Sunday, 10 June 2018

Update Google Chrome Immediately to Patch a High Severity Vulnerability

Security researcher MichaƂ Bentkowski discovered and reported a high severity vulnerability in Google Chrome in late May, affecting the web browsing software for all major operating systems including Windows, Mac, and Linux.


Without revealing any technical detail about the vulnerability, the Chrome security team described the issue as incorrect handling of CSP header (CVE-2018-6148).
"Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed," the Chrome security team notes.
Content Security Policy (CSP) header allows website administrators to add an extra layer of security on a given web page by allowing them to control resources the browser is allowed to load.

Mishandling of CSP headers by your web browser could re-enable attackers to perform cross-site scripting, clickjacking and other types of code injection attacks on any targeted web pages.

The patch for the vulnerability has already been rolled out to its users in a stable Chrome update 67.0.3396.79 for Windows, Mac, and Linux operating system, which users may have already receive or will receive over the coming days/weeks.

So, make sure your system is running the updated version of Chrome web browser. We'll update the article, as soon as Google releases further update.

Firefox has also released its new version of the Firefox web browser, version 60.0.2, which includes security and bug fixes. So, users of the stable version of Firefox are also recommended to update their browser.

Tuesday, 15 May 2018

The Cybersecurity 202: Security community has its own encryption debate after discovery of new flaw

Security experts are at odds over how to respond to new research showing hackers could decrypt emails that were supposed to be protected by a popular encryption tool known as PGP, or Pretty Good Privacy. 
A group of European researchers on Monday revealed a flaw in the way certain email programs handle PGP and S/MIME, a similar encryption protocol commonly used by businesses and other enterprises, as my colleague Brian Fung and I reported yesterday. 
The discovery of the flaw, dubbed Efail, blew open a rift between defenders of PGP who insist the encryption is sound — and others who say it’s time to move away from the 30-year-old technology in favor of encrypted messaging apps such as Signal.
“This whole PGP infrastructure is kind of a mess and needs to be hardened up and fixed, or we need to start using something better,” Matt Green, a cryptography expert and assistant professor at Johns Hopkins University, told me. “Signal, Wired and other encrypted chat applications aren’t vulnerable the way PGP is. They’re not only more secure, they’re more widely used.”
PGP has been the gold standard for encrypting emails since it was released in 1991. But today, people want the convenience of using their smartphones. And encrypted apps are more widely available than ever. 
With the discovery of this flaw, it’s a good time to make the switch, tweeted Barton Gellman, a senior fellow at the Century Foundation and former Washington Post reporter who covered the National Security Agency leaks by Edward Snowden: 


I'm against defeatism. I'd say "possibly not." And that assumes you're targeted by a proficient adversary. Journalists, activists, political opposition should take extra care. Large majority of people would get much more privacy out of GPG than not, and certainly from Signal. https://twitter.com/NickOchsnerWBTV/status/996039315519102977 
Ads info and privacy
Yet the flaw isn’t in PGP itself but in the way certain email programs handle it. Researchers said affected email applications include Mozilla Thunderbird, Apple Mail and some versions of Outlook. (A full list is available from the researchers' report.)
The vulnerability allows hackers to read an encrypted email by making changes to its HTML, which essentially tricks the affected email applications into decrypting the rest of the message. To do this, a hacker would need access to the victim’s encrypted emails — for example, by snooping on network traffic or otherwise compromising email accounts. 
Green explains it simply: “The attacker can modify the encrypted email, and when the person for whom it’s intended opens it or previews it, the mail program will send the contents out to a remote server the attacker has set up,” he said. “All you have to do is look at it and it will decrypt itself and send it out to the attacker.”
This could put whistle blowers, political activists and others who depend on encrypted email at risk, the researchers said in a blog post. That added urgency to warnings from the digital rights group Electronic Frontier Foundation, which urged users of the affected email programs to immediately disable tools that allow the email apps to use PGP or S/MIME. 
“Until the flaws described in the paper are more widely understood and fixed," EFF said, "users should arrange for the use of alternative end-to-end secure channels, such as Signal, and temporarily stop sending and especially reading PGP-encrypted email." 
But some security experts said these dire warnings were overkill.

My $50,000 Twitter Username Was Stolen Thanks to PayPal and GoDaddy

I had a rare Twitter username, @N. Yep, just one letter. I’ve been offered as much as $50,000 for it. People have tried to steal it. Password reset instructions are a regular sight in my email inbox. As of today, I no longer control @N. I was extorted into giving it up.


While eating lunch on January 20, 2014, I received a text message from PayPal for one-time validation code. Somebody was trying to steal my PayPal account. I ignored it and continued eating.

Later in the day, I checked my email which uses my personal domain name (registered with GoDaddy) through Google Apps. I found the last message I had received was from GoDaddy with the subject “Account Settings Change Confirmation.” There was a good reason why that was the last one.

From: <support@godaddy.com> GoDaddy
To: <*****@*****.***> Naoki Hiroshima
Date: Mon, 20 Jan 2014 12:50:02 -0800
Subject: Account Settings Change Confirmation
Dear naoki hiroshima,
You are receiving this email because the Account Settings were modified for the following Customer Account:
XXXXXXXX
There will be a brief period before this request takes effect.
If these modifications were made without your consent, please log in to your account and update your security settings.
If you are unable to log in to your account or if unauthorized changes have been made to domain names associated with the account, please contact our customer support team for assistance: support@godaddy.com or (480) 505-8877.
Please note that Accounts are subject to our Universal Terms of Service.
Sincerely,
GoDaddy

I tried to log in to my GoDaddy account, but it didn’t work. I called GoDaddy and explained the situation. The representative asked me the last 6 digits of my credit card number as a method of verification. This didn’t work because the credit card information had already been changed by an attacker. In fact, all of my information had been changed. I had no way to prove I was the real owner of the domain name.

The GoDaddy representative suggested that I fill out a case report on GoDaddy’s website using my government identification. I did that and was told a response could take up to 48 hours. I expected that this would be sufficient to prove my identity and ownership of the account.


Click on the link below to read the full story:


https://medium.com/@N/how-i-lost-my-50-000-twitter-username-24eb09e026dd



Sunday, 15 April 2018

Highly advanced spyware that’s capable of stealing WhatsApp messages from victims has been discovered by cyber security researchers.
The malware can “spy extensively” on people, and force their phones to record audio and video and take pictures, and steal text messages and call records, all “without arousing suspicion”, the researchers say.
It has been dubbed “Skygofree”, but it has no connection to Sky or any of its products, and does not affect the Sky Go service. 
Kaspersky Lab describes it as “one of the most advanced mobile implants” it has ever come across, and says it “includes a number of advanced features not seen in the wild before”, which can give an attacker full remote control of an infected device.
One of its most noteworthy features is the ability to steal WhatsApp messages, by making use of the Accessibility Services feature on Android. It doesn’t take advantage of any vulnerabilities in the messenger app itself.
“Upon receiving a specific command, the implant can download a special payload to grab sensitive information from external applications,” Kaspersky Lab says, adding that it found a payload that exclusively targets WhatsApp.
“The payload uses the Android Accessibility Service to get information directly from the displayed elements on the screen, so it waits for [WhatsApp] to be launched and then parses all nodes to find text messages.”
Though it requires a special permission from a victim to carry out the message theft, it can obtain this through the delivery of a deceptive phishing message. 
Skygofree can also “eavesdrop on surrounding conversations and noise when an infected device enters a specified location – a feature that has not previously been seen in the wild”, the researchers say.
The malware can enable an infected phone’s microphone and force it to record everything going on around it.
Kaspersky Lab says it is also capable of taking pictures and videos, seizing call records, text messages, geolocation data, calendar events and business-related information stored in the device’s memory.
The researchers found 48 different commands that can be implemented by attackers, which are listed here
They say the malware has been active since 2014 and that the campaign is still ongoing. It has successfully infected “several” victims, all of whom are based in Italy, and is targeting Android and Windows users.
Kaspersky Lab says it has “a high level of confidence that the developer behind the Skygofree implants is an Italian IT company that offers surveillance solutions”, adding that the malware was designed for “targeted cyber-surveillance”.
“If in doubt, call the service provider to verify.”

Hackers Can Steal Data From Air-Gapped Computers Through Powerlines

Do you think it is possible to extract data from a computer using its power cables?

If no, then you should definitely read about this technique.

Researchers from Israel's Ben Gurion University of the Negev—who majorly focus on finding clever ways to exfiltrate data from an isolated or air-gapped computer—have now shown how fluctuations in the current flow "propagated through the power lines" could be used to covertly steal highly sensitive data.


Air-gapped computers are those that are isolated from the Internet and local networks and therefore, are believed to be the most secure devices that are difficult to infiltrate or exfiltrate data.


"As a part of the targeted attack, the adversary may infiltrate the air-gapped networks using social engineering, supply chain attacks, or malicious insiders. Note that several APTs discovered in the last decade are capable of infecting air-gapped networks, e.g., TurlaRedOctober, and Fanny," researchers said.
"However, despite the fact that breaching air-gapped systems has been shown feasible, the exfiltration of data from an air-gapped system remains a challenge."

Dubbed PowerHammer, the latest technique involves controlling the CPU utilization of an air-gapped computer using a specially designed malware and creating fluctuations in the current flow in morse-code-like pattern to transfer data hints in binary form (i.e., 0 and 1).

In order to retrieve modulated binary information, an attacker needs to implant hardware to monitor the current flow being transmitted through the power lines (to measure the emission conducted) and then decodes the exfiltrated data.

"We show that a malware running on a computer can regulate the power consumption of the system by controlling the workload of the CPU. Binary data can be modulated on the changes of the current flow, propagated through the power lines, and intercepted by an attacker," researchers said.

According to the researchers, attackers can exfiltrate data from the computer at a speed of 10 to 1,000 bits-per-second, depending upon their approach.
The higher speed would be achieved if attackers are able to compromise the power lines inside the target building that connects the computer. This attack has been called "line-level powerhammering."

The slower speed is achieved in "phase-level powerhammering" that that can be exploited from the outside electrical service panel of a building.

In both variants of the attack, the attacker measures and encodes the emission conducted and then decodes the exfiltrated data.

With the line-level PowerHammering attack, researchers were able to exfiltrate data from a PC running an Intel Haswell-era quad-core processor at the rate of 1000 bits/second and an Intel Xeon E5-2620-powered server at 100 bits/second, both with a zero percent error rate.

The phase-level variant attack suffers performance degradation. Due to the background noise in the phase level, (since power is shared with everything else connected, such as appliances and lights), the researchers could achieve speeds up to 3 bits/second at a zero percent error rate, though this increased to 4.2% at speeds of 10 bits/second.

"The results indicate that in the phase level power-hammering attack, desktop computers could only be used to exfiltrate small amount of data such as passwords, credential tokens, encryption keys, and so on," the researchers said.

For more details on the PowerHammer attack, you can head onto the paper [PDF] titled, 'PowerHammer: Exfiltrating Data from Air-Gapped Computers through Power Lines.'

Friday, 13 January 2017

WhatsApp vulnerable to 'backdoor' spying - report

The Facebook-owned mobile messaging service WhatsApp is vulnerable to interception, the Guardian newspaper reported on Friday, sparking concern over an app advertised as putting an emphasis on privacy.
The report said that WhatsApp messages could be read without its billion-plus users knowing due to a security backdoor in the way the company has implemented its end-to-end encryption protocol.
The system relies on unique security keys "that are traded and verified between users to guarantee communications are secure and cannot be intercepted by a middleman," the report said.
But WhatsApp can force the generation of new encryption keys for offline users "unbeknown to the sender and recipient of the messages," it said.
Tobias Boelter, a cryptography researcher at the University of California told the Guardian: "If WhatsApp is asked by a government agency to disclose its messaging records, it can effectively grant access due to the change in keys."
Boelter said he had reported the backdoor vulnerability to Facebook in April 2016 and was told that Facebook was already aware of the issue but that it was not actively being worked on.
The company said in a statement that it provided a "simple, fast, reliable and secure" service.
It said there was a way of notifying users when a contact's security code had changed.
"We know the most common reasons this happens are because someone has switched phones or reinstalled WhatsApp.... In these situations, we want to make sure people's messages are delivered, not lost in transit," it said in a statement.
But the Guardian said it had verified that the security backdoor still exists.
The paper quoted Steffen Tor Jensen, head of information security and digital counter-surveillance at the European-Bahraini Organisation for Human Rights, saying: "WhatsApp can effectively continue flipping the security keys when devices are offline and re-sending the message, without letting users know of the change till after it has been made, providing an extremely insecure platform".
Facebook bought WhatsApp in 2014 but it continues to operate as a separate app.

Thursday, 8 September 2016

eThekwini shuts down e-services after user data leak

The eThekwini Municipality, which comprises Durban, has shut down its e-services website after it was revealed on Thursday that it was potentially leaking personal data.

Fin24 reported on Thursday that the KwaZulu-Natal municipality's e-services website is susceptible to hacking as residents’ personal information such as ID numbers and other data risks being exposed with just the change of a web address.
Local software developer, Taylor Gibb, has said that by simply changing a part of the web URL on the eThekwini website, full details on users can be seen. Gibb outlined this in a blog post that he wrote and posted on Thursday.
In the meantime, eThekwini has pulled down its e-services website.
“eThekwini Municipality is investigating claims that information is being shared relating to customers’ accounts and as a precautionary measure, the Municipality has taken the site offline in order to prevent any unauthorised access to our client data,” the municipality told Fin24 in statement.
Meanwhile, Gibb told Fin24 that it was a trivial task for someone who knew "a thing or two about computers".
“By changing a single portion of the URL, you are able to see full details for any other registered user on the system. You can see their email, ID number, deceased status, gender, account number and cellphone number,” he told Fin24 earlier. 
“The government has an obligation to protect our data, and I have an obligation to alert you that your data is not safe,” he said.
The municipality added that the site was expected to be back online on Monday, September 12.
“In the meantime eServices users can contact the Revenue call centre on 031 324 5000,” the municipality told Fin24.