Google Search

Showing posts with label hacked. Show all posts
Showing posts with label hacked. Show all posts

Tuesday, September 24, 2013

Why Twitter's two-factor authentication isn't going to stop media organisations from being hacked

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Twitter has announced the availability of two factor authentication (2FA) for its service, meaning that users can opt-in to something stronger than just a username and password to protect their accounts.

Twitter login code

In a blog post, Twitter explains how the new security measure works.

If you decide to turn 2FA on for your Twitter account, every time you try to log into the site you will be prompted to enter a six-digit code that Twitter sends to your phone via SMS.

Here is a video Twitter released, demonstrating the feature:

So, the big question is this... is this going to help media organisations such as The Guardian, NPR, the Financial Times, and others who have found their Twitter accounts hijacked by the likes of the Syrian Electronic Army?

Sadly, I don't think it's going to help them at all.

Media organisations who share breaking news via social media typically have many staff, around the globe, who share the same Twitter accounts.

2FA isn't going to help these companies, because they can't all access the same phone at the same time.

Either those people will have to leave themselves permanently logged into Twitter (which is itself unwise from the security perspective), or one central trusted person will have to "own" the phone - and share the six-digit code with journalists as they try to log in to share breaking news stories.

Twitter verification

It's a complex problem to fix, and for that reason many media organisations may choose not to enable Twitter's additional security at this time.

Of course, *another* solution would be to have an intermediary service, acting as a proxy, to which journalists could post their Twitter updates (using appropriate authentication) and then have *that* service feed the official Twitter account.

If you take that approach, just ensure that you have proper security systems in place for that proxy service - to keep out hackers and mischief-makers.

Corporations with "shared accounts" on Twitter would be wise to keep their defences updated, educate their staff on security and best practice, and learn the lessons of how Twitter accounts have been hacked in the past.

If you do enable Twitter two-factor authentication, whether you are Joe Public or a multinational corporation, realise that the technology isn't going to help if you have users who are easily phished.

Determined online criminals could use "man-in-the-middle" techniques to grab the six digit passcode alongside your password and username if they are determined.

So, even if you do turn on Twitter's 2FA, you still need to double-check that when you enter your username and password, or your six digit code, that you are *really* on Twitter's https website.

HTTPS on Twitter's website

Otherwise, the crooks can just use all three items to log in as you...

In time, Twitter will surely mature and offer appropriate security, and mechanisms which recognise how many corporate brands and news organisations are using Twitter today.

Maybe they will one day adopt a system like Facebook has, where multiple users can have access to an account - all with different levels of authority, all with different usernames and passwords.

Right now Twitter's 2FA is more likely to be welcomed by individuals who own personal accounts, and small companies with a Twitter presence, than embraced by the high profile victims attacked by the Syrian Electronic Army in the past.

Follow @gcluley

View the original article here

Thursday, September 12, 2013

FT hacked. Syrian Electronic Army hijacks Financial Times blogs and Twitter accounts

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Financial TimesThe Syrian Electronic Army has struck again - this time adding the scalp of the prestigious Financial Times to its collection of hijacked accounts belonging to well-known media organisations.

Hackers from the Syrian Electronic Army appear to have stolen the usernames and passwords of FT staff with access to the newspaper's social media accounts, and posted unauthorised blog entries and tweets earlier today.

Here are some examples of the damage caused by the hackers:

FT blog

FT tweets

Of course, the hacking of such a prestigious target doesn't go unnoticed - and the FT's security team scrambled into action, warning readers about the issue and deleting offending messages as they were found.

FT hack statement

The Syrian Electronic Army isn't above rubbing salt into the wounds, clearly finding it amusing to publish the email address and password of at least one FT staff member who seemingly (we won't republish it here) chose a rather silly password.

SEA reveal FT password

In recent weeks Syrian Electronic Army hackers have successfully broken into online accounts belonging to the likes of The Guardian, the BBC, NPR, and CBS with apparent ease, prompting Twitter take the unusual step of reaching out to news and media organisations to warn them about the current attacks, and offer advice on defensive measures.

The problem is compounded by Twitter's current system of insisting that every Twitter account only has one username/password connected with it.

This is unlike the way Facebook pages work where individual users can be assigned different rights for managing and administering their firm's online presence. Combined with two factor authentication (known as Login Approvals on Facebook) this provides a higher level of security, and greater granularity about what users can do.

Twitter's approach inevitably leads to media agencies, who are pressured to tweet breaking stories around the clock, to share Twitter passwords with many staff worldwide - and hold their breath that none of them get hacked or have their credentials phished.

It would be great if Twitter could introduce two factor authentication. It would be great if Twitter could introduce a way for firms to give different staffers separate logins for the same account.

And it would be great if media companies could train their staff to be suspicious of unsolicited emails, be wary of clicking on unknown links, and of unwittingly handing their passwords over to criminals.

The blame for the hackers' success, after all, shouldn't entirely fall on Twitter's doorstep. Ultimately it was a human, working for the media organisation, who made a mistake and was tricked into giving the keys to the castle to a bunch of hackers.

Follow @gcluley

View the original article here

Tuesday, September 3, 2013

Sex and the City author hacked, draft of new book is leaked online

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Candace BushnellCandace Bushnell, the author famous for "Sex and the City", has fallen victim to a hacker who not only broke into her Twitter account, but also posted extracts of her as-yet-unfinished next book online.

Although the creator of Carrie Bradshaw seems to have expelled the hacker from her Twitter account, and deleted the offending tweets, an early draft version of what seem to be the first 50 pages of Bushnell's book - currently entitled "Killing Monica" - are available online for anyone to download and read to their heart's content.

Tweet from Candace Bushnell's hacked account

In addition, the hacker has also posted screenshots of private communications from Bushnell's Earthlink account between her, her publishers and her literary agents.

Interestingly, the hacker who is taking credit for the compromise of Bushnell's accounts and the leak of her book draft is "Guccifer".

Regular readers of Naked Security will remember that Guccifer is the hoopy frood who thought it was a good idea to break into accounts belonging to Colin Powell and former US Presidents George H and George W Bush.

Book extract

From the looks of things, Candace Bushnell has been sloppy with her computer security - perhaps choosing an easy-to-guess password, using the same password in multiple places or allowing her password to be phished by a hacker.

But furthermore, the incident underlines the importance of encrypting sensitive documents (such as the first 50 draft pages of an upcoming book) so even if your email account *is* compromised, a hacker won't be able to read any attachments which could be confidential or commercially sensitive.

Nobody likes to be hacked, of course. And it is a criminal act which should be investigated by the authorities. And Bushnell and her publishers have the right to choose how and when extracts from her book are shared with a wider audience.

But you can't help but wonder if Candace Bushnell's publishers might be able to turn a potential disaster into a PR opportunity, and turn around this unfortunate incident and use it as a chance to heighten interest in the famous author's next book.

Follow @gcluley

View the original article here

Monday, September 2, 2013

Seriously, this is how the Syrian Electronic Army hacked The Onion

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The Syrian Electronic Army hacked into The Onion’s Twitter account on Monday, publishing fake anti-Israeli stories and an anti-Obama "meme" image.

The Onion twitter

Then the satirical news publication kept tongue firmly in cheek with a post, titled "Syrian Electronic Army Has A Little Fun Before Inevitable Upcoming Deaths At Hands Of Rebels":

"We figured that before they bust in here and execute every single one of us, we might as well have a good time and post some silly tweets about Israel from a major media outlet’s feed."

By Wednesday, after it had served up tips to avoid getting hacked,* the Onion's tech team got serious and posted this writeup of how the takeover happened.

In a nutshell, the Onion fell prey to phishing, with three separate methods that breached Onion employees' Google Apps accounts.

Syrian Electronic ArmyThe first attempt came around May 3, when the SEA sent phishing emails to some Onion employees. It included a spoofed link, purportedly to an article about The Onion published by The Washington Post, which actually went through a few redirects before depositing its targets at a site that requested Google Apps credentials before redirecting to a Gmail inbox.

The tech team says that the emails came from "strange, outside addresses" and were sent to just a few employees, making them appear to be "just random noise rather than a targeted attack."

At least one employee fell for it.

After breaching that account, the attackers used it to send the same phishing email to more Onion staff around 2:30 AM on Monday.

Coming from a trusted address, the email got a lot of click-throughs.

Most staffers refrained from entering their login credentials, but two fell for the ruse. Unfortunately, one of the two had access to all of The Onion's social media accounts.

The Onion discovered that at least one account had been compromised and sent out an email asking that all staffers change passwords immediately.

But the attacker used another undiscovered, compromised account to send a duplicate email that again included a link to the phishing page, this time disguised as a password-reset link.

When the attackers sent this duplicate email, they cannily skipped sending it to members of The Onion's tech or IT teams, ensuring it went undetected.

This third and final phishing attack compromised at least 2 more accounts, The Onion reports, one of which was used to further abuse the Twitter account.

The OnionThat's when the editorial team started to publish satirical articles inspired by the attack.

The article about how the SEA would soon be slaughtered provoked the attacker, who began posting editorial emails on their Twitter account.

At that point, The Onion figured it couldn't know whose Google Apps accounts had been hacked, so it forced a password reset on everybody's account.

The Onion published these tips to avoid getting our Twitter accounts hacked. These are the ones that we should all take seriously:

Make sure that your users are educated, and that they are suspicious of all links that ask them to log in, regardless of the sender.The email addresses for your Twitter accounts should be on a system that is isolated from your organization’s normal email. This will make your Twitter accounts virtually invulnerable to phishing (providing that you’re using unique, strong passwords for every account).

[Note: either use a password manager to generate and store passwords or check out Graham Cluley's method to create a strong password.]

All Twitter activity should go through an app of some kind, such as HootSuite. Restricting password-based access to your accounts prevents a hacker from taking total ownership, which takes much longer to rectify.If possible, have a way to reach out to all of your users outside of their organizational email. In the case of the Guardian hack, the SEA posted screenshots of multiple internal security emails, probably from a compromised email address that was overlooked.

*Tips to avoid getting hacked that you should not take seriously, also courtesy of The Onion, via National Public Radio:

Move site to a new web address every few minutes.**Reduce interest in your website by avoiding popular subjects.*** If you receive an email asking for your password, dig deeper by entering information.****

[**This is impossible.]
[***This is inadvisable if you want anybody to read your site.]
[****No, no, no, no, no.]

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Thursday, August 29, 2013

US Department of Labor website hacked, serves malware, now fixed

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

You may have read about the US Department of Labor "getting hacked".

It's true, but fortunately the story is not quite as gory as it sounds in those two fateful words.

A subdomain of the Department's main website, running off a separate server - what's known colloquially as a microsite - was modified to serve up malware.

There's a sort of double irony here, because news about the breach broke on May Day, which is Labour Day in much of the world, though not in the United States, where it is celebrated in September.

The affected microsite was www.sem.dol.gov, which is currently (2013-05-02T10:22Z) offline.

SEM stands for Site Exposure Matrices, but the "site" in the name refers not to websites but to worksites.

The SEM "is a repository of information on toxic substances present at Department of Energy sites and other locations where radiation exposure is a possible hazard.

We've already seen speculation that the radiation-related nature of the SEM site tells us that this is a targeted attack, and certainly the site is not one you would expect to draw a lot of traffic.

On the other hand, of course, it might just be that the site was attacked because it was vulnerable while other parts of the Department of Labor site were not.

? Many organisations use microsites for special purposes, such as conducting one-off marketing campaigns or, as in this case, for presenting specialised data. Often, this is to avoid bothering the IT team with change requests for the main website, or in order to try something new. If you use microsites this way, make sure you don't take any security shortcuts while you are "innovating".

The attack used a malicious JavaScript file to get your browser to download a file called bookmark.png.

This sounds like an image file, but is in fact a Windows program with the first byte altered so that it can't run by itself.

In theory, your browser shouldn't do anything more than simply, and harmlessly, download the offending file.

But the malicious JavaScript then uses the function called helo() in the script above in an effort to trigger the CVE-2012-4792 remote code execution vulnerability in Internet Explorer.

The attackers hope that this will trick your browser into jumping over its security checks to modify and run the downloaded malware program without asking you.

The exploit seems to have borrowed both code and concept from a publicly-available Metasploit module that gives more detail (perhaps a little too much for some readers' comfort) about this exploit.

The good news is that if you've patched Windows recently, or if you are using Internet Explorer 9 or 10, you should be safe, since the vulnerability will be fixed, the exploit won't work and the non-functional bookmark.png file will do you no harm.

? Sophos security products block the drive-by-download exploit script as Troj/ExpJS-IT and the "payload" executable as Troj/Agent-ABOB.

The attack also uses a malicious script file that includes what are known as anti-anti-virus techniques.

This means that the attacker actively attempts to evade detection by interfering with the operation of one or more of the anti-virus tools you may be running.

If you're using BitDefender, the script even tries to connect to the local web console to reconfigure the product on your behalf.

? Sophos security products block this malicious script as Troj/ExpJS-IV.

To summarise:

A patched version of Windows should be immune to the exploit used in this attack.Internet Explorer later than version 8 should be immune.The hacked site is off the air and unlikely to reappear until it is clean and safe.An up-to-date anti-virus ought to block the malicious files, even on an unpatched computer.

Oh, and one more thing.

If you use microsites for special-purpose content, take care to avoid introducing special purpose risks at the same time!

Follow @duckblog


View the original article here

Saturday, August 10, 2013

50,000,000 usernames and passwords lost as LivingSocial "special offers" site hacked

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

LivingSocial, the online offers site owned in largish part by Amazon, has just emailed its userbase, said to be 50,000,000-strong, to fess up to a data breach.

That's right: another day, another shed-load of password hashes in the hands of crooks.

At least LivingSocial's password database was salted and hashed, which reduces the impact of the breach a lot.

Naked Security reader Chris, from Melbourne, Australia, kindly sent us a copy of the notification email he received:

LivingSocial recently experienced a security breach on our computer systems that resulted in unauthorised access to some customer data from our servers. We are actively working with the authorities to investigate this issue.

The information accessed includes names, email addresses, the date of birth of some users, and encrypted passwords; technically 'hashed' and 'salted' passwords. We never store passwords in plain text.

To revise password storage quickly: don't store the actual password.

Store a random string of characters instead, combine the password and this random string (that's "salting" the string to vary its flavour), and pass the salted password through a non-reversible cryptographic function to get a message digest code (that's "hashing" the data by slicing, dicing and stirring together the salted input in a digital mixing bowl).

A crook can check to see if your password is, say, s3cr3cy by salting-and-hashing himself, but he has to start with a guess, because he can't go back from the hash to your password.

That's why easy-to-guess passwords are bad: the crooks crack them first.

? You often hear the term "hashed and salted", as in the email above, but technically you salt and then hash, otherwise the salt wouldn't get mixed into the hash calculation.

The silver lining I'm always determined to find when SNAFUs like this occur is that LivingSocial took the opportunity to sneak an additional, and pertinent, security reminder into its breach notification:

Please note that LivingSocial will never ask you directly for personal or account information in an email. We will always direct you to the LivingSocial website – and require you to login – before making any changes to your account. Please disregard any emails claiming to be from LivingSocial that request such information or direct you to a website that asks for such information.

Good advice, not least because cybercrooks love to take security announcements, from patches and updates to breach notifications, and use them to try to get new victims on the hook.

And it's just when you're expecting a notification from a company you do business with that you are at the greatest risk of believing emails that you'd probably discard out of hand at any other time.

? Never click on login links contained in emails. A reputable company will never send you such emails, precisely so you can assume that all email-borne login links are bogus, and ignore them. The same sort of reason why many jurisdictions require game hunters, whom you'd expect to sneak around in camouflage, to wear conspicuously lurid and unnatural-looking jackets. If you're dressed entirely unlike any other animal on Planet Earth, you won't be mistaken for one.

If you read LivingSocial's online warning, you will see a further suggestion on what to do next:

We also encourage you, for your own personal data security, to consider changing password(s) on any other sites on which you use the same or similar password(s).

That's also good advice, but a few more words would have made it even better: if you've used the same password on multiple sites, change the passwords on those sites so that they are all different.

And if you are in the habit of re-using passwords, don't wait until one of your accounts gets hacked before you go and change all those common passwords.

The whole idea of using different passwords on different sites is to avoid what you might call a "race to the bottom," where all your logins end up as insecure as the slackest, sloppiest, weakest site on the list.

And if you struggle to come up with decent passwords, fear not: watch fellow writer Graham Cluley's venerable and amusing video, which gives you a surprisingly easy and effective technique to stay off the "easily guessed" password lists.

(Enjoy this video? Check out the SophosLabs YouTube channel!)

Follow @duckblog


View the original article here

Friday, July 26, 2013

Hosting company Hostgator hacked, suspect arrested after being "rooted with his own rootkit"

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A system administrator - or, more accurately, a former system administrator - from Hostgator, a server hosting company in Houston, Texas, has been arrested for hacking into his former employer's network.

Court documents allege that after Eric Gunnar Grisse, 29, got the sack from his job at Hostgator, he jumped right back into the company's network, using a backdoor Trojan he had planted earlier.

Hosting companies do just what their name suggests: they run racks full of servers, plus a network to connect them all up, and then rent you time and space on one or more of them, so you don't need to own and operate your own IT infrastructure.

The services available typically include: simple websites, where your web pages are handled by a web server that also hosts other user's websites; virtual servers, where virtualisation is used to share out powerful physical servers amongst multiple customers; and dedicated servers, where a specific physical server is provisioned with an operating system and turned over to you almost as if it were your own.

?Web hosting is a bit like renting a bed in a backpackers' dormitory; a virtual server is like a room in a boarding house; and a dedicated server is like an apartment in a high-rise block.

Obviously, if you misconfigure your own hosted setup, you run the risk of being hacked and having your online presence ruined.

Most hosting companies try to prevent you from making egregious mistakes, but if you choose to give edit rights to your web pages to an careless contractor, say, that's your lookout.

At the same time, you put a lot of trust in the security competence of your hosting provider.

After all, if your provider configures its network badly, then other customers might wrongly be able to mess with your servers, even though you set up your parts of the system correctly.

Worse still, hackers who are able to get into the operational innards of a hosting business might be able to mess with any and all of the systems on the network.

Gisse, it is alleged, was able to get unlawful access somewhere between these two levels.

According to the affidavit in this case, Gisse's remote access program was found on 2723 separate servers inside Hostgator's network.

That's about 25% of the servers entrusted to Hostgator, according to a commentator on the online community forum webhostingtalk.com.

The court documents claim, amongst other things, that Gisse:

Named his backdoor program pcre, which makes it look vaguely like a commonly-used system library known in full as Perl Compatible Regular Expressions.Altered the system tools ps and netstat, which list running programs and network activity respectively, to hide his own presence. (This makes his hack a "rootkit", in the old-school Unix sense of the word.)Stole a Hostgator SSH login key file so he could continue to authenticate even from outside, after being sacked.

SSH (secure shell) is a ubiquitous and general-purpose way of accessing Unix systems remotely by creating an authenticated and encrypted network connection between two computers. Typically, there are two ways of logging in over SSH: by typing in a traditional username and password, and by using a pre-computed public/private key pair.

The keypair approach is popular with sysadmins because it avoids the need to keep typing in usernames and passwords. You generate a keypair, and upload the public key to a secure area on the server; then you can login from any computer on which the private key file is installed.

You can encrypt the private key if you like, which protects it against theft, but many people don't bother so that they can write automation scripts that use the key to carry out administrative tasks.

Gisse was caught, it is claimed, due to evidence that included:

Logs saved as part of a once-a-minute screenshotting tool implemented by Hostgator to keep an audit trail of IT operations. The investigators claim that Gisse expressed the intention to "get himself fired" and to steal data from the company, and also identified logins from his Hostgator account, under the name acdc, to a server in Germany named efnet.pe.An illicit network connection, open at the time of investigation, between Hostgator and efnet.pe. Apparently, the investigators were able to use the connection in reverse to locate a stash of hacking tools, exploits, and data belonging to Hostgator, as well as a logged-in user called acdc.

If the allegations are true, it sounds as though the suspect was hoist by his own petard, or at least rooted with his own rootkit!

Follow @duckblog


View the original article here

Saturday, July 6, 2013

Planes can be hacked remotely with Android app, researcher claims

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Airplane. Image from ShutterstockA security researcher and trained commercial pilot combined his interests and cooked up an exploit framework and Android app that can be used, at least theoretically, to hack a plane.

That includes potentially gaining information about an aircraft's onboard computer, changing the intended destination, flashing interior lights, delivering spoofed malicious messages that affect the behavior of the plane, and, just maybe, if pilots don't manage to turn off autopilot and/or have difficulty with manual flight operation, crashing the plane.

These are theoretical exploits demonstrated by Hugo Teso, a security consultant at n.runs AG in Germany, who gave a talk about his research at the Hack in the Box conference in Amsterdam on Wednesday.

Of course, Teso hasn't tried any of this out on real planes, given that there aren't many planes lying around waiting for people/plane/landscape annihilation, which would, at any rate, be illegal and amoral.

Rather, he conducted his research on aircraft hardware and software he acquired from various places.

That includes equipment from vendors offering simulation tools that use actual aircraft code and from eBay, where he found a flight management system (FMS) manufactured by Honeywell and a Teledyne Aircraft Communications Addressing and Reporting System (ACARS) aircraft management unit, according to Network World.

According to Help Net Security's Zeljka Zorz and Berislav Kucan, Teso's demonstration shed light on "the sorry state of security of aviation computer systems and communication protocols."

Teso created these two tools to exploit vulnerabilities in new aircraft management and communication technologies:

An exploit framework named SIMON, andAn Android app named, appropriately enough, PlaneSploit, which delivers attack messages to the airplanes' FMSes.

The two vulnerable technologies Teso exploited with these tools:

The Automatic Dependent Surveillance-Broadcast (ADS-B) (this surveillance technology, used for tracking aircraft, will be required by the majority of aircraft operating in US airspace by Jan. 1, 2020), and The Aircraft Communications Addressing and Reporting System (ACARS), a protocol for exchange of short, relatively simple messages between aircraft and ground stations via radio or satellite that also automatically delivers information about each flight phase to air traffic controllers.

According to Help Net Security, Teso abused these "massively insecure" technologies, using the ADS-B to select targets.

He used ACARS to siphon data about the onboard computer and to exploit its weaknesses by delivering spoofed messages that tweak the plane's behavior.

Using the Flightradar24 flight tracker - a publicly available tool that shows air traffic in real time - Teso's PlaneSploit Android app allows the user to tap on any plane found within range - range that would be limited, outside of a virtual testing environment, to antenna use, among other things.

Flight Radar 24The application has four functions: discovery, information gathering, exploitation and post exploitation.

According to Help Net Security, these are some of the functions Teso showed to the conference audience:

Please go here: Allows user to change the targeted plane's course by tapping locations on the map.Define area: Set detailed filters related to the airplane, such as activating something when a plane is in the area of X kilometers or when it starts flying on a predefined altitude.Visit ground: Crash.Kiss off: Remove plane from the system.Be puckish: Trigger flashing lights and buzzing alarms to alert the pilots that something is seriously wrong.

Teso has, thankfully, responsibly, refrained from disclosing details about the attack tools, given that the vulnerabilities have yet to be fixed.

In fact, he told his listeners that he's been pleasantly surprised by the receptivity he's received by the industry, with companies vowing to aid his research.

Given Teso's belief in responsible disclosure, the industry can take steps to patch the security holes before someone with more malicious intent has an opportunity to exploit them.

From the sound of things, this researcher has garnered plenty of media attention but still values aircraft and passenger safety well over fame and glory.

Kudos, Mr. Teso, and thanks.

Follow @LisaVaas
Follow @NakedSecurity

Image of plane courtesy of Shutterstock.


View the original article here

Friday, May 10, 2013

Jailed cybercriminal hacked into his own prison's computer system after being put in IT class

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Here's a piece of advice for those running classes training prisoners about information technology.

It's probably not a good idea to let notorious hackers join the course - or, if you do, to keep a very close eye on what they're up to.

Teenager Nicholas Webber ran the infamous GhostMarket.Net cybercrime website, which sold stolen credit card details and offered tutorials to budding criminals about how to commit identity theft and online scams.

Nicholas Webber

With 8,500 members, GhostMarket was the biggest criminal website ever uncovered by the British authorities.

It's said that GhostMarket's activities can be linked to frauds around the world which saw £8 million stolen from 65,000 bank accounts.

Media reports have detailed the playboy lifestyle enjoyed by Nicholas Webber, GhostMarket's founder, who had only just turned 18 at the time of his arrest in October 2009.

Webber was sentenced to five years imprisonment in May 2011, and found himself at HM Prison Isis, a Category C male Young Offenders Institution, in South East London.

Cells at HM Prison Isis

Normally you would expect (and hope) a hacker's criminal career to end there, but sadly that wasn't to be.

As the Daily Mail reports, Webber somehow managed to sign-up for the prison's IT class, and from there managed to hack into the prison's mainframe computer.

According to the report, a spokesman for the prison service has confirmed that Webber was involved in the hack, but has downplayed the significance of the hack:

"At the time of this incident in 2011 the educational computer system at HMP Isis was a closed network. No access to personal information or wider access to the internet or other prison systems would have been possible."

The story of the 2011 prison hack has only come to light now because Michael Fox, the IT class's teacher, is claiming unfair dismissal. Fox says that it was not his decision to admit Webber to the class, and that he was not aware of Webber's history of cybercrime.

Earlier this year, an official report claimed that HM Prison Isis was "bedevilled" by technological problems, including a breakdown in its biometric thumbprint security system.

Let's hope that they didn't ask Webber to help them fix that...

Follow @gcluley

View the original article here

Sunday, May 5, 2013

Evernote hacked - almost 50 million passwords reset after security breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

EvernoteEvernote, the online note-taking service, has posted an advisory informing its near 50 million users that it has suffered a serious security breach that saw hackers steal usernames, associated email addresses and encrypted passwords.

It's not clear how the hackers managed to gain access to Evernote's systems, or how long the hackers had access to Evernote's account information.

However, in an interview with TechCrunch, Evernote said that they had first noticed suspicious activity on February 28th.

The good news is that no payment details were stolen, and according to the company the hackers were not able to access notes that users had stored on the Evernote service.

Furthermore, it sounds as though the passwords were encrypted, using hashes and salting to prevent login details falling into the wrong hands. (It would be reassuring - of course - to have more details shared by Evernote of how the passwords were hashed and salted).

Evernote advisory

The investigation has shown, however, that the individual(s) responsible were able to gain access to Evernote user information, which includes usernames, email addresses associated with Evernote accounts and encrypted passwords. Even though this information was accessed, the passwords stored by Evernote are protected by one-way encryption. (In technical terms, they are hashed and salted.)

While our password encryption measures are robust, we are taking additional steps to ensure that your personal data remains secure. This means that, in an abundance of caution, we are requiring all users to reset their Evernote account passwords. Please create a new password by signing into your account on evernote.com.

What's not good news is that the hackers now have access to the usernames and email addresses of Evernote customers. It is easy to imagine how this information could be abused - for instance, the hackers could send out spam emails to those users claiming to come from Evernote, and trick them into visiting a malicious website.

And, of course, it's another cautionary tale about the risks which can exist with trusting the cloud to look after your personal information. Evernote sounds to me like it's another online service that would benefit from providing its users with additional account security - such as two factor authentication.

Evernote advises users to choose a strong password, and to be suspicious of reset password links sent to users via email. Furthermore, everyone should ensure that they are not using the same password on multiple sites.

Evernote appears to have acted reasonably rapidly in response to this security incident, and it will be interesting to see if they share any more information about how the hack might have occurred in the coming days.

Further reading: Evernote shoots itself in foot over "never click on 'reset password' requests" advice

Follow @gcluley

View the original article here

Friday, May 3, 2013

Donald Trump has his Twitter hacked by "lowlives"

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Donald Trump. Image from ShutterstockIf you are one of the more than two million people who follow Donald Trump on Twitter, you might have seen an unusual tweet from the impossibly coiffed real estate mogul yesterday.

Rather than plugging his "The Apprentice" American TV show, or chirping up on a political issue, the multi-millionaire appeared to have chosen to quote a lyric by hip-hop artist Lil' Wayne.

These hoes think they classy, well that’s the class I’m skippen

It turns out that Donald Trump had, in reality, had his Twitter account hacked.

Offending tweet

The offending tweet was swiftly erased, and "the Donald" - who doesn't believe in cover-ups - posted an explanation:

Tweets from Donald Trump

My Twitter has been seriously hacked--- and we are looking for the perpetrators.

Twitter will soon be irrelevant if lowlifes are so easily able to hack into accounts.

Of course, things could have been much worse. Imagine if Donald Trump's hijacked Twitter account had been exploited to post a link to a malicious website, for instance. With some clever social engineering ("Win free tickets for 'The Apprentice' grand final"?) you can easily picture many people clicking on a dangerous link and potentially infecting their computers with malare or having their passwords phished.

Quite how Trump's account was compromised is unclear, but a reasonable guess would be that he had either chosen a weak, easy-to-guess password, or that he was using the same password in multiple places. Never a good idea.

Multi-millionaire Trump stopped short of fellow celebrity Jeremy Clarkson, who vowed to kill the people who hacked his Twitter account earlier this week.

Follow @gcluley

Donald Trump image from Shutterstock.


View the original article here

Thursday, May 2, 2013

Mandiant report, iOS coders owned, Twitter accounts hacked, and more... [PODCAST]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Adobe, Adobe Flash, Apple, Facebook, Featured, Google, Java, Microsoft, Oracle, Podcast, Privacy, Security threats, Twitter

Have you joined thousands of others, and become a loyal listener to the "Chet Chat" yet?

Sophos has been recording security-related podcasts since 2006.

One of our most popular shows is the regular "Chet Chat" series, hosted by Senior Security Advisor Chester Wisniewski.

Chet discusses the latest security news with a series of experts, and offers actionable advice on what you and your company should do about it.

The latest "Chet Chat", episode 103, features Chet and popular guest Paul "Duck" Ducklin, who bring you their customary and entertaining mixture of insight, expertise, scepticism, and advice:

(24 February 2013, duration 15:24 minutes, size 9.3 MBytes)

Sophos Security Chet Chat #103 (MP3)

The Chet Chat typically lasts about 15 minutes, so why not make it a regular quarter-hour in your lunchtime security fix, or listen to it as part of your commute?

And why not take a look at the back-catalogue of Sophos Podcasts in our archive? We have loads of interesting stuff for your listening pleasure.

Follow @NakedSecurity

Tags: Adobe, Apple, Burger King, chet chat, clarkson, Facebook, flash, gmail, Google, jeep, Malware, Mandiant, Microsoft, passwords, Patching, Podcast, Spam, sscc, trump, Twitter, vulnerability


View the original article here

Sunday, April 14, 2013

Was Alicia Keys hacked, or is she cheating on BlackBerry with iPhone this Valentine’s Day?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Alicia Keys. Image from ShutterstockBlackBerry recently surprised the tech industry when they announced at their major launch event on January 30 the appointment of musician, Alicia Keys, as the Global Creative Director.

And since then Keys has been pimping BlackBerry’s new smartphone model, Z10, tweeting from it since launch. But is there a secret that Keys has been keeping? An extra-cellular affair with the iPhone?

At the BlackBerry launch, Keys told the audience about her on-again/off-again love affair with BlackBerry.

She said she had been lured away from BlackBerry by “hotter, sexier phones, something with more bling” in the past, but now declaring that she and Blackberry were “exclusively dating”.

So it was a bit of a surprise when a tweet from her account went out to her 11 million followers on February 11 – just days after the BlackBerry launch – sent not from her exclusive BlackBerry, but from her ex, the iPhone.

Started from the bottom now were here!

Later the same day, Keys sent out a tweet stating that the previous tweet quoting lyrics from recording artist, Drake, had not come from her, but likely a hacker. (But don’t be offended – she still likes Drake.)

What the h*ll?!!!! Looks like I’ve been hacked… I like @Drake but that wasn’t my tweet :-(

But that doesn't explain this tweet pic posted a day before from her account showing the musician looking radiant in her dressing room at the Grammys with not just one, but two, of her exes in reach – iPhones.

Alicia Keys at the Grammys

Now, we at Naked Security have seen our fair share of hacked Twitter accounts of celebrities such as Justin Bieber and Britney Spears – and this doesn’t quite smell the same.

Would a hacker that has gone through the trouble of hacking an account of such a well-known figure with access to *11 million followers* really only send one tweet with just a song lyric?

This story reminds us of a previous incident when Kim Kardashian claimed her Twitter account was hacked after having trouble logging in to Twitter from her home computer.

Could it be that Keys is using the many recent celebrity Twitter hacks as a scapegoat for her mishap?

Of course, there is also the possibility that Keys could have her PR people monitoring and tweeting on her behalf, and this error could have been a mistake on their part. We can’t know for certain.

But the one thing we do know is that whoever accessed her Twitter account is hanging out with her ex.

Awkward.

Follow @NakedSecurity

Alicia Keys headshot image courtesy of Featureflash / Shutterstock.com


View the original article here

Friday, April 12, 2013

Bit9 hacked, used to inject malware into customers' networks

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Security vendor Bit9 has been hit by a serious security breach of its own network.

Intruders broke into a core part of the company's service and used its own trusted digital certificates to create pre-authorised malware.

The result, apparently, was that a small number of customers got infected with malware that wasn't merely missed by Bit9's detection algorithms, but was actively endorsed by its protection system.

It's always tricky to write about compromises and problems with competitors' products, but please bear with me here. I'll try to be as balanced as I can.

As a colleague wryly and compactly pointed out the other day when Kaspersky hit the news by cutting customers off from the internet with a dodgy update, "John 8:7."

Bit9's case is a bit different because the company eschews traditional security and anti-malware techniques and instead favours whitelisting.

? I'm not a fan of that name because at least some people find it offensive, and because there is a much clearer, self-descriptive alternative: allowlisting. Likewise, blacklisting is much more directly rendered as blocklisting. Simply put, blocklisting aims to recognise known bad stuff and to stop it. Allowlisting aims to recognise known good stuff and to stop everything else.

For what it's worth, Bit9 has done the right and honourable thing, and 'fessed up on its website.

The company is still keeping the precise details close to its chest, as it's entitled to, but has offered a general overview that's pretty clear. Call me old-fashioned, but that counts for a lot.

I'm not entirely convinced by the entire explanation, however.

Bit9's observation that "this incident was not the result of an issue with our product," for instance, is a trifle misleading.

I think I know what they mean, and why they said it, but the truth is simple: Bit9's service made the wrong call.

It misrecognised malware as good software (a false negative, in industry jargon) and let an infection through.

Conceptually, this is no different (in industry jargon, it had a similar failure mode) to what happens when a traditional anti-virus fails to spot malware as malware.

The truth is that any programmatic means of analysing another program and predicting its behaviour must be imperfect.

Regular readers of Naked Security will have heard me pronouncing on this matter before. That's because I'm a big fan of Alan Turing, who studied this very issue back in the 1930s, before digital computers even existed.

It's known as the Entscheidungsproblem (usually rendered into English as the Halting Problem), and it pretty much says that any security software must, at least occasionally, make mistakes.

It's become fashionable recently to bash anti-virus software harder than ever, decrying it as reactive, behind-the-times and even as "digital homeopathy." (Even I had to smile at that tweet.)

Allowlisting is often trumpeted as the preferred, scientific, simpler, cleaner, greener approach.

There's a lot to be said for that, if you can reliably predict in advance the complete list of software files you will need on your computers, and if you don't make any mistakes in ensuring that everything on the list really is good.

Of course, the pace of change is swift enough these days that you need to keep updating the list of known good stuff, and that's where errors can creep in.

In practice, modern anti-virus software doesn't rely on (indeed, hasn't relied on for about two decades already) a purely reactive, list-of-known-badness approach.

Today's anti-malware solutions aren't merely blocklists, and if you buy one and engage only its pure-play blocklisting parts, you're missing a trick.

Several tricks, in fact.

Similarly, any decent product that claims to work by permitting only known-good stuff doesn't rely entirely on allowlisting.

If a file is already known to be bad, you'd be silly not to use that information to ban the file so it never gets onto your allowlist by mistake!

No security solution can be perfect, because no solution can decide all the answers.

That's why defence in depth is really important, and why you should run a mile from any security vendor who still makes claims like "never needs updating" or "all others are imposters."

To the Bit9 crew: when I read the part where you wrote that "the threat from malicious actors is very real, extremely sophisticated, and that all of us must be vigilant," I felt your pain, brothers and sisters.

We may have varying approaches and differing opinions, but we're on the same side here.

I hope you catch the villains behind this, or at least find out more about the who, what and why...

Follow @duckblog


View the original article here

Sunday, April 7, 2013

Sarah Ferguson, Hugh Grant and Doctor Who win substantial damages after having their phones hacked

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Sarah Ferguson. Image from ShutterstockA court in London has heard that Sarah Ferguson, the former wife of Prince Andrew, is one of more than 100 people who have received significant payouts in the wake of the News of the World phone hacking scandal.

Sarah Ferguson, the former Duchess of York, demanded a public apology from the newspaper's publisher News Corporation, after reportedly having had her phone's voicemail intercepted since 2000 to feed the tabloid's appetite for juicy gossip.

Others who have received damages include Hugh Grant, former Doctor Who Christopher Eccleston and spoon-bender Uri Geller according to The Guardian.

The story of the British media's penchant for phone hacking dominated Britain's news headlines during 2011 and 2012, and has resulted in both criminal investigations and a government inquiry.

With such a high profile given to the issue, there's really no reason for anyone to have poorly-protected voicemail anymore. But in case you are still in doubt, here's our guide on how phone hacking worked, and how to make sure you're not a victim.

The story isn't over yet, of course, with ongoing police investigations into not just the interception of mobile phone voicemail systems but also the hacking of public figures' computers and email accounts using spyware Trojan horses.

Follow @gcluley

Sarah Ferguson image from Shutterstock.

Tags: Christopher Eccleston, Doctor Who, Hugh Grant, News Corporation, News of The World, NOTW, phone hacking, Royalty, Rupert Murdoch, Sarah Ferguson, Uri Geller


View the original article here

Wednesday, April 3, 2013

Twitter hacked, at least 250,000 users affected: what you can do to protect yourself

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Ouch. Hyperpopular microblog-type-thing Twitter is the latest web property to admit that intruders seem to have been wandering around its network for some time.

Earlier this week, both the New York Times and the Wall Street Journal came out with similar revelations.

With an irony that even the most literal-minded reader is unlikely to miss, Twitter published a blog post entitled Keeping our users secure:

This week, we detected unusual access patterns that led to us identifying unauthorized access attempts to Twitter user data. We discovered one live attack and were able to shut it down in process moments later. However, our investigation has thus far indicated that the attackers may have had access to limited user information – usernames, email addresses, session tokens and encrypted/salted versions of passwords – for approximately 250,000 users.

The article goes on to say that the company has "reset passwords and revoked session tokens" for the accounts that it thinks were affected.

A session token is a one-off cryptographic cookie that your browser submits to Twitter every time you revisit the site once you've logged in, so you don't need to enter your username and password over and over again.

A crook who steals your salted-and-hashed password can make educated, offline guesses at your password by trying out popular passwords (at great speed on modern password cracking kit), but if you have chosen a decent password, will probably get nowhere.

On the other hand, a crook who steals your session token can, in theory, take over your account, at least until he or you next log off.

By revoking your token unilaterally, Twitter will cause only minor annoyance to you (you will have to type in your password again) but create a major headache for any session hijacker (who will, if you have chosen well, be unable to enter your password to get back in).

Twitter also links to advice on how to turn off Java in your browser, but doesn't actually say whether the activation of Java in your browser had anything to do with the breaking to Twitter's network.

A client-side vulnerability on a Twitter administrator's computer might produce such an outcome, as happened when a Twitter staffer chose a shabby password a few years ago, but it's difficult to see how vulnerabilities on your client could lead to a server-side database compromise at Twitter.

We also echo the advisory from the U.S. Department of Homeland Security and security experts to encourage users to disable Java on their computers in their browsers.

Seems that Twitter took against the whole of Java at first, then scaled back its advice to suggest that you kick it out of your browser only, not that you uninstall it altogether. That matches the advice Chester and I gave in our recent podcast. Our Java discussion can be found at 4'50":

Still a raft of unanswered questions here.

How did they get in? Why undetected for so long? Who were they? What else did they get? Are users beyond the initial 250,000 affected? And so forth.

Twitter's being pretty open about this, and investigation continues, so my inclination is to take the company's comments and advice at face value.

If you were using your Twitter password anywhere else...you know what to do. Change the other passwords and don't do that again.If you're using short or easily-guessed passwords, change them and don't do that again.If you have Java on in your browser and you aren't already 100% certain you need it, turn it off.Don't stay logged in to services like Twitter when you aren't actively using them. That makes it less likely that your session will be hijacked. It also means you won't forget you're logged in and click/like/post/approve something you didn't really intend to.

The above precautions would have protected you proactively, even if you were one of the users whose data was spilled by Twitter.

Longer, complex passwords are harder to crack from their hashes; regular logouts mean your session cookies are valid for shorter periods.

Further reading: Questions and answers about the Twitter hack.

Follow @duckblog


View the original article here

Friday, February 8, 2013

Man who hacked Scarlett Johansson's email gets a whopping ten years in prison

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The crook who cracked into the email of numerous celebrities, including Scarlett Johansson and Mila Kunis, has been sent to prison.

A federal judge in Los Angeles, California, sentenced 36-year-old Christopher Chaney, of Florida, USA, yesterday.

Although Chaney had already pleaded guilty, thus sparing the expense and complexity of a trial, and although the prosecution had apparently asked for a sentence of just under six years, Judge Otero hit Chaney with a mammoth ten year stretch.

One report suggests Chaney drew an over-the-odds sentence because he continued his cracking activities even after he knew he was under investigation and his computer had been seized.

As we wrote earlier this year, Chaney's modus operandi seems to have been to use the 'forgot password' feature on his victim's email accounts.

He'd then use publicly accessible information - the sort of stuff many of us share in bits and pieces on social networking sites - to answer his victims' security questions and finish off the password reset.

Having got hold of the new passwords and illegally accessed the accounts, Chaney would activate the 'forward a copy of incoming mail' option. This means he could continue to harvest his victims' private emails, even if they changed their passwords back.

Chaney stole nude photos, lurid text messages and emails. Many of these were then shared with two online celebrity gossip sites.

Interestingly, although Chaney drew a harsh penalty, we haven't heard of anything happening to the gossip sites that willingly went public with the stolen material.

The story might have been different had the gossip-mag journalists been in Australia.

Sydney-based journalist Ben Grubb, for example, was briefly arrested in Queensland, Australia, in 2011, and had his iPad confiscated, after he published a supposedly private Facebook photograph that he had acquired from a security researcher.

The researcher had apparently got hold of the photo - a privacy-protected picture of a rival's wife - as a "proof of concept" for a conference talk about a security flaw in Facebook's privacy system.

The researcher couldn't resist sharing the photo with Grubb, who couldn't resist publishing it online (albeit blurred).

Ben Grubb in hot water

In the end, Grubb wasn't charged, quickly got his iPad back, and was vindicated - at least in the public's eyes - by strong criticism of his arrest.

But Queensland police obviously felt strongly enough to go after Grubb under a Queensland law dating back to 1889, which dispassionately observes that "a person who receives tainted property, and has reason to believe it is tainted property, commits a crime."

And there are two important lessons in that:

• Don't put tainted property online, especially if it affects the privacy of others.

It's easy to say, "But the information's out there now, so the crime of getting it in the first place is already done."

Have some concern and respect for the privacy of others. The way data breaches seem to be going, you may very well need the same sort of concern and respect in return some time soon.

• Review all your account settings if you think you've been hacked.

After a malware attack, an unexpected password change, or anything else which suggests that someone else has been riffling around in your digital stuff, be sure to check your configuration settings.

Be on the alert for changes which might let the crooks carry on their dirty work even after your initial cleanup.

Crooks can add new accounts to your PC, set email forwarding options (like Chaney did), change firewall settings, install remote access software, and much more. If you are unsure what to look for, ask someone you know and trust for help.

Follow @duckblog

Image of hands courtesy of Shutterstock.


View the original article here

Tuesday, January 8, 2013

Hacked Go Daddy sites infecting users with ransomware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Go DaddyUsers are getting infected with ransomware thanks to criminals managing to hack the DNS records of Go Daddy hosted websites.

That's not welcome news for the world's largest domain name registrar.

To understand how these attacks work, a short primer on DNS is required.

In a nutshell, DNS provides a system where computers on a network (the internet) can be referenced by a user-friendly name. These names are known as hostnames, and DNS translates them into what is known as an IP address.

A key feature of DNS is that changes can be made and applied very rapidly, allowing resources to be moved between machines/networks/locations without affecting end users. The hostnames remain constant, and DNS handles any changes in the IP address as the resources move.

In this current spate of attacks, criminals are exploiting DNS by hacking the DNS records of sites, adding one or more additional subdomains with corresponding DNS entries (A records) referencing malicious IP addresses. The legitimate hostname resolves to the legitimate IP address, but the added sub-domains resolve to rogue servers.

This enables the attackers to use legitimate-looking URLs in their attacks, which can help to evade security filtering and trick users into thinking the content must be safe.

In some cases, users have had several subdomains added, pointing to one or more malicious IP addresses.

owner.[redacted].com
move.[redacted].com
mouth.[redacted].com
much.[redacted].com
muscle.[redacted].info
music.[redacted].mobi

The rogue servers are running an exploit kit calling itself 'Cool EK'.

As noted last week, this is actually very similar to Blackhole exploit kit.

The Russian origin of the kit is evident from the login page for the admin panel.

Users hitting the malicious site are hit with various malicious files, exploiting several vulnerabilities, in order to infect them with ransomware.

snake.[redacted].info/r/l/certainly-devices.php (exploit landing page, Mal/ExpJS-AV)snake.[redacted].info/r/32size_font.eot (CVE-2011-3402, Troj/DexFont-A)snake.[redacted].info/r/media/file.jar (Mal/JavaGen-E)snake.[redacted].info/r/f.php?k=1&e=0&f=0 (ransomware payload, Troj/Ransom-KM)

Once running, the ransomware displays the familiar payment page, with contents that vary based on the country of the victim.

Here is a British example, which uses the name of the Police Central E-Crime Unit:

And here is the type of lock page you would see if you lived in, say, Bulgaria:

Note the use of an animated GIF in this lock page to mimic the video from the user's webcam! This sort of attention to detail is what helps convince many users that the warning is legitimate.

At the time of writing, an important question remains to be answered. How were the attackers able to hack these Go Daddy DNS records?

One likely cause is compromised user credentials (stolen or weak passwords). To help confirm this I suggested one of the affected webmasters check his historical login activity. Sadly, this does not seem to be readily possible for users. Furthermore, the response from Go Daddy offers no help as well.

Thank you for contacting Online Support regarding your account. Please note we have security devices and protocols in place to protect our network and infrastructure. As stated previously, we can not release information regarding account logins or activity. If you feel that someone has logged into your account, you best defense is to change your password. Please see our previous response for instructions on how to do this.

Sigh. Enabling users to view historical login activity is a very simple way of helping to spot malicious activity early. Let's hope Go Daddy change their stance on this.

Go DaddyGiven the prevalence of attacks against web sites for the purpose of malware distribution it is high time that associated services (Registrars, hosting providers etc) pay adequate consideration to security.

Users should not be allowed to use weak passwords. Two-factor authentication should be readily available, if not enforced.

With a little forethought and consideration to what happens when the keys to the kingdom get lost, malicious activity can be disrupted more quickly.

Go Daddy customers who wish to check they have not been affected by these attacks should check their DNS configuration according to the Go Daddy support page.

Aside from contacting some of the affected webmasters, we have contacted Go Daddy to alert them to these attacks.

Thanks to the webmasters who responded to my notifications about these attacks, whose input was very helpful in putting together the content for this post.

-- Update: November 26th, 2012 --

We have received a statement from Go Daddy concerning these attacks, a copy of which is included below:

Go Daddy has detected a very small number of accounts have malicious DNS entries placed on their domain names. We have been identifying affected customers and reversing the malicious entries as we find them. Also, we're expiring the passwords of affected customers so the threat actors cannot continue to use the accounts to spread malware.

We suspect that the affected customers have been phished or their home machines have been affected by Cool Exploit as we have confirmed that this is not a vulnerability in the My Account or DNS management systems.

Go Daddy highly recommends that US- and Canada-based customers enable 2-Step Authentication to help protect their accounts. Details on how to set up this feature are located at http://support.godaddy.com/help/article/7502/enabling-twostep-authentication.

If a customer suspects their account may have an issue, we encourage them to contact Go Daddy Customer Care or fill out the form at the following link: https://support.godaddy.com/support/?section=support.

It is good news that out initial suspicions are confirmed - compromised user credentials are responsible for these hacks. Thanks to Go Daddy for their quick response confirming this to be the case. We would encourage all CA and US users to enable 2-factor authentication. Users elsewhere should ensure their passwords are strong and unique to Go Daddy.

Follow @SophosLabs

View the original article here