quinta-feira, 13 de novembro de 2014

Pen drive , are you safety?

The researcher Karsten Nohl and his team presented an update of their BadUSB study.It is impossible to discriminate patchable devices from inpatchable ones.

Earlier August 2014 the security expert Karsten Nohl and his team discovered that an attacker could exploit a new class of attacks based on a USB device to compromise a targeted machine. The attack could be used to compromise personal computers and is able to evade all actual security protections loading malicious software in low-cost computer chips that control the functions of USB devices.

“Nohl and Lell’s BadUSB demonstrations during Black Hat illustrated how their code could overwrite USB firmware and turn a USB device into anything. A flash drive plugged into a PC, could for example, emulate a keyboard and issue commands that steal data from the machine, spoof a computer’s network interface and redirect traffic by altering DNS settings, or could load malware from a hidden partition on the drive.”

The researchers point a series of flaws in the software used to run a tiny electronic components, these components are usually designed without protections against tampering with their code. Hackers can uncover such flaws and exploit them creating serious problems to the targeted architecture.

badusb vulnerability

“You cannot tell where the virus came from. It is almost like a magic trick,” said Nohl.

As reported in a blog post published by Wired unpatchable security flaw in USB devices affects only the fifty percent of USB devices, but it is nearly impossible to discriminate secure USB units from the insecure ones “without ripping open every last thumb drive”.

Last week Nohl, and his fellow researchers Jakob Lell and Sascha Krissler, presented an update to his BadUSB research at the PacSec security conference in Tokyo. The experts analyzed the USB controller chips sold by the eight biggest vendors (Phison, Alcor, Renesas, ASmedia, Genesys Logic, FTDI, Cypress and Microchip) discovering that half of them were vulnerable to the attack, but the expert revealed that it was impossible to predict which chip a device uses is impossible for the final user.

“It’s not like you plug [a thumbdrive] into your computer and it tells you this is a Cypress chip, and this one is a Phison chip,” says Nohl, naming two of the top USB chip manufacturers. “You really can’t check other than by opening the device and doing the analysis yourself…The scarier story is that we can’t give you a list of safe devices.”

The experts analyzed versions of each chip both by looking up its published specs and by plugging a device using it into a USB port and attempting to overwrite the firmware in the chip.

“They found an unpredictable patchwork of results. All of the USB storage controllers from Taiwanese firm Phison that Nohl tested, for instance, were vulnerable to reprogramming. Chips from ASmedia weren’t, Nohl’s tests found. Controller chips from fellow Taiwanese company Genesys that used the USB 2 standard were immune, but ones that used the newer USB 3 standard were susceptible. In other categories of device like USB hubs, keyboards, webcams and mice, the results produced an even messier Excel spreadsheet of “vulnerable,” “secure,” and “inconclusive.”” reports Wired.

Unfortunately, device makers don’t provide info on the manufacture of the chips they have integrated, in some cases, they use chips from different vendors, even in the same product, this politic allows them to choose the cheapest suppliers for different lots of production.

The only way to prevent the exploitation of the BadUSB is to request device makers to label the chips they use in their products.

“You’d never get away with this in a laptop. People would go crazy if they bought a computer and it wasn’t the chip they saw in the review they read,” explains Nohl. “It’s just these USB devices that come as black boxes.”

It’s clear that what Nohl suggest is quite impossible to realize, so the researcher decided not to release the proof-of-concept code for his BadUSB attack when he demonstrated it at Black Hat.

The company Imation already implemented a solution to protect its users against the BadUSB attacks, its solution Ironkey requires that any new updates to its chip firmware be digitally signed with an unforgeable cryptographic signature. The process was designed to prevent malicious reprogramming of the USB firmware. According to Nohl, other USB makers could adopt the same strategy to secure their users.

Nohl highlighted that the total lack of transparency in the USB device industry exposes everyone use a USB device to the risk of attack, every device is potentially exploitable by bad actors.

“Some people have accepted that USB is insecure. Others remember BadUSB only as the Phison bug. That second group needs to wake up to the same level of awareness of the first group,” Nohl says. “For practical purposes, it affects potentially everything.”

Pierluigi Paganini

How conected world affect privacity?

Featured news
The biggest challenges around connected devices
Infosec industry: Time to put up or shut up
Organized cyber crooks plunder SMBs with simple, cheap keyloggers
Latest Microsoft patches crucial for all Windows users
Report: Targeted digital threats against civil society organizations
Do senior executives value information security?
Whitepaper: Still using proxies for URL filtering? There’s a better way
SAP finally patches critical, remotely exploitable bugs in GRC solution
Many IT pros store compromising material on their mobile phones
73% of organizations say BYOD increases security risks
First victims of the Stuxnet worm revealed
Vigilance and the Enterprise of Things
8 criteria to decide which ISO 27001 policies and procedures to write
Application Threat and Usage Report 2014
A holistic approach to protecting intellectual property
Fake malware-laden Amazon emails target UK, US shoppers

The biggest challenges around connected devices
Posted on 13 November 2014.
Few European IT departments or workplaces are ready for the invasion of wearable technology and other connected devices.

According to a 110-country survey of ISACA members who are business and IT professionals, 43% of respondents in Europe, the Middle East and Africa (EMEA) say their organization has plans in place to leverage the Internet of Things or expects to create plans in the next 12 months.

However, the majority is not ready for wearable technology in the workplace. More than half (57%) say their BYOD policy does not address wearables and a further 24% do not even have a BYOD policy in place. This is a concern, as approximately 8 in 10 respondents (81%) say BYOW (bring your own wearables) is as risky as—or riskier than—BYOD.

Overall, half of ISACA members across EMEA believe the benefit of the Internet of Things outweighs the risk for individuals (50%), while nearly a third believe the risk outweighs the benefit for enterprises (31%). Yet despite the risks, nearly a third (30%) says the Internet of Things has given their business greater access to information and a quarter (25%) say it has improved services in their organization.

Approximately four in 10 hope to benefit from improved services (40%), increased customer satisfaction (39%), and greater efficiency (38%) as a result of connected devices.

Despite the benefits of connected devices, more than half (51%) of respondents believe the biggest challenge regarding the Internet of Things is increased security threats, while a quarter (26%) are concerned about data privacy issues. Two-thirds (68%) admit they are very concerned about the decreasing level of personal privacy.

More than a quarter of respondents say the general public’s biggest concerns about connected devices should be that they don’t know how the information collected on the devices will be used (28%) or they don’t know who has access to the information collected (26%).

‘The Internet of Things is here to stay, and following the holidays, we are likely to see a surge in wearable devices in the workplace,” said Ramsés Gallego, international vice president of ISACA. “These devices can deliver great value, but they can also bring great risk. ISACA’s research found that more than a third (35%) of EMEA ISACA members believe Big Data has the potential to add significant value, yet one-fifth (21%) admit their organization lacks the analytics capabilities or skills to deal with it.”

terça-feira, 11 de novembro de 2014

End of life 2003 server


NCCIC / US-CERT
National Cyber Awareness System:

TA14-310A: Microsoft Ending Support for Windows Server 2003 Operating System
11/10/2014 07:19 AM EST

Original release date: November 10, 2014
Systems Affected

Microsoft Windows Server 2003 operating system

Overview

Microsoft is ending support for the Windows Server 2003 operating system on July 14, 2015.[1] After this date, this product will no longer receive:

Security patches that help protect PCs from harmful viruses, spyware, and other malicious software
Assisted technical support from Microsoft
Software and content updates
Description

All software products have a lifecycle. End of support refers to the date when Microsoft will no longer provide automatic fixes, updates, or online technical assistance.[2] As of July 2014, there were 12 million physical servers worldwide still running Windows Server 2003.[3]

Impact

Computer systems running unsupported software are exposed to an elevated risk to cybersecurity dangers, such as malicious attacks or electronic data loss.

Users may also encounter problems with software and hardware compatibility since new software applications and hardware devices may not be built for Windows Server 2003.

Organizations that are governed by regulatory obligations may find they are no longer able to satisfy compliance requirements while running Windows Server 2003.

Solution

Computers running the Windows Server 2003 operating system will continue to work after support ends. However, using unsupported software may increase the risks of viruses and other security threats. Negative consequences could include loss of confidentiality, integrity, and or availability of data, system resources and business assets.

The Microsoft "Microsoft Support Lifecycle Policy FAQ" page offers additional details.[2]

Users have the option to upgrade to a currently supported operating system or other cloud-based services. There are software vendors and service providers in the marketplace who offer assistance in migrating from Windows Server 2003 to a currently supported operating system or SaaS (software as a service) / IaaS (infrastructure as a service) products and services.[4,5] US-CERT does not endorse or support any particular product or vendor.

References

[1] Microsoft Product Lifecycle Listing
[2] Microsoft Support Lifecycle Policy FAQ
[3] Redmond Magazine, Prepare for Windows Server 2003's End of Support
[4] Windows Server 2003 Migration Support
[5] TechTarget, Weighing next steps following Windows Server 2003 end-of-life
Revision History

November 10, 2014: Initial Release

More one IOS attack

Researchers at FireEye identified a new attack dubbed the Masque, which allows attackers to replace a genuine app with a malicious one.

In these days Apple the community has discovered that is vulnerable to WireLurker, a new strain of malware that is able to infect Apple iPhone and iPad syphoning user’data.

The malware was discovered for the first time by experts at Palo Alto Networks that revealed it exhibited behavior that had never been seen before malware targeting Apple mobile devices, unfortunately, it has yet to be patched.

Meanwhile the security experts analyze the WireLurker case, the disclosure of a new attack in the wild exploiting a vulnerability dubbed the Masque is attracting the interest of the experts. Practically the exploitation of the Masque flaw allows bad actors to replace enterprise-signed apps, overwriting them with trojanized apps.

The Masque  vulnerability allows an attacker to swap out a legitimate iOS app with a malicious one, the attack scheme is effective against jailbroken and non-jailbroken devices.

Masque affects iOS 7.1.1, 7.1.2, 8.0, 8.1, and 8.1.1 beta, its attack schema is quite different from WireLurker that infects Apple mobile devices once connected via USB, but it can also be run remotely via an SMS or email message pointing a victim toward a malicious app.

Also in this case the problem seems to be caused by a poor implementation of an authentication process, the expert Tao Wei, a senior staff research scientist at FireEye, explained that Apple’s enterprise provisioning feature does not analyze digital certificates for apps given identical bundle identifiers.

The Enterprise provisioning service implemented by Apple allows enterprise iOS developers to develop and distribute iOS apps without having to upload the app to Apple.

“FireEye mobile security researchers have discovered that an iOS app installed using enterprise/ad-hoc provisioning could replace another genuine app installed through the App Store, as long as both apps used the same bundle identifier.”

“This vulnerability exists because iOS doesn’t enforce matching certificates for apps with the same bundle identifier,” Tao Wei said on the company’s blog post. “An attacker can leverage this vulnerability both through wireless networks and USB.” “iOS doesn’t check certificates during updating,” “Attackers can replace the old app with a fake app.” “Currently there is not MDM API to get the certificate information for each app,” Wei said. “Thus, it is difficult for the MDM to detect such attacks.”

Wei speaking about the WireLurker, explained that it is the unique case of attack up until now observed that is exploiting the Masque vulnerability. Let’s remind that the WireLurker malware in a first stage infects a host (desktop or laptop), which downloaded the malicious software from the web, then it waits for an Apple device (i.e. iPhone or iPad) to be connected via USB.

Once the Apple device is connected to the infected PC, WireLurker scans it analyzing the installed applications, then if a target app is present, it copies the app from the mobile device to the host, infects it and then install it again on the mobile unit.

The blog post published by FireEye also includes a demonstration of an attack, the experts have exploited the Masque replacing a valid Gmail app downloaded from the Apple App Store with a malicious version of the same app that is able to syphon the user’ messages. The attack starts with an SMS sent to the victims that invite it to download a new version of a legitimate app New Flappy Bird.

“In one of our experiments, we used an in-house app with a bundle identifier “com.google.Gmail” with a title “New Flappy Bird”. We signed this app using an enterprise certificate. When we installed this app from a website, it replaced the original Gmail app on the phone.” states the post. “By using the Masque attack, attackers can get all your existing sensitive data on your iPhone,” Wei added.

Masque demonstation

The attack is very dangerous, a bad actor would be able to mimic the original app to steal a user’s credentials, the risk is serious if we thin the possibility to compromise also signed banking apps. Experts at FireEye also explained that user’s data stored in the legitimate app’s directory, including local data caches, could be accessed by the malware.

“Masque Attacks can replace authentic apps,such as banking and email apps, using attacker’s malware through the Internet. That means the attacker can steal user’s banking credentials by replacing an authentic banking app with an malware that has identical UI. Surprisingly, the malware can even access the original app’s local data, which wasn’t removed when the original app was replaced. These data may contain cached emails, or even login-tokens which the malware can use to log into the user’s account directly.”

The principal problem for the security community is related to the simplicity in the exploitation of the Masque vulnerability.

“It is a very powerful [vulnerability], but at the same time, it is very easy to exploit,” Wei said. “It can make the enterprise provisioning attack more powerful and more coverage over the victim. It’s easy to exploit and that’s why we are so concerned and why we think users should be warned.”

In order to avoid falling victim of a Masque Attack, it is suggested to adopt simply practices:
Do not download mobile apps clicking on a link received via email, text messages, or present on a web page.
Don’t install apps offered on pop-ups from third-party websites.
If the mobile device displays an alert about an “Untrusted App Developer,” click “Don’t Trust” on the alert and uninstall the application.
Pierluigi Paganini

Us Mail employees may be leaked

State-sponsored hackers are suspected of breaching the systems of the United States Postal Service exposing the data of more than 800,000 employees.

The U.S. Postal Service has suffered a major data breach that may have exposed the personal information of more than 800,000 employees, including data on customers who contacted Postal Service Customer Care Center by telephone or email from January through August 16.
“Contact information from an estimated 2.9 million customers was also exposed during the breach. ” states a post published on Business2community website
According to the U.S. Postal Service, the data breach did not affect credit card data from other online services including Click-N-Ship, the Postal Store, PostalOne! or change of address services.
The U.S. Postal Service confirmed that the employees’ personal information exposed includes names, dates of birth, Social Security numbers, addresses, beginning and end dates of employment and emergency contact information.
“The intrusion is limited in scope and all operations of the Postal Service are functioning normally,” USPS spokesman David Partenheimer said in an official statement.
Security experts speculate that a persistent threat actor is behind the attack, several specialists hypothesized the involvement of a foreign government, like China or Russia.
United States Postal Service
Partenheimer added that the attack was run by a “sophisticated actor” that was not interested in credit card fraud neither to arrange large scale scam with stolen data.
The U.S. Postal Service was a privileged target for state-sponsored hackers,  for this reason it is not simple to imagine who is behind the data breach.
“There’s a lot of information there and it has great value,” to nation-states like China or cybercriminals in Russia,” said George Kurtz, chief executive of cybersecurity firm CrowdStrike.
“The U.S. Post Office moves billions of letters each year and all of that is captured digitally,” Kurtz told Reuters.“The information flow of where letters and packages and correspondence are going and who is talking to whom is very interesting to them.”
As usually happens in these cases to the company that suffers the attack, also the U.S. Postal Service would pay for victims to get credit monitoring services for one year.
The principal fear of US law enforcement and Intelligence, is that stolen information could be used in a secondary major attack (i.e. spear phishing campaign) against vital national structures.
The U.S. Postal Service breach follows a couple of major attacks occurred in the last months; in August the US Investigations Services (USIS), which provides background checks for the US government, was hacked, meanwhile early July, alleged Chinese hackers hacked the system of the Office of Personnel Management (OPM).
As reported by the Reuters agency, the U.S. Representative Elijah Cummings asked Postmaster General Patrick Donahoe in a letter Monday for more detail on the databreach.
“The increased frequency and sophistication of cyber-attacks upon both public and private entities highlights the need for greater collaboration to improve data security,” wrote Cummings, the senior Democrat on the House of Representatives Oversight and Government Reform Committee.
The FBI is leading the investigation on the data breach.

segunda-feira, 10 de novembro de 2014

Ciber espionagem na reunião do G20

Fantasmas Aussie advertiram de ciberataques "reais e persistentes" sobre participantes da próxima conferência do G20 em Brisbane. Os líderes mundiais foram aconselhados ao homem os seus dispositivos de perto enquanto o público australiano é sobre um alerta de código vermelho para uma ameaça eminente.

Meses após suposta governo russo apoiados alvo dos hackers da OTAN computadores e agências de governos europeus, a agência de inteligência Austrália relataram possibilidades de ciber-ataques "reais e persistentes", afirmou assados ​​sobre os participantes da próxima cúpula do G20 em Brisbane.
A conferência altamente vigiado discute questões de alta potência diplomáticos, econômicos e políticos de todo o mundo e é um bom phishing terreno para informações do governo classificadas como advertido pela Direcção Sinais Austrailian (ASD).
"Segmentação de eventos de alto nível, como o G20 por adversários estrangeiros patrocinados pelo Estado ou outras, os ciber-criminosos e grupos motivados-edição é uma ameaça real e persistente", disse a diretoria em sua assessoria G20 cibersegurança .
Os líderes mundiais que participam na cimeira na capital de Queensland em 15 de novembro th e 16 thforam alertados que atente engenharia social, phishingscams através de e-mails.
"Garantir a legitimidade de suas comunicações de e-mail, se disponível, ter a opção de assinar digitalmente seus e-mails ao se comunicar externamente como parte de seus deveres do G20", dizia a segurança aconselhá G20
Mais importante, os líderes do G20 devem evitar o uso de redes sem fio públicas para a comunicação oficial ou aceitar uma mídia removível como presentes alguns dos quais poderiam ser corrompidos para phish informação governamental sensível.
"As informações contidas em sistemas de governo, seja classificada ou não classificada, é de interesse estratégico para os adversários cibernéticos. As informações recolhidas através de espionagem cibernética pode ser usado para ganhar uma vantagem econômica, diplomática ou política ", dizia o comunicado de segurança.
O público Austrailian também foi colocada em estado de alerta de possíveis infiltrações de rede.
"As redes australianas, consequentemente, tornar-se um alvo mais atraente para espionagem cibernética ou ataque", disse a agência de assessoria organização para aplicar técnicas de mitigação, tais como listas brancas Apps, Aplicativos e patches do sistema operacional, e limitando os direitos Administrar em sistemas de computador.
Ministros das Finanças do G20 e Governadores dos Bancos Centrais começam sua reunião anual em Sydney
O ASD que alimenta o exército Austrália com inteligência sinal ainda está para fixar pontos possíveis mandantes dos ataques, mas a China ea Rússia já foram apregoados no topo da lista.
"Porque a China é um suspeito óbvio e Rússia é um suspeito óbvio, um monte de hackers de todo o mundo têm saído do seu caminho e desenvolveu-lo em um pouco de uma forma de arte para colocar a culpa no da China e da Rússia pés para todos tipos de hacks ", disse o porta-voz do CREST Austrália Greg Rudd.
Hackers têm como alvo grande defesa e conferências diplomáticas no passado, incluindo ataques de phishing falsos sobre Cooperação Econômica Ásia-Pacífico, em julho do ano passado, e os ciber-ataques contra a Associação de Nações do Sudeste Asiático em Novembro de 2012.
Biografia do autor: 
Ali Qamar é um entusiasta de pesquisa de segurança da Internet que gosta de pesquisa "profundo" para cavar descobertas modernas na indústria de segurança. Ele é o fundador e editor-chefe do SecurityGladiators.com, uma fonte definitiva para a conscientização da segurança em todo o mundo com a missão suprema de tornar a internet mais segura, segura, consciente e confiável

domingo, 9 de novembro de 2014

Google study says that phishing is the most effective ciber attack

A study published by Google demonstrates that manual phishing attacks are the simplest and most effective method for hacking email accounts.

A study recently published by Google demonstrates that so-called manual phishing attacks are the simplest and most effective method for hijacking users’ email address.

Let’s consider that the manual phishing attacks, as suggested by the name, doesn’t use any automated tool to compromise the user’s account and for this reason it is rare in comparison with other technique of attacks.

Experts at Google revealed that only nine attacks per million users every day adopt the manual phishing technique, considering that the number of Gmail users was more than 425 million users in 2012, meaning that thousands of individuals fall victim manual attacks a day.

manual phishing attack

Manual phishing attacks are considered time consuming, the hack of a single Gmail account request a considerable amount of time. According to Google, once the attacker gains the access to the account he will spend more than 20 minutes to exploit the account for maximum gain. The first operation made by the attacker is to lock out the legitimate owner, changing the password, as a second step he tries to gather as much information as possible from the account like social media and other email accounts.

“Around 20% of hijacked accounts are accessed within 30 minutes of a hacker obtaining the login info. Once they’ve broken into an account they want to exploit, hijackers spend more than 20 minutes inside, often changing the password to lock out the true owner, searching for other account details (like your bank, or social media accounts), and scamming new victims.”states Google in a blog post.

Google confirms that phishing is the most effective technique to hijack an email account, the hacked accounts are usually recruited to send phishing messages to victim’s contacts present in the address book.

“Most of us think we’re too smart to fall for phishing, but our research found some fake websites worked a whopping 45% of the time. On average, people visiting the fake pages submitted their info 14% of the time, and even the most obviously fake sites still managed to deceive 3% of people. Considering that an attacker can send out millions of messages, these success rates are nothing to sneeze at.”states Google.

” People in the contact list of hijacked accounts are 36 times more likely to be hijacked themselves.”

Google also tried to track the profile of hackers that run manual phishing attacks, despite it is very hard to identify them, the company states that they operate mainly from China, Ivory Coast, Malaysia, Nigeria and South Africa.

manual phishing attack attackers by country

According to the experts at Google, the attackers are professional hackers that approach their work like a full-time job, with regular working days and time.

The attackers running manual phishing attacks demonstrate the capability to adapt their operation to countermeasures implemented by Google, when the company started asking users to verify suspicious activity by confirming their city of residence, the attackers promptly began sending phishing e-mails to obtain the correct information from their victims.

Google explained that several security features can be highly effective in preventing manual phishing attacks, including the two-factor authentication and the recently launched Security Key that will allow clients authentication with a USB stick.

The principal problem is that a limited number of users is aware of cyber threats and too few individuals adopt these tools for the protection of their accounts.

Pierluigi Paganini

G 20 in code red to ciber war

Aussie spooks have warned of ‘real and persistent’ cyberattacks on participants of the upcoming G20 conference in Brisbane. World leaders have been advised to man their devices closely while the Austrian public is on a code red alert for an eminent threat.
Months after alleged Russian government backed hackers’ targeted NATO computers and European Governments agencies, the Australia intelligence agency have reported possibilities of “real and persistent” stated baked cyber-attacks on participants of the upcoming G20 summit in Brisbane.

The highly guarded conference discuses high-powered diplomatic, economic and political issues around the globe and is a good phishing ground for classified government information as warned by the Austrian Signals Directorate (ASD).

“Targeting of high-profile events such as the G20 by state-sponsored or other foreign adversaries, cyber-criminals and issue-motivated groups is a real and persistent threat,” the directorate said in its G20 cyber-security advisory.

World leaders attending the summit in Queensland’s capital on November 15th &16th have been cautioned to watch out social engineering phishing scams through emails.

“Ensure the legitimacy of your email communications, if available, take the option to digitally sign your emails when communicating externally as part of your G20 duties,” read the G20 security advise

More importantly, G20 leaders should avoid using public wireless networks for official communication or accepting removable media as gifts some of which could be corrupted to phish sensitive government information.

“The Information contained on government systems, whether classified or unclassified, is of strategic interest to cyber adversaries. Information gathered through cyber espionage can be used to gain an economic, diplomatic or political advantage,” read the security advisory.

The Austrian public has also been put on high alert of possible network infiltration.

“Australian networks will consequently become a more attractive target for cyber espionage or attack,” said the agency advising organization to apply mitigation techniques such as Apps whitelisting, Apps and OS patching, and limiting administrate rights on computer systems.

G20 Finance Ministers and Central Bank Governors begin their annual meeting in Sydney

The ASD which feeds the Australia army with signal intelligence is yet to pin points possible masterminds of the attacks but China and Russia have already been touted to top the list.

“Because China is an obvious suspect and Russia is an obvious suspect, a lot of the hackers all over the world have gone out of their way and developed it into a bit of an art form to lay the blame at China and Russia’s feet for all sorts of hacks,” said CREST Australia’s spokesman Greg Rudd.

Hackers have targeted large defense and diplomatic conferences in the past, including spoofed phishing attacks on  Asia-Pacific Economic Cooperation in July last year, and cyber-attacks on the  Association of Southeast Asian Nations in November 2012.

Written by: Ali Qamar, Founder/Chief Editor at SecurityGladiators.com

Author Bio:
Ali Qamar is an Internet security research enthusiast who enjoys “deep” research to dig out modern discoveries in the security industry. He is the founder and chief editor at SecurityGladiators.com, an ultimate source for worldwide security awareness having supreme mission of making the internet more safe, secure, aware and reliable.

Malware Wirelurker afects Apple users

A new strain of malware dubbed WireLurker  is threatening Apple users, the malicious code is cable to infect Apple iPhone and iPad syphoning user’data and collecting .

The malware was discovered for the first time by experts at Palo Alto Networks that revealed it exhibited behavior that had never been seen before malware targeting Apple mobile devices. The company estimates several hundred thousand Apple users have been already infected by WireLurker.

The malware in a first stage infects a host (desktop or laptop) which downloaded the malicious software from the web, then it waits for an Apple device (i.e. iPhone or iPad) to be connected via USB.

Once the Apple device is connected to the infected PC, WireLurker scans it analyzing the installed applications, then if a target app is present, it copies the app from the mobile device to the host, infects it and then install it again on the mobile unit.

The experts discovered that WireLurker only collect data from the compromised device, but, to date, no other malicious activity has been observed. The following graph shows detections of the WireLurker malware made by expert at Kaspersky Lab on OSX.

WireLurker malware Kaspersky

The experts at Palo Alto Networks expressed their concerns in the official blog post on the WireLurker malware:

“We believe that this malware family heralds a new era in malware attacking Apple’s desktop and mobile platforms based on the following characteristics:”

Of known malware families distributed through trojanized / repackaged OS X applications, it is the biggest in scale we have ever seen
It is only the second known malware family that attacks iOS devices through OS X via USB
It is the first malware to automate generation of malicious iOS applications, through binary file replacement
It is the first known malware that can infect installed iOS applications similar to a traditional virus
It is the first in-the-wild malware to install third-party applications on non-jailbroken iOS devices through enterprise provisioning
Apple mobile devices are becoming a privileged target of cybercriminals due to the large number of devices worldwide and the lack of security measured installed by the Apple users.

The infection was spread initially through several hundreds apps offered via Maiyadi, a third-party Chinese software website .

“WireLurker was used to trojanize 467 OS X applications on the Maiyadi App Store, a third-party Mac application store in China. In the past six months, these 467 infected applications were downloaded over 356,104 times and may have impacted hundreds of thousands of users.” states the post.

WireLurker primarily targets Apple devices that have been “jailbroken” and that result vulnerable because users had disabled some security feature to run certain apps.

Experts also detected a strain of WireLurker that targets iPhones and carries an Apple digital certificate, but that version needs user approval to be executed.

The instance of WireLurker detected also targets popular Chinese apps like Taobao, Alipay or Meitu.

Apple has blocked the apps that could be used by threat actor to propagate the infection.

Pierluigi Paganini

quinta-feira, 6 de novembro de 2014

Ferramenta de ataque cibernético BlackEnergy crimeware pode atacar sistemas Linux , Windows e roteadores Cisco

Pesquisadores de segurança da Kaspersky Lab desenterraram novas capacidades na arma BlackEnergy crimeware que tem agora capacidade de hackear  roteadores , sistemas Linux e Windows, tendo como alvo a indústria por meio de dispositivos de rede Cisco.

Pesquisa e Análise Global Team do fornecedor de antivírus divulgou um relatório detalhando segunda-feira alguns dos novos " relativamente desconhecidas capacidades plug-in personalizado "que o grupo de espionagem cibernética desenvolveu para BlackEnergy para atacar dispositivos de rede Cisco e alvo plataformas ARM e MIPS.

O malware foi atualizado com plugins personalizados incluindo Ciscoapi.tcl que tem como alvo kit do Borg, e de acordo com os pesquisadores, a versão atualizada continha vários invólucros sobre Cisco Exec-comandos e " uma mensagem gorducho para Kaspersky , "onde se lê:" F * UCK U , Kaspersky !!! U nunca obter um novo B1ack En3rgy. Assim, graças C1sco 1TD para embutido backd00rs & 0-dia. "

Programa de malware BlackEnergy foi originalmente criado e usado por cibercriminosos para lançar Distributed Denial-of-Service (DDoS). O desenvolvedor do malware então adicionado alguns plugins personalizados usados ​​para canalizar informações bancárias.

Mais recentemente malwares BlackEnergy foi observada em alegados ataques patrocinados pelo Estadovisando a Organização do Tratado do Atlântico Norte (OTAN) , as agências governamentais ucranianos e poloneses, e uma variedade de indústrias europeias sensíveis ao longo do último ano.

Agora, a espionagem cibernética grupo aprimorou o programa de malware que também tem os recursos como varredura de portas, roubo de passwords, a coleta de informações do sistema, o roubo de certificado digital, conectividade de desktop remoto e limpeza de disco rígido e destruir mesmo.

No caso, se a vítima sabia da infecção BlackEnergy em seu sistema, o atacante ativa " dstr ", o nome de um plugin que destrói discos rígidos, substituindo-os com dados aleatórios. A segunda vítima foi comprometida usando credenciais VPN tomadas a partir da primeira vítima.

Os pesquisadores de segurança, Kurt Baumgartner e Maria Garnaeva , também me deparei com versão BlackEnergy que funciona em sistemas baseados em ARM e MIPS e descobriu que ele tem comprometido dispositivos de rede fabricados pela Cisco Systems.

No entanto, os especialistas não têm certeza com o propósito de alguns plugins, incluindo um que reúne IDs de instância do dispositivo e outras informações em drives USB conectados e outra que coleta informações sobre a BIOS (Basic Input / Output System), placa-mãe e processador de infectados sistemas.
Temos certeza de que a nossa lista de [BlackEnergy] ferramentas não está completa, "escreveram os pesquisadores. Por exemplo, ainda temos de obter o plugin de acesso roteador, mas estamos confiantes de que ele existe. As evidências também apoia a hipótese de que existe um plugin de decodificação para arquivos vítima . "
Várias empresas de vítimas não identificadas em diferentes países foram alvo com o malware mais recente BlackEnergy, incluindo as vítimas na Rússia, Alemanha, Bélgica, Turquia, Líbia, Vietnã e vários outros países.

Outro grupo crimeware, a equipe Sandworm , que se acredita ter usado a BlackEnergy exclusivamente ao longo de 2014, sites vítimas e incluiu plugin e os scripts de seu próprio costume. Também no mês passado, a Equipe Sandworm tinha como alvo organizações em todo o mundo em uma campanha de espionagem , e iSight Partners revelou que a equipe usou spêra phishing como o principal vetor de ataque para vitimar seus alvos

Irmandade Mussulmana ISIS utiliza grupo Hacker para desfigurar sites.

Um grupo de hackers que apoiam o ISIS teriam hackeado o site da equipe de rugby Keighley pumas, os atacantes desfiguraram o site com slogans pró ISIS.

Keighley Cougars Rugby site da equipe foi invadido por extremistas islâmicos, ISIS. Usuários que tentaram o site no domingo foram recebidos por uma página web com preto "Hacked by Team System Dz" e "eu te amo" ISIS slogans.
ISIS defacement
O motivo do hack não é clara, mas os especialistas acreditam que os extremistas ISIS só estavam usando o site para transmitir suas frustrações políticas com o governo dos Estados Unidos e não para fins comerciais. Alguns dos slogans anti-americanos exibidos na página inicial do site chamado de "eliminação da América e os aliados dos infiéis".
 "Este é um momento do Islã e da vitória", afirmou outra declaração no site "A aliança do mundo contra o Estado do Islã não vai ter sucesso e vai oferecer ao martírio e jihad. Amaldiçoe a América ". A mensagem supostamente enviada a toda a população e os governos no mundo declarado o" estado do Islã "estava se expandindo.
"É sinistro o que aconteceu eo que quer organização, onde quer que esteja no mundo, não deve ser o seqüestro de mídia de outras pessoas", disse o presidente, Gary Fawcett, disse o Keighley News. "E eu espero que a polícia descubra quem fez isso onde quer que estejam e trazê-los a prestar contas."
Fawcett estava preocupado as imagens assustando de vítimas de guerra feridos e outras imagens perturbadoras exibidos no site hackeado teria efeito psicológico sobre os usuários da Internet jovens "
É uma preocupação que as crianças possam ver algumas dessas imagens de pesadelo. "Referindo-se a imagens de casas destruídos" muçulmanos "e as mulheres e crianças vítimas da crise em curso na Síria .
West Yorkshire departamento de polícia em conjunto com a unidade anti-terrorismo estão investigando a violação. "Estamos cientes do incidente e já passou para a nossa unidade de contra-terrorismo", disse o porta-voz da polícia de West Yorkshire."Vamos trabalhar com o clube em relação a isso e estão fazendo perguntas."
O clube de nível dois de rugby postou uma mensagem em sua alimentação o tweet pedindo desculpas pelo incidente hacking. "Desculpas, o site foi hackeado. Os desenvolvedores estão trabalhando nisso. Vai deixar você saber quando é voltar a funcionar ", afirmou o clube em um tweet.
"Enquanto nós desenvolvemos o site, nós não hospedá-lo, isso é feito por uma empresa em Londres e eles foram contatados por um de nossos diretores. Foi, obviamente, feito em uma noite de domingo, quando seria mais difícil para qualquer um tomar uma ação rápida. Infelizmente é uma declaração terrorista e eu entendo a polícia de West Yorkshire já passou para a polícia anti-terrorismo ", afirmou o presidente do clube.
Embora o site corte Keighley Cougars pode parecer como um incidente isolado, relatórios de mídia social indicar o ISIS hackeado um servidor host com mais de 60 sites para a difusão do "mensagem global."
Enquanto isso, o ISIS ainda está para publicar uma declaração oficial a assumir a responsabilidade para o hack, mas o grupo é conhecido por sua crueldade e estratégias rebeldes. Circulam vídeos on-line mostram combatentes do ISIS abate prisioneiros de guerra, incluindo a decapitação de Alan Henning- um trabalhador humanitário britânico. O grupo radical também anexou grandes territórios no oeste do Iraque e da guerra-rasgado Síria.
Biografia do autor:
Ali Qamar é um entusiasta de pesquisa de segurança da Internet que gosta de pesquisa "profundo" para cavar descobertas modernas na indústria de segurança. Ele é o fundador e editor-chefe do SecurityGladiators.com, que é uma fonte definitiva para a conscientização da segurança em todo o mundo com a missão suprema de tornar a internet mais segura, segura, consciente e confiável.

EM 2026, CIBERSEGURANÇA DEIXOU DE SER UM PROBLEMA TÉCNICO A transição da defesa tática para a liderança estratégica em infraestruturas crít...