Google Search

Showing posts with label blogs. Show all posts
Showing posts with label blogs. Show all posts

Thursday, September 12, 2013

FT hacked. Syrian Electronic Army hijacks Financial Times blogs and Twitter accounts

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Financial TimesThe Syrian Electronic Army has struck again - this time adding the scalp of the prestigious Financial Times to its collection of hijacked accounts belonging to well-known media organisations.

Hackers from the Syrian Electronic Army appear to have stolen the usernames and passwords of FT staff with access to the newspaper's social media accounts, and posted unauthorised blog entries and tweets earlier today.

Here are some examples of the damage caused by the hackers:

FT blog

FT tweets

Of course, the hacking of such a prestigious target doesn't go unnoticed - and the FT's security team scrambled into action, warning readers about the issue and deleting offending messages as they were found.

FT hack statement

The Syrian Electronic Army isn't above rubbing salt into the wounds, clearly finding it amusing to publish the email address and password of at least one FT staff member who seemingly (we won't republish it here) chose a rather silly password.

SEA reveal FT password

In recent weeks Syrian Electronic Army hackers have successfully broken into online accounts belonging to the likes of The Guardian, the BBC, NPR, and CBS with apparent ease, prompting Twitter take the unusual step of reaching out to news and media organisations to warn them about the current attacks, and offer advice on defensive measures.

The problem is compounded by Twitter's current system of insisting that every Twitter account only has one username/password connected with it.

This is unlike the way Facebook pages work where individual users can be assigned different rights for managing and administering their firm's online presence. Combined with two factor authentication (known as Login Approvals on Facebook) this provides a higher level of security, and greater granularity about what users can do.

Twitter's approach inevitably leads to media agencies, who are pressured to tweet breaking stories around the clock, to share Twitter passwords with many staff worldwide - and hold their breath that none of them get hacked or have their credentials phished.

It would be great if Twitter could introduce two factor authentication. It would be great if Twitter could introduce a way for firms to give different staffers separate logins for the same account.

And it would be great if media companies could train their staff to be suspicious of unsolicited emails, be wary of clicking on unknown links, and of unwittingly handing their passwords over to criminals.

The blame for the hackers' success, after all, shouldn't entirely fall on Twitter's doorstep. Ultimately it was a human, working for the media organisation, who made a mistake and was tricked into giving the keys to the castle to a bunch of hackers.

Follow @gcluley

View the original article here

Wednesday, July 3, 2013

WordPress blogs and more under global attack - check your passwords now!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

If you have a web service that supports remote users, you will know that malevolent login attempts are an everyday occurrence.

Even on my own home-hosted SSH server, listening unassumingly on an IP number on a DSL line, I've seen thousands of login attempts from dozens of different IP numbers in the course of a single day.

But hosting providers worldwide are reporting that they've been seeing systematic attempts, over the last 48 hours or so, to breach blogs and content management systems (CMSes) at well above average levels.

The primary target seems to be WordPress, with Joomla users also reportedly getting a bit of a hammering.

Word from the anti-DDoS world is that a botnet is responsible, with estimates of "up to 90,000," "more than tens of thousands," and "up to 100,000" infected computers (all those figures can be true at the same time, of course) orchestrating the felonious login attempts.

Since it would take too long to try every possible username and password on every known WordPress or Joomla server, this onslaught is using what is known as a dictionary attack.

That's where a crook settles on a list of the most likely usernames and passwords, and tries those in quick succession.

The idea is simple: automate the password guessing, speed up the attack, and don't spend too long on any individual site.

Look for the low-hanging fruit, and harvest it as quickly as you can; if you can't get in within a few hundred or thousand attempts, move on to the next potential victim.

It's doorknob rattling, but on an industrial and international scale.

Tireless cybercrime and underweb reporter Brian Krebs has published a list of sample WordPress usernames and passwords used in this attack, courtesy of security breach cleanup company Sucuri.

The top thirteen generically-chosen dictionary entries for username and password are as follows:

It's worth a look at the list (click on the image above), if only to reassure yourself that you haven't taken chances with any of your own passwords.

Notice also that the attackers are focusing on the username admin, used in 90% of the login attempts, because it's the default WordPress administrative username.

A username shouldn't be considered a secret (that's what the password is for), but you can avoid unwanted attention from low-hanging-fruit attacks by choosing something other than the default, as WordPress founder Matt Mullenweg himself advises.

Matt's suggestions are pithy and clearly put, so I'll repeat them here; they make up good advice for any web service product, whether you're blogging, file sharing, or running a CMS:

Almost 3 years ago we released a version of WordPress (3.0) that allowed you to pick a custom username on installation, which largely ended people using "admin" as their default username. Right now there’s a botnet going around all of the WordPresses it can find trying to login with the "admin" username and a bunch of common passwords, and it has turned into a news story (especially from companies that sell "solutions" to the problem).

Here’s what I would recommend: If you still use "admin" as a username on your blog, change it, use a strong password, if you’re on WP.com turn on two-factor authentication, and of course make sure you're up-to-date on the latest version of WordPress. Do this and you'll be ahead of 99% of sites out there and probably never have a problem. Most other advice isn't great — supposedly this botnet has over 90,000 IP addresses, so an IP limiting or login throttling plugin isn't going to be great (they could try from a different IP a second for 24 hours).

There you have it.

Not being the low-hanging fruit isn't a generic solution to this problem, as it's a bit like outrunning your buddy when you are chased by a hungry lion: it saves you, but leaves someone else to take the hit.

But that is no reason not to move your fruit to higher branches.

Remember that if someone breaks into your server, that's bad for you, but it is also bad for everyone else.

It gives the crooks a free ride for hosting malware, launching further attacks, publishing phishing pages, disseminating fake updates or bogus information, and much more.

All with your imprimatur, and, in the end, with your services blocklisted by anyone who's security conscious.

Remember, password-guessing attacks of this sort happen all the time.

The attack volume in this case has been sufficient to attract global attention, which is a good thing, but it's currently thought to be only about three times the usual level.

In other words, even when "normal service" is resumed, we'll all still be firmly in the sights of the cybercriminals, so take this as a spur to action!

Follow @duckblog

Image of Dictionary with magnifying glass courtesy of Shutterstock.


View the original article here

Tuesday, August 21, 2012

Insecure WordPress blogs unwittingly host Blackhole malware attack

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SophosLabs has intercepted a major malware campaign, spread via spam email and compromised self-hosted WordPress blogs, which attempts to infect computers using the notorious Blackhole exploit kit.

Be on your guard if you have received an email entitled "Verify your order", as links contained within the email could take you to a poisoned webpage, designed to install malware onto your PC.

Here's what a typical email looks like:

Malicious email

Subject: Verify your order

Message body:
Dear [name],

please verify your order #[random number] at [LINK]

We hope to see you again soon!

WordPressThe websites that are being linked to aren't ones that have been created by the malicious hackers.

They are legitimate websites that are running a self-hosted installation of the popular WordPress blogging platform. (Note, this does not include the many millions of bloggers who use the WordPress.com service - the vulnerable sites are those where people have installed their own WordPress software).

Unfortunately, some people haven't properly secured their sites - which has allowed malicious hackers to plant malicious code from the Blackhole exploit kit, and means that malware is now downloading onto innocent users' computers.

Sophos products detect the malware as Troj/PDFEx-GD, Troj/SWFExp-AI, Mal/ExpJS-N and Troj/Agent-XDM.

More and more of the attacks that we are intercepting involve the Blackhole exploit kit - recent examples include emails posing as traffic tickets from NYC, rejected wire transfer notifications and fake Facebook photo tag notifications.

Remember to not just keep your anti-virus software up-to-date, but also to ensure that any software you run on your web server is also properly secured, and kept patched and current (that includes blogging software like WordPress and any plugins that it might use).

Follow @gcluley

View the original article here