Thursday, 24 September 2015

HP Laser Printers Protects Against BIOS Attacks


Computer manufacturer HP has three new laser printers announced which security (pdf) that enable attacks to be prevented in the BIOS of the printer. The BIOS (Basic Input / Output System) is a set of basic instructions for communication between the operating system and printer hardware.

It is essential for the operation of the printer, and also the first major software that is loaded. Attacks on the BIOS are difficult to detect and may give attackers longer period of time access to a device. Printers run while also risk of being attacked. Many corporate networks are printers on the network accessible. The security of the network printer is often forgotten, so that the devices can serve as input for attackers.

To protect printers, HP has therefore implemented various security measures. This involves HP Sure Start, a measure that can recognize malicious BIOS attacks and recover. This protection was already present in the Elite line of HP computers, but has now also been added to the printers. Furthermore, it is whitelisting used only known allowable firmware to install the printer and there is "Run-time Intrusion Detection" which monitors the printer memory for malicious attacks.

The three new security measures are standard in the Enterprise LaserJet printers and OfficeJet printers with HP Enterprise X Page Wide Technology. In addition to the features through a firmware update on several HP LaserJet Enterprise printers installed that are available since April. Furthermore, whitelisting and Run-time Intrusion Detection are added to HP LaserJet and OfficeJet printers Enterprise Enterprise X printers since 2011. For this, an HP FutureSmart service pack update must be installed.

Wednesday, 23 September 2015

Gmail Lets Users Email Addresses Block


A new feature in Gmail makes it now possible for users to block mail from specific email addresses. According to Sri Harsha Somanchi Google must give the new feature users more control over their inbox, for example if they are harassed by e-mail .

In case a user specific email address block the e-mail sender will be automatically placed in the spam folder. The option is now available to Gmail users and will appear next week for Android. In addition, Android users will soon have the option to unsubscribe simply from the Gmail app for newsletters.

Mozilla Patches Numerous Leaks In Firefox 41


Mozilla has released a new version of Firefox where 27 vulnerabilities patched. Through six vulnerabilities an attacker without much interaction from a user his or her system in the worst case can take over completely. This would require visiting a hacked or malicious Web site or see getting an infected ad suffice.

In Firefox 41 are further resolved numerous other bugs and added new features. One of the new additions to the browser is perfect forward secrecy for WebRTC. WebRTC is an open source project developed by Google which provides browsers with Real-Time Communications (RTC). To the communications from users secure for applications and applications that WebRTC now use perfect forward secrecy required.

PFS at each session to generate a separate key and removed after the end of the session or sending a message. In the case attackers the encryption key compromise, they do not yet have access to the previously stored messages (sessions) of users, as these are generated using a separate derived key. WebRTC, according to critics, a privacy risk because the information users can leak. Updating to Firefox 41 via the automatic update feature of the browser, Mozilla.org.

Forbes.com Spread Malware Via Infected Adverts


On the very popular website of business magazine Forbes have been infected for some time ads shown to infect visitors with malware tried. Forbes.com state according to market researcher Alexa on the 74th spot of most visited websites in the United States and the 154th place worldwide.

The website is monthly by more than 31 million visited visitors. Those visitors were from 8 to 15 September dished ads so they were undetected to a website with the Angler- and Neutrino-exploit kits. This exploit kits exploit known vulnerabilities include Adobe Flash Player. In case there is no up-to-date software was used silently malware could be installed on the computer, says security firm FireEye.

For what exactly will the malware was not disclosed. The ads were via an advertising service from a third party displayed on the Forbes website. According FireEye use of contaminated advertising remains a popular attack method for criminals.Via advertising platforms, especially those that hold real-time auctions for ad space, attackers can choose exactly where their malicious content is displayed.

In case the infected appear ads on popular websites the chance of massive infection is significantly increased, allowing both users and businesses at risk, according to the security company. After being informed Forbes has removed the infected ads. Last year, even though malware via Forbes.com spread. When attackers used a widget on the website that zero-day vulnerabilities in Internet Explorer and Adobe Flash Player attacked.

Snowden: Encryption Can Hinder Contact With Aliens


Although he is a strong supporter of encrypted communications, the use of encryption make it difficult to capture extraterrestrial signals and communications, says whistleblower Edward Snowden. Snowden recently appeared on Star Talk, the radio show astrophysicist Neil DeGrasse Tyson, who last year with Cosmos: A Space Odyssey Time had a popular television series about the cosmos.

During the interview Snowden showed that extraterrestrial civilizations would encrypt their communications probably just like people do on earth. That could also be the reason that alien communication still not been collected. "If you're an alien civilization trying to listen to other civilizations or our civilization that listens to aliens, there is only a small stage in the development of their society, all of their communications sent via the most primitive and insecure ways," says the whistleblower.

After this, the default message will be encrypted and will not be recognized. According to Snowden could it be that we received extraterrestrial television shows or calls, but it does not differ from cosmic background radiation for us. We would have by not even in that case we hear extraterrestrial communications. "Assuming they not have the same security problems as we have," replied Tyson. The conversation went wide aliens on several other topics. The section on alien communication can be heard from 33:00 minutes.

Researchers: Thousands Infected Apps In App Store


In the Apple App Store have been infected thousands of apps and a number of infected apps is still offered, say researchers from the Chinese Pangu Team. They have an app developed to iOS users can check whether they have downloaded an infected app.

The infected apps with the XcodeGhost-malware become infected. The name refers to Xcode, Apple's official tool for developing apps for iOS or OS X. Several Chinese developers had an infected version of Xcode which also downloaded the apps they developed became infected. Last Friday, September 18th, Apple began with the removal of the infected apps. On Sunday, let Apple know that all known infected apps was removed.

Monday, however, showed that there are still familiar with XcodeGhost infected apps were in the App Store, says security company Palo Alto Networks. How many apps now have become infected is unclear. Palo Alto first suggested that they were 39. China's Qihoo 360 did a survey of 344 apps, while Pangu Team says the 3418 infected apps have been identified. The researchers say that the actual number is much higher. In addition, not all infected apps from the App Store removed.

In previous posts Palo Alto Networks said that the malware was able to carry out phishing attacks on users by showing warning windows where people than their passwords might fill. This appears to be wrong afterwards. Today's malware is there not capable, but can be easily modified to do this.

Advice

In addition to turning the Pangu Team app and remove any found infected apps, users can also have two-factor authentication as an additional layer of security set, so advises Palo Alto Networks. Furthermore, app developers are advised to download development tools only through the official provider. Xcode should therefore only through the Apple website to download and no other location. Also need developers during development Gatekeeper protect their OS X machine set at the default level. Finally app developers are advised to check the integrity of their development tools and libraries before they release a new version of the app.

Swiss Government Warns Of Contaminated Ads


The Computer Emergency Response Team (CERT) of the Swiss government has warned Internet users to infected ads that tried to install a Trojan horse. The ads were distributed through a popular Swiss ad network was hacked.

The ads were equipped with malicious code that abuse of known vulnerabilities in Internet Explorer, Firefox, made Java or Adobe Flash Player. In case users this software were not up to date and had a German or French institution, the Gozi Trojan was installed. This is a Trojan specifically designed to steal money from online bank accounts. The version that was spreading through the ads focused on five Swiss and two Thai sofas.

According to the Swiss CERT are potentially hundreds of thousands of Internet users become infected through contaminated ads. Last Friday, the owner of the botnet suddenly decided to remove the malware. All the infected computers were instructed to uninstall the Trojan horse. The reason is unclear, according to the CERT. The government organization thinks the botnet administrator may have earned enough money or that he saw the CERT operation had been discovered and therefore decided to disable the botnet.

Ransomware: US County Pays Ransom



The IT department of Miami County in the US state of Ohio has on the advice of a security $ 700 paid to the creators of CryptoWall-ransomware so the county encrypted files recovered. Early September was faced by the county with an infection.

The administrative computer system of the communication was via e-mail gets infected by the ransomware said Troy Daily News. This center is also responsible for the 911 emergency service in the county, but the network of these became infected. The ransomware early $ 700 in bitcoins, which Miami County on the board finally paid advised by a security expert. According to the expert would be the retrieval of the encrypted document in this way be cheaper and faster, reports Dayton Daily News.

Malware On Google Play Infected 200 000 Android Devices



Criminals have managed to place two infected apps on Google Play downloaded between 200,000 and 1 million times. These are two versions of an app called Brain Test. Once users have downloaded the app which tried four different exploits to gain root access. In case this was managed persistent malware installed posing as a system module.

Then the app installed additional applications on the infected machine. In order to prevent removal Brain Test uses two system applications in order to monitor the removal of one of the components. Once one of the parts is removed, the second reinstallation. The malware was discovered by a user who deleted the infected app, but then saw how returning to the unit by itself again.

After being briefed by security company Check Point has one of the infected apps September 15 removed. The first version was removed from Google Play on August 24th. Android Users whose phone has been infected are advised to delete the app. In the case which comes back to the persistent system module is installed, which means that the operating system via an official ROM must be re-installed.

Business Lauds $ 1 Million For Zero-Day Vulnerability In iOS 9



A company that zero-day vulnerabilities from researchers buys and prepares them to government agencies and large enterprises to sell through has a reward of one million dollars promised for a zero-day vulnerability in iOS 9. This is a vulnerability that needs to be through the browser are attacked and the attacker gives permanent access to the iOS device.

There should be no further user interaction is required, except to visit the web page. In addition, researchers get paid even if the attack can be performed via SMS or MMS. Zerodium, as the company is called, says that the vulnerability should be exclusive. In its own text with the requirement for zero-day talk of an "untethered jailbreak", but according to security expert Robert Graham, this is a red herring because it Zerodium not a jailbreak to do.

"A 'browser-based jailbreak is the same as a browser-based zero day", says Graham. According to the expert, there is intelligence from a high demand for these types of vulnerabilities. Especially now, half of iPhone users now iOS 9 installed would intelligence lose access can get into the systems of targets. Unless they have a new zero-day attack, says Graham. Since Zerodium states that the zero-day vulnerability to be exclusive, he expects the company's vulnerability will then sell them to multiple parties.

Apple Patches Critical Vulnerabilities In Apple Watch


Apple has released a new version of watchOS, the operating system for Apple Watch, in which a large number of vulnerabilities has been resolved. Through two of the patched vulnerabilities could execute a malicious website arbitrary code on the smart watch.

Also, various other vulnerabilities made the execution of arbitrary code as possible, for example, in the processing of a malignant font. Furthermore, there is a problem solved in apple pay making a payment terminal could figure out some recent transaction data on a payment. Also, it was for an attacker having a "privileged network position" is possible to intercept SSL / TLS connections and to monitor the activities of the user.

A vulnerability in the "Core Crypto" could allow an attacker to determine the RSA private key of the user. In total, Apple has watchOS two 37 vulnerabilities patched. Updating via the Software Update feature of the operating system.

Tuesday, 22 September 2015

India Protects Online Banking And Social Media In Encryption Law



The Indian Government under pressure online banking, social media and online shopping a new encryption law excepted. Recently the Indian government published a draft version of the bill (pdf),where citizens and businesses to October 16 this year to respond.

The policy Indians required to store a decrypted version of encrypted data 90 days, and their visible for making intelligence services. There was a storm of criticism, because a large part of the internet presence of encryption use. For example, the popular chat app WhatsApp encrypts data, as well as banks for online banking. Therefore, there is now for this type of service made ​​an exception, reports the BBC.

The bill also proposes that service both within and outside India who use encryption must first sign an agreement with the Indian government before they are allowed to offer such services in India. In addition, the bill states that the Indian government will prescribe the allowable encryption algorithms and key lengths.

According Pranesh Prakash, director of the Center for Internet and Society in Bangalore, the proposal is a bad idea coming from people who do not understand encryption. He also finds it strange that the bill not "sensitive government" applies. "What the government should do is to establish minimum encryption standards for government use, but here the opposite happens," said Prakash across the India Times.