Friday, 22 May 2015

Private Data 3.9 Million Members Adult Dating Leaked


Attackers have managed to gain access to a database of popular adult dating site Adult FriendFinder and subsequently the private data of 3.9 million members leaked. It is the sexual preference of users, whether they are heterosexual or homosexual, and extramarital relationships search and e-mail addresses, user names, birth dates, post codes and IP addresses. Among the leaked data are also data from users who had asked the website to delete their account.

Reported that the British television Channel4 . The data of the users would be traded on a black market, where the captured email addresses now with all kinds of spam and infected e-mails are bombarded. The data stolen were also found data from British government and army personnel. Experts warn that these data can be used for targeted attacks on interesting individuals.

In a statement, the dating site says that there are now cooperating with the authorities and a forensic investigation. Depending on the results will take measures to protect the website users. How the attackers access to the database managed to get is unknown.

Secret Unit Google Fights Against Botnets And Click Fraud


Google has a secret unit of over a hundred people who are working every day with combating botnets click and ad commit fraud. The botnets generate traffic and clicks for ads and would advertisers and advertising platforms billions of euros.

Google is the largest ad provider on the Internet ad fraud and therefore constitutes a serious risk to giant internal. A risk is increasing. "We are at a point which malware is being used mainly for advertising fraud," says Douglas Hunter Google versus Ad Age . The website received a unique insight into the workings of the secret unit, whose existence has not been made ​​public by Google.

Malware

To combat fraud, the ad team analyzes all kinds of malware, which include Google through the online virus scan service VirusTotal receives. By analyzing the malware a click fraud botnet can be mapped. Then look at the traffic that generates the malware. Traffic which malware authors try to make it look as human as possible.

In the Google case "non-human" traffic will encounter the publisher ads showing not paid and the advertiser is no fee will be charged. By now inspire to step outside Google hopes other companies to share their findings and to tackle together ad fraud."Our job is to increase the cost for the fraudsters to a point that advertising fraud no longer interesting for them," concludes De Jager.

Google Loopholes In Using Secret Question


Using only a secret question to reset a forgotten password is unsafe and should be avoided, as Google sets on the basis of own research ( pdf ). Many sites still use the secret question as a way for users to access their account if they have forgotten the login details. The problem of the secret question is that attackers can try to guess the answer and so to reset the password.

Thus, an attacker with the secret question of English users "what is your favorite meal" 19.7% chance to guess which one time. The answer is "pizza". With ten attempts an attacker 24% chance the question "what is the name of your first teacher" to answer in Arabic speaking users. With the same number of attempts an attacker 21% chance the question of Spanish speakers, "What is your father's middle name," to answer. In the case of Koreans make ten attempts a success rate of 39% on the question "what city were you born" and 43% with the question of what is the favorite food.


It also showed that many users had identical answers to secret questions which are believed to be correct very safe, such as "what is your phone number" and "what is your airmiles number". In this case it was found that 37% of people intentionally wrong information by filling out the idea that this makes the answer more difficult to guess. The research, which Google hundreds of millions of secret questions and answers analyzed, also shows that 40% of English speaking users the answer to the secret question no longer know if they have to fill.

Unfit

According to the researchers, the study shows that the secret question really is unfit to reset passwords and websites as well as users should think carefully whether they want to use secret questions. Google says that the secret question not be used as a standalone way to reset passwords. Furthermore, should website owners use other authentication methods, such as SMS codes or a second email address. "That is both safer and easier to use," concludes Elie Bursztein Google.

NSA Wanted To Infect Android Users On Google App Store


The US National Security Agency has set up a project in the past which attempted to infect users of the Google Play Store and Samsung App Store with spyware, according to documents from whistleblower Edward Snowden of late 2011 and early 2012 date.

According to the documents sought the NSA and British, Canadian, New Zealand and Australian intelligence agencies to find ways to attack smartphone users. Through the previously disclosed XKEYSCORE system smartphone traffic was identified.Through another project that had looked into development of the connection from the user to the aforementioned app stores was to hijack so that could then be controlled via a man-in-the-middle attack malignant "implants" to the smartphone .


In this way the intelligence services could monitor the target then. In addition to using the app stores as a springboard for the spread of spyware intelligence also sought ways to hijack them and spread misinformation among targets. Also wanted the intelligence to access the app store servers so that they could gather information about users, so notify the intercept and CBC News .

UC Browser


The documents also show that the intelligence services had discovered vulnerabilities in UC Browser, an immensely popular browser in Asia, and particularly China and India. Worldwide, 500 million people would use the program. The browser was found to leak all kinds of information over the phone. Information used by the intelligence services too. Canadian CitizenLab UC Browser has studied because the documents in April and discovered numerous vulnerabilities, which have now been remedied through an update. Google declined to comment on the findings and Samsung has given no substantive response.

Full Document Report

Thursday, 21 May 2015

Private Data On Your Android Smartphone After Reset Not Go Away


Owners of an Android smartphone to factory reset the device, called 'factory reset', run the risk of private information are still to recover and attackers can even take over the Gmail account. Researchers at Cambridge University bought 21 second Android smartphones from five different manufacturers, with Android versions 2.3 to 4.3.

Of knew all devices with the factory reset the investigators had failed to retrieve the "Google master cookie", which it is possible to log into the Gmail account of the previous owner. E-mails and chat conversations were recovered and tokens for different apps like Facebook. Full disk encryption can solve the problem, but the researchers discovered that a failed factory reset leave enough data to recover the encryption key.

The reasons that resetting failed, according to the researchers, complex and are caused by errors in Android itself, the upgrade process of the supplier and poor integration and testing by the supplier. The problem is particularly acute among older phones and the phones of Google itself perform better than OEM suppliers. Yet it is a big problem, the researchers said."Finding out information on units sold is a growing threat, now more users buy used equipment."

Sales of appliances is in fact important for manufacturers because more people buy new models as they know they can resell later. If it appears that data on these devices are to figure this could distort the market growth. In their report ( pdf ), the researchers make several recommendations that may apply manufacturers. They also call for further research, where it is checked whether manufacturers have improved the situation on the basis of the present report.

Adblock Plus Launches Its Own Browser For Android


The makers Adblock Plus , the popular browser extension on the Internet, launched its own browser for Android that ad blocking is central. Through Adblock Plus can block Internet ads. According to the developers, the add-on downloaded over 300 million times. If we look at the statistics of active daily users would look about 20 million Firefox users and over 10 million users use Chrome extension.

In the past, Adblock Plus created an extension for Android users, but Google has removed from the Google Play Store, because the add-on products or services other influences. By not being available in app stores is very difficult to reach mobile users, thereby fail not of existence. Additionally Adblock Plus for Android could only block ads on HTTP. In recent months, developers have therefore been working on its own mobile browser that integrates ad blocking.

Today is the first beta version of the browser released. The browser is open source and based on Firefox. The reason is that the Adblock Plus developers Mozilla as a project and as a company really admire. "Firefox for Android is a great mobile browser," so they claim. Most users would not know it, but the browser supports numerous extensions, including Adblock Plus. "Unlike Firefox on the desktop, we are very limited when it comes to integrating Adblock Plus in the user interface of Firefox for Android."

By developing its own browser have to integrate the developers more freedom to adblocking as basic feature that is both understandable and easy to configure. The developers say that they have big plans for the future. So we look to combine the Adblock browser and desktop browser users in a meaningful way. So far the mobile browser now gets all the attention and Internet recalled that test. According to the website of the Adblock Browser comes soon a version for iOS.

New Encryption Leak Threatens Web Servers And Mail Servers



A well-known cryptography professor has discovered a vulnerability in TLS encrypted connections allowing attackers to web and mail servers to attacks and eavesdropping. The vulnerability by Matthew Green " logjam "named and located in the Diffie-Hellman key exchange , a cryptographic algorithm that Internet protocols can establish an encrypted connection. It is essential for various protocols, including HTTPS, SSH, IPsec, SMTPS and protocols that rely on TLS.

Through the logjam attack attacker can, located between the victim and the Internet is vulnerable TLS connections to a 512-bit encryption downgrade. This allows an attacker to decrypt all the data on the encrypted connection and thus read and adjust. The vulnerability is similar to the FREAK-attack which was unveiled in March. Both vulnerabilities are caused by the US export policy in the early 1990s, making strong encryption could not be exported. Instead, if there is only "export-grade" encryption provided. The encryption keys were allowed in this case only 512 bits in size. However, the logjam-attack is focused on the exchange of keys via the Diffie-Hellman algorithm in place of the RSA-algorithm.

The attack affects all servers that Diffie-Hellman "export" encryption support. According to Green, all modern browsers and 8.4% of the 1 million most visited websites on the Internet vulnerable. The researchers experimented with attacking the most common primes 512-bit Diffie-Hellman used to exchange keys and were thus 80% of the servers with Diffie-Hellman "export" encryption downgrade. An intelligence could crack a 1024-bit prime and thus tapping 18% of encrypted connections from the 1 million most visited websites. Cracking a second prime number would make it possible to monitor 66% of VPN servers and 26% of the SSH servers.

Owners of a mail server or Web server are advised to disable the support of export encryption and generate a unique 2048-bit Diffie Hellman Group. Internet users should install the updates for their browsers as they become available. All suppliers are now working on an update. Finally get the advice to system administrators and developers to ensure that TLS libraries up-to-date and Diffie-Hellman Groups are refused less than 1024 bit.

Millions Of Routers Vulnerable To Criticism NetUSB Leak


A critical vulnerability in a component that "USB over IP" functionality to routers offers ensures that millions of routers at risk. Before warns security firm SEC Consult . The vulnerability is present in the NetUSB software of the Taiwanese Kcodes.

NetUSB via USB devices such as printers, external hard drives and USB sticks that are connected to a Linux-based embedded system, such as a router or access point, are accessible via the network. For this load a Linux kernel driver that starts a server on port 20005. Standard was the feature on all devices examined on SEC Consult.

Using the vulnerability, an unauthenticated attacker got on the local network to cause a buffer overflow resulting in a Denial of Service or in the worst case, the execution of arbitrary code. In some devices, it is also possible for a remote attacker to execute arbitrary code and thus take over the device.

The problem is a large number of manufacturers, including Netgear, TP-Link, Zyxel and D-Link and probably Western Digital, and Sitecom TRENDnet. The complete list of manufacturers in the advisory to find. Users are advised to install new firmware, if available. Other solutions are blocking port 20005, or disable "USB device sharing".

Wednesday, 20 May 2015

Digital Attacks On Oil Traders Without Malware


Researchers from the Spanish anti-virus company Panda Security discovered a digital attack on oil traders with no malware was used and the traders also were not the ultimate target. The attack starts with an executable file that looks like a PDF document.

In reality, it is a self-extracting archive file with several files, including various scripts, batch files and .exe files. Yet these files themselves are not malicious. "These are all legitimate applications that anyone can use," the researchers said that the threat of "The Phantom Menace" ( pdf call). The applications are created to store user names and passwords in the e-mailcient and browser in a text file and send it via FTP.

On the FTP server of the attackers, the researchers discovered more than 80,000 text files. It turned out to be files from ten companies in the oil sector. However, these companies were not the ultimate target. These are namely oil buyers. And especially oil buyers seeking special oil from the Nigerian city of Bonny. This oil is very popular because of its composition.In Nigeria holds the Nigerian National Petroleum Corporation (NNPC) on each transaction oil supervision.

Anyone who wants to sell in Nigeria oil must also be registered with the NNPC. Fraudsters operating in this market approaching traders and brokers and, for example offer a large amount of oil from Bonny at a very attractive rate. The potential buyer requests for documents that the product also exists. For this, several documents can be issued by the NNPC.

To use to inform the buyers on the scammers legitimate documents they captured at the previously attacked oil traders. Then the buyer will see this document and pay a deposit, for example, 50,000 to 100,000 dollars, but gets its oil never see.Eventually Panda Security was able to trace the possible culprit behind the attacks. The problem is that none of the attacked oil traders will report it, for fear of damage to reputation and the fact that they themselves have become a victim. This allows the police can not start investigation and the alleged perpetrator is still at large.

US Bank Reset Passwords After DNS Attack


Attackers are there in late April failed to adjust the DNS settings of a website of a US bank, allowing visitors to a malicious website were redirected where possible their credentials stolen. The attack was directed against the Federal Reserve Bank of St. Louis.

The attackers modified the IP address of the subdomain research.stlouisfed.org , pointing normal to a research site.Through the research site can all kinds of economic data and research information is requested. Of users on 24 April this year on the website tried to log on possible stolen the data, so the bench late in a warning to know which IT journalist Brian Krebs features. Across from CNBC , the bank confirmed the attack. Because of the potential data theft, the bank reset the passwords of all users. How the attackers were able to change the DNS settings is not known.

Safari Flaw Allows Malware And Phishing Attacks Possible



A vulnerability in Safari allows you to execute malware and phishing attacks. The vulnerability can any URL displayed in the address bar, while another site is loaded. The vulnerability was revealed by the UK security Deusen.

As evidence it put a proof-of-concept online. This test looks like the website of the Daily Mail is open, while this is not so."While this proof-of-concept is not perfect, it can be certainly improved and is then very easy to use for phishing attacks," said Manuel Humberto Santander Pelaez of the Internet Storm Center . The attack may not work if cookies only from the currently open website are allowed.

Infected Version Of PuTTY Steals Passwords


Cyber criminals are spreading on the Internet an infectious variant of the popular SSH client PuTTY, which is designed to steal passwords. PuTTY is a free open source terminal emulator application as a client for SSH, Telnet, rlogin, and raw TCP protocols can serve.

The now discovered version is not on the official PuTTY download site spreads, but via a hacked another page. The infected version would have been the end of 2013 and then already been distributed over the Internet. Recently, anti-virus company Symantec observed more infections. The infection starts with a user searching through a search engine to PuTTY.

Instead of choosing the official website, the user selects a hacked website. The hacked website sends the user several times and let him finally downloading an infected version. When the user logs in via the infected version on a system, the login information can be sent to the attacker. Users also are advised to check that they only download software from the official website of the supplier or developer.