Google Search

Saturday, September 8, 2012

Apple zombie malware 'NetWeird' rummages for browser and email passwords

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

When we write Naked Security articles about Mac malware, we often end up creating a bit of a stir. Usually that's not on account of the malware itself, but on account of us writing about it in the first place.

Here's how it goes down.

We write the article. The politically-sensitive Apple fanbuoys come out swinging, saying we only write about Apple malware because we're down on Cupertino.

The artistic fanbuoys (Apple users who are in a band, for example) chime in even more fiercely, saying Mac malware is a figment of everyone else's unimaginative delusion.

The geeky fanbuoys (the ones who know where bash is, and what it's for) come out firmly to remind us - utterly without any accuracy - that if it doesn't ask for the Admin password, it can't be malware.

And then the long-suffering but battle-hardened Windows users pop up and say, "Back in 1991, we felt the same way. It didn't end well." Those of a philosophical bent repeat, with sincerity and concern, the words of George Santayana. "Those who cannot remember the past are condemned to repeat it."

So, with a deep breath, here's some Mac malware news.

There's been a touch of fuss in the media about it, which is the first reason we thought that we ought to tell you about it; the second reason is that it has an engagingly curious name: NetWeird. (No, I don't know why, either.)

NetWeird is interesting primarily because it is uninteresting. It's not very well written; it's not very well tested; it's probably not going to catch you unawares (but watch out if you're in a band!); and so far as we can tell, it's not in the wild.

But someone has gone to the trouble of creating it and, according to our chums at French Mac anti-virus outfit Intego, is actually trying to sell it on the underground market for the ambitious price of $60.

And that makes it interesting: it seems that the crooks really are getting into the habit of churning out new Mac malware, not to show how clever they are, but merely to see if they can repeat the trick that's worked on Windows for years: making money out of next to nothing. Those who remember the past often choose to repeat it, especially if there's money to be made.

And now about the malware.

NetWeird installs itself into your home directory as an application bundle called WIFIADAPT.app.app. That makes it rather obvious.

It adds itself to your login items, presumably with the intention of loading up every time you reboot your Mac. But a bug means that it adds itself as a folder, not an application. All that happens when you log back in is that Finder pops up and displays your home directory.

NetWeird also calls home to a hosted server located in The Netherlands. This makes it a bot, or zombie.

Bots use an outbound connection to listen for command-and-control signals from a cybercrook known as a botmaster. This works because a TCP connection, once established, is fully bidirectional, so the client side can behave as a server, and vice versa.

The commands that the bot can process allow it to run arbitrary programs via the shell, monitor running processes, take screenshots, exfiltrate files, and to rummage through the password files of well-known third-party browsers and email clients Opera, Firefox, SeaMonkey and Thunderbird.

You're not likely to see this thing, but if you do, Sophos Anti-Virus will mop it up for you under the name OSX/NetWrdRC-A.

If you do get infected, deleting the above-mentioned application bundle and rebooting should get it off disk and out of memory.

And if you're running Mountain Lion in its default security settings, you won't be able to run it anyway, because it's not from the App Store and isn't digitally signed by an Apple-endorsed developer.

That's about all you need to know about it.

Follow @duckblog
-

Stirrer image courtesy of Shutterstock.

Tags: apples, bot, cupertino, Malware, netweird, netweirdrc, netwrd-a, OS X, osx, Trojan, zombie


View the original article here

Thursday, September 6, 2012

Google staffs up 'Red Team' to protect the world from its privacy lapses

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Privacy. Image from ShutterstockAfter agreeing earlier in the month to cough up a record $22.5 million in a settlement with the Federal Trade Commission for sneaking tracking cookies past Safari browsers' no-tracking controls, Google is creating a privacy "Red Team" to police its products' own privacy bugs and dangers.

The settlement is over Google's override of the cookie controls in Apple's Safari browser.

As the FTC explained, Google snuck around those controls by creating an invisible HTML form and then using JavaScript to pretend a user had submitted it.

Google thereby bypassed the browser's blocking of third-party cookies - i.e., those set by sites other than the ones a user originally visits.

The form was invisible and lacked either content or a Submit button, meaning the user could never have actually submitted it.

But Safari, duped into thinking the user had submitted a form, then allowed Google to place a DoubleClick cookie on the user's computer.

The FTC cried foul, charging Google with misrepresenting its use of tracking cookies and of breaking its privacy promises.

Now, Google's hiring a ninja - pardon me, make that a "back-end ninja" - to slap itself into privacy shape.

Specifically, a recently posted job listing advertises for a Data Privacy Engineer to join its team of privacy "back-end ninjas".

Google job advert

The task of the Google back-end ninja:

As a Data Privacy Engineer at Google you will help ensure that our products are designed to the highest standards and are operated in a manner that protects the privacy of our users. Specifically, you will work as member of our Privacy Red Team to independently identify, research, and help resolve potential privacy risks across all of our products, services, and business processes in place today.

Red teams are nothing new: the term refers to an independent group that serves to challenge an organization to keep it on its toes.

Penetration-testing is on Google's wish list, so the search empire is obviously planning to kick its own privacy tires.

The responsibilities are to:

Analyze software and services from a privacy perspective, ensuring they are in line with Google's stated privacy policies, practices, and the expectations of our users.

That sounds, actually, like whoever assumes the role will function as something of an ombudsman, watching out for the constituent interests of the user base.

Google to date hasn't done much to earn users' trust that even a large-ish fine will stop it from pulling egregious privacy shenanigans.

When Sophos's Paul Ducklin polled users, over 90% said that no, financial penalties are certainly not enough to make the online behemoths play ball on privacy.

Well, hiring a privacy red team certainly sounds like Google's on the road to improving a situation that led to its slipping ghost forms, cookies and ads past the blocks on users' browsers.

This time, let's hope Google's privacy promises aren't as empty as that Safari-bamboozling, empty HTML form.

Follow @LisaVaas

Privacy image from Shutterstock.

Tags: browsers, Data Privacy Engineer, DoubleClick, Federal Trade Commission, fine, ftc, Google, job listing, Red Team, Safari, settlement


View the original article here

Wednesday, September 5, 2012

Google announces Pwnium 2, raises prize money for Chrome hack to $2m

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

In March this year we wrote about Pwnium, Google's "hack the Chrome browser for money" competition run at the CanSecWest conference.

Two winners took home $60,000 each after crafting devious, multi-stage attacks against the Mountain View browser.

The competition is back, with Pwnium 2 set to take place at the 2012 Hack in the Box conference in Kuala Lumpur, Malaysia.

If you fancy a prize, you've got just under two months to get your exploit ducks in a row - not a terribly long time, if the complexity of the previous winning entries is anything to go by.

There are a few changes from March.

The prize money goes up from $1m to $2m - perhaps a bit of a media stunt by Google, since last time only 12% of the prize money was actually claimed.

The prize categories are adjusted from $20k-$40k-$60k for low-medium-full exploits to $40k-$50k-$60k. As Google explains:

[W]e've compressed the reward levels closer together for Pwnium 2. This is in response to feedback, and reflects that any local account compromise is very serious. We're happy to make the web safer by any means - even rewarding vulnerabilities outside of our immediate control.

The final prize change is that instead of presenting every winner with a Chromebook, Google will present the writer of the best exploit with the Acer laptop used as the standard test platform during the competition.

(That's doesn't seem like much of an endorsement for Google's Chromebook devices - dedicated netbook-type computers that aren't an awful lot more than a walled-off browser lashed to Google's cloud apps. Can't even give the jolly things away.)

What I've referred to as low, by the way, means an exploit that relies entirely on vulnerabilities outside Chrome itself; medium means that some non-Chrome bugs were combined with a Chrome flaw; and full means that only bugs in Chrome were exploited. You need to achieve what Google calls "Win7 local OS user account persistence" for your attack to qualify as an exploit.

Local OS means you're running as a regular application, so you've escaped the limitations of running inside the browser; persistence means you'll keep running even after the browser exits and the computer is rebooted; and user account means you don't need to get all the way to administrator privilege.

Loosely speaking, that means your exploit would be perfect for a drive-by malware attack that would leave the computer infected inconspicuously and indefinitely.

Your exploit, of course, needs to be what is known as zero-day - Chrome and the surrounding OS will be fully patched when the competition opens.

Note to Mac users. Malware with admin privilege can, indeed, do a lot more damage than user-level malware. But even malware running with regular user privileges can be perfectly harmful, on OS X as well as on Windows. The notion that "malware which doesn't prompt for the admin password isn't really malware" is still prevalent amongst Mac fans, and it's a myth. Software which runs as you has the power to do anything you could do yourself, including downloading and running yet more malware; reading and writing files; uploading data to web servers; posting to social networks; and emailing your very own ill-tempered letter of resignation to the Chairman of the Board.

Follow @duckblog
-


View the original article here

Tuesday, September 4, 2012

Parliamentarians in schoolboy prank set poor standards for electorate

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

MPs in the New South Wales Parliament couldn't resist perpetrating an online prank on one of their number earlier this week.

The victim of the prank was Andrew Gee MP, sitting member for Orange. Naked Security readers will remember Orange as the home of convicted Aussie hacker David Cecil, a.k.a. Evil, who clocked up a two-and-a-half year prison sentence earlier this year for offences relating to the unauthorised access to and modification of data.

Gee was up on his hind legs, orating to the House, when messages started coming from his Twitter account. He's deleted them now, but that hasn't expunged them from the record - the Sydney Morning Herald faithfully reported them on its light-hearted Friday back page, The Diary:

I'm talking about really good things now

So many memories being had

My shoes are shiny

Gee's iPad wasn't lost or stolen. It was lying in what I'm sure he imagined was supervised safety on the parliamentary furniture. He simply hadn't banked on the sort of "supervision" his party colleagues had in mind.

Tweets not yet eradicated by the embarrassed Mr Gee explain away his apparently magical Tweet-whilst-talking powers, laying the blame on Messrs Wollondilly and Drummoyne (those are the names of the seats, not the MPs!) and unnamed others.

Gee's boss, State Premier Barry O'Farrell, joined in online with a short but entirely pertinent Tweet to say:

@AndrewGeeMP & set your iPad lock

This, in turn, provoked the Member for Orange to observe:

But you wouldn't have thought you'd need to use it in such distinguished company.

A fair comment, perhaps.

In truth, though, you would (or at least should) have thought exactly that.

Computer security is no longer really suited to the idea of a trusted interior and a hostile exterior.

You should work on the assumption that bad things could happen at any time. Then take a defensive security posture to suit that assumption.

The Premier is right. Set your iPad lock. While you're about it, consider all the other security-oriented settings from which you and your users could benefit, and think about how to ensure that everyone is doing the right thing.

(Yes, that image to the right is a shameless plug for a Sophos product which helps you do just that :-)

And never mess with another guy's computer or mobile phone.

Wollondilly and Drummoyne, it seems, were careful not to put anything truly embarrassing or derogatory into Andrew Gee's mouth, with the result that little harm was done. But it would have been much better - and would have set much higher standards - if they'd resisted the temptation altogether.

I may sound like a bit of a wet blanket for saying that, but it's hard to take a position against hacking, cybercrime, identity theft and other serious online crimes if you're prepared to condone the unauthorised use of someone else's iPad simply because it suits your own sense of humour.

As it happens, Section 308D of the New South Wales Crimes Act of 1900 (as of 6 July 2012) specifies a penatly of up to ten year's imprisonment for Unauthorised modification of data with intent to cause impairment.

Gee's jesting chums may not quite have broken this law [*], but that doesn't matter.

They shouldn't have done what they did...and Gee shouldn't have made it easy for them.

Follow @duckblog
-

[*] Are you a lawyer? If so, why not leave us a comment letting us know how close you think these MP pranksters came to breaking the portentously-named Crimes Act of 1900?


View the original article here

Sunday, September 2, 2012

Facebook is finally deleting your 'deleted' photos

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Bin image courtesy of ShutterstockIt looks like the whole Facebook-not-deleting-your-photos-when-it-said-it-had saga might be coming to an end.

Back in February, we reported that the "Delete this photo" button wasn't actually deleting the photo from Facebook's content delivery networks, at least not for a long while anyway.

So despite the photo disappearing from your profile, if you plugged the image url straight into your browser you could still see it.

It's less shutting the door on the photo and more masking it with a beaded curtain.

Now the problem has been fixed, as Frederic Wolens from Facebook told Ars Technica:

As a result of work on our policies and infrastructure, we have instituted a 'max-age' of 30 days for our CDN links.

However, in some cases the content will expire on the CDN much more quickly.

I tried it myself and it instantly seemed to work:

Facebook photo deleted

This content is currently unavailable

The page you requested cannot be displayed at the moment. It may be temporarily unavailable, the link you clicked on may have expired, or you may not have permission to view this page.

This all sounds like good news. Although it's important to remember that if something has been ever posted on the internet, it's possible that someone could have grabbed it and posted it somewhere else.

So that nude photo of you riding a camel, carrying firecrackers in each hand and balancing a chair on your head might not have disappeared forever.

By the way, you can keep up to date on the latest changes to Facebook by liking the Sophos Naked Security Facebook page.

Follow @NakedSecurity

Bin image courtesy of Shutterstock


View the original article here

Saturday, September 1, 2012

Megaupload bad boy founder gets to see FBI's extradition evidence, says NZ judge

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Kim Dotcom - image from bgr.comMegaupload founder Kim Dotcom has been facing extradition to the US for serious charges, including racketeering and money laundering, related to his file-sharing service.

Today, he and his lawyers will be breathing a little easier as a New Zealand judge upheld the defence's request, ordering the FBI to show its hand, revealing the evidence to be used at Dotcom's extradition trial.

The Crown has so far refused access to the information, despite the defendant's arguments that it is needed to prepare for the extradition hearing.

So what do the FBI have to reveal? A fuller list is available at TorrentFreak, but it includes

information connected with covert operations related to the upload and download of files on the Megaupload siteevidence collected of alleged copyright infringementcommunications between the copyright holders and Megaupload regarding take-down notices.

Mr Dotcom vs the Feds has been a popcorn-munching drama since January this year, when the New Zealand-based Megaupload founder was arrested, found hiding in his $30 million mansion's panic room.

Kim DotcomThis police raid - where 18 luxury vehicles were seized, $11 million (NZ) in cash was secured from bank accounts, and 150TB (yes, Terabytes) of data was taken - was later considered illegal, reported Ars Technica.

The defendant and his posse are certainly not shy, retiring types. Some of high-end motors even sported some catch-me-if-you-can licence plates: GOOD, EVIL, MAFIA, HACKER, STONED, GOD and GUILTY.

If you are unfamiliar with the backstory, do check out other colourful anecdotes.

In the meantime, I suspect that the defence eagerly awaits the FBI paperwork, so they can roll up their sleeves and get to work on building a case. I wonder if it will be sent to them buried in a glut of unrelated information? Knowing what has happened so far with his story, it wouldn't surprise me.

Follow @caroletheriault

picture of Kim Dotcom courtesy of www.bgr.com


View the original article here

Steve Jobs calls home to Apple and catches an iPad thief!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Geolocation and related technologies that keep track of you and your devices have loomed large and Big Brotherishly in recent Naked Security coverage.

We've written about TrapWire, a surveillance system that makes use of real-time facial profiling to search databases of red-flagged individuals.

We've reported on the social networking overexuberance of Michael Dell's daughter Alexa, leading to her being suspended from Twitter for being too open with details of the family's activities and whereabouts on social networks.

And - having advised Alexa Dell to turn geolocation off, on the grounds that regular and precise updates of your whereabouts are a form of personally identifiable information - Naked Security has looked more closely into the risks of geolocation, as exemplified by WeKnowYourHouse, a website which aims to show everyone where you live based on your tweets.

Is there a good side to geolocation and on-line tracking?

Seems there is.

About a month ago, a down-on-his-luck burglar allegedly pinched goods to the value of $60,000 from the Silicon Valley house of Laurene Powell Jobs, widow of the late turtleneck afficionado and Apple co-founder, Steve.

The accused tea-leaf, a certain Mr McFarlin, apparently couldn't resist using one of the iPads he'd nicked to access his own iTunes account.

McFarlin obviously failed to notice the late Mr Jobs's driving licence in the wallet he trousered along with all the other loot - which was a costly oversight.

Of all the call home signals received by Apple's infrastructure, you'd want to bet that a beyond-the-grave WHOOP! WHOOP! STOLEN IPAD ALERT! report from a Jobsian device (and in this context, I mean Jobsian quite literally, not merely in a general economico-spiritual sense) would enjoy the same sort of special attention as "Friend Request from Elvis" and "Voicemail from Alexander Graham Bell."

And so it turned out.

The iPad's call home provided both identity and location for the most likely suspect, who was arrested and is now stuck in jail.

(McFarlin couldn't make the $500,000 bail. Not even with the contents of Steve Jobs's wallet - he was down to his last $1, apparently.)

Follow @duckblog
-

Geolocation "booooooop" image courtesy of Shutterstock.


View the original article here