Showing posts with label vulnerability. Show all posts
Showing posts with label vulnerability. Show all posts

Tuesday, July 10, 2012

Mac Flashback trojan exploits unpatched Java vulnerability, no password needed




The icon in the red box in this screenshot is PNG content returned by the remote sites exploiting an unpatched Java vulnerability. The image is dropped onto vulnerable Macs and can be changed any time the author wants.

Developers behind the Flashback trojan for the Mac have updated it to exploit a vulnerability in the Java software framework that has yet to be patched for machines running Mac OS X, an antivirus firm warned on Monday.


Flashback.K, as the latest variant is called, is able to hijack Macs even when users don't enter an administrative password. Instead, it does this by exploiting a critical Java vulnerability classified as CVE-2012-0507, F-Secure researchers wrote in a blog post. Although Oracle released a fix for the security threat in February, a patch has yet to be released for OS X users. That's because Apple distributes Java updates itself and the company has yet to make one for the specific flaw, or indicate when it plans to do so.
Flashback first surfaced in September as a trojan that masqueraded as an installer for Adobe's Flash Player. Over the past few months, it has taken on increasingly sophisticated features, including theability to bypass built-in OS X malware protections and attack code that exploits long-ago patched Java vulnerabilities. The version analyzed by F-Secure is the first known time Flashback has exploited a vulnerability for which no fix is currently available.
Although Apple stopped bundling Java by default in OS X 10.7 (Lion), it offers instructions for downloading and installing the Oracle-developed software framework when users access webpages that use it. Some security researchers have for years criticized Apple for lagging behind Microsoft and Linux distributors in releasing Java updates to its users. F-Secure has recently joined others in counseling Mac users to disable Java on machines that don't regularly use it. The antivirus provider also has provided instructions for checking if your Mac is infected.
Attacks that exploit CVE-2012-0507 recently went mainstream when they were added to automated exploit kits such as Blackhole. Once it infects a Mac, Flashback changes the contents of some of the webpages it displays.

Saturday, June 30, 2012

Drones can be hijacked by terrorist, Researchers says Vulnerability Exist



Drones+can+be+hijacked+by+terrorist




Fox News is reporting that researchers say that terrorists or drug gangs, with the right kind of equipment could turn the drones into “suicide” weapons.


A University of Texas researcher illustrated that fact in a series of test flights recently, showing that GPS "spoofing" could cause a drone to veer off its course and even purposely crash. This is particularly worrisome, given that the US is looking to grant US airspace to drones for domestic jobs including police surveillance or even FedEx deliveries


In other words, with the right equipment, anyone can take control of a GPS-guided drone and make it do anything they want it to. Spoofers are a much more dangerous type of technology because they actually mimic a command by the GPS system and convince the drone it is receiving new coordinates. With his device what Humphreys calls the most advanced spoofer ever built (at a cost of just $1,000) he was able to override the signal from space with a more powerful signal from the device.


Congress recently passed legislation paving the way for what the FAA predicts will be somewhere in the region of 30,000 drones in operation in US skies by 2020.Critics have warned that the FAA has not acted to establish any safeguards whatsoever, and that congress is not holding the agency to account.

Friday, December 30, 2011

GSM security vulnerability affects 80 percent of mobile phones worldwide


mobile, smartphone, hacking, gsm, vulnerability, karsten nohl, security research labs, mobile phone
A new flaw in the GSM (Global System for Mobile Communications) cellular network technology could potentially allow a hacker to gain control of a phone and force the device to send text messages or place phone calls. Criminals could use the exploit to send messages or make the calls to expensive premium phone services, lining their pockets with cash and leaving phone owners to foot the bill.

GSM technology is used by billions of people worldwide and is said to represent about 80 percent of the global mobile market according to Reuters. The latest vulnerability was discovered by Karsten Nohl, head of Germany’s Security Research Labs. Nohl says that his team can perform the attack on hundreds of thousands of phones in a short timeframe.

Nohl will be speaking at a hacking convention in Berlin on Tuesday. Although he isn’t planning to present details of the attack at the show, he notes that the code will likely be replicated within a few weeks.

Similar attacks have been waged on landline phone systems in the past. Hackers will set up bogus 900-type numbers in Africa, Asia and Easter Europe then force thousands of phones to call the numbers, charging ridiculous fees to the phone provider who then passes them on to the owner of the line. Users usually don’t even notice any fraudulent activity until they receive their bill. By that time, the hacker has shut down shop and set up a new operation somewhere else.

Wednesday, December 14, 2011

SMS flaw discovered in Windows Phone 7.5


Microsoft's mobile platform is coming under increased scrutiny after it was revealed that smartphones running Windows Phone 7.5 are at risk of denial-of-service (DoS) attacks that can disable their messaging functions.

Khaled Salemeh, who has been commenting about it on his Twitter account, discovered the flaw. He enlisted the help of WinRumors on Monday and both parties are in the process of disclosing the issue to Microsoft directly. According to WinRumors, the vulnerability works by sending a specially crafted SMS to a Windows Phone device, causing the handset to reboot with the messaging hub functionality disabled.

The site tested it on several different handset models including HTC's Titan and Samsung's Focus Flash. They also noted that the devices used both WP7.5 version 7740 and the Mango RTM build 7720.

"The attack is not device specific and appears to be an issue with the way the Windows Phone messaging hub handles messages," says the report. WinRumors also found that the bug could be triggered if a user sent a Facebook chat message or Windows Live Messenger message to someone in their contacts list.

The site found that this flaw affects other aspects of the Windows Phone operating system too. In particular, if a user has pinned a friend as a live tile on their device and that friend posts a particular message on Facebook, then the live tile will update and cause the device to lock up. One way to work around this is quickly removing the live tile as soon as the handset loads to the home screen.

WinRumors believes the issue relates to the way the mobile OS handles messages, and doesn't represent a security threat. There is no workaround to mitigate it though and for those experiencing a problem the only way of restoring messaging functions is to perform a hard reset of the handset.