Friday, 2 October 2015

Researcher Bypasses Gatekeeper Security Mac OS X


A researcher has managed to circumvent the Gatekeeper security of Mac OS X, making it possible to run unsigned code on systems. Gatekeeper is a security measure since 2012 is present in OS X and determines which applications can run.

For this Gatekeeper performs several checks. By default, Gatekeeper configured to make only apps from the Mac App Store and identified developers allow. In the latter case, it is developers who have a valid Apple Developer ID certificate. Users can also set Gatekeeper to allow only apps or all apps that come from the Mac App Store.


Check

Researchers Patrick Wardle has now found a way to bypass Gatekeeper. The security measure because it does not appear to check whether an app or other apps code loads from the same or a related directory. Gatekeeper trusts the app, on the basis of the first static control. An attacker can abuse this by allowing the user a signed and infected app download or through a third party via a man-in-the-middle position. In this case, the download should take place over HTTP.

In the case of the attack that the investigator has developed, the user will be offered a DMG file. Once the user opens the file, the malicious file is executed in the same DMG file. The problem is present in OS X Yosemite and the beta version of El Capitan, Wardle so late Threat Post know.

Apple is already working on a solution for the short term until a full patch can be deployed. Users get to the appearance of this workaround or patch advised to only download apps via HTTPS and reliable sites such as the Mac App Store. Wardle today gives at the Virus Bulletin conference a presentation about the issue.

StageFright 2.0: Android Phones Vulnerable To New Stage Fright Leak


Millions of devices with Android are vulnerable because of a new vulnerability in the Stage Fright-media library and a security update from Google is not yet available. Reported security Zimperium. Stage Fright is a library that handles a variety of media formats.

A problem in the handling of MP3 or MP4 files ensures that an attacker could execute arbitrary code in the worst case to the unit. In late July, investigators were already several vulnerabilities in the Stage Fright library known. These include leak made ​​it possible to attack Android devices via MMS messages. The two now discovered vulnerabilities as "Stage Fright 2.0 identified". The first vulnerability is present in every Android device since version 1.0 was launched in 2008.

The researchers discovered a second leak making them the first leak on devices with Android 5.0 and newer can attack if a specially crafted MP3 or MP4 file is processed. Older phones may be at risk if the vulnerable component is invoked via third party apps or placed by the operator on the phone.

The primary attack vector for the first Stage Fright-leakage was via MMS, but this is in new versions of the Google Hangouts, and Messenger apps no longer possible. The researchers therefore see the browser as the main attack vector. An attacker could entice a user for example to a website or may execute the exploit via a man-in-the-middle. Google was informed on August 15 about the problems, but a patch is not yet available.

Google Will Support HTTPS For Blogspot



Owners of a blog on Google can now set HTTPS, so that traffic to and from the blog is encrypted. That Google has announced. The Internet giant has in recent years more and more services HTTPS enabled, but not for the popular blog platform Blogspot.


That is about to change. For blogs can enable encryption are important because, according to Jo-el Bergen, software engineer at Google Security. HTTPS can define users as to whether they are on the right website and not redirected to a malicious site. There may also be detected via HTTPS or an attacker to manipulate the data that is sent from Blogspot to a visitor, says Van Bergen.

HTTPS is not immediately available automatically to all Blogspot users, and will be gradually rolled out. Bloggers can Enable all myself. It only applies to blogs here, which are accessible via the domain of Blogspot. Bloggers who use their own domain name will be later supported. Bloggers do get a warning that after enabling HTTPS certain things may not work as templates, gadgets or content. It often matters that are offered via HTTP. To set a good example Google is now also a number of own blogs to move HTTPS.

Symantec: WinRAR Flaw Less Serious Than Thought




A vulnerability in the popular WinRAR archiving progam which no update is available, and for which recently the National Cyber ​​Security Center (NCSC), the government warned is less severe than thought, say Symantec and developer RARLAB.

WinRAR is a very popular program for packing and unpacking files. Besides the standard RAR archive, the software can also make a Self Able Extract (SFX) archives. In this case the archive file is unpacked automatically when the user opens the file, regardless of whether they have installed WinRAR or not. SFX archives are basically just exe files and consist of the packed file and the un pack module WinRAR. By letting users open a malicious SFX archive an attacker could execute arbitrary code with the rights of the logged-in user, as this video shows.

The vulnerability makes it possible to be carried out when opening the SFX archive automatic code of the attacker, like downloading and installing malware. Contrary to some media reports, the problem not only for users of WinRAR, but to all Windows users who receive a malicious SFX archives. Symantec and RARLAB, developer of WinRAR, users need to open exe files, whether it is an SFX archive or not, always be careful.

RARLAB said in a statement that there are much simpler ways to attack users via a malicious SFX archive. Users also are advised not to open unexpected files or files from unknown or untrusted sources. The developer of WinRAR is therefore no plans to remove the option is now displayed where the use of attack, as this only legitimate users would hit.

Thursday, 1 October 2015

Suspicious Windows Update Shows Test Microsoft


A Windows update that was rolled out unannounced yesterday among users caused some panic, but in retrospect it proved to be a wrong test performed by Microsoft. The update, which was labeled as important, was offered as an additional language update.


The name and description of the update consisted of a random string of characters and contained several broken links. On the forum of Microsoft thought users therefore attackers had managed to compromise Windows Update and so spread malicious updates. Twelve hours after the update was released, Microsoft had opposite Ars Technica that unintentionally a test update was issued and the update has now been removed.

A user who installed the update states that after this laptop are not working properly and the regular Windows Explorer crashed. System would no longer work and the update could not be removed. The fear among users was not unjustified. In the past, attackers have managed the Flame malware spreading via Windows Update on a local network.

Apple Close 147 Vulnerabilities In OS X, iOS And Safari


Apple yesterday updates to Mac OS X, iOS and Safari released, which fix 147 vulnerabilities added. The biggest update was for Mac OS X. OS X El Capitan (OS X 10:11) Apple also has many new features in addition to fixed 101 vulnerabilities.

Through the vulnerabilities an attacker could execute arbitrary code in the worst case. Also, it appeared to be possible to gain access to keychain items and Safari users to follow as they were using private-browsing. Furthermore, an attacker could intercept via a man-in-the-middle SSL / TLS connections, decrypt SSL traffic and determine RSA private keys.

It is now no longer possible to flash the firmware with a malignant Ethernet Apple Thunderbolt adapter. In addition, it appeared that the "Secure Empty Trash" option to permanently delete files, deleted files are not always permanent. A list of all solved problems on the website of Apple to find. The new OS X version can be downloaded via the Mac App Store and Apple.com.

IOS

Yesterday released a new version of iOS. IOS 9.0.2 fixes a vulnerability allowing someone with physical access to the device photos and contacts could approach, even though the screen lock was active. Due to a problem with the lock screen could these data and files are still accessed. Apple has solved this by limiting the options available on a locked device. The update can be downloaded via iTunes and the Software Update feature.

Safari

In Safari 9 for OS X Mavericks, OS X Yosemite and El Capitan OS X, Apple has fixed 45 vulnerabilities. Through the vulnerabilities an attacker could determine the browsing history of users and Safari Extensions replaced. Due to a problem with the Safe Browsing option users were not warned when they visited a known malicious website. In the worst case, an attacker could execute when visiting a hacked or malicious website arbitrary code on the system. Safari 9 can be downloaded via the Mac App Store.

Microsoft Received 175 000 Complaints About Telephone Scammers



Since May last year, Microsoft has more than 175,000 complaints received telephone scammers. It is in this case to telephone scammers posing as Microsoft employees. The scammers call people and say that there are problems with the computer, such as a malware infection.

It then attempts to get the victim to install a program that allows the scammer can take over your computer. Ultimately have to pay the victim for the correction of non-existent problems, which can amount to hundreds of euros. According to Microsoft this year will be an estimated 3.3 million people in the United States more than $ 1.5 billion to pay scammers. It is not clear whether this just about telephone scammers. In order for people to warn the scam Microsoft is working now with the American Association of Retired Persons (AARP). There is an information leaflet developed (pdf) and workshops are organized.

Adblock Plus For iOS App Store Officially Launched


The makers of the popular browser extension Adblock Plus now also have a version for iOS nine developed which is free from the App Store to obtain. Through the AdBlocker allows users to block ads on their iPhone and iPad. This can save users data traffic, protect themselves against infectious ads, improve privacy and reduce battery consumption, according to the developers.

To use Adblock Plus for iOS users must perform some actions. The developers of the browser extension therefore have a very brief guide put online. Adblock Plus has been downloaded over 300 million times and has tens of millions of active users. It is by far the most popular browser extension on the Internet. The iOS version is free via the App Store to download. Yesterday launched also the Finnish anti-virus firm F-Secure its own free AdBlocker. Since Apple iOS nine state AdBlocker apps increasing, which now several apps has produced.

Research: Install Patches Costs Companies 100 Days


Companies have on average between 100 and 120 days to install patches for vulnerabilities, giving them some time vulnerable to attackers. Some vulnerabilities are not patched, however. According to research (pdf) of Kenna Security among 50,000 companies.

While companies need between 100 and 120 days to deploy available security updates, shows that attackers operate much faster. Most vulnerabilities are namely attacked in the first 60 days since the release of the patch. Between 40 and 60 days, there is a chance of 90% that a vulnerability is attacked.

The researchers argue that in the case of unpatched vulnerabilities that are attacked often for very famous and ancient leak is where patches have long been available, but not installed by organizations. "When evaluating the data we got this over and over against", so let them know. For example, last year 121 000 successful attacks on a vulnerability in phpMyAdmin measure that had already been patched in 2010. Another example is the vulnerability that uses the Slammer worm. This vulnerability dates from 2002, but last year there were still 156 000 successful attacks using the vulnerability instead.

Leak In Nvidia Driver Could Give Local Attacker Root Privileges


Chip manufacturer Nvidia has released a new driver because of a vulnerability allowing a local attacker could gain root privileges or could cause a Denial of Service. The problem is present in all supported Nvidia drivers and all GPUs, for both Windows and Linux.

Researchers at the HP Software Security Response Team. The problem is not with Nvidia Tegra products based on Android. In order to take advantage of the vulnerability, an attacker must first have access to the system. Such a problem was discovered last week in TrueCrypt. The drivers from Nvidia, however, are installed on more systems, which increases the impact of the problem.

Depending on the driver version installed on the system to get Windows users advised to version 353.82 or newer, or version 341.81 or newer upgrade. Linux users need to version 304 128 or newer, version 340.93 or newer, or version 352.41 or newer upgrade. The drivers are on the website of Nvidia download.

Google AdWords For Blue Screen Of Death Scam



Criminals have used Google Adwords to lure users to pages that called a Blue Screen of Death show (BSOD). For resolving the problem should then phone calls. Eventually adjust the telephone scammers that they can fix it for an amount between 199 and 599 dollars, let anti-malware company Malwarebytes know.

To get people to the pages used to lure the BSOD be AdWords, the largest online advertising service from Google. When users via the Google search engine for the term "youtube" searching pull them alongside the search results to see two ads above the results. It seems here that the ads point to YouTube, but loaded into reality the BSOD page. After being informed, Google removed the ads. According to analyst Jerome Segura is consciousness but the best protection against these scams.

Anti-virus Company AVG Switches To Windows 10-Like Model


The Czech anti-virus company AVG has announced a new series of products that will be updated automatically when new versions are available, as is done with Windows 10. Also, there is now full support for Windows 10 added.

The new update model has to provide updates on a continuous basis and ensure that users always have the latest version. According to AVG this is the first step of the company towards "Security as a Service". It succeeds Microsoft that Windows 10 direction "Windows as a Service goes." The anti-virus software AVG offers both free and paid versions and is available for different platforms.

Recently, the company was still under fire for its new privacy policy, which states that the virus fighter must collect all sorts of data from users. AVG responded by stating that it will not sell users' personal data.