Google Search

Showing posts with label Opera. Show all posts
Showing posts with label Opera. Show all posts

Saturday, November 23, 2013

Opera breached, has code cert stolen, possibly spreads malware - advice on what to do

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Malware

Norwegian-based Opera, makers of one of the most popular browsers outside the Big Four, has announced a scary-sounding network intrusion.

The official story is still somewhat unclear.

But here are the relevant paragraphs from Opera's official mea culpa document:

On June 19th we uncovered, halted and contained a targeted attack on our internal network infrastructure. Our systems have been cleaned and there is no evidence of any user data being compromised. We are working with the relevant authorities to investigate its source and any potential further extent. We will let you know if there are any developments.

The current evidence suggests a limited impact. The attackers were able to obtain at least one old and expired Opera code signing certificate, which they have used to sign some malware. This has allowed them to distribute malicious software which incorrectly appears to have been published by Opera Software, or appears to be the Opera browser.

It is possible that a few thousand Windows users, who were using Opera between 01.00 and 01.36 UTC on June 19th, may automatically have received and installed the malicious software. To be on the safe side, we will roll out a new version of Opera which will use a new code signing certificate.

The title of the article is Security breach stopped, but that doesn't sound quite right to me.

The conclusions I reached, based on the announcement above, were:

The network was breached.A code-signing key was stolen.Malware has been signed with it and circulated.At least one infected file was posted on an Opera server.That file may have been downloaded and installed by Opera itself.Cleanup and remediation has now been done at Opera.

That sounds a bit more like Security breach not stopped to me.

How else could a signed-and-infected file have been automatically downloaded by an already-installed instance of Opera?

Anyway, wouldn't Opera's auto-update have failed or produced a warning due to the expired certificate?

Until Opera has worked out the answer to these questions, Opera users probably want to assume the worst.

The good news is that the malware involved is widely detected by anti-virus tools, and the period of possible exposure via Opera itself was at most 36 minutes.

? According to Opera, Sophos products block the offending file as Mal/Zbot-FG.

So, if you are an Opera for Windows user:

Download a fresh copy of the latest version (since the buggy download appears to be a thing of the past).Make sure your anti-virus is up to date.If you can spare the time, do an on-demand ("scan now") check of your computer.

If we find out more detail about whether malware was distributed by existing Opera installations or not, we'll let you know.

Sophos can help with an emergency cleanup of your Windows PC.

You can use the standalone Sophos Virus Removal Tool to detect and clean malware. This tool can be used alongside your existing anti-virus. (Free download, no registration required.)

You can download a fully-functioning evaluation version of Sophos EndUser Protection for Windows and use it for malware detection, prevention and clean-up. (Free download, registration required.)

Or you can use the Sophos Bootable Anti-Virus utility. SBAV requires you to download a Windows program to create and then use a bootable CD or USB key, so some technical expertise is recommended. The advantage of SBAV is that it is immune to malware already on your PC, as it runs from a self-contained Linux-based operating system. (Free download, no registration required.)

Follow @duckblog


View the original article here

Wednesday, November 20, 2013

Facebook leak, Canadian spam, Opera breach - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

It's Saturday, and that means 60 Second Security, where we aim to touch on some of the more thought-provoking security topics of the past week in just one minute of video.

Why not give this week's video a go? [Higher resolution available directly from YouTube. Click the Captions icon for closed captions.]

Facebook suffers a data leakage crisis where information uploaded by X about Y may be downloadable by Z.Canada is the last G8 country to go for anti-spam legislation. Only it just got delayed again. Might be ready by 2014. Or 2017.A Korean graphical designer created an "anti-surveillance" font. It doesn't work, but, hey, it's the thought that counts.And Opera wrote up a "Security attack stopped" incident. Except it was more like "Security attack not stopped."

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, anti-spam, anti-surveillance, breach, browser, Canada, certificate, Code signing, data breach, Facebook, font, korean, leak, legislation, Malware, opera, PRISM, Spam, typeface, typography, zxx


View the original article here

Thursday, September 27, 2012

Is Opera *really* the safest browser?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

An online poll conducted on the Naked Security site has come up with an interesting finding: Opera, a relative minnow in the web browser market, is reckoned to be a more secure browser than the likes of Google Chrome, Mozilla Firefox and Internet Explorer.


Poll results, Thursday noon. Click to vote for your favourite

We were interested in discovering which browser our readers would recommend to friends or family who had suffered a computer security problem.

The poll opened on the morning of Monday 3rd September, and saw Chrome and Firefox take an early lead with Internet Explorer, Safari and Opera lagging far far behind.

Everything changed yesterday, however, as Opera surged in its share of the vote. The Norwegian browser - which had earlier only been receiving less than two votes every hour suddenly was receiving five votes every minute!

Impressive for a browser which has a much smaller marketshare than the big players.

Voting. Click for larger version

So, what happened? Had thousands of people suddenly woken up to the realisation that Opera *was* their favourite browser, and that they should vote for it instead of Chrome or Firefox?

Well, we did a little digging around and found that Opera's marketing department wasn't resting on its laurels.

The guys and gals at Opera tweeted and posted on Facebook, inviting their fans to participate in the poll.

Opera tweet. Click for larger version

Opera has some 1.7 million fans on Facebook, so it's really no surprise to see some of them vote for their browser of choice. And sure enough, straight after Opera publicised the poll via social media, the votes for Opera began to flood in.

Opera votes surge. Click for larger version

As of midday in the UK, Opera had raced into the lead.

We don't actually mind that Opera publicised our browser poll - after all, we didn't say that vendors were bound from rallying their supporters. If anything, Opera's marketroids have shown some admirable velocity in encouraging their fans to take part.

But we do suspect that our (admittedly unscientific) poll may have been skewed somewhat by this spike in Opera-loving votes. (Interestingly, there was also a synchronous rise in votes for Opera's rivals - presumably from those who follow Opera on social networks, but aren't necessarily diehard fans).

So, come on Firefox lovers and those of you who think Chrome is the greatest thing since Netscape Navigator - what are you waiting for? There's still time to cast your vote!

And is there really no-one who has a good word to say about Internet Explorer?

Internet Explorer's poor showing

If you have an explanation for IE's poor showing, or think Opera is right to be considered the safest browser, or have any other opinions on the survey - why not leave a comment below?

Follow @gcluley

Thanks to Sara Warner for helping crunch the data, necessary to write this article.


View the original article here