Saturday, 17 January 2015

Phishing Attack On LinkedIn Users With HTML Attachment


LinkedIn users have become the target of a phishing attack that through html files attempting to steal credentials. The email has the subject "LinkedIn Alert" and argues that there is a mandatory security update is necessary due to unusual activity.

LinkedIn phishing email

For this check is sent an html file. When users open the file, they get to see a copy of the real LinkedIn site. However, the code has been modified so that users via the HTML page to try to log their data forwarding to the attackers, warns anti-virus company Symantec. The IT security advises users to turn on two-factor authentication. Even if the credentials are stolen an attacker can therefore not on the account login.

Friday, 16 January 2015

Google Adsense Used For Malicious Ads


Cybercriminals have used Google Adsense to display ads on all sorts of malicious websites that visitors to these sites for several scam sites by sent. Numerous webmasters complained about the ads that ensured that visitors were redirected automatically.

The scam sites where visitors ended up offered all kinds of products to lose weight, aging combat, combat skin problems or improve IQ. The websites looked like blogs and magazines with so-called scientific studies and research on the products, complemented by all kinds of false responses from people who supposedly had tried the products.

The problem with the malicious ads would play since mid-December, but was last Friday, January 9th widely felt. On the Google AdSense forum, more than 180 responses from angry webmasters inside. Webmasters who use Google Adsense on their websites and see how visitors were redirected by the malicious ads.

On January 10, Google would have solved the problem. According to security firm Sucuri used the attackers behind the attack two legitimate AdSense campaigns, they probably via guessed or stolen credentials managed to hijack. However, it is not excluded that the scammers Adsense accounts have created yourself and initially did occur that it was legitimate campaigns.
Code

Researcher Denis Sinegubko of Sucuri is wondering why Google allows advertisers may use this type of potentially dangerous code. "I realize that Google advertisers flexibility in managing their campaigns and the use of scripts will give their own pages. And I realize that at the first check these scripts did nothing malicious, and is only misbehaved after they were approved. But there would have to be more in control of third-party scripts. "

Sinegubko further notes that nobody likes ads, but they are indispensable for many websites. "I will not tell you to remove all ads from your site," he says to webmasters. "But I ask you to think about the safety and reputation effects that may have bad ads for your site. Consider each script from a third party that you place on your website as a potential threat. Especially those scripts that others who do not knows, allow you to place content on your site. "

Cryptowall 3.0 - "Microsoft Sees Hundreds Of New Infections By CryptoWall"


After two months of silence, there is a new version of the CryptoWall-ransomware appeared that managed to infect one day 288 Windows computers, says Microsoft. CryptoWall 3.0 spreads the same way as previous versions, namely via drive-by downloads and installation by malware already present on computers. Once active encrypts CryptoWall kinds of files and then asks for an amount of 500 euros in bitcoin. Victims receive 167 hours to pay, and the price is increased. In previous versions it was then a sum of 1,000 euros.

Cryptowall Decrypt Service.

Communicated the older versions of CryptoWall still using the Tor network, CryptoWall 3.0 uses I2P, which stands for Invisible Internet Project (I2P), says researcher JuK of the blog Malware Do not Need Coffee . I2P is a network layer allowing application messages safely and pseudo-anonymous can exchange. 

Cryptowall 3.0 communications with C&C

The earlier versions of CryptoWall would be more than 830,000 computers have been infected, making it the most "successful" ransomware until now.

VirusTotal Report Zip File: c77a463c5f6481efee38bba2bc8bf085

VirusTotal Report: 6c3e6143ab699d6b78551d417c0a1a45

VirusTotal Report: 47363b94cee907e2b8926c1be61150c7

Thursday, 15 January 2015

Researcher Warns Of Software On Download.com


Download.com is a popular download site, but how secure is the software that is actually offered here?A researcher from How-To Geek decided the ten most popular programs from Download.com to install and startled by the result that he advises users not to repeat the experiment on their own computer. For the experiment, the programs were completely installed by default, as a typical user would do.

Download.com , which is part of CNet News, sets the policy that all downloads are offered free of adware, spyware or other malicious software. Many of the software appeared to be bundled with a variety of other programs. Via Download.com users can download the software directly, but there is also a Download.com -installer, which is much more apparent. This includes an installer that in addition to the desired program installs all sorts of other programs. It appears to include "browser hijackers" and fake "registry cleaners" to go.

Remarkably, the virus Avast is one of the first programs were installed and then some other downloads blocked because they were labeled as malicious. "Free software vendors to bundle earn almost all money through complete nonsense and scareware that mislead users to pay to clean up their PCs, regardless of the fact that you can avoid this by this" crappy "freeware nothing to install," says Lowell Heddings .

The experiment was repeated for several months and each time ended Heddings with other software on the computer. "Every software that unifies itself brings with it the same culprits: browser hijackers that hijack your search engine and home page and place ads everywhere because if the product is free, you are the real product.."

Gitrob - "This New Tool Crawls GitHub Sensitive Data"


For developers and organizations that work with GitHub is a new tool appeared which makes it possible to search the platform on sensitive data. GitHub is a popular online platform for software developers that code and files can be shared.

Also can work on projects together over the platform. Many companies and projects use GitHub to host both internal and public projects. Sometimes it happens that employees publish things that actually may not be published. This relates to sensitive data or business with which a system can be made ​​immediately. "This can happen by accident or because the employee does not realize the sensitivity of the information," said Michael Henriksen .


So it still happens regularly that developers publish things as private keys and credentials. Henriksen therefore developed Gitrob , enabling organizations and security professionals can find this kind of sensitive data. The tool collects all the public "repositories" of the organization, as well as all employees and their public repositories. Then all available files are collected and analyzed to see if they match patterns for sensitive files.

Henriksen works for SoundCloud and had to develop a system that monitors GitHub sensitive files. He notes that organizations can look through his tool or no sensitive files roam. In addition, penetration testers and more "offensive" security professionals can use the tool to collect information about a potential target.

Wednesday, 14 January 2015

Crypto Stick For Secure Login And Encryption Is Now Called Nitrokey


The Crypto Stick, a USB stick with which Internet users can log in and secured files and email can encrypt, has been given a new name, namely Nitrokey . The new name should reflect the development of the stick, which is now finally ready for consumers.

The secret keys Nitrokey used to encrypt or sign located on the USB stick. According to the developers, it is impossible to extract these secret keys Nitrokey, making the device would be immune to viruses and Trojans. Furthermore, the PIN that the user must choose and the "do not manipulate the" smart card to ensure that the Nitrokey in case of theft or loss is still protected. Both the hardware and software Nitrokey are both open source.


The USB stick can be used for various purposes, such as secure login via a One Time Password for example Google or Dropbox, email encryption based on S / MIME and OpenPGP, encrypting files and hard drives and user authentication on both local computers as networks. Mozilla uses the Crypto Stick to secure its infrastructure.

The Crypto Stick is already since 2008 as "hobby open source project" in development. The developers say that they have learned during this time that developing a system that works is one thing, but delivering a device that is stable and ready for consumers, is a whole different story. The development of the latest version of Crypto Stick took two years to complete and is now complete. Now the system operates stably concentrate the developers at its production. Because of the new phase of the project has decided to change the name of Crypto Stick Nitrokey. "The goal is to provide the best open source securitykey to our users remains unchanged," they note

Shielded Instagram Pictures Were Still Public


Photos on the popular social networking site where users thought they were screened were still accessible to others. The problem was caused by the way dealt with Instagram photos shielded and public accounts. By default Instagram accounts public.


However, users can protect their account and choose to share photos only followers. Photos that were shared for this adjustment could still be viewed as the URL of the picture was known, even though the user thought they were screened, as reported Quartz. Instagram has corrected the problem this weekend so photos shielded accounts really are screened, regardless of whether they were previously accessible via a public profile.

Tuesday, 13 January 2015

CENTCOM's YouTube And Twitter Accounts Hacked By CyberCaliphate



Tonight the YouTube and Twitter accounts from hijacked the US Army. The social media accounts of the US Central Command showed messages from a group calling itself "CyberCaliphate". In addition to the notices published in the YouTube channel propaganda videos of IS terror group.

Screenshot from Twitter (@CENTCOM)

Both the YouTube account as the Twitter account is now inactive. In a statement to US media Central Command confirms that the social media accounts have been hijacked, but does not explain how this could happen. According to the press officer of the White House the impact of a hacked Twitter account can not be compared to a large data theft. Central Command oversees US troops fighting in Iraq, Syria and Afghanistan.

Monday, 12 January 2015

Porndroid - Android Ransomware Locks 180,000 Android Devices


A form of ransomware that focuses on Android devices and is distributed through fake porn sites has locked least 180,000 Android devices, claims a researcher. Porndroid such as ransomware is called, occurs when users need to install video player to pornographic content visit. Through various Traffic Distribution Systems (TDS), and especially malicious ads, mobile Internet users are redirected to porn sites.


According to researcher JuK of the blog Malware Do not Need Coffee is about 500,000 visitors each day who find themselves in this way on the fake porn sites. The websites instantly show a message that a "porn player" must be installed to view the porn video. However, it is a malicious app that asks, among other administrative privileges. Once installed, the malware is active and locks the device.


The ransomware locks the device with a so-called warning from the FBI stating that the user has committed a crime prohibited by visiting porn sites. The warning will be displayed as evidence four child pornography images and a photo of the user. This picture was taken secretly through the camera on the phone. To unlock the device should be a fine of $ 500 to be paid. Most victims of Porndroid-ransomware are located in the United States, says JuK.

Only in December were locked between 180,000 and 240,000 Android devices. Average hit every day 7,000 devices infected by the ransomware and between 0.4% and 1% of users pay the ransom. Together would have yielded the ransomware in December alone $ 500,000, says the researcher. The reason there is spoken in his little about Porndroid because the victims are ashamed.

Sunday, 11 January 2015

Steam Will Combat Malware With Captcha


The popular online game distribution platform Steam, with more than 100 million active users, has taken measures against malware that attempts to steal virtual goods. Steam users are regularly targeted by phishing attacks and malware. The Dutch researcher Yonathan Klijnsma He recently made ​​a comprehensive analysis of Steam malware. The malware attempts virtual goods that allow users to move their account to other accounts, where they are eventually sold at physical money.

To thwart this type of malware must now enter a captcha in the trading of virtual goods. "We know this is annoying, and we want to make it act not difficult for our users, but we expect that will help users who are tempted to install malware and so lose their stuff," says John Cook from Valve, the company that Steam developed. Cook asked users what they think of the captcha, which now yielded 700 responses, many of which are negative.


Factories Target Online Banking Malware


Trojans designed to steal money from online bank accounts are also used at industrial plants and factories, so has had a security researcher know. Kyle Wilhoit anti-virus firm Trend Micro discovered thirteen different types of malware that occurred as software in SCADA (supervisory control and data acquisition) environments used. It involves, for example, Siemens WinCC, GE Cimplicity, Advantech and other human machine interface (HMI) products.

Although attacks on industrial environments often with attacks by countries are linked, it would be here involve ordinary cybercriminals. "It's an interesting trend, traditional banking Trojans and no targeted attacks," Wilhoit as late versus Dark Reading know. According to the researcher criminals focus their sights on SCADA / ICS systems because they are unsafe.

Many HMI machines run on Windows and would not use a virus scanner or are not equipped with the latest signatures. Most malware Wilhoit encountered no problems would be detected by an up-to-date virus scanner. While targeted attacks are still at risk managers should also take into account normal "crimeware", as the consequences can be just as bad. HMI systems are very susceptible to interference. Infection by a banking Trojan can also just as easily get the system down.

Wilhoit saw in October for the first peak in the attacks, but does not know what the occasion is. The criminals behind the malware use spear phishing mails and drive-by downloads to infect computers. Fake websites are used on that instance, resemble those of Siemens and supposedly download a WinCC update, while it is actually malware. Wilhoit 32 recently discovered malware instances that occurred as WinCC software. Next week, the researcher during a conference SCADA give more details about his research.

Saturday, 10 January 2015

Sony Hackers Were Deliberately Left Possible Traces


The hackers managed to break into Sony may have deliberately discarded tracks and were not sloppy like the FBI this week claimed. So say a former North Korean official and a South Korean security expert versus the Wall Street Journal.

"While it is impossible to prove whether the hackers proof accidentally or deliberately left behind, it can not completely hide their tracks also mean that North Korea wanted it known," said Choi Sang-myung, advisor to the South Korean cyberwarfare commands. The theory is supported by Jang Jin-sung, a former officer of a North Korean propaganda unit.

He argues that North Korean hackers have an incentive to leave evidence behind, because successful attacks against the enemy will be rewarded with promotions. "People compete fiercely to prove their loyalty. They must leave behind evidence that they have done it," Jin-sung says.

In an attack on South Korean television companies and banks in 2013 would have been visible a short time a North Korean IP address, because the Chinese servers that were used as a proxy temporarily not working. According to security expert Richard Bejtlich let this story shows that technical features are just one part of the grant of an attack. "There should therefore be taken into account not only national but also personal incentives to solve the attribution question," he notes.