Google Search

Showing posts with label Again. Show all posts
Showing posts with label Again. Show all posts

Tuesday, April 29, 2014

Here we go again: Viber mobile messenger app leaves user data unencrypted

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

viber-app-170Viber, a mobile messenger app that allows users to make phone calls and send text messages and images for free, also gives up plenty of free user data to anyone who wants to listen.

According to researchers from the University of New Haven (UNH) in Connecticut, US, Viber's app sends user messages in unencrypted form - including photos, videos, doodles, and location images.

All of that rich data from users is also stored unencrypted on Viber's servers, rather than being deleted immediately, and is accessible without credentials, just a link, the UNH researchers said.

It's the second cryptographic blunder exposed by UNH researchers in as many weeks - the UNH Cyber Forensics Research & Education Group disclosed on 13 April 2014 that the WhatsApp messenger app also gives away user location data in unencrypted form.

Using a Windows PC as a Wi-Fi access point, the UNH team was able to capture data sent by an Android smartphone with regular traffic sniffing tools, the same approach taken by UNH in their experiments with WhatsApp.

In a video posted on the UNH website and YouTube, the researchers demonstrated capturing messages sent between two test Android phones.

Data can be intercepted by poisoned access points, by malicious users on the same Wi-Fi network, or elsewhere in the network between you and Viber.

In the video, one of the researchers said the unencrypted messages can also be retrieved from Viber's servers by anyone who knows the message URL:

The data is stored on Viber's server in an unencrypted manner. There is also no authentication method used, so anybody who has access to these links can look at this data, retrieve this data, and do whatever they want with it.

The researchers, Dr Ibrahim Baggili and Jason Moore, said in a blog post that they reported the security flaw directly to Viber before publishing their results but did "not receive a response from them."

In a statement to CNET, Viber said it would be releasing a fix soon for Android and iOS, and said the issue has been "resolved."

This issue has already been resolved. It is currently in QA and the fix will be released for Android and submitted to Apple on Monday. As of today we aren't aware of a single user who has been affected by this.

The fact is that an modern online messaging app shouldn't really be "fixing" this sort of blunder - encryption should have been baked in from the start.

And for all that Viber may have "fixed" its apps to exchange data securely now, it hasn't said anything about addressing the insecurities that UNH found in Viber's cloud, where your messages are stored.

The company also lists only Android and iOS as getting updates, leaving users of its numerous other supported platforms in the dark.

That includes users of Viber on the desktop, via Samsung's Bada ecosystem, on Microsoft's various mobile operating systems, and on Blackberry and Nokia phones.

With all of this in mind, Viber's claim that "we aren't aware of a single user who has been affected by this" rings very hollow.

After all, the company didn't bother to apologize for not spotting these problems in its own QA – and putting its customers at needless risk.

whatsapp-viber-snapchatAs is becoming all too common with the new breed of mobile messenger apps - including the Facebook-owned WhatsApp and the photo and video-sharing app Snapchat - security and privacy of user data seems to be an afterthought.

Although both WhatsApp and Viber said they will work to fix their encryption oversights, at times these young companies have exhibited a cavalier and disdainful attitude towards data privacy and security.

Viber, founded in 2010, has had a couple other security incidents in the past year.

In July 2013, a security researcher managed to use pop-up notifications from the Viber app to bypass the lock screen on an Android device.

And in April 2013, Viber's support page was hacked by the Syrian Electronic Army, although no user data was lost in the attack.

WhatsApp's founder Jan Koum famously said that "respect for your privacy is coded in our DNA," after his company was bought out by Facebook for $19 billion in March.

That's a nice sentiment, but WhatsApp has made repeated cryptographic blunders that left user data vulnerable.

Another rapidly growing messenger app, Snapchat, ignored warnings from security researchers that the app allowed unlimited searches of user phone numbers - a flaw that led to an attacker dumping 4.6 million usernames and phone numbers online after Snapchat dismissed the attack as "theoretical."

When asked to appear voluntarily before a Congressional hearing on data breaches, Snapchat refused to testify, leading one US Senator to say the company was "hiding something."

Which is ironic, since hiding user data from prying eyes doesn't appear to be one of the company's strengths.

Despite promises it made to users that their private messages would "disappear forever," Snapchat has acknowledged that user Snaps aren't deleted right away from their servers or from users' phones.

These popular messenger apps may be free, but at a cost to privacy for their hundreds of millions of users.

Follow @JohnZorabedian
Follow @NakedSecurity

Get it now for free...


View the original article here

Saturday, November 30, 2013

Android holed again, JAY Z and “Magna Carta”, Tumblr and HTTPS – 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

How did rapper JAY Z take the concept of Magna Carta to a whole new level?

Watch this week's 60 Second Security and find out!

? Can't view the video on this page? Watch directly from YouTube. Can't hear the audio? Click on the Captions icon for closed captions.

Google's Android operating system has another security hole. Same story as before: uou can tamper with other peoples' digitally-signed packages and Android won't notice.Rapper JAY Z's latest album release, "Magna Carta", was preceded by a custom Android app that had some privacy boffins up in arms.Tumblr managed to forget the S in HTTPS in a recent release of its iOS app. The social networking company is "tremendously sorry."

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Android, APK, app, carter, Code signing, data breach, Data Collection, EPIC, Exploit, exra field, Google, https, ios, Jay Z, master keys, Privacy, sniffing, Social Networking, Spam, Tumblr, vulnerability


View the original article here

Friday, June 7, 2013

iOS 6.1.3 security flaw allows passcode lock bypass... again [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Passcode bypassiOS 6.1.3 has only just been released by Apple, and already a security hole has been followed - allowing anyone to bypass the passcode lock on iPhones, and access private data on the device.

Embarrassingly for the Cupertino company, one of the main reasons for installing iOS 6.1.3 was that it promised to fix other security flaws that allowed the lock screen to be bypassed.

The flaw was found by "videosdebarraquito", who seems to be making a hobby of embarrassing Apple by uncovering lock bypass flaws. In a video he demonstrates that it's not particularly complicated to avoid the iOS 6.1.3 passcode lock if you have physical access to the device and a widget for removing the SIM card.

Here is videosdebarraquito's video, where he demonstrates how the passcode can be bypassed:

It appears that circumventing the passcode lock can allow an unauthorised party access to the device's photo gallery and use the phone.

The good news is that this security flaw can be easily prevented. The passcode bypass relies upon use of the "Voice Dial" feature of iPhones, which is disabled on devices using Apple's Siri voice recognition feature.

If you *aren't* using Siri, then the recommendation is to disable "Voice Dial". If you do that, your device shouldn't be prone to this passcode bypass.

Disable the Voice Dial option

You can disable "Voice Dial" on your iPhone by going to Settings / General / Passcode Lock. (Note that if you have Siri enabled you won't see an option for "Voice Dial" there, as it has been automatically disabled).

Easy as it is to avoid this flaw putting your iDevice at risk, it's still embarrassing for Apple as it comes so soon after other passcode lock bypasses were publicised.

Let's hope that Apple fixes this flaw soon, and shuts a permanent door on passcode lock bypasses.

Follow @gcluley

View the original article here

Monday, May 20, 2013

PWN2OWN results Day Two - Adobe Reader and Flash owned, Java felled yet again

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Adobe, Adobe Flash, Apple, Apple Safari, Featured, Firefox, Google, Google Chrome, Internet Explorer, Java, Microsoft, Oracle, PDF, Security threats, Vulnerability

PWN2OWN 2013 is over.

Day Two ended in a similar fashion to Day One, with everyone who went in to bat slugging the ball into the crowd.

Yesterday, all the mainstream browsers (sorry, Opera fans!) except for Safari fell, though no-one actually tried Safari and failed.

Java fell three times yesterday, though under the contest rules, only the first attacker was due to win the $20,000 prize.

But in a fit of largesse, the sponsors announced that they'd pay up not just to the first successful attacker in each category, but to everyone who popped any of the products:

That put a biggish additional lump of cash on the table, with two more Java attacks to pay out on from yesterday ($40k), and a possible $100k extra if Pham Toan's scheduled attack on IE 10 worked out.

As it happened, IE 10 wasn't owned today.

From the results shown below, it looks as though Pham didn't actually make his attempt, as he's no longer listed at all, not even as trying and failing.

But a pre-registered contestant named Ben Murphy stepped up instead.

Not in person, but through a proxy (I assume this means a human proxy appearing live but following Ben's instructions), who successfully popped Java for a fourth time in the competition.

The final results look like this:

With HP's announcement that everyone will get paid for each attack, the prize monies will be divvied up as follows:

James Forshaw: Java = $20KJoshua Drake: Java = $20kVUPEN Security: IE10 + Firefox + Java + Flash = $250kNils & Jon: Chrome = $100kGeorge Hotz: Adobe Reader = $70kBen Murphy: Java = $20k

The total damage to the prize fund comes out at a whopping $480k.

That's only a fraction of the $p million that Google put up independently for its own Pwnium competition, held in parallel.

That was a chance to hack Chrome OS, Google's locked-down/open-source "browser is the operating system" platform that is largely based around the Chrome browser.

Chrome OS, like Android, is built on a Linux base.

In a similar way that Android has been adapted to suit mobile applications on phones and tablets, Chrome OS is adapted for web applications and the cloud.

Google will no doubt be rejoicing, from both a financial and a marketing point of view, because no-one managed to own the Chromebook (Google's name for laptops designed to run Chrome OS) used in the Pwnium 2013 contest.

And that ends the fun-and-games at this year's CanSecWest conference.

Now all that remains is to discuss whether this sort of "hacking as a professional sport" is the right way to encourage vulnerability research.

Is this competitive approach to vulnerabilities and exploits creating a market for malware that might end up out of control?

Or is it simply matching willing sellers with willing buyers, with some of the the edginess of sports-like competition thrown in?

Let us know your opinion in the comments below...

Follow @duckblog

Tags: Adobe, cansecwest, chrome, Exploit, Firefox, flash, IE, Java, Pwn2Own, reader, Safari, vulnerability


View the original article here

Wednesday, March 27, 2013

Apple (again) washes its hands of the Java mess

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mac and JavaApple's thrown in the towel on the Java mess and has, for the second time in two weeks, blocked all versions of Java on OS X 10.6 (Snow Leopard) and later.

The new block applies to the plugin for Java 7 update 11 version 1.7.0_11-b22, which, like last time, is one build ahead of the current version 1.7.0_11-b21.

According to The Register, the blockade was first noted by the French blog MacGeneration.

Apple issued the update to its XProtect malware-handling system in OS X early Thursday morning. XProtect is a rudimentary anti-malware system built into recent releases of Mac OS X that Apple updates periodically to blacklist certain malware.

The update now blocks all versions of the Java Web plug-in before version 1.7.11.22 (previously the limit was version 1.7.10.19).

The move is likely due to issues outlined in Oracle's latest security alert regarding its Java problem child.

In that most recent Java headache, which came out in mid-January, Oracle's CVE-2013-0422 security alert concerned Java applets being able to escape from Java security and infect PCs with malware.

Within weeks of that security advisory hitting the airwaves, the Polish researcher Adam Gowdiak, who specializes in Java leakage, poked two new holes in it.

Apple's not the only one shunning Java. On Tuesday, Mozilla announced an end to auto-loading of plug-ins for Firefox.

If you haven't already booted Java out of your browser, consider following our simple steps on how to turn off Java in your browser.

Forgive me if it's cavalier to casually suggest unhooking the Java catheter.

It's obviously hard for large, heterogeneous networks to adapt a complex change. As Paul Ducklin notes, sysadmins are complaining that it's just not easy to ditch Java suddenly, and it's thoughtless of Naked Security to suggest it.

Unfortunately, as he also points out, the problem(s) with Java security don't look like they're going away anytime soon, legacy systems or no.

I welcome input from sysadmins on how you're dealing with the Java issue, beyond, presumably, tearing your hair out.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Saturday, July 2, 2011

MasterCard Taken Down by Hackers Again in Support of WikiLeaks

Hackers have attacked MasterCard's website in protest of the company's blockade of WikiLeaks.

"MasterCard.com DOWN!!!, thats what you get when you mess with @wikileaks @Anon_Central and the enter community of lulz loving individuals :D," tweeted @ibomhacktivist, who seems to be connected with the hacker collective Anonymous.

[More from Mashable: LulzSec Shuts Down, Ends Hacking Campaign]

Though MasterCard's site is currently online, there are reports that it was completely offline at one point due to the DDoS (distributed denial of service) attack.

In December 2010, hackers took down Mastercard's website, along with Postfinance and PayPal, for the exact same reason: a WikiLeaks blockade.

[More from Mashable: Dropbox Bug Made Accounts Accessible Without Passwords]

Shortly after the attack on MasterCard, WikiLeaks acknowledged on its official Twitter account that several banks still won't do business with the organization. "The unlawful banking blockade against WikiLeaks in 6th month: The culprits: VISA, MasterCard, PayPal, Bank of America, Western Union," said the tweet.

LulzSec, the hacker group that wreaked havoc on corporate and government websites in the past two months, recently disbanded. However, the Anonymous hacktivist collective vowed to continue their hacking activities, and we can already see proof that they weren't kidding.

[via Finextra]

This story originally published on Mashable here.


View the original article here