Google Search

Showing posts with label trick. Show all posts
Showing posts with label trick. Show all posts

Monday, November 18, 2013

Anatomy of a browser trick - you've heard of "clickjacking", now meet "keyjacking"...

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

An Italian security researcher has rediscovered a trick known as user interface redressing.

He's used the concept to detail some potentially risky behaviour in some versions of Internet Explorer on Windows 7 and 8.

As that's a fairly common combination, and because the trick is worth pondering for anyone who likes to be thoughtful about computer security, here's what Rosario Valotta came up with last week.

? If you've ever been confused by the term UI redress, you aren't alone. To keep it clear, imagine it written as UI re-dress. It means that you put a new layer of clothes over an interface object as a sneaky way of changing its appearance, not that you right the wrongs that were done to it (the usual sense of "redress" when written as an unhyphenated word).

You may remember clickjacking, where your cursor is placed over a clickable button, such as a Facebook Like, that is itself placed over an innocent-looking image.

Then the button is made transparent, so that the image "re-dresses" the button and you think you are clicking on the image.

Valotta's trick is keyjacking, which is like clickjacking but with the re-dressing done the other way around.

You initiate a download window, which, at least under Internet Explorer 8 on Windows 7, produces a Run|Save|Cancel dialog.

You cover up the dialog with a window that looks like a CAPTCHA with R as the first character you need to type in.

Then you remove focus from the foreground window so that if the user does innocently press R, it is fed into the underlying dialog, not into the fake CAPTCHA window.

In IE 8 on Windows 7, that tricks you into choosing the Run option, so the downloaded file is launched automatically, apparently with your official blessing.

? In clickjacking, you click on a button that is opaque to your mouse (so it accepts and processes your click), but transparent to your eyes. In keyjacking, you type a character into a window that is opaque to your eyes, but transparent to your keyboard (so it passes your keystroke through to a hidden window underneath).

Here's what is supposed to happen in Valotta's demo, starting with the launch page:

If you click the button to launch the demo, it opens a window containing an invisible IFRAME that's populated, using JavaScript, with an EXE file:

Pushing an EXE file into the IFRAME initiates a file download and causes a double popup, the first to denote the start of the download, and the second to ask you whether you'd like to Run, Save or Cancel:

But you can't see any of this, because the window responsible for the download is a pop-under window, re-dressed on top with a window that appears to be asking for input, but isn't:

(In the on-line demo, the field into which you are supposed to enter the CAPTCHA text is actually an animated GIF containing a flashing cursor, for added realism. The CAPTCHA in the demo starts with E, which stands for Esegui, the equivalent of Run on Valotta's Italian-language version of Windows.)

In theory, then, the CAPTCHA acts as a realistic and innocent-looking subterfuge that sneakily tricks you into signalling Run to a dialog you can't see.

In practice, in my tests using a default installation of IE 8 on Windows 7 Enterprise, IE automatically averted the danger by blocking the download with a yellow security bar:

To initiate the download, you have to click on the security bar in the offending window, select the Download File... option from the dropdown menu that appears, and only then click Run or type R:

Since the security bar is out of sight, there doesn't appear to be an easy way to trick you into following that sequence of steps.

And if you're a Firefox user, like me, the subterfuge is immediately obvious, at least with Valotta's demo.

The hidden window doesn't pop up underneath, and both the IFRAME border and the download dialog are clearly visible by default:

(The u are not character string visible in the background is partially-obscured text from the fake CAPTCHA window shown above.)

Valotta says the trick does work under IE 9 and 10 on Windows 7, and IE 10 on Windows 8, so his discussion is nevertheless worth studying, especially if you design web applications for a living.

[NB. Please see Valotta's comment below pointing out my error in an earlier version of this article. Apologies for the misunderstanding.]

It's a timely reminder, in today's web-based AJAX-heavy world, that what you see in your browser may not be precisely what you get, and that JavaScript's windows focus and transparency system are ripe for visual abuse.

Some of the things you can do for additional security include:

Turn on as much of your browser's real-time protection (e.g. popup blockers and protected mode) as you can tolerate in order to reduce the risk of unwanted browser windows.Use a web filtering product on your computer or as part of your network gateway in order to block access to suspicious URLs and files.Ensure that your on-access (real-time) virus scanner is turned on in order to stop dangerous downloads from launching, even if they are successfully downloaded.

Follow @duckblog

Image of laptop keyboard courtesy of Shutterstock.


View the original article here

Sunday, April 14, 2013

Unlock an iPhone without the passcode - harmless trick or computer crime?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A YouTube video showing you how to unlock an iPhone 5 without the passcode has racked up nearly 300,000 hits over the past two weeks.

There are some caveats, though:

You need physical access to the device.You need manual dexterity or a fair bit of practice.You only get access to some of the data.You have to make a phoney emergency call as part of the process.

I'm not going to repeat the instructions here.

I'll just say that they're reasonably arcane: you almost turn the phone off twice during the process, as well as actually placing an emergency call but cutting it off before it goes through.

For the last reason alone, I invite you never to pull this trick, even on your own phone "to see if it works".

Deliberately dialling the emergency services when you don't need to, or, indeed, when you know your intention is not to complete the call at all, is a pretty poor show.

I'm not sure what the regulations are in your country, but there's every possibility you could get in trouble with the authorities for that part of the trick alone.

In fact, it's not really a trick. It's a crime, even without the bogus emergency call.

Not, perhaps, a terribly serious crime. But mucking around with other people's computers is behaviour we ought to stamp out of our lives.

Interestingly, the last time we wrote about this sort thing was when an MP in the New South Wales parliament live-tweeted joke comments from a colleague's iPad while the latter was giving a speech.

I suggested a zero-tolerance policy, especially from members of a legislative assembly, who ought to be setting standards, not flouting them, but not everyone was so sure.

Commenters Josh and foo suggested otherwise:

? For the record, I would vigorously oppose any attempt to regulate whoopee cushions. Like Dr Sheldon Cooper of the Big Bang Theory, "I still maintain the whoopee cushion has comic validity."

The good news is that this unlock crime trick doesn't give full access to the phone, but apparently only to your contact list, voicemails and photos.

That's still a lot of important stuff, though.

Macworld reports that Apple told the magazine that it was "aware of this issue, and will deliver a fix in a future software update."

That beats Apple's usual tight-lipped (and still apparently official) policy.

For the protection of our customers, Apple does not disclose, discuss or confirm security issues
until a full investigation has occurred and any necessary patches or releases are available.

So, watch out for the update, watch out for your phone, and don't let this bug make you complacent about phone lock codes overall.

It's still worth having a decent password on your iPhone, to protect all the data this bug doesn't give a miscreant access to.

To help you choose wisely, here are the Top Ten iPhone passcodes not to use:

5683, by the way, spells out L-O-V-E.

In conclusion, let the arcane nature of this trick remind you that hackers, in both the good and bad sense of the word, aren't deterred by secrecy, obscurity or complexity.

Indeed, this trick is surely making you wonder, "How did they think of that?"

Bear that in mind if you are ever called upon to design, implement or enforce security software, policies or procedures.

Follow @duckblog

Image of mobile phone courtesy of Shutterstock.


View the original article here

Wednesday, November 7, 2012

Skype worm spreads, using LOL trick to infect unwary users

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SkypeSkype users are warned to be on their guard, regarding malicious instant messages that have been sent through the service, designed to infect Windows computers.

A malicious worm is taking advantage of the Skype API to spam out messages similar to the one below:

lol is this your new profile pic? http://goo.gl/[REDACTED]?img=[USERNAME]

Clicking on the suspicious links leads to the download of a ZIP files (variously called skype_06102012_image.zip or skype_08102012_image.zip) that contains executable files detected by Sophos anti-virus products as Troj/Agent-YCW or Troj/Agent-YDC.

The Trojan horse opens a backdoor, allowing a remote hacker to take control of infected PCs, communicating with a remote server via HTTP.

On execution the malware copies itself to

%PROFILE%\Application Data\Jqfsfb.exe

and sets the autostart entry as below:

entry_location = "HKCU\Software\Microsoft\Windows\CurrentVersion\Run"entry = "Jqfsfb"description = "Skype "publisher = "Skype Technologies S.A."image = "c:\documents and settings\support\application data\jqfsfb.exe"launch_string = "C:\Documents and Settings\support\Application Data\Jqfsfb.exe"

Before you know it, your computer has been recruited into a botnet (the malware is a variant of the Dorkbot worm) and could fall victim to a ransomware attack.

There have been many variants of the Dorkbot attack spotted over the least year or so, spreading via Facebook and Twitter. The threat can also spread via USB sticks, and various instant messaging protocols.

The danger is, of course, that Skype users may be less in the habit of being suspicious about links sent to them than, say, Facebook users.

Always remember to be suspicious of unsolicited out-of-character messages sent to you by your online friends.

You don't know that it was a friend who sent you the message, all you know is that it was their account which posted it to you... and who knows if it was compromised or not?

Follow @gcluley

Thanks to Anna and Julie at SophosLabs for their assistance with this article.


View the original article here