Google Search

Saturday, April 27, 2013

Talking Angela iPhone app scare spreads on Facebook

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Talking Angela iPhone appA bogus warning is spreading across Facebook, telling parents of young children to watch out for a rogue iPhone/iPad app that (the warning claims) steals children's names, details of where they go to school, and even takes secret pictures of their faces.

The chain letter warning about the "Talking Angela" iOS app is being unwittingly spread by Facebook users, presumably with the thinking of "better safe than sorry" rather than "maybe I should just check the facts before forwarding this scare onto my friends".

The truth is that "Talking Angela" appears to be entirely benign, and there are no obvious privacy concerns that differentiate it from thousands of other iPhone apps.

Indeed, the "Talking Angela" app is no different from other similar popular children's apps from reputable iOS developer Out Fit 7 Ltd, including "Talking Tom Cat", "Talking Ben the Dog" and "Talking Gina the Giraffe".

Here's what a typical warning looks like when it is spread on Facebook:

Talking Angela warning

WARNING FOR TO ALL PARENTS WITH CHILDREN THAT HAVE ANY ELECTRONIC DEVICES , EX : IPOD,TABLETS ETC .... THERE IS A SITE CALLED TALKING ANGELA , THIS SITE ASKS KIDS QUESTIONS LIKE : THERE NAMES , WHERE THEY GO TO SCHOOL AND ALSO TAKE PICTURES OF THEIR FACES BY PUSHING A HEART ON THE BOTTOM LEFT CORNER WITHOUT ANY NOTICES . PLEASE CHECK YOUR CHILDREN'S IPODS AND ALL TO MAKE SURE THEY DO NOT HAVE THIS APP !!! PLEASE PASS THIS MESSAGE ON TO YOUR FRIENDS AND FAMILY MEMBERS THAT HAVE KIDS !!!!

The inference from the all-caps warning is clearly that "Talking Angela" is somehow a risk to children.

However, whoever started this scare has got their facts in a muddle.

Talking AngelaFor one thing, "Talking Angela" is an iOS app - not a website (although there is an optional Facebook component).

Also, the app's purpose is to wait until the child says something and then mimic what they say back to them (albeit in a Parisian feline fashion) rather than to pilfer details of where they go to school.

None of this, of course, is to say that you shouldn't be careful about what smartphone apps you install, and which Facebook applications you grant access to your social networking profile.

Furthermore, it's always a good idea to keep a close eye on what children are doing on the internet - in case they get themselves into a spot of bother.

But the warning spreading across Facebook appears to be nothing more than a scare - setting the cat amongst the pigeons unnecessarily.

Keep your wits about you and stay informed about the latest scams, hoaxes and malware attacks spreading fast across Facebook. Join the Naked Security from Sophos Facebook page, where more than 200,000 people regularly share information on the latest security issues.

Follow @gcluley

View the original article here

Thursday, April 25, 2013

China blamed for EADS and ThyssenKrupp hack attacks

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Two more major organisations have gone public about, what they claim, were attempts by Chinese hackers to infiltrate their networks and steal sensitive information.

EADS, the European Aeronautic Defense and Space company, and steelmaker ThyssenKrupp are said to have become the targets of hack attacks originating in China, according to Der Spiegel.

EADS - who makes the Eurofighter jet, as well as spy drones, surveillance satellites, and even rockets for French nuclear weapons - are said to have contacted the German government last year to warn them that the military contractor's computer network has been hacked.

Eurofighter

Officially, EADS have described the attack as "standard" and insisted that no harm has been done.

However, the attacks is against a backdrop created over the last few years of of other hacks against the defence industry including the likes of Lockheed Martin, L-3 Communications and Northrop Grumman.

And, of course, it's only 18 months since the then US Deputy Defense Secretary William Lynn claimed that a foreign intelligence agency was behind a hack attack that stole classified information about a top secret weapons system.

Meanwhile, ThyssenKrupp has also said to have confirmed that it was attacked by hackers - adding the detail that the attack occurred in the United States, and appeared to originate from a Chinese internet address.

According to Der Spiegel, the attacks against ThyssenKrupp were described as "massive" and of "a special quality", and the company was not sure of what (if any) information had been stolen by the hackers.

It is becoming increasingly clear that organisations need to defend themselves not only from the day-to-day financial-orientated cybercrime attacks which can impact anyone with a computer, but also from sophisticated targeted attacks that may be designed to spy and surreptitiously steal information.

BlueprintThe truth is that these hacking stories aren't really describing a technological problem. They're describing a human problem. It's remarkably easy to dupe someone into clicking on a link or opening an attachment in an email, and for their computer to become compromised.

You can reduce the chances of a targeted attack working by keeping your software (such as your PDF reader, your web browser, your word processor, as well as your operating system) up-to-date with the latest patches.

Furthermore, you should run a layered defence - that means not just running up-to-date anti-virus software, but also firewalls, email filtering technologies, vulnerability assessment, using DLP (data loss protection) technology and strong encryption to secure your most sensitive data.

Also, it's amazing how many people re-use passwords, and use the same weak password in multiple places. That means if you get hacked in one place, and your password is compromised, it may also unlock accounts elsewhere on the net. It's shocking how many people don't use different passwords for different places.

All of these methods can reduce your chances of suffering from a targeted attack.

But ultimately, there's no 100% technological solution as human beings can still make bad decisions. And that's why it's important to train users about threats, and warn them to be suspicious of unsolicited links and attachments and to always report suspicious activity.

Follow @gcluley

View the original article here

Tuesday, April 23, 2013

Microsoft admits it was also hit by hackers, malware infects their Mac business unit

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Late on Friday, Microsoft published a statement on its security blog revealing that it was joining the growing list of well-known companies who had suffered at the hands of hackers.

Microsoft says that a "small number of computers", including some in the company's Mac business unit, were infected by malware.

microsoft-statement

As reported by Facebook and Apple, Microsoft can confirm that we also recently experienced a similar security intrusion.

Consistent with our security response practices, we chose not to make a statement during the initial information gathering process. During our investigation, we found a small number of computers, including some in our Mac business unit, that were infected by malicious software using techniques similar to those documented by other organizations. We have no evidence of customer data being affected and our investigation is ongoing.

This type of cyberattack is no surprise to Microsoft and other companies that must grapple with determined and persistent adversaries (see our prior analysis of emerging threat trends). We continually re-evaluate our security posture and deploy additional people, processes, and technologies as necessary to help prevent future unauthorized access to our networks.

If Microsoft is right, and the attack is similar to those which impacted the likes of Facebook and Apple, then a key part of the attack was the exploitation of a Java browser plug-in vulnerability.

Simply visiting an infected webpage with a browser which had Java enabled would be enough to silently infect computers via a drive-by download.

If we have to say it once, twice or a thousand times - we'll keep on saying it:

Because if you don't, yours might be the next company having to make any uncomfortable announcement about a security breach.

Like Facebook before it, Microsoft chose to release the news on a Friday afternoon, west coast time.

microsoft-170Although some might view the timing of the disclosure cynically, and speculate that the bad news was released just before the weekend to limit its pick-up by the press, the good news is that Microsoft says it has found no evidence that any customer data was compromised as a consequence of the attack.

Let's not forget who the real villains are in this story - it's the criminal gangs who infected legitimate websites, and spread malware designed to steal information from unsuspecting computer users.

Knowing Microsoft, I am confident that they will be sharing information with the authorities and doing everything they can to ensure that the culprits are brough to justice.

If you haven't already done so, patch your computers and consider running anti-virus software on your Macs as well as your PCs. Clearly some of the bad guys are targeting Mac OS X, knowing that many "cool" developers prefer to write their software on shiny Apple hardware as well as dull beige PCs.

Sophos has a free Mac anti-virus for home users if you want to give it a whirl.

Follow @gcluley

Microsoft image from Shutterstock.


View the original article here

US soldiers and spies to get handheld biometric scanners

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Face being scanned. Image from ShutterstockUS soldiers and spies will soon be able to scan people's eyes, faces, thumbs and voices, at a distance, using everyday, commercially available smartphones - a boon for both the battlefield and for government snooping.

The biometrics company AOptix announced on Wednesday that the Pentagon has awarded it, along with CACI International Inc, a $3 million research contract to develop AOptix's Smart Mobile Identity devices for the US Department of Defense.

As Wired reported, the end result after two years of planned development will be a hardware peripheral and software suite that turns a regular smartphone into a device that scans and transmits data at distances not possible for current scanning technology.

AOptix's hardware is a peripheral that wraps around a smartphone, boosting the phone's sensing capabilities so that it can record biometric data.

Face scanning from mobile device. Image source: AOptix

Unlike the device currently used to scan, upload and transmit biometric data to the US military's wartime databases - the Handheld Interagency Identity Detection System (HIIDE) - the AOptix device can be operated single-handedly and will be as simple to use as a user-friendly smartphone application.

According to Wired, this new gadget will be able to scan faces at up to two meters away, irises from one meter, and voice from within a typical distance from a phone. Thumbprints will still require scanning against the phone's glass face.

AOptix executive Joey Pritikin told Wired that the system will be able to capture an iris in bright sunlight, which is a challenge for current biometric devices.

It will also be able to snap photos of a face or eye as soon as the phone focuses, without the need for the user to click, swipe or press.

It's easy to see the benefit of biometrics to troops. As early as the war in Iraq, fingerprint and iris scanners have been used to hire and maintain workforces, protect military bases and monitor inmates at detention centers.

For surveillance, biometrics has been more of a mixed bag.

As it is, the use of biometrics at borders is already threatening the security of undercover spies (and terrorists, or anybody traveling under assumed identity for any reason).

Wired reported in April that, pre-9/11, deep-undercover CIA operatives could use and toss false passports "like hand wipes," picking up new, fraudulent passports at local CIA stations.

Biometrics and linked databases are making that impossible, Wired reports, quoting an ex-spook who says that simply crossing the border with a real identity and then picking up a fake one in-country to conduct covert operations is presenting risks:

"When you go to check into a hotel room for a meeting with an asset, or even rent a car to drive to the meeting - or hold the meeting in the car - many hotels and car rental agencies upload their customer data, including passport number, to immigration every day... Most countries are looking for visa overstays. But when you show up on the list as never having entered the country... it brings the police around to ask questions."

Wired notes that, particularly in "hostile" places such as Iran, where the interior ministry's computers are assumably hard-wired into airline passenger lists and hotel guest lists, the use of false passport and travel data is a dangerous gambit.

Of course, "hostile" is a relative term. There are many who view the current state of über surveillance in the US, for example, as invasive, at best, and contemptuous of civil liberties, at worst.

It's understandable that government intelligence groups such as the CIA or the MI6 would be concerned for the safety of their deep-undercover agents.

AOptix hasn't identified which specific arms of US military or intelligence are gearing up to use the new biometrics scanners.

NSABut as normal Jane Doe citizens, particularly in these surveillance-happy post-9/11 days, it's a little scary to imagine ever-easier biometric scanning in the hands of outfits such as, say, the US's National Security Agency, which already has an insatiable hunger for data.

That's evidenced by the Utah Data Center, the vast facility the NSA is constructing to intercept, decipher, analyze, and store pretty much everything we do and everything we say, whether our communications are dragged up from undersea cables of international, foreign and domestic networks or pinched from the sky as relayed by satellite.

Do we really want US intelligence outfits to be able to identify us via biometrics, at a distance, and squirrel our movements away in their mind-bogglingly expansive data warehouses?

We have no choice in the matter, between the creation of hummingbird drones and the upcoming handheld scanners.

Let's just hope that more countries don't follow Canada's example and ban masks at protests.

Follow @LisaVaas
Follow @NakedSecurity

Facial scan image from Shutterstock. Image of man scanning other man's face from AOptix.


View the original article here

Monday, April 22, 2013

BlackBerry warns of TIFF vulnerability that could allow malware to run on enterprise servers

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Blackberry Enterprise ServerIf you are responsible for administering the BlackBerry phones used by staff at your company, there's some imporant security news.

According to a BlackBerry security advisory published last week, vulnerabilities exist that could allow remote hackers to run malicious code on the BlackBerry Enterprise Server (BES) software run by many firms.

The flaw, which has been rated as "high severity", involves how BlackBerry's enterprise software handles TIFF image files on webpages, in emails, and in instant messages.

According to BlackBerry's advisory:

Vulnerabilities exist in how the BlackBerry MDS Connection Service and the BlackBerry Messaging Agent process TIFF images for rendering on the BlackBerry smartphone.

Successful exploitation of any of these vulnerabilities might allow an attacker to gain access to and execute code on the BlackBerry Enterprise Server.

Depending on the privileges available to the configured BlackBerry Enterprise Server service account, the attacker might also be able to extend access to other non-segmented parts of the network.

In short, a malicious hacker could create a boobytrapped TIFF image file and either trick a BlackBerry smartphone user into visiting a webpage carrying the image, or embed the malicious image directly into an email or instant message.

According to BlackBerry, the BlackBerry Messaging Agent flaw does not even require a user to click on a link or view an email for the attack to succeed.

The risk is that by exploiting the flaw, hackers might be able to plant malicious code on your BlackBerry Enterprise Server that opens a backdoor for remote access.

Depending on how your network infrastructure is set up - intruders might be able to see into other parts of your network and steal information.

Alternatively, the hackers' code might cause your systems to crash - perhaps interrupting communications.

It's important to underline that these are not vulnerabilities in BlackBerry smartphones themselves. Like other BlackBerry-related vulnerabilities we've seen in the past, the potential attack is against the BlackBerry Enterprise Server used by businesses.

As more and more companies are waking up to the risk of targeted attacks with the apparent intention of stealing data and spying on activities, such a vulnerability is clearly a serious concern.

The good news is that BlackBerry has not received any reports of attacks targeting its enterprise customers, but obviously it is still a very good idea for affected customers to update their software as soon as possible. The company has published workarounds for those businesses who may not be able to quickly update their installation of Blackberry Enterprise Server.

Follow @gcluley

View the original article here

Sunday, April 21, 2013

Boy meets girl. Girl strips on webcam. Tells boy to do the same. Girl blackmails boy

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

# And when two lovers woo
They still say, "I love you."
On that you can rely
No matter what the future brings
As time goes by. #

The famous song Dooley Wilson sang in Casablanca may have got it wrong. For the age-old romantic story of "Boy meets girl" has surely become an awful lot more complicated now the internet has come along.

At least, that's what male computer users in Singapore are discovering.

We've warned readers before about some of the dangers involved in finding love online. Such as the true story of the Facebook blind date that turned into a supermarket robbery.

Now, people are being warned about another risk of finding love in the online world - webcam extortion.

Webcam extortion. Image from ShutterstockBut it's not the familiar headline of perverted hackers blackmailing young women into stripping in front of the camera.

This time the tables have turned, and it's *men* who are being victimised by *women*, in a peculiar twist on traditional webcam extortion.

Singapore's Police Force has warned of femme fatales befriending potential victims on sites such as Facebook and Tagged.com.

The women enter steamy webcam conversations with their prey, where they strip and encourage their male victim to do the same.

What the man doesn't realise, as he feverishly rips his clothes off and agrees to engage in various sexual acts in front of the camera, is that his female love interest is secretly recording everything that's going on.

The male victim is then blackmailed for money by the woman who threatens to circulate the compromising photographs and videos.

Ouch! That must put a dampener on the evening.

Here is a video of a Singapore TV programme which reconstructed just this kind of crime. (Warning: The acting is a bit cringeworthy)

The Singapore Police Force says it has seen a five-fold increase in the number of reported cases of such web extortion - over 50 in 2012, compared to 11 the previous year.

Here is a summary of their tips to avoid you becoming the next man to be duped in such a fashion:

Always be wary of strangers befriending you on social networks. If they're suddenly showing a romantic interest in you, ask yourself honestly if it's likely that they've selected you for online love out of the billions of other internet users.Never put yourself into a compromising position on your webcam. In short, keep your clothes on.. as you can't be sure if the person at the other end isn't making a video recording. At the same time, you shouldn't give away too much personal information to someone you don't really know.If anyone does ever attempt to extort money from you online, don't pay them. Contact the police instead. You may be embarrassed about the mess you have got yourself into, but the authorities are the right ones to investigate and (hopefully) bring the culprit to justice.

The threat doesn't just lie with webcam blackmail either. You can imagine how a man, believing he is being seduced online by a sexy woman, might be all too eager to click on a link she suggests or run a malicious program on his computer. Before he knows it, his computer could be under the control of a hacker.

Be careful out there, and keep your trousers on chaps.

Follow @gcluley

Webcam and female silhouette image from Shutterstock.


View the original article here

Friday, April 19, 2013

More Mac malware attacking minority groups in China

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft WordOver the last year, SophosLabs, has talked about attacks against minority groups in China that use old vulnerabilities in Microsoft Office, that already have patches available for them.

We have seen several attacks in the past.

Earlier this week, the folks at AlienVault saw another attack using the same vulnerability in Office products on Mac OS X, targeting the Uyghur people of East Turkestan.

The vulnerability, known as MS09-027, was patched by Microsoft back in June 2009, and allowed remote code execution in Microsoft Word.

That means simply opening a boobytrapped Word document on an unpatched computer could run malicious code on your Mac. While you are distracted, reading the contents of a Word file, malware is being invisibly and silently installed onto your computer.

Contents of Word document

Although many Mac users might clutch onto the hope that their operating system will ask for an administrator's username and password before installing any software, you won't see any such message pop-up with an attack like this as it is a userland Trojan and you will not be prompted for administrator credentials.

This is because neither the /tmp/ nor /$HOME/Library/LaunchAgents folders on Mac OS X require root privileges. Software applications can run in userland with no difficulties, and even open up network sockets to transfer data.

Word DOC code

Sophos products detect the malicious documents as Troj/DocOSXDr-B and the dropped malware as the Mac Trojan horse OSX/Agent-AADL.

OSX/Agent-AADL obviously went through some development during this campaign because we saw three distinct versions. The first was the most interesting:

Word DOC Trojan code

In later versions of the Trojan, the function and variable names were stripped out and the shell script filenames were further hidden/obfuscated.

Once again, Mac users need to remember to not be complacent about the security of their computers. Although there is much less malware for Mac than there is for Windows, that is going to be no compensation if you happen to be targeted by an attack like this.

Mac users, just like Windows users, need to pay attention to the latest security patches and ensure that their software is kept properly up-to-date.

If you're not already doing so, run anti-virus software on your Macs. If you're a home user, there really is no excuse at all as we offer a free anti-virus for Mac consumers.

Follow @SophosLabs

View the original article here