Showing posts with label Threats. Show all posts
Showing posts with label Threats. Show all posts

Wednesday, 25 October 2017

Security Company Develops DDE Feature Patch In Microsoft Office



A security company has developed an unofficial patch for the DDE feature in Microsoft Office where cybercriminals are currently exploiting abuse. Dynamic Data Exchange (DDE) is a feature that was added to older Windows versions and is still used in many places. The feature allows you to inject data from, for example, an Excel document into a Word document.

In the event that the Excel document is updated, this will be immediately visible in the Word document. However, the DDE feature also makes it possible to call a malicious application instead of Excel or a benign application that performs malicious commands. To perform the called application, the user must first give permission to two dialog boxes.

However, this does not seem to be a problem, as the functionality is currently being used by cyber criminals. Microsoft is not currently planning to resolve the issue through a security update. However, the Windows 10 Fall Creators Update features the Windows Defender Exploit Guard that can block attacks via the DDE feature. Since Microsoft did not get a patch for the time being, security company ACROS decided to look into the possibilities to develop a patch.

The result is a " micro-patch " for Office 2007, 2010, 2013, 2016 and 365, both the 32-bit and 64-bit versions. The patch causes the DDE feature not to invoke the specified application. Microsoft Word will still display the two dialog boxes, but if the user click here yes, the called application will not be executed. To install the micro patch, the free 0patch Agent software must run on the system. This is an unofficial patch and the use is at your own risk. ACROS has previously developed micro-vulnerability vulnerabilities in Windows and Foxit Reader, among other things.

Tuesday, 24 October 2017

Windows Defender Exploit Guard Protects Against DDE Attacks



With the launch of the Windows 10 Fall Creators Update, Microsoft has added new security measures to the operating system, which, among other things, protect against the DDE attack that has been in the news lately. The new security measures are called Microsoft Windows Defender Exploit Guard. It is a collection of features that should protect users from various threats.

For example, the feature is called Controlled folder access, which protects directories against ransomware. Only authorized applications will have access to files in specified folders in this case. Unauthorized executable files, dll files and scripts will not be accessed, even if they are running administrative privileges. In case ransomware approaches the files in the specified folders, Windows 10 gives a warning.

Attack Surface Reduction


Another feature is Attack Surface Reduction (ASR). This is a set of controls that allow organizations to prevent an attacker from infecting emails, scripts, or Microsoft Office systems. In the case of Microsoft Office, ASR can prevent apps from creating executable content or injecting themselves into a process. Also, macro code is blocked. Another attack that blocks ASR is through the Microsoft Office DDE feature, so Microsoft has announced .

The Dynamic Data Exchange (DDE) feature of Microsoft Office makes it possible to inject data from, for example, an Excel document into a Word document. This will add code to one document that points to the data in the other document. Instead of a document, malicious code may also be linked. Attackers now use this feature to infect internet users through Word documents with ransomware and other malware. Windows Defender Exploit Guard can detect and stop this attack. Furthermore, the feature stops JavaScript, VBScript and PowerShell code, as well as executable content that enters email or webmail.

Exploitation Protection

Windows Defender Exploit Guard also provides protection against exploits. It replaces Microsoft's well-known Enhanced Mitigation Experience Toolkit (EMET). Like EMET, Exploit Guard provides the system with additional security that provides protection against known and unknown exploits. The Fall Creators Update will remove EMET on Windows 10 computers if this tool is installed. EMET users can import their settings within Exploit Guard. The Fall Creators Update will be rolled out in Windows 10 in the coming months and can be installed manually .

Tuesday, 8 April 2014

Symantec: New era of mega-data leaks' has arrived

According to Symantec, a new era of "mega-data leaks' dawned. Cyber ​​attacks are becoming larger and cost tens of millions of dollars in damage.



At the end of 2013, the most damaging cyber attacks occurred in history, according to the annual Internet Security Threat Report (ISTR) from Symantec. The report shows a significant change seen in the way cybercriminals operate. Kept criminals rather mainly with fast attacks that had a small profit result, now they take months to prepare that generate a lot of money. Larger data leaks for
"A mega attack produces sometimes the same as 50 smaller attacks," said Tom Welling, Security Expert at Symantec Benelux. "Although the level of attacks continues to rise, more and more criminals have more patience and they wait until they can commit to deliver more money with a major attack."

Netherlands
The report also reveals that cyber criminals often use networks in the Netherlands to commit cyber attacks. If so-called "threat-source country rises Netherlands internationally from place to place 7 4. In the top ten of threat-source countries, only the Netherlands and Russia increased relatively strongly in 2013.



Increase
The number of data breaches in 2013 increased by 62 percent compared with 2012. As a result, more than 552 million online identities exposed to cyber criminals. So Cybercrime remains a real and damaging threat to both consumers and businesses. In the Netherlands, the favorite sector of cybercriminals each attack varies. The telecom industry is the biggest target for spam (77 percent), followed by the financial sector (64 percent). When it comes to malware, it is the largest retail target.



Compared to 2012, targeted attacks increased by 91 percent in 2013. Moreover, the attacks in 2013 lasted on average three times as long. Looking at occupations, personal assistants and PR staff are most attacked, because they are often a prelude to prominent figures such as celebrities or executives of large corporations.



Protect
According to Symantec, there are certain steps that businesses and consumers can take to protect against possible data leaks, targeted attacks, or general spam better.

Tips for Business
Know your data: information should be the focus of protection are not the devices or the data center. Knowing where sensitive information is located and where it is flowing, helps determine the best policy and the best procedures to protect the data.

Organization
Inform employees supervised workers in protecting their information. Give them an insight into the corporate policies and procedures for protecting sensitive data on personal and corporate devices.
Implement proper security infrastructure: strengthen the security infrastructure through prevention practices aimed at data loss, network security, endpoint security, encryption, strong authentication and defensive measures, such as reputation-based technologies.



Tips for consumers
Be smart in the field of security: Choose a strong password and update all your devices with the latest security software.
Pay attention: check bank and credit card statements for irregularities and be careful when responding to unsolicited or unexpected emails. Also be alert for online deals that seem too good to be true, because usually they are just that.
Know with whom you work, make sure you are familiar with the policies of retailers and online services that can retrieve bank or personal information. If this information should be shared, please do so via the official website of the company and not through an email link.

Detailed Report