Google Search

Showing posts with label attacks. Show all posts
Showing posts with label attacks. Show all posts

Wednesday, May 28, 2014

New technique targets C code to spot, contain malware attacks

Researchers from North Carolina State University have developed a new tool to detect and contain malware that attempts root exploits in Android devices. The tool improves on previous techniques by targeting code written in the C programming language -- which is often used to create root exploit malware, whereas the bulk of Android applications are written in Java.

Root exploits take over the system administration functions of an operating system, such as Android. A successful Android root exploit effectively gives hackers unfettered control of a user's smartphone.

The new security tool is called Practical Root Exploit Containment (PREC). It refines an existing technique called anomaly detection, which compares the behavior of a downloaded smartphone application (or app), such as Angry Birds, with a database of how the application should be expected to behave.

When deviations from normal behavior are detected, PREC analyzes them to determine if they are malware or harmless "false positives." If PREC determines that an app is attempting root exploit, it effectively contains the malicious code and prevents it from being executed.

"Anomaly detection isn't new, and it has a problematic history of reporting a lot of false positives," says Dr. Will Enck, an assistant professor of computer science at NC State and co-author of a paper on the work. "What sets our approach apart is that we are focusing solely on C code, which is what most -- if not all -- Android root exploits are written in."

"Taking this approach has significantly driven down the number of false positives," says Dr. Helen Gu, an associate professor of computer science at NC State and co-author of the paper. "This reduces disturbances for users and makes anomaly detection more practical."

The researchers are hoping to work with app vendors, such as Google Play, to establish a database of normal app behavior.

Most app vendors screen their products for malware, but malware programmers have developed techniques for avoiding detection -- hiding the malware until users have downloaded the app and run it on their smartphones.

The NC State research team wants to take advantage of established vendor screening efforts to create a database of each app's normal behavior. This could be done by having vendors incorporate PREC software into their app assessment processes. The software would take the app behavior data and create an external database, but would not otherwise affect the screening process.

"We have already implemented the PREC system and tested it on real Android devices," Gu says. "We are now looking for industry partners to deploy PREC, so that we can protect Android users from root exploits."

The paper, "PREC: Practical Root Exploit Containment for Android Devices," will be presented at the Fourth ACM Conference on Data and Application Security and Privacy being held March 3-5 in San Antonio, Texas. Lead author of the paper is former NC State graduate student Tsung-Hsuan Ho. The paper was co-authored by Daniel Dean, a Ph.D. student in Gu's lab at NC State.

The work was supported by the National Security Agency; U.S. Army Research Office grant W911NF-10-1-0273; National Science Foundation grants CNS-1149445, CNS-1253346, and CNS-1222680; IBM Faculty Awards and Google Research Awards.

Cite This Page:

North Carolina State University. "New technique targets C code to spot, contain malware attacks." ScienceDaily. ScienceDaily, 4 March 2014. .North Carolina State University. (2014, March 4). New technique targets C code to spot, contain malware attacks. ScienceDaily. Retrieved May 5, 2014 from www.sciencedaily.com/releases/2014/03/140304141856.htmNorth Carolina State University. "New technique targets C code to spot, contain malware attacks." ScienceDaily. www.sciencedaily.com/releases/2014/03/140304141856.htm (accessed May 5, 2014).

View the original article here

Sunday, July 14, 2013

Hacker "Kayla" admits attacks on Sony, Murdoch, Nintendo

By Estelle Shirbon

LONDON (Reuters) - A British computer hacker pleaded guilty on Tuesday to cyber attacks on targets including Sony, Nintendo, Rupert Murdoch's News International and the Arizona State Police.

Ryan Ackroyd's plea meant his planned jury trial did not go ahead and, as a result, the court did not hear any evidence on the motivation behind the attacks he made using the persona of a 16-year-old girl named Kayla as part of hacking group LulzSec.

Dressed in a tracksuit bottom and t-shirt, with a large tattoo on his arm and crew-cut hair, Ackroyd spoke only to identify himself and to enter his plea.

Ackroyd, 26, was arrested in 2011 with three other British young men in connection with an international cyber crime spree by LulzSec, a splinter group of hacking collective Anonymous.

The other three had already pleaded guilty to several charges including cyber attacks on the CIA and Britain's Serious Organised Crime Agency (SOCA).

Anonymous, and LulzSec in particular, made international headlines in late 2010 when they launched what they called the "first cyber war" in retaliation for attempts to shut down the WikiLeaks website.

Ackroyd faced four charges but pleaded guilty to just one. Prosecutors said they would not pursue the other charges.

Ackroyd and his three fellow hackers will be sentenced on May 14, judge Deborah Taylor said.

Mustafa Al-Bassam, 18, and Jake Davis, 20, had both pleaded guilty to two counts while Ryan Cleary, 21, had pleaded guilty to six counts including that he attacked Pentagon computers operated by the U.S. Air Force.

Cleary, Al-Bassam and Davis admitted to launching so-called distributed denial of service (DDoS) attacks in which websites are flooded with traffic to make them crash.

Ackroyd denied taking part in DDoS attacks but admitted, as did the three others, to hacking into computer systems, obtaining confidential data and redirecting legitimate website visitors to sites hosted by the hackers.

The targets listed in the charge to which Ackroyd pleaded guilty also included Britain's National Health Service, the U.S. public broadcaster PBS and 20th Century Fox.

The defendants are free on bail pending their sentencing, under the condition that they do not access the Internet.

Cleary was indicted by a federal grand jury in Los Angeles last June but U.S. authorities have indicated they would not seek his extradition as he was being prosecuted in Britain on the same charges.

The name LulzSec is a combination of "lulz", another way of writing "lols" or "laugh out loud", and security.

(Editing by Louise Ireland)


View the original article here

Friday, July 12, 2013

LulzSec: Hacker Admits Joining In Web Attacks

A 26-year-old has pleaded guilty to hacking websites of major institutions including the National Health Service, Sony and News International.

Ryan Ackroyd, from Mexborough, South Yorkshire, pleaded guilty to one charge of carrying out an unauthorised act to impair the operation of a computer, contrary to the Criminal Law Act 1977.

He had been due to stand trial charged with taking part in a string of cyber attacks but ended up admitting just the one charge.

Southwark Crown Court in London heard he admitted being a member of hacking group LulzSec.

As a member he acted as a "hacker" to access websites for Sony, 20th Century Fox, the NHS, Nintendo, the Arizona State Police, and News International between February and September 2011.

In July 2011 the Sun's website was hacked and users were briefly re-directed to a spoof page that falsely claiming that Rupert Murdoch had died.

Prosecutor Sandip Patel told the court: "He was the hacker, so to speak. They turned to him for his expertise as a hacker."

She said Ackroyd admitted using the persona of a 16-year-old girl Kayla on the site.

He will be sentenced on May 14 and the court heard prosecutors are not planning to pursue other charges against the 26-year-old.

Earlier today, Southwark Crown Court heard that fellow hackers Mustafa Al-Bassam, 18, from Peckham, south London, and Jake Davis, 20, from Lerwick, Shetland, have also now pleaded guilty to hacking.

The pair were also involved in launching cyber attacks on a range of organisations, including the CIA and the Serious Organised Crime Agency.

Ryan Cleary, 21, of Wickford Essex, has pleaded guilty to the same two charges as well as four separate charges including hacking into US air force agency computers at the Pentagon.

The men are said to have carried out distributed denial of service (DDoS) attacks on the institutions with other unidentified hackers belonging to online groups such as LulzSec, Anonymous and Internet Feds.

The DDoS attacks they carried out flood websites with traffic, making them crash and rendering them unavailable to users.

To do it, they used a remotely controlled network of "zombie" computers, known as a "botnet", capable of being programmed to perform the attack.

LulzSec is a spin-off of the loosely organised hacking collective Anonymous. Lulz is internet slang that can be interpreted as "laughs", "humour" or "amusement", and Sec refers to "security".


View the original article here

Thursday, June 13, 2013

TDoS attacks target US emergency call centers

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Red telehone. Image from ShutterstockEmergency call centers in the US are suffering a rise in TDoS (telephony denial of service) attacks, according to an alert issued recently by the Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI).

According to the alert, reposted [PDF] on security journalist Brian Krebs's site, dozens of attacks have targeted PSAP administrative lines (not the 911 emergency line), tying up the system from receiving legitimate calls.

Air ambulance, ambulance and hospital communication lines have been targeted, in addition to various businesses and public entities, the alert goes on, including the financial sector.

The recent attacks are aimed at extortion. Here's how they work, according to DHS and the FBI:

An individual calls, claiming to represent a payday loan collections company.The caller typically has a strong accent and asks to speak with a current or former employee about an outstanding debt.The caller demands payment of $5,000 because an employee (who no longer works for the company or never did) defaulted on a loan. When the target fails to cough up the money, the attacker launches a TDoS.The organization is then inundated with a continuous stream of calls for an unspecified but lengthy period of time.Phone service is disrupted, preventing incoming and/or outgoing calls.

Call center operators. Image from ShutterstockThe agencies are speculating that these businesses and emergency services in particular are being targeted because phone lines are crucial to their operations.

The current TDoS attacks are, at this point, skipping over emergency service 911 lines.

Emergency hotlines aren't always spared in TDoS attacks, of course.

UK police last year arrested two teenage boys following a series of prank calls and TDoS attacks launched against the Anti-Terrorist Hotline.

More recently, as CSO's Antone Gonsalves notes, last month, the Louisiana State Analytical and Fusion Exchange, a center for distributing information across law enforcement offices, reported a similar extortion scheme against two public sector entities, including a 911 call center.

The current attacks against US emergency services, which last for intermittent time periods over several hours, are creating a deluge of calls large enough to force roll-over to alternate facilities, the FBI and DHS reported.

The attacks are sporadically re-starting over weeks or months.

While these attacks are clearly profit-motivated, past TDoS attacks have been, apparently, pranks, albeit on the malicious side.

In 2008, it was the Gladys Porter Zoo in Houston, Texas that suffered a barrage of calls after cryptic SMS text message spam was sent to thousands of people, saying things like:

New text message. Image from Shutterstock Call now someone is looking for you.Call now and we will settle this.Somebody talking down on you, look for themHey y is someone calln me and lookn for u n askn me where r u at n where u live heres tha # tell then to stop calln me

...and telling them to call the zoo's number. The phone-clogging continued on into May, when the zoo eventually threw in the towel and called in the FBI to help.

Dublin Zoo suffered a similar fate around the same time, with at least 5,000 people receiving SMS text message spam that prodded them to urgently ring the zoo's phone number and ask for a fictitious person (Rory Lion, Anna Conda, C Lion or G Raffe according to news reports such as this one from the Irish Independent).

Whether TDoS attacks are launched as pranks, as vendettas, or as extortion schemes, they serve to cripple their targets.

Zoos don't deserve that any more than ambulance services or the like.

The stakes, however, are potentially higher when you're talking about crippling life-saving businesses. Even if these attacks aren't targeting 911 emergency lines, they still reflect a blatant disregard for humanity.

Please, if you can help the DHS or FBI pull the plug on these malicious schemes, fill them in on the details of any attacks that have targeted your business, and encourage your peers to do the same.

The agencies have offered these recommendations for targeted organizations:

Don't pay the blackmail. Report all attacks to the FBI by logging onto the website http://www.ic3.gov/default.aspx. Use the keyword "TDoS" in your report title. Identify your organizations as a public safety answering point (PSAP) or Public Safety organization. List as many details as possible, including: Calls logs from the “collection” call and TDoS Time, date, originating phone number and traffic characteristicsCall-back number to the “collections” company or requesting organizationMethod of payment and account number where the “collection” company requests the debt to be paidAny information that you can obtain about the caller, or his/her organization Contact your telephone service provider; they may be able to assist by blocking portions of the attack.

Follow @LisaVaas
Follow @NakedSecurity

Red telephone, call center operators and text message images from Shutterstock


View the original article here

Thursday, April 25, 2013

China blamed for EADS and ThyssenKrupp hack attacks

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Two more major organisations have gone public about, what they claim, were attempts by Chinese hackers to infiltrate their networks and steal sensitive information.

EADS, the European Aeronautic Defense and Space company, and steelmaker ThyssenKrupp are said to have become the targets of hack attacks originating in China, according to Der Spiegel.

EADS - who makes the Eurofighter jet, as well as spy drones, surveillance satellites, and even rockets for French nuclear weapons - are said to have contacted the German government last year to warn them that the military contractor's computer network has been hacked.

Eurofighter

Officially, EADS have described the attack as "standard" and insisted that no harm has been done.

However, the attacks is against a backdrop created over the last few years of of other hacks against the defence industry including the likes of Lockheed Martin, L-3 Communications and Northrop Grumman.

And, of course, it's only 18 months since the then US Deputy Defense Secretary William Lynn claimed that a foreign intelligence agency was behind a hack attack that stole classified information about a top secret weapons system.

Meanwhile, ThyssenKrupp has also said to have confirmed that it was attacked by hackers - adding the detail that the attack occurred in the United States, and appeared to originate from a Chinese internet address.

According to Der Spiegel, the attacks against ThyssenKrupp were described as "massive" and of "a special quality", and the company was not sure of what (if any) information had been stolen by the hackers.

It is becoming increasingly clear that organisations need to defend themselves not only from the day-to-day financial-orientated cybercrime attacks which can impact anyone with a computer, but also from sophisticated targeted attacks that may be designed to spy and surreptitiously steal information.

BlueprintThe truth is that these hacking stories aren't really describing a technological problem. They're describing a human problem. It's remarkably easy to dupe someone into clicking on a link or opening an attachment in an email, and for their computer to become compromised.

You can reduce the chances of a targeted attack working by keeping your software (such as your PDF reader, your web browser, your word processor, as well as your operating system) up-to-date with the latest patches.

Furthermore, you should run a layered defence - that means not just running up-to-date anti-virus software, but also firewalls, email filtering technologies, vulnerability assessment, using DLP (data loss protection) technology and strong encryption to secure your most sensitive data.

Also, it's amazing how many people re-use passwords, and use the same weak password in multiple places. That means if you get hacked in one place, and your password is compromised, it may also unlock accounts elsewhere on the net. It's shocking how many people don't use different passwords for different places.

All of these methods can reduce your chances of suffering from a targeted attack.

But ultimately, there's no 100% technological solution as human beings can still make bad decisions. And that's why it's important to train users about threats, and warn them to be suspicious of unsolicited links and attachments and to always report suspicious activity.

Follow @gcluley

View the original article here

Thursday, April 18, 2013

Point-of-Sale malware attacks – crooks expand their reach, no business too small

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Malware

Numaan Huq and Richard Wang of SophosLabs have been keeping track of the evolution of Point-of-Sale malware.

We've recently been tracking a set of incidents involving malware attacking Point-of-Sale (PoS) equipment.

Your personally identifiable information (PII) flows into PoS devices, across PoS networks, and is processed by PoS servers, every time you pay for things without using cash.

As a result, PoS equipment and the local-area networks to support it are found all over the world, in both developed and developing countries.

When was the last time you tried to pay for a hotel stay in cash, for example?

Even if you settled the bill with cash, you probably swiped or waved a payment card when you checked in, just to avoid having to lay down a large cash deposit.

As a result, PoS systems are a lucrative target for crooks.

So it's not surprising that we've written about this particular malware family, Troj/Trackr-Gen, and its thirst for credit card data before.

It seems the criminals behind it have added a few new tricks in the last 15 months.

The most interesting development is that some versions now include the ability to exfiltrate data directly rather than just dumping it to disk.

? The Payment Card Industry has a set of Data Security Standards, known unsurprisingly as PCI-DSS. The standards specify, amongst other things, that credit card data must in general be encrypted if it is stored, and that some data, such as CVV numbers, mustn't be stored at all once a transaction is complete. Ironically, the crooks have learned from this, and are avoiding reading from or writing to disk themselves.

Another change is found when examining some of the targets.

As before, the criminals are avoiding very large businesses but in addition to the commonly attacked hospitality industry and hotel targets there are smaller victims, including a single car dealership in Australia.

A couple of cosmetic changes have also been made.

There is a new generator for random filenames, creating completely random five-character names such as IXWIG.exe and KPAOE.exe.

For variants using hardcoded names the common use of rdasrv.exe has been extended to include filename options designed to hide in plain sight such as windowsfirewall.exe or msupdate.exe.

It seems that no victim is too small for Point-of-Sale malware.

The popularity of terms like "Advanced Persistent Threat" and "state-level malware actors" may make it sound as though only the biggest multinationals and parastatals are at risk these days.

But stealing $75 each from 1,000,000 people gives the same financial result as stealing $75 million from a megacorporation.

So you simply cannot assume that your business or organization is not a big enough target to worry about web attacks or targeted malware.

Remember this: there is no radar below which you can fly.

As a final thought, since we already know the how and the why of this latest round of PoS attacks, we invite you to consider the where.

There's an intriguing hint buried in the code:

We don't know if that's where the crooks are from, or if it's where they've been most successful in infiltrating PoS networks (Botswana, home to the astonishing inland Okavango Delta, has a strong hospitality industry), or perhaps just where they spent some of their ill-gotten gains on a vacation.

Do you run a small business that relies on PoS equipment?

If so, how much of a challenge are you finding it to stay ahead of crooks like this?

Have your say in the comments...

Follow @sophoslabs

Image of PoS machine courtesy of Shutterstock.


View the original article here

Sunday, February 10, 2013

Zero day vulnerability in Internet Explorer being used in targeted attacks, FixIt now available

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft releases fix for Internet Explorer security hole, full patch coming FridayInternet Explorer users beware, there is a new zero day (previously unknown, unpatched vulnerability) attack targeting your browser.

Microsoft has issued an advisory about the flaw and it is being referred to as CVE-2012-4792. Microsoft has also made a temporary FixIt available until it can deliver a formal patch.

The flaw affects users of Internet Explorer 6, 7 and 8, but not 9 or 10 and allows for remote code execution with the privileges of the logged in user.

Another poignant reminder that running your computer as a non-administrative user pays off when new flaws are uncovered.

Non-privileged users will severely limit the damage that can be done using a vulnerability like this one.

The vulnerability was initially
" href="http://blog.fireeye.com/research/2012/12/council-foreign-relations-water-hole-attack-details.html" rel="nofollow">discovered by FireEye on the Council on Foreign Relations website on December 27th, 2012.

SophosLabs has records showing the Council's website infected as far back as December 7th.

We have seen the exploit used on at least five additional websites suggesting the attack is more widespread than originally thought.

The attack appears to be closely related to attacks we reported on last June that were targeting visitors to a major hotel chain.

While the vulnerability being exploited is entirely different, the payload is nearly identical to the hotel attack and others we have associated with the Elderwood Project.

shutterstock-Wateringhole200While the attacks appeared to be targeted to a small number of sites, there is no obvious link between the victims.

Some are referring to this as a "watering hole" attack, but the evidence we have doesn't necessarily support that conclusion.

If you use Internet Explorer, be sure you are using at least version 9 to avoid being a victim of these attacks. If you can't upgrade, consider using an alternative browser until an official fix is available.

Microsoft's FixIt is intended as a temporary workaround that could also be considered, but until an official fix is available I recommend avoiding IE 8 and lower.

If further information becomes available, we will publish the latest here on Naked Security.

Sophos Anti-Virus on all platforms blocks this malware as follows:

Sus/20124792-B: Misc. files specifically associated with this attack
Sus/Yoldep-A: Encoded payload also seen in other Elderwood Project attacks
Troj/SWFExp-BF: Adobe Flash component
Sus/DeplyJv-A: JavaScript components evolved from earlier Elderwood Project attacks

Follow @chetwisniewski

Watering hole photo courtesy of Shutterstock.


View the original article here

Saturday, February 2, 2013

Three people arrested over "Police ransomware" computer attacks [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Money. Image from ShutterstockThe Metropolitan Police have arrested two men and a woman in connection with a spate of computer attacks that have held innocent internet users to ransom.

Ransomware is malicious software that locks you out of your computer or your data, and demands money to let you back in.

One "brand" of ransomware, widely known as Reveton, has been very widely circulated in recent months pretending to be a warning from your country's national police service, locking you out of your PC, and threatening criminal proceedings within 48 hours - usually for unspecified copyright offences.

According to a police press release, officers from the Police Central e-Crime Unit (PCeU), assisted by colleagues from Staffordshire Police, searched three properties yesterday in connection with the ransomware attacks.

A 34-year-old man and 30-year-old woman from Stoke on Trent have been arrested on suspicion of conspiracy to defraud, money laundering and possession of items for use in fraud. Additionally, a 26-year-old man also from Stoke on Trent was also arrested on suspicion of conspiracy to defraud. All three are currently in custody at a Staffordshire police station.

Naked Security's Paul Ducklin demonstrates ransomware in the following video:

(Enjoy this video? Check out more on the SophosLabs YouTube channel.)

For a deeper understanding of ransomware, check out some of our recent articles on the subject:

Follow @gcluley

Money image from Shutterstock.


View the original article here

Wednesday, December 12, 2012

IP theft attacks can hide on networks for years, unspotted by corporate victims, report claims

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Complicated blueprintOrganizations in the financial services and public administration sectors are the primary targets of sophisticated attacks aimed at stealing intellectual property, with attacks involving both external and internal agents and lasting for months or years, according to a new report.

A Verizon report [PDF] reports just 101 incidents of intellectual property theft - around 12 percent of the total data breach incidents it documented - during 2011, but attacks that stole intellectual property were both longer-lasting and more complex than other data breach incidents.

Attackers commonly relied on both external agents and insiders to carry out the attacks.

Professional criminal gangs, hacktivist groups, competitors and state-sponsored actors were "identified or suspected" in many of the IP theft crimes.

Threat agents. Source: VerizonTheir methods were both more sophisticated and determined than the average cybercriminals, the report noted.

Because intellectual property often resides deep within a company's network on protected systems, IP theft attacks frequently relied on insiders to facilitate.

Verizon found evidence of internal "threat agents" in 46% of the IP theft-related attacks, compared with just 4% of all data breach incidents in 2011.

And, in news that's bound to be disheartening to companies worried about sophisticated attacks, the report supports the notion that slow, secretive attacks are hard to spot and remove.

Once on a target network, attackers interested in stealing intellectual property hung around. Verizon claims that 17% of the IP-theft related incidents it reviewed persisted for "months" before discovery, while 31% took "years" to discover.

More than half took months, after discovery, to contain and recover from.

Timespan. Source: Verizon. Click for larger version

Database servers, file servers and finance and accounting systems were popular targets in IP-theft related attacks.

The information on intellectual property attacks ran counter to the overall trend in 2011, which found that "opportunistic" attacks by external agents against poorly protected systems were the cause of most data breaches.

In the population in general, attacks on the hospitality industry - including hotels and restaurants - accounted for more than half of the 855 incidents Verizon reported during 2011.

In contrast, targeted attacks to steal intellectual property were spread across just four verticals: financial services, public administration (e.g. government agencies), information technology and manufacturing.

Verizon said that there is no "silver bullet" for companies worried about intellectual property theft. Companies should "adopt a common sense, evidence-based approach" to security management and study incidents at organizations similar to them to see what kinds of threats and failures they are likely to encounter.

Companies should also look closely at the possibility of rogue insider acting in ways that could subvert security measures and address common security lapses such as weak passwords and vulnerable SQL server applications.

Follow @paulfroberts
Follow @NakedSecurity

Tags: data breach, verizon, government, Trojan, data theft, hacking, Malware, compliance, Advanced Persistent Threat, Data Breach Investigation Report, intellectual property theft, IP theft, insider threat, financial services


View the original article here

Wednesday, October 24, 2012

Leading US banks targeted in DDoS attacks

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Bank. Image from ShutterstockAttacks against the websites of leading banks in the United States have the banking and financial services industry on edge.

The Financial Services ISAC (Information Sharing and Analysis Center) set its Threat Level to “High” on Wednesday, September 19, indicating a high risk of cyber attacks.

That proved prophetic, as websites for banks including Bank of America, JP Morgan Chase and Wells Fargo suffered outages in recent days that some are attributing to politically motivated hacktivist groups.

A string of statements posted online in the last week has claimed responsibility for the attacks in the name of a Muslim hacking group calling itself Izz ad-Din al Qassam Cyber Fighters.

The group has claimed responsibility for attacks on the New York Stock Exchange, Bank of America and Chase last week. This week brought attacks against Wells Fargo, US Bank and PNC.

Wells FargoWells Fargo used its Twitter account to apologize for service interruptions on Wednesday and said it was working to "quickly resolve this issue." Most of the targeted banks were back online and operational Thursday.

The events prompted U.S. Senator Joe Lieberman (I-CT) to use an interview on C-SPAN to point the finger of blame at the Iranian government and its elite Quds Force.

Lieberman said he believed the attacks were in retaliation for attacks on that country’s nuclear program, though he didn’t offer any evidence to support his claim. Gholam Reza Jalali, the head of Iran’s Civil Defense Organization, denied that the country was behind the attacks in a statement to Iran’s Fars News Agency.

Public statements on Pastebin taking credit for the attacks don’t mention Iran’s nuclear program as a motivation.

However, they do mention the roiling controversy about the anti-Islamic film "Innocence of Muslims" that has provoked riots and civil unrest throughout the Muslim world.

"These series of attacks will continue until the Erasing of that nasty movie from the Internet," one statement reads.

Of course, as is always the case, it was impossible to verify the authenticity of any of the statements posted online or their connection to whomever is responsible for the attacks against the banking websites.

Politically motivated hacks – or hacktivism – have been on the rise in recent years, with the activities of Western-based groups like Anonymous and Lulzsec drawing attention to the doings of ideologically motivated hacking crews.

But the phenomenon isn’t limited to Europe and the United States.

Politically aligned hacking groups are also common in Asia and the Middle East. Notably: a group called Electr0n defaced Libya’s top level domain with messages opposed to then-dictator Muammar Gaddafi.

Follow @paulfroberts
Follow @NakedSecurity

Bank image from Shutterstock.

Tags: Bank of America, Banking, BoA, Chase, DDoS, denial of service, hacking, hacktivism, Iran, Izz ad-Din al Qassam Cyber Fighters, US Bank, Wells Fargo


View the original article here

Sunday, September 23, 2012

Attacks on Java security hole hidden in bogus Microsoft Services Agreement email

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Globe. Image from ShutterstockOnline scammers are using a recent email from Microsoft as bait in a widespread spam campaign that exploits vulnerabilities in Oracle’s Java software to install malicious programs on vulnerable systems.

Experts at The SANS Institute's Internet Storm Center warned on Saturday that operators there received multiple reports of a spam campaign that uses a recent Microsoft email regarding changes to its Services Agreement for products such as Hotmail and Skydrive to fool users.

The attacks have prompted renewed calls for internet users to disable Java on their systems pending a new update from Oracle Corp. to fix critical, remotely exploitable vulnerabilities in the ubiquitous web technology.

According to SANS, the malicious email is based on an August 27 communication from Microsoft titled "Important Changes to Microsoft Services Agreement and Communication Preferences."

The phishing email replaces links in the original messages with malicious links that send unwitting readers to websites that install a new variant of the Zeus malware, ISC handler Russ McRee warned in a post on September 1st.

The actual Microsoft message, dated August 27, can be viewed here.

It details changes in the terms of a services agreement for users of a wide range of products, including Hotmail, Windows Live Messenger, Microsoft Photo Gallery and SkyDrive, the company’s hosted storage offering.

Blackhole, courtesy of ShutterstockThe malicious websites in question are running the latest versions of the Blackhole Exploit Kit, a kind of Swiss Army Knife for compromising vulnerable computers.

The Blackhole Exploit Kit is capable of analyzing the configuration and software installed on machines visiting web sites on which the exploit kit is installed, and then serve up just exploits that are likely to work against the intended target.

The recent addition of exploit code for the Java vulnerability has more than doubled the success rate of Blackhole exploits, compromising tens of thousands of new systems, according to data from the security firm Seculert.

This isn't the first phishing email that has been linked to attacks on the Java vulnerability. Last week, experts at SophosLabs discovered malicious emails purporting to including information on a tax rate increase that contained links to websites exploiting the Java hole.

Database giant Oracle acquired Java when it bought Sun Microsystems in 2009 and has faced criticism from security experts for failing to respond quickly to security vulnerabilities in the ubiquitous web technology before.

The latest security holes haven’t improved the company's image. It was forced to rush out a patch for the Java security hole last week and received withering criticism after the polish security consultancy Security Explorations disclosed that it reported the critical security hole to Oracle in April, four months earlier.

The company's image was further damaged when the patch Oracle released to fix the flaw failed to fully close the security hole. Security Explorations said that it informed Oracle on Friday that systems running the patched Java 7 Version 7 could be circumvented in a similar manner to earlier versions, allowing for "complete Java sandbox bypass."

Oracle has confirmed receipt of that report and is investigating, Security Explorations said.

In the meantime, ISC and others are advising users to disable Java until the next update is ready.

For those who want to keep Java running, SANS ISC said that email recipients should scrutinize the hyperlinks in any email messages by hovering their mouse cursor over the link prior to clicking on it and by inspecting email headers for suspicious messages.

Sophos experts Paul Ducklin and Chet Wisniewski offer more easy-to-understand advice about Java in the latest Techknow podcast: "All about Java".

Follow @paulfroberts

Blackhole and Globe image, courtesy of Shutterstock

Tags: BlackHole, Blackhole exploit kit, Internet Storm Center, ISC, Java, Malware, Microsoft, Microsoft Services Agreement, SANS, Spam, vulnerability


View the original article here

Tuesday, August 28, 2012

Invisible iFrame drive-by malware attacks explained [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

FrameiFrames and script tags are being used by malicious hackers to serve up drive-by internet attacks, silently and invisibly.

iFrames allow webmasters to embed the content of one webpage into another, seamlessly.

There are legitimate reasons why some websites may want to do that - but what cybercriminals do is exploit the functionality (presumably they have been able to gain write access to the website) to deliver malware such as fake anti-virus or a PDF vulnerability exploit to infect your computer.

What's sneaky is that malicious hackers can make the embedded content invisible to the naked eye, by making the window zero by zero pixels in size. You can't see the threat, but your web browser is still dragging it down.

Check out the following video by our own Chet Wisniewski, which shows how malicious iFrames work:

(Enjoy this video? Check out more on the SophosLabs YouTube channel.)

If you want to learn more you can subscribe to our YouTube channel for similar videos. But even better than that, we hold regular "Anatomy of Attack" events where we demonstrate malware threats and you can quiz Sophos experts.

If there's not an "Anatomy of an Attack" event scheduled in your area soon, drop us a note and we'll let you know if and when one is coming to your part of the world.

http://twitter.com/gcluley

Empty picture frame image from Shutterstock.


View the original article here

Thursday, May 17, 2012

Norwegian teenagers arrested over denial-of-service attacks

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Norwegian face painting. Image from ShutterstockTwo teenagers have been arrested in Norway in connection with a series of distributed denial-of-service (DDoS) attacks against websites in the country, and elsewhere around the world.

Norway's National Criminal Investigation Service (NCIS) has refused to go into much detail of which websites were targeted by the attacks, but news reports have suggested that victims are believed to include the Norwegian Lottery, the Norwegian Police Security Service, the Norwegian bank DNB, Germany's Bild Magazine, and the UK's Serious Organised Crime Agency (SOCA).

SOCA was hit by a high profile denial-of-service attack last week, preventing internet users from reaching it.

The motivation for the attacks is presently unclear.

The arrested teenagers, who have not been named, are aged 18 and 19 years, and are said to have launched the attacks over a period lasting "several weeks", flooding websites with unwanted traffic to such an extent that legitimate visitors would find them inaccessible. In simple terms, a DDoS attack is the equivalent of "15 fat men trying to get through a revolving door at the same time" - nothing can move.

If found guilty, the teenagers could face a maximum sentence of six years in jail.

Once again, it seems worth reminding computer users that participating in a denial-of-service attack is against the law, and is not viewed leniently by the authorities.

Follow @gcluley

Norwegian face painting image, courtesy of Shutterstock.


View the original article here

Tuesday, November 22, 2011

Android under assault as hacker attacks on phones go up 472 per cent in four ... - Daily Mail

By Daniel Bates

'Rogue' apps in market conceal malicious softwareDownloading can allow hackers to spy on your emailsApps 'steal' by sending texts to premium numbersAndroids at risk because apps aren't vetted before they join Android Market - unlike iPhone apps

Last updated at 3:17 PM on 18th November 2011


The success of phones running Google's Android software has meant cyber-attacks have risen 472 per cent in just three months - from cyber-spying apps to apps that add to your phone bill The success of phones running Google's Android software has meant cyber-attacks have risen 472 per cent in just three months - from cyber-spying apps to apps that add to your phone bill

Google's Android operating system is far, far ahead of Apple's iPhone - analysts Gartner said that phones running the operating system accounted for 52.5 per cent of the smartphone market this year, compared to 15.6 per cent for iOS devices.

But in computing, success always comes at a price.

Hackers target the most successful operating systems with their most virulent and hi-tech attacks, simply because there are more victims.

Malware infection rates amongst Android users are going up at their highest rate ever, putting huge pressure on Google to improve its security.

Since July the number of attacks has increased by 472 per cent with most of those coming in the past few weeks

The rise comes off the back of a report in May which said that over the previous year malware incidents had gone up 400 per cent.

The studies were carried out by IT security firm Juniper Networks which blamed Google’s poor security for allowing so many users to be affected.

It said that once installed malicious programmes could either send personal information to a third party, or send text messages to a premium rate number without the person’s knowledge, costing them money that is not recoverable.

Google is particularly vulnerable because it doesn't 'vet' apps in its marketplace, unlike Apple - making it open season for hackers.


HTC's Evo 4G handset runs Google's popular Android software: But the internet giant's anything-goes approach to its app store has led to an increase in cyber attacks on users HTC's Evo 4G handset runs Google's popular Android software: But the internet giant's anything-goes approach to its app store has led to an increase in cyber attacks on users

Google’s Android is now the most popular platform for downloading apps, beating the iPhone and the iPad combined.

The operating system accounted for 44 per cent of all app downloads in the second quarter of this year. Apple only got 31 per cent across all of its platforms.

Android has become a target for hackers and others with malicious intent partly because it is the market leader.

But according to Juniper Networks, Google must also take some of the blame because there is no review process before an app is placed in the App Store.

Adding to the problem is that Android is open source, meaning it is far easier to create and App for free and redesign their own hardware.

October showed a 110 per cent increase in malware sample collection over the previous month and a 171 per cent increase from what had been collected up to July 2011.

Not only are the numbers going up, but the malicious programmes are getting more sophisticated too.

In its reporter Juniper Networks said: ‘We have since seen exponential grow in Android malware over the last several months.

‘The months of October and November are shaping up to see the fastest growth in Android malware discovery in the history of the platform.

‘The majority of malicious applications target communications, location, or other personal identifying information. 

‘Of the known Android malware samples, 55%, acts in one way or another as spyware.

‘The other major type of attack, which make up 44%, are SMS Trojans, which send SMS messages to premium rate numbers owned by the attacker in the background of a legitimate application, without the person’s knowledge.

‘Once these messages are sent, the money is not recoverable, and the owners of these premium rate numbers are generally anonymous.’

The report adds that the main suspects behind such programmes are the same people who targeted other phones but have shifted because Android is now the most popular operating system.


View the original article here

Thursday, June 23, 2011

Hackers say attacks are entertainment

Computer hackers who have hit the websites of the CIA, US Senate, Sony and others during a month-long rampage say they stage the attacks for their own entertainment.

'You find it funny to watch havoc unfold, and we find it funny to cause it,' the hacker group known as Lulz Security said in a 750-word online 'manifesto' on Friday.

'For the past month and a bit, we've been causing mayhem and chaos throughout the internet, attacking several targets including PBS, Sony, Fox, porn websites, FBI, CIA, the US government, Sony some more, online gaming servers,' Lulz said.

'While we've gained many, many supporters, we do have a mass of enemies, albeit mainly gamers,' Lulz said, adding that they were not concerned.

'This is the lulz lizard era, where we do things just because we find it entertaining,' said Lulz, whose name is a derivative of the text shorthand for LOL, or 'laugh out loud.'

'This is the internet, where we screw each other over for a jolt of satisfaction,' the group said.

'We release personal data so that equally evil people can entertain us with what they do with it,' Lulz said. 'And that's all there is to it, that's what appeals to our internet generation.

'We're attracted to fast-changing scenarios, we can't stand repetitiveness, and we want our shot of entertainment or we just go and browse something else, like an unimpressed zombie,' Lulz said.

The group said it will 'continue creating things that are exciting and new until we're brought to justice, which we might well be.'

Lulz has released tens of thousands of user names and passwords in recent weeks but the group said Friday they were 'sitting on' the personal information of 200,000 users of the Brink videogame.

'It might make you feel safe knowing we told you, so that Brink users may change their passwords,' Lulz said.

On Wednesday, Lulz knocked the CIA's public website, cia.gov, out of commission for about two hours.

Lulz, in a message on their Twitter feed LulzSec on Friday, also denied reports that they were in conflict with the hacker group Anonymous, from which Lulz is believed to have formed.

'To confirm, we aren't going after Anonymous,' Lulz said.

Anonymous has been staging cyberattacks for years on companies cracking down on music and movie piracy and gained notoriety last year with cyberattacks in support of controversial website WikiLeaks.


View the original article here