Showing posts with label Vulnerability News. Show all posts
Showing posts with label Vulnerability News. Show all posts

Wednesday, 5 September 2018

Google Chrome Will No Longer Show 'Protected' At HTTPS Sites



To celebrate the tenth anniversary of Google Chrome, a new version of the browser has appeared that does not show the word 'secured' at https sites, makes using Flash Player more difficult, introduces an improved password manager and fixes 40 security vulnerabilities.

On 2 September 2008 , Google launched its own browser, which has since become the dominant browser. According to StatCounter, Chrome has a market share of almost 68 percent on the desktop . In the Netherlands, around 54 percent of desktop users would browse with Chrome. Yesterday evening the 69th version of Chrome appeared that contains all kinds of new features and improvements.

This allows Chrome 69 to enter passwords, address details and credit card numbers more accurately. It is data stored in the user's Google account and accessible directly from the Chrome toolbar. The browser also has an improved password manager that can generate unique passwords for websites and accounts. Saved passwords are then available to users with a Google account on both the computer and mobile devices.

Furthermore, Chrome 69 does not show the word "secured" on websites with a secure connection. Only the lock icon indicates that a secure connection is being used. Eventually the lock icon will also disappear. Google decided in July to display the message "Unprotected" at all http sites. The internet giant wants https sites to be the norm and users will only see a notification at http sites.

Also, in the browser measures have been taken to make the use of Adobe Flash Player more difficult. Previously, users could whitelists websites that wanted to access the built-in Flash Player. That has now changed. Users must allow this separately each time a website wants to enable Flash content, regardless of whether they have done so in previous sessions.

In addition, Google has fixed 40 vulnerabilities in the browser that prevented an attacker from stealing or modifying data from other websites in the worst case scenario. Updating to Chrome 69.0.3497.81 will happen automatically on most systems. For Android users, Chrome 69.0.3497.76 has been made available.

Tuesday, 4 September 2018

Google Employee Hacks RFID Access System Own Office



A Google employee hacked the RFID access system of Google's own office in Sunnyvale, allowing him to open doors without an access pass and prevent other employees from gaining access. Google uses the iStar Ultra and IP-ACM systems from supplier Software House. The access system works via an RFID access pass.

Google employee David Tomaschik monitored the encrypted network traffic of the iStar Ultra and IP-ACM systems. The encrypted traffic turned out not to be random, whereas it should have been the case. Further research by Tomaschik revealed that all Software House devices used a hard-coded encryption key. This made it possible to forge commands, such as the command to open a door. He was also able to replay captured network traffic and thus open or block a door.

Furthermore, it was possible to perform these actions without creating a log. Software House has developed a solution, but organizations where the vulnerable systems are in use are still at risk, according to business magazine Forbes. Google also mentions that it has segmented its own network to provide protection against vulnerable systems.

Monday, 12 March 2018

Recent Adobe Flash Player Vulnerability Leak Attacked Via Exploit Kits



A recently patched vulnerability in Adobe Flash Player is being actively attacked via exploit kits. This means that visiting a hacked website or seeing infected ads with a vulnerable Flash Player version is sufficient to infect with malware.

The vulnerability in question was resolved by Adobe on February 6 through an emergency patch . The vulnerability appeared to have been targeted against South Korean organizations since last November . Here Excel and Word files with embedded Flash objects were used. Now it appears that cyber criminals also have the exploit to use them via the web.

Flash Player was and still is the most popular target for exploit kits. Due to the absence of new exploits, and the fact that more and more browsers are phasing out the support of Flash Player, the effectiveness of exploit kits has declined sharply in the past period . According to researcher Kaffeine of the Malware do not need coffee blog , this is the first new Flash exploit that has been added to an exploit kit since July 2016 for a Flash leak. The new Flash exploit will be deployed via infected ads and will successfully install the Hermes ransomware. Users are therefore advised to upgrade to Flash Player version 28.0.0.161 or later, as the vulnerability has been corrected.

Wednesday, 28 February 2018

Decrease Of Malicious Advertisements In The Second Half Of 2017



The number of malicious advertisements that Internet users tried to infect with malware, tried to deprive data or attempted to defame it in another way, was reduced in the second half of 2017, security company RiskIQ claims. In the third quarter, the security company detected 53 percent less malvertising than in the second quarter of 2017. In the fourth quarter, this decline continued and 10 percent fewer malicious ads were detected.


The use of advertisements to attack unpatched internet users, for example through vulnerabilities in Adobe Reader or Internet Explorer, decreased by 36 percent in the third quarter and 20 percent in the fourth quarter. Other malware in ads decreased by as much as 67 percent in the fourth quarter. The fourth quarter, however, saw an increase of 16 percent in the number of ads pointing to a scam, but overall there were fewer rogue ads in both the third and fourth quarters.

Tuesday, 24 October 2017

25,000 Fortinet Devices Vulnerable To DUHK Attacks


Over 25,000 Fortinet devices used for vpn connections and accessible via the Internet are vulnerable to a new DUHK cryptographic attack, allowing attackers to decrypt passive vpn connections to read traffic.

DUHK stands for Do not Use Hard-coded Keys and was developed by Matthew Green , cryptographer and professor at Johns Hopkins University, in collaboration with Nadia Heninger and Shaanan Cohney. Vulnerability occurs with the ANSI X9.31 Random Number Generator (RNG) in combination with a hard-coded seed key. The ANSI X9.31 RNG is a more than 20 year old algorithm that was used to recently to generate cryptographic keys that are used to protect vpn connections and web sessions so that third parties can not intercept.

Through the DUHK attack, an attacker of vulnerable implementations can detect the secret encryption key, thus decrypting and reading traffic from vpn connections and web sessions. This may include sensitive information, such as company information, login information, credit card information, and other confidential content. The ANSI X9.31 RNG is used in many government-certified products. Until last year, ANSI X9.31 RNG was one of four number-generators approved by the United States for use in cryptographic modules. However, it has been removed from the list.

Network manufacturer Fortinet made use of this vulnerable number generator. It's about devices with FortiOS 4.x. All Fortinet vpn devices with FortiOS 4.3.0 to FortiOS 4.3.18 can be decrypted by a passive network attacker who can detect encrypted handshake traffic. Fortinet released FortiOS 4.3.19 last year to update the problem. According to Green, there are more than 25,000 vulnerable vpn devices on the Internet. The professor argues that it is a "conservative number", as only machines were counted that responded to the researchers' scans. The researchers have published a document with their findings ( pdf ) but will not disclose the attack code.

WordPress Sites Attacked Via Zeroday Leak In Plug-In




A zeroday leak in the WordPress plug-in Ultimate Form Builder Lite is actively used to attack and acquire websites before an update was available. Ultimate Form Builder Lite is a WordPress plugin for creating contact forms and runs on over 50,000 websites.

Vulnerability was discovered by security investigators of Wordfence.Wordfence already warned Zeroday leaks in three plug-ins, named Appointments, Flickr Gallery and Registration Magic-Custom Registration Forms, which were actively attacked. These three plug-ins were used in total by 21,000 websites. During the investigation of the attacks, the researchers discovered that attackers had also provided it with WordPress sites with Ultimate Form Builder Lite.

The attackers used SQL injection in combination with a php vulnerability. By sending one request, attackers could completely take over vulnerable websites. The developer of the WordPress extension was informed on October 13 and rolled out an update on Sunday, October 22, which solved the problem.

Monday, 23 October 2017

Attack Via Office DDE Feature Also Works In Microsoft Outlook



The Microsoft Office DDE feature currently used to attack Internet users through Word documents also works in Microsoft Outlook, so researchers have shown. The attack can be performed by sending emails and calendar invitations set up in Rich Text Format (RTF).

The Dynamic Data Exchange (DDE) feature of Microsoft Office makes it possible to inject data from, for example, an Excel document into a Word document. This will add code to one document that points to the data in the other document. Instead of a document, malicious code may also be linked. Attackers now use this feature to infect internet users through Word documents with ransomware and other malware.

The attackers send emails that have attached a Word document. As soon as the recipient opens the document, he will see several dialog boxes asking for permission to run the code that is linked. However, it is not necessary to send Word documents, so researchers have shown . Researcher Kevin Beaumont found a way to use the DDE feature in Microsoft Outlook via e-mail. In this case, users get the same notification as with Word asking for permission to execute code.


In addition to a RTF-generated email, the attack can also be performed via a calendar invitation. According to anti-virus company Sophos , the attack is easy to stop, users need to click on no-click in the first window asking for code execution. If the user clicked yes in the first window, a second dialog will appear for permission. Only when yes is clicked is the code called through DDE executed. Another option that users can apply to protect themselves is to display emails in plain text.

Monday, 9 October 2017

WordPress Sites Vulnerable By Leak Into Postman SMTP Plug-In



Over 100,000 WordPress sites are vulnerable due to a vulnerability in the Postman SMTP plug-in, and a developer security update is not yet available. Postman is an SMTP mailer that helps send emails generated by the WordPress site.

The plug-in is vulnerable to reflected cross-site scripting, which allows an attacker to steal the content of cookies from, for example, the administrator, according to security company White Fir. Due to the unpatched vulnerability, WordPress decided to remove the plug-in from the database with available plug-ins on WordPress.org . Meanwhile, GitHub has published a patched version of Postman, but it has not been developed by the original author. The original developer would have been informed about the problem.

Wednesday, 4 May 2016

Many Websites Vulnerable ImageMagick Leak


A serious vulnerability in ImageMagick , a popular software library to handle with graphics, ensures that a large number of websites are vulnerable and at risk of being hacked. In case a website allows users to upload an image and using ImageMagick, an attacker can, at worst, run arbitrary code on the Web server.

Several plug-ins for image processing depend on the ImageMagick library, such as PHP's imagick, Ruby's RMagick and paperclip and NodeJS's imagemagick. The vulnerability is called " ImageTragick received" and was discovered by security researcher Nikolay Ermishkin . According to researcher Ryan Huber, it's easy to make abuse and will exploit them for short term appear.

The prediction Huber yesterday evening did turned out to be correct, because now such exploits include published. The developers of ImageMagick have a solution available that prevents the attack. Administrators should add a few lines of code in this case a file used by ImageMagick. A security will be released this weekend.

Wednesday, 20 April 2016

Ad Network Distributes Hundreds Of Infected Ads


A Scottish ad network that gets 10 billion impressions per month in his own words has been used in recent weeks to distribute hundreds of infected ads. Through the ads, which appeared under other porn sites and torrent sites, ransomware was disseminated.

This enables anti-malware company Malwarebytes . The company in the past two weeks had more than 400 unique infected ads of the Scottish advertising network AdsTerra, also known as Terra Clicks stemmed. Malwarebytes decided to warn AdsTerra but has not received a response yet. The ads direct visitors unnoticed by the Magnitude exploitkit. This exploitkit uses known vulnerabilities in Adobe Flash Player and Internet Explorer to infect computers with Cerber-ransomware.

Users who are not redirected to the Magnitude exploitkit, for example because they use certain security software or a virtual machine, will see a pop-up that there is a problem with their computer and they need to call a helpdesk. These are the familiar phone scam in which fraudsters try to gain access to the computer and victims to resolve not charge existing problems.

Tuesday, 19 April 2016

Adobe: Flash Player Security Thwart Hackers


Adobe security measures in recent months have added to Flash Player ensures that hackers could not carry out successful attacks on the media player during a recent hacking contest, as the software company announced.

During the annual Pwn2Own contest hackers are rewarded for demonstrating unknown vulnerabilities in different browsers and Adobe Flash Player. During the last edition of March Flash Player was finally twice successfully hacked , but that number could be higher, says Peleus Uhley of Adobe. In preparation for the hack contest Adobe rolled several updates to enhance the security of Flash Player.

These measures paid off as several attempts to hack Flash Player failed thus said Uhley. Still, Flash Player has been successfully hacked twice. "These victories show that there is always more vendors can do to improve security," he continues. Uhley notes that companies such as Adobe, Microsoft and Google are engaged in a race with hackers.

Adobe invests in his own words than a lot of security and regularly adds features to thwart it. hackers as only goal. "Such measures are increasingly being added. The companies themselves will change on the frontline of this battle and to grow the more expensive." According Uhley help hacking contests like Pwn2Own software companies to develop. "While Pwn2Own each year seems to take the same required innovations and challenges to books every year results," said Uhley.

Friday, 12 February 2016

Ads On Skype Spreading Ransomware



Cyber Criminals have managed to show ads to Skype users who were trying to infect computers with ransomware, says anti-virus firm F-Secure. Although the ads appeared within Skype, does not mean that the browser is not open to advertising.


In the case of observed infected ads which showed the browser unnoticed load a page with the Angler-exploitkit. This exploitkit uses known vulnerabilities in Adobe Flash Player to infect computers with malware. Users who had not patched their Flash Player could become so infected with the Tesla Crypt-ransomware. Like other ransomware encrypts Tesla Crypt sorts files for ransom. The ads on Skype came from the AppNexus-advertising platform, which in the past often for the spread of infectious advertisements used. Meanwhile, the offending ads are no longer displayed.

Thursday, 11 February 2016

Russian Hospital Hacked Via Wifi And Old XP Flaw



A researcher has managed to hack a Russian hospital by a weak wifi password and a nearly 8-year-old vulnerability in Windows XP. The hack took place with the permission of the hospital in Moscow, let researcher Sergey Lozhkin know anti-virus company Kaspersky Lab.

He was using the Shodan search engine discovers a login portal of a CT scan machine hospital, which was only secured with a default password. Lozhkin had a friend who controlled the hospital and warned him. The hospital then agreed to an informal penetration test. The researcher decided to attack the hospital could do as a real attacker and began the Wi-Fi network of the hospital. He managed to retrieve the password through a brute force attack, let it faces Threat Post know.

After he had gained access to the wireless network he found a Windows XP machine that contained a vulnerability that Microsoft on October 23, 2008 had been patched. However, the update was not rolled out by the hospital. It was the vulnerability that also used the infamous Confickerworm to spread. Lozhkin then managed on the network to find the administrator panel of an MRI machine that was not password protected. Through the panel he had access to patient data and diagnoses were performed by the machine. According to the researcher shows his work that IT security too often forgotten by software developers, both in the medical industry and in other sectors.

Google Stops From 2017 With Flash Ads


From January 2017 Google stops displaying Flash ads on their own ad networks, such as the Google Display Network and DoubleClick, as the Internet giant has over Google Plus disclosed. According to Google, it's important for advertisers to switch to HTML5 ads, so many people can be reached.

To accelerate this process will AdWords and DoubleClick Digital Marketing from June 30 to accept new Flash ads this year.From January 2, 2017 Flash ads will no longer be on the Google Display Network are displayed via DoubleClick. Google warns advertisers that they should have converted their ads to HTML5 for these dates. For now, the new measure does not affect video ads created in Flash.

Google has long been working to make Flash unnecessary. As YouTube videos are automatically played through HTML5. In the case of Flash ads that are distributed through AdWords, which are automatically converted to HTML5 since February last year. Since September 1st of last year, most Flash ads automatically in Google Chrome paused .

Last year, also called Alex Stamos, the new Chief Security Officer (CSO) of Facebook, which with Adobe Flash technology to stop , so that it can be switched completely on HTML5. HTML5 is natively supported by modern browsers and allows playback of videos and other "rich content" without installing additional plug-ins possible.

Wednesday, 10 February 2016

Major Updates For Windows, IE, Office And Edge


During the February Patch Tuesday, Microsoft released 13 security updates for critical vulnerabilities in Windows, Internet Explorer, Microsoft Edge Office, Microsoft Server Software, the .NET Framework and Adobe Flash Player. Six of the updates are rated as critical.

In this case, an attacker could execute arbitrary code on the computer with hardly any user interaction. It involves, for example just visiting a malicious or hacked website. The remaining updates are for vulnerabilities that an attacker who already had access to a system to increase its rights or cause a denial of service.

Two of the vulnerabilities in Microsoft SharePoint and Windows, were already known before Microsoft had released an update.These vulnerabilities would not be attacked active. Most problems have been resolved in Internet Explorer. It involves a total of 13 vulnerabilities. There are also two critical vulnerabilities in the built-in PDF reader in Windows 8.1 and later. Via a malicious PDF document, it was possible for an attacker to take over your computer. An overview of all updates on this page to find. Updating is done on most Windows computers automatically.

Adobe Close Critical Vulnerabilities In Flash Player And Photoshop



Adobe has patched critical vulnerabilities in Flash Player and Photoshop computers could allow an attacker to take complete. In the case of Flash Player is about 22 critical vulnerabilities which allowed an attacker to execute arbitrary code on the computer, such as installing malware by just visiting a hacked website or see it from an infected ad.

There was no further interaction required from users. As far as known vulnerabilities are not attacked on the Internet. Since attackers often develop after the release of Flash Player updates exploits to attack unpatched users, Adobe advises to update to Flash Player version 20.0.0.306 within 72 hours. This can be done via the automatic update function or Adobe.com. In the case of Google Chrome, Internet Explorer 10 and 11 on Windows 8 and 8.1 and Internet Explorer 11 and Microsoft Windows 10 Edge Embedded Flash Player will be updated using the browser. Through this Adobe page can be verified that the system version is installed.

There is also a security update for Adobe Photoshop CC and Adobe Bridge CC appeared. The update fixes three critical vulnerabilities that an attacker could take over your computer if opened a malicious file. Because Photoshop traditionally not been a target for attackers, Adobe advises users and administrators to install the update if it suits them. Updating via the built-in updater of drawing programs. In the case of Photoshop CC 02.04.2014 is the update to download only via Adobe.com.

Saturday, 28 November 2015

Leak VPN Providers Can Reveal IP Address Users


A vulnerability in some VPN providers can ensure that the real IP address of users is revealed, warns VPN provider Perfect Privacy. A VPN (Virtual Private Network) is a secure connection between a computer and a server elsewhere on the Internet.

This connection is encrypted which others can not observe. All Internet traffic to and from the computer goes through this route shielded and can on this part will not be overheard. Additionally, VPN users can thus protect their IP address as websites visited only see the IP address of the VPN provider. According Perfect Privacy walk users of some VPN providers still risk their real IP address is known.

Port forwarding

The problem is with VPN providers offering port forwarding. It does not matter whether users of the VPN providers themselves use port forwarding, only the attacker must set it. To determine the IP address of a victim, there must be fulfilled several conditions. For example, the attacker must have an active account with the same VPN provider and the victim. The attacker must know the 'exit' IP address of the victim and the victim to open a file or page.

An attacker who port forwarding is activated can then request to see the image or website which the real IP address of the victim is from. In total, nine tested Perfect Privacy VPN providers, of which five were found vulnerable. These parties have been notified. The problem, however, with other VPN providers are not tested, warns Perfect Privacy.

BitTorrent

According to security expert Darren Martyn can leak be used to expose BitTorrent users who illegally download copyrighted material. To shield their IP address are BitTorrent users who use a VPN service. By leak holders can still see the IP addresses of illegal downloaders. Martyn expects that companies connected with suing copyright infringers concerned will use this vulnerability to sue BitTorrent users.

Hacked Site Reader's Digest Spread Malware


Attackers have managed to hack the website of Reader's Digest and use this now to spread malware. Before that anti-malware company cautions Malwarebytes. According to the company, there is an increase in the number of hacked WordPress websites and Reader's Digest is one of them.


On the hacked websites is placed code that visitors unnoticed to a page with the Angler-exploitkit forward. This exploitkit is using known vulnerabilities in Adobe Flash Player and Internet Explorer users have not patched. In case the attack is being installed Bedep Trojan on the computer successfully, which can install additional malware again.

Reader's Digest was a few days ago warned by Malwarebytes, but the security company and got no response when a blog posting about the infection appeared online yesterday distributed the website still malware.

Friday, 27 November 2015

EFF Wants Stronger Encryption Against Terrorists And Criminals



If the government were to ask people to remove the good locks on their doors and windows and replacing them worse so that government employees can penetrate more easily in case someone is a terrorist, no one would accept this because bad locks make everyone vulnerable.

Yet this is exactly what governments and law enforcement agencies in the case of encryption will, according to the American civil rights movement EFF. Regularly advocate agencies like the FBI to add backdoors in encryption, ensuring encrypted communication can still be tapped. This is similar to prevent people from getting access to good locks and locksmiths can produce good locks.

In this last example, most people would understand that this is not a wise idea, says Cindy Cohn of the EFF. However, when it comes to Internet and technology, such as the operation of encoding, which for many people is less clear. Parties such as the FBI and politicians would also have known better, says Cohn. "The answer to insecure networks and digital technologies must be correct in order to make them safer."

But that is not what is happening, so she continues. Policymakers are therefore urged to take this into account. "Ensuring that everyone's door is unlocked, is not the answer to crime or terrorism. That is the development and support of better security," Cohn decision.

Thursday, 26 November 2015

Millions Of Vulnerable Devices By The Same Encryption Keys


Researchers warn that millions of devices such as Internet routers, IP cameras and modems are vulnerable because they use the same encryption keys. Attackers can therefore perform man-in-the-middle attacks and eavesdropping and decrypt encrypted traffic.

Therefore might enter sensitive information into the wrong hands. The problem is with so-called embedded devices, including routers, modems, IP cameras and VoIP phones. Researchers from security firm SEC Consult watched for their research firmware more than 4,000 such devices from more than 70 manufacturers.

They mainly looked at cryptographic keys in firmware, such as public keys, private keys and certificates. It mainly involves keys that are used to connect through SSH and X.509 certificates used for HTTPS. In total, were found more than 580 unique private keys in the 4,000 studied devices.

This information was then correlated with data from large-scale Internet scans. It emerged that the dataset with the 580 unique keys contains the private keys of 9% of the HTTPS web hosts and the private keys of more than 6% of all SSH hosts.At least 230 of the 580 keys were actively used and seen by millions of hosts.

The keys are added by manufacturers to provide connection via HTTPS and SSH. The problem is that all devices with the appropriate firmware using the same keys. It was remarkable that the same keys were found in the products of different manufacturers. For example, a certificate of Broadcom were found on the Internet at more than 480,000 units, including Linksys and ZyXEL. The problem also arises in Cisco, Huawei, Ubiquiti Networks and other vendors. The devices are especially vulnerable in the United States (26.3%) and Mexico (16.5%).

Solution

SEC Consult has worked with the CERT Coordination Center (CERT / CC) at Carnegie Mellon University to warn the manufacturers involved and browser developers. Meanwhile, some parties have released updates. Manufacturers also are advised to use unique cryptographic keys for each device. In addition, Internet service providers to ensure that remote access over the WAN port to the equipment of their subscribers is not possible. Finally end users are advised to generic SSH keys and X.509 certificates on their devices to replace unique versions. However, the CERT / CC states that in many cases, there is no practical solution is available.