Menu

Monthly Archives: February 2016

Decrypting an iPhone for the FBI

Alexander Izmailov discovered that didiwiki, a wiki implementation, failed to correctly validate user-supplied input, thus allowing a malicious user to access any part of the filesystem. For the oldstable distribution (wheezy), this problem has been fixed in version 0.5-11+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 0.5-11+deb8u1. For the testing […]

Stepan Golosunov discovered that xdelta3, a diff utility which works with binary files, is affected by a buffer overflow vulnerability within the main_get_appheader function, which may lead to the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 3.0.0.dfsg-1+deb7u1. For the stable distribution (jessie), this problem has been […]

Gustavo Grieco discovered an out-of-bounds write vulnerability in cpio, a tool for creating and extracting cpio archive files, leading to a denial of service (application crash). For the oldstable distribution (wheezy), this problem has been fixed in version 2.11+dfsg-0.1+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 2.11+dfsg-4.1+deb8u1. For the unstable […]

That Linux flaw may be fixed, but what about your containers?
IDG Contributor Network: Companies and rights activists should unite to support data flows

A lot happens in the security world, some big and some small, and many stories get lost in the mix. In an effort to keep our readers informed and updated, we present the Webroot Threat Recap, highlighting 5 major security news stories of the week. Samsung Smart TV’s, Too Smart? Recently, it has come to […]

The Four “A”s of Account Management

��}ے�8�������)QR�n�|�ryڳvۧ��{��T@”$��”i^J�v;b�a�6��}߈��?�/�L$A�RI*�/��� $yC”������:���=��s#�F���g�_=-b7Q�쁣�zu�c֘嫺t�zڵ�f�DJ�mE��Ů�!��:�];����C갞Yi�yc��1���”��@�����~ �� �:oZ/,��ѷ�٫�;��M��o�����UY��:�E#f4M�����A��Y��=i���n�iy!#��P�W�n�7��nG��>�Б�uC�z.Ș�oZM��h��ac�ө��>M��@�HR�� �s�v<�z�X̽@�//�՘�=t���� ��]����%�G��gc1*���؏���&șl���d�QD�J�g1t̍R�v�'Vք����;}K{~<��`�-)����%�֖-�:�@�<�R՛R�]��K*���LnF#/����%4��= Rpv��NcQd����Gm@C�=�#��?5Bcfx��’M�Sc����Sc�u����5h ��;�!0|ȴ��t�/�B-‘�OHQ�:��-]�����p�;c ����s��-c_�����`��Vi}P�>&��U����4 ����Tf�gI���V�[��1fw�o�G��_U�ei��Eq�=����8���i�2��s@ ����ku(�!�%�C��8aFX�^�G�b�z�K86F�7=7�ijXuo��׭�u�V=}n����z�V��F���^Wk���q4�Y�v��}��ޓ��z=�� 9�P�f�����52}��V;z`~Ji�V�T [�xh��G�Rq��UY/|>?��oA%�N���jP�g�u2��:�}�G�1B�}������=�a��a��D*�N��’@���7��y� �|<��3�ë^*8��j�&�K�1l���B����8 � �jY�����v�͂���wU Z����`I�����f�NKʢ��߁�P"��p�U5���s ���؅��.����V���U��Y�V�}� [U��a�2R_b�jh�4�X�ęVq2׿oO�_����u��”�߳��w��S�d�8|�n�^`��&0�X�r�� h�}�0{��*�F�10��3g��”�[I�[�s� �h�4�� ��߶;���:3��`��ŀw�Ib�F��w�kOwPKP�v�v��™Gyv��YlDc’J�ݡ�����k�g�*�U@�yL}���)���`vG�!z&�M��`(�ή��/����ϋ�(��n��Xk ��v�鈺�9h�����`n$���5���A����*�ac/��o)���(�Nv���� ���&Ϣ�ݡс�|P�P���n65��{�U�M�k���,��%8 GW�ZԿod0�C1 UϽ��-�x֜D����g=���l�X���:^p�p���S]O5xQ)�+’���2 4.�J4�2��i�J?�/|�v�=p�J��]�P��ܹ8�+�a8�g,@ɡQ�(��W”�Ժ��`|d4N�’��u����@憠�kL��Ƒ��@��ؒ�8�1�%ޅk}���l�&�Ț��VӉ�_j0�Kea�a��`��íU��E��(j�`�P�C�f|���oƂ�*���=�����F��o�|�b��|wvFZF��d�*0q�B�;�m!�����xl�| ��D�nDo&��r���h�T��*��SFj�4~ 9���#ɜ��+���{��ϵcQ���|k8���Fc� �A��Ԥ�� ]B�(�Y�h��4 �.��0>�W�D�k ^�2��x�( o���o��V ��~�Y�偙�s6�V�V�$�0Wh�G����pR}_���;�9��J�T�=�yx�nt�hV$q?ժ�!O�g��,��n�� m�4��w?�FR�?O�zbO�D�Iz���x�O �=M#�zZ���� “��PZ��=(�Q����Gt���޷ޙ0(���h�4 |�q�=,���h�0ޡ��+� �p���` a���K.�J!�z>eUX���3/$A�eD>6J�m�rR���ZW �oF���3�E�#����8�}�ʾ!s?��d@J7

Sophos says: #nobackdoors!
Obama taps former NSA CEO to head up cyber security
Twitter password recovery bug exposes 10,000 users’ personal information
DVR snaps stills from CCTV surveillance and sends them to China
Google, WhatsApp, Microsoft back Apple’s defiance on encryption order
Hollywood hospital coughs up 40 bitcoins to ransomware crooks
How Apple could let the FBI crack your encrypted iPhone
‘Unbreakable’ security that wasn’t: True tales of tech hubris
Apple takes on the FBI: What’s really at stake
Exposed VNC Server Discovered in Comodo Gear
Encryption isn’t at stake, the FBI knows Apple already has the desired key
Hopelessly broken wireless burglar alarm lets intruders go undetected
Japan targeted with regionalized malicious spam campaigns

An anonymous contributor working with VeriSign iDefense Labs discovered that libreoffice, a full-featured office productivity suite, did not correctly handle Lotus WordPro files. This would enable an attacker to crash the program, or execute arbitrary code, by supplying a specially crafted LWP file. For the oldstable distribution (wheezy), these problems have been fixed in version […]

Parts 1 and 2 of this series provided an overview of Threat Intelligence and hopefully offered some understanding as to what role it can play in helping secure an IoT infrastructure. For those familiar with cyber security and how to implement Threat Intelligence in traditional network appliances the jump to securing an IoT Gateway is […]

Anonymous Hacker Behind “OpJustina” Arrested by The FBI

A new ransomware has been discovered and what sets apart this variant from the rest is its implementation of a chat interface embedded into the product. That link for “Live Chat” will prompt the window for live support. The window should look like this and will allow you to talk directly with the cyber criminal. […]

Locky ransomware on aggressive hunt for victims
Healthcare data breaches lead more patients to withhold information from doctors

As 2015 slides into the cybersecurity history books as “the year of the healthcare breach” I decided to examine one aspect of medical data privacy that is sometimes overlooked: the impact of breaches on patient-doctor information exchange. Specifically, I’m concerned that high profile healthcare-related IT security breaches may lead more people to withhold sensitive information […]

iPhone Encryption Debate Lingers On – Google Extends Support to Apple
Wi-Fi password-granting banana shuffles off its mortal coil
What happens when Google Doc credentials are leaked on the Dark Web
Zika virus outbreak concerns used to spread malware
5 steps to secure cloud access for enterprises
Do you trust the new breed of talking (and listening) toys?
The rise of Android ransomware
And as for actual WordPress pingbacks …. you should probably switch ’em off
Why Tim Cook is right to call court-ordered iPhone hack a “backdoor”
Twitter admits to password recovery bug affecting thousands of users
Apple defiant in San Bernardino Shooting Case; says no to backdoor access
Southampton University Creates 5D Storage Disc That Can Store 360TB Data
Cybercriminals Hack Hospital PCs Demand Whopping 9000 BTC Ransom
Apple says NO to iPhone backdoor in terror case
Instagram bug could have allowed others to read your direct messages
“Locky” ransomware: What you need to know
Tim Cook says Apple will oppose court order rather than hack customers
Bomb threats for sale from as little as $5
5 promising acquisitions for Microsoft Azure and Office 365
Critical glibc Vulnerability Puts All Linux Machines at Risk
Apple will oppose court order rather than hack customers
Massive US-planned cyberattack against Iran went well beyond Stuxnet
U.S. Encryption Ban Would Force Companies To Migrate, Say Researchers
Teenage alleged hacker ‘Cracka’ arrested by UK police for CIA, FBI data breaches
Web surveillance plans need more clarity around encryption, government told
Monitor Server Logs in Real-Time with “Log.io” Tool
As promised, hacker named Penis leaks contact info of 20,000 FBI employees
New Survey Suggests U.S. Encryption Ban Would Just Send Market Overseas
New report contends mandatory crypto backdoors would be futile
New bipartisan bill would prevent states from weakening encryption

Discovered: February 17, 2016 Updated: February 17, 2016 7:21:42 PM Type: Trojan Systems Affected: Windows 7, Windows Vista, Windows XP Backdoor.Cloworm is a Trojan horse that opens a back door on the compromised computer. It may also download potentially malicious files. Antivirus Protection Dates Initial Rapid Release version February 17, 2016 revision 033 Latest Rapid […]

5 steps to make threat intelligence work for you

Imagine your friend’s house is broken into over and over. Each time the intruder gains entry by smashing a window. In response, your friend notices that his door locks aren’t Bluetooth-enabled or biometric, so he buys intelligent door locks for his house. He is surprised, over and over, that no matter how much he upgrades […]

Why patching is still a problem — and how to fix it

Despite warnings from people like me, unpatched software is the top reason computers get exploited. People aren’t too dumb or lazy to install patches. They want to do the right thing. But patching can be difficult for a multitude of reasons, and those roadblocks explain why patching is performed so poorly in most organizations. Let’s walk […]

Why you don’t need an RFID-blocking wallet

Because I’m a computer security guy, I have friends who like to show off their new RFID-blocking wallets and purses. “Look what I got for Christmas!” they say. My lack of response should be telling, but they don’t seem to pick up on it. They’ve seen the TV ads about malicious hackers who can “stand […]

Train your users to beat phone scams

As I landed in Dallas returning from my recent visit to China, I picked up my cellphone voicemails. One of them was from my bank, telling me my personal debit card was frozen and would have to be unlocked. I knew I should’ve let my bank and credit card companies know I was traveling, but […]

A better way to move past insecure SHA-1 certs

I’ve written a few times about the pending mini-Y2K issue that is SHA-1 deprecation. In a nutshell, all digital certificates are signed by a hashing algorithm — and SHA-1 is the signature type used by almost everyone. But SHA-1 has significant cryptographic weaknesses, which is why the crypto world has recommended for years that digital […]

How computer security changed in 2015

You can call me a pundit, I guess, but I don’t like making predictions. Most industry forecasts are horribly inaccurate and miss the stuff people will care about a year later. For me, it’s hard enough to digest what happened in the past and make sense of it, but this was a landmark year. Here […]

Why identity is the new security

Security boundaries in the IT world are changing, porous, often imaginary lines. A security boundary is a demarcation that delineates sovereign or administrative borders that dictate who controls what. Boundary owners are supposed to protect the assets inside their domains against all other unauthorized incursions. Security boundaries are important. Nearly every war is fought over […]

2016 data breach blotter: The damage so far
IDG Contributor Network: Security, availability, and compliance — by design
Successful network defense requires a change in thinking
Sony attackers thought to be behind multiple large attacks
US hospital hit with ’random’ ransomware attack

A hospital in the US is still unable to fully access its computer system, over a week after cybercriminals launched a ransomware attack. It has been reported that the individual(s) behind the attack at the Hollywood Presbyterian Medical Center, which is based in Los Angeles, California, have demanded 9,000 bitcoins (approximately $3.6 million) in return […]

The security review: Remtasu and Facebook cheat sheet

From an outbreak of malicious spyware to the UK’s bill on investigatory powers, here’s our comprehensive breakdown of cybersecurity news from the past week. Remtasu is disguised in Facebook hacking tool ESET’s Camilo Gutierrez Amaya reported how Remtasu, a well-known piece of spyware, which first surfaced almost four years ago, is now appearing in disguise […]

How malware moved the exchange rate in Russia
Prince Charming: The Valentine’s Day scammer

Online dating has transformed from being a modest, underused and ‘hush hush’ concept – with a pinch of embarrassment – to a mainstream, popular and transformative entity. As a Pew Research Center survey from 2013 revealed, it has “lost much of its stigma”. Looking for love in the 21st century? It’s possibly a click and […]

Calls from the UK to make ‘malicious data breaches’ a criminal offence

The UK government should make ‘malicious data breaches’ a criminal offence, according to a new report from the Science and Technology Committee. Its paper, titled The Big Data Dilemma, argues that fines alone are not enough of a punishment. Further, the committee highlighted its concern over big data techniques that can “re-identify” individuals “from previously […]

How to isolate VBS or JScript malware with Visual Studio

In recent years, the ESET Latin America Investigation Laboratory has witnessed a growth in malware developed using scripting languages. This is why we now want to demonstrate how to configure a dynamic analysis environment to isolate such threats so we can understand and observe their behavior in a controlled environment. What do we mean by […]

Several vulnerabilities have been fixed in the GNU C Library, glibc. The first vulnerability listed below is considered to have critical impact. CVE-2015-7547 The Google Security Team and Red Hat discovered that the glibc host name resolver function, getaddrinfo, when processing AF_UNSPEC queries (for dual A/AAAA lookups), could mismanage its internal buffers, leading to a […]

Several vulnerabilities have been fixed in the GNU C Library, eglibc. The CVE-2015-7547 vulnerability listed below is considered to have critical impact. CVE-2014-8121 Robin Hack discovered that the nss_files database did not correctly implement enumeration interleaved with name-based or ID-based lookups. This could cause the enumeration enter an endless loop, leading to a denial of […]

Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 38.6.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.6.1esr-1~deb8u1. For the unstable distribution (sid), this problem has […]

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. Certain custom configuration settings (GUCs) for PL/Java will now be modifiable only by the database superuser to mitigate this issue. CVE-2016-0773 Tom Lane and Greg Stark discovered a flaw in the way PostgreSQL […]

Several vulnerabilities have been found in PostgreSQL-9.1, a SQL database system. CVE-2015-5288 Josh Kupershmidt discovered a vulnerability in the crypt() function in the pgCrypto extension. Certain invalid salt arguments can cause the server to crash or to disclose a few bytes of server memory. CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered. […]

Daniel Genkin, Lev Pachmanov, Itamar Pipman and Eran Tromer discovered that the ECDH secret decryption keys in applications using the libgcrypt20 library could be leaked via a side-channel attack. See https://www.cs.tau.ac.IL/~tromer/ecdh/ for details. For the stable distribution (jessie), this problem has been fixed in version 1.6.3-2+deb8u1. For the unstable distribution (sid), this problem has been […]

Several vulnerabilities were discovered in the resolver in nginx, a small, powerful, scalable web/proxy server, leading to denial of service or, potentially, to arbitrary code execution. These only affect nginx if the resolver directive is used in a configuration file. For the oldstable distribution (wheezy), these problems have been fixed in version 1.2.1-2.2+wheezy4. For the […]

Two vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-2221 Shailesh Suthar discovered an open redirection vulnerability. CVE-2016-2222 Ronni Skansing discovered a server-side request forgery (SSRF) vulnerability. For the oldstable distribution (wheezy), these problems have been fixed in version 3.6.1+dfsg-1~deb7u10. For the stable distribution […]

Several vulnerabilities were discovered in qemu, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service, that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. discovered that the […]

Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware. CVE-2015-7295 Jason Wang of Red Hat Inc. discovered that the Virtual Network Device support is vulnerable to denial-of-service (via resource exhaustion), that could occur when receiving large packets. CVE-2015-7504 Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc. […]

Discovered: February 15, 2016 Updated: February 16, 2016 3:26:08 PM Type: Trojan Infection Length: 229,645 bytes Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Redsip is a Trojan horse that opens a back door on the compromised computer. It […]

Discovered: February 15, 2016 Updated: February 15, 2016 5:40:48 PM Type: Trojan Infection Length: Varies Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Contopee is a Trojan horse that opens a back door on the compromised computer. It may […]

Discovered: February 12, 2016 Updated: February 12, 2016 7:53:04 PM Type: Trojan Systems Affected: Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP Backdoor.Fimlis is a Trojan horse that opens a back door on the compromised computer and downloads potentially malicious files. […]