Google Search

Tuesday, April 9, 2013

Mega's bug bounty program - one week down, "a few billion billion years" to go

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mega, the cloud storage service brought to you by larger-than-life New Zealand digeratus Kim Dotcom, has released the first feedback on its bug bounty program.

Mega, in case you missed it, is a recent reincarnation of the controversial Kiwi file-sharing service Megaupload.

Megaupload imploded a year ago when Dotcom was arrested in New Zealand to face extradition to the USA on serious criminal charges, including racketeering (organised criminality) and money laundering.

The background to the charges was the allegedly vast amount of pirated material hosted on the Megaupload site.

On the anniversary of the big fella's arrest (in case you haven't come across Dotcom before, he's said to have the impressive vital statistics of 200cm and 135kg - he's the silhouette on the left in the image above), Mega arose from the ashes of Megaupload.

This time the company aims to sidestep accusations that it's a front for piracy by using built-in cryptography so that it doesn't, and indeed cannot, know what you're uploading and downloading.

As we put it when Mega launched, "all it does is to store a giant pile of shredded cabbage on your behalf."

Cryptanalysts and cypherpunks soon took aim at some aspects of Mega's cryptography.

Critics came up with some interesting commentary about its design and implementation, such as:

Disapproving of the random number generation technique used when setting up your encryption keys.Questioning the cryptographic mechanism for generating confirmation links sent by email.Wondering how Mega could claim to offer a deduplication feature if it genuinely knew nothing about the content of your uploads.Lamenting that most of Mega's secure content servers used only 1024-bit public keys, currently considered the lowest rung of acceptability.

Mega soon fired its own verbal broadside back, declaring itself "not too impressed with the results."

The company was particularly scathing of the critique of its cheap-and-cheerful 1024-bit keys, pointing out that the 1024-bit-protected content was itself protected by a cryptographic checksum authenticated with 2048-bit security, so there.

That counterblast was followed a critique from hacking group fail0verflow, pointing out that Mega's programmers had got the implementation of the 2048-bit-protected checksum all wrong.

This time, Mega hit back with actions, not words, quickly adapting its own code to repair the mistakes, and rightly earning praise for the speed of its response.

Instead of concatenating all checksummed files and computing a single "combo-checksum", Mega began to publish separate checksums for each file.

Checksumming all files as if they were one is imprecise because you can alter the boundaries between the combined files without changing the checksum.

Subtle attacks might be possible by shifting JavaScript code out of one source file into another.

And instead of using a forgeable CBC-MAC checksum, it switched to SHA-256.

Shortly after that, Mega got onto the front foot and announced bug bounties that would pay "up to €10,000 per bug, depending on its complexity and impact potential."

It also published two outright challenges that are worth €10,000 each.

One requires you to to find the decryption key for a file on the site. (Decrypting the file is not enough. You have to recover the key, which is a somewhat stronger result.) The other requires you to recover the user's password from a confirmation email link.

Whatever you think of Mega, its founder, its raison d'etre, its bombasticity and even the value of the bounties its offering, it nevertheless reflects to the company's credit that it came out with the bounties at all.

And just a week after the bounties were announced, Mega has announced the first "interim results," as it calls them.

No mention of how much was paid to whom for exactly what, but no-one's pulled off a crown jewels crack yet (or Severity V and Severity VI in Mega's terminology: remote code execution or worse).

That's good news for Mega, though of course it's only a week into the bug bounty program.

Nevertheless, the company is as gung-ho as ever, needlessly mentioning that it is "needless to mention that nobody cracked any of the brute-force challenges yet (please check back in a few billion billion years)."

Let's hope the Megabloggers are right...

Follow @duckblog

Image of cabbage, including the shredded stuff, courtesy of Shutterstock.


View the original article here

Acai Berry fake news website operators fined millions of dollars by FTC

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Have you seen this online news report about the miraculous Acai Berry diet?

You may have seen it on a site like "News 6 News Alerts," "Health News Health Alerts," or "Health 5 Beat Health News".

Fake news website

Maybe you got to the webpage after clicking on a link shared by a friend on Twitter, who says they have lost a shed load of weight by following the diet?

Of course, the website is a fake (it's just pretending to be a legitimate news source) and your friend didn't tweet out that message - their account has been compromised by spammers.

Time and time again, spammers have compromised Twitter accounts, including those belonging to Hyatt Hotels and NHS Direct, exploiting them to spread fake endorsements of using colon cleansers and following an Acai Berry diet to lose weight.

Acai berry news spam

Sadly such scams have become so common that the Acai Berry "news" site has become very familiar to all of the experts at SophosLabs (clearly the spammers never felt the need to revamp the look-and-feel of their bogus media outlet).

Acai berry capsules, courtesy of ShutterstockThe good news is that the authorities are just as fed up as the rest of us with the illegal and deceptive practices of those hawking the diet pills.

The Federal Trade Commission has just announced that a company behind the bogus news websites has agreed to pay more than $1.6 million in settlements, permanently halting its operations.

Beony International, its owner Mario Milanovic, and employee Cody Adams, were each stung with a $13 million judgment. However, unless the FTC determines they lied about their finances, they may only have to pay over $1.6 million and sell a 2008 Porsche to settle with the authorities.

This is the latest settlement in the FTC's action against Acai Berry scammers, including a $2 million penalty leveled against a Florida-based affiliate advertising network last year.

Don't make life profitable for spammers and scammers. If you see an unsolicited spam message - don't try, don't buy, don't reply.

Follow @gcluley

Acai berry capsules, courtesy of Shutterstock


View the original article here

Sunday, April 7, 2013

Ex-President Bush doxed - family photos, personal email, bathtub portraiture leaked

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

George H W Bush George H W Bush

A hacker using the alias "Guccifer" has claimed responsibility for hacking the Bushes, aka the political family that gave the US its 41st president (George H.W. Bush) and its 43rd president (George W. Bush).

In email exchanges with The Smoking Gun, the hacker indicated last week that he (the male gender having been indicated by The Smoking Gun's coverage) had breached at least six email accounts, including:

The AOL account of Dorothy Bush Koch, daughter of George H.W. Bush and sister of George W. Bush;Willard Heminway, 79, an old friend of the 41st president; CBS sportscaster Jim Nantz, a longtime Bush family friend; former first lady Barbara Bush’s brother; and George H.W. Bush’s sister-in-law.

The Smoking Gun reports that the hacker claims to have stolen and published private material, including "interesting mails" about George H.W. Bush's recent hospitalization, "Bush 43," and other Bush family members.

The doxed material allegedly contains a confidential October 2012 list of home addresses, cell phone numbers, and emails for dozens of Bush family members, including both former presidents, their siblings, and their children.

Intimate details were stolen, including a four-digit code needed to enter a Bush home security gate, as well as correspondence about the need to write a eulogy for the elder Bush, who was hospitalized and assumed to be on his death bed at the time.

Bush emails

Photos of George W.'s self-portraits were also published.

If you can't live without having experienced the 43rd president's knobby knees sticking out of a bathtub or ex-presidential lathering in a steamy shower, the internet can now ease your need. No worries, the paintings are safe for work.

Guccifer also posted private photos of the Bush family, which The Smoking Gun republished.

The hacker told The Smoking Gun that "The feds" began investigating him a "long time ago," and that he has hacked "hundreds of accounts."

He also downplayed the FBI/Secret Service investigation that's sure to come, saying:

"I have an old game with the f**king bastards inside, this is just another chapter in the game."

What hubris, to pick on innocent people in the execution of a "game".

Regardless of whether you approve of the political agenda of the Bush dynasty, you've got to feel sorry for those whose personal correspondence, photos and artwork gets pulled into the glaring light of the public eye just to satisfy some guy's ego.

The takeaway: take care of what you send electronically. We're all fair game to be picked on by bullies like Guccifer.

If you don't want to see your words and images held up for public scrutiny and ridicule, think twice before you hit send.

By the way, the Bushes are far from the first Republican politicans to have suffered at the hands of hackers. Perhaps most memorably, Sarah Palin had her private Yahoo email account broken into when she was campaigning to be vice-president. On that occasion, the hacker ended up with a prison sentence.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Sarah Ferguson, Hugh Grant and Doctor Who win substantial damages after having their phones hacked

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Sarah Ferguson. Image from ShutterstockA court in London has heard that Sarah Ferguson, the former wife of Prince Andrew, is one of more than 100 people who have received significant payouts in the wake of the News of the World phone hacking scandal.

Sarah Ferguson, the former Duchess of York, demanded a public apology from the newspaper's publisher News Corporation, after reportedly having had her phone's voicemail intercepted since 2000 to feed the tabloid's appetite for juicy gossip.

Others who have received damages include Hugh Grant, former Doctor Who Christopher Eccleston and spoon-bender Uri Geller according to The Guardian.

The story of the British media's penchant for phone hacking dominated Britain's news headlines during 2011 and 2012, and has resulted in both criminal investigations and a government inquiry.

With such a high profile given to the issue, there's really no reason for anyone to have poorly-protected voicemail anymore. But in case you are still in doubt, here's our guide on how phone hacking worked, and how to make sure you're not a victim.

The story isn't over yet, of course, with ongoing police investigations into not just the interception of mobile phone voicemail systems but also the hacking of public figures' computers and email accounts using spyware Trojan horses.

Follow @gcluley

Sarah Ferguson image from Shutterstock.

Tags: Christopher Eccleston, Doctor Who, Hugh Grant, News Corporation, News of The World, NOTW, phone hacking, Royalty, Rupert Murdoch, Sarah Ferguson, Uri Geller


View the original article here

Saturday, April 6, 2013

Pope Benedict XVI to resign - Twitter sex spammers exploit breaking news story

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Pope Benedict XVI Pope Benedict XVI

Within seconds of the news breaking that Pope Benedict XVI was to resign, spam began to appear on Twitter taking advantage of the story.

Messages using the hashtag #pope - but with no connection whatsoever with the developing news story of the first Papal resignation for hundreds of years - have sprung up on the social network.

Most of the messsages are being posted from accounts which feature images of young women in a state of undress (rather than a state of distress, which is what you would devout expect Catholic followers of @Pontifex to be feeling right now).

Papal spam

What is happening here is what we see every day on Twitter - whether there is a Papal resignation or not.

Spammers scoop up the hottest trending topics on Twitter and use the popular phrases to sprinkle amongst their tweets - in the hope that social media users who are following a particular meme or subject will click on their link rather than a legitimate one.

Chances are that the accounts themselves are not being run by someone sat in their bikini at a keyboard, but actually automated bots under the control of a spammer who may have hundreds or thousands of bogus accounts at his beck and call.

Here are some other examples:

More pope spam

These are hardly the most sophisticated examples of spam in the world, and at the moment appear to primarily be designed to make money through affiliate links. But it's easy to imagine how cybercriminals can exploit interest in hot breaking news stories like this in order to drive traffic to poisoned webpages infected with malware or phishing sites.

We have already seen some of the links redirecting to webpages which claim to host adult videos:

Adult video image

If you see an account which is obviously sending spam messages, report it to Twitter so they can shut it down. The site's security team has an ongoing battle against spammers, but it's a game of whack-a-mole. Everytime they zap a bogus account, the bad guys can create umpteen more.

Be careful out there.

http://twitter.com/gcluley

Pope image from Shutterstock.


View the original article here

Friday, April 5, 2013

Microsoft readies monster-sized security patch for Windows users

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Mud golem. Image from ShutterstockPatch Tuesday is approaching, and for users of Microsoft's software it's going to be a monster.

In all, 57 separate security flaws are waiting to be fixed.

Perhaps the biggest concern will be related to the security holes in Internet Explorer.

According to Microsoft, every single version of Internet Explorer - from version 6 to version 10 - needs to be patched, as they are vulnerable to exploitation by drive-by attacks.

That means that simply visiting a boobytrapped webpage could silently infect your computer with malware - hijacking your PC for a hacker's own ends.

According to an advisory from the software giant, five of the 12 security updates have been given Microsoft's highest severity rating of "critical".

The worry will be, of course, that malicious hackers will examine the patches released by Microsoft and attempt to release exploit code to take advantage of vulnerable computers shortly afterwards.

The longer you take to update the security patches on your computer, the greater potential risk you could find yourself in.

Of course, the worry is even worse for corporations - many of whom are reluctant to automatically roll-out Microsoft security patches until they are confident that they don't cause conflicts that could increase calls to the internal support department.

So, if you are responsible for the security of your computer - do try to install the patches promptly.

If you work at a firm where there is a team who look after the computers on your behalf, buy them a cup of coffee and show a little more consideration next time you ring up to say that the laser printer has run out of toner again - it can't be much fun to have to deal with the multitude of security patches that come out every month.

Microsoft's security patches, alongside more detailed information, are due to be released at 1:00pm EST on Tuesday 12th February. Aside from Internet Explorer, other affected software dealt with by the patch includes Microsoft Windows, Server Software, Office, and .NET Framework.

Follow @gcluley

Mud golem image from Shutterstock.


View the original article here

Thursday, April 4, 2013

VMWare security hole - it sounds like you need the patch, even if it's not clear why

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

VMWare just announced a patch for a security hole in its virtual machine software.

The hyper-sized virtualisation company wasn't terribly clear about just how much risk the flaw exposes you to, or quite how badly you might get owned as a result.

So the best bet is probably to patch now and ask the questions later.

The bug was announced in VMSA-2013-0002, VMWare's most recent security advisory. It says simply:

VMware ESX, Workstation, Fusion, and View address a vulnerability in the VMCI.SYS driver which could result in a privilege escalation on Windows-based hosts and on Windows-based Guest Operating Systems.

As you probably know, virtualisation is a mechanism that allows one computer to pretend to be many.

Mainframes have been doing this for about half a century; on commodity hardware, turning one computer into several pseudoservers has only been practicable for about the past decade.

There are many benefits, mostly to do with scalability and flexibility.

It's much easier to add one more guest virtual machine (VM) onto an existing virtual machine server, known as the host, than it is to install and commission a brand new physical server.

? Starting a new VM, which these days can be as easy as clicking a mouse button, is still referred to in IT jargon by the quaint and anachronistic name of "standing up" a server.

Similarly, you don't face an economic dilemma when you want to stand down a virtual server.

The other VMs, known as guests in IT-speak, each just run a bit faster. You don't end up with a rack-unit of idle hardware and a financial controller making tut-tut noises.

Of course, there are some significant risks in virtualisation, too.

One of them is that your guests are no longer actually separate, as they were when each server was, if this doesn't sound too obvious, a separate server.

Indeed, the guests and the host are usually interconnected by means of a control interface, without which managing multiple guests on a single host would be tricky.

So, you have to assume, or at least to hope, that the control interface doesn't allow for greater interaction between guest and host, or guest and guest, than it ought to.

In VMWare, that interface is VMCI, the Virtual Machine Control Interface.

To quote further from VMSA-2013-0002:

VMware ESX, Workstation, Fusion, and View contain a vulnerability in the handling of control code in VMCI.SYS. A local malicious user may exploit this vulnerability to manipulate the memory allocation through the Virtual Machine Communication Interface (VMCI) code. This could result in a privilege escalation on Windows-based hosts and on Windows-based Guest Operating Systems.

You'll have to ask VMWare exactly what this means, but it certainly sounds as though a user at one end of the host-to-guest control channel can do stuff they aren't supposed to on the other end of the control channel, if the other end is running Windows (and thus the buggy VMCI.SYS driver).

In short, it sounds as though a user inside a guest VM might find himself able to do unauthorised stuff on the host operating system, and perhaps even in other guests.

That's always going to be a security nightmare, not least in a server hosting environment where the guests are outsiders from a range of different companies, and the service provider is relying on VMWare to keep the guests apart, at least from a security point of view.

Likewise, if you have a Windows guest server hosted in a virtual server farm, an unprivileged user at your hosting provider might be able to fiddle around inside your guest operating system. And that probably isn't the level of security you want.

As I said, VMWare has been a bit cagey (if you will pardon the hosted server farm pun) about exactly what this vulnerability means to its users.

So-called local privilege escalations are often of low concern because they require an attacker already to be logged on to the computer.

But if local in this case merely means "running in a guest VM on the host hardware", then such local users must be considered implicitly remote.

Unless and until a clearer explanation of the risks emerges, then, I'd suggest that you "just do it."

Grab the patch and apply it...

Follow @duckblog

Image of server rack courtesy of Shutterstock.


View the original article here