Saturday, 21 February 2015

Samsung Smart TV transmits voice audio unencrypted


The voice commands that smart saving TVs from Samsung and forwarding are sent unencrypted to a third party, as has discovered a security researcher. Recently there was great commotion about the voice recognition of the Samsung SmartTV which consumers via voice commands can control the TV.

Security Researcher David Lodge decided the traffic that comes to investigate the television. While he saw a connection on port 443, which normally indicates HTTPS. Lodge then decided to view the contents of the data stream and saw that it was not going to encrypted data. It was not even HTTP data, but a combination of XML, and a binary data packet. "The weasels, they use 443 / TCP to tunnel over the dates, probably because many standard default firewall configurations traffic to port 80 and 443 permit outside the network," said the researcher.



It also showed that all kinds of information on the screen is sent, such as MAC address and the version of the operating system. The voice command could be seen that he gave. It suggests Lodge that television does not listen to users unless it is activated by the command. Something, however, with each subsequent firmware update may change, making continuous listening which would be possible, he warns. Lodge Samsung therefore calls to use anyway SSL.

Superfish-Adware Is Lenovo Customers Cost


The Super Fish-adware that Lenovo laptops installed and making SSL connections risk reminiscent of the Sony rootkit scandal a few years ago and the computer manufacturer will ultimately cost customers.That says Adam Winn software company OPSWAT.

"Although the intentions may not be malicious, the implementation is certainly is. Superfish is more than just adware, it's a man-in-the-middle attack that occurs as adware. In an era of continuous security-related news it is shocking that Lenovo software installs the SSL chain breaks on in such a fundamental way. " Winn sees similarities with the Sony rootkit scandal in 2005, only this time the consequences are much greater.

"It touches both privacy as the fundamental trust that consumers have SSL-protected Web sites." He also predicts that this action Lenovo customers will cost. "Lenovo has a loyal following among IT professionals, as evidenced by the present Thinkpads anywhere within companies. There is no doubt that this incident will have a severe drain on the balance of Lenovo. No system tolerates a Man-in the-middle attack on proprietary or BYOD devices. "

The American civil rights movement EFF calls it an amateurish design choice of Superfish to inject ads through a self-signed certificate. "Lenovo's decision to provide this software was incredibly irresponsible and a great abuse of the trust that they received from customers." Lenovo late by Bloomberg know it was a mistake to install the software standard on laptops and that the only purpose was to improve the customer experience.

NSA And GCHQ Would Have Hacked Sim Manufacturer Gemalto


The American and British secret services were established in the Netherlands SIM card manufacturer Gemalto five years ago there have been hacked and stolen the encryption keys used to secure mobile communications. Thus, the NSA and the British GCHQ would mobile communications eavesdropping without permission of telecom operators and foreign governments.


That claims The Intercept using documents whistleblower Edward Snowden. Gemalto product annually honors 2 billion SIM cards and is one of the largest manufacturers in the world SIM card. According to a presentation in 2010 of the GCHQ, different computers are infected with malware Gemalto that the British secret service at the time thought full access to the network.

Gemalto CEO Paul Beverly called the news disturbing. "The important thing for me is to understand how this could happen just so we can take steps to prevent it does not happen again," he tells The Intercept opposite. After being informed Gemalto's security team has conducted an investigation, but could find no trace of any hack. However, the slides of Snowden dating five years ago.

D66 MP Gerard Schouw call it incredible. He and other policymakers will ask for clarification from the government and want to know whether the AIVD knew Gemalto was a target. "We have a law in the Netherlands on the activities of secret services and hacking is not allowed," said the MP. He also does not think Plasterk such operations would approve by foreign secret services.

250,000 routers discovered with same SSH key


A researcher who wrote a program to include the "fingerprints" of collecting SSH keys watched curiously when he found one fingerprint on over 250,000 devices. It turned out to routers of the Spanish telecommunications provider Telefonica de Espana.

Some network would default SSH feature, which the manufacturer decides to roll out the same operating system image on all devices. Researcher John Matherly , founder of the Shodan search engine, also found two keys that 200,000 and 150,000 times were used, respectively.

"By analyzing these cases it is easy to get a picture of the systemic problems both hardware manufacturers and ISPs pests," said Matherly. He has a list of unique fingerprints collected offers now via Github to. "It would not surprise me if you find interesting security problems by analyzing why these things are configured incorrectly," he notes.

Friday, 20 February 2015

Research Into TrueCrypt Encryption Start Soon


The investigation into the cryptographic operation of the encryption program TrueCrypt has been somewhat delayed, but will soon really begin, as the initiators announced. The end of 2013 decided cryptography professor Matthew Green and White a scientist Kenn Crowdfunding Initiative to start. The two wanted the website IsTrueCryptAuditedYet? fetch $ 25,000 to verify the cryptographic functionality of TrueCrypt and to have an audit. In total there were collected 62 104 dollars and 32.6 Bitcoins.

Despite the popularity of TrueCrypt, which makes it possible to encrypt files and hard drives, the source code and cryptographic software operation had never been audited. January last year decided security iSEC Partners to conduct the audit of the TrueCrypt boot loader and Windows kernel driver. In April it was audit report presented. Although there are several problems were found, the researchers found no backdoors. The second part of the audit would focus on the cryptographic operation of the encryption program.

Six weeks after the appearance of the first audit report, the TrueCrypt developers pulled the plug on the project. A day later showed Green and White, however, know that the crypto-audit they would still be, but then it jealously kept quiet. According to Green threw the sudden disappearance of TrueCrypt plans somewhat confused. As was given to whether the money could be better spent on different TrueCrypt successors.

Eventually there was a "Plan B" drawn up within budget and also makes sense. As part of this plan was a few weeks ago a contract with the just-launched Cryptography Services of NCC Group closed. Here the original TrueCrypt 7.1a will be audited.This version also forms the basis for various successors.

Green now reports that the audit will take place soon. In addition, let the promoters of the audit plan that they also look at parts of the code, including the Random Number Generator (RNG) TrueCrypt and other parts of the cryptographic implementation. "This will hopefully complement the work of NCC / iSEC and give a little more confidence in the implementation," said Green. He notes that it took a little longer than planned, but the results really come. Results of which he hopes she " really boring "will be.

Cisco Warns Of Attacks On The ASA VPN Software


Cisco warns organizations for attacks on the ASA software allowing attackers credentials can get their hands on for VPN connections or malware can spread. The vulnerability is in the Clientless SSL VPN software. The software provides ASA-administrators the ability to customize the appearance of the Client SSL VPN portal.

A vulnerability in the "customization framework" which the adjustments are made allow a remote attacker without login details the contents of the Clientless SSL VPN portal adjust. This makes it possible to steal login details, cross-site scripting (XSS) and other web attacks to perform and distribute malware instance. Once a VPN portal is compromised adaptations of the persistent attacker.

Restarting the server or changing the ASA Software custom objects will does not remove. The leak was unveiled late last year and patched. Yet who now find attacks rather abuse the vulnerability. In addition, on the Internet also exploit code appeared. Cisco has in the warning information also given how compromised VPN portal can be recognized.

Thursday, 19 February 2015

Adware Lenovo Laptops Brings SSL Connection In Danger


Chinese computer maker Lenovo installs default very aggressive adware on the laptops that sells to the customer, allowing all users to set up SSL connections that are at risk. It was some time known that Lenovo installs the Superfish-adware on laptops, only now its impact appears to be much greater than was assumed initially.


According to researcher Marc Rogers adware performs a "Man-in-the-middle attack" to gain access to sensitive data running over SSL connections and inject ads. In addition, Lenovo also installs a weak certificate on the system, so users no SSL connection that they can set up more confidence.


The problem was already on 21 January by a user on the Lenovo forum reported. According to the user hijacks Superfish, also known as Visual Discovery and Similar Products, all SSL / TLS connections using a self-signed root certificate authority that is trusted by the browser. The user in question has returned to his laptop and asked for his money back.

Through Superfish ads are displayed on the computer. Rogers calls it an infamous piece of adware that hijacks legitimate connections, user activity monitors, collects personal information and upload to servers, pop-up displays with adware and another attacking users of SSL connections and uses a self-signed certificate. Superfish used also a weak SHA1 certificate.SHA-1, however, has been replaced by SHA-256, SHA-1 as attacks on can now be carried out using standard computers. It also appears that there is a 1024-bit RSA key is used which is to crack.

The researcher suggests that Lenovo is therefore ignorant and reckless busy. "It's probably the worst I've seen put on a supplier customers." In a reaction that enables Lenovo Superfish temporarily of laptops has been removed. In addition, the manufacturer notes that the plug-in can not hurt.

Or the plug-in is removed only on new laptops and Lenovo can do this on existing computers is unclear. It is also unclear whether in this case the self-signed root certificate authority is removed. The Next Web reports that Firefox users are not at risk, because the open source browser uses its own certificate store. Furthermore, virus scanners would Superfish detect adware and recommend to remove.

Lenovo said in a statement that Superfish from January 2015 not installed on new systems. Furthermore Superfish would already sold Lenovo machines are turned off. According to the manufacturer the adware on only a "select few" consumer models installed.

Superfish Domains & IP Addresses
Security Researcher Conrad Longmore has published a list of IP addresses and domain names used by Superfish. He notes that the information is sent to US IP addresses. Superfish itself is Israeli. "What seems to be a popular place to develop adware," he notes.


Owners of a Lenovo laptop can through this page, check the Superfish Certificate Authority trusted by their browser and they are therefore at risk.


Several researchers have meanwhile managed to crack the password that the private key of the Superfish certificate used.The password proved "komodia" to be, according to an analysis by researcher Robert Graham . In theory it would be possible thus to perform man-in-the-middle attacks and encrypted traffic to intercept Lenovo users. For this, an attacker would have to place between the user and the Internet. Further says researcher Erik Loman that contrary to what was first reported Firefox users be vulnerable.


Lenovo showed earlier know Superfish is no longer installed in new laptops and existing installations were off.Whether this also the self-signed certificate is removed is unclear. Lenovo has asked for clarification but received no reply.

Lenovo late know that it completely stops Superfish and not on machines will install the software. Additionally, the software off in January of this year on the server side of Lenovo. Thereby Superfish would no longer be active. Or users themselves must remove the self-signed certificate is unclear. This question is still open at Lenovo.

The computer manufacturer also states that it has extensively researched the technology, but has found no evidence to justify the resulting safety concerns. "But we know that users are concerned about this problem and therefore immediate action taken by products with this software to deliver any more.

Espionage Firmware In Hard Disks To Detect Barely


The malicious firmware that a group of cyber spies computers permanent commitment to continue spying is hard to detect and extremely difficult to remove. "It is extremely difficult to detect. From the software level, it is impossible," said Vitaly Kamluk, researcher at Kaspersky Lab.

The Russian anti-virus company revealed this week the existence of the spy group who developed all kinds of highly advanced malware. One subset fell on, namely, the ability to infect the firmware of the various popular brands hard disks.Therefore, the malware remains hidden and active, even though the hard disk is formatted or reinstall the operating system.The code ensures that the attackers can create an invisible storage on the hard disk.

"This is unique and the first time we have seen this level of complexity of a sophisticated attacker," said security researcher.However, the module could have been used rarely. "Only a very select list of victims have received this. This is one of the most special modules that I've seen because it is so valuable. They do not want that to be known," Kamluk let know this week during a conference, so reports Threat Mail .

"It is a valuable plug-in that is used only in specific cases for very important people." To detect the malicious firmware should the PC be disassembled and made a dump of the firmware. "And we think that only a few people in the world are able to analyze the malicious code within the firmware, compare and discover," says Kamluk.

According to the researcher takes years to write firmware. But the espionage group would not use vulnerability, but only ride on the way manufacturers roll out firmware updates. "They left the door open and stood possible longtime open. The trick is that you have the full description, the full reference of the current firmware should have and how it works."

Kamluk speculates that the attackers may have access to internal manuals and documentation of the respective suppliers.Manuals that may be stolen by an insider or through another malware attack. "They do not abuse a leak in the code. It is a design flaw." Because of the proprietary communication protocols and algorithms took investigators months before they learned how the malware exactly worked. A truly infected firmware researchers have not been able to find.

Popular Porn RedTube Spread Malware


On the popular porn RedTube researchers have found malicious code that tried to infect visitors with malware. That leaves anti-virus company Malwarebytes know today. Unlike several other porn sites that for "drive-by downloads" were used, there were no infectious ads used in this case. The attackers had direct access to the code of the website.

The malicious code was executed inside an iframe and pointed to the Angler Exploitkit on another page. This exploitkit uses a recently patched vulnerability in Adobe Flash Player. In case users do not use the latest version of Flash Player, they can become infected with a Trojan horse. This malware steals personal information and installs browser helper objects showing ads. Some of these ads pointing again to other operating pages can infect your computer with malware so on.

RedTube leaves in front Malwarebytes know that last Sunday was attacked and the problem was resolved within a few hours.Meanwhile RedTube the malicious code would be removed . The porn is according to measurement agency Alexa on the 128th place of most visited websites on the internet. Earlier today, the anti-virus company warned that the website of chef Jamie Oliver malware spread . Also, this problem has now been resolved.

Hash:
1e0134d9b5b51d9ad233b0a2ecb7cf83

Disabled Device Malware: "Android Malware Disables Smartphones Called Off"


Researchers at anti-virus company AVG discovered malware for Android that allows users to believe that the device is turned off, while this is not the case. The "disabled" device malware can then make calls, take pictures and perform other tasks.

Recording A Call
How the malware from spreading and where it was found just let AVG not know. However, the virus fighter says that the malware after installation will require root privileges. Then, different processes and injected hijacked objects. When users want to disable their smartphone hereinafter there appears a hoax which offers the possibility to turn off also the device.

Transmitting A Private Message
Users who see the unit off now get the real closing animation and the screen is black. However, the phone is still on. This is possible because a function that the phone actually turns off because the infection can never be invoked. Users who also want to be sure that get off their device AVG advised to remove the battery.

Victim Fanny-Espionage Worm Early In 2010 Already To Help


A victim of this week unveiled Fanny spy worm, which through two zero-day vulnerabilities in Windows spread that later were used by Stuxnet, early in 2010, all Internet users for help. However, they received no answer. That discovered Maarten van Dantzig Fox-IT.

A Malaysian forum posted a user with the alias "dkk" a call on July 13, 2010 how he could prevent his computer became infected with this virus. The user notes that he is infected via its USB stick, even though they are Autorun and Autoplay disabled. Much to the surprise of the user, different files found on the USB stick and the names also mentioned this, including Fanny.bmp. He also added a copy of the virus. However, there was no response.

Fanny.bmp is the same file that the report ( pdf ) from anti-virus firm Kaspersky Lab is known about the malware. The report also stated that Malaysia is among the countries where the worm is still active. Opposite Ars Technica confirms Kaspersky Lab that files who names the forum user match those of the Fanny worm. The worm was developed by a highly sophisticated espionage group and would have been deployed since 2008.

Desert Falcons Malware: "Million Files Stolen By Rtlo-Trick And RAR Attachments"


A group of cyber spies has managed through various social engineering tricks more than 3,000 computers to infect, with about 1 million files were stolen. Also in the Netherlands observed one or more infections, as reported anti-virus firm Kaspersky Lab.

The attackers, who would operate from the Middle East, had to cater to political and military intelligence. To infect victims were applied various tricks. So were sent spear phishing mails with attached RAR files. This RAR files contained and SCR and EXE files. The attackers used a trick with shortcuts.

Targets were given a RAR file sent to that extracted yielded several files, including two .doc files. One file, however, was a shortcut. Once users opened the shortcut malware was performed. Another trick used was using rtlo, which stands for Right-to-Left Override and ensures that through a special Unicode character sequence of characters of a filename can be reversed.


This will SexyPictureGirlAl [rtlo] gpj.exe appear in Windows as SexyPictureGirlAlexe.jpg. In the case of these attacks did the malware via rtlo for as a PDF document includes corresponding icon, but was in fact an executable SCR file. Users can recognize rtlo attacks by setting the detail view in Windows folders. Behind the file name also appears the file type. In this case there would be stated that this was an application.

The attackers were also active on Facebook, where she targets via the social networking approached. Once the trust was won were sent RAR files that contained malware. For large-scale infections among activists and political figures Facebook was also used. In this case, Facebook Messages posted there were pointing to malicious pages that malware was offered. Or again, the attackers to a page with an example being censored video. To view the video had offered "RealPlayer plug-in" installation. The file offered, however, was malware.


After the new computers were infected targets were divided into groups. Next, a list of all XLS, DOC, JPG and WAV files on the hard drive and connected USB sticks sent to the attackers. The attackers then used to connect to the computer to steal interesting photos and images. Also gathered there chats and screenshots. Depending on the targeted surveillance was then intensified or discontinued. In total, the attackers managed to steal more than 800,000 files from hard drives and more than 80,000 files from USB sticks.