Friday, 13 March 2015

Microsoft patches up FREAK and Stuxnet security flaws on Windows


Microsoft has come up with its most important Patch Tuesday for this year, addressing the recently disclosed critical the FREAK encryption-downgrade attack, and a separate five-year-old vulnerability leveraged by infamous Stuxnet malware to infect Windows operating system.

Stuxnet malware, a sophisticated cyber-espionage malware allegedly developed by the US Intelligence and Israeli government together, was specially designed to sabotage the Iranian nuclear facilities a few years ago. First uncovered in 2010, Stuxnet targeted computers by exploiting vulnerabilities in Windows systems.

Thankfully, Microsoft has issued a patch to protect its Windows machines that have been left vulnerable to Stuxnet and other similar attacks for the past five years. The fixes are included in MS15-020 which resolves Stuxnet issue.

The company has also issued an update that patches the FREAK encryption vulnerability in its SSL/TSL implementation called Secure Channel (Schannel). The fixes for the vulnerability are included in MS15-031.

As we have mentioned in our previous report, FREAK — short for Factoring attack on RSA-EXPORT Keys — was initially thought to be associated with Apple's Safari and Android's stock browsers, but it was found to affect Windows PCs as well.

This decades-old FREAK vulnerability allows an attacker on your network to force the software using Schannel component such as Internet Explorer to use weak encryption over the web, so that they can easily decrypt the intercepted HTTPS connections.

Among these two critical issues, the company has also released a bunch of other updates. Microsoft's March 2015 Patch Tuesday update bundles a total of 14 security-related updates for 43 vulnerabilities affecting Internet Explorer, VBscript, Text Services, Adobe Font Drivers, and Office.
·         MS15-018 - A Cumulative Security Update, rated as 'critical', affects all supported versions of Internet Explorer and addresses a number of Memory Corruption vulnerabilities, two elevation of privilege vulnerabilities, and a VBscript memory corruption vulnerability.
·         MS15-019 - This update addresses a scripting vulnerability in some older versions of Windows operating systems. The vulnerability doesn't affect Windows 7 and later desktop versions.
·         MS15-021 - It addresses eight vulnerabilities in the Adobe Font Driver components for Windows and Windows Server exploitable through a malicious website or file. It is also rated 'critical' due to the possibility of remote code execution.
·         MS15-022 - This update fixes three unknown flaws in Office document formats as well as multiple cross-site scripting (XSS) issues for SharePoint Server, and applies to all supported versions of Microsoft Office, as well as the server-based Office Web Apps and SharePoint Server products.
·         MS15-023 - This bulletin, rated as 'important', addresses four vulnerabilities in the Windows Kernel-Mode driver allowing elevation of privilege and information disclosure attacks by launching a specially-crafted application.
Rest of all, MS15-024MS15-025MS15-027MS15-028MS15-29 and MS15-30, are rated as 'important' and affected Windows and Windows Server. Microsoft is advising all its users and administrators to install the new updates as soon as possible.


Tuesday, 13 January 2015

Secrets Of Hacking


A Systematic Process
Although portrayed otherwise in Hollywood films and in television shows, hacking is a systematic, tiresome process in which the attacker attempts methodically to locate computer systems, identify their vulnerabilities, and then compromise those vulnerabilities to obtain access. Experts have identified six steps that are generally followed in the hacking process. These include (1) footprinting (reconnaissance); (2) scanning; (3) enumeration; (4) penetration; (5) advance; and (6) covering tracks.

Footprinting.
The first technique often used by hackers is called footprinting. The objective is to gather information essential to an attack and enable an attacker to obtain a complete profile of an organization’s security posture. During this phase, the hacker might gain information about the location of the company, phone numbers, employee names, security policies, and the overall layout of the target network. Often, hackers can perform this work with a simple web browser, a telephone, and a search engine. Unfortunately, humans are often the weakest security link in a corporation. A clever phone call to the technical support department can often compromise critical information: “Hi—this is Bill and I forgot my password. Can you remind me what it is?”



Scanning.
Next, hackers perform scanning to gain a more detailed view of a company’s network and to understand what specific computer systems and services are in use. During this phase, the hacker determines which systems on the target network are live and reachable from the Internet. Commonly used scanning techniques include network ping sweeps and port scans. A ping sweep lets the attacker determine which individual computers on the network are alive and potential targets for attack. Port scanning can be used to determine what ports (a port is like a door or window on a house) are open on a given computer, and whether or not the software managing those ports has any obvious vulnerabilities.

Enumeration.
The third phase is the process of identifying user accounts and poorly protected computing resources. During the enumeration stage, the hacker connects to computers in the target network and pokes around these systems to gain more information. While the scanning phase might be compared to a knock on the door or a turn of the doorknob to see if it is locked, enumeration could be compared to entering an office and rifling through a file cabinet or desk drawer for information. It is definitely more intrusive.

Penetration.
During the fourth phase, penetration, the attacker attempts to gain control of one or more systems in the target network. For example, once an attacker has acquired a list of usernames during enumeration, he can usually guess one of the users’ passwords and gain more extensive access to that user’s account. Alternatively, once the attacker has determined that a target computer is running an old or buggy piece of software or one that is configured improperly, the hacker may attempt to exploit known vulnerabilities with this software to gain control of the system.

Advance.
In the advance phase of hacking, the attacker leverages computers or accounts that have been compromised during penetration to launch additional attacks on the target network. For instance, the attacker can break into more sensitive administrator root accounts, install backdoors or Trojan horse programs, and install network sniffers to gather additional information (for example, passwords) from data flowing over the network.

Covering Tracks.
In the final phase of hacking, the hacker eliminates any records or logs showing his malicious behavior. By deleting log files, disabling system auditing (which would otherwise alert the administrator to malicious activities), and hiding hacking files that the hacker has introduced, he can cover his tracks and avoid detection. Finally, the hacker can install a root kit—a series of programs that replace the existing system software to both cover his tracks and gather new information.

Thursday, 23 October 2014

Remove Android Patter Lock Instantly


Note – This method involves wiping off all data on your phone, including installed apps and the setting you have done.

1.) Turn the phone off the phone.

2.) Long press the upper volume key, menu key and the power key simultaneously relieve for a fraction as soon as you see the screen display in “Samsung Galaxy Y young” again press the 3 keys simultaneously.

3.) Now you will see a screen displaying “Android system Recovery”

4.) select the 3rd option (“Wipe data/factory reset“) using the volume keys and press the centre menu key

5.) select the “Yes” option again using the same keys.

6.)after some time, it will say, the reset is done

7.) just select the reboot option and your phone is UNLOCKED.


Though it will wipe all your data, I find it relevant as it saves some of your bucks. It’s done…!!!

Friday, 12 September 2014

5 Million Gmail Usernames and Passwords Leaked online, Check Yours Now



Gmail credentials leaked online? Oh my God! Again I have to change my password…!! Yes, you heard right. Millions of Gmail account credentials (email address and password) have been stolen and made publicly available through an online forum, causing a large number of users worldwide to change their Gmail password again.


The website that published the email addresses with matching passwords is Russian. The credentials seem to be old and likely sourced from multiple data breaches. It is believed that the leaked passwords are not necessarily those used to access Gmail accounts, but seem to have been gathered from other websites where users used their Gmail addresses to register.



5 MILLION GMAIL CREDENTIALS LEAKED ONLINE

The news broke when a user posted a link to the log-in credentials on Reddit frequented by hackers, professional and aspiring. But the archive file containing nearly 5 million Gmail addresses and plain text passwords was posted on Russian Bitcoin security forum known as btcsec.com on Tuesday night by a user with the online alias “TV skit”, according to C News, a Russian news outlet.



The user who exposed Gmail users’ credentials said that almost 4.93 million accounts allegedly affected belong to English, Russian and Spanish users and claimed that over 60 percent of accounts are active.



This means, there is a silver lining in this leak, i.e., 40 percent of the passwords are invalid or out of date, which could be a good news for those Gmail users who have recently changed their passwords and are concerned about their account’s security – there’s a chance that they’re not at risk at all.



"We can't confirm that it is indeed as much as 60 percent, but a great amount of the leaked data is legitimate," said Peter Kruse, the chief technology officer of CSIS Security Group.



GOOGLE SAYS NO SECURITY BREACH

Google, on its part, believes that the usernames and passwords didn't come from a security breach of its system. That means, the credentials had been stolen by phishing campaigns and unauthorized access to user accounts.


"It’s important to note that in this case and in others, the leaked usernames and passwords were not the result of a breach of Google systems," Google, which operates Gmail email service, explained in a post on its online security blog. "Often, these credentials are obtained through a combination of other sources."



"We found that less than 2% of the username and password combinations might have worked, and our automated anti-hijacking systems would have blocked many of those login attempts. We've protected the affected accounts and have required those users to reset their passwords."


The leaked passwords not only give access to users’ Gmail accounts, but other Google services as well, including Google Drive, and the mobile payment system Google Wallet.



CHECK IF YOU ARE AFFECTED

A website called isleaked.com allows users to check if their email address is among those leaked. People who are concerned about the security of their account are advised to go ahead and change their password.


I already have Google two-factor authentication (2FA) enabled and recommend you same to do this for Google and other accounts. Many web services, including Gmail, Facebook, Twitter, Dropbox, GitHub and AWS, offer 2FA option, a security measure where users are required to provide a passcode sent to their mobile devices before any changes can be made to their account. This would prevent an attacker from logging in without access to a user’s smartphone.


Saturday, 9 August 2014

Millions of WordPress & Drupal websites are vulnerable to DoS Attack

Users running the website on a self-hosted WordPress or on Drupal are strongly recommended to update their websites to the latest version immediately.

A moderately critical vulnerability was discovered in the way Drupal and WordPress implement XMLRPC, which can lead an attacker to disable your website via a method known as Denial of Service (DoS).

VULNERABILITY RESULTS IN DoS ATTACK
The latest update of WordPress 3.9.2 mainly addresses an issue in the PHP’s XML processor that could be exploited to trigger a DoS (denial of service) attack. The vulnerability affects all previous versions of WordPress.

The XML vulnerability was first reported by Nir Goldshlager, a security researcher from Salesforce.com's product security team that impacts both the popular website platforms. The issue was later fixed by Michael Adams and Andrew Nacin of the WordPress security team and David Rothstein of the Drupal security team.

ATTACK MAKES YOUR WEBSITE COMPLETELY INACCESSIBLE
The vulnerability makes use of a well-known cyber-attack, XML Quadratic Blowup Attack. When executed, it has the capability to take down the whole website or server almost instantly, with the use of only a single machine.

The XML vulnerability can cause complete CPU and memory exhaustion and the site’s database to reach the maximum number of open connections, and as a result, the vulnerable site and server become unavailable for a period of time, hence affecting Availability of your website.

In short, when the vulnerability is exploited, your website and web server can become totally inaccessible.

WORDPRESS AND DRUPAL USED BY MILLIONS OF WEBSITES
The issue is actually serious because WordPress and Drupal is being used by millions of websites. The recent statistics from the World Wide Web Consortium (WC3) says that WordPress alone powers nearly 23% of the web, and over one million websites used by Drupal.

WordPress is a free and open source blogging tool and a content management system (CMS) with more than 30,000 plugins, each of which offers custom functions and features enabling users to tailor their sites to their specific needs, therefore it is easy to setup and use, that’s why tens of millions of websites across the world opt it.

HOW EXPLOIT WORKS

As explained earlier, the XML vulnerability makes use of an XML Quadratic Blowup Attack, which is almost similar to a ‘Billion Laughs Attacks’ that allows a very small XML document to completely disrupt the services on machine in a matter of seconds.

The XML Quadratic Blowup Attack exploits the use of entity expansion, instead of using nested entities inside an XML document, it replicates one large entity with tens of thousands of characters over and over again.

In this type of attack, a medium-sized XML document of nearly two hundred kilobytes in size could require within the range of hundreds of megabytes to several gigabytes of memory. That if exploited by an attacker, could easily bring down an entire website or web server.


Friday, 1 August 2014

Introducing Operation Emmental: A new banking malware causing havoc around the world


A new piece of banking malware called "Operation Emmental" is targeting banks around the world, particularly in countries like Switzerland and Austria.
Operation Emmental, apparently so-named due to the full-of-holes security systems of many major banks, is designed to bypass the generic two-factor authentication mechanism that banks employ to ensure that their customers' money remains safe.
The Operation Emmental attacks are spread using phishing emails, which masquerade as legitimate mail in order to coax a user into clicking a booby-trapped link.
The attacks bypass session tokens sent by a bank's remote server to users' mobile devices via text messaging. Customers preferring to bank online are required to mandatorily enter these session tokens, to start new sessions and verify/authenticate the login credentials.
The infrastructure required to pull the attack off is not inconsequential, however. The attackers need a Windows malware binary, a malicious Android app sporting various banks' logos, a rogue DNS resolver server, a phishing Web server with several fake bank site pages, and a compromised C&C server to successfully pull off an Operation Emmental strike.
"Emmental is an attack that has very likely evolved over time," according to Trend Micro. "The fact that the most salient part of the attack—the PC malware—is not persistent likely helped the attackers keep a low profile."
"We believe this allowed them to use different infection strategies, not just through emails".

Banking malware Zeus caused chaos over the years it was active, infecting 3.6 million PCs in the United States alone, and stealing millions of pounds from banks around the world, including in the UK. It is most often used to steal banking information through man-in-the-browser keystroke logging and form grabbing. It is also used to install the CryptoLocker ransomware
More recently, a new premium piece of malware called Kronos has begun to be advertised on a Russian cybercriminal forum, it's capable of stealing credentials from browsing sessions in Internet Explorer, Mozilla Firefox and Google Chrome by using form-grabbing and HTML content injection techniques.