Google Search

Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Sunday, April 27, 2014

Microsoft devours Nokia and charges ahead with Windows Phone 8.1

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

microsoft-nokia-170Microsoft's multi-billion-dollar deal to acquire the devices arm of mobile phone maker Nokia is finally done, and smartphones under the name Microsoft Mobile will soon be rolling out of Nokia's former factories.

The acquisition, which will be finalized on Friday 25 April 2014, gives Microsoft complete ownership of Nokia's Windows Phones, including the flagship Lumia.

Nokia's web and social media properties will continue for up to a year under Microsoft, along with the bulk of its manufacturing facilities, Microsoft's General Counsel and Executive Vice President Brad Smith said in a blog post.

According to a leaked letter from Nokia to its suppliers, the company's official name of Nokia Oyj will be changed to Microsoft Mobile Oy ("Oy" denotes that it's Finnish Limited company).

nokia-history-logoWhat Microsoft is hoping to get out of the deal is a chance to make Windows Phone the alternative to the iPhone and popular Android devices like the Samsung Galaxy.

Windows Phone 8.1 steps up to the competition with consumer-friendly features such as Cortana, the virtual assistant that is Microsoft's answer to Siri on the iPhone.

Smith said the deal will "accelerate innovation and market adoption for Windows Phones."

The completion of this acquisition follows several months of planning and will mark a key step on the journey towards integration. This acquisition will help Microsoft accelerate innovation and market adoption for Windows Phones. In addition, we look forward to introducing the next billion customers to Microsoft services via Nokia mobile phones.

With BlackBerry falling off the charts, Windows Phone is still a distant third to Apple and Android smartphones, at around 3% marketshare in 2013, but projected by IDC to reach about 4% in 2014 and 7% in 2018.

nokia_lumia_930_range-170The Nokia Lumia series of devices mirrors the iPhone, but Microsoft also gets the Nokia Asha, a feature phone version of that's really popular in emerging markets, where Windows Phones have taken off.

On top of that, Microsoft is giving away Windows Phone 8.1 to equipment and device manufacturers, in an effort to take some of the OS market share away from Google's Android.

Microsoft's commercial spots advertising the Nokia Lumia series of Windows Phones target the younger, social media and photo sharing buffs, highlighting its 41 megapixel camera and sharing apps.

But it's not just consumers Microsoft is eyeing - industry watchers observe that Windows Phone is poised to make inroads in the enterprise market and presents an attractive alternative to Android.

Microsoft says Windows Phone 8.1 is its most business-friendly version yet.

It has all the native Microsoft apps built in, for free, on devices with screens smaller than nine inches, and helps Microsoft move closer to a universal OS for Windows PCs, tablets, and smartphones.

Windows Phone 8.1 brings a lot of features that should appeal to enterprise customers who need to meet data security requirements, including full-device encryption, remote lock-and-wipe, app control, secure VPN, and more options for device, app, and certificate management.

Businesses can manage updates from a mobile device management system from Microsoft, or use third party software.

As Timothy Green wrote for The Motley Fool, with Windows Phone 8.1 Microsoft has finally caught up to Google in terms of features, and the growth potential in the mobile market is "significant" (and he's not the only one saying that).

Presumably because of its small user base, Windows Phone isn't currently attracting much attention from cybercriminals, but security is obviously still a concern and incidents still happen.

In March, Microsoft's app market - Windows Phone Store - mistakenly approved several fake Google apps before taking them down from the store.

Malicious or phony apps appear from time to time in Google Play, and although Google's system for policing apps in the Play Store has kept malware apps out pretty well, abusive advertising practices have been hard to control.

Microsoft has developed its own program for finding apps that violate its terms of service for advertising, and according to the MIT Technology Review, Microsoft's "Monkey" program uncovered that 1,000 of the Windows Phone Store's 50,000 apps violated the terms.

So, does Windows Phone 8.1 get security right?

Naked Security writer Paul Ducklin says the Microsoft approach, with its locked down mobile OS and closely monitored app market more closely resembles that of Apple than Google's more diverse and widespread Android ecosystem.

Of course, there are security risks no matter which OS you have on your smartphone, including Windows Phones.

If you upload the right file to the wrong person, or lose a smartphone without having encrypted or locked it, or type in your banking password on an imposter site, you may end up in harm's way regardless of your operating system.

Will Windows Phone 8.1 security features help Microsoft make inroads to the enterprise market?

Whatever happens, it's going to be interesting to see how the Microsoft-Nokia integration goes and if the market responds.

Follow @JohnZorabedian
Follow @NakedSecurity

Images of Nokia Lumia smartphones and Nokia seal courtesy of Microsoft.

Tags: adware, Android, BlackBerry, Google, Google Play Store, Microsoft, Mobile device management, Nokia, Samsung, Windows 8.1, windows phone, Windows Phone 8.1, Windows Phone Store


View the original article here

Sunday, June 30, 2013

Microsoft tells all Windows 7 users to uninstall security patch, after some PCs fail to restart

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft has advised all users of Windows 7 (and the server version, Windows Server 2008) who installed a security update on Tuesday to uninstall it, after some customers found their computers would not restart or applications would not load.

Users who experienced problems described how they saw fatal system errors like the following:

Windows fatal system error

STOP: c000021a {Fatal System Error}
The Session Manager Initialization system process terminated unexpectedly with a status of 0xC000003a (0x00000000 0x00000000).
The system has shutdown.

The problem appears to be connected with Update 2823324 in Microsoft Security Bulletin MS13-036, a security update for the Windows file system kernel-mode driver (ntfs.sys).

In a blog post on the Microsoft Security Response Center, the company blamed the problem on conflicts with third-party software:

We are aware that some of our customers may be experiencing difficulties after applying security update 2823324, which we provided in security bulletin MS13-036 on Tuesday, April 9. We’ve determined that the update, when paired with certain third-party software, can cause system errors. As a precaution, we stopped pushing 2823324 as an update when we began investigating the error reports, and have since removed it from the download center.

Contrary to some reports, the system errors do not result in any data loss nor affect all Windows customers. However, all customers should follow the guidance that we have provided in KB2839011 to uninstall security update 2823324 if it is already installed.

According to media reports, computers in Brazil have been particularly badly hit - with machines continually rebooting.

Windows 7 patchMicrosoft's knowledgebase article on this issue, explains that one symptom of the bug can be that Kaspersky Anti-Virus for Windows may display a message claiming its license is invalid, and that as a consquence it may no longer provide anti-malware protection.

Microsoft has already acknowledged the issue and said that it’s working on a fix. Yes, that's right. Some people had problems with the Patch Tuesday update, so there will be an update. But in the meantime, don't update the bit that's broken.

Users are recommended to block the 2823324 security update or uninstall it if its already present. More information on how to do this is detailed in this Microsoft knowledgebase article.

Follow @gcluley

View the original article here

Friday, April 5, 2013

Microsoft readies monster-sized security patch for Windows users

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mud golem. Image from ShutterstockPatch Tuesday is approaching, and for users of Microsoft's software it's going to be a monster.

In all, 57 separate security flaws are waiting to be fixed.

Perhaps the biggest concern will be related to the security holes in Internet Explorer.

According to Microsoft, every single version of Internet Explorer - from version 6 to version 10 - needs to be patched, as they are vulnerable to exploitation by drive-by attacks.

That means that simply visiting a boobytrapped webpage could silently infect your computer with malware - hijacking your PC for a hacker's own ends.

According to an advisory from the software giant, five of the 12 security updates have been given Microsoft's highest severity rating of "critical".

The worry will be, of course, that malicious hackers will examine the patches released by Microsoft and attempt to release exploit code to take advantage of vulnerable computers shortly afterwards.

The longer you take to update the security patches on your computer, the greater potential risk you could find yourself in.

Of course, the worry is even worse for corporations - many of whom are reluctant to automatically roll-out Microsoft security patches until they are confident that they don't cause conflicts that could increase calls to the internal support department.

So, if you are responsible for the security of your computer - do try to install the patches promptly.

If you work at a firm where there is a team who look after the computers on your behalf, buy them a cup of coffee and show a little more consideration next time you ring up to say that the laser printer has run out of toner again - it can't be much fun to have to deal with the multitude of security patches that come out every month.

Microsoft's security patches, alongside more detailed information, are due to be released at 1:00pm EST on Tuesday 12th February. Aside from Internet Explorer, other affected software dealt with by the patch includes Microsoft Windows, Server Software, Office, and .NET Framework.

Follow @gcluley

Mud golem image from Shutterstock.


View the original article here

Tuesday, February 26, 2013

Windows tablets - easy, one-stop jailbreak now available for everyone. What should Microsoft do? [POLL]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Earlier this week, Chester wrote an article about what he referred to as the "jailbreaking" of Windows RT.

That "jailbreak" was a means of liberation that allowed you to run traditional desktop-style applications of your own choice, painstakingly worked out by a smart and well-organised hacker (in the benevolent and complimentary sense of the word) called @clrokr.

? Windows RT, very loosely speaking, is Windows 8 ported to the ARM processor and locked down. You can't alter the bootloader (preventing you switching to, say, Android or Linux) and you can't install anything other than Windows-approved apps from the Windows Store. From a flexibility standpoint, Windows RT is to Windows 8 as iOS is to OS X.

The quotation marks around the word "jailbreak" were Chester's own, as it isn't a method for the fainthearted.

You need to: use the Windows RT remote debugger, assemble some ARM code, patch it into memory, find where KERNEL32 is loaded, and use it to help you find the location of an operating system component you'll need in a moment. (You can't guess where it is because of Address Space Layout Randomisation, or ALSR).

That's just the start of the "jailbreak".

Once you've located the needed system function (NtQuery­System­Information), you use it to locate a second system function (TerminalServer­RequestThread) that includes a call to a third function that is exploitable (NtUser­SetInformation­Thread).

Then you set a breakpoint to grab control just after the vulnerable function call, redirect execution to your previously-entered patch, and finally unset the breakpoint and let the operating system go back on its merry way.

Phew. Now you can draw breath.

All this to adjust a single byte in kernel memory: the place where the operating system remembers how much slack it will cut you in respect of code signing.

The lower the value, the more relaxed the system will be. Drop it to zero and you have effectively made Windows RT as liberal as Windows 8.

Despite the complexity, Chester guessed that "someone [would] create a tool to replicate @clrokr's efforts for those with less knowledge of a debugger."

And that's exactly what happened. A helpful coder called Netham45 has already released his RT Jailbreak tool.

In Netham45's own words, it's an "all-in-one program to jailbreak Windows RT tablets using the method recently released by clrokr."

Grab it today if you have a Windows RT tablet and you want the freedom to run desktop applications. A growing list of ported applications has already sprung up on the XDA website.

You can get software such as the TightVNC server and client (so you can do screen sharing), PuTTY (so you can run SSH and administer your UNIX boxen), various text editors popular with coders, and a Nintendo Gameboy emulator (because you know you want it).

That's good news. Isn't it?

? Netham45's jailbreak won't survive a reboot. The secure bootloader ensures that the code signing level gets set back to 8 after a restart. But Netham45 wants you to know that this is not a tethered jailbreak. That would mean you'd need to connect (tether) your tablet to another device, usually a PC, to reboot it. This jailbreak runs from the tablet itself. Netham45 also reminds you that his tool is not intended to assist with piracy, and, for that matter, doesn't.

One question, of course, is, "What will Microsoft do?"

When Microsoft released the Kinect depth-sensing camera a couple of years ago for its gaming platform, the open source community immediately began to work on open-source drivers for it.

At first, Redmond was apparently unamused, to the point of bringing the cops into it:

Microsoft does not condone the modification of its products. With Kinect, Microsoft built in numerous hardware and software safeguards designed to reduce the chances of product tampering. Microsoft will continue to make advances in these types of safeguards and work closely with law enforcement and product safety groups to keep Kinect tamper-resistant.

Two weeks later, when the open source hackers had not only got the Kinect working for themselves, but already adopted it as a groovy technological darling, Redmond changed its mind just as quickly, with one Microsoft "experience creator" effusive with her praise:

I'm very excited to see that people are so inspired that it was less than a week after the Kinect came out before they had started creating and thinking about what they could do.

The issue of whether Microsoft would take legal action against Kinect hackers went from "working closely with law enforcement" to "absolutely not."

How do you think Microsoft will react this time?

Tell us what you think the Legal Beagles in Redmond ought to do by voting in our poll!

Follow @duckblog


View the original article here

Wednesday, February 13, 2013

Windows RT "jailbroken", shows its Windows 8 roots

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Open cage image courtesy of ShutterstockHey Windows RT, your roots are showing!

Not that it is all that surprising to most people, but the first person to post about jailbreaking a Microsoft Windows RT device says it is a direct port of Windows 8.

Microsoft has gone to some lengths to disguise this fact: no desktop mode applications (except Office, Explorer and IE10), only runs software from the Windows Store and can't install an alternative OS.

The primary difference aside from CPU architecture is that Windows RT has the "minimum signing level" of executable code set to require Microsoft's digital signature.

This ensures no other desktop applications can be loaded and only software approved by Microsoft can execute.

This is the essence of Microsoft's approach to locking down, or jailing, applications. This is hoped to prevent malware from infecting RT devices as well as ensuring Microsoft a tidy profit on application sales.

A security researcher known as @clrokr used their knowledge and access to Windows 8 systems to determine how they might go about changing the minimum code signing level used to implement Microsoft's restrictions.

Being that Windows RT is a direct Windows 8 port made this attack surprisingly easy. Observing memory addresses in Windows 8 and working with a remote debugger they were able to locate the right byte to modify.

While it involves a level of expertise few users possess, I imagine someone will create a tool to replicate @clrokr's efforts for those with less knowledge of a debugger.

The technique @clrokr used can only modify this setting in memory, so it will not survive a reboot. This is similar to jailbreaks on iOS devices known as a "tethered jailbreak".

Jailbreaking your Windows RT device comes with the same caveats as does hacking your Android or iDevice.

While you gain the freedom to run any code you like, you also become responsible for that code and ensuring it isn't doing something you don't want it to.

If jailbreaking Microsoft tablets becomes a popular way to run pirated applications we may begin to see more malicious apps like have been observed on Android.

Let's hope that the goal of unlocking these tablets remains for research and flexibility purposes and we can avoid that unfortunate outcome.

http://twitter.com/chetwisniewski

Open cage image courtesy of Shutterstock.


View the original article here

Tuesday, January 29, 2013

Windows passwords: "Dead in Six Hours" - paper from Oslo password hacking conference

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Windows

OK, so Dead in Six Hours isn't quite what the paper is called. I made that up.

It's actually called Exacerbating Global Warming. (It is. Really.)

In the paper, researcher Jeremi Gosney describes a pet project of his.

He's lashed together 25 AMD Radeon Graphics Processing Units (GPUs) into a specialised computing cluster.

It will cost you about $20,000 to build one, and you'll need twenty rack units of space in a server room. (That's just under a rack-metre.)

You'll also need an industrial-style power supply delivering 7kW, which is where the paper's title comes from, plus some half-decent air conditioning.

In return for your investment, claims Gosney, you'll be able to brute-force all regular eight-character Windows passwords from their NTLM hashes in about six hours.

That's about four times faster than Gosney's previous top-end hashbusting machine, which needed 24 hours - an entire day! - to do the same job.

Why so fast? And why Windows passwords?

The reason is that NTLM relies on one of the easiest-to-crack hashing systems still in widespread use: a straight, unsalted, uniterated MD4 hash of your password. (The raw password is presented in little-endian UCS-2 format, with 16 bits per character, not as an ASCII string.)

If you have a UNIX-flavour command prompt and some common utilities handy, you can convert any ASCII password to its NTLM hash like this:

$ echo -n "password" | iconv -f ASCII -t UCS-2LE \ | openssl dgst -md4(stdin)= 8846f7eaee8fb117ad06bdd830b7586c

Note that, with no salt, everyone who chooses "password" as a password will end up with the same hash, so you can use a pre-computed database of common hashes.

But with Gosney's cracker, you might as well not bother pre-calculating anything: you can churn through nearly 400,000,000,000 MD4 hashes per second and save yourself the space you'd need to store the lookup table.

Big deal, you say. Microsoft no longer recommends NTLM anyway, and Active Directory logins don't use it.

But perhaps consumers and small businesses should be worried? After all, if you have an ad hoc network of Windows computers, without Active Directory or a Windows domain, you're still wedded to NTLM.

In fact, any local accounts on a Windows PC have NTLM hashes stored locally in the Security Accounts Manager (SAM) database. Grab the hashes, and you can attack them offline.

Big deal, you say. If hackers can leech your SAM database, they've already got Administrator rights, so they don't need your password.

But if they do get and crack your password hashes, they may be able to get back in later at their leisure, even if you close the security hole they used to grab your SAM data. And they'll have the plaintext of your password, which could cost you if you have used it anywhere else.

So here are two lessons we can learn from this:

Eight characters just isn't long enough for a password these days.

? Choose long and complex passwords, or use a password management tool to help you. That way, you keep ahead of the bulk cracking tools. If eight characters gives 98-to-the-power-8 choices, adding just three more randomly-chosen characters multiplies that by a further 98-to-the-3, or close to 1,000,000-fold.

You probably have other passwords even more easily crackable than your Windows one.

Some websites or online services may even even keep plaintext, or unhashed, copies of your password. Cracking time for those is zero.

? Don't use the same password for multiple accounts. That way, you don't lose the keys to the whole castle if any of your individual passwords is compromised.

Oh, and if you're looking for the briefest of technical challenges over the holiday season, why not satisfy yourself how risky simple passwords are by having a go at the hashes in the Windows 8 screen shot above?

Estimated time to crack once you're ready to go, even without a GPU: well under a second.

Here they are, cuttable-and-pastable for your cracking pleasure:

Administrator:500::F773C5DB7DDEBEFA4B0DAE7EE8C50AEA:::duck:1001::BECEDB42EC3C5C7F965255338BE4453C:::

Enjoy.

Follow @duckblog


View the original article here

Saturday, December 29, 2012

Microsoft pushes IE 9 tweak via Windows Update to close three critical security holes

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Internet Explorer 9Microsoft has reminded Internet Explorer users of the importance of keeping their browser updated against security threats.

Microsoft said on Thursday that it had pushed an update to its Internet Explorer Version 9 web browser through its Windows Update feature earlier in the week in an effort to quickly close three, critical security holes.

If unpatched and exploited by cybercriminals, the vulnerabilities could allow an attacker to use a webpage to install and run malicious code on vulnerable systems.

The company announced the release of IE Version 9.0.11 via Windows Update in a blog post, and advised users of IE 9 to apply it immediately.

The update fixes security holes associated with the recently released MS12-071 Security Bulletin.

The vulnerabilities affected the IE 9 browser running on every supported version of Windows. However, earlier versions of Internet Explorer were not affected, nor was IE 10, the latest version of Microsoft's popular web browser.

Microsoft blog post

Microsoft has described the security vulnerabilities as caused by a flaw in the way that IE 9 accesses an object that has been deleted or not correctly initialized. It affects three Internet Explorer components, named CFormElement, CTreePos and CTreeNode.

Attackers could exploit the so-called "use after free" vulnerabilities using a variety of techniques: websites, malicious ActiveX controls embedded in an application or Office document or malicious advertisements displayed on legitimate sites.

Attacks would still require users to click on the malicious content, and the attackers would be limited by the victim's permission levels on his or her own machine.

As we noted in our coverage of the November Patch Tuesday release, "use after free" bugs happen when software gives back memory to the operating system in order to free up resources it no longer needs, but then carries on using that memory anyway.

The update closes the security holes. Microsoft said that most IE9 users will get the upgrade automatically using Microsoft's Automatic Update feature. (A description of how to configure automatic updates can be found in a Microsoft knowledgebase article.)

Those who haven't enabled the Auto Update feature were advised to use the Microsoft Update service to download and install it.

The IE 9 update was released on Tuesday, one of six security bulletins released with Microsoft's monthly security patch release.

Follow @PaulFRoberts
Follow @NakedSecurity


View the original article here

Tuesday, December 25, 2012

Sophos awarded VB100 in Windows Server 2003 R2 comparative anti-virus test

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

VB100 awarded to Sophos in October 2013 comparative testThe latest edition of Virus Bulletin magazine includes a comparative test of 36 different anti-virus products, exploring their ability to reliably detect malware on the Windows Server 2003 R2 platform.

Just as with the tests that Virus Bulletin conducts on other operating system platforms, the VB100 title is only awarded if a product is capable of detecting all in-the-wild viruses in both on-demand and on-access modes without suffering from any false positives.

Sophos performed well in the tests, outperforming a number of competing firms, and was awarded the VB100 title by detecting 100% of the viruses in Virus Bulletin's "in-the-wild" collection and not having any false alarms.

Virus Bulletin's Technical Consultant & Test Team Director John Hawes praised Sophos's stability, and highlighted our consecutive awards:

“Sophos put in a very strong performance in our latest comparative, easily earning VB100 certification and achieving good scores in all our measures. Stability was particularly impressive, with no problems encountered at all even in heavy stress tests - this earns Sophos our highest possible rating of ‘Solid’ for a second consecutive test, one of only two products to achieve this feat.”

More information about this latest test can be found in the October 2012 edition of Virus Bulletin magazine, that has just been published.

Don't forget that you can see Sophos's long track record in independent comparative tests on Sophos's reviews page.


View the original article here

Wednesday, December 19, 2012

Windows Phone 8 malware? This teen hacker claims to have created a prototype

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Windows Phone 8A teenage hacker prodigy in India claims to have developed a prototype of malware that will run on smartphones running Microsoft's new Windows Phone 8 operating system - the first known instance of Windows Phone 8 malware.

The researcher responsible for the prototype, Shantanu Gawde, is known as India's "youngest ethical hacker". He says he will unveil the malware prototype at the Malcon security conference in New Delhi, India, later this month.

Gawde's presentation will "demonstrate approaches and techniques for infecting... Windows Phone" including "how to steal contacts, upload pictures and steal private data of users, gain access to text messages etc."

However, little is known about the malware. For example, whether it relies on an exploit of an underlying vulnerability in Windows Phone 8 or masquerades as a malicious mobile application.

Dave Forstrum, director at Trustworthy Computing, Microsoft, commented:

"Microsoft is aware of the upcoming presentation but further details have not been shared with us. As always, we will investigate any issues disclosed in the talk, and will take appropriate action to help protect our customers."

At 16, Gawde is the world's youngest Microsoft Certified Application Developer (MCAD), having earned that designation at the age of just seven. In 2011, he presented a malware application that used Microsoft's Kinect gesture recognition technology at the same conference.

The Windows Phone 8 mobile operating system was released on October 29. It marks a major re-make of the Windows Phone 7 OS and includes higher screen resolution and support for multi-core processors, as well as Near Field Communications (NFC), a wireless technology that is integral to evolving mobile payments solutions.

The new OS also boasts some additional security features, including secure boot and native 128-bit Bitlocker encryption.

Microsoft also claims that the apps available in its mobile application store are "certified" - and vetted for malicious code and other security issues.

Follow @paulfroberts
Follow @NakedSecurity


View the original article here

Tuesday, June 19, 2012

Flame malware used man-in-the-middle attack against Windows Update

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Microsoft update revoking Flame compromised certificatesMicrosoft has released an emergency update for all versions of Windows to address a certificate flaw that was used to spread the Flame malware from machine to machine.

Of course you have to trust that your connection to Windows Update is not being attacked while you're retrieving the update that prevents you from being attacked.

This is not the first time we have seen malware abusing digital certificates, but this one is a bit more advanced than previous attacks.

What happened? The Flame malware needed a way to silently infect machines in the target environment, without making the mistake of spreading where it shouldn't like Stuxnet did.

Flame-infected computers can be instructed to impersonate a Web Proxy Autodiscovery Protocol (WPAD) server. Windows machines set for automatic proxy detection (the default) will try to contact a server called wpad.(company domain name) to check for instructions for when to use a HTTP proxy.

Windows Update logoFlame would tell machines on the network that the infected computer was to be used for proxying requests to Microsoft's Windows Update service. Ordinarily this would not work, as Microsoft signs updates with their special digital certificates to ensure you only receive updates that are tamper proof.

But the Flame authors had discovered a critical flaw in Microsoft's certificate infrastructure. The Microsoft Terminal Server Licensing service is used for license management and authorization in many enterprise environments. Microsoft had been mistakenly issuing certificates for use on these servers that could be used to digitally sign code.

Flame appears to have used one of these certificates to sign its payload and perform a man-in-the-middle attack to inject it onto additional machines on the same network. It isn't clear whether it was a certificate obtained legitimately from Microsoft or whether weak ciphers were targeted.

Two of the three certificates Microsoft revoked in this update used the MD5 hashing scheme. It has been demonstrated in the past that MD5 is prone to collisions, which may have also aided the Flame authors in successfully making it look like the malware was from Microsoft.

Managing encryption, ciphers and digital signatures is no easy task and a simple mistake like Microsoft accidentally issuing certificates that can be used to sign code using outdated ciphers is enough to put everyone at risk.

The idea of someone with malicious intent impersonating Windows Update has been discussed for years in the security community. It is sort of a nightmare scenario and I suppose it is good news that it was being used in such a limited way.

Few computers were compromised using this malware compared to the impact we would see if traditional opportunistic malware exploited this flaw. Fortunately the average user will now be protected from this attack moving forward.

These certificates can also be used for signing software for Microsoft's Windows Mobile and Windows Phone 7 devices, but no patch is available as of yet.

I think a friend of mine in the local Vancouver security community put it best: "Maybe 'Genuine Microsoft Advantage' should check the *other* side of the transaction?"

http://twitter.com/chetwisniewski

View the original article here

Tuesday, May 1, 2012

Python-based malware attack targets Macs. Windows PCs also under fire

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Mac and WindowsExperts at SophosLabs have identified a new malware attack that is targeting both Mac and Windows computers, exploiting the infamous Java security vulnerability that allowed the Flashback botnet to commandeer 600,000 Macs.

Internet users who visit compromised webpages may find themselves at risk of infection via a Java exploit that downloads malicious software onto their computer.

The latest malware attack exploits the Java vulnerability to download further malicious code onto the computer (Sophos products detect the attack as Mal/20113544-A and Mal/JavaCmC-A).

Note: Patches for the Java vulnerability have been available since February 14th for Windows, Linux and Unix computers and since early April for some Mac users. Unfortunately, Apple has chosen not to issue a Java security update for users running versions of Mac OS X prior to 10.6 (Snow Leopard), meaning those users remain undefended. Presumably Apple wants them to update to a later version of Mac OS X.

So, there may still be some users whose computers are not patched against the Java vulnerability - and are at risk of attack.

The malicious Java code downloads further code onto the victim's computer - depending on what operating system they are using. On Windows, the downloaded file will be detected by Sophos as Mal/Cleaman-B. On Mac OS X, the downloaded file (install_flash_player.py) will be detected as OSX/FlsplyDp-A.

This is not, however, the end of the story.

The downloaded programs will then install further malicious code - downloading the Troj/FlsplyBD-A backdoor Trojan on Windows computers, and decrypting a Python script called update.py (extracted from install_flash_player.py) on Mac OS X.

This Python script acts as a Mac OS X backdoor, allowing remote hackers to secretly send commands, uploading code to the computer, stealing files and running commands without the user's knowledge.

Sophos is adding detection of the final Python script as OSX/FlsplySc-A.

The backdoor Python script allows remote hackers to steal information

This attack is quite different from the earlier Flashback attack, and may indicate that other cybercriminal gangs are exploring the possibilities of infecting Mac computers.

Certainly, whoever wrote the script has left a clue that they may be planning to make developments to their code in the future.

The script has been written with future development in mind

The easiest way to look for an infection is, of course, to run an up-to-date anti-virus product. But if you want to check your Mac by hand to see if it is infected by this backdoor Trojan, here's a quick way to do it:

Examine /Users/Shared/ and look for files called update.sh and update.py.

update.sh is a shell script that will execute update.py, the Python script. These files can be safely deleted.

Files on Mac OS X

It should go without saying that you really should be running an up-to-date anti-virus, and be keeping up to date with security patches (like those available for Java).

Although Windows users are generally pretty good about running anti-virus protection, Mac users are only just waking up to the need. We have a free Mac anti-virus for home users, if you think it's time to take your computer's security more seriously.

Follow @gcluley

Thanks to SophosLabs researcher Xiaochuan Zhang for his assistance with this article.


View the original article here