Friday, 3 July 2015

Researcher: Companies Must Use Microsoft EMET


Companies can by installing the Microsoft Enhanced Mitigation Experience Toolkit (EMET) make it more difficult for attackers to gain access to systems and networks. That says researcher Grant Willcox . He decided to look for his thesis on the effectiveness of EMET 5.1.

EMET is a free tool from Microsoft that makes it harder for attackers to use both known and unknown vulnerabilities in applications. Wilcox decided to modify three exploits to see if he could bypass the security of EMET this. With one operates succeeded the researcher. But he had made ​​the assumption that it was possible to bypass all three exploits EMET. Since this was not successful as the late Wilcox see the effectiveness of the security tool.

Featured

The researcher says that on the basis of the results it is recommended that companies EMET 5.1 or later use, since it is a "very effective solution" is to prevent attackers use common problems within programs. "It probably will not prevent a determined attacker will use exploits to gain access to the corporate network, but it will put less determined attacker and force them to use alternative solutions."

Companies that choose to roll must be used within the recommended profile of EMET EMET. EMET has different profiles for programs to help determine the level of security. By performing tests can then be examined or higher levels of security are possible without crashing programs. "Although the security of EMET is not waterproof, it raises the bar quite to attack programs," concludes Wilcox.

T-Pot: Intel And Deutsche Telekom Launch HoneyPot Project



The German telco Deutsche Telekom and Intel are a honey pot project started to gather information about all kinds of threats and attacks on the internet. A honey pot is a system that aims to be attacked.Researchers can monitor the honey pot as how the attackers exact procedure and use this information to protect other systems.

If Deutsche Telekom is the honey pot technology in each device will be used which is connected to the Internet so that everywhere "cyber security sensors" are active. At present, Deutsche Telekom worldwide put down all kinds of honeypots.Through collaboration with Intel will this network be expanded with new sensors. It will also examine how honeypots can be developed and eventually be processed into a product for customers.

The development of new sensors, which can be integrated into any device with a computer, it is the ultimate goal of the project. This is to ensure that customers faster attacks are warned and can take action. For organizations and users now want to establish whether a honey pot, Deutsche Telekom's DTAG Community Honeypot Project created. Through the project, software is offered, for example, an Ubuntu system to change into a honey pot platform.

Qualcomm Develops Smartphone Kill Switch At The Chip Level



Chip manufacturer Qualcomm has developed a kill switch for smartphones that can lock the device at the chip level and will be applied by the software of the Czech anti-virus company AVG. The measure to protect consumers and their data in the event of a lost or stolen smartphone.

Safe Switch, as the technology is called, the device locks on the chip level. In addition, it protects users by encrypting data on the device. Any attempt to replace the SIM card, perform a factory reset or PIN to brute force makes the device temporarily unusable. After locking only the owner via a "master" PIN to unlock the device.

The technology will now be used in the applications of AVG and works on a select number of smartphones with Snapdragon chipsets. This week both companies demonstrated their solution. The cooperation should ensure that later this year an "end-to-end" business solution can be offered, says AVG .

Ransomware Distributed Through Google And Yandex Disk Drive



Cyber criminals have started a new campaign in which she websites of ministries and energy companies to recreate and then spread through Google Drive and Yandex Disk ransomware. It is a campaign of the Torrent Locker ransomware, which according to the Japanese anti-virus company Trend Micro focuses primarily on UK Internet users.

The attack begins with an email from British Gas, the Ministry of Interior or the Ministry of Justice seems to come. Unlike many other ransomware attacks the e-mail contains no attachment but a link that points to a convincing website. This site seems to be a copy of the original site of the power or ministry, stating that the user must enter a captcha, for example, to see his energy bill.

The captcha is probably the researchers used automated analysis to avoid anti-virus companies and researchers. Once the captcha is completed there will be downloaded a zip file. Were these zip files before storage services SendSpace, MediaFire and Copy.com stored now use the cyber criminals Disk Yandex and Google Drive.

For hosting the images used in the emails make criminals using hacked websites. Trend Micro discovered a total of 800 hacked domains where the images were stored or used as redirect the link in the e-mails functioned. 

Thursday, 2 July 2015

Anonymous Surfing Via Wi-Fi Network In Kilometers


An IP address usually leads to the physical location of an Internet user, but a security researcher has developed a hardware-based solution that makes it possible to surf the Internet anonymously via Wi-Fi networks that are located on kilometers away.

Even if the IP address is traced, the actual location and identity of the user is protected. The solution devised Benjamin Caudill , founder of Rhino Security Labs, the ProxyHam. Anonymity on the Internet is as Caudill under fire, especially for whistleblowers. Although Tor provides some anonymity, there is still a fundamental vulnerability present. Namely, the direct relationship between the IP address and a physical location.

"If your real IP address is detected, the game is over, a big threat if the enemy manages the infrastructure," he tells the notice of the ProxyHam. This device will present at the upcoming Caudill Defcon conference and Internet users must provide more anonymity. The ProxyHam acts as a hardware proxy traffic from the user sends to a Wi-Fi network that is located on kilometers away, says the researcher opposite Vice Magazine.

Hardware

The device consists of a Raspberry Pi computer with Wi-Fi card and three antennas. An antenna that connects to an open Wi-Fi network, for example at a Starbucks or library, and two antennas that send the data to and from the user via a 900Mhz frequency. A user can be located at a position of 4 kilometers. To make the connection ProxyHam the user must connect a 900Mhz antenna on the Ethernet port. An attacker would detect the user will find that only the IP address of the ProxyHam.

The signal emitted by the ProxyHam has such a low frequency that it is difficult to follow. In addition there are in this frequency range of other devices, such as cordless phones, baby monitors and walkie-talkies. Caudill is now working on new features, including an option to destroy the proxy to let themselves be messed with it. The researcher tries to hide the proxy in certain objects like a book. Because of this disguise it can take years before the device according to Caudill is found in a library.

Researcher Circumvents NoScript Firefox Through Google Cloud


A researcher has managed to circumvent the popular Firefox extension NoScript by using the Google cloud. NoScript is an extension that can block JavaScript and other code on websites. It thus prevents malicious code on a compromised Web site can be started or ads, trackers and active content are automatically loaded.

The add-on protects both security and privacy. More than 2.2 million Firefox users have installed NoScript, making it one of the most popular extensions for Firefox. NoScript also allows users to set up a whitelist domains. Scripts in this domain will be run automatically. Some areas are already standard on the NoScript whitelist, such as Mozilla, YouTube, Google and Yahoo.

This concerns not only the fields, but also the sub-domains under the domain. Besides google.com also scripts on voorbeeld.google.com automatically accepted by NoScript. Recently discovered researcher Matthew Bryant that one of the areas that had expired stood on the NoScript whitelist and thus was available to everyone. Bryant registered the domain and placed here Javascript code, which automatically performed by NoScript. The developer of NoScript came with an update so that the domain from the default whitelist has been removed.

The publication of Bryant urged another researcher to look for a new opportunity, as well as subdomains of whitelisted domains attack vector for an attack can be used. Researcher Linus Sarud saw that the domain googleapis.com standard in the whitelist, meaning that script code storage.googleapis.com this is done by default. Through this domain, users can host files as they use the Google cloud storage. Another researcher named Mathias Karlsson worked out the idea and came up with code that NoScript was again defeated.

The problem has been fixed by the domain googleapis.com change to the whitelist in ajax.googleapis.com . However, subdomains are still automatically whitelist. Users of NoScript, however, can delete the default whitelist and only own domains to this place.

Malwarebytes: Also Driver Updaters Are Often Scams


Programs that claim to be able to update drivers on the computer are often scams reason for anti-virus company to Malwarebytes' driver updaters "as potentially unwanted software (PUP) to criticize. The virus fighter would get a lot of complaints from users about these types of programs.

Driver updaters scan the computer and check on missing or new drivers, for example, printers, network cards and video cards. Most computers as Malwarebytes no drivers needed to operate. "Only in some edge cases, updating drivers are handy," as late as the anti-virus company know . Updating drivers including driver updaters advise, Malwarebytes also advises against. The potential benefits would not outweigh the clear disadvantages.

To install the missing drivers that enable the driver updaters users should find the software first or register, which must eventually be paid. In most cases, however, be free to download drivers for consumers. "That is the core of the problem. This driver update programs can sometimes solve a problem by installing a new driver, but in most cases they replace an identical driver and ask for money here," said the virus fighter.

The company's software driver updaters which will behave aggressively, to be appointed by example, certain standard checking checkboxes or bundled surreptitiously, classify as PUP. In this case the software is quarantined. It is ultimately up to the user whether he really wants to remove the driver updater or still want to use. "We can make it clear that these types of programs are scams, but we will not force you not to use them," explains the anti-virus company from. Malwarebytes recently decided even against so-called registry cleaners to act, which also designates it as a scam.

Apple Closed 164 Vulnerabilities In OS X, iOS, Safari, iTunes, And QuickTime


Apple yesterday evening updates for Mac OS X, iOS, Safari, iTunes, QuickTime, and Mac EFI released that fix vulnerabilities 164 together. Most of the updates, 77 in total, appeared for Mac OS X in the form of OS X Yosemite 10.10.4 and Security Update 2015-005 .

Thus, clearing the logjam attack through these updates, as well as several vulnerabilities which could allow an attacker at worst arbitrary code on the computer. This could for instance by the user to open a malicious zip file. The updates can be downloaded via the Mac App Store or Apple's download site.

IOS

In iOS 8.4 , Apple fixed 33 security vulnerabilities. Through the vulnerabilities could allow an attacker who is between the user and the Internet was to intercept network traffic, execute arbitrary code, external HTML in the Mail app loading, accounts taken over by users to a malicious website visits or perform the logjam attack. For arbitrary code execution, an attacker could use a malicious SIM card. Updating to iOS 8.4 can automatically or manually via iTunes or the Software Update feature.

Safari and Mac EFI

Apple also released new versions of Safari. Safari 8.0.7, Safari 7.1.7 and Safari 6.2.7 fix four vulnerabilities allowing a malicious website could approach the WebSQL database from other websites, visiting a specially prepared website made ​​it possible to hijack accounts, there via a malicious link to a PDF file was embedded in a website cookies could be stolen and the worst could be executed arbitrary code when visiting a malicious website. Updating via the Mac App Store.

Apple also patched the leak making it possible via a malicious app with root privileges EFI firmware to match. Furthermore, among the Rowhammer attack, which investigators DDR3 memory could attack the past. Also EFI Mac Security Update 2015-001 is available via the Mac App Store.

Windows Users

For Windows users also appeared updates. These are patches for QuickTime and iTunes for Windows. iTunes 12.2 for Windows 7 and Windows 8 fixes 39 vulnerabilities could allow an attacker, who was between the user and the Internet, could execute arbitrary code on the computer and the iTunes Store was visited. In QuickTime was the execution of arbitrary code.This, however, had to be opened a specially prepared file. The nine leaks in QuickTime 7.7.7 corrected.

Wednesday, 1 July 2015

Researchers Found Vulnerabilities In Antivirus ESET



A researcher from Google has discovered a vulnerability in the security of the Slovak anti-virus company ESET, but a day before the virus fighter problem patched a group of other researchers unveiled a new vulnerability in ESET Smart Security 8.

Last week Google revealed researcher Tavis Ormandy a critical vulnerability which he computers using ESET software without user interaction could remotely take over completely. After being informed ESET came after three days with an update. Ormandy discovered another problem in the security software. This time could an attacker when unpacking a specially prepared Symbian installation cause a heap overflow, and thus execute malicious code on the computer. On June 26, after having been informed within three days, came ESET with an update to address the vulnerability.

Second vulnerability

Another group of researchers called QWERTY Lab discovered a vulnerability in a part of ESET Smart Security 8. Through the leak an attacker can gain the highest privileges in Windows. Then, the virus can be disabled, but it is also possible to bypass Windows access controls and sandboxes, as the researchers claim. As proof, they published a proof-of-concept exploit.According to the researchers, the problem confirmed Smart Security 8 but were also other anti-virus company vulnerable. On June 25, the issue was made ​​public, the researchers decided to inform ESET in advance.

The virus fighter know that the vulnerability found in several earlier versions for Windows is available. The latest version of the security software is not vulnerable. At present we are working on an update for the problem which "fast" should appear, but an exact date could not give ESET. Following the various vulnerabilities requires another investigator when ESET and other anti-virus companies are auditing their products.

Survey: Most VPN Services Leak IPv6 Traffic


Twenty percent of European Internet users use a VPN service to encrypt its Internet or IP address to foreclose, but many of these services leakage data users, say researchers at Queen Mary University of London (QMUL).

VPN services are among others used to visit for example censored or domestically not accessible websites, but also to encrypt traffic so for example, the home network can not monitor this. The researchers looked at the services of the 14 most popular VPN providers and found that there are 11 user information leaked, so leave them in their research report ( pdf know).This involves things like websites visited and the content of comments posted online. The problem is not with websites visited via HTTPS.

IPv6


The problem is caused by the leakage of IPv6 traffic, also referred to as "IPv6 leakage". IPv6 is the successor to IPv4, which is the standard now. The Internet Protocol is the communications protocol that is used to identify hosts on networks, and to determine their location. The advantage of IPv6 is that many more addresses are available, and provides the protocol features that are not present in IPv4. Many network operators steps now to IPv6, but many VPN services protect only IPv4 traffic.

For the study the fourteen most popular VPN providers were used and made from different devices with a Wi-Fi network connection. Attacks were carried out from this access point that could perform attackers. There was passive monitoring place where unencrypted data was stored, and "DNS hijacking, in which the users' browser was redirected to another location.

The researchers also looked at the safety of different mobile platforms when using VPN services and discovered that Apple's iOS offers more protection, but data from Android users can leak. "There are several reasons why someone wants to hide his identity and it is worrying that they are at risk, even though they use a service that is precisely designed to protect them," said QMUL researcher Gareth Tyson. He is particularly concerned about people living in repressive regimes and surfing via a VPN.

USB Worms Most Active Malware In European Union


Worms that spread via USB drives and shared network drives and folders were in the second half of last year, the most active malware in the European Union, so says Microsoft. Just over 10% of all malware observed in this period by the software giant had come from three worm families. Malware that spreads through exploit kits, which use is made ​​of unpatched vulnerabilities, was much less common.

Is looked specifically at the EU countries shows that Finland, Denmark and Sweden to do with the least infections had. In Bulgaria, Italy, Romania and France, most infections were found. Netherlands also doing very well in the reviews of Microsoft and reached the lowest level in four years. According to Microsoft's Tim Rains is a lot of malware to avoid operating in the EU by keeping computers up-to-date and use security software.

Hacked Routers Used To Distribute Malware Dyre



Cyber criminals hacked routers to distribute the Dyre-malware, as discovered and reported Bryan Campbell , security researcher at Fujitsu. Dyre , also known as Dyreza, is a Trojan specifically designed to steal money from online bank accounts.

Be emails with infected e-mail attachments used for the distribution of Dyre. Annexes instance pose as an invoice, but is actually the Upatre downloader that eventually install the Dyre Trojan on the computer. Once active Dyre will the browser (Internet Explorer, Google Chrome or Firefox) and hijack login information for online banking returned to the criminals. Then the malware installs a spam module on the computer and will use it to send new e-mails.

Campbell found that Dyre used to install the "payload" hacked routers. It is Ubiquiti Networks routers that use the operating system airos. Besides these routers would also routers manufacturer MicroTiK, running on RouterOS, are the target. The researcher makes on his own blog know that making the Dyre instances that he studied with many hacked airos routers connection. The routers are probably using known vulnerabilities or default credentials hijacked.