Showing posts with label Vulnerability. Show all posts
Showing posts with label Vulnerability. Show all posts

Wednesday, 13 March 2013

Pakistani Student Rewarded by $500 USD for detecting HTML Injection Vulnerability in Facebook

Haider Mehmood Qureshi, an independent security researcher from Islamabad has been rewarded with $500 for detecting HTML Injection Vulnerability in Facebook. 

According to Haider, Facebook was vulnerable in HTML code, their are some serious Remote HTML injection. Remote User was able to add any brand Name and Radio buttons, hence allowing Remote HTML injection. It was as simple as it sounds. The issue can also cause adding junk/spam entries into the database.



Bug details:

Vulnerability title: HTML Injection
Vendor homepage: http://m.facebook.com
Remote/Local: Remote
Tested on: Windows 7 64 bit Firefox browser (but should have worked on other OS and browsers (not sure about IE))
Vulnerability Submitted on: 12/1/2013
Vulnerability Status: FIXED


Detail: Facebook mobile provides a survey to evaluate the mobile user experience as they surf Facebook mobile site. Here is the survey https://m.facebook.com/survey.php . While entering the mobile phone brands , it provides a list of brands in case you didn't type the correct brand.


The list that was provided contained their HTML code inside the parameter https://m.facebook.com/survey.php?incorrect_brand&params=[HTML code of Brands and Radio Buttons]
Remote User was able to add any brand Name and Radio buttons, hence allowing Remote HTML injection. It was as simple as it sounds. The issue can also cause adding junk/spam entries into the database.



Haider Mehmood Qureshi, BS Computer Sciences Student from Comsats Intitute of information technology Islamabad. Started learning pentesting/hacking in 2009. Initially was into defacing, later realized to make Pentesting/security auditing as my career. His Friends motivated him to go for bug bounties. 
Contact: haidermehmoodqureshi@yahoo.com


Friday, 7 September 2012

Blogger DNS 0day Vulnerability 2012 By Shadow008, Pakistani Hacker

Blogger DNS 0day Vulnerability 2012

[#] Author : Shadow008
[#] Reported On : The Hackers Media
[#] Country : Pakistani Hacker

New BlogDNS 0day, Discovered By Shadow008
Lets just say, any site pointing to Google server can Be Hacked and Defaced

1st) Find a target where as its subdomain or its main domain is pointing to google or blogger server I.P
2nd) If it is pointing to Google Server I.P, You will see a page 100% like this >> http://ghs.google.com/

404. That’s an error.

The requested URL / was not found on this server. That’s all we know.

If that shows, That means its vul to BlogDNS 0day

3rd) Go to http://www.blogger.com/ and Login / Create an account
4th) Create a Blog
5th) Name it anything you want as a subdomain for blogger.
6th) Once blog is created, Go to Settings > Publishing > Switch To Advanced Mod and add that site URL domain. (example:direct.madleets.com) Please note that it MUST be pointing to google or blogger server I.P.
and Save it.

Clear You cache and go to that sites subdomain which you added. You will see its in your control  .
Now go to Design > Edit HTML > Revert to Classic Template > Add Deface Code There (Switch of Navbar to OFF) and Hit Save, Clear Cache and check site will be defaced  .


Note: I have used Old Blogger Interface, I don't use the New Blogger Interface as I find the old one more easy

I hope it was clear and understood
Have fun and don't share

Special Thanks To Shadow008 for all this

Sites which are hacked using this method:
http://direct.thehackernews.com/
Mirror: http://zone-h.org/mirror/id/18307796

http://direct.pkhackerz.com/
Mirror: http://zone-h.org/mirror/id/18307953

http://mail.dl4hacks.net/
Mirror: http://zone-hc.com/archive/mirror/8d752fd_mail.dl4hacks.net_mirror_.html

Thursday, 6 September 2012

Apple Patches Zero-Day Vulnerability in OS X

Apple Patches Zero-Day Vulnerability in OS X

Java OS X icon


Apple has released its own patches for OS X users affected by a zero-day vulnerability in Oracle’s Java platform that was discovered in August. Java for OS X 2012-005 and Java for Mac OS X 10.6 Update 10 are free updates to all Mac OS versions starting with Snow Leopard.

The Cupertino, California-based Apple Inc. reveals in a security bulletin that Java for OS X 2012-005 and Java for Mac OS X 10.6 Update 10 are now available for Mac OS X v10.6.8, Mac OS X Server v10.6.8, OS X Lion v10.7 or later, OS X Lion Server v10.7 or later, and OS X Mountain Lion 10.8 or later.


 “An opportunity for security-in-depth hardening is addressed by updating to Java version 1.6.0_35,” the Mac maker notes, directing customers to Oracle’s site for more information.

Oracle explains that the flaws don’t apply to Java running on servers or standalone Java applications. Oracle server-based software is also unaffected.

However, a cybercriminal can potentially exploit the flaws remotely, “without authentication, i.e., they may be exploited over a network without the need for a username and password.”

“To be successfully exploited, an unsuspecting user running an affected release in a browser will need to visit a malicious web page that leverages this vulnerability,” Oracle explains. “Successful exploits can impact the availability, integrity, and confidentiality of the user's system.”

Oracle urges customers to apply the updates “due to the severity of these vulnerabilities.”

For its part, Apple instructs Mac users on how to obtain the new Java releases.

“Java for OS X 2012-005 and Java for Mac OS X 10.6 Update 10 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site: http://www.apple.com/support/downloads/,” according to the fruity company in Cupertino, California.

Mac users should note that both these Java updates will configure their web browsers to not automatically run Java applets. However, users can re-enable these by clicking the region labeled "Inactive plug-in" on a web page.

Download Java for Mac OS X (Free)

Tuesday, 4 September 2012

Hackers Create Bogus Microsoft Services Agreement Email To Exploit Users


Hackers create bogus Microsoft Services Agreement email to exploit users

Installs malware based on an exploit in Oracle's Java software

malware virus security threat scam

HACKERS are using a recent Microsoft email notification regarding changes in its Services Agreement to trick people into installing malicious programs based on an exploit in Oracle's Java software.
The SANS Institute's Internet Storm Centre issued warnings about the rogue emails at the weekend, saying that they are based on a 27 August communication from Microsoft about popular products such as Hotmail and Skydrive.
"We're receiving multiple reports of a phishing campaign using the template from a legitimate Microsoft email regarding Important Changes to Microsoft Services Agreement and Communication Preferences," SANS Internet Storm Centre security incident handler Russ McRee said in a blog post.
"The evil version of this email will subject [the] victim to a hyperlink that will send them to a Blackhole-compromised website, which will in turn deliver a fresh Zeus variant."
McRee said that this type of attack is effective because it requires no user interaction to achieve its goal.
Security firm Sophos said in a blog post that the attacks have prompted "renewed calls for internet users to disable Java on their systems" as they await an update from Oracle to fix the Java vulnerabilities.
Microsoft acknowledged the malware when responding to a user question regarding the fake email, and advised users not click on any links.
"If you received an email regarding the Microsoft Services Agreement update and you're reading your email through the Hotmail or Outlook.com web UI, the legitimate email should have a Green shield that indicates the message is from a Trusted Sender," Microsoft representative Karla L said on the firm's Answers website.
"If the email does not have a Green shield, you can mark the email as a Phishing scam. Do not click through the links in the email if you are not sure it is safe."

Oracle's Java Patch Not Enough to Stop Hackers


Oracle's Java Patch Not Enough to Stop Hackers

oracle logo
Despite Oracle's recent Java security patch, hackers found a way into the program and conducted email phishing campaigns directed at Microsoft and Amazon users.
Researchers at the SANS Institute's Internal Storm Center (ICS) and security firm Websense this weekend issued separate reports about the vulnerability, which became public late last month.
ICS focused on fake Microsoft Services Agreement emails that claimed to contain information about "Important Changes to Microsoft Services Agreement and Communication Preferences." The phishing email copied a legitimate, Aug. 27 email from Redmond, but replaced one of the hyperlinks with a virus.
Meanwhile, hackers used illegitimate "Amazon order" emails to deliver malicious links intended to access personal and financial data, according to Websense. On Sept. 1, the security site intercepted more than 10,000 emails with the subject "You Order With Amazon.com," which urged recipients to click on a hyperlink that sent the victim to a Blackhole exploit kit hacking tool.
"This email campaign further illustrates the ingenuity and speed at which cyber-criminals package and propagate malicious content along with social-engineering techniques in order to exploit both recent software vulnerabilities and the trusting nature of end-users," Websense said.
Oracle released an out-of-band fix last week, but didn't patch the hole entirely. Polish firm Security Explorations said Friday that the update contains a bug that allows hackers to bypass and exploit the system. Security Explorations alerted Oracle to the problem on Friday.
Based on Oracle's four-month update cycle, which rolls around again on Oct. 16, a full fix could be on its way next month. In the meantime, PCMag's lead analyst for security, Neil Rubenking, suggested disabling Java altogether.
Earlier this year, the Flashback Trojan infected more than 550,000 Macs when websites exploited the Java flaw that allows Flashback.K to download itself onto Apple computers without warning.

Sunday, 2 September 2012

Critical buffer overflow vulnerability in Photoshop CS6

Critical buffer overflow vulnerability in Photoshop CS6




Adobe has released an update for Photoshop CS6 that closes a critical heap-based buffer overflow vulnerability (CVE-2012-4170) in its popular graphics editing program. Both the Mac and Windows versions of Photoshop CS6 (aka Photoshop 13.0) contain a critical vulnerability that could allow an attacker to take control of affected systems.
Furthermore, company officials say Adobe is unaware of any attacks against this vulnerability.That said, the Photoshop 13.0.1 update contains 75 other bug fixes, including 31 for problems known to cause crashes, 18 pertaining to 3D features, and 15 for drawing and graphics features.

Adobe said that users and administrators can download and install the patch by lunching the "update" tool within the Photoshop help menu.The company credited a pair of Secunia researchers in discovering and reporting the flaw directly.

According to a Secunia advisory, the problem is caused by a boundary error in the "Standard MultiPlugin.8BF" module when processing certain PNG image files. Both Windows and Mac OS X versions of Photoshop CS6 (13.0) are affected and upgrading to the new 13.0.1 release fixes the problem.

ADS-B Is Insecure and Easily Spoofed, Say Hackers


ADS-B Is Insecure and Easily Spoofed, Say Hackers


The ADS-B system that is the cornerstone of the FAA’s NextGen ATC modernization plan is at risk of serious security breaches, according to Brad Haines, a hacker and network security consultant who is worried about ADS-B vulnerabilities. Haines first outlined his concerns during a presentation he gave at the Def Con 20 hacker conference in Las Vegas in July. Automatic Dependent Surveillance-Broadcast (ADS-B) is on track to replace radar with a system that broadcasts GPS-based position data to controllers and other ADS-B-equipped aircraft as part of the NextGen system. Yet according to Haines–aka RenderMan–ADS-B signals are unauthenticated and unencrypted, and “spoofing” or inserting a fake aircraft into the ADS-B system is easy.
 
Haines and another hacker named Nick Foster demonstrated this by spoofing a fake aircraft into the simulated busy airspace over San Francisco, using the open source Flight Gear flight simulator program. Spoofing a target into the real ADS-B system would be a simple matter of transmitting the signal on the ADS-B frequencies (978 and 1090 MHz).

The FAA told AIN that the ADS-B system is secure. “We have ways of validating the data that shows up on a controller’s screen so that spoofed targets are filtered out,” an FAA spokeswoman said. “An FAA ADS-B security action plan identified and mitigated risks and monitors the progress of corrective action. These risks are security sensitive and are not publicly available. The air traffic system is based on redundancies to ensure safe operations. The FAA plans to maintain about half of the current network of secondary radars as a backup to ADS-B in the unlikely event it is needed.”

According to Haines, the FAA’s method for filtering spoofed targets relies on multilateration, which is a technique for identifying a target using ground stations that detect transmissions from the target (usually transponder signals). But such filtering, he pointed out, would remove spoofed targets only from the FAA’s TIS-B feed, which sends ADS-B data to aircraft from ADS-B ground stations. “The spoofing threat can be mitigated with multilateration,” Haines noted. “However, an airplane receiving ADS-B [air-to-air] data has no way to do that.” In other words, an ADS-B in receiver on an aircraft will have no way of telling whether the ADS-B signal that it is receiving is from another aircraft or from a spoofed target transmitted on the ADS-B frequencies.

Longstanding Concerns about ADS-B Security

Concerns about ADS-B security aren’t new. In a 2009 graduate research project at the Air Force Institute of Technology at Wright-Patterson Air Force Base in Dayton, Ohio, Air Force Major Donald McCallie identified ADS-B vulnerabilities. “As early as 2006, concerns were raised about the ability of hackers to introduce as many as 50 false targets onto controllers’ radar screens. With open broadcast and no encryption there is no confidentiality; a lack of any authentication provides no integrity; and the ability to jam signals brings into question availability. The ADS-B infrastructure requires that all surveillance be open, and therefore non-secure, communications. As ADS-B is implemented, the potential exists for an attacker to exploit the inherent vulnerabilities of such an open system,” according to the paper.

McCallie’s paper outlines six key ways that attackers could harm the ADS-B system, ranging from relatively easy disruptions using jamming equipment to more difficult target ghost inject (spoofing) to flood denial, which means disrupting the ADS-B frequencies. While McCallie characterizes airborne target spoofing as a medium-high difficulty operation, he wrote, “Because there is no data correlation like that which may occur in a ground station, it may be somewhat easier to inject a ghost target into an aircraft; although, physical access may offset that advantage.”

Looking even farther back, a paper dated Sept. 18, 2001, and written by the FAA’s Ron Jones raised the issue of ADS-B security in relation to the 9/11 terrorist attacks that had taken place a week earlier. Jones raised two issues: “Probably the most fundamental security issue with ADS-B is the core idea of broadcasting the identity and precise location of each aircraft. This would open the door for a terrorist to attack specific aircraft or aircraft of a specific airline or corporation. While some people have suggested some form of encryption might be applied, I do not see any way in which this could be effective without fully undermining the basic ADS-B concept and associated benefits.” The second issue foreshadowed the current concern with fake targets. “As already briefly noted in DO-242 [RTCA standards] some applications may require independent validation of the ADS-B information. This has two aspects. One is simply to detect failures that result in errors in the reported aircraft location. The second is to detect spoofing and this is the aspect where the security concerns are raised.”

Haines is pleased that his bringing up the issue of ADS-B security has ignited some discussion of the subject, although he told AIN that no authorities have contacted him seeking advice on the system’s vulnerabilities. He also worries that other countries implementing ADS-B are not addressing these security issues. If it were up to him, he said, he would focus on “training, policies and procedures. [And] understanding the risks and that one needs to ask questions like ‘what happens if this thing that is supposed not to fail fails.’ Ifa way for multilateration to be spoofed is found, what then? If our [fake target] attack is actually possible, how does that undermine the reliability?How quickly can the industry adapt? I would also build in more capacity for outside testing. The tools and techniques to screw with this stuff are at a maturity level that make it accessible to most people.Are the FAA et al thinking they have covered every possibility? Just remember how many ‘secure’ systems were compromised by teenagers in their parents’ basements.”

Saturday, 1 September 2012

Mozilla Issues Java Block and Notifications for Firefox


Mozilla Issues Java Block and Notifications for Firefox

Firefox will notify users that the Java plugin has been disabled

Mozilla has implemented the solution to the Java exploits that have been wreaking havoc this past week. A few days ago, Mozilla announced plans to disable the vulnerable plugin in Firefox, but also provide a notification system to let users know that the plugin has been blocked when they visit sites that require it.
That system is now live and users will start seeing the notifications soon. In the meantime, Oracle also released an emergency update to Java fixing the vulnerabilities actively exploited in the wild.

"We have enabled an update notification that will show up every time a user visits a site with a Java applet using a vulnerable Java plugin. The notification points to our Plugin Check page, which should assist users in getting Java up to date," Mozilla announced.

"This block will be initially applied to Windows users and Linux users who have the Oracle version of the Java RE, but we expect to extend it to Mac OS X (where the majority of users are unaffected) and the IcedTea plugin on Linux," it said.

The block is still in place for vulnerable versions, but at least users have a patched version available. Initially, it wasn't clear whether Oracle would update Java ahead of schedule. Mozilla's block would have affected all Java versions, though users would have been able to re-enable the plugin if they needed it.

Mozilla issues this type of blocks quite regularly, unfortunately, to either disable vulnerable plugins or ones that are causing a lot of crashes in Firefox.

The issue should be less of a problem once Firefox gets a proper implementation of the click-to-play plugins feature. The feature is built into Firefox 15 but is disabled by default. Click-to-play plugins should be ready for a wide release by the time Firefox 18 comes out, a few months from now.

Friday, 31 August 2012

Oracle Fixes Java Zero-Day Flaw, Users Advised to Download Patch

Oracle Fixes Java Zero-Day Flaw, Users Advised to Download Patch

Oracle fixes vulnerability in JRE

Although few people expected it (many hoped), Oracle has released an out-of-band patch to address the zero-day flaw that affects Java Runtime Environment (JRE) 7. Since attacks that rely on this vulnerability have already been spotted, the company advises users to immediately apply the patch.

The patch addresses a number of three different, but related, bugs that don’t affect standalone desktop applications or servers. However, they affect Java running on desktop web browsers.


 “Due to the high severity of these vulnerabilities, Oracle recommends that customers apply this Security Alert as soon as possible,” said Eric Maurice, director of software security assurance at Oracle.

“Furthermore, note that the technical details of these vulnerabilities are widely available on the Internet and Oracle has received external reports that these vulnerabilities are being actively exploited in the wild.”

Yesterday we reported that users from the Netherlands were targeted with VAT rate increase emails that led to this particular exploit. Similar campaigns are most likely already active and new ones will probably emerge in the upcoming days.

It’s likely that this vulnerability will be exploited for quite some time because, as we’ve seen on numerous occasions, many users fail to apply patches in time.

Hopefully, at least companies will rush to apply the patch to ensure that cybercriminals are not able to disrupt their business workflow.

The fact that this JRE vulnerability caused so much havoc once again highlights a very important thing. Dangerous security holes are discovered all the time in Java, and although many users don’t actually utilize it, they keep it installed on their computers.

We advise you to take a good look at the applications you’re using and the websites you’re surfing. In case they don’t require Java (most of them don’t), be sure to uninstall it.

The latest (patched) version of Java Runtime Environment is available for download here.


Android Malware Owners Fined by UK Regulatory Body

Android Malware Owners Fined by UK Regulatory Body

PhonepayPlus fines Russian company and forces it to refund users


PhonepayPlus, the organization that regulates all premium rate phone services in the UK, has ordered a Russian company – Connect Ltd – to pay a fine and refund users after researchers highlighted the fact that an application it owned was attempting to trick Android users into signing up to expensive mobile services.

Developers create malicious applications that sign up users to shady mobile services and send SMS to premium rate numbers. When security firms find the malware, they place it on a blacklist and warn users about it, thus preventing the crooks from stealing more money. Then it starts all over again with the release of a new malware.


 However, this may not always be the case and there may be some good news for those who have fallen victim to such crimes, Graham Cluley of Sophos reports.

Back in February, we learned of an application that tricked Facebook users into installing a malicious application on their Android phones. Once it found itself on a phone, the malware sent out an SMS message and subscribed the unwitting individual to a premium service.

After confirming that the application in question presented a suspicious behavior and after determining that the victims might have paid as much as £250,000 ($395,950 or €314,000) for the shady services, PhonepayPlus decided to fine the company.

In case the company doesn’t comply and pay the £50,000 ($79,000 or €63,000) fine and refund all the victims (whether they filed a complaint or not), the agency has the ability to “bring a breach of sanction case” in which a court could impose even tougher penalties.

Besides the considerable fine, in the next couple of years, Connect Ltd will also have to ask PhonepayPlus for permission to offer premium rate services to UK citizens.

Unknown Virus Disrupts World’s Second Largest Liquefied Natural Gas Company


Unknown Virus Disrupts World’s Second Largest Liquefied Natural Gas Company


RasGas headquarters

Another mysterious virus hits the Middle East. This time, the victim is RasGas – a Qatar-based company that’s considered to be the second largest liquefied natural gas (LNG) producer in the world, after Qatargas.

According to Arabian Oil and Gas, the virus disrupted the company’s offices, forcing them to shut down their systems, including the public-facing website rasgas.com.


 The organization’s representatives state that cargo deliveries and operations in Ras Laffan Industrial City haven’t been impacted by the incident.

This is the second time this month when such a firm becomes the target of hackers. Earlier in August, multiple hacktivist groups took credit for disrupting the operations of Saudi Aramco, the world’s largest oil company.

At the time, experts found that the attack – which affected some 30,000 computers – might have involved a piece of malware known as Shamoon. The malware covers its tracks by overwriting the stolen files and by completely wiping the infected device’s master boot record.

Saudi Aramco admitted that its systems have been infected with a virus, but a statement released a few days ago reveals the fact that the organization has addressed the problem.

“We addressed the threat immediately, and our precautionary procedures, which have been in place to counter such threats, and our multiple protective systems, have helped to mitigate these deplorable cyber threats from spiraling,” stated Khalid A. Al-Falih, president of Saudi Aramco.

On the other hand, one of the hacker crews which took credit for the attack, claims to have hit the company once again on August 25. On this occasion they leaked the details of core, backup and middle routers.

Similar to Saudi Aramco, RasGas is expected to publish a statement after its systems will be back online. For now, rasgas.com is still unavailable to visitors.

Thursday, 30 August 2012

Intuit Security Tool Spam Campaign Making the Rounds Once Again

Intuit Security Tool Spam Campaign Making the Rounds Once Again

Fake Intuit email

Around one and a half years ago, malicious emails claiming to originate from Intuit attempted to convince recipients that they need to install a piece of software in order to access their QuickBooks accounts, giving them a three-day deadline to comply.

It seems that this spam campaign has been reinitialized in an attempt to steal sensitive information from Intuit customers. Here’s what these emails look like:


 You will not be able to access your Intuit QuickBooks account without Intuit Security Tool (IST) after 31th of August, 2012.

You can download Intuit Security Tool here.

After a successful download please run the setup for an automatic installation, then login to Intuit Quickbooks online to check that it is working properly.

Basically, the email looks exactly the same as the old variant, but the cybercrooks updated the date, and most likely they’ll continue doing so.

The links from the email currently lead to a compromised website from Denmark on which the cybercriminals planted a phishing webpage.

The company has warned users to avoid such emails ever since the campaign started. They highlight the fact that legitimate emails will never contain “software update” or “software download” attachments.

Furthermore, Intuit will never ask customers for their usernames and passwords. Finally, similar to other organizations, they promise never to request banking information or credit card details via email.

And this is not the only type of Intuit email you should beware of. Back in June we reported that fake Intuit tax information update notifications were making the rounds, luring recipients to another hijacked website from Denmark.

Users are advised to report any suspicious emails to spoof@intuit.com. By reporting suspicious emails you can help the company keep all its customers informed on the latest threats that may be leveraging its reputation to cause damage to the computers of unsuspecting internauts.

Wednesday, 29 August 2012

Latest Java software opens PCs to hackers: Experts

Latest Java software opens PCs to hackers: Experts



BOSTON: Computer security firms are urging PC users to disable Java software in their browsers, saying the widely installed, free software from Oracle Corp opens machines to hacker attacks and there is no way to defend against them. 

The warnings, which began emerging over the weekend from Rapid7, AlienVault and other cyber security firms, are likely to unnerve a PC community scrambling to fend off growing security threats from hackers, viruses and malware. Researchers have identified code that attacks machines by exploiting a newly discovered flaw in the latest version of Java. 

Once in, a second piece of software called "Poison Ivy" is released that lets hackers gain control of the infected computer, said Jaime Blasco, a research manager with AlienVault Labs. 

Several security firms advised users to immediately disable Java software - installed in some form on the vast majority of personal computers around the world - in their Internet browsers. Oracle says that Java sits on 97% of enterprise desktops. 

"If exploited, the attacker will be able to perform any action the victim can perform on the victim's machine," said Tod Beardsley, an engineering manager with Rapid7's Metasploit division. 

Computers can get infected without their users' knowledge simply by a visit to any website that has been compromised by hackers, said Joshua Drake, a senior research scientist with the security firm Accuvant. Java is a computer language that enables programmers to write one set of code to run on virtually any type of machine. 

It is widely used on the Internet so that Web developers can make their sites accessible from multiplebrowsers running on Microsoft Windows PCs or Macs from Apple. An Oracle spokesperson said she could not immediately comment on the matter. 

Security experts recommended that users not enable Java for universal use on their browsers. Instead, they said it was safest to allow use of Java browser plug-ins on a case-by-case basis when prompted for permission by trusted programs such as GoToMeeting, a Web-based collaboration tool from Citrix Systems. Rapid7 has set up a Web page that tells users whether their browser has a Java plug-in installed that is vulnerable to attack: www.isjavaexploitable.com 

Cyber-disclosure norms become rule


Cyber-disclosure norms become rule


Six companies were asked to reveal security threats they face


New York: Securities and Exchange Commission guidelines on when companies should disclose cyber-attacks have become de facto rules for at least six companies, including Google and Amazon.com, agency letters show.
The six companies were asked to break silence and tell investors in future filings that intruders had breached their computer systems, according to the SEC letters. Companies such as Amazon argued that the attacks weren’t important enough to reveal. Hacking admissions can hurt reputations, give competitors useful information and trigger investor litigation.
Before the requests, Seattle-based Amazon, the largest internet retailer, hadn’t said in its reports that cyber-thieves had raided its Zappos.com unit, stealing addresses and some credit card digits from 24 million customers in January. In April, Amazon was asked by the SEC to disclose the cyber-raid in its next quarterly filing, which it did.
Google, the world’s biggest search engine, agreed in May to put its previously disclosed cyber-assault in an earnings report. American International Group, Hartford Financial Services Group, Eastman Chemical Co and Quest Diagnostics were also prodded to improve disclosures of cyber-risks, according to SEC letters available on the regulator’s website.

New Java Zero-Day Exploit Added to Metasploit and BlackHole Exploit Kit


New Java Zero-Day Exploit Added to Metasploit and BlackHole Exploit Kit


Java zero-day exploit added to Metasploit and BlackHole

Soon after the world learned about the existence of a new zero-day that affects all the latest Java run-time environment (JRE) versions, researchers started analyzing the exploit, trying to figure out a solution to protect computers against it.
Security experts from Deep End Research have come up with a patch that they’re willing to share with anyone who’s in charge of administrating company networks. In the meantime, until Oracle comes up with a permanent patch, users are advised to disable Java in their web browsers. 

In case they need Java, internauts are recommended to use two different browsers, but only one of them with Java enabled. The one with Java should be utilized for operations that require the component, and the browser without Java should be used for regular tasks, such as reading emails (the malicious exploit might arrive via email).

These pieces of advice are very important for the following reasons: the exploit has become public and it has been added to Metasploit. Furthermore, according to Brian Krebs, it’s about to be added to the infamous BlackHole exploit kit as well.

The developer of the BlackHole has told Krebs that the price for such an exploit would be around $100,000 (€80,000).

There is one more noteworthy thing about the new exploit. According to Deep End Research, it doesn’t affect Chrome, but Rapid 7 experts – the ones who contributed to adding the exploit to Metasploit – claim that on Windows XP it works not only on Internet Explorer and Mozilla, but also on Google’s web browser.

“Don't know, maybe Rapid 7 'improved' the exploit and you can send them your thanks if you wish, but the original exploit does not work on Chrome,” Andre M. DiMino and Mila Parkour of Deep End Research wrote in a post.

Tuesday, 31 July 2012

Power failure Across India, Hit by Malware Attack

India’s Northern power grid crashed on Monday morning wreaking havoc at airports, railway and metro stations, hospitals and across traffic congested roads, its worst power outage in a decade.

Indian power infrastructure under attack: India losing out millions in just hours same snag developed within just 24 hours of recovery reports say the system is infected by sophisticated malware.
Malware is spreading; today more than 67 crore people are without power. Cyber analysts suspect "PAK"- CHINA nexus behind this attack.


 Hundreds of millions of people have been left without electricity in northern and eastern India after a massive power breakdown.

There are some analyst saying that it is cyber Attack by a Malware but no Indian Authorities confirmed it yet. Authorities are restoring the service suggest the whole thing is out of their skills, meanwhile mainstream media has been barred from reporting as this could bring disgrace to security services of India.

Since the first power trip up on Monday, there have been discussions within the security establishment about the possibility of entities trying to carry out a sophisticated cyber-attack to cripple the grids.

Officials who carried out an audit of critical information infrastructure admit it is "theoretically possible" to cripple India's power grids through a cyber-attack.


Despite such a possibility, the shutdown did not seem to have led to a crisis management procedure that aimed at ruling out or confirming a cyber-attack.

"Given the fact that our grids are vulnerable to a cyber-attack, those responsible for managing grids should have a proactive policy to rule out cyber-attack as part of their crisis management procedures," a senior official said. "But none of it was visible," he added.

Sources aware of contacts among power ministry, power grid authorities and those in both CERT-IN ( Computer Emergency Response Team-India) and NTRO (National Technical Research Organisation) say there was no proactive effort by those responsible for power grids.

However, both CERT-IN and NTRO are believed to have established their own procedures to ensure the shutdowns were not a cyber-attack, having been brought on by massive over-the-limit withdrawals by states to supply electricity for pumps tapping groundwater in the absence of rainfall during this monsoon.

Officials said the government is now discussing possible ways to speed up the setting up of National Critical Information Infrastructure Protection Centre (NCIPC), which would act as the command and control centre for monitoring the critical information infrastructure of the country. NCIPC was recently approved by the National Security Council headed by the Prime Minster.

Sources said the government is also planning to hold a national consultation of all stakeholders involved in critical information infrastructure.

The government is already setting up dedicated CERT-INs for various critical sectors such as power and civil aviation.

Officials point out to breaches reported from power grids in the US, cyber intrusion into the Iranian nuclear network and other such incidents around the world to warn that India needs to have a more robust crisis management procedure that includes proactive ruling out of cyber-attacks.

16 Arrested for hacking Globe Telecom system


MANILA, Philippines – Sixteen people, including several South Korean nationals, have been arrested by police for allegedly hacking into the Globe Telecom’s system to make unbilled international calls.

Director Samuel Pagdilao, Chief of the Criminal Investigation and Detection Group (CIDG), said in a statement Tuesday that nine Koreans and several Filipino suspects have been apprehended through successive raids in Pasig, Manila, and Mandaluyong cities.


He said they belong to a cybercrime group that has been placed under police surveillance for several weeks.

The Koreans were identified as Eun Young Bae, Kwang Ming Song, 27, Junggyn Yang, 30, Kim Tae Hyung alias Martin Kim, Sehun Park, a certain Choi, Jong-Seok alias Edward Choi, Jung Dongchan alias Kevin Jeong, Jinwan Kim alias Liam Jin.

The other suspects were identified as Marcela Dela Paz, Chachin La Evidia Bornales, Christine Joy Gicale Carondoy alias Joya, 18, Joan Gicale Turno alias Queennie, 19, Jazzy Romero de la Cruz, 20, Jessa Grande Llaguno, 18, and Michelle Cambe Nacional, 26.

The suspects will be charged with violation of Republic Act No. 8484 or “Access Devices Regulation Act of 1998,” Pagdilao said.

Senior Superintendent Gilbert Sosa, CIDG’s Anti-Transnational and Cyber Crime Division (AFCCD) Chief, said that Globe had complained about the alleged hacking being done by the suspects through International Simple Resale (ISR) of international calls.

“ISR is an illegal act in the country because it deprives government of unrealized revenues and to the prejudice of Globe Telecom, where unbilled international calls were being charged and rerouted as mere local calls,” Sosa said.

Authorities confiscated computers, network hubs, GSM Modems, and bundles of unused SIM cards of Globe and Touch Mobile that were used to hack into Globe’s networks.

Two vehicles—a black Hyundai Tucson and silver Toyota Camry have also been confiscated by authorities in the raids.

The separate raids were conducted in Tower A, Renaissance 3000 building, Meralco Avenue, Ortigas, Pasig City, Pearl of the Orient Tower, Roxas Boulevard, Ermita, Manila, North Tower, Lee Garden Condominium, Laurel St. Mandaluyong City, and Royal Plaza, Twin Towers, Malate, Manila

Pagdilao said that “the arrests of Korean and Filipino suspects demonstrate the need for a tougher law to deal with new challenges in the fight against cybercrime.”

Last week, CIDG anti-fraud operatives have arrested Hak Mo Kim in Mandaluyong City for hacking into SMART Communications networks.

Thursday, 26 July 2012

Microsoft Names Two Zeus Botnet Operators


Three months after initially disrupting the Zeus botnet, Microsoft officials have named two of the people who they think are behind the malware network, a pair of Ukrainians who already are sitting in jail in the UK.
From the beginning of the anti-Zeus operation, which became public in March, Microsoft officials and lawyers from other organizations, including NACHA, have been trying to identify the dozens of John Does named in the initial legal complaint. Those efforts hadn’t met with any success, until last week when Microsoft named Yevhen Kulibaba and Yuriy Konovalenko as two of the John Does behind the Zeus botnet. The company has told both the FBI and the authorities in the UK of their findings, and also included the men’s names in the amended legal complaint.


“In an amended complaint, filed last week, Microsoft named Yevhen Kulibaba and Yuriy Konovalenko as defendants. Microsoft has learned that these particular defendants were already serving jail time in the United Kingdom for other Zeus malware related charges. Microsoft has advised the U.K. government of the criminal referral to the FBI. By referring this case to the FBI, as we did in September 2011 with our case against the operators of the Rustock botnet, we are affirming our commitment to coordinating our efforts with law enforcement. Our goal is always to work in ways that are complementary to law enforcement. Our hope is that the evidence we provided to the FBI in this case will lead to a criminal investigation that brings the perpetrators to justice,” Richard Boscovich, a senior attorney in Microsoft’s Digital Crimes Unit, said in an analysis of the operation.
The anti-Zeus operation is the latest in a line of botnet takedowns and anti-cybercrime actions undertaken by the Microsoft DCU, a relatively new gorup inside the company that’s devoted to investigating and helping stem cybercrime. The DCU also was involved in the takedown of the Rustock botnet, as well as operations against the Kelihos and Waledac botnets.The Zeus takedown hs been unique for a couple of reasons, chief among them the use of the civil section of the RICO anti-racketeering statute to aid in the investigation.
“In criminal court cases, the RICO Act is often associated with cases against organized crime; the same is true in applying the civil section of the law to this case against what we believe is an organization of people behind the Zeus family of botnets. By incorporating the use of the RICO Act, we were able to pursue a consolidated civil case against everyone associated with the Zeus criminal operation, even if those involved in the ‘organization’ were not necessarily part of the core enterprise,” Boscovich said at the time of the initial Zeus takedown.
Microsoft is working with ISPs to help them identify Zeus-infected machines and alert the users about the infection.

Facebook offer Bug bounty To hackers, who find flaws in its systems

Several companies already reward 'white hat' hackers who responsibly report flaws in their web services, but Facebook is apparently going a step further with payments to those who find vulnerabilities in their internal systems


Facebook and Google have for some time offered bounties to hackers who find vulnerabilities in their public-facing systems, but now the social network has gone a step further by offering to reward hackers who find and report flaws in Facebook's corporate network.

According to a Bloomberg report on Thursday morning, the move will be announced at the DefCon hacking conference. "If there's a million-dollar bug, we will pay it out," Facebook security response chief Ryan McGeehan was quoted as saying.

The idea of a company paying so-called 'white hat' hackers to probe their sites and report flaws — rather than exploiting them — is rare, but far from new. Google and Facebook do it, as do Mozilla, HP and, as of last month, PayPal.

However, rewarding people for breaking into internal systems is an even riskier proposition. According to the Bloomberg piece, Facebook was moved to introduce the new bounty scheme after an external researcher informed the company of a flaw that meant outsiders could listen in to their internal conversations.

Facebook's bug bounty page says the company will pay a minimum of $500 for each responsible disclosure, as long as the bug could "compromise the integrity of Facebook user data, circumvent the privacy protections of Facebook user data, or enable access to a system within Facebook's infrastructure".

The only kinds of bugs that Facebook won't pay out for are those in third-party apps or websites, denial-of-service vulnerabilities, and spam or social engineering techniques, none of which Facebook has any control over.

Monday, 23 July 2012

Hacker Will Expose Potential Security Flaw In Four Million Hotel Room Keycard Locks

The next time you stay in a hotel room, run your fingers under the keycard lock outside your door. If you find a DC power port there, take note: With a few hacker tricks and a handful of cheap hardware, that tiny round hole might offer access to your room just as completely as your keycard.



At the Black Hat security conference Tuesday evening, a Mozilla software developer and 24-year old security researcher named Cody Brocious plans to present a pair of vulnerabilities he’s discovered in hotel room locks from the manufacturer Onity, whose devices are installed on the doors of between four and five million hotel rooms around the world according to the company’s figures. Using an open-source hardware gadget Brocious built for less than $50, he can insert a plug into that DC port and sometimes, albeit unreliably, open the lock in a matter of seconds. “I plug it in, power it up, and the lock opens,” he says simply.

In fact, Brocious’s break-in trick isn’t quite so straightforward. Testing a standard Onity lock he ordered online, he’s able to easily bypass the card reader and trigger the opening mechanism every time. But on three Onity locks installed on real hotel doors he and I tested at well-known independent and franchise hotels in New York, results were much more mixed: Only one of the three opened, and even that one only worked on the second try, with Brocious taking a break to tweak his software between tests.

Even with an unreliable method, however, Brocious’s work–and his ability to open one out of the three doors we tested without a key–suggests real flaws in Onity’s security architecture. And Brocious says he plans to release all his research in a paper as well as source code through his website following his talk, potentially enabling others to perfect his methods.

Brocious’s exploit works by spoofing a portable programming device that hotel staff use to control a facility’s locks and set which master keys open which doors. The portable programmer, which plugs into the DC port under the locks, can also open any door, even providing power through that port to trigger the mechanism of a door lock in which the battery has run out.

The system’s vulnerability arises, Brocious says, from the fact that every lock’s memory is entirely exposed to whatever device attempts to read it through that port. Though each lock has a cryptographic key that’s required to trigger its “open” mechanism, that string of data is also stored in the lock’s memory, like a spare key hidden under the welcome mat. So it can be immediately accessed by Brocious’s own spoofed portable device and used to open the door a fraction of a second later.

Brocious believes that the unreliability of his method stems from timing issues in how his hacked-together unlocking device communicates with Onity’s locks. He doesn’t plan to complete the development and debugging of the technique himself, due to what he says are time constraints and concerns about what a universally effective exploit would mean for the security of millions of hotel guests. But he believes that with more experimentation and tweaking, someone could easily access a significant fraction of hotel rooms around the country without leaving a trace.

In fact, Brocious isn’t the only one who knows his tricks. His former employer, a startup that sought to reverse engineer Onity’s hotel front desk system and offer a cheaper and more interoperable product, sold the intellectual property behind Brocious’s hack to the locksmith training company the Locksmith Institute (LSI) for $20,000 last year. LSI students, who often include law enforcement, may already have the ability to open Onity doors at will.

“With how stupidly simple this is, it wouldn’t surprise me if a thousand other people have found this same vulnerability and sold it to other governments,” says Brocious. “An intern at the NSA could find this in five minutes.”

The ability to access the devices’ memory is just one of the two vulnerabilities Brocious says he found in Onity’s locks. He says the company also uses a weak encryption scheme that allows him to derive the “site code”–a unique numerical key for every facility–from two cards encoded one after another for the same room. By reading the encrypted data off of two cards and testing thousands of potential site codes against both cards until the decoded data displays a predictable interval between the two, he can find the site code and use it to create more card keys with a magnetizing device. But given that he can only create more cards for the same room as the two keys he’s been issued, that security flaw represents a fairly low risk compared with the ability to open any door arbitrarily.

Brocious says he stumbled upon the the flaws in Onity’s locks while working as the chief technology officer for a startup called Unified Platform Management Corporation, which sought to compete with bigger players in the hotel lock industry by creating a universal front end system for hotels that used common lock technologies. Brocious was hired to reverse engineer hotel locks, and Onity was his first target. The discovery of Onity’s security vulnerabilities was entirely unintentional, he says.

UPM failed to find customers or investment and soon folded. With the exception of the sale of his exploit methods to LSI–the biggest sale the startup ever achieved–Brocious kept quiet about his discovery, until now.

“This wasn’t the way we wanted to disrupt the business, exactly,” says Brian Thomason, one of UPM’s founders. “But hey, stuff happens, right?”

In a move that may dismay security practitioners, Brocious never contacted Onity or its parent company United Technologies Corporation to tell the firm about its security flaws, and doesn’t plan to ahead of his talk. But he says that’s because there’s little the company could do: the locks can’t be simply upgraded with new firmware to fix the problem. New circuitboards will have to be installed in every affected lock, a logistical nightmare if millions of locks prove to be vulnerable. “I didn’t want to delay putting this out there any further than I had to. I see no path to mitigate this from Onity’s side,” he says. “The best way to help hotels at this point is educate them about this, not to go through Onity and delay getting the information out longer than I had to.”

When I contacted Onity and provided a detailed description of Brocious’s work, the company responded with this statement: “We have not seen Mr. Brocious’ presentation and cannot comment on the content. Onity places the highest priority on the safety and security provided by its products and works every day to develop and supply the latest security technologies to the marketplace.”

And if Onity’s locks are in fact as insecure and unsecurable as Brocious says, how does he suggest hotels and their guests protect themselves? “Hotels need to come up with a plan to move to more secure locks,” he says.