Showing posts with label Zero-Day Vulnerability. Show all posts
Showing posts with label Zero-Day Vulnerability. Show all posts

Sunday, 8 November 2015

NSA Would Most Zero-Day Vulnerabilities In Software Report


The NSA would be 91% of the most critical zero-day vulnerabilities it finds in software used in the United States or developed report, as the US Secret Service let the website know. How many software vulnerabilities and what exactly is going unreported.

The remaining 9% of the vulnerabilities found is resolved before the NSA, the supplier can inquire or is not reported due to national security reasons. Zero-day vulnerabilities are vulnerabilities for which no security update from the vendor is available.Through this kind of leak attackers have a greater chance of a successful attack, for example, to gain access to systems.

"The US government is committed to an open, interoperable, secure and reliable internet. In most cases, the reporting responsibility of a newly discovered vulnerability clearly in the national interest," according to the explanation of the NSA.Secret Service claims that there advantages and disadvantages to the decision to report a leak. This could cause the possibility of being lost to collect important foreign intelligence among other "terrorist attacks" may occur.

The NSA now uses a process to determine when it reports a vulnerability. "While these decisions may be complicated, the government tends to be a responsible and discreet reporting vulnerabilities." According to current and former government officials, the reassurances of the NSA, however, misleading, because the Secret Service vulnerabilities yourself first used to conduct attacks them before the companies inform that these problems can fix and patches to users can roll, reports news agency Reuters .

Friday, 2 October 2015

Symantec: WinRAR Flaw Less Serious Than Thought




A vulnerability in the popular WinRAR archiving progam which no update is available, and for which recently the National Cyber ​​Security Center (NCSC), the government warned is less severe than thought, say Symantec and developer RARLAB.

WinRAR is a very popular program for packing and unpacking files. Besides the standard RAR archive, the software can also make a Self Able Extract (SFX) archives. In this case the archive file is unpacked automatically when the user opens the file, regardless of whether they have installed WinRAR or not. SFX archives are basically just exe files and consist of the packed file and the un pack module WinRAR. By letting users open a malicious SFX archive an attacker could execute arbitrary code with the rights of the logged-in user, as this video shows.

The vulnerability makes it possible to be carried out when opening the SFX archive automatic code of the attacker, like downloading and installing malware. Contrary to some media reports, the problem not only for users of WinRAR, but to all Windows users who receive a malicious SFX archives. Symantec and RARLAB, developer of WinRAR, users need to open exe files, whether it is an SFX archive or not, always be careful.

RARLAB said in a statement that there are much simpler ways to attack users via a malicious SFX archive. Users also are advised not to open unexpected files or files from unknown or untrusted sources. The developer of WinRAR is therefore no plans to remove the option is now displayed where the use of attack, as this only legitimate users would hit.

Tuesday, 4 August 2015

Adware Uses Zero-Day Vulnerability In Mac OS X



A vulnerability in Mac OS X last month by a German researcher was revealed and has not yet been patched by Apple is now actively used by adware. Through the vulnerability could allow a local attacker to increase his or application user rights.

Anti-virus firm Malwarebytes recently discovered an adware installer that uses the vulnerability to gain root privileges on Mac computers. Besides installing the VSearch adware installer also installs the adware Genieo and the very controversial MacKeeper on computers. Finally sends users to the Mac App Store to download the Download Shuttle app there. Do not know where the adware is offered exactly Malwarebytes late, but the company advises users to be careful what they download.

Tuesday, 14 July 2015

Hacking Team Has BIOS Rootkit For Permanent Infection



The Italian Hacking Team has an UEFI BIOS rootkit to infect computers with spyware permanently from the company. This enables the Japanese anti-virus company Trend Micro on the basis of the data that was recently at the Italian company captured.

Hacking Team offers government agencies a "Remote Control System" (RCS) allows investigators to remotely access the computers, for example, suspects can get. To ensure that the software remains on computers even if the hard drive is formatted or replaced by a new one, Hacking Team has an UEFI BIOS rootkit developed.

The BIOS (Basic Input / Output System) and the Unified Extensible Firmware Interface (UEFI), the successor to the BIOS is a set of basic instructions for communication between the operating system and hardware. It is essential for the operation of the computer, and also the first major software that is loaded. In the case of Hacking Team involves a rootkit for UEFI BIOS, Insyde Software. The company makes BIOS software for laptops.

Physical Access

To install the rootkit do have to have physical access to the system can be obtained. According to analyst Philippe Lin Trend Micro can not be ruled out that it is also possible to remotely install the rootkit. The Italian company also developed a tool to help users of the rootkit and provides support in the event the BIOS image is not compatible. According to Lin, the rootkit can be modified so that it also works with other BIOS software, such as the well-known software vendor AMI.

To protect themselves against the attacks, users of Lin's advice to enable UEFI Secure Flash BIOS, update the BIOS if updates are available and set a password to access the BIOS or UEFI. However, it is in many computers as possible to reset the password, but in this case, a user can see that something is wrong because he forgot no longer have to specify whether his original password no longer works.

Tuesday, 10 March 2015

Researchers Develop Attack For Leakage In DRAM Memory


Google researchers have developed an attack for a leak in some DDR3 memory chips so they can get kernel rights on Linux systems or sandboxes can break. " Rowhammer "as the attack is called, is a problem with some DRAM memory chips last year by researchers was discussed.

Memory chips are arranged in a kind of grid pattern of "rows" and "columns". In recent years, memory chips have become increasingly larger capacity, in which the memory cells to be placed closer and closer together. Therefore the costs, but the cell density has negative consequences for the reliability of the memory.

According to researchers, this density can ensure that the cells have an impact on each other. By repeatedly accessing memory rows can corrupt data in adjacent rows. The attack, the researchers takes advantage of Google, which repeatedly accessing a memory array can ensure that bits are in adjacent rows "flipped".

By flipping of these bits, it is ultimately possible to read-write access to get to the entire physical memory, after which it is possible to get kernel rights. A second exploit that developed the Google researchers makes it possible to escape from a sandbox system for the browser.

Impact

The presence of the problem, was tested on 29 different laptops, 15 of which were found to be vulnerable. The total number of vulnerable machines worldwide unknown, and the percentage of affected systems that can be patched. However, the researchers argue that the attack can be adapted to other operating systems. The attack is preventable. So memory manufacturers must ensure that if a system refreshes the DRAM memory, a particular row is not changed often without this happening at nearby stores.

According to security expert Robert Graham require end users to worry about just this vulnerability, but it could be a problem with other bugs. It is also a problem for designers of security solutions, hardware and software, says Graham. The researchers suggest in the report that they were not working for ECC memory the attack. This is memory that can correct errors, but according to Graham, this type of memory still susceptible if an attacker can flip multiple bits.

Meanwhile, network giant has Cisco a study set to sensitive products. In addition, researchers at Google have a tool put online which can be tested on the DRAM problem. They warn that while the use of the tool is not without risks, because these systems can crash.

Tuesday, 10 February 2015

Dailymotion Denies Showing Infected Ads


The very popular video website Dailymotion states that it has shown no infectious ads that tried to infect visitors with malware, but one security expert says that this is not true and users are indeed attacked. On February 2, warned anti-virus company Trend Micro that on Dailymotion.com were infected ads appeared who attacked a new vulnerability in Adobe Flash Player.

At the time of the attack, there was no security available. Were therefore users of Internet Explorer and Firefox on Windows that had Flash Player installed the risk of becoming infected with malware. The observed attack only worked against these two browsers. Later confirmed also anti-virus company Malwarebytes that the infected ads on Dailymotion.com had seen.

Yet Dailymotion poses in a statement that users will not be attacked. All advertisements should be checked namely. JuK security expert criticizes the statement. "That's not right," as he lets on Twitter know. He points to an analysis of the Fiddler tool. This shows that there are infected ads are displayed on Dailymotion.

Sunday, 8 February 2015

Emergency Patch Flash Player Addresses 18 Vulnerabilities


The emergency patch Adobe this week for a critical vulnerability in Flash Player fixes rolled out a total of 18 vulnerabilities. This is evident from the Security Bulletin that the software company has disclosed.Initially suggested that the Adobe emergency patch only attacked leak CVE-2015-0313 rectified.

The update to version 16.0.0.305 was first rolled out only via the automatic update feature of Flash Player. Now the update also manually download the full Adobe Security Bulletin published. Besides leak which the emergency patch initially appeared also includes 17 other vulnerabilities mentioned. 14 of them make it possible for an attacker to take vulnerable computers at worst completely.

Google played an important role in the discovery of the now patched problems. Eight vulnerabilities were in fact discovered by employees of Google and the Google Project Zero team. Four other leaks were reported through the Chromium Vulnerability Rewards Program from Google. Users are advised to update to Adobe Flash Player 16.0.0.305, which can be done via the automatic update feature and Adobe.com . This page shows which version is installed on the computer.

Saturday, 7 February 2015

Flash Player Vulnerability In Chrome And Internet Explorer Patched


Both Microsoft and Google yesterday released updates for a critical Flash Player vulnerability in Google Chrome and Internet Explorer 10 and 11 on Windows 8 and Windows 8.1. The vulnerability was Wednesday already patched by Adobe. Both Chrome on all supported platforms as IE10 and IE11 on the newer Windows versions feature an embedded Flash Player must update Google and Microsoft.

The vulnerability in Flash Player, the last few days and possibly since late last year actively used in attacks against Windows users. This happened partly through contaminated ads on popular websites . The exploit used in these attacks would according to Trend Micro not against Google Chrome users. Adobe also said in the warning that the observed attacks only against Firefox and IE users place on Windows.

In the case of Google Chrome in addition to the Flash Player leak also eleven vulnerabilities fixed in the browser itself.Through these vulnerabilities, an attacker could in the worst case read confidential information of other websites or modify.For most users of both Chrome and IE update will be installed automatically. Through this page , users can check whether they are using the latest version of Flash Player (16.0.0.305).

Friday, 6 February 2015

Ads With Flash Attack On Popular Websites


On several popular websites are infected ads appeared that abuse of a vulnerability in Adobe Flash Player were true at the time of the attack no update was available. It is about the vulnerability where yesterday emergency patch for appeared.

Before the emergency patch was available display ads on various websites infecting users with Flash Player. It was Firefox and Internet Explorer users on Windows. Google Chrome users would have run no risk. It was already known that the infected ads on the wildly popular video site Dailymotion appeared. Now let anti-virus company Malwarebytes know that the ads also include theblaze.com , nydailynews.com , tagged.com , webmail.earthlink.net , mail.twc.com and my.juno.com shown.

The infected ads would have ended through a bidding process on the websites. For only 0.9 cents per impression they were eventually appear. Although this ad campaign was discovered recently left a researcher F-Secure recently know that this particular flaw in Flash Player possibly since December 20 last year will be used for attacks.

The emergency patch will be distributed via the automatic update feature of Flash Player. Google Chrome and Internet Explorer 10 and 11 on Windows 8 and 8.1, which have an embedded Flash Player, the update will eventually be rolled out by Google and Microsoft. However, these updates are not yet available. In the case of IE, users therefore advised to temporarily disable Flash Player or use a different browser.

Thursday, 5 February 2015

Adobe Distributes Emergency Patch Attacked Flash Leak


Adobe has released an emergency patch yesterday rolled out for a critical vulnerability in Flash Player that is actively used to infect Windows users with malware. It is the third emergency patch in a short time made ​​available for Flash Player. The previous patches appeared on 22 and 24 January

In this case, the update to Adobe Flash Player 16.0.0.305 meant for the vulnerability that is identified as CVE-2015-3013. As with the previous emergency patch rollout takes first place among users who have enabled the automatic update feature. This is the default browser plug-in. Expected to appear today manual download.

It also cooperates there with Google and Microsoft. Chrome and Internet Explorer 10 and 11 on Windows 8 and 8.1, namely feature an embedded Flash Player that can be updated using the browser and operating system. The attacks so far observed are directed against users of Internet Explorer and Firefox on Windows 8.1 and older. Previously showed Trend Micro already know that the exploit does not work against Google Chrome. Through this page , see what version of Flash Player is installed on the system.

Wednesday, 4 February 2015

1800 Subdomains Used For Flash Player Attack


Cybercriminals last week a large number of subdomains created and used for attacking Flash Player users. For carrying out the attack, the attackers used more than 50 legitimate GoDaddy accounts that they had hijacked. GoDaddy is an Internet domain registrar where to register. In addition, customers can through the GoDaddy account to manage their domain names. By this steal account information the attackers had access to a large number of domain names.

They used the access to create subdomains , which were then used to host a Flash Player exploit. This is an exploit for a vulnerability in Adobe Flash Player that on January 26 was patched this year. The use of subdomains took place between 26th and 30th of January. Unlike many attacks where cyber criminals hacking and using legitimate websites to infect visitors were not adjusted in this case the main domains.

The attackers used the subdomains created to host the Flash Player operates as well as an exploit for Microsoft Silverlight.Contaminated ads was then made ​​to these subdomains. Users with vulnerable Flash Player who got to see could be infected with malware in this way the ads, according to Cisco . Statistics from VirusTotal shows that exploits barely detected by virus scanners, which indicates that it is important to immediately install the available updates.

Tuesday, 3 February 2015

Symantec Recommends Temporarily Disabling Flash Player


Internet users who are worried about the new vulnerability in Flash Player which no update is available, get anti-virus company Symantec's advice to temporarily disable the browser plug-in. The vulnerability allows cybercriminals in the worst case the computer can take over completely when users visit a compromised or malicious website or see infected ads.

The leak could have been used by infected ads on Dailymotion, one of the most popular video sites on the Internet. Users who have the website with Flash Player and Internet Explorer or Firefox on Windows visited at risk to be infected with malware. "Users who do not block ads and Flash are set to automatically play the most vulnerable," said Adam Winn software company OPSWAT.

He advises Flash Player from users who want to protect themselves against infectious ads to set Click to play and use an ad blocker. "Although controversial ad blocking a highly effective way that enables users to protect themselves against malvertising. An average user can these two things set up within an hour and be sure that he is nearly invulnerable to malvertising and Flash attacks in general "said Winn. Adobe announced this week that it comes with an emergency patch for the leak.

Monday, 2 February 2015

Adobe Vulnerability: "Warning New Attacked Flash Player Leak"

Internet users are warned again a new vulnerability in Adobe Flash Player which no update is available and actively used to infect computers with malware. The vulnerability is in Flash Player 16.0.0.296 and earlier versions.

Visiting a hacked or malicious Web site with a vulnerable Flash Player installation is enough to get infected. The attacks which until now have been observed to focus on users of Internet Explorer and Firefox on Windows 8.1 and older, according to the advisory . The leak, which is listed as CVE-2015-0313, was discovered by researchers at Trend Micro and Microsoft.

Adobe says that it will come this week with an emergency patch. It would be the third emergency patch in less than two weeks. Previously published a need patches on January 23 and January 26 . This emergency patches were for vulnerabilities via contaminated ads , among other porn sites were attacked. Through this page, Adobe, Internet users see which version of the software on their computers and what is the latest version.

Trend Micro let know that the new zero-day vulnerability has been used by infected ads on the website Dailymotion.com . A website according to Alexa on the 83th spot of most visited websites on the Internet is Dailymotion. Visitors to the popular video site were without them knowing redirected to a page with an exploit that made ​​abuse of the Flash Player leak. The attacks since January 14 monitored by the anti-virus company, which is from January 27 to see a spike in the number of users will be redirected to the exploit. Meanwhile the infected ads would not be shown on Dailymotion.

Saturday, 31 January 2015

Vulnerabiltiy: Google Reveals Adobe Reader Leak for Mac OS X


Google has unveiled a vulnerability in Adobe Reader in the Windows version of the PDF reader would be patched, but the Mac version is still present. The vulnerability was reported to Adobe in October last year.In December there was an update for the Windows version appeared, but Adobe had to Google that it had failed to deliver a solution for the Mac version.

This week, however, went the deadline had asked Google. "Project Zero Team" of the search giant is looking specifically for vulnerabilities in commonly used software. Once a leak is found will the supplier 90 days to come up with an update, other details are the vulnerability automatically made ​​public. Adobe was warned by Google that it would reveal the details.

Via the leak, it is possible to let the application crash, which is possible up to a "heap-based buffer overflow" can cause.Noteworthy is the way that Adobe to Google said to have patched the flaw in the Windows version. The leak in question, known as CVE-2014-9160, however, does not appear in the list of Adobe Reader update.

Apple Blocks Unsafe Flash Player On Mac OS X


To protect users from potential attacks, Apple insecure versions of Adobe Flash Player on Mac OS X blocked. Mac OS X has a "Web Plugin blocking mechanism" that Apple regularly will update to block unsafe plug-ins and prevent drive-by downloads.

This weekend Adobe patched a critical vulnerability in Flash Player that is actively used to attack Windows users. Who surfs on Mac OS X with Safari and not using the latest version of Flash Player and a site visit to see the plug-in calls notifies ranging from "Blocked plug-in", "Flash Security Alert" or "Flash out-of-date ". The message is that Adobe Flash Player is outdated and there is a newer version can be downloaded from Adobe.

Flash Player versions on Mac OS X Flash Player 16.0.0.296 and 13.0.0.264. All versions are blocked before. Users who still want to use an older version of Flash Player can do this via the "Internet Plug-in management" in Safari, and so the plug-in running on reliable websites in an insecure fashion. Further notes that Apple users who have problems downloading or installing Flash Player, this should contact Adobe.

Monday, 26 January 2015

Emergency Patch For Adobe Flash Player Attacked Leak


Adobe has this weekend an emergency patch released for a critical vulnerability in Flash Player that asset is used by cybercriminals to infect computers with malware. Because of the vulnerability had Internet Storm Center decided to alert the Internet to color code yellow to increase.

The emergency patch this weekend only rolled out to users who have enabled the automatic update feature, which is the default for Flash Player. For users who want to download the update itself will update appear this week at the Adobe website.Additionally, Adobe has announced that with distribution partners cooperate to the update for Google Chrome and Internet Explorer 10 and 11 make it available. These browsers include an embedded version of Flash Player.

Adobe confirms that the leak is used to attack users of Internet Explorer and Firefox on Windows versions up to Windows 8.1.Initially, it was stated that users until Windows 8 walked risk. The critical vulnerability has been fixed in Adobe Flash Player 16.0.0.296 . Through this page can be viewed which version is installed on the system.