Friday, 20 November 2015

VMware Warns Of Vulnerability In Adobe Flex Software


VMware has warned of a vulnerability in a software module Adobe Flex used in a number of products including vCenter Server and vCloud Director. According to the report, the versions of VMware vCenter Server 5.5 and older vulnerable. Only version 6.0 of vCenter Server is not.

Upgrading

"You do not want unnecessary risks we advise you to upgrade to a higher version of our products," a spokesman of VMware reacts briefly. Users of vCloud Director 6.0 and Horizon are advised to upgrade to install VMware.

It is striking or the time of the alert. VMware Wednesday released a security advisory, while the problem certainly since august known is. Adobe has also been there at the time for warning.

An attacker can with a special XML command to the server to make sure that there are unintended data is disclosed.

Big Malware Advertising Campaign Unraveled


Malwarebytes claims to have exposed one of the largest advertising campaigns to malware of recent months. With the campaign large numbers of visitors were redirected to websites casino while their computers were infected with malware.

The campaign focused on visitors somewhat questionable websites including torrents, live streams of the latest movies and pirated software. Some ads that were on those sites, visitors automatically sent by (without having to click on the ad) to one of the casino sites.


Iframes

These sites were used as a diversion while there were loaded onto the background iframes variety of domains, which ultimately caused the Angler exploit kit to the victim was installed. Since this week would also Neutrino exploit kit can be used.

The ad campaign would be launched on October 21 and have lasted at least three weeks. That it took so long is, according Malwarebytes because both visitors and administrators of the dubious torrent sites had little need to report abuse, since they themselves were engaged in illegal content.

According SimilarWeb, a service that collects and analyzes data on website traffic, these ad networks generated in October visit more than two billion.

Thursday, 19 November 2015

Amazon Makes Two-Factor Authentication


Amazon has quietly for the shop two-factor authentication enabled. The option is currently still stand out. Logging in Amazon normally goes with a username and password. But for added security, users can now also receive a code on their phone they have to fill in the login.

The introduction of two-factor authentication will the attackers more difficult for someone else to log on because they need to know in this case, both username and password, but also have access to the smartphone.

An employee of Engadget discovered the new option this week. According to reports on Twitter, Amazon would be the new two-factor identification introduced about two weeks ago.

Two-factor authentication is a widely used method to prevent abuse of login data. Other major Internet companies that offer this login method, include Google, Twitter and Facebook.

Who at Amazon wants to use the two-factor authentication, should go to their account settings and select it by changing the settings for 'advanced settings'.

Botnet Tool Uses Twitter Direct Messages



Cyber criminals can control their botnet recently via Direct Messages on Twitter. The Python program Twittor called, was designed by the idea of GCAT, a similar program cyber criminals command & control servers to be managed via Gmail. Twittor made ​​by self-appointed security researcher Paul Amar and available from September, but is now observed by Sophos.

The tool uses direct messages on Twitter. The "advantage" of them, as compared to the conventional way of managing command & control servers, which the Direct Messages on Twitter are private. And the traffic is not stopped with IP filtering because Twittor use the Twitter API.

In addition, Twitter announced earlier this year that the limit of 140 characters is widened in private messages. This will therefore also more malicious traffic. The limitation is that there is a maximum of 1 000 direct messages per day can be sent.A botmaster can therefore no more than approximately 100 bots manage per account.

Many security tools such as Nmap and Metasploit, are not only useful for cyber criminals also useful for security researchers. Publishing a free tool that makes it possible to create a botnet via Twitter Direct Message operate seems an odd way of security research, says John Zorabedian Sophos.

New Version Tesla Crypt Spotted In The Wild



There's a new version around the stubborn ransomware trojan Tesla Crypt. Although not much seems to have renewed the software, it is very difficult for them to komen.De off new variant, Tesla Crypt v2.2.0, encrypts files with the .ccc file extension, such as happened in previous versions.

What is new is that there are multiple names for ransom notification files. According to posts on forums that filename can vary and it looks like "_how_recover_.HTML 'or' _how_recover_.TXT.

The ransomware Crypt Tesla earlier this year for the first time discovered and has targeted files with extensions which had mainly to do with games. To regain access to the files, often $ 500 was demanded.

According Bleepingcomputer it is virtually impossible to undo the encryption of Tesla Crypt v2.2.0 without paying the cyber criminals. Because version 1 yet made ​​use of a symmetric encryption method, soon developed a tool to "liberate" hostage files without paying. This new variant is working tool which unfortunately no longer.

Wednesday, 18 November 2015

Public Wifi Especially Risky In Airports And Hotels



Most of unsafe open Wi-Fi networks can be found in airports and hotels. There is the chance that you log in to a hotspot of a malicious greatest. That's Janne Pirttilahti, Director of Product Management Next Gen Security at F-Secure, said Tuesday.

Pirttilahti demonstrated during Wifi Now in Amsterdam how easy it is to create a fake hotspot and people in the area to let the network use with the aim to steal private information from them.

Hotels And Airports

Hotels and airports are the easiest locations to set up fake hotspots around because there are a lot of businessmen or people who have to spend money, says Pirttilahti talking. "There are interesting targets, while falls in those locations do not like someone pops open a laptop with antennas. Sometimes it can even from a hotel room. But in a coffee shop is much faster suspicious."

Research by F-Secure among UK consumers also shows that many consumers are well aware of the risks they run if they use public Wi-Fi networks. A whopping 52 percent of consumers surveyed avoid using public Wi-Fi networks because they are afraid that their personal information into the hands of hackers.

VPN Connection

59 percent says open Wi-Fi networks not to use it because they are afraid of viruses or malware. Still, says nearly one in every three month to use at least once and sometimes daily public wifi networks. The advice is to at public Wi-Fi networks in any event using a VPN connection.

New Service Makes Online Extortion Easily Accessible


A new service enables online extortion using ransomware easily accessible. Interested parties can log on to the new service by paying one-time $ 50 and the amount to indicate that victims must pay to regain access to their files hostage.

10% commission

The proceeds are paid directly into Bitcoin payments, minus a 10 percent commission for the new Crypto Locker Service, says Trend Micro. The recommended amount of the ransom is $ 200. The crypto ransomware where use is made ​​of, is effective with Windows users but it seems that there are also plans to develop this crypto locker for other operating systems.

The owner of the crypto locker service is a familiar face in the cyber underworld. It is about 'Fakben "the former manager of Evolution, the black market on the Tor network which was closed earlier.

Although it is not yet clear what the implications of this new service will be, it is not inconceivable that the number will rise ransomware incidents. It is recommended to make regular backups so there is no need to pay the extortionists in the event of an incident. Paying ransom will publish only encourage more attacks.

FireEye: Precision Attacks Possible Thanks Analytics


Webanalytics may be used to collect online information to let go then very targeted attacks on those visitors. Such practices to gather information would be even sponsored by certain governments. Claiming security company FireEye in the report pinpointing targets.

WITCHCOVEN

According FireEye is information about visitor behavior gathered through more than 100 websites that were hacked and manipulated. Anyone who visits such a site, imperceptibly redirected to a second site where the script WITCHCOVEN in is processed.

This script collects detailed information from the user's computer and install a "super cookie" to track the visitor. The information from the computer used according FireEye for later use very targeted exploits that work on those specific configuration and software of the user.

Gmail App Allows Spoofing


The Gmail app for Android installed already standard on many smart phones, enables users to send spoof emails. Google acknowledges the findings, but still taking no steps to remedy it.

Security Researcher Yan Zhu discovered that it is possible in the Gmail app to send emails from a fake sender address. The trick is very simple and will only work with the Gmail app for Android.


If the display name is changed in the settings, the app itself removes the real address from which the message is sent. For the receiver it is therefore difficult to check the sender via the headers. For demonstration Zhu sent a mail from the account security@google.com.

Although not found bug is serious, it can easily be abused. Spoofing is a technique widely used by cyber criminals to lure potential victims to a particular site.

Yan Zhu its findings in late October when Google reported, writes Motherboard, but who denies that this is a vulnerability.

Tuesday, 17 November 2015

"A Quarter Of IoT Devices Is Leak '


Connecting IoT devices in the home is like playing Russian roulette. Nearly one in four 'connected' devices for home use is not secured. Or there are errors in the firmware or the Web portal to gain access to the device is not secure enough. That's the conclusion of researchers from the French Eurecom and the Ruhr University in Bochum, Germany. They examined the firmware on routers, modems, VoIP phones, network cameras and other IoT devices that can be managed via the internet.

Attempts were made to undermine security by customizing the firmware by malicious software updates, but also to attack the web portal of the aircraft. The portals were exposed to frequent attacks such as XSS (cross-site scripting), CSRF (cross-site request forgery), SQL injection and RCE (remote code / command execution).

In total, were investigated in 1925 firmware images from 54 different manufacturers. More than 9200 vulnerabilities were found in 185 firmware images. Although only 8 percent of the firmware php code contained in the management of the portal, was found in 143 firmware images whopping 5000
XSS Vulnerabilities.

The study seems to confirm what even last week at Black Hat Europe emerged. A survey conducted by Information Week and Dark Reading which showed that IT professionals believe that in two years the security of IoT will be a top priority. Now the priority is still mainly in the security of applications and end users.

Png Files Vulnerable To Buffer Overflow


The code to handle PNG files is a serious vulnerability. The problem that has been identified in libpng, the PNG library is used in a lot of software.

The leak was reported Friday by Glenn Randers-Pehrson. Thanks png files with manipulated image headers hackers are able to create a buffer overflow and allow applications to crash. An attacker could also execute malicious code when a successful attack.

A complicating factor is that many programs use the libpng library to display png files or save. They include the most web browsers, Android, image viewers, media players and virtually all Office programs.

Updates

It is expected that in the very short term already widespread abuse will be made ​​of the leak. The libpng version 1.6.19, 5.1.24, 1.4.17, 1.2.54 and 1.0.64 which were released last week, are no longer vulnerable. These versions can be downloaded via libpng.sourceforge.net.

American Police Cameras Contain Conficker Worm



Cameras US police seem standard to include the Win32 / Conficker.B! Inf worm. The malware is installed and can easily infect unprotected PCs. That network integrator iPower Technologies discovered. This company is the producer of cameras Martel Electronics testing and technical in screening since iPower a cloud storage service for the action cameras is developing on behalf of the US government.

Quarantine

According to Jarrett Pavao and Charles Auchinleck of iPower is the Conficker virus once the camera is connected to a protected computer, put immediately into quarantine. Unprotected computers are infected, however, and there is the worm itself spread further over the network and internet.

According to Pavao and Auchinleck is not about an incidental finding, but has been demonstrated the presence of the worm several times. The producer of the camera has promised to come up with an explanation.

The GPS cameras, which each cost about $ 500, by agents but also by other officials worn on the body in the United States to capture street actions on screen.