Showing posts with label security news. Show all posts
Showing posts with label security news. Show all posts

Friday, June 28, 2013

Update Your FIREFOX to FIX the four critical SECURITY holes

  • Friday, June 28, 2013
  • asd
  • Mozilla has released the Firefox version 22 that addresses more than 10 Security vulnerabilities.


    Four Critical security bugs including "Execution of unmapped memory through onreadystatechange event", "Privileged content access and execution via XBL", "Memory corruption found using Address Sanitizer" and "Miscellaneous memory safety hazards" have been fixed in the latest version.

    Six High level security bugs including "Inaccessible updater can lead to local privilege escalation", "XrayWrappers can be bypassed to run user defined methods in a privileged context", "Data in the body of XHR HEAD requests leads to CSRF attacks" also have been fixed.

    Users are recommended to update their Firefox to the latest one.
    read more

    Friday, May 31, 2013

    Drupal hacked, resets passwords after millions of accounts exposed

  • Friday, May 31, 2013
  • asd
  • Passwords for almost one million accounts on the Drupal.org website are being reset after hackers gained unauthorized access to sensitive user data.
    Drupal.org is the official website for the popular open-source content management platform. The breach is the result of an attack that exploited a vulnerability in an undisclosed third-party application, not in Drupal itself, Holly Ross, executive director of the Drupal Association, wrote in a blog post published Wednesday. The hack exposed usernames, e-mail addresses, country information, and cryptographically hashed passwords, although investigators may discover additional types of information were compromised.
    "Malicious files were placed on association.drupal.org servers via a third-party application used by that site," Ross wrote. "Upon discovering the files during a security audit, we shut down the association.drupal.org website to mitigate any possible ongoing security issues related to the files. The Drupal Security Team then began forensic evaluations and discovered that user account information had been accessed via this vulnerability."

    There's no indication credit card data was intercepted. There's also no evidence that any unauthorized changes were made to Drupal source code or projects.

    Drupal.org administrators have responded by rebuilding production, staging, and development systems and enhancing most servers with grsecurity, a set of security patches for the Linux operating system. The admins have also hardened their configuration of the Apache Web server application and added antivirus scanning to their security routine. Some Dupal.org subsites, particularly those with older content, have been converted to static archives so they can't be updated in the future.

    Drupal.org account holders will be required to change their password by visiting this link, entering their username or e-mail address, and following the link included in the e-mail message that follows. Ross also encouraged account holders to change login credentials on other sites that used the same or a similar password used on Drupal.org.

    Most of the passwords stored by Drupal.org were both salted and, more importantly, passed through a cryptographic hash function multiple times using the open-source phpass application. Some older passwords weren't salted. If Drupal engineers followed good practices—and there's no indication they didn't—the repeated hash iterations will go a long way to preventing anyone who obtains the data from quickly cracking the hashes and exposing the underlying plaintext that generated them. (Cryptographic salting, which appends unique characters to each password before it's hashed, is also helpful, although people frequently overstate the protection it provides. For much more on password protection see the Ars feature Anatomy of a hack: How crackers ransack passwords like “qeadzcwrsfxv1331”.)

    Ross didn't identify the exploited third-party application. Given Drupal.org's use of Apache, it's possible the site was compromised by the same attack that has plagued at least 20,000 other sites in recent weeks. Researchers still don't know how attackers are gaining almost unfettered, "root" access on these servers, but the same backdoor, often known as Linux/Cdorked, more recently started compromising sites that run on the nginx and Lighttpd Web servers too.

    The hacks are underscoring the growing vulnerability of websites to serious malware attacks. On Tuesday, evidence emerged that servers running the Ruby on Rails framework were being compromised and made part of a botnet. The attackers in that case were exploiting an extremely critical vulnerability that was patched in early January.

    Drupal's front page states there are 967,545 people in 228 countries (speaking 181 languages) using the platform.
    read more

    Thursday, May 30, 2013

    Chinese hackers breach key US weapons designs

  • Thursday, May 30, 2013
  • asd
  • The Washington Post is reporting that the designs for many of the U.S.’s “most sensitive advanced weapons systems have been compromised by Chinese hackers.”

    While the U.S. has started to increase its pressure on China, it is a dollar short and a day late. Rather than allow state-sponsored hackers to continue to harm U.S. national and economic security, the U.S. needs to take stronger actions to deter future cyber aggression.
    The new report by the Defense Science Board lists at least 29 specific weapons system designs that were stolen by hackers. These included several missile defense systems, such as the Aegis Ballistic Missile Defense System, the Terminal High Altitude Aerial Defense, and the Patriot Advanced Capability-3. Aircraft, such as the F-35 and F/A 18 fighter planes, the C-17 cargo plane, and the UH-60 Black Hawk Helicopter, were compromised, as were the Navy’s new Littoral Combat Ship and several information and control systems.

    According to those familiar with these hacks, the vast majority are part of an ongoing and growing Chinese cyber-espionage campaign to steal U.S. technologies, advance Chinese weapons development, and then turn them against their creators. Earlier this year, the security firm Mandiant also identified a specific bureau of the Chinese military as responsible for stealing huge amounts of data from U.S. companies over the past seven years. Taken together with countless other confirmed and suspected Chinese hacks, clearly the U.S. should do more to stop cyber aggression.

    First, the U.S. should continue to name and shame China. This will mean issuing more reports that identify China as a bad cyber actor and then having U.S leaders use this information to call out China in speeches and diplomatic discussions. While the U.S. is starting to actually put the blame on China in some of its reports, our leaders continue to naively treat China as a cyber ally.

    In April, the highest-ranking American military officer, chairman of the Joint Chiefs General Martin Dempsey, stated that the U.S. sought “collaboration and transparency” with China, since “cyber threatens our economy and [the Chinese] economy.” U.S. leaders should be pointing the finger at the Chinese instead of inviting them to steal U.S. secrets.

    Second, the U.S. should actually take a tougher line on China by ceasing to cooperate with China on cybersecurity. The U.S. should not be engaging in cyber war games and cyber exchanges with the Chinese when they are merely using that information to learn how to do a better job hacking U.S. systems. Continuing to collaborate with China only proves that the U.S. knows about the problem but lacks the will to do anything about it, thus further emboldening China. The U.S. should also consider working with allies to take economic and legal actions against Chinese companies that peddle stolen property.

    U.S. military and business secrets are being stolen as part of an extensive cyber campaign by the Chinese to advance their weapons capabilities and economy. The U.S. should stand up to China and make them feel pain when they steal U.S. secrets. Failing to do so would further endanger U.S. national security and economic growth.
    read more

    Monday, May 27, 2013

    Sky News Google Play page defaced

  • Monday, May 27, 2013
  • asd
  • Sky News seems to have a habit of letting its credentials escape into the outside world, apparently letting the Syrian Electronic Army get its paws on its Google Play admin account.
     
    As a result, it's had the embarrassment of having the Sky News app screenshots in Google Play replaced with an announcement that “The Syrian Electronic Army Was Here”.

    To rub salt into the wound, the company's help desk Twitter account was also taken over to send out a message stating “Both Sky+ and SkyNews Android apps were replace, please uninstall”. However, that claim may have exaggerated the extent of the attack, since it seems more likely at this stage to be a case of the SEA putting its graffiti on the Google Play store page for the Sky News apps.

    The account takeover also included redirecting the developer help e-mail account to the SEA.

    It's not the first time Sky News has been embarrassed by being careless with security. Earlier in May 2013, one of its Twitter accounts was compromised to post “Colin was here”. In 2009, a Web petition being run by the broadcaster was defaced.
    The Register has contacted Sky News seeking further information on the attack, but has yet to receive a response. ®
    read more

    Monday, May 20, 2013

    Hacker jailed for ATM skimming invented ATM security scheme

  • Monday, May 20, 2013
  • asd
  • A Romanian man serving a five-year jail sentence for bank-machine fraud says he's come up with a device that can be attached to any ATM to make the machine invulnerable to card skimmers.

    Valentin Boanta was arrested in 2009 and charged with supplying ATM skimmers – devices that can be attached to ATMs to surreptitiously copy the data from unwitting users' cards – to a local organized crime gang.

    It was during his subsequent trial and sentencing that Boanta saw the light and traded in his black hat for a white one, Reuters reports.

    "Crime was like a drug for me. After I was caught, I was happy I escaped from this adrenaline addiction," Boanta told reporters from his jail cell in Vaslui, Romania. "So that the other part, in which I started to develop security solutions, started to emerge."

    Boanta's solution, known as the Secure Revolving System (SRS), is an ingenious one that uses mechanical rather than digital security.

    ATM skimmers work by installing a second, concealed card reader over the one that's built into the ATM. When an unsuspecting bank customer inserts a card into the slot, the card's magnetic stripe first runs past the read head of the skimmer, allowing it to copy all of the card's data. The transaction then proceeds as normal and the ATM returns the card to the customer, who is none the wiser.

    With Boanta's device installed on the ATM, however, that all changes. Customers insert their cards into the slot long side first, so that the magnetic stripe is parallel to the face of the machine. The device then rotates the card 90 degrees into the ATM, where the legitimate card reader scans the magnetic stripe, then rotates it back out again to return it to the customer.

    That rotation makes it impossible for an add-on skimmer to read the card, because the magnetic stripe never moves in a straight line until it is secure inside the ATM.

    While awaiting the outcome of his trial, Valentin pitched his idea to Mircea Tudor and Adrian Bizgar of Bucharest-based technology firm MB Telecom, who helped him to patent his idea and funded development of the SRS device.

    The design would go on to win the International Press Prize at the 41st International Exhibition of Inventions in Geneva, Switzerland, in April. Boanta, however, wasn't available to accept the award. He's currently just six months into his sentence and won't see freedom for another four and a half years. Still, his partners at MB Telecom say all credit for the SRS design should go to him.

    "He fully deserves such recognition," Tudor told Reuters. "He's taking part in improving Romania's image abroad and he'll surely join our team when released."

    MB Telecom is currently finalizing details of the commercial version of the device and expects to bring it to market in the second half of the year
    read more

    Sunday, May 19, 2013

    Yahoo Japan suspects 22 million user IDs stolen

  • Sunday, May 19, 2013
  • asd
  • Unauthorized access attempt of Yahoo! Japan portal may have led to theft of up to 22 million user IDs, Yahoo has revealed.
    There has been no information about leaks of such a massive database of user IDs as yet and according to Yahoo, the information that was stolen didn’t have passwords or any other information that would allow unauthorized users to carry out user identity verification. 

    Yahoo hasn’t ruled out the possibility of a leak though considering the volume of traffic it noticed flowing from its servers to external entities.

    Following the alleged breach, Yahoo has revealed that it has beefed up its security controls to avert any such future attempts. Yahoo is the top most search provider when it comes to Japan with over 50 per cent market share. Google holds 40 per cent market share in comparison.

    Japan has already acknowledged that the country lags behind in cyber security plans specifically in the preventative aspects that would otherwise deter such attacks.

    Why Yahoo! Japan?

    Yahoo! Japan is controlled by Japan’s mobile phone operator SoftBank (35.5%) and  Yahoo! Inc (34.7%), what is interesting is the market share of the portal Yahoo! Japan that holds 50% of the top search engine position in Japan, a figure superior to the Google concurrence at 40%, it’s clear that the corporation represents a privileged target of cyber criminals and state-sponsored hackers.

    Which information has been stolen exactly?

    According first investigation it seems that the exposed information doesn’t include any data that could be used to identify the user’s identity or that could be exploited successively to force password reset.

    Yahoo! has immediately started the incident response procedure adopting any countermeasure to prevent further incidents.

    On the case is also working the Japan’s national police agency that recently announced the  launch an investigation team specialized in cybercrimes, let’s remind that in the last years the Japan has been hit by a huge quantity of cyber attacks that interested the Japan Aerospace Exploration Agency, Sony and Government itself.
    read more

    Thursday, May 16, 2013

    Critical Linux vulnerability imperils users, even after “silent” fix

  • Thursday, May 16, 2013
  • asd

  • For more than two years, the Linux operating system has contained a high-severity vulnerability that gives untrusted users with restricted accounts nearly unfettered "root" access over machines, including servers running in shared Web hosting facilities and other sensitive environments. Surprisingly, most users remain wide open even now, more than a month after maintainers of the open-source OS quietly released an update that patched the gaping hole.
    The severity of the bug, which resides in the Linux kernel's "perf," or performance counters subsystem, didn't become clear until Tuesday, when attack code exploiting the vulnerability became publicly available (note: some content on this site is not considered appropriate in many work environments). The new script can be used to take control of servers operated by many shared Web hosting providers, where dozens or hundreds of people have unprivileged accounts on the same machine. Hackers who already have limited control over a Linux machine—for instance, by exploiting a vulnerability in a desktop browser or a Web application—can also use the bug to escalate their privileges to root. The flaw affects versions of the Linux kernel from 2.6.37 to 3.8.8 that have been compiled with the CONFIG_PERF_EVENTS kernel configuration option.
    "Because there's a public exploit already available, an attacker would simply need to download and run this exploit on a target machine," Dan Rosenberg, a senior security researcher at Azimuth Security, told Ars in an e-mail. "The exploit may not work out-of-the-box on every affected machine, in which case it would require some fairly straightforward tweaks (for someone with exploit development experience) to work properly."
    The fix to the Linux kernel was published last month. Its documentation did not mention that the code patched a critical vulnerability that could jeopardize the security of organizations running Linux in highly sensitive environments. This lack of security advisories has been standard practice for years among Linus Torvalds and other developers of the Linux kernel—and has occasionally been the subject of intense criticism from some in security circles.
    Now that a fix is available in the kernel, it will be folded into all of the affected stable kernel releases offered by kernel.org, which maintains the Linux core code. Individual distributions are expected to apply the fix to their kernels and publish security updates in the coming days.
    Additional details of the bug are available hereherehere, and here. People running vulnerable machines with untrusted user accounts should check with their distributors to find out when a patch will be available and what steps can be taken in the meantime. One user of a Red Hat Linux distribution posted temporary mitigation steps here, although at time of writing, Ars was unable to confirm that they worked. Readers are encouraged to post other mitigation advice in comments.
    read more

    Firefox 21 Fixes 3 Critical Flaws, Introduces New Health Report

  • asd

  • Mozilla fixed eight vulnerabilities, three critical, in the 21st build of its flagship Firefox browser yesterday.
    One of the fixes remedies an Address Sanitizer memory corruption flaw (MFSA 2013-48) that could’ve allowed remote code execution. The other two critical flaws could’ve also led to arbitrary code execution and deal with fixing memory safety bugs (MFSA 2013-41), and a video resizing bug (MFSA 2013-46) in Firefox and Thunderbird.

    For a complete list of the bugs fixed by Firefox 21, all 681 of them, head to Bugzilla.

    The latest version of the browser also introduces something Mozilla is calling the Firefox Health Report, a tool that aims to give users a comprehensive look into the browser’s health and usage. The report will breakdown any insecure and unstable plugins it blocks throughout the day and will also document crash history and malware attack history, according to a post on Mozilla’s Future Releases blog by Jonathan Nightingale, the company’s Vice President of Engineering.

    Users can choose whether they want the tool to share data Mozilla gathers about their browser with the company. If shared, the information will be aggregated and anonymized and used to help Firefox’s security team improve the browser. Users can change their preferences in the Data Choices section of the browser’s Options menu.

    The update also brings expanded social API and Do Not Track options to help users better customize their privacy settings.

    The social API opens the browser up to sidebar and toolbar providers like Cliqz, msn NOW and Mixi, while the Do Not Track update tweaks an already existing setting in the browser. The new default privacy setting doesn't tell websites anything about the users’ tracking preferences. Users can change that and choose whether they want to tell sites if they want to be tracked (Do Track, Do Not Track, No Preference) in the settings.

    The updates are being pushed to Firefox users via the browser’s automatic update system, per usual. Those who don’t have that set up can download them through both the Firefox and Thunderbird download pages.
    read more