Google Search

Tuesday, July 16, 2013

Anatomy of an exploit - Linksys router remote password change hole

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A security researcher from San Jose in California has published a how-to guide detailing a number of vulnerabilities in various Linksys routers.

Phil Purviance, who goes by the handle of SUPER.EVR (EVR stands for Exploitation Vulnerability Research), reported the holes privately on 05 March 2013:

Hello Cisco PSIRT, I would like to report several vulnerabilities in Linksys network equipment. A public advisory regarding these issues may be released 30 days after sending this report.

And Purviance certainly lived up to his threat, publicly releasing the gory details on 05 April 2013 on his blog.

I don't want to get sidetracked into a discussion about the disclosure process here - whether 30 days was long enough, whether it was fair to expect a reply after emailing Cisco, which no longer owns the Linksys brand, or whether explicitly documenting the holes was wise.

You'll have to make your own mind up on those issues, because the purpose of this article to zoom in on one of the holes to see what we can learn from it.

The vulnerability we'll be looking at is:

Linksys EA2700 Password Change Insufficient Authentication and CSRF Vulnerability

Imagine that you are trying to penetrate a network inside a building that is monitored by security guards, offers no remote computer access, and is surrounded by an electric fence and motion detectors.

You're not going to get inside, but now imagine yourself holding up a placard outside one of the office windows saying, "Kindly enable remote login on port 5128 and change the password to b4nana," and waiting a while.

Imagine if it worked!

That's a simile for one of the bugs that Purviance found.

It gets the tag CSRF, for Cross Site Request Forgery, because it lets you embed, in an external web page (that's the placard outside the window), a URL that refers to a configuration script that will run on your router (that's the list of instructions on the placard).

So the Cross Site Request isn't a demand from an angry web server, but rather a web page that deliberately takes you to site B via site A.

In this case, visiting an otherwise innocent-looking external site can cause your browser to initiate internal actions on your router.

And if the router assumes that you are authorised simply on the basis that you are issuing the request from inside the network, an external attacker can easily use you as his "inside proxy" to violate security.

The unprotected configuration page found by Purviance permitted just the sort of silent reconfiguration jokingly shown on our placard: enabling external router admin (something you should never be tempted to do by choice), changing the password, and more.

So much for the metaphorical electric fence, the security guards and the motion detectors.

Of course, for this attack to work, the criminal needs to know what internal URL to embed in his external web page, which means he needs to know the internal name or IP number of your router:

That's so that when your browser processes the dodgy URL, the malicious reconfiguration request goes to the right web page on the right router, and produces the right HTTP request, as in the example above.

In Purviance's example, as above, he chose 192.168.1.1, which is a good guess for many networks.

? Private IP address ranges for your home or business network run from 10.0.0.0 to 10.255.255.255, from 172.16.0.0 to 172.31.255.255, and from 192.168.0.0 to 192.168.255.255. Advocates of security through obscurity suggest choosing randomly from the available private spaces, and as long as you don't rely on this as a security measure in its own right, you might as well do just that.

By the way, the problem of internal command-and-control URLs embedded into external websites (the Cross Site Request part) is why many web services require you to enter your password again to authorise key operations, even if you are already logged in.

That not only does prevents curious (or malevolent) colleagues from making long-term changes to your configuration if you inadvertently leave your screen unlocked, but also makes attempted alterations caused by CSRF more obvious.

Requiring re-authentication not only makes the CSRF fail, but also draws your attention to the attempt because an unexpected password dialog pops up.

So, the lessons to learn from this bug are:

Don't gripe at websites that ask for your credentials again when performing configuration or security-related tasks. The inconvenience is a small price to pay for the additional safety.Keep your eye open for firmware updates for your routers and other network hardware. Security patches don't just apply to desktop operating systems and applications.When writing web services that are worth password-protecting, don't just protect access to the URL of the relevant starting page. Make sure that the individual URLs that accept and process commands (whether by GET or POST requests) are all authenticated, too.Logout from web services when you aren't using them. Don't needlessly leave yourself in the position that accidental or unexpected clicks can have unintended side-effects.

? Yes, the last point above includes logging out routinely from Facebook, Twitter and your webmail, too. It's much more convenient to stay logged in all day, but much less safe, and very much less secure.

As for closing this hole if you have a Linksys EA2700 router, Dan Goodin of Ars Technica reports that:

A statement issued by officials from Belkin, which recently acquired the Linksys brand, said the vulnerabilities documented by Purviance had been fixed in the Linksys Smart Wi-Fi Firmware that was released in June.

And according to Linksys, the June 2012 firmware release was itself superseded in July, October and November last year:

Purviance didn't make it clear, in his vulnerability disclosure, which firmware version he used during his research.

But if you aren't on the latest firmware version, you probably ought to grab it anyway.

After all, this isn't the first time we've written about vulnerabilities in, and the external misuse of, SoHo routers.

And if you're really keen, you can use the hacking-by-numbers tool Metasploit to do a penetration test against your own router, as exploit modules for Purviance's holes are already available online.

Follow @duckblog


View the original article here

Sunday, July 14, 2013

Hacker "Kayla" admits attacks on Sony, Murdoch, Nintendo

By Estelle Shirbon

LONDON (Reuters) - A British computer hacker pleaded guilty on Tuesday to cyber attacks on targets including Sony, Nintendo, Rupert Murdoch's News International and the Arizona State Police.

Ryan Ackroyd's plea meant his planned jury trial did not go ahead and, as a result, the court did not hear any evidence on the motivation behind the attacks he made using the persona of a 16-year-old girl named Kayla as part of hacking group LulzSec.

Dressed in a tracksuit bottom and t-shirt, with a large tattoo on his arm and crew-cut hair, Ackroyd spoke only to identify himself and to enter his plea.

Ackroyd, 26, was arrested in 2011 with three other British young men in connection with an international cyber crime spree by LulzSec, a splinter group of hacking collective Anonymous.

The other three had already pleaded guilty to several charges including cyber attacks on the CIA and Britain's Serious Organised Crime Agency (SOCA).

Anonymous, and LulzSec in particular, made international headlines in late 2010 when they launched what they called the "first cyber war" in retaliation for attempts to shut down the WikiLeaks website.

Ackroyd faced four charges but pleaded guilty to just one. Prosecutors said they would not pursue the other charges.

Ackroyd and his three fellow hackers will be sentenced on May 14, judge Deborah Taylor said.

Mustafa Al-Bassam, 18, and Jake Davis, 20, had both pleaded guilty to two counts while Ryan Cleary, 21, had pleaded guilty to six counts including that he attacked Pentagon computers operated by the U.S. Air Force.

Cleary, Al-Bassam and Davis admitted to launching so-called distributed denial of service (DDoS) attacks in which websites are flooded with traffic to make them crash.

Ackroyd denied taking part in DDoS attacks but admitted, as did the three others, to hacking into computer systems, obtaining confidential data and redirecting legitimate website visitors to sites hosted by the hackers.

The targets listed in the charge to which Ackroyd pleaded guilty also included Britain's National Health Service, the U.S. public broadcaster PBS and 20th Century Fox.

The defendants are free on bail pending their sentencing, under the condition that they do not access the Internet.

Cleary was indicted by a federal grand jury in Los Angeles last June but U.S. authorities have indicated they would not seek his extradition as he was being prosecuted in Britain on the same charges.

The name LulzSec is a combination of "lulz", another way of writing "lols" or "laugh out loud", and security.

(Editing by Louise Ireland)


View the original article here

Saturday, July 13, 2013

Hacking highlights dangers to Seoul of North's cyber-warriors

By Ju-min Park

SEOUL (Reuters) - A hacking attack that brought down three South Korean broadcasters and two major banks has been identified by most commentators as North Korea flexing its muscles as military tensions on the divided peninsula sky-rocket.

Officials in Seoul traced Wednesday's breach to a server in China, a country that has been used by North Korean hackers in the past. That reinforces the vulnerability of South Korea, the world's most wired economy, to unconventional warfare.

China's Foreign Ministry said that hacking attacks were a "global problem", anonymous and cross-border.

"Hackers often use the IP addresses of other countries to carry out their attacks," ministry spokesman Hong Lei told reporters.

One government official in Seoul directly blamed Pyongyang, although police and the country's computer crime agency said it would take months to firmly establish responsibility.

Jang Se-yul, a former North Korean soldier who went to a military college in Pyongyang to groom hackers and who defected to the South in 2008, estimates the North has some 3,000 troops, including 600 professional hackers, in its cyber-unit.

Jang's alma mater, the Mirim University, is now called the University of Automation. It was set up in the late 1980s to help North Korea's military automation and has a special class in professional hacking.

The North's professional "cyber-warriors" enjoy perks such as luxury apartments for their role in what Pyongyang has defined as a new front in its "war" against the South, Jang told Reuters.

"I don't think they will stop at a temporary malfunction. North Korea can easily bring down another country in a cyber-warfare attack," Jang said.

Like much about North Korea, its true cyber capabilities are hard to determine. The vast majority of North Koreans have no access to the Internet or own a computer, a policy the regime of Kim Jong-un strictly enforces to limit outside influence.

The nominee to be the next South Korean intelligence chief told MPs recently the North was suspected of being behind most of the 70,000 cyber-attacks on the country's public institutions over the past five years, local TV channel YTN reported.

North Korea recently threatened the United States with a nuclear attack and said it would bomb South Korea in response to what it says are "hostile" war games in the South by Washington and Seoul.

Threats to bomb the mainland United States are empty rhetoric as Pyongyang does not have the capacity to do so and its outdated armed forces would lose any all-out war with South Korea and Washington, military experts say.

That makes hacking an attractive, and cheaper, option.

"North Korea can't invest in fighter jets or warships, but they have put all their resources into raising hackers. Qualified talent matters to cyber warfare, not technology," said Lee Dong-hoon, an information security expert at Korea University in Seoul.

However much of North Korea's limited funds go into its nuclear and ballistic missile programs.

LIMITED ATTACK

Wednesday's attack hit the network servers of television broadcasters YTN, MBC and KBS as well as two major commercial banks, Shinhan Bank and NongHyup Bank. South Korea's military raised its alert levels in response.

About 32,000 computers at the organizations were affected, according to the South's state-run Korea Internet Security Agency, adding it would take up to five days to fully restore their functions.

It took the banks hours to restore banking services. Damage to the servers of the TV networks was believed to be more severe, although broadcasts were not affected.

South Korea's military, its core power infrastructure and ports and airports were unaffected.

Investigations of past hacking of South Korean organizations have led to Pyongyang.

"There can be many inferences based on the fact that the IP address is based in China," said the South Korean communication commission's head of network policy, Park Jae-moon. "We've left open all possibilities and are trying to identify the hackers."

North Korea has in the past targeted South Korea's conservative newspapers, banks and government institutions.

The biggest hacking effort attributed to Pyongyang was a 10-day denial of service attack in 2011 that antivirus firm McAfee, part of Intel Corp, dubbed "Ten Days of Rain". It said that attack was a bid to probe the South's computer defenses in the event of a real conflict.

However, the hacking attack on Wednesday doesn't appear to be state sponsored, security vendor Sophos said, noting the malicious software it detected was not sophisticated.

"It's hard to jump to the immediate conclusion that this was necessarily evidence of a cyber-warfare attack coming from North Korea," said Graham Cluley, senior technology consultant at Sophos.

North Korea last week said it had been a victim of cyber-attacks, blaming the United States and threatening retaliation.

"North Korea is able to carry out much bigger attacks than this incident such as stopping broadcasts or erasing all financial data that could panic South Korea," Lee of Korea University said.

(Additional reporting by Jack Kim, Narae Kim, Hyunjoo Jin, Joyce Lee, Se Young Lee in Seoul and Ben Blanchard in Beijing; Editing by David Chance and Nick Macfie)


View the original article here

Friday, July 12, 2013

LulzSec: Hacker Admits Joining In Web Attacks

A 26-year-old has pleaded guilty to hacking websites of major institutions including the National Health Service, Sony and News International.

Ryan Ackroyd, from Mexborough, South Yorkshire, pleaded guilty to one charge of carrying out an unauthorised act to impair the operation of a computer, contrary to the Criminal Law Act 1977.

He had been due to stand trial charged with taking part in a string of cyber attacks but ended up admitting just the one charge.

Southwark Crown Court in London heard he admitted being a member of hacking group LulzSec.

As a member he acted as a "hacker" to access websites for Sony, 20th Century Fox, the NHS, Nintendo, the Arizona State Police, and News International between February and September 2011.

In July 2011 the Sun's website was hacked and users were briefly re-directed to a spoof page that falsely claiming that Rupert Murdoch had died.

Prosecutor Sandip Patel told the court: "He was the hacker, so to speak. They turned to him for his expertise as a hacker."

She said Ackroyd admitted using the persona of a 16-year-old girl Kayla on the site.

He will be sentenced on May 14 and the court heard prosecutors are not planning to pursue other charges against the 26-year-old.

Earlier today, Southwark Crown Court heard that fellow hackers Mustafa Al-Bassam, 18, from Peckham, south London, and Jake Davis, 20, from Lerwick, Shetland, have also now pleaded guilty to hacking.

The pair were also involved in launching cyber attacks on a range of organisations, including the CIA and the Serious Organised Crime Agency.

Ryan Cleary, 21, of Wickford Essex, has pleaded guilty to the same two charges as well as four separate charges including hacking into US air force agency computers at the Pentagon.

The men are said to have carried out distributed denial of service (DDoS) attacks on the institutions with other unidentified hackers belonging to online groups such as LulzSec, Anonymous and Internet Feds.

The DDoS attacks they carried out flood websites with traffic, making them crash and rendering them unavailable to users.

To do it, they used a remotely controlled network of "zombie" computers, known as a "botnet", capable of being programmed to perform the attack.

LulzSec is a spin-off of the loosely organised hacking collective Anonymous. Lulz is internet slang that can be interpreted as "laughs", "humour" or "amusement", and Sec refers to "security".


View the original article here

Wednesday, July 10, 2013

McCann Investigations Houston Computer Forensics Division Releases White Paper on Digital Intellectual Property Theft

McCann Investigations releases white paper which explores the complexities of digital intellectual property theft and methods by which a business can protect its data.

Houston, TX (PRWEB) April 11, 2013

McCann Investigations, a Texas-based computer forensics firm released a white paper titled Digital Intellectual Property Theft: Protecting your Organization. This paper explores the complexities of digital intellectual property. The sophistication of cyber assaults has increased at alarming rate allowing hackers to steal intellectual property from individuals and small companies, to large companies with a significant global presence.

In many cases, intellectual property theft occurs during a data breach which can often come from external sources such as hackers. But many times, intellectual property theft occurs when present for former employees (sometimes in collusion with one another) download or export proprietary company information such as engineering drawings, client lists or trade secrets. This is often done when those employees are seeking to create a competing company. In many intellectual property theft cases facilitated by employees, there is a component of non compete violations. Many companies have solid non compete agreements in place to prevent intellectual property theft and infringement issues.

“Intellectual property theft has become a big business for foreign countries looking to gain an edge in the global market.” Says Daniel Weiss, Managing Partner of McCann Investigations. “Smaller companies are more at risk given that they often do not have the resources as a larger company to secure their networks against such attacks.” Continued Weiss

McCann Investigations Houston Division specializes in several case types including fraud, embezzlement, theft, non compete enforcement, digital debugging, data breach incident response and complex family, civil and criminal.

About McCann Investigations

McCann Investigations is a Texas-based private investigations practice focused on comprehensive investigations incorporating digital forensics, surveillance, undercover work and backgrounds for clients in various case types. Case types include intellectual property theft, non compete enforcement, fraud, embezzlement and family law. McCann Investigators are experts in the latest computer forensics tools and are licensed with the state of Texas. McCann computer forensics examiners have provided expert testimony and reporting in hundreds of cases across the state.

Through digital investigations, McCann also delivers digital debugging and data breach and incident response services.    In cases where there is suspected external or internal hacking with the installation of malware of spyware or when data and privacy loss has occurred due to network breach, McCann investigations computer forensics and IT security experts use cutting-edge tools to document, evaluate and respond to the incident. McCann works with clients to analyze their IT networks and put protocols in place to secure the network.

McCann Investigations utilizes multiple tools in their comprehensive investigations including digital investigations, digital debugging, corporate investigations, litigation support, IT security audit and oversight, complex family, civil and criminal.

http://www.mccanninvestigations.com


Facebook: http://www.facebook.com/McCannInvestigations


Twitter: @mccanngi

Malisa Vincenti
McCann Investigations
800-713-7670
Email Information


View the original article here

Tuesday, July 9, 2013

Major computer crash in SKorea; hackers suspected

SEOUL, South Korea (AP) — Computer networks at major South Korean banks and top TV broadcasters crashed en masse Wednesday, paralyzing bank machines across the country and prompting speculation of a cyberattack by North Korea.

Screens went blank at 2 p.m. (0500 GMT), with reports of skulls popping up on some computer screens, the state-run Korea Information Security Agency said — a strong indication that hackers planted a malicious code in South Korean systems. Some computers came back online more than 2 ½ hours later.

Police and South Korean officials couldn't immediately determine the cause. But experts said a cyberattack orchestrated by Pyongyang was likely to blame. The rivals have exchanged threats following U.N. sanctions meant to punish North Korea over its nuclear test last month.

The shutdown appeared to be more of an inconvenience than a source of panic. There were no immediate reports that bank customers' records were compromised. It also didn't affect government agencies or networks essential to the country's infrastructure, such as power plants or transportation systems.

Still, it raised worries about the overall vulnerability to attacks in South Korea, a world leader in broadband speed and mobile Internet access. Previous hacking attacks at private companies compromised millions of people's personal data. Past malware attacks also disabled access to government agency websites and destroyed files in personal computers.

The shutdown comes amid rising rhetoric and threats of attack from Pyongyang in response to U.N. punishment for its December rocket launch and February nuclear test. Washington also expanded sanctions against North Korea this month in a bid to cripple the regime's ability to develop its nuclear program.

North Korea has threatened revenge for the sanctions and for ongoing routine U.S.-South Korean military drills it considers rehearsals for invasion.

Seoul believes North Korea runs an Internet warfare unit aimed at hacking U.S. and South Korean government and military networks to gather information and disrupt service.

Seoul blames North Korean hackers for several cyberattacks in recent years. Pyongyang has either denied or ignored those charges. Hackers operating from IP addresses in China have also faced blame.

The latest network paralysis took place just days after North Korea accused South Korea and the U.S. of staging a cyberattack that shut down its websites for two days last week. Loxley Pacific, the Thailand-based Internet service provider, confirmed the outage but did not say what caused the shutdown in North Korea.

Shinhan Bank, a major South Korean lender, reported a two-hour system shutdown Wednesday, including online banking and automated teller machines. It said networks later came back online, and that banking was back to normal at branches and online. Shinhan said no customer records or accounts were compromised.

The other bank, Nonghyup, also a major lender, said its system eventually came back online. Officials didn't answer a call seeking details on the safety of customer records.

Jeju Bank said some of its branches also reported network shutdowns.

At one Starbucks in downtown Seoul, customers were asked to pay for their coffee in cash, and lines were forming outside disabled bank machines. Seoul is a largely cashless city, with many people relying on debit and credit cards to pay for goods and services.

Broadcasters KBS and MBC said their computers went down at 2 p.m., but officials said the shutdown did not affect daily TV broadcasts. Computers were still down more than three hours after the shutdown began, the news outlets said.

The YTN cable news channel also said the company's internal computer network was completely paralyzed. Footage showed workers staring at blank computer screens.

KBS employees said they watched helplessly as files stored on their computers began disappearing as the computer went into shutdown mode.

"It's got to be a hacking attack," Lim Jong-in, dean of Korea University's Graduate School of Information Security. "Such simultaneous shutdowns cannot be caused by technical glitches."

The South Korean military raised its cyberattack readiness level but saw no signs of cyberattacks on its networks, the Defense Ministry said.

No government computers were affected, officials said. President Park Geun-hye called for quick efforts to get systems back online, according to her spokeswoman, Kim Haing.

In 2011, computer security software maker McAfee Inc. said North Korea or its sympathizers likely were responsible for a cyberattack against South Korean government and banking websites earlier that year.

The analysis also said North Korea appeared to be linked to a 2009 massive computer-based attack that brought down U.S. government Internet sites.

Pyongyang denied involvement.

But the accusations from both sides show that the warfare between the foes has expanded into cyberspace.

Last week, North Korea's official Korean Central News Agency accused South Korea and the U.S. of expanding an aggressive stance against Pyongyang into cyberspace with "intensive and persistent virus attacks."

South Korea denied the allegation and the U.S. military declined to comment.

Lim said hackers in China were likely culprits in the outage in Pyongyang.

But signs Wednesday pointed to North Korea, he said.

"Hackers attack media companies usually because of a political desire to cause confusion in society," he said. "Political attacks on South Korea come from North Koreans."

Last week, North Korea's Committee for the Peaceful Reunification of Korea warned South Korea's "reptile media" that the country was prepared to wage a "sophisticated strike" on the country.

Orchestrating the mass shutdown of the networks of major companies would take at least one to six months of planning and coordination, said Kwon Seok-chul, chief executive officer of Seoul-based cyber security firm Cuvepia Inc.

The company that provides network services for the companies that suffered outages said it did not spot signs of a cyberattack on its networks, said Lee Jung-hwan, a spokesman for LG Uplus Corp.

Lim said tracking the source of the outage would take months.

___

Associated Press writers Sam Kim and Foster Klug contributed to this report.


View the original article here

When is a password not a password? When Excel sees "VelvetSweatshop" [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Boobytrapped Excel fileOver the last few months, I've spent a significant proportion of my time researching the CVE-2012-0158 vulnerability.

I'm glad to say that that research has paid off, and I will be presenting a technical paper at the Virus Bulletin conference in Berlin, later this year.

The paper, "Between an RTF and OLE2 place: an analysis of CVE-2012-0158 samples", will be a summary of my research so far into the threat.

One of the issues in detecting CVE-2012-0158 samples is that the delivery mechanism can be RTF, Word or Excel files.

Word and Excel files can be password-encrypted, meaning that it can be harder for an anti-virus scanning engine to see the malicious code.

The problem the attackers have, of course, is that they not only have to trick users into clicking on the attachment with social engineering, but also need to dupe their potential victims into entering a password.

With Excel, however, there is another method and that is to save the boobytrapped file as "Read Only".

"Read Only" applies the same encryption method and uses a default password chosen by the Microsoft programmers: "VelvetSweatshop".

Here is a short video showing how malware can use this default Excel password in its attempt to infect unsuspecting computer users.

(Enjoy this video? Check out more on the SophosLabs YouTube channel.)

If you would like to know more about the CVE-2012-0158 vulnerability then I urge you to attend the Virus Bulletin conference later this year. While you are there you can also listen to and meet other experts from Sophos:

My SophosLabs colleagues Numaan Huq and Peter Szabo also have a reserve paper at the conference: "Trapping unknown malware in a context web".

A strong showing for the SophosLabs experts at this year's Virus Bulletin conference, I'm sure you will agree. We look forward to meeting many of you in Berlin.

Follow @SophosLabs
Follow @NakedSecurity


View the original article here