Wednesday, 22 April 2015

SRI Data Leak

Indiana-based SRI Incorporated – which conducts tax sales, deed sales and foreclosure sales relating to the recoupment of delinquent tax for local governments – is notifying roughly 9,000 individuals that their personal information may be at risk.

How many victims? Roughly 9,000.

What type of personal information? Names, addresses, Social Security numbers, tax identification numbers, and bank account and routing numbers.

What happened? New files were added to the software behind SRI`s auction website, enabling an unauthorized outside user to access, post and delete files stored on the website.

What was the response? SRI removed all personal information from its system and the personal information is no longer viewable. SRI is migrating all of its online auctions to a new auction system with enhanced security. All impacted individuals are being notified. An investigation is ongoing.

Details: Google notified SRI on March 13 of suspicious activity occurring on the SRI website. SRI believes the unauthorized access may have begun in December 2014. SRI has found no evidence that information was viewed or downloaded.

Quote: `The incident appears to have involved a total of approximately nine thousand individuals in fifty (50) states and countries,` according to a notification letter.

Source: doj.nh.gov, `SRI Incorporated,` April 2, 2015.


Read original article

Valve combat scammers

Valve has added a new feature to Steam accounts, hopefully removing most of the bots and phishing scams currently plaguing the PC gaming service.
It locks accounts that have spent under £5 in a 'Limited Access' mode, where they cannot use most of the features available on normal Steam accounts. Since most of the bot accounts do not spend a penny, this change has hopefully removed most of them.

Even for active phishing accounts set up by humans, it will become harder to scam people unless the scammer buys games first. Once Valve is alerted that someone is a scammer, they can get their account shut down, meaning it is less likely scammers will use Steam.

In Limited Access, Steam users will not have access to:

•Sending friend invites
•Opening group chat
•Voting on Greenlight, Steam Reviews and Workshop items
•Participating in the Steam Market
•Posting frequently in the Discussions
•Gaining Profile Levels (Locked to level 0) and Trading Cards
•Submitting content on the Steam Workshop
•Posting in an item's Workshop Discussions
•Accessing the Web API
•Using browser and mobile chat

That is quite a hefty amount of things put on hold, meaning spam bots voting for Greenlight projects will be incapable of making instant new accounts to make hundreds of votes.

Valve offers a lot of ways to lift Limited Access, including simply buying a game on Steam. Users can also download a video game, by a Steam gift or redeem a Steam card. It will not allow demos, betas or CD ROM codes as valid forms of purchase, meaning users need to buy something inside Steam's walled garden.

Steam has often been the target of scammers with 60 million active users, making it the most popular platform for gaming. The only other platform of that size is Riot Games' League of Legends, but that is split between different regions vastly limiting the scope, and Riot has added its own barriers to block scammers from adding random people.

Read original article

APT28 Back inRussianDoll Attack

Security firm FireEye has discovered a recent targeted attack campaign likely to have been backed by the Kremlin which exploits zero day vulnerabilities in Adobe Flash and Microsoft Windows.

Operation RussianDoll, as it has been dubbed by the vendor, began on 13 April and has been spotted targeting a `specific foreign government organization.`

After studying its `technical indicators and command and control infrastructure,` FireEye believes it to be the work of a group known as APT28, which it unmasked in October 2014 as having probable state backing for its activities.

After being tricked into clicking on a malicious link, users will be taken to a website controlled by the group, the firm said.

An HTML/JS launcher page will then serve up a Flash exploit to trigger CVE-2015-3043, which Adobe actually patched last week.

Shellcode then downloads and runs an executable payload to exploit a Windows local privilege escalation vulnerability (CVE-2015-1701) to steal a System token.

Although the Adobe flaw has been patched, Microsoft has yet to issue one for the Windows vulnerability.

The target firm is an `international government entity` in an industry which APT28 is known to have targeted in the past, said FireEye.

The attack also uses a malware variant that shares characteristics with APT28 backdoors.

The security vendor explained:

`CHOPSTICK and CORESHELL malware families, both described in our APT28 whitepaper. The malware uses an RC4 encryption key that was previously used by the CHOPSTICK backdoor. And the C2 messages include a checksum algorithm that resembles those used in CHOPSTICK backdoor communications. In addition, the network beacon traffic for the new malware resembles those used by the CORESHELL backdoor. Like CORESHELL, one of the beacons includes a process listing from the victim host. And like CORESHELL, the new malware attempts to download a second-stage executable.`

C2 locations for RussianDoll also match known or suspected APT28 domains, the firm said.

APT28 was unmasked last year has having been in operation since 2007.

It is known for using relatively sophisticated malware which is designed to hamper reverse engineering techniques used by the white hats.

Read original article

Tuesday, 21 April 2015

Google Encrypts Ad Traffic

Encryption by default is a popular goal for internet companies, and Google has done its part to use strong HTTPS encryption, for Search, Gmail, YouTube and Drive. The company is now moving its advertising platforms to HTTPS as well. Most of its ads will be served over encrypted links by the end of June.

`In addition to providing a secure connection on our own products, we've been big proponents of the idea of HTTPS everywhere, encouraging webmasters to prevent and fix security breaches on their sites, and using HTTPS as a signal in our search ranking algorithm,` said Neal Mohan, vice president of product management, display and video ads, and Jerry Dischler, vice president of product management for AdWords, in a blog.

The search giant has already moved its YouTube ads to HTTPS as of the end of 2014, and the majority of mobile, video and desktop display ads served to the Google Display Network, AdMob and DoubleClick publishers will be encrypted by June 30.

Also, advertisers using any of the buying platforms, including AdWords and DoubleClick, will be able to serve HTTPS-encrypted display ads to all HTTPS-enabled inventory.

`Of course we're not alone in this goal. By encrypting ads, the advertising industry can help make the internet a little safer for all users,` Mohan and Dischler added, noting that recently, the Interactive Advertising Bureau (IAB) published a call to action to adopt HTTPS ads.

Many ad systems are already supporting HTTPS—a survey of IAB membership late last year showed nearly 80% of member ad delivery systems supported it. But, there's still more work to do.

`That's a good start, but doesn't reflect the interconnectedness of the industry,` it said. `A publisher moving to HTTPS delivery needs every tag on page, whether included directly or indirectly, to support HTTPS. That means that in addition to their ad server, the agency ad server, beacons from any data partners, scripts from verification and brand safety tools, and any other system required by the supply chain also needs to support HTTPS.`

Read original article

Outlook Phishing Scam

Discontinue Support'—Latest Phishing Scam Targeting Microsoft Outlook Users.

An email is being circulated by cybercriminals that appears to be sent by Outlook.com team informing users that on 11th May 2015, MS Outlook will be discontinuing `support on your account and security.` The message is nothing else but another crude phishing attempt.

The email warns users that if they don't update their account before 11th May 2015, they won't be able to send and receive or read emails. They also will be prohibited from accessing their account and salient features of MS Outlook.

Further, the email compels users to click on an `Update your Account` URL to resolve the issue.

Evidently, the email hasn't been sent by Outlook Team and not even by any member of the Microsoft team.

The actual senders of the email are cybercrooks and it is just another phishing scam devised to deceive innocent users and obtaining their Microsoft Account Login credentials. By clicking on that link, you will be redirected to a fake website that looks just like the real Outlook login page.

When you enter your Microsoft account details, you will automatically be taken to the real Microsoft website. The purpose of this scam is obvious; hackers need your login credentials for hijacking your Microsoft account.

Microsoft Account is the new name of what we previously knew as the Windows Live ID.

By obtaining a single set of MS Login credentials, cybercriminals can access numerous Microsoft services. Therefore, your account login info is valuable data for scammers, reports Hoax-Slayer.

The Account Update to avoid Blocking or Suspension has become a rather common scammer tactic

Read original article

Russian hackers use Flash

fresh attack a week ago by a long-known hacking group suspected to be linked with Russia did little to mask its activity.

The computer security firm FireEye wrote on Saturday that the group -- called APT 28 -- attacked an `international government entity` on April 13, using two recently disclosed software flaws, one of which has not been patched.








mobile malware















The attack sought to trick victims into clicking on a link that led to a website which attacked their computer. It first used a vulnerability in Adobe Systems` Flash player, CVE-2015-3043, then used a still unpatched Microsoft vulnerability, CVE-2015-1701, to gain higher privileges on a computer.

In a white paper released last year, FireEye said APT 28 had conducted attacks against political and military-related organizations since at least 2007. The group compiles `malware samples with Russian language settings during working hours consistent with the time zone of Russia`s major cities, including Moscow and St. Petersburg.`

The malware delivered in the latest attack is very similar to CHOPSTICK, a backdoor known to be used by APT 28. In fact, the malware delivered in the latest attack used the same RC4 encryption key that was used by CHOPSTICK, FireEye said.

Even hacking groups considered to be sophisticated often reuse infrastructure or components, which over the long term help security researchers identify their attacks. FireEye also said the latest malware connects to the same command-and-control infrastructure that APT 28 has used.

The exploit used by APT 28 won`t work if users have upgraded to the latest Flash version released on Tuesday, so administrators are advised to patch.


Read original article

Monday, 20 April 2015

MongoDB Patches Vulnerability

MongoDB, a popular NoSQL database used in big data and heavy analytics environments, has patched a serious denial-of-service vulnerability that is remotely exploitable. Companies using the default installation of MongoDB, which does not require authentication to access the database, are urged to update immediately to a patched version, and set up authentication. Hackers using a Shodan query or scanning the Internet for vulnerable installations, can easily find MongoDB servers online. According to the MongoDB website, large organizations such as MetLife, Bosch, Expedia, and The Weather Channel have the database in production for a variety of uses.

Researchers at Fortinet's FortiGuard Labs discovered the vulnerability in separate areas of MongoDB on Feb. 20 and 23 respectively, and disclosed privately immediately to MongoDB, which made updates available on March 17. `A potential attacker doesn't have to be authenticated or have rights to the database to exploit the vulnerability,` said Aamir Lakhani, security strategist, FortiGuard Labs. `All they have to do is send a crafted packet, a particular regex query, to crash the database.`

According to an advisory on the Fortinet website, the vulnerability is in an old PCRE library (8.30) of regular expressions used in MongoDB querying. MongoDB patched the library in version 3.0.1 and 2.6.9, the last two major releases in production. Up-to-date versions of MongoDB ship with a patched version of PCRE (8.36 and beyond). `I would say a skilled attacker who understands regex wouldn't have too much of a difficult time with this attack, especially after examining the code,` Lakhani said. `Some things would stand out with a skilled attacker.

And at some point as usually happens with these things, someone will automate it or develop a Metasploit plugin that will make an exploit easy to execute.` Cutting into that simplicity would be the enablement of authentication. `You can set up Mongo to ensure authentication is required. It's the recommended best practice,` Lakhani said. `If Mongo is set up in a way that does not allow for anonymous access, at that point, an anonymous user cannot run an attack. But if a user has legitimate credentials, they can execute the same attack.`

The Fortinet exploit is basically a regular expression that meets a number of conditions that would cause the database to crash. Variants of the crafted regex work, Fortinet said, but it did not disclose the details. `There are several ways to carry out an attack against this vulnerability,` Lakhani said. `The most common is to connect to the MongoDB server through a website query or using a MongoDB client tool to connect to the server.

The attacker puts in a regex string with an input field where MongoDB reads it and processes the input. As soon as it looks at the packet, the server is taken down.

Read original article