Although it’s probably not something that concerns most of us, some individuals are worried that there’s an inherent flaw in the upcoming iPhone 5S’s fingerprint authentication system: a thief could potentially sever your finger and use the appendage to unlock the device. Once inside, they could access protected third party apps and potentially break into one’s bank account.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Wednesday, September 18, 2013
Thieves won't be able to sever your finger to unlock the iPhone 5S
Although it’s probably not something that concerns most of us, some individuals are worried that there’s an inherent flaw in the upcoming iPhone 5S’s fingerprint authentication system: a thief could potentially sever your finger and use the appendage to unlock the device. Once inside, they could access protected third party apps and potentially break into one’s bank account.
Tuesday, July 31, 2012
Ubisoft Uplay DRM security hole exposed, promptly fixed
Ubisoft’s always-on DRM mechanisms have been a point among a majority of gamers who feel they are a hassle to paying customers and ineffective at thwarting pirates. Well, it appears that even more worrisome side-effects are possible too, with the revelation that installing the company's UPlay game management system can open up your computer to malicious code insertion through the web browser.
The flaw was disclosed by Google security engineer Tavis Ormandy this morning, who noted that a browser plugin installed alongside Uplay, meant to launch locally-stored games from the web, doesn't have a filter for what websites can use it. This essentially left an open door on thousands of machines that can be exploited via a maliciously crafted web page.
Ormandy posted a few lines of JavaScript code as a tentative proof of concept. The story later made it onto Hacker News and so did a working implementation of the proof of concept that launched the built-in calculator in Windows. The code was confirmed to work on a Windows 7 PC with Assassin's Creed and Firefox installed.
Ubisoft has since released an update for their browser plug-in (found in over 20 different titles) to address the issue. You can also disable the plug-in altogether in your browser settings. Below is the company’s official statement and the full list of games that install the plug-in in question:
“We have made a forced patch to correct the flaw in the browser plug-in for the Uplay PC application that was brought to our attention earlier today. We recommend that all Uplay users update their Uplay PC application without a Web browser open. This will allow the plug-in to update correctly. An updated version of the Uplay PC installer with the patch also is available from Uplay.com.
Ubisoft takes security issues very seriously, and we will continue to monitor all reports of vulnerabilities within our software and take swift action to resolve such issues.”
List of Uplay enabled games
- Assassin’s Creed II
- Assassin’s Creed: Brotherhood
- Assassin’s Creed: Project Legacy
- Assassin’s Creed Revelations
- Assassin’s Creed III
- Beowulf: The Game
- Brothers in Arms: Furious 4
- Call of Juarez: The Cartel
- Driver: San Francisco
- Heroes of Might and Magic VI
- Just Dance 3
- Prince of Persia: The Forgotten Sands
- Pure Football
- R.U.S.E.
- Shaun White Skateboarding
- Silent Hunter 5: Battle of the Atlantic
- The Settlers 7: Paths to a Kingdom
- Tom Clancy’s H.A.W.X. 2
- Tom Clancy’s Ghost Recon: Future Soldier
- Tom Clancy’s Splinter Cell: Conviction
- Your Shape: Fitness Evolved
Labels:
DRM,
Google security,
security,
Ubisoft,
uplay,
Windows 7 PC
Monday, July 30, 2012
Apple to talk iOS security at Black Hat 2012 conference
Apple is set to make its first official appearance at the security-focused Black Hat conference this year. The move is both surprising given the company’s tradition of avoiding most major technology conferences, and significant as their products have become a bigger target for hackers in recent times.
Apple hasn’t made an official announcement yet and declined to comment on rumors, but Black Hat’s general manager Trey Ford told Bloomberg that Apple's platform security team manager Dallas De Atley is scheduled to give a presentation on key security technologies within the iOS platform.
Interestingly, Ford claims a panel of Apple insiders were originally scheduled to speak about the company's security-response team at Black Hat four years ago, but cancelled abruptly when Apple’s marketing department caught wind of it. “Bottom line — no one at Apple speaks without marketing approval,” he said, while confirming that this time around Apple marketing is on board for Black Hat 2012.
Microsoft security researchers first spoke at the conference in 1998 and the first time Google took the stage was in 2010. Now, under Tim Cook’s helm, it appears Apple is finally acknowledging the need to publicly engage with the community and discuss the security of its own platforms.
Earlier this year, the company was criticized for being to slow to respond to a Java flaw exploited by the Flashback Trojan, which ended up infecting more than 600,000 Macs between February and May. They were also in the spotlight recently over a simple hack that allowed iOS and Mac users to install premium in-app purchases from the App Store for free, which ultimately affected developers.
Friday, July 20, 2012
World's third largest spam botnet 'Grum' taken down
Security researchers announced they’ve dismantled the world's third-largest botnet, known as Grum, which is believed to have been responsible for 18% of the world's spam.
The shutdown was a joint effort between California security firm FireEye, the British-based Spamhaus Project, and the Russian-based Computer Security Incident Response Team known as CERT-GIB who worked together and convinced the companies that hosted Grum’s command and control servers to pull the plug on the operation.
Grum relies on two types of control servers: one to push configuration updates to the infected computers that are part of the botnet and another to tell the botnet what spam emails to send.
Initially researchers from FireEye were able to take down two command and control (CnC) servers hosted in the Netherlands of the second kind.
While this crippled the botnet’s operation, remaining CnC servers hosted in Russia, Panama, and a few in Ukraine that cropped up at the last minute in response to the previous shutdowns could still be used to update the botnet and direct it to new spam template servers.
Fortunately, that didn’t happen and yesterday Grum was dealt its final blow as folks in the worldwide security industry collaborated to apply pressure to local ISPs and domain registrars to shut down the remaining servers.
The researchers said the botnet had been using as many as 120,000 infected "zombie" computers to send out spam each day. More than 20,000 computers are apparently still spewing out junk email, but without the active CnCs they will soon be rendered ineffective.
Labels:
botnet,
command and control,
Computer Security,
grum,
russia,
security,
spam
Sunday, June 24, 2012
Flame virus created by U.S. and Israel sources say, Iran is target
The Washington Post reports that Flame, an extremely sophisticated virus which was first discovered in Iranian oil refineries, is the brainchild of U.S. and Israeli efforts to slow Iran's nuclear program. This information comes from several Western officials who purportedly have knowledge of the project, but wish to remain anonymous.
Despite the report's veiled sources, Flame's U.S. origins aren't necessarily a surprise. Earlier this month, the New York Times shed light uponOperation: Olympic Games, a U.S. project which utilized other sophisticated viruses known as Duquand Stuxnet. These virus targeted Iranian SCADA systems, allowing their creators to access, gather intelligence and even control certain aspects of Iran's nuclear and oil refining facilities.
Security researchers recently discovered Stuxnet code within Flame -- an unofficial confirmation that the creators of Stuxnet (i.e. U.S. government) were also behind the virus. After this discovery was made, the virus began to self-destruct, hastily removing itself from infected computers as though it were taking cues from a spy novel.
Flame wowed security researchers with its incredible sophistication. The 20MB virus carried a payload which could be transmitted through spoofing Windows Updates, allowing it to infect even non-compromised computers on the same network. The creators used what is believed to be an unknown MD5 collision attack to forge Microsoft's digital signature on a fraudulent certificate, an achievement which was described by security researchers as the holy grail of malware writers.
Flame also has modules which could utilize microphones and web cameras, log keystrokes, collect screen shots and allow it to propagate via removable media (i.e. USB thumb drives), allowing it to be introduced into sensitive networks isolated from the public. It would even use Bluetooth to send commands to other computers, providing a bevy of vectors for infecting, monitoring and controlling nearby workstations.
Labels:
Flame virus,
government,
hacking,
iran,
malware,
NSA,
security,
united states
Friday, June 22, 2012
Check your system for vulnerabilities using CVEChecker
The goal of cvechecker is to report about possible vulnerabilities on your system, by scanning the installed software and matching the results with the CVE database. Indeed, this is not a bullet-proof method and you will most likely have many false positives (vulnerability is fixed with a revision-release, but the tool isn’t able to detect the revision itself), yet it is still better than nothing, especially if you are running a distribution with little security coverage.
Still, the tool remains useful. With the proper reporting in place, you are immediately warned when a new CVE has been released that might match your system. You can then take the appropriate steps (acknowledge report, verify incident, fix package or mark as false positive).
The tool however needs your help as well. The most work is to tell cvechecker how to detect which software is installed and what version. For more information, see the cvechecker man-page.
Install required packages:
Code:
root@coresec:~# apt-get install libconfig8-dev libsqlite3-dev libxslt1-dev
Compilation Process:
root@coresec:~# tar -zxvf cvechecker-3.1.tar.gz root@coresec:~# cd cvechecker-3.1/ root@coresec:~/cvechecker-3.1# ./configure --enable-sqlite3 root@coresec:~/cvechecker-3.1# make root@coresec:~/cvechecker-3.1# make install
Initialize SQLite3 Database:
Code:
root@coresec:~/cvechecker-3.1# cvechecker -i
To pull the necessary data from the Internet:
Code:
root@coresec:~/cvechecker-3.1# pullcves pull Downloading nvdcve-2.0-2002.xml... ok Converting nvdcve-2.0-2002.xml to CSV... ok Loading in nvdcve-2.0-2002.csv in cvechecker. I am missing the index cveidx2. This is to be expected if this is the first run of cvechecker since an upgrade. I will now create cveidx2 for you, no further actions are needed. Some updates have occurred which might affect the database initialization. Please restart the command. Downloading nvdcve-2.0-2003.xml... ok Converting nvdcve-2.0-2003.xml to CSV... ok Loading in nvdcve-2.0-2003.csv in cvechecker. Loading CVE data from /usr/local/var/cvechecker/cache/nvdcve-2.0-2003.csv into database 100 records processed (0 already in db)... 200 records processed (0 already in db)... 300 records processed (0 already in db)... .....
Generate List of Files:
Code:
root@coresec:~/cvechecker-3.1# find / -type f -perm -o+x > scanlist.txt root@coresec:~/cvechecker-3.1# echo "/proc/version" >> scanlist.txt
Gather List of Installed Software/Versions:
Code:
root@coresec:~/cvechecker-3.1# cvechecker -b scanlist.txt Searching for known software titles... - Found match for /lib/libpthread-2.12.1.so: cpe:/a:gnu:glibc:2.12.1::: - Found match for /sbin/resize2fs: cpe:/a:ext2_filesystems_utilities:e2fsprogs:1.41.12::: - Found match for /sbin/mkfs.ext4: cpe:/a:ext2_filesystems_utilities:e2fsprogs:1.41.12::: - Found match for /sbin/iptables-save: cpe:/a:netfilter_core_team:iptables:1.4.4::: - Found match for /sbin/iptables-save: cpe:/a:netfilter_core_team:iptables:1.4.4::: .....
Output Matching CVE Entries:
Code:
root@coresec:~/cvechecker-3.1# cvechecker -r File "/bin/dbus-daemon" (CPE = cpe:/a:freedesktop:dbus:1.4.0:::) on host coresec (key coresec) Potential vulnerability found (CVE-2010-4352) Full vulnerability match (incl. edition/language) File "/bin/dbus-uuidgen" (CPE = cpe:/a:freedesktop:dbus:1.4.0:::) on host coresec (key coresec) Potential vulnerability found (CVE-2010-4352) Full vulnerability match (incl. edition/language) File "/usr/bin/dbus-launch" (CPE = cpe:/a:freedesktop:dbus:1.4.0:::) on host coresec (key coresec) Potential vulnerability found (CVE-2010-4352) Full vulnerability match (incl. edition/language) ......
Export to CSV format:
Code:
root@coresec:~/cvechecker-3.1# cvechecker -r -C
Documentation: http://cvechecker.sourceforge.net/documentation.html
Download: http://cvechecker.sourceforge.net/download.html
Download: http://cvechecker.sourceforge.net/download.html
Labels:
compile,
configure,
CVE,
cvechecker,
install,
Linux,
scanner,
security,
unix,
Update,
vulnerabilities / Add Comment
Google discovers over 9,500 new malicious sites per day
On its security blog today, Google shared some of the numbers behind its anti-malware and anti-phising efforts. In the post, the company touts its Safe Browsing API which is used by the likes of Safari, Firefox and Chrome and offers some interesting details regarding the types of attacks unscrupulous individuals use against unsuspecting web surfers.
Over the years, says Google, the company has learned a great deal from having to protect its own servers, users, webmasters and Internet service providers. This expertise has aided Google during the past five years in its fight against Internet evildoers, a self-ascribed duty which has been (and continues to be) a mostly proactive effort.
Google says it finds an average of 9,500 new malicious sites every day. The company also delivers several million warnings on a daily basis through its Safe Browsing API, an anti-malware and anti-phishing service which Chrome, Safari and Firefox use to warn their 600 million collective users of harmful websites. In that same amount of time, Google also hands out about 12-14 million warnings to users trawling through its search engine.
Through Google's partnership with StopBadware.org, the company also alerts thousands of webmasters every day regarding infected websites -- hackers frequently gain access to websites in order to insert malicious code into otherwise trustworthy websites and blogs.
Not surprisingly, the big G reports that malware and phishing attacks have grown in both numbers and sophistication. Malicious websites often have a short life -- less than an hour -- and periodically pop up under new, randomly generated domain names in order to avoid detection.
Even though the problem has grown and become a more international problem, web-based malware and phishing authors have also become better at targeting users with increasingly specific practices like spear phishing.
Interestingly, the origins of most phishing scams can be traced back to hosts in the U.S. and Brazil. Iran, Spain, Australia and Peru are amongst least active countries when it comes to playing host or falling victim to phishing attempts.
Tuesday, January 10, 2012
Chrome 17 beta brings speed and security improvements
Google has pushed a new version of Chrome into the beta channel that's designed around improving two of the browser's key aspects: speed and security. The first major change in version 17 is the ability for pages to start loading in the background before a user has even finished typing a URL into the Omnibox address and search bar.
"If the URL auto-completes to a site you're very likely to visit, Chrome will begin to prerender the page," explained Dominic Hamon, a software engineer at Google, while announcing the browser update. The pre-rendering makes the full site show up almost instantly, according to Google.
Google also introduced an extension to its Safe Browsing technology that protects users against malicious downloads by analysing executable files, including Windows .exe and .msi files, for known malware. Chrome will issue a warning if a certain file appears to be malicious and will also alert the user if a file is downloaded from a website with a poor reputation for hosting malware-infected files.
This protection targets the "social engineering" type of threat, such as the common fake anti-virus product being offered online, but it's still up to the user to proceed with the download or discard it. The database of known malware is relatively small for now but should grow rapidly as the feature moves into the stable release.
A number of other minor changes and the usual slew of bug fixes are also included in Chrome 17 beta. Additionally, Google updated the browser's Stable channel to version 16.0.912.75, closing three high risk security holes. Hit the links below to download the latest stable or beta versions of Chrome.
Israel likens hacker to terrorist for exposing 400,000 credit cards
Last week, a hacker known as "0xOmar" (also being mistakenly reported as OxOmar by most news media) took credit for publishing an illicit bounty of 400,000 credit card numbers, a claim yet to be fully corroborated by news agencies. On Friday, Israeli officials condemned the action as a form of terrorism and made a provocative claim that no hostile actor is immune to the country's potential retaliation.
Reuters reports:
Such cyber-attacks are "a breach of sovereignty comparable to a terrorist operation, and must be treated as such," Deputy Foreign Minister Danny Ayalon said in a speech, adding that Israel had not yet ruled out the possibility that the hacking had been carried out by a group "more organized and sophisticated ... than a lone youth."
"Israel has active capabilities for striking at those who are trying to harm it, and no agency or hacker will be immune from retaliatory action," he said, without elaborating.
The hacker claims 400,000 stolen credit card numbers were leaked but accuses the "Jewish lobby" ofdown-playing the total. The individual also claims he has over one million social security numbers in his possession, according to this public statement hosted by Pastebay.com.
Reports have been mixed as different news agencies continue to report conflicting numbers about how many stolen credit card numbers were released. However, journalists have been reporting figures mostly around 15,000. The confusion may center around the fact that the overwhelming majority of the 400,000 numbers are said to be invalid card numbers.
Since the hacker's attack on "Zionist" credit cards, a number of journalistic outfits have conducted email-based interviews with 0xOmar. One blogger claims he has identified the hacker, a supposed 19 year-old citizen of the United Arab Emirates who currently lives in Mexico.
0xOmar, him or herself, claims to be a member of both Anonymous and an Israeli-based hacking group "Wahhabi".
Reuter's noted there does not appear to be any dialogue between the Israeli and Mexican governments as of yet, but Israel's strong rhetoric suggests they will be taking the matter very seriously.
The Bank of Israel says the financial institute will unconditionally protect all cardholders that had their credit card information stolen, in accordance with law. The Banking Supervision Department recommends cardholders look at their monthly statement carefully and report any unauthorized transactions.
Friday, December 30, 2011
Wi-Fi Protected Setup design flaw leaves routers open to attack
Design flaws in the Wi-Fi Protected Setup (WPS) standard used by most modern routers could make it easier to retrieve a wireless network's password through brute force and leave it open to attack. The issue was first brought to light by security researcher Stefan Viehböck and has since prompted a vulnerability notice from the U.S. Computer Emergency Readiness Team (CERT).
The WPS standard was created in 2007 by the Wi-Fi Alliance in order to provide non-technical users with simpler methods of setting up secure wireless networks. One of these methods uses a predefined eight-digit PIN number printed on a sticker by the router manufacturer. The problem, according to Viehböck, is that entering the wrong PIN returns information that could be useful to a hacker.
Ideally an eight-digit PIN code would produce 100,000,000 possible combinations, enough to keep an attacker busy for a few years if attempting a brute force break-in. But the protocol used by Wi-Fi Protected Setup responds to failed authentication attempts by indicating if the first or second halves of the PIN number are correct, significantly reducing the possible combinations. Plus, the last digit is actually the checksum of the other seven. That means an attacker only has to try 11,000 different combinations to find the right PIN.
In his tests, Viehböck found that an authentication attempt takes between 0.5 and 3 seconds and the majority of routers don't implement lock-down periods after several consecutive failed WPS authentication attempts. Only one router from Netgear slowed its responses to failed authentication attempts in order to mitigate against the attack, but that only extended the attack time to a day or so -- otherwise it can take 2-4 hours.
Devices from Buffalo, D-Link, Linksys, Netgear and others are affected. Presummably, the flaw can be addressed with a simple software fix, but until then the US-Cert is recommending users switch off WPS.
GSM security vulnerability affects 80 percent of mobile phones worldwide
A new flaw in the GSM (Global System for Mobile Communications) cellular network technology could potentially allow a hacker to gain control of a phone and force the device to send text messages or place phone calls. Criminals could use the exploit to send messages or make the calls to expensive premium phone services, lining their pockets with cash and leaving phone owners to foot the bill.
GSM technology is used by billions of people worldwide and is said to represent about 80 percent of the global mobile market according to Reuters. The latest vulnerability was discovered by Karsten Nohl, head of Germany’s Security Research Labs. Nohl says that his team can perform the attack on hundreds of thousands of phones in a short timeframe.
Nohl will be speaking at a hacking convention in Berlin on Tuesday. Although he isn’t planning to present details of the attack at the show, he notes that the code will likely be replicated within a few weeks.
Similar attacks have been waged on landline phone systems in the past. Hackers will set up bogus 900-type numbers in Africa, Asia and Easter Europe then force thousands of phones to call the numbers, charging ridiculous fees to the phone provider who then passes them on to the owner of the line. Users usually don’t even notice any fraudulent activity until they receive their bill. By that time, the hacker has shut down shop and set up a new operation somewhere else.
Labels:
gsm,
hacking,
karsten nohl,
mobile,
security,
smartphone,
vulnerability
Subscribe to:
Posts (Atom)