Tuesday, 21 April 2015

Flash Player Vulnerabilities Ever Attacked Quickly After Patch



Vulnerabilities in Adobe Flash Player are getting faster attacked after the release of a patch, which increases the pressure on users to install available updates as soon as possible. On April 14, patched a critical vulnerability in Adobe Flash Player that could allow attackers the underlying computer in the worst case can take over completely if a malicious or hacked website is visited or appear infected ads.

Only three days later, on April 17, there appeared an exploit that allows the vulnerability abuse. The exploit was added to the Angler-exploit kit, making all kinds of cyber criminals have access. By cyber criminals exploit kits can easily Internet attacks by placing on hacked websites iframes and JavaScript, pointing to the exploit kit. In case users do not patched malware can be installed on the computer.

There has been a trend in which leaks in Flash Player, after the release of an update, still attacked quickly. On the basis of the updates, the attackers can find out where exactly is the vulnerability and develop an exploit here. A development that reveals security experts worry, says security firm FireEye . The observed now operates first look at the user's system and then determines whether a parent or Tuesday patched vulnerability to be attacked. What kind of malware is distributed via the new exploit is unknown.

JavaScript Annex Spreads CryptoWall-Ransomware


In many email attacks are used executables and Office documents, but there are spammers that use JavaScript attachments. Before warns Trustwave. The security company recently discovered a spam campaign where emails were sent that contain supposedly a resume laity.

There was a zip file as an attachment sent with it a Javascript file, ending .js. Once the recipient opened the file the script tried to download an executable, which turned out to be a variant of the CryptoWall-ransomware. This ransomware encrypts all kinds of files on the computer and then asks hundreds of dollars for decrypting it.

On another spam campaign Trustwave discovered a phishing attack that also made ​​use of JavaScript. In this case, an HTML file was sent to JavaScript which recipients must enter their account details. "If an e-mail telling you to enable JavaScript that you should not really do," says analyst Brian Bebeau. "Despite the use of executable files and other exploits you can not ignore JavaScript attachments in your e-mail traffic. They can both your users and yourself cause problems."

Monday, 20 April 2015

Steam Launches Limited User Accounts From Abuse


The popular game distribution platform Steam has announced a new measure against abuse such as phishing and spam attacks on users, namely the obligation for Limited User Accounts to spend at least $ 5 before they can use certain features. These include the posting, use the chat function and participation in the Steam Fair.

According to Valve, developer of Steam, the measure must protect users from spam and phishing. Steam has 125 million users worldwide. Through the platform, users can buy all sorts of games and digital objects. Some research argue that sold 75% of all PC games through Steam. Steam Accounts with many games or digital goods are also a favorite target of cyber criminals, who often approach users through chat or other parts of the platform.

"Malicious users often use accounts that have spent no money, which reduces the risk of the actions they perform," said Valve. Viewing the purchase history would be one of the main ways to distinguish normal users of malicious users. Malicious users would in fact do not care about the life of their account.

That's why we decided to introduce the limit of $ 5 before accounts can use all the features. Steam Users are happy that something against the scams on the platform is being done, but there are also critical voices of people who only buy physical ex. PC games and spend nothing on Steam, as evidenced by the lively discussion on Reddit .

Sony Had Pirated Copies Of Books On Hacking Network


Sony is known for the battle that is against software piracy, but the company itself also appears to have clean hands. Last week leaked WikiLeaks documents 30,000 and 170,000 emails at Sony Pictures Entertainment were captured. Among the documents discovered security expert Jeffrey Carr a pirated copy of his book "Inside Cyber ​​Warfare", let him through Twitter know.

The Daily Dot also discovered a second pirated book, namely Hacking the Next Generation, which was a full version of the Sony servers. The presence is remarkable, since Sony in the stolen emails discusses all sorts of tactics to combat piracy and the arrest of the founder of a torrent site is The Pirate Bay described as a great victory.

Drupal.org Accidentally Leaked Email Addresses Users


The website Drupal.org this week inadvertently leaked the email addresses of hundreds of logged in users. Drupal is a popular content management system with a vibrant community. An adjustment to the permissions of the web site on April 15 was a "small" part of the user to see a list of email addresses of users logged.

It would be a total of some 44 IP addresses that the information at that time approached. According Drupal went mainly to managers of Drupal.org and community participants who reported the incident. The problem was 13 hours after being rectified and introduced within 3 hours after such notice was made. The complete solution was made ​​to be within 24 hours after the onset. According Drupal were visible the email addresses of less than 500 people, all of which will be informed immediately. However, all users are advised to be careful with emails that ask for personal information.

Sunday, 19 April 2015

Ransomware Allows Victims To Recover From Error Files



A new ransomware variant that first appeared in late January and make the last month was increasingly active shows an error causing casualties without paying their files can be recovered. It is the Threat Finder ransomware which spreads through vulnerabilities in Java, Adobe Flash Player and Microsoft Silverlight that Internet users are not patched.

Once the ransomware encrypts which operates numerous files and asks here for 1.25 bitcoins, what with the current exchange rate is 259 euros. A researcher from Bleeping Computer discovered that the ransomware the Volume Shadow Copies are not removed from the computer, making it possible to access the files using the " Previous options can restore "of Windows, or a tool like Shadow Explorer .

Sony Condemns WikiLeaks Due To Publish Stolen Data


Sony Pictures Entertainment has lashed out at WikiLeaks for publishing 170,000 emails and 30,000 documents were stolen from the company. This week published the WikiLeaks "Sony Archive" because the stolen data according to the whistleblower site are newsworthy.

Sony is thinking differently. "Despite the so-called commitment to freedom of expression, WikiLeaks rewards the behavior of a totalitarian regime that dissidents want silence and entities as Sony tries to discourage those trade secrets, confidential information and intellectual property protection are subject to their rights exercise, " says Sony lawyer David Boies.

According Boies, most media organizations refused to help the attackers with their extortion and plan attacks on Sony's employees, resources and freedom of expression. "Unfortunately WikiLeaks has chosen to deliberately and indiscriminately to download the stolen data from Sony, copying, indexing and use and others to use and help the access to it," Boies writes in a comment.

Zero-Day Vulnerabilities Attacked In Flash Player And Windows



Attackers have recent period zero-day vulnerabilities in Adobe Flash Player and Windows uses to break into organizations. The vulnerability in Flash Player has been patched , but Microsoft is still working on an update. According to security firm FireEye involves targeted attacks.

For carrying out the attack must open a link target of the attackers. Subsequently, a site loaded that leak in Flash Player used to execute code. Through the Windows Player attackers can then increase their rights on the computer. At the time of the attack were both vulnerabilities not yet been patched.

Although Windows still waiting for an update, users should install the latest Flash Player security risk no longer walk. The attack on the Windows play would effectively observed only in combination with the Flash Player leak, according to the American FireEye. In case the attack is successfully installed malware on the system that allows full access to the attackers. Who is behind the attack is unknown, but FireEye calls it "likely" that it is a Russian spy group.

FBI Gets Security Expert From Plane After Tweet


The FBI on Wednesday met a security of an aircraft and its computer equipment confiscated because of a tweet. He was not yesterday after his release along with the airline. Chris Roberts posted a message online in which he expressed his doubts about the safety of the aircraft network, but the American investigative thought he plane of United Airlines wanted to hack, so notify CNN and Forbes.

After his arrest his iPad, MacBook Pro, three hard disks and various USB stick were confiscated. His phone was allowed to keep Roberts. All devices were encrypted, however. "It will be interesting to see if the encryption keeps" the security expert showed through Twitter know. Against both Forbes and CNN Roberts from his frustration that vulnerabilities in aircraft are not resolved, even though they are known for years. He was questioned after his arrest four hours.

United Airlines

Roberts has his computer still not recovered, but has by now released. Yesterday he tried to fly to the RSA Conference in San Francisco, where he will give a presentation. After the expert had received his boarding pass and wanted to board the plane he was stopped by security personnel of the airline.

Eventually he could at the last minute along with another airline, but the American civil rights movement EFF criticizes the actions of United Airlines. "As a member of the research community, it is his job to find vulnerabilities so they can be resolved," said Andrew Crocker of the EFF. Crocker notes that the EFF is worried about this kind of reflexes on legitimate security research, which ultimately can have a paralyzing effect on researchers, eventually causing problems go unnoticed.

Even Linux Users Targeted By Cyber Espionage



Appear regularly reports of attacks by cyber spies who have provided at Windows users, but the Japanese anti-virus company Trend Micro claims to have discovered an attack which also Linux users were targeted. The attacks come from a group that the defense companies, media organizations, Russian dissidents, members of NATO and even the White House has provided.

The attackers have been active for some time and use different tactics to infect their victims with malware. There Microsoft Office documents are used as containing spyware. In another attack were on a Polish government site posted several exploits that install malware on the same unpatched users. Finally phishing emails were also used those users to fake login pages for Microsoft Outlook Web Access (OWA) by sent.

Linux

In the first quarter of this year, the group was very active and used it several new attacks, including sending e-mails with malicious links, which supposedly to news reports seem to indicate. When a user opens the link, and certain conditions are met does the so-called news site with a message that there must be an HTML5 plugin installed to view the content of this website. In the case of Linux users who visit the website will be the X Agent or Fysbis spyware offered, while Windows users get the Sednit spyware.

Furthermore, the attackers use again the counterfeit OWA logon pages. These contain phishing pages JavaScript that when the user opens the link from the OWA preview pane, a tab opens with the intended site. In addition, the JavaScript causes the OWA session is forwarded in another tab to a phishing page that lets you know that the user is logged out and must log in again.

White House

Trend Micro also says to have proof that the group the White House has targeted. Four days after three YouTube bloggers President Barack Obama had interviewed these bloggers were the target of a Gmail phishing attack. According to the virus fighter they tried bloggers likely to use as a springboard for attacks against the White House. Who is behind the attacks is spying is not to say the anti-virus company.

140,000 Merchants Vulnerable Magento Leak



A serious vulnerability in the shopping cart software Magento enables merchants 140,000 at risk of being hacked, warns the Dutch hosting company Byte. The vulnerability was in February by the developers patched but examining Byte April 14 shows that 60% of merchants who still uses a vulnerable version running on Magento. That equates to 140,000 shops.

There are no observed attacks yet, but if there is an exploit appears Byte expects all vulnerable web shops will be hacked within 48 hours. To help, there is a merchants website appeared online that reports whether the shop is vulnerable or not. In addition, administrators are advised to install the update. According to an employee of security firm Check Point on Reddit , the company will next week more details about the vulnerability publicly, but no exploit code. Or the employee states that it is a very serious leak.

Flash Player Leak Sites Gave Access To Webcam



Vulnerability in Adobe Flash Player that patched this week made ​​it possible for websites to enable the webcam and microphone without permission from visitors. The problem was present on all systems that support Flash Player, says researcher Jouko Pynnönen .

In addition, it did not matter what the visitor had turned in the configuration panel of Flash Player. This panel can be shown that websites can not access the webcam. However this could not prevent the attack. Details on the vulnerability Pynnönen will not release, as there is a potential variation of the leak, possibly present in the most recent version of Flash Player is investigated.


Through the vulnerability it is possible to call another leak, allowing an attacker in the worst case could take over the computer. Also this vulnerability was last Tuesday resolved. To demonstrate the webcam attack the researcher made ​​the following video .