Monday, 30 November 2015

British Woman For 2.3 Million Euros Ripped Through Dating Scam


In Britain, a woman for 2.3 million euros ripped through a dating scam. The woman met on a dating site a man posing as a wealthy engineer. After the man's wife had built a relationship she was asked during a period of 10 months for various loans. Eventually she made about 1.6 million pounds, converted 2.3 million.

Two of the gang members were sentenced last week. According to the British police in the past year 100 victims of dating fraud analyzed taking internet scammers managed to steal a total of 5.7 million euros. In addition, people walk not only on dating sites risk. Recently, a British woman approached via Skype and eventually ripped off for 360 000 euros.

British police advises Internet users who are talking with potential partners over the internet to pierce pathetic stories, and not by just letting a photo fooled. Also, people can not send money to people abroad that they have not met or barely know. Continue to be drawn to the question of potential online partners in doubt. Many scammers give all sorts of compliments and ask many questions, but tell little about himself.

Sunday, 29 November 2015

NSA Stopped Mass Storage Phone Data


US intelligence NSA has stopped the massive storage of telephone data, so reporting news agency Reuters, CNN and the intercept. In June, President Barack Obama decided to implement various reform measures and to limit the powers of the NSA.

So the Secret Service should not collect unfocused phone records of US citizens. Instead, the NSA will now have to be more focused work, in which first a court order is required, after which telecom operators may be asked to keep phone records of certain people or groups of people for a maximum period of six months.

The measure is a victory for privacy advocates and saw Edward Snowden, who felt that the NSA had this much power to spy on citizens. However, the NSA has asked the court to be allowed to continue using the data stored to date to February 29, 2016 on a limited scale. The judge must still here a judgment on it.

Major Security Flaws In Hacked Toy Manufacturer VTech


The Chinese manufacturer of educational toys VTech where recently the data of 4.8 million adults and 200,000 children were stolen customer data had not properly secured, according to the Australian security expert Troy Hunt that captured customer data analyzed.

Recently managed to get an attacker access to the customer database and approached Vice Magazine. The journalist of the magazine then contacted Hunt to verify the data. Hunt was sent several files, the largest of which was 1,7GB. This file, called parent.csv, he found the details of 4.8 million people. It was e-mail addresses, names, IP address, mailing address and encrypted passwords. The password proved to be hashed with the MD5 algorithm. It is therefore not directly readable, but MD5 has long been considered unsafe because it is easy to 'crack'. This allows an attacker can still retrieve the password.

VTech had not taken additional measures to protect the passwords, such as the use of "salts" and "stretching". However, it is not the only security problem, says Hunt. As the website does not use SSL, so all communications, including passwords, unencrypted occurs. There is no cryptographic protection of sensitive data, the expert noted. The website appears to provide a SQL statement back at login. The attacker said that he had come in via SQL injection, a problem that has been known since 1998 but is ignored by some companies still. Finally Hunt criticizes the extensive use of Flash on the website of VTech.

The expert also manages the website Have I Been Pwned, where Internet users can check whether they appear in the database of hacked websites. The data of the 4.8 million adults from the database of VTech here are now added. That does not apply to the data of 227 000 children who also were in the stolen data. Hunt has not been added. VTech has confirmed a burglary, but do not know how the attacker managed to get inside.

Saturday, 28 November 2015

Criminals Copy Debit Cards Via Stereo Skimming


The past quarter have criminals in a European country copied via stereo skimming debit cards, reports the European ATM Security Team (EAST), an organization that maps fraud with payment terminals. EAST receives data from a large number of countries.

It is the first time that the organization receives notification to stereo-skimming successfully applied. In traditional skimming criminals copy the magnetic stripe of a debit card through a cross mouth placed on the ATM. In order to prevent skimming anti-skimming devices are used that emit a "jamming signal". In stereo skimming there are two headlines that read information from the magnetic strip and store it via audio technology. The first reading head strikes the jamming signal and map data, while the second read head only stores the jamming signal. Due to the one of the other subtracting remain on the map data.

Thanks to MP3 technology, this method would again make a comeback, according to InformationWeek. The technique in the past, has been used once before. In 2013 a simple stereo-skimming device was an Irish ATM discovered. In late September of this year reported security TMD Security that it had found new stereo-skimming technology in Ireland. The device would be based on existing stereo-skimming technology, but use sophisticated new technologies allowing the jamming signal be neutralized.

EAST late in the present report do not know to which country it is where the message came from, but Ireland is one of the countries that provide data to the organization. However, it still seems to be a novelty, since 17 countries reported the traditional skimming of debit cards. Also made ​​one country reported criminals who had downloaded via malware money from an ATM, and also became a 'black box attack reports', where criminals connect a personal device on the ATM and the machine so give commands to money through the issuance channel off to give.

Leak VPN Providers Can Reveal IP Address Users


A vulnerability in some VPN providers can ensure that the real IP address of users is revealed, warns VPN provider Perfect Privacy. A VPN (Virtual Private Network) is a secure connection between a computer and a server elsewhere on the Internet.

This connection is encrypted which others can not observe. All Internet traffic to and from the computer goes through this route shielded and can on this part will not be overheard. Additionally, VPN users can thus protect their IP address as websites visited only see the IP address of the VPN provider. According Perfect Privacy walk users of some VPN providers still risk their real IP address is known.

Port forwarding

The problem is with VPN providers offering port forwarding. It does not matter whether users of the VPN providers themselves use port forwarding, only the attacker must set it. To determine the IP address of a victim, there must be fulfilled several conditions. For example, the attacker must have an active account with the same VPN provider and the victim. The attacker must know the 'exit' IP address of the victim and the victim to open a file or page.

An attacker who port forwarding is activated can then request to see the image or website which the real IP address of the victim is from. In total, nine tested Perfect Privacy VPN providers, of which five were found vulnerable. These parties have been notified. The problem, however, with other VPN providers are not tested, warns Perfect Privacy.

BitTorrent

According to security expert Darren Martyn can leak be used to expose BitTorrent users who illegally download copyrighted material. To shield their IP address are BitTorrent users who use a VPN service. By leak holders can still see the IP addresses of illegal downloaders. Martyn expects that companies connected with suing copyright infringers concerned will use this vulnerability to sue BitTorrent users.

Hacked Site Reader's Digest Spread Malware


Attackers have managed to hack the website of Reader's Digest and use this now to spread malware. Before that anti-malware company cautions Malwarebytes. According to the company, there is an increase in the number of hacked WordPress websites and Reader's Digest is one of them.


On the hacked websites is placed code that visitors unnoticed to a page with the Angler-exploitkit forward. This exploitkit is using known vulnerabilities in Adobe Flash Player and Internet Explorer users have not patched. In case the attack is being installed Bedep Trojan on the computer successfully, which can install additional malware again.

Reader's Digest was a few days ago warned by Malwarebytes, but the security company and got no response when a blog posting about the infection appeared online yesterday distributed the website still malware.

Registry Hack Windows Defender Will Change To "Adware-Killer '


Yesterday, Microsoft announced that it is the business security of a new feature has provided thus also potentially unwanted software and adware are stopped, but via a small adjustment to the registry, this function can also be activated by consumers.

It reports the German Heise Online. Under potentially unwanted software called Microsoft understands software bundles containing adware, toolbars and other unwanted programs. To protect against organizations here, the software giant's business solution System Center Endpoint Protection (SCEP) and Forefront Endpoint Protection (FEP) with a new opt-in feature. In conjunction with Windows Defender can therefore download and install unwanted software are blocked.

The feature is not exclusive to business environments. Due to a change in the registry which is namely also available for common Windows systems. According to Heise Online is the function to stop adware not only added to SCEP and FEP, as well as Windows Defender, which is present in all Windows versions since Windows 8. In a test by the German IT magazine shows Windows Defender after the adjustment indeed unwanted software such as blocking Freemake Video Converter. The test was performed on the Home and Pro version of Windows 10.

To make the adjustment must be set below in bold text in a text file, which then the file extension from .txt to be changed in reg. Then the file must be opened and the register adjustment is made.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows Defender \ MpEngine] "MpEnablePus" = dword: 00000001

Friday, 27 November 2015

Microsoft Protects Companies From Unwanted Software


Microsoft has the business security of a new feature provided in order to protect businesses and organizations from potentially unwanted software. It involves, for example so-called software bundles containing adware, toolbars and other unwanted programs.

According to the software giant this program may increase the risk of getting infected corporate networks with malware or make it harder to identify malware infections. It would also burden the helpdesks and time consuming to remove the applications. To protect corporate users from this kind of software security solutions System Center Endpoint Protection (SCEP) and Forefront Endpoint Protection (FEP) with a new opt-in feature rich, so Microsoft through a blog posting disclosed.

The feature can detect potentially unwanted programs and stop, so they are not downloaded or installed. Microsoft claims that the blocking of such software should be an explicit choice, and companies are wise to do to set policy on here. Even end users should be alerted in this case, so they know that potentially unwanted programs are not allowed in the operating environment and will block the security products such software.

FBI Warns Online Shoppers To Online Fraud


The FBI has the festive arrival of online shoppers for Internet fraud warning, as offers that are too good to be true. According to the police for criminals prepare themselves for the holidays and will try through creative scams to steal both money and private information.

Thus, Internet users are advised to not fall into offers that seem too good to be true. Also should be avoided websites that offer high discounts. Consumers should also pay attention to social media and installing smartphone apps, according to the FBI. Before an app downloaded from an unknown source users must first read reviews. In addition, some apps pose as game and are offered free, but in reality, trying to steal all kinds of personal information.

In addition to the FBI, the Computer Emergency Readiness Team of the US Government (US-CERT) Internet phishing, malware and other scams during the holidays warned. This will include recommended to purchase online to pay by credit card because it provides extra protection. Also, all online transactions should be printed before the arrive purchased products.

EFF Wants Stronger Encryption Against Terrorists And Criminals



If the government were to ask people to remove the good locks on their doors and windows and replacing them worse so that government employees can penetrate more easily in case someone is a terrorist, no one would accept this because bad locks make everyone vulnerable.

Yet this is exactly what governments and law enforcement agencies in the case of encryption will, according to the American civil rights movement EFF. Regularly advocate agencies like the FBI to add backdoors in encryption, ensuring encrypted communication can still be tapped. This is similar to prevent people from getting access to good locks and locksmiths can produce good locks.

In this last example, most people would understand that this is not a wise idea, says Cindy Cohn of the EFF. However, when it comes to Internet and technology, such as the operation of encoding, which for many people is less clear. Parties such as the FBI and politicians would also have known better, says Cohn. "The answer to insecure networks and digital technologies must be correct in order to make them safer."

But that is not what is happening, so she continues. Policymakers are therefore urged to take this into account. "Ensuring that everyone's door is unlocked, is not the answer to crime or terrorism. That is the development and support of better security," Cohn decision.

Ransomware Irritates Users Via Audio Message



Besides which also ransomware encrypts files or computers locking is ransomware that attacks only the browser, and a new variant users try a different way to force them to pay. The browser ransomware pretends to be "Microsoft Official Support".


A pop-up ransomware users to believe that there are problems with the computer and a phone number to be called. In addition, an audio message will be repeated continuously which states that there are viruses and adware on the computer are available and the specified number to be called to remove them. If users try to close the pop-up will open a new pop-up.

Unlike ransomware that encrypts or locks the computer files, browser-ransomware is easy to solve. Users can close the browser using the Task Manager, which is also browser-ransomware disappears. Security firm RSA says that despite the simplicity of the solution, this ransomware focuses on users who have no knowledge of this type of threat or know how they can remedy via Task Manager, and finally call the telephone number provided. This number is then the victim of scam artists who try to light up.

FBI Suspect In Case Of 1.2 billion Stolen Logins


The FBI has a suspect in the case of 1.2 billion stolen usernames and passwords. Last August announced the US firm Hold Security that it had uncovered a gang that through SQL-injection 1.2 billion unique passwords had been stolen at about 420,000 websites.

Research documents from the FBI show that the investigation service has found an email address that may be involved in the theft. The email address was registered in 2010 and was one of "mister gray" who offered his spam services. As part of the investigation, the FBI discovered on a Russian hacking forum a message from one "mr.grey" which in 2011 the login details of Facebook, Twitter and UK users offered. The information comes from a request from the FBI last year submitted to search e-mail and data last week has become public and which news agency Reuters on message. Further details about the state of research are lacking.