Showing posts with label Website. Show all posts
Showing posts with label Website. Show all posts

Thursday, 4 June 2015

Indian Researcher Can Hack Your Computer Using Just An Image


The hidden using steganography malicious code runs when you view the image in the browser.
Indian security researcher Saum Shah (Saumil Shah) published a report on the attack method developed by him, based on the popular among users sharing links to pictures. The expert was able to hide the harmful executable code in an arbitrary pixel images, thus leaving his exploit in the most prominent place.

Part 1:

Part 2:

The researchers note that hide malicious code directly in the image was the most difficult, and for this he had to use steganography. Parts of malicious code distributed in Shah pixel image that allows you to decode them back using Canvas element of HTML 5, a conductive dynamic rendering of images.

"For a successful attack I do not have to worry about hosting your own web-site. I do not even need any domain, - the expert emphasizes. - I can take a picture, post it in the public domain, and if the victim load it in your browser, it will compromise the system. "

Separately, an expert noted that the changes occurring in the final image of the presence of extraneous code, visible only at multiple zooming images. His attack technique called Shah Stegosploit, and its details he revealed in a recent held in Amsterdam conference on Information Security Hack In The Box. Video with the details of attack, and expert commentary published on YouTube.

PDF

Tuesday, 17 February 2015

Cookies Have Life Of 7985 Years



Cookies that websites place on the computers of visitors may 7985 last year, according to international research that was conducted in the Netherlands ( pdf ). The 59 sites were surveyed Dutch total 2089 cookies behind. Dutch media sites on average put most cookies per visitor 42.2. Webshops follow with 25.9 cookies. Dutch websites scoring average this.

It is mainly British media sites (83.1 cookies), French media sites (73.8 cookies) and Danish media sites (75.3 cookies) protruding. The study also specified where cookies come from. In the case of the Dutch sites, there were 607 of the 2089 cookies originating from the visited website. The remaining 1482 cookies were placed by third parties such as advertisers and trackers. Netherlands ends with this agent in the moot.

Websites can also specify if the cookies expire. Two Danish and one British website have their cookies on 31/12/9999 expired. Ie about 7985 years. In total, 15 sites were found to place cookies with a lifespan of over 100 years. The average lifespan of a cookie that is placed by the visited website is 14.34 years. Cookies are not counted over 100 years, then the researchers at two years out.

In the case of cookies from third parties, there was a French website that a third party cookie left behind that 7985 year went along. A total of 15 third parties were found placed 27 cookies with a life of more than 68 years. The average lifespan of any "third party" cookies thus amounts to 1.77 years. Cookies are more than 68 years are not included, the average life is 1.33 years. Most third-party cookies come from Doubleclick.net , which was found on 213 web sites and placed 247 cookies.

"Setting a long expiration date for a cookie does not only mean that the device's usefulness will survive, but the person using it at the time. Although the life of a cookie on a device depends on the purpose for which it was placed, it is difficult for an expiration date in the year 9999 to justify, " says Simon Rice of the UK Information Commissioner's Office.

Thursday, 1 January 2015

Security Researcher Hijacks PayPal Accounts via Flash File


A security researcher has discovered a flaw in the PayPal website so he could take over users' accounts. The vulnerability was in the page to generate invoices. The page allows users to upload different types of files. PayPal turned out only to check the extension of the uploaded files, not the content, so the researcher discovered.



This allowed him to a Flash file with full read on www.paypal.com upload. Then, to take account of a user, the user must visit a Web site of the researcher. The researcher can then execute arbitrary commands with the PayPal account, such as the transfer of money and steal data.



The researcher reported the problem with us that rewards bug reports through a special program. However, eight days after he was told that another researcher had already reported the problem and, therefore, no compensation was paid. "I know that researchers sometimes find the same bugs, but I think that PayPal better to deal with this double bug reports," said the disappointed researcher.

Monday, 15 December 2014

'SoakSoak' Malware Infected 100,000+ Wordpress Websites




At over 100,000+ WordPress sites researchers have found malicious code that attempts to infect visitors with malware. The code is loaded from the Russian domain SoakSoak. Google would now more than 11,000 infected websites have put on a blacklist.


Visitors who use Firefox or Chrome receive when visiting these WordPress sites a warning that the site contains malware. According to security firm Sucuri is the number of affected sites much larger and would amount to more than 100,000 WordPress installations. Also on the forum WordPress complain many users SoakSoak on their website.

How the attackers managed to get the malicious code on the WordPress sites is still unknown, but it is suspected that the sites a vulnerable version of the WordPress Slider Revolution use premium plugin. By September WordPress sites with a vulnerable version of the plug-in even though the target of attacks.