Google Search

Showing posts with label Adobe. Show all posts
Showing posts with label Adobe. Show all posts

Monday, May 20, 2013

PWN2OWN results Day Two - Adobe Reader and Flash owned, Java felled yet again

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Adobe, Adobe Flash, Apple, Apple Safari, Featured, Firefox, Google, Google Chrome, Internet Explorer, Java, Microsoft, Oracle, PDF, Security threats, Vulnerability

PWN2OWN 2013 is over.

Day Two ended in a similar fashion to Day One, with everyone who went in to bat slugging the ball into the crowd.

Yesterday, all the mainstream browsers (sorry, Opera fans!) except for Safari fell, though no-one actually tried Safari and failed.

Java fell three times yesterday, though under the contest rules, only the first attacker was due to win the $20,000 prize.

But in a fit of largesse, the sponsors announced that they'd pay up not just to the first successful attacker in each category, but to everyone who popped any of the products:

That put a biggish additional lump of cash on the table, with two more Java attacks to pay out on from yesterday ($40k), and a possible $100k extra if Pham Toan's scheduled attack on IE 10 worked out.

As it happened, IE 10 wasn't owned today.

From the results shown below, it looks as though Pham didn't actually make his attempt, as he's no longer listed at all, not even as trying and failing.

But a pre-registered contestant named Ben Murphy stepped up instead.

Not in person, but through a proxy (I assume this means a human proxy appearing live but following Ben's instructions), who successfully popped Java for a fourth time in the competition.

The final results look like this:

With HP's announcement that everyone will get paid for each attack, the prize monies will be divvied up as follows:

James Forshaw: Java = $20KJoshua Drake: Java = $20kVUPEN Security: IE10 + Firefox + Java + Flash = $250kNils & Jon: Chrome = $100kGeorge Hotz: Adobe Reader = $70kBen Murphy: Java = $20k

The total damage to the prize fund comes out at a whopping $480k.

That's only a fraction of the $p million that Google put up independently for its own Pwnium competition, held in parallel.

That was a chance to hack Chrome OS, Google's locked-down/open-source "browser is the operating system" platform that is largely based around the Chrome browser.

Chrome OS, like Android, is built on a Linux base.

In a similar way that Android has been adapted to suit mobile applications on phones and tablets, Chrome OS is adapted for web applications and the cloud.

Google will no doubt be rejoicing, from both a financial and a marketing point of view, because no-one managed to own the Chromebook (Google's name for laptops designed to run Chrome OS) used in the Pwnium 2013 contest.

And that ends the fun-and-games at this year's CanSecWest conference.

Now all that remains is to discuss whether this sort of "hacking as a professional sport" is the right way to encourage vulnerability research.

Is this competitive approach to vulnerabilities and exploits creating a market for malware that might end up out of control?

Or is it simply matching willing sellers with willing buyers, with some of the the edginess of sports-like competition thrown in?

Let us know your opinion in the comments below...

Follow @duckblog

Tags: Adobe, cansecwest, chrome, Exploit, Firefox, flash, IE, Java, Pwn2Own, reader, Safari, vulnerability


View the original article here

Monday, May 6, 2013

Apple bans outdated Adobe Flash plugins from Safari

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Last week, Apple showed that it is getting more serious about security by turning all strict about the version of Flash you're allowed to use in Safari.

OS X users received an automatic update via Apple's basic threat protection system, Xprotect, to lock old Flash player plugins out of your browser. If your browser is Safari, of course.

The idea is simple, and a good one.

Once Apple thinks you've had enough time to get around to updating Flash (two days in the case of the most recent update), it issues a new Xprotect signature that pretty much forces your hand.

Presumably (and we don't know, because this is the first time Apple has done this for Flash, though it did something similar for Java back in January 2013), the amount of time you get before Apple drops the hammer will vary depending on the apparent risk.

The most recent update was an emergency fix for an in-the-wild exploit that was being used against both Windows and Mac users.

Two days to patch an at-risk computer that you use for browsing is brisk, but nevertheless seems pretty reasonable to me.

According to Apple's notification, the Xprotect update turned up on 28 Feb 2013, and produces a warning like this inside the window that Flash is trying to use:

Clicking on it takes you to an OS X supplied dialog that explains more:

From here, of course, at least as things stand today), there's not much that Apple and OS X can do except to shovel you into Adobe's update process, so, as Apple explains, the dialog doesn't achieve much more than taking you to Adobe's Flash Player installer website.

You have to complete the necessary process yourself:

As I've mentioned previously, Adobe's update process is straightforward, but mildly intrusive, as it requires you to shut down many applications, including the browser from which you got to Adobe's download page in the first place.

If you back off at this point so you can come back later when it's more convenient, Adobe will will re-download the whole installer, which is a further annoyance for those on the road, who may be paying over the odds for bandwidth.

But it works, and it's worth doing: Flash, like Java, is a popular, multi-platform attack vector for the Bad Guys, with three updates in February 2013 alone (on the seventh, the twelfth and the 26th of the month).

Don't forget that you can check whether you have Flash active in your browser, and, if so, what version you are using by visiting Adobe's Flash/About page.

This also handily shows you what versions are current on which platforms:

Solaris users will be surely be happy to note they're still on the list, albeit a couple of point releases behind.

Follow @duckblog


View the original article here

Wednesday, December 5, 2012

Six critical vulnerabilities in Adobe Shockwave patched

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Adobe ShockwaveIf your Windows or Mac computer uses the Adobe Shockwave Player, it's time to update your systems.

Adobe has issued an advisory, warning of a number of security vulnerabilities in its Shockwave media player software, and is urging users to update to Adobe Shockwave Player 11.6.8.638.

According to the firm, the update addresses vulnerabilities that could allow attackers to run malicious code on affected systems. Specifically, it addresses buffer overflow and array out of bounds vulnerabilities that could lead to code execution.

In plain English, unless you are up-to-date with your patches boobytrapped Shockwave content could infect your computer with a Trojan horse or other form of malware.

Adobe recommends that users of Adobe Shockwave Player 11.6.7.637 and earlier update to the new version 11.6.8.638 immediately. It's available from Adobe's website at get.adobe.com/shockwave/.

Note that Adobe Shockwave is a different technology from the more commonly encountered Flash software from the same company.

Many users may not have any requirement for Shockwave. You can check if your computer currently has Shockwave installed by visiting this page on the Adobe website.

http://twitter.com/gcluley

View the original article here

Monday, October 29, 2012

Adobe revokes certificate after hackers compromise server, sign malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

AdobeAdobe security chief Brad Arkin has warned that hackers have managed to create malicious files with Adobe's digital code-signing signature.

According to a blog post published on Thursday, the issue appears to have been the result of hackers compromising a vulnerable build server.

Malware seen using the digital signature includes pwdump7 v 7.1 (a utility that scoops up password hashes, and is sometimes used as a single file that statically links the OpenSSL library libeay32.dll.)

According to Adobe, the second malicious utility is myGeeksmail.dll, a malicious ISAPI filter.

Adobe blog

Adobe plans next week to revoke the certificate for all code signed after July 10, 2012, according to an advisory from the company:

The certificate revocation will affect the following certificate:

sha1RSA certificateIssued to Adobe Systems IncorporatedIssued by VeriSign Class 3 Code Signing 2010 CASerial Number: 15 e5 ac 0a 48 70 63 71 8e 39 da 52 30 1a 04 88sha1 Thumbprint: fd f0 1d d3 f3 7c 66 ac 4c 77 9d 92 62 3c 77 81 4a 07 fe 4cValid from December 14, 2010 5:00 PM PST (GMT -8:00) to December 14, 2012 4:59:59 PM PST (GMT -8:00)

However, even when a CA (Certificate Authority) revokes a certificate for an abused private key, any digital signature made before the revocation date will remain valid.

This very topic was covered in a paper presented by my SophosLabs colleague Mike Wood at the Virus Bulletin conference in Vancouver two years ago, "Want My Autograph? The use and abuse of digital signatures by malware".

For that reason, Adobe will be publishing updates for those existing Adobe software products which are signed using the compromised certificate.

SophosLabs has released detection for the malicious files that Adobe references in its advisory, identifying them as Troj/HkCert-A.

SophosLabs researchers are also actively exploring whether there are other threats that may have misused the same certificate.

Further information can be found in Adobe's security advisory (APSA12-01).

Since Mike Wood discussed the abuse of digital signatures in Vancouver two years ago, there have been several stories about certificate abuse in attacks.

It is probably just an odd coincidence that news of this latest instance of certificate abuse has come to light while the world's leading anti-virus experts are once again meeting at the Virus Bulletin conference, this time in Dallas.

Follow @SophosLabs

View the original article here

Saturday, October 1, 2011

Flashback Mac Trojan poses as Adobe Flash update, opens backdoor

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Mac users are once again being reminded to keep their anti-virus software up-to-date, following the discovery of a Trojan horse that poses as an update to Adobe Flash.

The OSX/Flshplyr-A Trojan horse (called "Flashback" by our friends at Intego, who first publicised it), is disguised as an installer for the popular Adobe Flash program.

Mac backdoor Trojan

Once in place, Trojan horse could allow a remote hacker to gain access to your computer or download further malicious code to your Mac.

Sophos products, including Sophos's free anti-virus for Mac home users, detects the Flashback malware as OSX/FlshPlyr-A.

Sophos Anti-Virus detecting the Mac malware

It's easy to imagine how cybercriminals could trick Mac users into infecting their computers with this malware.

For instance, it would be child's play to create a website which pretends to show something salacious ("Scarlett Johansson nude video!" would probably do well at the moment, for instance) and then when you try to view it, you're prompted to install an update to Adobe Flash. Of course, rather than the genuine Flash you would be installing the Trojan horse.

Similar tricks have certainly worked well in the past - against both Windows and Mac users.

Here's a video of another malware attack that tripped up Mac and Windows users, by duping them into installing a fake update to watch a sex movie of Leighton Meester:


(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like)

Maybe now you can see just how easy it is for some folks to fall for this kind of trick. This is just one example of if happening in real life, there have been plenty of others.

Flashback is just the latest example of Mac malware follows hot on the heels of another Trojan horse for the OS X platform. The OSX/Revir-B Trojan was discovered, displaying a political hot potato of a PDF as a distraction while it did its dirty work.

We all know that there is much much more malware written for Windows than there is for Mac OS X. But that doesn't mean it's non-existent, and it's no excuse for leaving Apple Macs unprotected.

Sophos Anti-Virus for Mac Home Edition is fully-functioning and free for home use. What have you got to lose?

Follow @gcluley

View the original article here