoft.com can specify as the sender. The Network Attack Blocker could then access to Windows Update are blocked, preventing users from Windows updates would receive more.

The second problem is a possible such scenario, then only via e-mail. In this case, the security component would have blocked user access to its server. Ormandy warned Kaspersky Lab on September 11, after the update was released last Thursday. Then the Google researcher has decided to details of the vulnerabilities disclose.

Friday, 2 October 2015

Avast Close Criticism SSL Vulnerability In Anti-Virus Software



The Czech anti-virus company Avast has a critical vulnerability in the anti-virus software patched it was discovered by a researcher from Google and which allowed an attacker to execute arbitrary code by users. The problem arose in Web Shield, part of the anti-virus software.

The virus Avast scans the contents of this web traffic. To be able to check via HTTPS encrypted traffic install the anti-virus software an own root certificate. A controversial practice that was also used by the Super Fish-adware. The way Avast this had been implemented made ​​it possible for websites to execute arbitrary code on the system remotely via a specially crafted SSL certificate.

The vulnerability was discovered by Google researcher Tavis Ormandy, who also significant problems in the anti-virus software from Sophos, ESET and Kaspersky Lab discovered. Ormandy warned Avast on September 25 and yesterday evening the virus fighter rolled an update for the problem. The researcher shows via Twitter, however, know that there are still more arrive.

Thursday, 24 September 2015

Google: Anti-Virus Software, Kaspersky Still Leak


The anti-virus software of the Russian anti-virus firm Kaspersky Lab still contains multiple vulnerabilities, says Google researcher Tavis Ormandy. Recently released the virus fighter that's been a big leak could poem was found by Ormandy and the system could allow an attacker to take complete without users here had to do something.

The researcher Google has much more major vulnerabilities found in the anti-virus software, so Ormandy late in an analysis of the leak know that are already patched. The analysis was made ​​on the Project Zero blog from Google. Project Zero is a team consisting of Google hackers and researchers looking for vulnerabilities in popular software. This included the anti-virus software from Kaspersky scrutinized.

Not patched

"Many of the bug reports I submitted are still not patched, but Kaspersky has made enough progress that I can talk about some of the problems," as the researcher says. Ormandy had found dozens of bugs in the anti-virus software and reported. The research shows that some of the most dangerous leaks were very easy to abuse. The researcher is pleased that Kaspersky Lab here for additional security rolls out. The impact of a vulnerability will increase in anti-virus software because the virus often file system and network traffic intercepted.

Visiting a website or receive an e-mail is enough to be attacked. It is then not even be necessary to open the e-mail, since the input / output of the reception of the e-mail is sufficient to cause the vulnerability. Besides the discovered vulnerabilities Ormandy also found several major design flaws in other parts of the anti-virus software. These other vulnerabilities to attack his distance. As the updates previously been deferred, he will discuss these issues later.

Security software harmful?

According to Ormandy, there are strong indications that there is an active trade in exploits for antivirus software exists."Research shows that a readily accessible attack surface that exposure to targeted attacks increased enormously," says the researcher. Therefore, he believes that security software developers the strictest security guidelines when developing their software must implement in order to reduce problems caused by the software. Something that fail anti-virus companies. In the past Ormandy has major problems in the software of anti-virus company Sophos and ESET found.

The researcher concludes with a warning and request for anti-virus companies. They would parts of their software does not have to run with system privileges. "Do not wait for the network worm that it has provided in your software, or targeted attacks against your users. Add even today the development of a sandbox to your development plan." Regarding the outstanding vulnerabilities in the software of Kaspersky Ormandy says that the anti-virus company responds very quickly and that a number of critical vulnerabilities in the coming weeks will be patched.

Tuesday, 8 September 2015

Kaspersky Close Critical Vulnerability In Anti-virus Software


The Russian anti-virus firm Kaspersky Lab last week released a critical security vulnerability in the anti-virus software patched. Through the vulnerability an attacker could completely take over the system without users here had to do something. The leak was discovered by Tavis Ormandy.

Ormandy works for Google, but also carries out research in its own right. According to the researcher, who also critical vulnerabilities in anti-virus software from ESET and Sophos discovered, the problem arose in the default configuration. Ormandy called the leak as bad as it can be. Through the vulnerability an attacker could execute code with system privileges ie, without user interaction.

Where exactly the problem was and how an attacker can use them was not disclosed. At first it was difficult, according to the researcher to a security contact at Kaspersky found. After being informed was the Russian virus fighter within 24 hours with an update that was rolled out to users, so let Ormandy on Twitter know.

Wednesday, 1 July 2015

Researchers Found Vulnerabilities In Antivirus ESET



A researcher from Google has discovered a vulnerability in the security of the Slovak anti-virus company ESET, but a day before the virus fighter problem patched a group of other researchers unveiled a new vulnerability in ESET Smart Security 8.

Last week Google revealed researcher Tavis Ormandy a critical vulnerability which he computers using ESET software without user interaction could remotely take over completely. After being informed ESET came after three days with an update. Ormandy discovered another problem in the security software. This time could an attacker when unpacking a specially prepared Symbian installation cause a heap overflow, and thus execute malicious code on the computer. On June 26, after having been informed within three days, came ESET with an update to address the vulnerability.

Second vulnerability

Another group of researchers called QWERTY Lab discovered a vulnerability in a part of ESET Smart Security 8. Through the leak an attacker can gain the highest privileges in Windows. Then, the virus can be disabled, but it is also possible to bypass Windows access controls and sandboxes, as the researchers claim. As proof, they published a proof-of-concept exploit.According to the researchers, the problem confirmed Smart Security 8 but were also other anti-virus company vulnerable. On June 25, the issue was made ​​public, the researchers decided to inform ESET in advance.

The virus fighter know that the vulnerability found in several earlier versions for Windows is available. The latest version of the security software is not vulnerable. At present we are working on an update for the problem which "fast" should appear, but an exact date could not give ESET. Following the various vulnerabilities requires another investigator when ESET and other anti-virus companies are auditing their products.

Thursday, 25 June 2015

Google Finds Critical Vulnerability In Virus ESET


A researcher from Google alone in a few days a critical vulnerability in the virus scanners and security of the Slovak anti-virus company ESET discovered which allows remote attackers computers and systems can completely take over, without any user interaction is required. The vulnerability would therefore be ideal for a worm which business networks that use ESET software can be completely infected.

ESET software uses a mini-filter to intercept all input and output (I / O) to the hard disk, analyze and then emulate in case it comes to executable code. Through emulation, a file can be carried out partially before the virus signatures are used to determine whether the file is malicious or not.

Through the browser, email client, instant messaging, file sharing, network, USB and many other ways an attacker disk I / O and so cause execute the attack. The problem is in fact caused by the emulation performing ESET. The emulator does not appear to be robust and easy to compromise, says researcher Tavis Ormandy of Google. They may run malicious code with root privileges.

The problem is at all ESET products, including virus scanners for Linux, Mac OS X and Windows. As proof Ormandy developed a working exploit which systems to attack from a distance. Last Friday warned Google ESET, where the results were discussed in person with the company. Three days later, on Monday, the Slovak virus fighter came with an update to resolve the issue.

Risk

According to Ormandy, however whether users are the risks and benefits of security weigh. In the past, even though Ormandy revealed major problems in the anti-virus software from Sophos , and this week it was announced that the NSA and GCHQ to vulnerabilities have sought in anti-virus programs. Attacking users through their virus is therefore not a theoretical risk, according to Ormandy.