Saturday, 25 July 2015

FBI Launches Campaign Against Economic Espionage



The FBI in the United States a campaign launched to warn companies and research institutes for economic espionage. According to the investigation department of industrial espionage is a growing threat that causes more damage. The exact damage is difficult to determine, but the losses are "substantial" amount and possibly hundreds of billions of dollars annually, according to the FBI.

They are mostly foreign competitors and countries that trade secrets, manufacturing methods, innovations and insights in trade and labor disputes  search. The FBI would not only see an increase in the attempts to steal company secrets, but the way is getting nastier too. "We had cases where people literally warehouses and factories within walking to steal trade secrets," said Randall Coleman, deputy director of the FBI's Counterintelligence Division. "It is shocking to see how much effort they do to steal information."

The companies would use different ways to sit behind the espionage attacks to steal information from US companies. Thus, current and former foreign employees of US companies and research institutes contacted. In addition, "technical operations" conducted as computer hacking, searching bins and bribing staff. Finally go on seemingly innocent business relationships with US companies in order to make economic information as booty.

The FBI gives American companies and organisations also advice how to protect their business and trade secrets. This relates to matters such as ongoing security training for staff to draw up a plan to protect business secrets and implement physical security measures. There is also a 36 minute video made ​​based on a real case, which tries to make the threat clear.

Google: Consumers Wary Of Security Updates


Average Internet users are wary of security updates, and consider even mistaken as a security risk, according to research ( pdf ) from Google. The Internet giant decided the security behaviour of 231 294 security experts and Internet users who are not experts to compare.

For example, among other things, to the top five security measures take any consideration of both groups. It shows that average Internet users underestimate the importance of security updates seriously. 35% of the experts called to install security updates as a security measure, while only 2% of users doing this. As a result, the installation of the patches is a security measure, with the largest difference between users and experts.


Further research into this behaviour shows that 39% of the experts shows automatically install updates, while among users is 29%. In addition, 25% of the experts said that updates are installed immediately. When the user, this is done by only 9%.According to the researchers did not make installing updates as timely as possible with bad past experiences or that users do not realise its effectiveness.

Passwords

The study also shows that password management is important for both users and experts, but there different approaches are used. The experts often use password managers. The difference between experts and users is a factor of three. 24% of users said for some accounts using a password manager, while it is 73% of the experts. Furthermore, users will find anti-virus software very important, while experts prefer other measures.

"Our results show that experts and non-experts take various measures to protect themselves on the Internet. The action of the experts be experts considered good advice, while the actions of the non-experts get mixed reactions from experts," said the researchers. They argue that there is room for improvement when it comes to identifying the main security and to then make this clear to users.

Friday, 24 July 2015

Research: Smart Watches Full Privacy And Vulnerabilities


Smart Watches are full privacy and security holes, so that information users may end up with all kinds of parties and the devices are vulnerable to various types of attacks. That set of HP researcher who examined ten popular smart watches ( pdf ).

The researchers ran during the investigation against all kinds of problems. For example, information collected often sent to multiple destinations at the watch, including third parties. The information also appears to intercept simple. Something that was possible in nine of the ten models. Furthermore, the firmware of seven aircraft is sent unencrypted. The impact of this problem is limited because many watches only allow signed firmware updates. Five watches offer also no way to activate a screen lock.

HP has not disclosed to the watch models and manufacturers involved. The computer giant advises consumers not to use smart watches for opening of housing and cars, unless there is strong authorization is offered. In addition, consumers should always set strong passwords and make maximum use of two-factor authentication. Finally have no requests from unknown devices and applications are permitted who want to link the smart watch.

Microsoft Launches New Security Product In August


Microsoft will next month launch a new security product which sophisticated attacks must stop and previously used deep packet inspection (DPI). Advanced Threat Analytics (ATA), such as the solution is called, uses a combination of behavior analysis by real-time detection.

It focuses on Active Directory-related network traffic and information from Security Information and Event Management (SIEM). On this basis, behavioral profiles of users, machines and other prepared 'resources'. The solution may then detect behavior that is different from these profiles. "After researching many incidents in my previous job, I realized that network logs are not sufficient to find sophisticated attacks," says Microsoft's Idan Plotnik.

He states that the analysis of log files is similar to finding a needle in a haystack. "Even if you find a clue, is figuring out when, how and where something happened almost impossible. With ATA Microsoft therefore taken a different path." Our secret is a combination of DPI, Active Directory information and analysis of specific events "Plotnik says.

Microsoft emphasizes that ATA is a very simple and user-friendly solution, which is used in local businesses. There are no rules, policies or agents required. There only needs to be a port configured to send a copy of all Active Directory-related traffic to the solution. Something that should be arranged within a few hours. A preview version of Microsoft Advanced Threat Analytics can be for some time to download . The full version will be published next month. Price information is not yet available.

Four Zero-Day Vulnerabilities In Internet Explorer Unveiled



Computer giant HP has unveiled four vulnerabilities in Internet Explorer that could allow an attacker in the worst case, the computer can take over completely and that no updates from Microsoft are available. The vulnerabilities were collected as part of the HP Zero Day Initiative. Through this initiative, HP will reward researchers for reporting of unknown vulnerabilities.

One of the vulnerabilities was during the Mobile Pwn2Own contest demonstrated and last November reported by HP to Microsoft. HP has a default policy to disclose a vulnerability after 90 days. However, Microsoft said that it needed more time to resolve the issue. However, the date that marked itself as Microsoft deadline was not met by the software giant. Then HP decided to publish the vulnerability. It is in this case a leak in all versions of Internet Explorer, including Windows Phone.

To attack a user would have to visit a malicious or hacked website vulnerability, to see an infected ad should have or open a malicious file. Then there is the rights of the logged in user arbitrary code execution. The other three vulnerabilities were reported in January and have the same impact. Microsoft again asked for more time to resolve the problems and once again the deadline was not met, so these three vulnerabilities are made ​​public. Exact details HP, however, not given.

Users who wish to protect are advised to so in Internet Explorer to be there for executing Active Scripting permission to use, or Active Scripting in the Internet and Local intranet security zone is disabled.

AV Comparatives Test Lab: Experienced Mac User To A Virus Scanner


Experienced Mac users can watch what they download a virus scanner, according to the Austrian test lab AV-Comparatives . The test lab decided to test ten virus for Mac OS X on the detection of malware. In addition, specimens were taken for both Mac and Windows, because the Mac virus indicate that they can also detect Windows malware.

The reason is that Mac computers can also get in touch with Windows malware, for example in the case of e-mail attachments or USB sticks. What is striking about the test, the amount of malware which has been tested. In the case of Mac malware is about 105 newly discovered specimens, while the most prevalent malware specimens were used for Windows. In other tests of AV-Comparatives for Windows be used thousands of malware examples, but the number for Mac is so low that the counter remains stabbing at 105.

Of the ten scanners able to detect seven parcels 100% of all Mac malware, while a similar number this occurs in the Windows malware. Avast, AVG, ESET, Kaspersky and Sophos are the scanners that detect all malware in both areas. When it comes to Windows malware are the only F-Secure (28%) and Intego (50%) who stabbing drop in the detection of Windows malware.Meanwhile, all the anti-virus companies have their signatures updated to missed malware are detected.

The question remains whether Mac users now need a virus scanner. "Experienced and responsible Mac users to be careful with the programs they install and where they get which can reasonably argue that they do not risk running Mac malware," said AV-Comparatives. The lab says that users who are not experts, children and users with regular software experiment there can take advantage of to use a Mac virus scanner.

Thursday, 23 July 2015

New WordPress Leak Less Serious Than First Announced


There is a new version of the popular content management system (CMS) WordPress appeared in which a leak is patched which is less severe than initially announced. The creators of WordPress announced this afternoon that there is a critical update to WordPress 4.2.2 was released.

A cross-site scripting (XSS) vulnerability would make it possible for anonymous users to fully take over websites. Meanwhile, the text of the notice is amended and the word "critical" removed. It also appears that anonymous users can not take over websites. The leak is about to fall only by users who have the role of author or contributor, according to the new text . The previous version is still in the cache to find Google. In addition to the XSS vulnerability is also fixed 20 bugs. Users are advised to go directly to their websites WordPress 4.2.3 update.

Dozens Of Apps On Google Play Quietly Visit Porn Sites



Researchers have discovered in recent months, dozens of apps on Google Play that Android devices unnoticed kinds of porn sites allow visits. It involves a total of 60 apps posing as popular games, such Dubmash, Clash of Clans and Subway Surfers.

The apps are in the last period downloaded at least 210,000 times. Once active try the apps to hide from the user and then visit various porn sites in the background. Presumably the author get paid for the clicks generated by the apps. Clicks that advertisers think they are performed by people. According to anti-virus company ESET, there is a cat-and-mouse game between Google and the authors of the fraudulent apps. Once Google remove an app is a new upload.

Most of the fraudulent apps have no or a few tens of downloads before they are found and removed. A single app falls on, like Subway Surfers 2, which was downloaded at least 50,000 times. According to ESET caused the click fraud apps no direct harm to users, such as steal passwords, but they generate a lot of traffic that users with data limit on cost can hunt.

Bug In OpenSSH Makes Brute-Force Attacks Possible


A bug in the popular OpenSSH allows attackers to try thousands of passwords, while the software actually after six failed logins should disconnect. The vulnerability was by a security researcher with the alias " Kingcope announced. "

OpenSSH, also known as OpenBSD Secure Shell, is a set of network tools based on the SSH protocol, and allows users to securely log on to servers for instance, or remotely manage machines. Servers that allow login via SSH are regularly targeted by brute force attacks. In the case of OpenSSH, this is limited by after six unsuccessful attempts to disconnect. By using the vulnerability, it is possible to try to open thousands of passwords via a log-in window, that by default a two minute open state.

The problem is in the latest version of OpenSSH present, the researcher says. Which warns it especially FreeBSD systems at risk, because that keyboard-interactive authentication is enabled by default. On Reddit let a reader know that the "Challenge Response Authentication no" protects against the attack and was involved in its installation standard.

Criminals Use Malware To Empty ATMs


In the first months of this year, criminals in four European countries malware used to empty the contents of ATMs. These are so-called 'cash out' or 'jackpot ting' attacks, reports the European ATM Security Team (EAST) in a new report ( pdf ).

Which countries will be concerned and how many do not know when the attack was captured late EAST. Malware to empty with ATMs is not new and was last year for the first time in Western Europe discovered . Criminals with physical access to the machine and then install the malware via a USB connection or CD-ROM. Through the malware and entering a special key combination can then be emptied the contents of the cash cassettes. Late last year, however, there were also discovered attacks in Russia where attackers remote ATMs with malware had infected by first banks to attack .

Most countries had so far mainly due to skimming, although seven countries recorded a decline in the number of skimming incidents and two countries saw an increase. There is also avoid a growing trend skimmers countries with an EMV chip. The greatest damage was skimming through this years ago in Indonesia, followed by the United States and the Philippines. The data from the EAST report come from 19 countries in the Single Euro Payments Area (SEPA) and two non-SEPA countries.

Microsoft Will Remove Revenge Porn From Search Results



Placing revenge nude photos on the Internet by an ex-partner, also known as 'revenge porn', is increasingly common and can have serious consequences for victims, says Microsoft. The software giant is therefore left to these pictures and videos now remove from search results of Bing.

Microsoft will also make the material inaccessible when it is shared via onedrive and Xbox Live. The removal of both the left and the material will be done globally in these cases. To make it easier for victims to report cases of revenge porn, there is also a new page was launched. According to Jacqueline Beauchere, Microsoft Online Chief Safety Officer, however this is only a first step. Removing left in search results does not remove the images from the Internet, so let them know. Beauchere argues for better protection of victims.

600TB To MongoDB Databases Freely Accessible Via The Internet


MongoDB is popular database software that is used by many websites and services, but because many organizations outdated versions of software installed such a 600TB database is freely accessible via the Internet. That allows John Matherly , founder of search engine Shodan.

Earlier this year researchers warned that such a 40,000 installations of MongoDB can be accessed by anyone without a password. Through its own search engine comes Matherly on a small installations from 30 000. Something that surprised him, because MongoDB standard should not be accessible over the internet. This, however, appears to only recently have been adjusted. In late April of this year, the final version appeared which was the standard by anyone to access via the web.Further examination of Matherly found that the problem with the default setting, though it was reported in 2012.

A configuration file to resolve the problem a year later put ready, but not added to the system. Therefore, the institution was still unsafe as default until the end of April this year. Although the problem is no longer present in new versions, there are still many databases accessible to everyone. Matherly discovered that it mainly involves installations which are administered by cloud providers such as Digital Ocean, Amazon and Linode. It seems that these cloud services using vulnerable versions of MongoDB for their images, allowing their customers deploy insecure versions of the database software.

Matherly decided to look how large the extent of the problem is made and connection with the outstanding databases. It turns out to nearly 600TB of data. Forty percent of the plant also uses a very old version of MongoDB, namely 1.8.1, which was released in early 2011. Matherly says that such problems have existed for years and are everywhere. He hopes that more people are going to look at the services responsible for the data in the databases, rather than focus only on the Web interfaces.