Showing posts with label Whitelist. Show all posts
Showing posts with label Whitelist. Show all posts

Thursday, 2 July 2015

Researcher Circumvents NoScript Firefox Through Google Cloud


A researcher has managed to circumvent the popular Firefox extension NoScript by using the Google cloud. NoScript is an extension that can block JavaScript and other code on websites. It thus prevents malicious code on a compromised Web site can be started or ads, trackers and active content are automatically loaded.

The add-on protects both security and privacy. More than 2.2 million Firefox users have installed NoScript, making it one of the most popular extensions for Firefox. NoScript also allows users to set up a whitelist domains. Scripts in this domain will be run automatically. Some areas are already standard on the NoScript whitelist, such as Mozilla, YouTube, Google and Yahoo.

This concerns not only the fields, but also the sub-domains under the domain. Besides google.com also scripts on voorbeeld.google.com automatically accepted by NoScript. Recently discovered researcher Matthew Bryant that one of the areas that had expired stood on the NoScript whitelist and thus was available to everyone. Bryant registered the domain and placed here Javascript code, which automatically performed by NoScript. The developer of NoScript came with an update so that the domain from the default whitelist has been removed.

The publication of Bryant urged another researcher to look for a new opportunity, as well as subdomains of whitelisted domains attack vector for an attack can be used. Researcher Linus Sarud saw that the domain googleapis.com standard in the whitelist, meaning that script code storage.googleapis.com this is done by default. Through this domain, users can host files as they use the Google cloud storage. Another researcher named Mathias Karlsson worked out the idea and came up with code that NoScript was again defeated.

The problem has been fixed by the domain googleapis.com change to the whitelist in ajax.googleapis.com . However, subdomains are still automatically whitelist. Users of NoScript, however, can delete the default whitelist and only own domains to this place.

Thursday, 4 December 2014

Kaspersky - Regin Malware Copy 1999

The Russian anti-virus firm Kaspersky Lab has a copy of the advanced Regin-espionage malware found in 1999. This involves the oldest copy that is known up to now. Earlier, a specimen was labeled in 2003 as a senior. The existence of Regin was recently made ​​public by several anti-virus companies.

Regin Platform Diagram

An analyst at Kaspersky Lab named the malware even more sophisticated than Stuxnet . Yet there was also criticism of the anti-virus companies as long as they would have waited to disclose the information. The Russian anti-virus company this refers to a comparison of Sean Sullivan from F-Secure. He likened the search for Regin with the work of paleontologists who found the bones of an unknown dinosaur. Everyone has a bone, but the entire skeleton is missing.


In the case of Regin Kaspersky Lab discovered in 2012 damaged "bone" of a hitherto unknown malware. Figuring out the size of a particular campaign or espionage malware family can sometimes take months or years, the company notes. As it sometimes worked with other parties who may have other parts of the malware possession. "It makes little sense to publish your discovery until you can confirm that the samples really are big and dangerous," said the Russian anti-virus company.

Most Regin copies date from 2007, 43 pieces in total, followed by 35 copies in 2009. Kaspersky also addresses accusations that anti-virus companies, the existence of Regin would have concealed. "We have never been asked by a customer or government agency to whitelist certain malware or to pass through. We would never meet such a request, no matter who it comes from."