Showing posts with label D'oh. Show all posts
Showing posts with label D'oh. Show all posts

Friday, March 16, 2012

Geotagging Poses Security Risks

Via US Army Homepage (Cheryl Rodewig) -

The question was posed by Brittany Brown, social media manager of the Online and Social Media Division at the Office of the Chief of Public Affairs. It may sound outlandish, but in the age of social geotagging, it can be a reality.

There are a number of location-based social media applications and platforms, including Foursquare, Gowalla, SCVNGR, Shopkick, Loopt and Whrrl, currently on the market. They use GPS features, typically in the user's phone, to publish the person's location and offer rewards in the form of discounts, badges or points to encourage frequent check-ins.

Security risks for the military:

A deployed service member's situational awareness includes the world of social media. If a Soldier uploads a photo taken on his or her smartphone to Facebook, they could broadcast the exact location of their unit, said Steve Warren, deputy G2 for the Maneuver Center of Excellence, or MCoE.

"Today, in pretty much every single smartphone, there is built-in GPS," Warren said. "For every picture you take with that phone, it will automatically embed the latitude and longitude within the photograph."

Someone with the right software and the wrong motivation could download the photo and extract the coordinates from the metadata.

Warren cited a real-world example from 2007. When a new fleet of helicopters arrived with an aviation unit at a base in Iraq, some Soldiers took pictures on the flightline, he said. From the photos that were uploaded to the Internet, the enemy was able to determine the exact location of the helicopters inside the compound and conduct a mortar attack, destroying four of the AH-64 Apaches.

[...]

Ways to stay safe:

"In operations security, we talk about the adversary," said Kent Grosshans, MCoE OPSEC officer. "The adversary could be a hacker, could be terrorists, could be criminals; someone who has an intent to cause harm. The adversary picks up on pieces of information to put the whole puzzle together."

Grosshans suggests disabling the geotagging feature on your phone and checking your security settings to see who you're sharing check-ins with.

"If your husband's deployed and you go ahead and start posting all these pictures that are geotagged, now not only does an individual know your husband's deployed and he's not at home, but they know where your house is," he said.

Ultimately, it's about weighing the risks.

"Do you really want everyone to know the exact location of your home or your children's school?" Sweetnam said. "Before adding a location to a photo, Soldiers really need to step back and ask themselves, 'Who really needs to know this location information?'"

Grosshans said it's as important to Soldiers as to family members.

"Be conscious of what information you're putting out there," he said. "Don't share information with strangers. Once it's out there, it's out there. There's no pulling it back."

Tuesday, December 6, 2011

Downed RQ-170 Drone Was On CIA Mission

Via CNN's Security Clearance Blog -

A stealth US drone that crashed in Iran last week was part of a Central Intelligence Agency reconnaissance mission which involved both intelligence community and military personnel stationed in Afghanistan, two U.S. officials tell CNN. The officials said they did not believe the mission involved flying the drone directly over Iran because the reconnaissance capability of the RQ-170 drone allows it to gather information from inside Iran while remaining on the Afghanistan side of the border. The officials also for the first time acknowledged to CNN it was an RQ-170 drone that was lost.

When the drone crashed in Iran late last week, the U.S. briefly considered all potential options for retrieving the drone or bombing the wreckage, according to a third official. But those ideas were relatively quickly discarded as impractical, the official said. There was also satellite surveillance over the site which helped confirm the location of the wreckage before the Iranians retrieved it.

All of the officials have direct knowledge of the events, but spoke on the condition of anonymity because of sensitive intelligence matters. CIA officials have declined to comment.

Thursday, October 13, 2011

US Air Force: Flying Operations of Remotely Piloted Aircraft Unaffected by Malware

http://www.afspc.af.mil/news1/story.asp?id=123275647

To correct recent reporting, the malware detected on stand-alone systems on Creech Air Force Base, Nev., in September, has not affected Remotely Piloted Aircraft operations.

On 15 September, 24th AF first detected and subsequently notified Creech AFB regarding the malware on their portable hard drives approved for transferring information between systems. It was detected and isolated by the 24th Air Force using standard tools and processes for monitoring and protecting Air Force computer systems and networks. The Air Force then began a forensic process to track the origin of the malware and clean the infected systems.

The malware was detected on a stand-alone mission support network using a Windows-based operating system. The malware in question is a credential stealer, not a keylogger, found routinely on computer networks and is considered more of a nuisance than an operational threat. It is not designed to transmit data or video, nor is it designed to corrupt data, files or programs on the infected computer. Our tools and processes detect this type of malware as soon as it appears on the system, preventing further reach.

The infected computers were part of the ground control system that supports RPA operations. The ground system is separate from the flight control system Air Force pilots use to fly the aircraft remotely; the ability of the RPA pilots to safely fly these aircraft remained secure throughout the incident.

"It's standard policy not to discuss the operational status of our forces," said Colonel Kathleen Cook, spokesperson for Air Force Space Command. "However, we felt it important to declassify portions of the information associated with this event to ensure the public understands that the detected and quarantined virus posed no threat to our operational mission and that control of our remotely piloted aircraft was never in question."

"We continue to strengthen our cyber defenses, using the latest anti-virus software and other methods to protect Air Force resources and assure our ability to execute Air Force missions. Continued education and training of all users will also help reduce the threat of malware to Department of Defense systems."


------------------------------------------------------------------

Some of the recent reporting, they were looking to correct....

Tuesday, September 20, 2011

Testing Web Servers for Slow HTTP Attacks

Via Qualys Security Labs -

Following the release of the slowhttptest tool, I ran benchmark tests of some popular Web servers. My testing shows that all of the observed Web servers (and probably others) are vulnerable to slow http attacks in their default configurations. Reports generated by the slowhttptest tool illustrate the differences in how the various Web servers handle slow http attacks.

[....]

Final Thoughts

Software configuration is all about tradeoffs, and it is normal to sacrifice one aspect for another. We see from the test results above that all default configuration files of the Web servers tested are sacrificing protection against slow HTTP DoS attacks in exchange for better handling of connections that are legitimately slow.


Because a lot of people are not aware of slow http attacks, they will tend to trust the default configuration files distributed with the Web servers. It would be great if the vendors creating distribution packages for Web servers would pay attention to handling and minimizing the impact of slow attacks, as much as the Web servers’ configuration allows it. Meanwhile, if you are running a Web server, be careful and always test your setup before relying on it for production use.

Thursday, July 7, 2011

Phishers’ World in Your Cell Phone

Via Symantec Uber Security Response Blog -

Technologies in cell phones are advancing day after day, and so phishers are also seeking various means to exploit vulnerable cell phone users. The two key areas in which we can see this trend are, firstly, the increase in phishing against wireless application protocol (WAP) pages, and secondly, the use of compromised domain names that have been registered for mobile devices.

Many legitimate brands have designed their websites for cell phones or WAP pages. The difference between a WAP page and a regular Web page is that the WAP page uses reduced file sizes and minimal graphics. This is done for cell phone compatibility and also to achieve higher browsing speeds while the user is on the move. Symantec has recorded phishing sites spoofing such Web pages and has monitored the trend. In June, social networking and information services brands were observed in these phishing sites. In the example shown below, the phishing page consists of nothing more than a form asking for users’ credentials. (This is a typical design created for cell phones.) When a victim enters the required information, the phishing page is redirected to the WAP page of the legitimate brand. The phishing site in this case was hosted on a free Web hosting site.

[...]

The domain names used for websites accessed by mobiles devices commonly have a “.mobi” top level domain (TLD). These domain names are compromised and utilized by phishers to host several phishing sites. Over the past six months, about 65 percent of these phishing sites spoofed brands from the banking sector, whereas 19 percent were from the e-commerce sector and the remaining were from the ISP, social networking, and information services sectors.

The primary motive of phishers in these attacks continues to be identity theft. Targeting cell phone users is just part of a new strategy for achieving the same result.


---------------------------------------------------------------------------

In January 2011, Trusteer, makers of the Rapport security software, gained access to the log files of several web servers that were hosting phishing websites. Analysis of these logs yields some interesting insight:
  1. Mobile users are the first to arrive at the phishing website
  2. Mobile users accessing phishing websites are three times more likely to submit their login info than desktop users
  3. Eight times more iPhone users accessed these phishing websites than Blackberry users
While the data obtained by Trusteer is quite limited in scope, it does seem to reinforce the concern expressed by Symantec above – mobile phone users are as susceptibility (likely more susceptibility) to phishing as desktop users.

Compound that idea with the current lack of mobile phone security suites in general use (e.g. Anti-virus, Anti-phishing, etc) and you have a massive unprotected userbase which is more likely to act in a dangerous manner when mobile.

Tuesday, June 14, 2011

Assessing the Risk of the Microsoft's June Security Updates

Terminology - Microsoft releases "bulletins" which contain fixes or patches for individual vulnerabilities. It isn't uncommon to see people call a single bulletin (MS11-050) a "patch", but it is important to remember that, most of the time, a single bulletin addresses many vulnerabilities.

----------------------------------------------------------------------------

This month, the number of bulletins rated critical was nine, which is the exact number outlined in the advanced notification.

However, the exploitability index number was divided into two separate numbers recently - 
  • Exploitability Index for Latest Software Release (Windows 7 & 2008 R2)
  • Exploitability Index for Older Software Releases (Windows XP)

According to today’s bulletin summary, CVE-2011-1262 (part of MS11-050) has an exploitability index of “2” for new operating systems and an exploitability index of “1” for older operation systems. New operating systems have more mitigation layers (Default DEP, ASLR, UAC, etc) and therefore are less vulnerable than older operating systems. The summary table list details for each vulnerability in each bulletin.

While the SRD table is just combining all the individual vulnerability data and listing the “max” severity rating and "max" exploitability rating (in this case, the lowest – since lower is more exploitable) for each bulletin as a whole.

Given all of this, I would say the numbers in the SRD table seems to be the safest route when assessing the risk.

Thursday, June 2, 2011

Apple to Malware Authors: Tag, you're It!

Via NakedSecurity.com (Sophos) -

Last night the malware authors behind the Mac Guard fake anti-virus changed their methods again to bypass the updates Apple released yesterday afternoon to protect OS X Snow Leopard users. Apple fired back shortly after 2 p.m. Pacific Daylight Time today with a new update to XProtect. Computers that have Apple update 2011-003 for Snow Leopard now check for updates every 24 hours.

As the cat-and-mouse game continues it will be interesting to see how the attackers proceed. The major change to bypass Apple's detection yesterday was to use a small downloader program to do the initial infection, then have that program retrieve the actual malware payload.

This approach may be successful as it will be easier for the malware authors to continually make small changes to the downloader program to evade detection while leaving the fake anti-virus program largely unchanged.

Why is this important? Apple's XProtect is not a full anti-virus product with on-access scanning. XProtect only scans files that are marked by browsers and other tools as having been downloaded from the internet.

If the bad guys can continually mutate the download, XProtect will not detect it and will not scan the files downloaded by this retrieval program. Additionally, XProtect is a very rudimentary signature-based scanner that cannot handle sophisticated generic update definitions.


---------------------------------------------------------------------------

These criminals behind the FakeAV scams are rapidly adapting in order to protect a real revenue stream, therefore it is highly unlikely they will walk away without a serious fight.

Apple is allowing itself to be pulled into a cat-and-mouse game of malicious whack-a-mole. A game which highlights the well-known weakness of pure signature-based detection. This is a lesson AV companies learned long long ago.

Apple's XProtect isn't up for the battle and in short order, updates every 24 hours won't be enough....a full-time scanning solution will be needed - enter on-access AV on Apple.

Wednesday, June 1, 2011

Apple Adds Daily Malware Updates to OS X, Attackers Adapt Quickly

Via Threatpost.com -

Apple on Tuesday shipped the promised update to help remove the MacDefender malware, and in a surprise move, also added functionality to Mac OS X that will now check for new malware definitions daily.

The move by Apple to add daily malware checks is a significant shift in the way that the company handles malware and potential infections of its customers. Until now, Apple has handled such incidents on a case by case basis and pushed OS changes when it needed to address a new problem. But now the company has essentially included an auto-updating anti-malware system with OS X.

The security update that Apple released Tuesday performs several specific tasks. It adds a new definition to the existing anti-malware checks in OS X, and also will automatically remove any instances of the MacDefender malware that it finds on the machine. But most significantly, security update 2011-003 adds the automatic daily checks for new malware signatures.


----------------------------------------------------------------------------

Apple's move to add daily update ability to its anti-malware XProtect List means it will be better suited to react to future variants of Apple malware.

However, there are now reports, the criminals adapted within hours and are now pushing out a new MacDefender FakeAV variant which bypasses the original signature protection from Apple.

The next move is on Apple - will it allow it to be pulled into a game of whack-a-mole with monetized crimeware or will it finally suggest all users install AV?

Thursday, May 26, 2011

DNS Filtering Legislation Would Derail DNSSEC, Experts Contend

Via DarkReading.com -

A key provision in an intellectual property protection bill that was approved today by the Senate Judiciary Committee could sabotage Internet security and specifically, DNSSEC, according to a who's who of Internet infrastructure and security experts including Dan Kaminsky.

The PROTECT (Preventing Real Online Threats to Economic Creativity and Theft of Intellectual Property Act) IP Act calls for using recursive DNS servers to blacklist and block domain names of servers offering pirated music or other illegally obtained intellectual property. A group of renowned Internet security experts including Kaminsky released a white paper explaining how forcing these millions of recursive servers on the Internet to filter out DNS requests to those sites would basically cripple the emerging DNSSEC technology. DNSSEC is currently in the process of being adopted on the Internet; it provides verification that the site a user visits is indeed that site and not a spoofed or redirected one.

Along with Kaminsky, who discovered and helped get patched a serious flaw in DNS, the authors of the paper include Steve Crocker, an IETF pioneer and CEO of Shinkuro; David Dagon, a post-doctoral researcher at Georgia Institute of Technology studying DNS security and a co-founder of Damballa; Danny McPherson, chief security officer for Verisign; and Paul Vixie, principal author of the pervasive BIND DNS server software and creator of several DNS standards.

The authors say they support enforcement intellectual property rights, but that the DNS filtering requirement would stymie federal government and private industry efforts for beefing up Internet security -- namely DNSSEC. And the filters could easily be bypassed and therefore would likely be unable to quell online copyright infringement, they say.

"It's like trying to make a telephone that won't carry swear words," Kaminsky says of the DNS-filtering approach.

They maintain that the DNS filtering—which would force the censoring of websites via blacklists published by the Department of Justice--would clash with DNSSEC by encouraging the brand of network manipulation that DNSSEC aims to prevent.

[...]

A full copy of the "Security and Other Technical Concerns Raised by the DNS Filtering Requirements in the PROTECT IP Bill" is available here for download.

Thursday, April 21, 2011

Insecure Mail Server Offers Chinese Government Accounts To The Masses

Via Threatpost.com -

A security researcher who identified holes in SCADA software used by utilities in China has issued a new warning to that country's CERT about insecure Web infrastructure, including an e-mail server that allows any Web user to create their own Chinese government mail account.

Dillon Beresford, a security researcher at NSS Labs, notified China's Computer Emergency Response Team (CERT) on Wednesday about a hole in the mail server for Guizhou Province that allows any user to create a new mail account and log in to the Provincial government's mail server. The critical hole is just one example of what Beresford said is a public sector Web infrastructure that is rife with vulnerable and insecure applications, despite China's popular reputation as an aggressor in the arena of cyber espionage and cyber warfare.

The vulnerable e-mail server doesn't require users to authenticate to it with a user name and password and lacks proper access controls, Beresford wrote in the e-mail, which was shared with Threatpost. Threatpost verified that the script allows unauthenticated users to create e-mail accounts for the Internet domain for Guizhou Province, which is located in southwestern China, one of the country's coal producing regions.

The ramifications behind the security hole are extremely serious," he said in an e-mail addressed to China's CERT and official email addresses for the province. "An attacker could represent themselves as an official from the Chinese Government and use the accounts to socially engineer and attack other Government workers in the People's Republic of China," Beresford wrote.

A moderately sophisticated user could also leverage access to the Webmail server to escalate their privileges. Beresford confirmed that the server in question was vulnerable to SQL injection attacks that could give a hacker access to other e-mail accounts, as well.

Wednesday, April 13, 2011

Rebels Hijack Gadhafi's Phone Network

Via WSJ -

A team led by a Libyan-American telecom executive has helped rebels hijack Col. Moammar Gadhafi's cellphone network and re-establish their own communications.

The new network, first plotted on an airplane napkin and assembled with the help of oil-rich Arab nations, is giving more than two million Libyans their first connections to each other and the outside world after Col. Gadhafi cut off their telephone and Internet service about a month ago.

That March cutoff had rebels waving flags to communicate on the battlefield. The new cellphone network, opened on April 2, has become the opposition's main tool for communicating from the front lines in the east and up the chain of command to rebel brass hundreds of miles away.

While cellphones haven't given rebel fighters the military strength to decisively drive Col. Gadhafi from power, the network has enabled rebel leaders to more easily make the calls needed to rally international backing, source weapons and strategize with their envoys abroad.

To make that possible, engineers hived off part of the Libyan cellphone network—owned and operated by the Tripoli-based Libyan General Telecommunications Authority, which is run by Col. Gadhafi's eldest son—and rewired it to run independently of the regime's control. Government spokesman Moussa Ibrahim, asked about the rebel cellphone network, said he hadn't heard of it.

Wednesday, March 23, 2011

Comodo CA Compromised by Iran?

http://www.comodo.com/Comodo-Fraud-Incident-2011-03-23.html

Report of Incident on 15-MAR-2011
An RA suffered an attack that resulted in a breach of one user account of that specific RA. This RA account was then used fraudulently to issue 9 certificates (across 7 different domains). All of these certificates were revoked immediately on discovery. Monitoring of OCSP responder traffic has not detected any attempted use of these certificates after their revocation.

Fraudulently Issued Certificates
9 certificates were issued as follows:

Domain: mail.google.com [NOT seen live on the internet]
Serial: 047ECBE9FCA55F7BD09EAE36E10CAE1E

Domain: www.google.com [NOT seen live on the internet]
Serial: 00F5C86AF36162F13A64F54F6DC9587C06

Domain: login.yahoo.com [Seen live on the internet]
Serial: 00D7558FDAF5F1105BB213282B707729A3

Domain: login.yahoo.com [NOT seen live on the internet]
Serial: 392A434F0E07DF1F8AA305DE34E0C229

Domain: login.yahoo.com [NOT seen live on the internet]
Serial: 3E75CED46B693021218830AE86A82A71

Domain: login.skype.com [NOT seen live on the internet]
Serial: 00E9028B9578E415DC1A710A2B88154447

Domain: addons.mozilla.org [NOT seen live on the internet]
Serial: 009239D5348F40D1695A745470E1F23F43

Domain: login.live.com [NOT seen live on the internet]
Serial: 00B0B7133ED096F9B56FAE91C874BD3AC0

Domain: global trustee [NOT seen live on the internet]
Serial: 00D8F35F4EB7872B2DAB0692E315382FB0

[...]

Our Interpretation

  • The circumstantial evidence suggests that the attack originated in Iran.
  • The perpetrator has focused simply on the communication infrastructure (not the financial infrastructure as a typical cyber-criminal might).
  • The perpetrator can only make use of these certificates if it had control of the DNS infrastructure.
  • The perpetrator has executed its attacks with clinical accuracy.
  • The Iranian government has recently attacked other encrypted methods of communication.
  • All of the above leads us to one conclusion only:- that this was likely to be a state-driven attack.
---------------------------------------------------------------------

Microsoft Security Advisory (2524375)
Fraudulent Digital Certificates Could Allow Spoofing
http://www.microsoft.com/technet/security/advisory/2524375.mspx

Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root Certification Authorities Store on all supported versions of Microsoft Windows. Comodo advised Microsoft on March 16, 2011 that nine certificates had been signed on behalf of a third party without sufficiently validating its identity. These certificates may be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer.

-----------------------------------------------------------------

Cyber Attack Attribution is Inherently Difficult

Seems like a very effective method to enable a government to man-in-the-middle their own citizens for surveillance purposes. However, based on just the public information, the attribution to Iran should be taken with a gain of salt.

July 15, 2010: US Congress - Planning For The Future of Cyber Attack Attribution
'Given that the Internet is intended to be open and anonymous, the attribution of cyber attacks can be very, very difficult to achieve and should not be taken lightly." - Congressman David Wu (Chairman, Subcommittee on Technology and Innovation, Committee on Science and Technology)

Errata Security - No Reason to Believe Comodo Attack Came From Iran
http://erratasec.blogspot.com/2011/03/no-evidence-comodo-compromise-was-from.html

In the end, if you are responsible for information / cyber security of a corporation, it doesn't really matter if it is 16 year old kids or Iran - you don't want them on your network and you don't want them stealing your data. Period.

Saturday, February 19, 2011

SpyTunes: Privacy Hole Lets Anyone with Your Email Address Spy on Your iTunes Library

Via Andrew McAfee's Blog -

A little while back I was putting together an iTunes playlist to give to my Mom as a gift, and found myself frustrated by the application’s user interface. It kept telling me that Mom already had one song after another, and refusing to let me complete the gifting process until I removed the duplicate song from the playlist.

After I did this three or four times I gave up, complaining to my girlfriend how clunky the process was. She replied “That’s not the real problem. The real problem is that iTunes is telling you what music someone else has.”

She’s right. I’ve been doing some poking around, and have found that it’s pretty straightforward for one person (let’s call him George Smiley, after John Le Carré’s master spy) to find out what music, video, and apps someone else (like me) has purchased or had gifted to them on iTunes.

Tuesday, February 15, 2011

The Cyberweapon that Could Take Down the Internet

Via NewScientist.com -

A new cyberweapon could take down the entire internet – and there's not much that current defences can do to stop it. So say Max Schuchard at the University of Minnesota in Minneapolis and his colleagues, the masterminds who have created the digital ordnance. But thankfully they have no intention of destroying the net just yet. Instead, they are suggesting improvements to its defences.

Schuchard's new attack pits the structure of the internet against itself. Hundreds of connection points in the net fall offline every minute, but we don't notice because the net routes around them. It can do this because the smaller networks that make up the internet, known as autonomous systems, communicate with each other through routers. When a communication path changes, nearby routers inform their neighbours through a system known as the border gateway protocol (BGP). These routers inform other neighbours in turn, eventually spreading knowledge of the new path throughout the internet.

A previously discovered method of attack, dubbed ZMW – after its three creators Zhang, Mao and Wang, researchers in the US who came up with their version four years ago – disrupts the connection between two routers by interfering with BGP to make it appear that the link is offline. Schuchard and colleagues worked out how to spread this disruption to the entire internet and simulated its effects.

Surgical strike

The attack requires a large botnet – a network of computers infected with software that allows them to be externally controlled: Schuchard reckons 250,000 such machines would be enough to take down the internet. Botnets are often used to perform distributed denial-of-service (DDoS) attacks, which bring web servers down by overloading them with traffic, but this new line of attack is different.

"Normal DDoS is a hammer; this is more of a scalpel," says Schuchard. "If you cut in the wrong places then the attack won't work."

[...]

Meltdown not expected

So is internet meltdown now inevitable? Perhaps not. The attack is unlikely to be launched by malicious hackers, because mapping the network to find a target link is a highly technical task, and anyone with a large enough botnet is more likely to be renting it out for a profit.

An alternative scenario would be the nuclear option in a full-blown cyberwar – the last resort in retaliation to other forms of cyberattack. A nation state could pull up the digital drawbridge by adjusting its BGP to disconnect from the internet, just as Egypt did two weeks ago. An agent in another country could then launch the attack, bringing down the internet while preserving the attacking nation's internal network.

Tuesday, February 8, 2011

ZDI Public Disclosure: Microsoft

http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsoft

These vulnerabilities are being published as per the ZDI disclosure changes announced in August of 2010.
  • ZDI-CAN-811 = Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
  • ZDI-CAN-829 = Microsoft Office Excel Office Art Object Parsing Remote Code Execution Vulnerability
  • ZDI-CAN-904 = Microsoft Office Excel Axis Properties Record Parsing Remote Code Execution Vulnerability
  • ZDI-CAN-798 = Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
  • ZDI-CAN-827 = Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
-------------------------------------------------------------------------------------------

ZDI Outlined Mitigations

1) Microsoft Office File Block Policy can be used to block the opening of Office 2003 and earlier documents from unknown or untrusted sources and locations. This mitigation could be problematic in environments where 2003 binary files are still used.

2) Use Microsoft Office Isolated Conversion Environment (MOICE) when opening Excel and PowerPoint files in Office 2003 or 2007 - http://support.microsoft.com/kb/935865 & http://support.microsoft.com/kb/935865#FixItForMeAlways (Enable MOICE with Simple “Fix it”)

3) Use Microsoft’s Enhanced Mitigation Experience Toolkit (EMET) with Microsoft Excel and Microsoft PowerPoint processes to force utilization of ASLR (only on Windows Vista or Windows 7) and DEP mitigations which could prevent exploitation.

Wednesday, February 2, 2011

Facebook HTTPS Fail

According to Michael Brennan (@brennan_mike)...

http://twitter.com/#!/brennan_mike/status/32859085120471041
Facebook HTTPS fail. If you use an app that doesn't support it, FB asks you to switch to HTTP and then reverses your default HTTPS setting.
----------------------------------------------------------------------------

Since I use very few applications in Facebook, I am unable to verify his claim. However, there has to be a large number of FB apps which don't use SSL, so it makes sense they might work around that fact in this manner.

This could result in users unintentionally modifying their HTTPS setting to a less secure settings (aka disabling it).

With that being said, it is still recommended to enable HTTPS for Facebook, if you haven't already done so.

The checkbox can be found at: Account (at the upper right corner) --> Account Settings --> Account Security --> Secure Browsing (https)

Tuesday, January 18, 2011

China CERT: We Missed Report On SCADA Hole

Via Threatpost.com -

China's Computer Emergency Response Team (CERT) admitted that it missed a September e-mail message from a researcher at NSS Labs that pointed out a critical vulnerability in a commonly used SCADA (Supervisory Control And Data Acquisition) software package. The lapse resulted in a gap of almost four months before the hole was patched.

Threatpost first wrote about the heap overflow in software produced by Wellintech on Monday, after researcher Dillon Beresford wrote that his efforts to inform the company about the hole - one of many he has uncovered in Chinese SCADA packages - had hit a wall. In an unsigned e-mail to Threatpost.com, the Chinese CERT said the organization missed Beresford's September e-mail identifying the remotely exploitable hole, and only became aware of the vulnerability in the Kingview Version 6.5.3 in late November, after a senior member of the vulnerability analysis team at U.S. CERT contacted the organization.

"After tracing back all email history based on the content of the report, we found that the email from Dillon Beresford on Sep.28 had been missed by the duty staff," the e-mail reads. Apparently, the Chinese CERT (CNCERT) is struggling to stay on top of the volume of e-mail reports it is receiving. "Our public incident report email box receives thousands of emails everyday. It's a big pity, as well as a mistake that our duty staff have not notice such an important email," CNCERT acknowledged.

The acknowledgement suggests that China's main clearinghouse for information on software security issues may be experiencing growing pains. According to a time line provided by CNCERT, after learning of the hole from U.S. CERT member Art Manion in late November, CNCERT verified the hole and notified vendor, Wellintech, of the hole. The company verified its existence, as well, and provided a report on it to the China National Vulnerability Database (CNVD), according to protocol. CNCERT and the CNVD worked with the company towards a patch. That patch was completed and published on December, 15, according to the timeline, but no notice of that was sent back to CNVD and CNCERT appears to have been unaware that it was issued.

The organization has since coordinated with Wellintech and issued an official notice of the hole on Thursday.

Friday, January 14, 2011

The First Combined Zeus/SpyEye Toolkit

Via McAfee Blog -

In our recent 2011 Threats Predictions report, McAfee Labs predicted that the recent merger of Zeus with SpyEye would produce more sophisticated bots due to improvements in bypassing security mechanisms and law enforcement monitoring. Both Zeus and SpyEye were prevalent and dangerous malware separately, the combination of their functionality certainly takes this threat to a new level.

Here we are just in mid-January and it seems that the first version of this toolkit has arrived on the black market, which means we can expect to see the malware it produces shortly. This version, v1.4.1, seems to have been published on January 11th, 2011:

[...]

Functionality updates include:
1. Brute force password guessing
2. Jabber Notification
3. VNC module
4. Auto-spreading
5. Auto-update
6. Unique Stub Generator for FUD and evasion
7. New Screenshot System

Price:
300$ without VNC and FF Inject
$800 all inclusive.

Sunday, December 26, 2010

Carders.cc, Backtrack-linux.org and Exploit-db.org Hacked

Via Krebs on Secuirty -

Carders.cc, a German security forum that specializes in trading stolen credit cards and other purloined data, has been hacked by security vigilantes for the second time this year. Also waking up to “you’ve been owned” calling cards this Christmas are exploit database exploit-db.org and backtrack-linux.org, the home of Backtrack, an open source “live CD” distribution of Linux.

The hacks were detailed in the second edition of “Owned and Exposed,” an ezine whose first edition in May included the internal database and thousands of stolen credit card numbers and passwords from Carders.cc. The Christmas version of the ezine doesn’t feature credit card numbers, but it does list the user names and hashed passwords of the carders.cc forum administrators. The carders.cc forum itself appears to be down at the moment.

Mati Aharoni, the main administrator for both exploit-db.org and backtrack-linux.org, confirmed that the hacks against his sites were legitimate. Shortly after my e-mail, Aharoni replied with a link to a short statement, noting that a hacking team called inj3ct0r initially took credit for the attack, only to find itself also targeted and shamed in this edition of Owned and Exposed.

“There’s nothing like having your butt kicked Christmas morning, which is exactly what happened to us today. We were owned and exposed, in true fashion,” Aharoni wrote. “Initially, the inj3ct0r team took ‘creds’ for the hack, which quickly proved false as the original ezine showed up – and now inj3ct0r (their new site) is no longer online. As a wise Chinese man once said: ‘do not anger one who has shell on your server’. The zine also mentioned other sites, as well as the ettercap project being backdoored.”
To his credit, Aharoni posted a link to the 2nd edition of Owned and Exposed.

“The irony of posting your zine in our papers section is not lost on us,” Aharoni wrote.


------------------------------------------------------------------------------------------------

Issue #2 - Owned and Exposed
http://nopaste.me/paste/4d15e1a4c4943.html

Saturday, December 4, 2010

Browser Privacy: CSS History Sniffing In the Wild

Via Forbes.com (The Not-So-Private Parts Blog) -

YouPorn is one of the most popular sites on the Web, with an Alexa ranking of 61. Those who visit the homemade-porn featuring site — essentially, a YouTube for porn enthusiasts — are subject to scrutiny, though, of the Web tracking variety. When a visitor surfs into the YouPorn homepage, a script running on the website checks to see what other porn sites that person has been to.

How does it work? It’s based on your browser changing the color of links you’ve already clicked on. A script on the site exploits a Web privacy leak to quickly check and see whether your browser reveals that the links to a host of other porn sites have been assigned the color “purple,” meaning you’ve clicked them before. YouPorn did not respond to an inquiry about why it collects this information, and tries to hide the practice by disguising the script with some easy-to-break cryptography.*

The porn site is not alone in its desire to know what other websites visitors have visited. A group of researchers from the University of California – San Diego trolled through the Web’s most popular sites to see which ones were collecting this information about visitors. They found it on 46 other news, finance, sports, and games sites, reporting their findings in a paper with the intimidating title, “An Empirical Study of Privacy-Violating Information Flows in JavaScript Web Applications.”

The popular finance website Morningstar was one of those that made the list of sites that run the script to check to see where else their visitors have been; its site checked to see if someone has been to Cars.com, Edmunds, and 46 others.

[...]

The researchers who wrote the paper identifying this practice call it “history hijacking” or “history sniffing.” Mozilla, the foundation behind Web browser Firefox, calls it the “CSS: visited history bug.” It’s a bug that’s been discussed in developer circles for over a decade. Some browsers have fixed the bug. If you’re surfing using Chrome or Safari, this script doesn’t work. Firefox has fixed it in its newest version (v4 Betas). Internet Explorer, the most popular browser out there, is vulnerable to the history sniffing (though you can prevent it by going through the slightly onerous step of activating InPrivate Browsing, according to a spokesperson. That feature also blocks ad networks’ cookies, reports Business Insider.)


--------------------------------------------------------------------------------------------------------------------

YouPorn Sued for Sniffing Browser History

http://news.cnet.com/8301-1009_3-20024696-83.html?tag=nl.e757

A site for sharing pornographic content is the target of a lawsuit accusing it of improperly checking what other Web sites visitors had used.

Defendants David Pitner and Jared Reagan, both of Newport Beach, Calif., accuse YouPorn operator Midstream Media of the Netherlands of violating the U.S. Computer Fraud and Abuse Act and California's computer crime law; of engaging in deceptive and unfair business practices; and of unlawful and unfair competition.

The suit, filed Friday in U.S. District Court for the central district of California, accuses YouPorn of, among other things, "intentionally accessing plaintiffs'...computers without authorization." The plaintiffs are seeking class-action status, an injunction to stop the history sniffing practice, and payment for damages.


-------------------------------------------------------------------------------------------------------------------

CSS History Sniffing - PoC
http://ha.ckers.org/weird/CSS-history-hack.html

--------------------------------------------------------------------------------------------------------------------

According to Jeremiah Grossman, the following browsers contain fixes for the CSS History Sniffing bug:
  • Firefox 4 (currently beta)
  • Google Chrome 8
  • Internet Explorer 9 (currently beta, Windows XP not supported)
  • Apple Safari 5