Tuesday, 24 March 2015

Many Computers Vulnerable To BIOS Leak


Estimated that millions of computers contain vulnerabilities in the BIOS (Basic Input / Output System) allowing attackers permanently infect a system and then steal all kinds of data. That researchers were LegbaCore Last week, during the CanSecWest conference in Vancouver. BIOS is a set of basic instructions for communication between the operating system and the hardware. It is essential for the operation of the computer and also the first major software that is being loaded.

During their demonstration ( pdf , pptx ), the researchers got different "incursion" vulnerabilities in the System Management Mode (SMM) see. SMM is a mode of Intel processors that firmware can perform certain functions. By using this mode, for example, the contents of the BIOS chip to be adapted or used for the installation of a "implant". Hence, it is possible to install and rootkits to steal passwords and other data from the system.

SMM malware also gives the opportunity to read all the data is in the machine's memory. The researchers therefore showed how they were able to access a BIOS through the incursion vulnerabilities, and then install the "Light Eater SMM implant" there. Via this malware they could GPG keys, passwords and steal decrypted messages from the Tails privacy operating system on an MSI computer.

Tails is a privacy and security-oriented operating system that can be loaded from DVD or USB stick. Tails removes even when closing all kinds of data from memory. Through the BIOS malware makes does not matter anymore, because all data from the memory of the computer can be stolen before cleanup occurs.

Attack

To install the BIOS malware attacker has two options, either through malware on your computer, for example, via an infected email or drive-by download. The second way is to have physical access to the system. The researchers would have already reported the problem to several manufacturers who are now working on a solution.

Even if released BIOS updates will probably have little effect. Most people install because no BIOS updates, the researchers said. According to the CERT / CC at Carnegie Mellon University are the vulnerabilities at least in systems from Dell and HP found. However, the status of many other suppliers is unknown.

Monday, 23 March 2015

Leak In Cisco IP Phones Allows Eavesdropping Possible


Networking giant Cisco warns of vulnerability in the SPA300 and SPA500 IP phones allowing attackers without credentials distance calls can eavesdrop or to gain access to the phone to call then himself. However, an update is not yet available.

Also could be used for a successful attack further attacks, said the advisory . The vulnerability is caused by authentication settings in the default configuration. An attacker would through a specially prepared XML request to send here to abuse a vulnerable device.

Cisco says that in order to exploit this vulnerability, an attacker allowing access to a trusted internal network behind a firewall should be to send the XML request. This requirement would reduce the possibility of a successful attack. Since there is no update available system get the advice to turn XML Execution authentication in the configuration settings.Furthermore, could protect a "solid firewall strategy" systems and can be considered to give only trusted IP addresses access.

Encrypted SMS With Android App SMSSecure


Announced a new app for Android should make it possible again to send encrypted text messages, now another popular Android app that made ​​this possible is stopped. Recently showed Open Whisper Systems , the developer of Secure Text, know that the support of encrypted SMS / MMS is stopped.

According to the developer will be encrypted SMS / MMS never easy to use as encrypted text messages, because users in encrypted SMS manual should exchange the encryption keys before it can be communicated. "We believe that people should not even know what a" key "is, so this obstacle always felt wrong," said the developers.

Also mentions Open WhisperSysms SMS and MMS a "security disaster", because metadata is continuously leaked. SMS messages pass through the servers of telecom companies. The developers do not want the state-run telecom companies like Saudi Arabia, Iran or China can access the metadata Text Secure users. Finally, the support of SMS / MMS make it more difficult for the developers in order to improve the app.

SMSSecure

On GitHub is a new app called appeared SMSSecure , a fork of Text Secure. It is a spin-off based on the source code of Text Secure and focuses on encrypted SMS messages. To go with the app to work there needs to be an unencrypted backup Text Secure, which can then be imported by SMSSecure. SMSSecure developed by the Frenchman Bastien Le Querrec.

Tommelein: Privacy Is Not A Black And White Tale



Privacy is not a black and white tale, but is always in relation to other rights and obligations, as has informed the Belgian State Secretary for privacy Bart Tommelein know. "There is no choice between whether or not privacy. Otherwise, the negotiations on the European regulation had long finished," he tells his own website. Tommelein argues that privacy is always in balance with other interests.

"How much of our privacy are we willing to sacrifice for our security? Consider the exchange of passenger data from flights. Badge Systems. CCTV." Cases which the Belgian State Secretary improve safety, but also new privacy questions entail, such as data storage, or anyone can be filmed and who gets access to these systems and data.

He calls find this difficult balance, pointing to the balance between protecting the privacy of the individual on the one hand and innovation on the other side. "A drone take pictures of a bike race, we find fantastic. But we find it a bit creepy when he flies above our own home."

Balance

One of the places where the balance should be found is the European privacy legislation, which dates from 1995 and according Tommelein is not up to date. There's already being talked about a new law, but the process is slow. However, the new privacy legislation will not be perfect warns the Belgian State Secretary. "Put ten people around a table and they each have a different definition of privacy." Nevertheless soon there should be a new privacy legislation he warns. "The world does not stop turning while we negotiate."

Tommelein closes his plea to the European legislation off by stating that even if the proper privacy balance is found, the highest will be temporary. "Privacy is never alone. You can not therefore 'fumble' privacy. You can at best balance between privacy and other interests. So that I do. Careful. Attentive. But without fear. Innovation is not something to be afraid of to be. The future is something to look forward to. "

Opera Buys Canadian VPN Service Provider Surf Easy


The Norwegian browser developer Opera has this week the Canadian VPN service provider Surf Easy acquired , allowing users to easily soon be able to go to protect their privacy, according to both companies. By using a VPN, it is possible to run an encrypted tunnel through the Internet to another computer, for example, in another country.

In this way, among other censored websites are visited and services are used that are not available in their own country. In addition, a VPN ensures that the network traffic is encrypted. Therefore, experts often recommend to use a VPN to open Wi-Fi networks. Through the cooperation both companies hope will soon be able to go to applications offer so users can take back control of their online privacy and freedom.

Microsoft Internet Explorer Still Alive


Internet Explorer was the last week in the American media declared dead now, Microsoft provides the following browser a new name, but according to the software giant's IE still alive. "Rumors of the demise of Internet Explorer are greatly exaggerated," says Microsoft's Dane King-Smith, program manager of Internet Explorer. In January, however, Microsoft announced that Windows 10 will launch a new browser, called " Project Spartan ". A name that Microsoft this week again brought to the attention.

However, the advent of this browser does not imply that it immediately with Internet Explorer has ended. According to King-Smith is important that all Windows users using the latest IE version. In addition, Microsoft has released an update for the Enterprise Site Discovery Toolkit for IE released. The first version of the toolkit was released in October and allows system administrators to measure the use of IE11 with internal applications, such as pages visited, Active X controls and used websites or applications that crash.

So organizations can see which applications staff use the most and in what way. This should make it easier to upgrade to the latest version of IE. Instead of testing a browser-upgade for all applications can be looked for which applications this is the most important. The update to the Enterprise Site Discovery Toolkit now also allows to collect information from IE8-, IE9- and IE10 users. System administrators should have the option to turn on the workstation, since IE collects this information yourself. In addition, no information is also collected as InPrivate browsing mode is selected.

Emergency Patches Firefox Remedy Pwn2Own Leak


Mozilla has released in a short time two emergency patches for Firefox that fix critical vulnerabilities that an attacker in the worst case, the computer could take over completely. It involves two vulnerabilities that were demonstrated during the Pwn2Own contest in Vancouver.

During the event, researchers can win cash prizes by showing vulnerabilities in popular browsers and browser plug-ins. In Firefox three vulnerabilities were demonstrated, where it earned two responsible investigators $ 45,000 together. A day after the demonstration had already updated to Mozilla Firefox 36.0.3 done that fixed the first two leaks. A few hours later by Firefox 36.0.4 for the third vulnerability.

Updating to Firefox 36.0.4 possible via the automatic update feature of the browser or Mozilla.org . Besides Firefox succeeded researchers during the event also to Internet Explorer 11 , Safari and Google Chrome hack. In IE11 most vulnerabilities were discovered, namely four. On the same day as Mozilla also came with a Google update for Chrome, but the description is not mentioned in it or this version vulnerabilities have been patched.

Sunday, 22 March 2015

NSA Director: US Must Invest In Cyber Attacks



The head of the US Cyber ​​Command and the NSA has a Senate committee announced that the US needs to invest more in the operation of cyber attacks, to deter as other countries. According to Michael Rogers, there is a tipping point .

"The US must consider how we our ability to expand the offensive side," Rogers told, so reports the New York Times.According to the NSA director and head of the Cyber ​​Command scares the current inadequate level off. Raising higher "cyber walls" is also never enough he continued. "We need to expand our ability to provide policy makers and operational commanders a wider choice of options. Because ultimately only a defensive reactive strategy both shows as many resources costs."

According to Rogers, President Obama has not yet decided to give him the authority to carry out cyber attacks. Policymakers would still not convinced that it is time, the cyber commander continued. "We need to increase the comfort and the knowledge of our policy makers with the properties that we have and what we can do."

British Secret Service Gives Companies Security Tips


British intelligence service GCHQ has all manner of security tips on how they can protect their systems, networks and information, including things like risk management, secure configurations, network, user, user awareness and prevent malware. A total of ten steps discussed to a safer environment.

The report with recommendations dating from 2013 ( pdf ), but appeared this week in the British media. The Daily Telegraph wrote about the measures in the report, partly because of the advice to turn off unnecessary input / output devices and remove access to removable media. Thus, companies should consider whether their staff access to things like MP3 players and smartphones requires. Would unused functionality should be disabled, such as USB ports, floppy drives and CD and DVD players.

According GCHQ users remain the weakest link in the security chain. "And will always be the primary target of all kinds of attacks. A successful attack simply by a user to leave open an email with malicious content." Organizations therefore be advised to monitor all user activity, as well as network traffic and all IT systems.

USB Flash Drives

In the advisory, a special chapter included drawing attention to removable media such as USB drives. For example, it is recommended to limit the use of removable media. "What use is unavoidable, organizations must limit the types of media that can be used together with the users, systems and the type of data that can be stored or moved to removable media."

Organizations would be wise to regularly scan removable media for malware and the information stored on it, depending on its value and the risks to which it, encrypt. In addition, removable media should be managed and disposed of active, to ensure that previously stored information is no longer accessible.

Companies Change Delivery Address Cisco Equipment Due To NSA


Some companies use other delivery addresses when ordering equipment from Cisco in order to evade the NSA, so, Cisco CEO John Stewart at a conference to know. Following his revelations of whistleblower Edward Snowden, showing that the NSA intercepted orders such as routers and then provides a backdoor. On one of the photos that were shown publicly through Snowden how NSA staff a box of Cisco equipment opens.

Stewart, chief security and trust officer at the networking giant says that it prevents companies specify delivery addresses that have nothing to do with the client, reports PC World . This should make it theoretically difficult for the NSA to focus on a particular company. Stewart did know, however, that once Cisco provides the equipment to a shipping company, it has no control anymore. However, Cisco could collaborate with customers to better control the integrity of delivered systems.

Yet then Stewart will always be risks that can not be avoided. "As a truly motivated team it has provided you, and they do this for a long period of time, this increases the chance that they will succeed again." Stewart was at the conference whether Cisco has ever encountered strange hardware in its own products which was placed there. "No, and that we could not know, because the only people who know for sure that the NSA," the CEO said.

14,000 US Patients Data Stolen By Email Hacking


An American healthcare has warned 14,000 patients that their data is stolen after a third party that handles billing with was to create an e-mail hack. One of the employees of this company was last year, according to the carer the victim of an " email hacking attack , "where username and passwords were compromised.

The incident was on December 3 last year discovered by the billing company, while the caregiver was told that on February 2 this year. Then there was established a research which showed that in the e-mail account of the attacked employee was the personal information of 14,000 patients, including names, date of birth, diagnosis, procedure, treatment dates, account numbers, costs and names of doctors.

In the case of 40 patients it was also to social security numbers. The healthcare provider will notify all affected patients by mail. In addition, there will be the email provider to see whether the already "robust security" can be tightened and staff will "email hacking attacks" are informed.

Just Patched Flash Player Flaw In sight Cybercriminals



A critical vulnerability in Flash Player that last week was patched used to attack Windows users. Through the vulnerability an attacker can place malware on your computer, for example if the user visits a malicious or hacked website or see a banner gets infected.

Report that security company FireEye and anti-virus company Malwarebytes . The exploits of the leak abuse is added to the Nuclear Exploitkit. This makes it easy for cybercriminals to attack unpatched Flash Users via the vulnerability. In the case, the attack is successful, a Trojan horse is installed there.

Although the update is available for a week does not mean that everyone who has installed, says analyst Jerome Segura."We know that in some cases, consumers, but usually companies, can not immediately install patches. In many cases, there must first be internally tested so that the patch does not disturb any business processes." The analyst advises organizations in this case to shield these systems from other systems on the network.