Microsoft Announces Windows 10 BlackBerry Launches Passport in India for Rs. 49,990 The World's Slimmest SmartPhone : Gionee Elife S5.1 iOS 8 Has Finally Arrived Apple Unveils iPhone 6 and iPhone 6 Plus

Showing posts with label hackers. Show all posts

NSA Monitoring ISIS' Cyber Capabilities

 
As U.S. military leaders outlined their strategy before Congress to fight Islamic State militants on the battlefield, the National Security Agency chief said on Tuesday he was watching the media-savvy group's cyber capabilities.Asked whether the Sunni Muslim group was planning cyber attacks on U.S. interests, Admiral Mike Rogers said he could not discuss specifics of the organization's technical capabilities.

"We need to assume that there will be a cyber dimension increasingly in almost any scenario that we're dealing with," Rogers said at a cybersecurity conference in Washington. Islamic State, which controls large swaths of Iraq and Syria, has posted carefully choreographed beheading videos online, trumpeted its violent acts on Twitter and used social media to recruit foreign Islamists to the fight.
"Its public messaging and social media is as slick and as effective as any I've ever seen from a terrorist organization," Homeland Security Secretary Jeh Johnson told the Council on Foreign Relations in New York last week.
Cybersecurity expert James Lewis of the Center for Strategic and International Studies said he did not think Islamic State posed any immediate cyber threat to American interests. While there may be no imminent or specific cyber threat from Islamic State, there is a wide-ranging intent to damage the West, a congressional aide said. Different jihadist groups have talked about launching cyber attacks and it may be just a matter of time before they find someone capable of doing it, the aide said on condition of anonymity.



Rogers, speaking generally on how cybersecurity threats are proliferating across all aspects of American life, said: "There is nothing but increased activity out there." As Pentagon officials told Congress on Tuesday they were preparing for a longer-term campaign against Islamic State in Syria and Iraq, Rogers said cyber defense was a long-haul effort.


The U.S. Cyber Command he leads hopes to have 6,200 cyber employees by 2016 to detect and deflect such threats, and Rogers urged greater cooperation on cybersecurity between government, business and industry. "There are a lot of groups out there - individuals, nation-states - who feel that this is an area worth investing in, because it achieves positive outcomes for them if they can penetrate systems," Rogers said at the Billington Cybersecurity Summit.

Tuesday, 30 September 2014
Posted by Unknown

Android's Next Version Will Come With Default Encryption


Yesterday, Apple commented that iOS 8 the user data stored on iPhones or iPads are fully encrypted, so no one, not even Apple, can access them, even with a court or government order. This is certainly an interesting point for the operating system of the Apple company, and Google seem to think the same. The reason is that a few hours after these statements, the guys at Google have announced that Android 5.0, the next version of the popular operating system for mobile devices, also have default data encryptio.

As we say, by this measure, the data stored on devices with newer versions of iOS and Android will be completely inaccessible, unless the person has the correct password. Three years ago, Google already offers the ability to encrypt our data Phones with Android installed, but this measure, it simply ceases to be a possibility , becoming a default feature. As a result, all users will benefit from this improved safety, because until now, it was an option that activated only those with technical expertise.

Undoubtedly, the two companies that dominate the market for mobile operating systems take such measures is something to behold. Anything that increases the security and privacy of user data is welcome.

A List of 5 Million 'Gmail Passwords' Leaked

A list of almost 5 million combinations of Gmail addresses and passwords was posted online on Tuesday. But the passwords seem to be old, and they don't appear to actually belong to Gmail accounts. Instead, it seems that many of the passwords were taken from websites where users used their Gmail addresses to register, according to some of the leak's victims as well as security experts.

For example, someone might have signed up for a website with the username "myaddress@gmail.com" and the password "mypassword." The list exposed this week makes it look like "mypassword" is the password for the Gmail account itself, but the user's actual Gmail password might be totally different.

The list was posted on a Russian Bitcoin forum on Tuesday evening, and local media started reporting on it on Wednesday. We can't confirm the authenticity of all the email addresses on the list, but a Mashable employee, Evan Engel, saw that his old Gmail password, which he hasn't used in years, is part of the leak.

A Google spokesman told Mashable that the company has "no evidence that our systems have been compromised," and security experts seem to agree that the passwords are either old Gmail passwords obtained through phishing, or are passwords that were actually used on other sites.

Matteo Flora, a computer security expert, reviewed the dumped file and found that around 60 email addresses were in his address book. After he alerted those people, 30 of them told him that the password either was never used for their Gmail accounts or was very old, Flora told Mashable.
Chester Wisniewski, a senior security adviser for security firm Sophos, told Mashable that he expects many of these accounts not to be valid. "There is no honor among thieves as they say, and often stunts like this are released as a sad attempt at gaining credibility among other criminals," he said.
Several Reddit users also confirmed that they found their email addresses in the leak, but that the associated password has never been their Gmail password.

To check if your password was one of the leaked, plug your Gmail address into this trusted tool from KnowEm. Alternatively, if you aren't comfortable giving out your email, you can change all your passwords now. Simply type your email address into the IsLeaked tool to see if your account has been exposed.

However, the tool is not without controversy. Life Hacker actually isn’t promoting it anymore after it said it discovered the “tool” was made public just two days before the Gmail leak was reported.


Google said in a blog post late Wednesday that "less than 2% of the username and password combinations might have worked," adding one more reason not to overreact to this dump.
Google also said that it has contacted the owners of the affected accounts "and have required those users to reset their passwords." So if you haven't heard back from Google, you should be fine. (Though periodically changing your password isn't a bad idea, and two-factor is a must.)

Meanwhile, more security experts seem to agree that the leak is probably almost entirely made of old passwords tken from previous leaks and dumps. Whoever put this particular one together, probably "concatenated several dozen dumps" and then published only the Gmail usernames and password combinations he found, said Jeremi Gosney, the co-founder of PasswordsCon, a hacker conference focusing specifically on passwords and other methods of authentication.
Friday, 12 September 2014
Posted by Unknown

WhatsApp Soon Becoming Police's Powerful Assistant


WhatsApp, the popular cross-platform messaging app, is gradually becoming a very powerful tool for police departments to curb crime. The Lucknow Police has introduced a WhatsApp complaint tool where users can send their complaints about traffic offences.

Police is also planning to connect the helpline no. 1090 with WhatsApp to curb eve teasing. Railway Police is also considering to use WhatsApp to keep a track on ticket collectors, vendors selling food products, and coach attendants.

The Police department in Mumbai has set up several WhatsApp groups aimed at helping people to lodge complaint about for crime such as eve teasing. The Delhi and Kochi police also have WhatsApp helpline number to help people report about corruption in the police department. With messaging apps such as WhatsApp becoming popular among users, it's heartening to see security agencies are also staying up to date with the latest trend. Source DeccanChronical.

Apple Is Gathering Celebrity Login Info For iCloud Hack Investigation


Apple is working directly with celebrities and their publicists to investigate the alleged iCloud hack that may have played a large part in a large cache of nude photographs being released online. Part of that investigation involves obtaining Apple account login information of the people affected, Mashable has learned.

It's not known exactly why Apple needs its users' login information, but presumably it gives them a level of access into a user's account records that they otherwise wouldn't be able to obtain, at least not easily. The company does say that password information stored in iCloud is encrypted and can't be read by Apple. Apple's internal investigation may shine some light on how nude photos of dozens of celebrities were gathered and then released over the weekend. While some have pointed to a potential vulnerability in iCloud security (which has reportedly been patched), there are indications, including the age of some of the photos, that the cache was part of a larger, more complicated effort.

At the same time, the FBI is looking into the iCloud hack, although it stopped short of saying it was opening a full investigation. The incident also raises unsettling questions about the general state of security for cloud storage services, which are now a major part of both personal services and business workflow.
Thursday, 4 September 2014
Posted by Unknown

You Can Hack Gmail with 92% Success Rate: Researchers


Your most trustworthy apps may be at risk. Researchers say they have found a way to hack Gmail apps with a 92 percent success rate. In a paper being presented Friday at the Usenix cybersecurity conference, the engineers said they also could steal check images from a Chase app with an 83 percent success rate and hack personal information such as address and Social Security numbers from H&R Block (success rate 92 percent), Newegg (86 percent), WebMD (85 percent), Hotels.com (83 percent) and Amazon (48 percent) apps.

The hacker would gain access by causing a user to install a seemingly harmless app such as phone wallpaper and expose a newly discovered public side channel that doesn't require privileges. This feature allows processes to share data efficiently and is quite common, since all a phone's downloaded apps interact with one operating system.

"The assumption has always been that these apps can't interfere with each other easily," researcher Zhiyun Qian said in a statement. "We show that assumption is not correct and one app can in fact significantly impact another and result in harmful consequences for the user."
The other contributors to the paper were Z. Morley Mao, associate professor at the University of Michigan, and Qi Alfred Chen, a Ph.D., student working with Mao. Qian, a recent doctoral graduate from Mao's group, is a professor at the University of California, Riverside. The researchers said they had only a 48 percent success with the Amazon app because it allows transition from one activity to almost any other, increasing the difficulty of guessing what the user is doing and finding the exact moment to steal data.

After a high-profile breach of credit card data at Target late last year, reports of cybersecurity attacks on companies and government agencies have been on the rise recently. He added that consumers will probably start looking more into state-of-the-art identification protection services.

"As secure as we thought we were a year or two ago, we're seeing another wave across app platforms everywhere," said Brian Blair, analyst at Rosenblatt Securities. "We're going to have to have app developers create a layer of new security. There's not much I see consumers can do. We have to wait for all companies that store our info to upgrade."


"Users should be cautious and only download apps from trusted sourcesbig, popular apps are hacker magnets," he said in an email. "Do a routine check of your smartphone and tablet, especially if you have little ones using the device, to ensure only apps that can be trusted are the only ones installed. Immediately uninstall apps that appear to be from unknown sources or are not necessary."
Monday, 1 September 2014
Posted by Unknown

Twitter's BotMaker Tool Cuts Spam by 40 Percent


Twitter has introduced a new anti-spam system called BotMaker and says that it is responsible for a 40 percent reduction in its key spam metrics. The BotMaker anti-spam system was created with one low-latency sub-system (Scarecrow) which checks in real time the content posted on the site and decides whether the content should be approved or not. The second computationally-intense and learning sub-system (Sniper) checking in ‘near real time’ the user and content event logs that make it past the Scarecrow.

The BotMaker is constantly fed information by Scarecrow and Sniper, and issues commands to approve, deny or challenge posts. The micro-blogging site also runs periodic jobs on all the data compiled by the BotMaker system for routine checks to specific exercises by the engineering department.

Twitter’s Raghav Jeyaraman stated in an official blog post the challenges faced by the team in creating BotMaker. He stated that due to Twitter’s wide-ranging developer APIs, meant for third-parties to interact with the platform, spammers “know (almost) everything” about how the micro-blogging network functions, which makes it difficult to create an anti-spam system.

Jeyaraman wrote, “These operating conditions are a stark contrast to the constraints placed upon more traditional systems, like email, where data is private and adding latency of tens of seconds goes unnoticed. So, to fight spam on Twitter, we built BotMaker, a system that we designed and implemented from the ground up that forms a solid foundation for our principled defense against unsolicited content,” he said. “The system handles billions of events every day in production, and we have seen a 40 percent reduction in key spam metrics since launching BotMaker.”

A recent report by Twitter revealed that nearly 23 million of active users on the site are ‘Bots’. However, the company says that these accounts are not necessarily spam accounts, which make up less than 5% of total MAUs. These spam accounts affect advertisers who are interested in reaching potential customers through the micro blogging site.

Ebola Fear Used as Bait, Leads to Malware Infection


News of the Ebola virus epidemic in West Africa has hit every news outlet around the globe, and cybercriminals are once again using the latest headlines to bait victims. Symantec has observed three malware operations and a phishing campaign using the Ebola virus as a social engineering theme.

Malware and Phishing Campaigns

The first campaign is fairly simple, where attackers send out an email with a fake report on the Ebola virus to entice victims and what users actually get is an infection of the Trojan.Zbot malware. In the second campaign, cybercriminals send out an email that impersonates a major telecommunications services provider and claims to offer a high-level presentation on the Ebola virus. An attached zip file with a title like “EBOLA – PRESENTATION.pdf.zip” actually

Interestingly, the executed Trojan is not the final payload. The malware is also crafted to inject W32.Spyrat into the victim’s web browser and allows attackers to perform actions such as, log key strokes, record from the web cam, capture screenshots, create processes, open web pages, enumerate files and folders, delete files and folders, download and upload files, gather details on installed applications, the computer, and operating system, and uninstall itself.

The third campaign piggybacks on some fresh Ebola news. In the last two weeks there has been talk of Zmapp, a promising Ebola drug still in an experimental stage. The crooks entice their victims with an email claiming the Ebola virus has been cured and the news should be shared widely. The email attachment is Backdoor.Breut malware.

Another is a phishing campaign that impersonates CNN with breaking Ebola news (with some terrorism thrown in). It gives a brief story outline and includes links to an “untold story.” The email also promises “How-to” precaution information and a list of “targeted” regions. If the user clicks on the links in the email they are sent to a Webpage, asked to select an email provider, and asked to input their login credentials. If the user performs this action, their email login credentials will be sent directly to phishers. The victim is redirected to the real CNN home page.

 Symantec advises all users to be on guard for unsolicited, unexpected, or suspicious emails. If you are not sure of the email’s legitimacy then don’t respond to it, and avoid clicking on links in the message or opening attachments.

Symantec advises all users to be on guard for unsolicited, unexpected, or suspicious emails. If you are not sure of the email’s legitimacy then don’t respond to it, and avoid clicking on links in the message or opening attachments. - See more at: http://www.channelworld.in/news/ebola-fear-used-bait-leads-malware-infection-514062014#sthash.dIZnWG56.dpuf


Interestingly, the executed Trojan is not the final payload. The malware is also crafted to inject W32.Spyrat into the victim’s web browser and allows attackers to perform actions such as, log key strokes, record from the web cam, capture screenshots, create processes, open web pages, enumerate files and folders, delete files and folders, download and upload files, gather details on installed applications, the computer, and operating system, and uninstall itself.
The third campaign piggybacks on some fresh Ebola news. In the last two weeks there has been talk of Zmapp, a promising Ebola drug still in an experimental stage. The crooks entice their victims with an email claiming the Ebola virus has been cured and the news should be shared widely. The email attachment is Backdoor.Breut malware.
Another is a phishing campaign that impersonates CNN with breaking Ebola news (with some terrorism thrown in). It gives a brief story outline and includes links to an “untold story.” The email also promises “How-to” precaution information and a list of “targeted” regions.
If the user clicks on the links in the email they are sent to a Webpage, asked to select an email provider, and asked to input their login credentials. If the user performs this action, their email login credentials will be sent directly to phishers. The victim is redirected to the real CNN home page.
- See more at: http://www.channelworld.in/news/ebola-fear-used-bait-leads-malware-infection-514062014#sthash.dIZnWG56.dpuf
News of the Ebola virus epidemic in West Africa has hit every news outlet around the globe, and cybercriminals are once again using the latest headlines to bait victims. Symantec has observed three malware operations and a phishing campaign using the Ebola virus as a social engineering theme.
Malware and Phishing Campaigns
The first campaign is fairly simple, where attackers send out an email with a fake report on the Ebola virus to entice victims and what users actually get is an infection of the Trojan.Zbot malware.
In the second campaign, cybercriminals send out an email that impersonates a major telecommunications services provider and claims to offer a high-level presentation on the Ebola virus. An attached zip file with a title like “EBOLA – PRESENTATION.pdf.zip” actually
- See more at: http://www.channelworld.in/news/ebola-fear-used-bait-leads-malware-infection-514062014#sthash.dIZnWG56.dpuf
News of the Ebola virus epidemic in West Africa has hit every news outlet around the globe, and cybercriminals are once again using the latest headlines to bait victims. Symantec has observed three malware operations and a phishing campaign using the Ebola virus as a social engineering theme.
Malware and Phishing Campaigns
The first campaign is fairly simple, where attackers send out an email with a fake report on the Ebola virus to entice victims and what users actually get is an infection of the Trojan.Zbot malware.
In the second campaign, cybercriminals send out an email that impersonates a major telecommunications services provider and claims to offer a high-level presentation on the Ebola virus. An attached zip file with a title like “EBOLA – PRESENTATION.pdf.zip” actually
- See more at: http://www.channelworld.in/news/ebola-fear-used-bait-leads-malware-infection-514062014#sthash.dIZnWG56.dpuf

Can a YouTube Cat Video Infect Your Computer?


Those cute little cat video you just watched could cost you millions. And it’s not just about cat videos – innocent videos on YouTube can be used to infect computers with dangerous malware, as revealed in the latest report by Morgan Marquis-Boire, a hacker-turned-researcher. In the report created for Citizen Lab, he described how a simple network injection tool can be used to infiltrate home computers.Such video attacks that use network injections have their own strengths and weaknesses. Other attacks like watering hole and phishing need the user to do something ‘wrong’, like clicking on an infected file or link. Network injections don’t need that. Any simple browser behavior, such as watching a funny cat video, can trigger such attacks. There is a limit, however – once the user’s computer has been infected, the infection is confined to the browser. And such network injection tools aren’t even difficult to find; they can be easily procured from companies like FinFisher and Hacking Team.

These tools, or rather appliances, are physical devices that can be stored inside ISP servers all over the world. To execute an attack, the malicious code is injected into the everyday browsing traffic. One simple way to do this is by using YouTube streams that are unencrypted. The hacker can target a user and then wait for them to watch a YouTube video. They can then intercept the traffic and replace it with their own code. This would give them complete control over the user’s device.

This method can be used for any unencrypted website that offers targeted traffic, but since YouTube is one of the most commonly visited websites, it can be an easy target for hackers. Another website that can be exploited in this way is login.live.com of Microsoft. Google and Microsoft have taken a note of this vulnerability and have encrypted all targeted traffic. This has made most videos safe; however, there are other vulnerabilities that devices from FinFisher and Hacking Team can exploit.

This can turn into a high-level problem, and companies have to take action to make sure that the Internet experience can become safe for an average user. Meanwhile, users can encrypt their files to make sure that no data can be stolen from their computers. This is not the only hacking tool that is easily available. Tools that could perform man-in-the-middle attacks have been openly available for many years. For example, the Ettercap open source tool allows the hackers to intercept and manipulate traffic on LANs. This tool was developed by Marco Valleri and Alberto Ornaghi in 2001. These two guys are the founders of Hacking Team, the same company that creates network injector devices that can infect YouTube videos.

The only thing that could prevent such attacks is encryption. With the rising number of hacking cases, there is a need for an encrypted Internet that can protect an average user from malware. Web developers need to make sure that their websites are encrypted and safe to use. Until then, users need to be wary of their online activities, including watching cat videos on YouTube.

Facebook's 'Color Change' Malware is Back


The color change scam tricks users into downloading malware via a site that claims to let users change the colors of their Facebook profile. The latest iteration of the scam has already affected more than 10,000 people around the world, according to Cheetah Mobile, a Chinese Internet company that highlighted the most recent appearance of the scam in its blog.

The malware begins by advertising an app that tells Facebook users they can change the color theme of their profile. Download the app and you're directed to a malicious phishing site, according to Cheetah Mobile's security researchers.

The website targets users in two ways. First it steals the users' Facebook Access Tokens by asking them to view a color changer tutorial video. Temporary access to the tokens allows hackers to connect to the user’s Facebook friends. If a user doesn’t view this video, the site then tries to get them to download the malicious application. If a user is on a PC, the site leads them to download a pornographic video player. If the user is on an Android device, the site issues a warning saying the device has been infected and advises users to download a suggested app.

The problem, according to Cheetah Mobile, stems from "a vulnerability that lives in Facebook’s app page itself, allowing hackers to implant viruses and malicious code into Facebook-based applications that directs users to phishing sites." Anyone who has already fallen victim to the scam should uninstall the app immediately (this can be done from the "app" menu in your Facebook settings) and change their Facebook password.
Monday, 11 August 2014
Posted by Unknown

Yahoo, Google Envision Spy-Free Emails

 
Yahoo said Thursday it will join an effort by rival Google Inc. Google to create a secure email system by next year that could make it nearly impossible for hackers or government officials to read users' messages. Even the email providers themselves won't be able to decrypt messages.

Google in June announced plans to develop spy-proof email. The addition of Yahoo is notable because the two have access to so many email users and Yahoo shed new details on the project. Google counts 425 million unique Gmail users, Yahoo 110 million.

Microsoft, which offers the free Web email service Outlook.com, has previously said it is working to incorporate encryption technologies into the service formerly known as Hotmail. Microsoft says there are more than 400 million active accounts in Hotmail and Outlook.com. Yahoo and Google say the encryption tool will be an optional feature that users will have to turn on. Engineers at the technology firms—bitter competitors in many fields—frequently talk to each other about the project, people at both companies say.

The tool will rely on a version of PGP encryption, a long-tested way of scrambling data that hasn't yet been cracked. Unlike traditional webmail services that rely on tech companies holding passwords and usernames for consumer accounts, PGP relies on users having their own encryption key stored on laptops, tablets and smartphones.

Mr. Soghoian said Yahoo and Google are taking early steps toward making the technology easier for normal consumers. Executives at both companies expect few users to adopt the technology immediately. Yahoo has altered its email process so users adopting encryption type messages in a separate window, preventing even Yahoo from reading the messages as they are typed. Mr. Stamos said his team is testing ways to get encryption keys on mobile devices. Yahoo also has to explain to users how PGP works and that it isn't a panacea for privacy concerns. For instance, it only encrypts the content of messages—not the data on who sends and receives the messages or the subject line.

Russian Hacker Group Steals 1.2 Billion Internet User Passwords


A U.S. security firm has uncovered what appears to be the largest Internet security breach in recent memory, conducted by a group of Russia-based hackers. According to Milwaukee-based firm Hold Security, which conducted an 18-month investigation into the breach, the online gang stole 1.2 billion username and password combos, as well as more than 500 million email addresses.

The hackers pulled off the data heist, which ultimately scooped up 4.5 billion records, using unsuspecting systems of botnet network victims (in this case, computers with viruses that allowed a single operator to control a large group of affected systems) to test websites for SQL vulnerabilities. When a vulnerability was discovered, the hackers were then able to execute SQL injections, enabling them to send malicious commands to a website and steal its data, including usernames and passwords.
The group managed to steal information from 420,000 web and FTP sites, Hold Security said.

Hold Security's blog post, which details the data breach, also promotes its own services. However, an independent security expert hired by The New York Times confirmed its findings. "Your data has not necessarily been stolen from you directly," the blog post said. "It could have been stolen from the service or goods providers to whom you entrust your personal information, from your employers, even from your friends and family."

The Russia-based cyber gang is comprised of a dozen men in their 20s who began as amateur spammers by buying information on the online black market back in 2011, The New York Times reported. Ironically, the hacking revelation has come during the Black Hat computer-security conference in Las Vegas, which takes place from Aug. 2 to 7.

The Times said Hold Security is trying to develop an online tool to help individual users identify whether or not they were impacted by the data breach. Those who use the Internet for online banking and shopping will likely be the most troubled by the company's report. As for businesses, they are advised to immediately run a check to see if their websites are vulnerable to SQL injections.
"If you haven’t updated your password recently, now would be the time," Adam Kujawa, head of malware intelligence at security company Malwarebytes Labs, told Mashable. "Make sure it’s a strong password containing capital and lowercase letters, numbers and special characters. Also, don’t use the same username and password combo for every site. This is especially true for sites that have personal information like the site to your bank or credit card."

Courtesy : Mashable
Thursday, 7 August 2014
Posted by Unknown

70 Percent Smart Devices Vulnerable to Hacking: Report


According to a recent study released by Hewlett-Packard (HP), examined 10 common smart devices, including thermostats, smart TVs and webcams. Each device had approximately 25 vulnerabilities, the study claimed. Many of the vulnerabilities had to do with a lack of password strength and weak protection software. Eight out of 10 devices failed to require passwords strong enough to be useful, and the same amount put users at risk of having their personal information intercepted via cloud services.

Information technology research firm Garner predicts there will be 26 billion individual Internet of Things objects in the world by the year 2020. In 2009, there were only about nine million of these devices sold.

"The fact is, that today, many categories of connected things in 2020 don't yet exist," Gartner research director Peter Middleton said in a statement. "As product designers dream up ways to exploit the inherent connectivity that will be offered in intelligent products, we expect the variety of devices offered to explode."

"Late last year, we were hearing a lot about Internet of Things, and a bit about IoT security, but had not seen anything that focused on the complete picture of IoT security," a statement from HP read. "So, we decided to start the OWASP [Open Web Application Security Project] Internet of Things Top 10 Project, which aims to educate on the main facets of Internet of Things security that people should be concerned with."

Researchers Warn About 'BadUSB' Security Flaw


Security researchers have long warned about the dangers of malicious files on infected USB sticks. But now experts have discovered a much more dangerous threat that is even more widespread, virtually untraceable and much more difficult to solve than simply installing anti-virus software. The Berlin-based researchers reverse-engineered the software files that control how the USB drive's software works - and revealed how this so-called firmware can be reprogrammed to take complete control of a PC. Firmware is a software program, or set of instructions, programmed onto a hardware device. It tells the device how to communicate with other devices, including computers. Firmware can be thought of as 'semi-permanent' since it remains the same unless it is updated by a 'firmware updater'.

Firmware updates are installed the first time a device is used, for example, or to update a device so it works on a new operating system. Drive manufacturers will often update firmware to improve the performance of their devices. These changes are made at a central level before being pushed out to individual devices. The flaw was discovered by Karsten Nohl and Jakob Lell at Security Research Labs has been dubbed BadUSB. It affects thumb drives and external hard drives, but also any device that connects to a PC using USB. This includes keyboards and the mouse, as well as the USB drives used to charge phones and tablets.

‘The [USB] interface standard conquered the world over the past two decades thanks to its versatility.

'Almost any computer peripheral, from storage and input gadgets to healthcare devices, can connect over the ubiquitous technology. And many more device classes connect over USB to charge their batteries.

‘This versatility is also USB’s Achilles heel: Since different device classes can plug into the same connectors, one type of device can turn into a more capable or malicious type without the user noticing.’

By reprogramming the USB central firmware with malicious code, which is then pushed to individual devices, the hackers could gain access to a PC once its connected to an infected USB.  This includes emulating a keyboard and issuing commands on behalf of the user, such as opening files or installing malware. Such malware could then be used to infect any other connected USB devices. The device can also spoof a network card and change the computer’s settings to redirect web traffic to certain sites. The researchers are due to present their research at the Black Hat security conference in Las Vegas next week.

‘USB has become so commonplace that we rarely worry about its security implications,' they continued.
Sunday, 3 August 2014
Posted by Unknown

India's Security Market to Reach $1.06 Billion in 2015: Gartner


Security market in India is expected to touch $ 1.06 billion by 2015 as an increasing number of enterprises invest in these solutions to protect their business especially in the digital world, research firm Gartner today said.

According to Gartner, security vendor revenue (hardware, software and services) in India will grow from $ 882 million in 2013 to $ 953 million in 2014. This is forecast to reach USD 1.06 billion in 2015, it added.

“Organisations are today increasingly more aware of security considerations in India, driven by factors like highly visible security incidents, increasing financially (corporate espionage, underground economy) and politically (hacktivists and nation states) motivated advanced targeted attacks and renewed regulatory focus on security and privacy,” Gartner said.

Of the total market, security services (consulting, implementation, support and managed security services) accounted for more than 55 per cent and this trend is expected to continue into the foreseeable future.

“Enterprises in India that traditionally did not focus on, or invest in, a lot of security technologies are now beginning to realise the implications that a weak security and risk posture can have on their business,” Gartner Principal Research Analyst Sid Deshpande said.
Gartner said though security awareness is increasing steadily among enterprises, consumer security sub-segment will display modest growth.

“The importance of data privacy and security is not well understood by consumers in India and this situation is likely to continue to affect market growth in the consumer security space,” Gartner said.
Saturday, 2 August 2014
Posted by Unknown

CERT-In Warns About Debit/Credit Card Information Stealing BrutPOS Virus


Debit and credit card owners in the country have been alerted by cyber security sleuths against the damaging activities of a virus which attacks Point of Sale (POS) business counters to steal confidential data like card number and passwords. The virus, of the deadly Trojan/Botnfamily, is prowling in the domestic online media and has been identified as 'BrutPOS' by the CERT-In.

CERT-In is the nodal national agency to combat hacking, phishing and to fortify security-related defences of the Indian Internet domain. "It has been reported that malware variants targeting Point of sale (POS) systems, dubbed "BrutPOS", is spreading. BrutPOS mainly targets windows based system by leveraging web as the main infection vector apart from being downloaded by other malware families," the latest advisory by the agency said.

The advisory added that once the system is infected with the malware, it communicates with its command and control servers to update its status and receive commands or list of IP address range to be scan for RDP servers having weak or default credentials.

Successful RDP brute force attack allows an attacker to execute another malware in the compromised system that steals payment cards data including card holders name, account no, expiration data, CVV code etc from POS systems. The virus also has tendencies to steal system information such as Operating System details, system configuration etc, the advisory said.

Once the secret data of a credit or debit card is stolen, it can be prone to a hacking or phishing attempts on the virtual currency, thereby incurring financial loss for the account holder. The POS denotes the cash counter of a shop or a business establishment where a customer or an individual makes online payment (from debit or credit card) after a purchase. According to existing RBI rules, while debit card owners are required to punch in their secret PIN number before making a payment at these counters, a credit card owner can simply swipe his plastic money to accomplish his transaction at the POS counter. The agency has also recommended some counter measures to check the activities of this new virus.

Some of them include keeping all POS systems thoroughly updated including POS application software, not allowing administrative access to systems, locking out accounts after N number of incorrect login attemptsm, limiting or eliminating the use of shared or group accounts and ensuring that the networks where POS systems reside are properly segmented from the non-payment network.

The agency has also recommended enabling firewall at gateway or desktop level, not visiting untrusted websites, not downloading or opening of attachments in emails received from untrusted sources or unexpectedly received from trusted users and installing and scanning anti-malware engines and keep them up-to-date.

Bladabindi' Virus Spreads Through USB Drives, Steals Personal Info


CERT-in has issued an wakeful against hacking attempts by a multi-identity virus - Bladabindi, that steals individualized entropy of a person through USB jiffy drives. The virus checks for camera drivers and can pose DLL plug-in to record and upload videos to unlikely hackers, as advisable as move Chrome/Firefox passwords.

Computer Pinch Greeting Team-India (CERT-In) expressed that the virus affects "Microsoft Windows operating system" and spreads finished extractible USB jiffy drives including pen drives and aggregation cards. CERT-in warns that the malware can take as some as 12 aliases to conceal its real identicalness and afterward relate a computer system or individual collection of a somebody.

"It has been reported that variants of the malware called Bladabindi are extension. This malware steals sensitive person collection from purulent computer group. Bladabindi could also be old as malware downloader to move added malware and cater backdoor way to the removed wrongdoer.

The agency expressed that a possibleness flack by the virus could prove into the decline of arch proprietary aggregation of a someone similar "machine enumerate, land and program ascertain, Windows individual appoint, computer's operating system type, Plate stored passwords, Firefox stored passwords, etc."

CERT-in has advisable countermeasures against "Bladabindi'. The assort expressed that users should not area uninvited web course or attachments in netmail messages and impose untrusted websites. The bureau also suggests using tough passwords and enable firewall at screen and gateway surface to protect their data from attacks. "See computer grouping with the liberate remotion tools, incapacitate the autorun functionality in Windows, use USB unsullied or immunization software, cook up-to-date patches and fixes on the operating group and program software, deploy up-to-date anti-virus and anti-spyware signatures at screen and gateway structure," the implementation additional.

CERT-In Reports Over 62,000 Cyber Attacks Till May 2014: Govt


Government's cyber security arm Computer Emergency Response Team-India (CERT-In) reported 62,189 cyber security incidents in the first five months of the current calendar year, Parliament was informed today. Similarly, the government body reported that 9,174 Indian websites were hacked by groups spread across the world, Communication and IT Minister Ravi Shankar Prasad said in a written reply to Lok Sabha.

"During the years 2011, 2012, 2013 and 2014 (till May), a total number of 21,699, 27,605, 28,481 and 9,174 Indian websites were hacked by various hacker groups spread across worldwide. In addition, during these years, a total number of 13,301, 22,060, 71,780 and 62,189 security incidents, respectively, were reported to the CERT-In," Prasad added. These incidents include phishing, scanning, spam, malicious code and website intrusions, the Minister said.

"These attacks have been observed to be originating from the cyber space of a number of countries including the US, Europe, Brazil, Turkey, China, Pakistan, Bangladesh, Algeria and the UAE," he added.It has been observed that the attackers compromise computer systems located in different parts of the world and user masquerading techniques and hidden servers to hide the identity of the actual system from which the attacks are being launched, Prasad said.In a separate query in the House, Prasad said with the increase in the proliferation of IT and related services there is a rise in the number of cyber crime and cyber security incidents. The trend in increase in cyber crime incidents is similar to that worldwide.

"As per the cyber crime data maintained by National Cyber Records Bureau, a total of 1,791, 2,876 and 4,356 cyber crime cases were registered under Information Technology Act during the year 2011, 2012 and 1013, respectively, thereby showing an increasing trend," he added.
A total of 422, 601 and 1,337 cases were registered under cyber crime related sections of the Indian Penal Code (IPC) during the year 2011, 2012 and 2013, respectively, he said.

Government Looks into Unauthorized Digital Certificates Issues


The government said it is looking into the matter raised by tech giants Google and Microsoft which have said that the National Informatics Center (NIC) has issued unauthorized digital certificates.
The Controller of Certifying Authorities issues licences and regulates the working of Certifying Authorities, who issue digital certificates for electronic authentication of users. Digital certificate is like an electronic passport that allows a person, computer or organisation to securely exchange information over the Internet. When contacted, Department of Electronics and Information Technology Secretary R S Sharma told PTI: “We are looking into this issue. Certifying Authority (CA) is taking appropriate steps and is working under the guidance of the CCA.”

In a blog post last week, Google said: “On Wednesday, July 2, we became aware of unauthorized digital certificates for several Google domains. ”The certificates were issued by NIC of India, which holds several intermediate CA certificates trusted by the Indian Controller of Certifying Authorities (India CCA).” Similarly, Microsoft said it is aware of improperly issued SSL certificates that could be used in attempts to spoof content, perform phishing attacks or perform man-in-the-middle attacks. ”SSL certificates were improperly issued by NIC, which operates subordinate CAs under root CAs operated by Government of India’s Controller of Certifying Authorities, which are CAs present in the Trusted Root Certification Authorities Store,” it added.
 
Meanwhile, CCA in a post on its website said: “Due to security reasons 3 CA Certificates issued to NICCA have been suspended and the corresponding CRLs have been updated for this purpose. Further updation will be notified.” Google said it had alerted NIC, India CCA and Microsoft about the incident and blocked the mis-issued certificates in Chrome with a CRLSet push. “On July 3, India CCA informed us that they revoked all the NIC intermediate certificates and another CRLSet push was performed to include that revocation.” The US-based firm said India CCA informed it about the results of their investigation on July 8. ”They reported that NIC’s issuance process was compromised and that only four certificates were misissued, the first on June 25. The four certificates provided included three for Google domains (one of which we were previously aware of) and one for Yahoo domains,” Google added.

Digital certificate provides identifying information, and is forgery resistant and can be verified. It contains certificate holder’s name, a serial number, expiration dates, a copy of certificate holder’s public key (used for encrypting messages and digital signatures) and digital signature of the CA so that a recipient can verify the certificate.

ISPs Facing Difficulties in Blocking Certain Websites: Government


Internet service providers (ISPs) are facing difficulties in blocking certain websites, which carry sensitive content, Parliament was informed yesterday.


“Difficulties have been reported to block the websites when the parameters relating to identification of such websites is encrypted with ‘https‘/secured protocols,” Minister of Communication and IT Ravi Shankar Parsad said in a written reply to Lok Sabha. The Minister was replying to a query on whether the government is aware that due to “certain technological shortcomings ISPs are finding it difficult to block certain websites having sensitive contents”. An Internet service provider (ISP) is an entity that offers users services of Internet access and related services.

The Minister said there are constraints of resources in terms of capacity of infrastructure deployed by the ISPs. ”The government is in regular touch with ISPs to address the difficulties,” he added. Section 69A of the IT Act, 2000 empowers government to block any information generated, transmitted, received, stored or hosted in any computer resource in interest of sovereignty and integrity of India. The other issues that can lead to blocking are defense of India, security of the state, friendly relations with foreign states or public order or for preventing incitement to the commission of any cognizable offence relating to the above.
Thursday, 31 July 2014
Posted by Unknown

Categories

Designed by Cyber Freak

News Flash


Blog Archive

Powered by Blogger.

Copyright © Cyber Era News. All rights reserved.- Powered by Eravations - Designed by Shantanu Chauhan -