listen more to learn more.

Tuesday, September 27, 2016

Apple Confirms Weakened Security in Local iOS 10 Backups

iOS 10 Allows for Brute Force Attacks of 6,000,000 Passwords Per Second to be Attempted on Local Backups

Apple admitted recently to an issue affecting the encryption strength for backups of devices on iOS 10 when backing up to iTunes on the Mac or PC and said a fix would be included in an upcoming update. 

Released mid-September, iOS 10 addressed a total of seven vulnerabilities, the most severe of which could be exploited by a man-in-the-middle (MitM) attacker to prevent a device from receiving updates. Because iOS 10 rendered some devices useless, Apple was quick to release iOS 10.0.1, which also included a new fix for one of the “Trident” security flaws patched last month.
The security weakness of local backups was discovered in iOS 10 backups by ElcomSoft, a company that specializes in password recovery tools. According to them, the bug introduced by Apple in iOS 10 makes local backups significantly more susceptible to brute-force attacks than those for previous operating system versions.  
According to ElcomSoft, they were able to recover passwords from iOS 10 backups at speeds several thousand times faster when compared to recovering from password-protected iOS 9 backups. The changes that Apple introduced in iOS 10 for offline (iTunes) backups appear to be the root cause of the problem.
ElcomSoft’s Oleg Afonin explains in a blog post that an alternative password verification mechanism was added to iOS 10 backups, but that it skips certain security checks, thus allowing for a brute-force attacker to try passwords 2,500 times faster than what the old mechanism would allow for. The attack, he says, was executed against a local backup on a machine powered by an Intel i5 processor.
ElcomSoft hasn’t provided specific details on the security vulnerability, but revealed that it has added an exploit for it to its Elcomsoft Phone Breaker 6.10. On the same machine, the company reveals, the tool could try only 2,400 passwords per second for iOS 9 backups, but iOS 10 allows for a total of 6,000,000 passwords per second to be attempted.
Only the password-protected local backups produced by iOS 10 devices allow an attacker to leverage this new vector. The old protection mechanism, Afonin notes, continues to be available for iOS 10 backups and delivers the same level of protection as it did for previous platform versions.
“All versions of iOS prior to iOS 10 used to use extremely robust protection. Chances of recovering a long, complex password were slim, and even then a high-end GPU would be needed to accelerate the recovery. As a result of our discovery, we can now break iOS 10 backup passwords much faster even without GPU acceleration,” Vladimir Katalov, ElcomSoft CEO, says.
Apple has already confirmed that the issue exists, and even told Forbes that it was considering a patch in an upcoming security update. The company revealed that the issue indeed affects the encryption strength for iOS 10 backups performed using iTunes on the Mac or PC, but underlined that iCloud backups are not affected by it.
The good news, of course, is that the attack can be performed only if the attacker can access or create a local iOS 10 backup to work with. Because the backup contains all of the content on the iOS device, including contacts, calls, messages, media files, and even passwords, a successful attack would result in full device compromise and even the compromise of other user accounts.
After security researchers discovered a series of zero-day iOS vulnerabilities leveraged in targeted attacks against human rights activists, journalists, and other persons of interest, Apple in early September released updates for Mac OS X and Safari too to address the same issues.

Monday, September 26, 2016

OpenSSL Patch for Low Severity Issue Creates Critical Flaw

A fix included in the OpenSSL updates released last week introduced a critical vulnerability that could potentially lead to arbitrary code execution, the OpenSSL Project warned on Monday.

OpenSSL versions 1.1.0a, 1.0.2i and 1.0.1u were released on September 22 to address more than a dozen security holes. One of the issues affecting OpenSSL 1.1.0 is a low severity denial-of-service (DoS) bug related to excessive allocation of memory in the tls_get_message_header() function.
The flaw, reported by Shi Lei of Qihoo 360 and identified as CVE-2016-6307, is considered “low severity” because it can only be exploited if certain conditions are met.
The OpenSSL Project rolled out a fix in version 1.1.0a, but Google Security Engineer Robert Swiecki soon discovered that the patch created a critical use-after-free vulnerability related to large message sizes.
“The patch applied to address CVE-2016-6307 resulted in an issue where if a message larger than approx 16k is received then the underlying buffer to store the incoming message is reallocated and moved. Unfortunately a dangling pointer to the old location is left which results in an attempt to write to the previously freed location,” the OpenSSL Project wrote in its advisory.
The critical flaw (CVE-2016-6309) can result in a crash, but it could also lead to arbitrary code execution. The problem has been addressed with the release of OpenSSL 1.1.0b.
OpenSSL developers also announced on Monday the release of version 1.0.2j, which patches a missing CRL sanity check issue affecting only version 1.0.2i (CVE-2016-7052).
The OpenSSL Project hopes that by quickly releasing a patch for the critical vulnerability, users will update their installations directly to the newest versions instead of the ones made available last week.
The most serious weakness fixed last week is CVE-2016-6304, which can be exploited for DoS attacks by sending an excessively large OCSP Status Request extension to the targeted server. Another interesting issue fixed last week, albeit a low severity one, is Sweet32, a recently disclosed attack method that can be leveraged to recover potentially sensitive data from a large volume of encrypted traffic.

Related Reading: Encrypted Network Traffic Comes at a Cost

UK Man Involved in 2012 Yahoo Hack Sentenced to Prison

The U.K. National Crime Agency (NCA) announced last week that one of the members of an international cybercrime group has been given a two-year jail sentence.

The individual, 23-year-old Nazariy Markuta from London, is believed to be a member of a hacker collective known as “D33Ds Company.” In 2012, the group leaked more than 450,000 email addresses and passwords from Yahoo’s Contributor Network.
The NCA has not named the affected company in its press release and instead referred to it as a “major Silicon Valley firm.”
An investigation conducted by the British law enforcement agency in collaboration with the FBI led to the identification of Markuta, who is believed to be a key member of D33Ds Company.
The man was arrested at his home in North-West London in March 2015. At the time of his arrest, agents discovered thousands of payment card records in his possession. Investigators determined that, between 2012 and 2014, he leveraged SQL injection vulnerabilities to also breach the systems of a video game reseller and an SMS messaging service.
Markuta had pleaded guilty to eight counts related to hacking and fraud – crimes covered by the Serious Crime Act 2007, the Computer Misuse Act 1990 and the Fraud Act 2006. He has been sentenced to a total of more than 11 years, but he will only spend up to two years in prison since it’s a concurrent sentence.
The fact that one of the individuals who hacked its systems back in 2012 has been sentenced to prison is likely of little comfort to Yahoo these days. Two other data breaches suffered by the company have come to light over the past weeks, shortly after Verizon agreed to buy its core business for $4.8 billion.
In early August, a hacker offered to sell the credentials of 200 million users allegedly stolen from Yahoo back in 2012. Then, last week, Yahoo admitted suffering a massive data breach in 2014, when attackers believed to be sponsored by a nation state accessed information associated with at least 500 million user accounts.
It’s still unclear who is behind the 2014 attack, but experts have speculated that it could be Russia, China or even North Korea.

Related Reading: Celebrity Email Hacker Sentenced to 6 Months in Prison

Related Reading: Romanian Hacker "Guccifer" Sentenced to Prison in US

Related Reading: Kosovo Hacker Linked to IS Group Gets 20 Years in U.S. Prison

Smartphone hacks 3-D printer by measuring 'leaked' energy and acoustic waves

The ubiquity of smartphones and their sophisticated gadgetry make them an ideal tool to steal sensitive data from 3-D printers.

That's according to a new University at Buffalo study that explores security vulnerabilities of 3-D printing, also called additive manufacturing, which analysts say will become a multibillion-dollar industry employed to build everything from rocket engines to heart valves.
"Many companies are betting on 3-D printing to revolutionize their businesses, but there are still security unknowns associated with these machines that leave intellectual property vulnerable," said Wenyao Xu, PhD, assistant professor in UB's Department of Computer Science and Engineering, and the study's lead author.
Xu and collaborators will present the research, "My Smartphone Knows What You Print: Exploring Smartphone-based Side-channel Attacks Against 3D Printers," at the Association for Computing Machinery's 23rd annual Conference on Computer and Communications Security in October in Austria.
Not a cyberattack
Unlike most security hacks, the researchers did not simulate a cyberattack. Many 3-D printers have features, such as encryption and watermarks, designed to foil such incursions.
Instead, the researchers programmed a common smartphone's built-in sensors to measure electromagnetic energy and acoustic waves that emanate from 3-D printers. These sensors can infer the location of the print nozzle as it moves to create the three-dimensional object being printed.
The smartphone, at 20 centimeters away from the printer, gathered enough data to enable the researchers to replicate printing a simple object, such as a door stop, with a 94 percent accuracy rate. For complex objects, such as an automotive part or medical device, the accuracy rate was lower but still above 90 percent.
"The tests show that smartphones are quite capable of retrieving enough data to put sensitive information at risk," says Kui Ren, PhD, professor in UB's Department of Computer Science and Engineering, a co-author of the study.
The richest source of information came from electromagnetic waves, which accounted for about 80 percent of the useful data. The remaining data came from acoustic waves.
Ultimately, the results are eye-opening because they show how anyone with a smartphone -- from a disgruntled employee to an industrial spy -- might steal intellectual property from an unsuspecting business, especially "mission critical" industries where one breakdown of a system can have a serious impact on the entire organization.
"Smartphones are so common that industries may let their guard down, thus creating a situation where intellectual property is ripe for theft," says Chi Zhou, PhD, assistant professor in UB's Department of Industrial and Systems Engineering, another study co-author.
Making 3-D printers more secure
The researchers suggests several ways to make 3-D printing more secure. Perhaps the simplest deterrent from such an attack is distance. The ability to obtain accurate data for simple objects diminished to 87 percent at 30 centimeters, and 66 percent at 40 centimeters, according to the study.
Another option is to increase the print speed. The researchers said that emerging materials may allow 3-D printers to work faster, thus making it more difficult for smartphone sensors to determine the print nozzle's movement.
Other ideas include software-based solutions, such as programming the printer to operate at different speeds, and hardware-based ideas, such as acoustic and electromagnetic shields.

Microsoft Removes Windows Journal Due to Security Flaws

Microsoft has decided to remove the Windows Journal application from its operating systems due to the discovery of several vulnerabilities that can be exploited through specially crafted Journal files.

Windows Journal is a note-taking application available in Windows versions from XP Tablet PC Edition through Windows 10. Notes and drawings created with the app are saved in .jnt files.
Over the past few years, researchers from various companies discovered roughly a dozen denial-of-service (DoS) and remote code execution vulnerabilities in Windows Journal.
The most recent issue was reported to Microsoft last month by Fortinet researcher Honggang Ren. The flaw identified by the expert is a heap overflow that can cause the application to crash. Fortinet published a blog post last week detailing the vulnerability.
Microsoft has not released a patch for the vulnerability found by the Fortinet researcher as it has decided to remove the component altogether. The update that removes Journal from Windows 7, 8, 8.1 and 10 is KB3161102, which the company first announced last month.
“The file format that's used by Windows Journal (Journal Note File, or JNT) has been demonstrated to be susceptible to many security exploits,” Microsoft explained.
The company has advised customers to migrate to OneNote, but users who depend on Journal can install it separately after they apply KB3161102. Those who want to continue using the app will be shown a security alert whenever they attempt to open Journal Note (JNT) or Journal Template (JTP) files.
Two memory corruption vulnerabilities have been resolved in Journal this year, including CVE-2016-0182, reported independently by Jason Kratzer and Bingchang Liu, and CVE-2016-0038, discovered by Rohit Mothe.
Microsoft informed customers this month that it has addressed an Internet Explorer/Edge vulnerability exploited in the wild. Experts revealed that the flaw had been leveraged in major malvertising campaigns since at least 2014.



Sunday, September 25, 2016

Necurs Botnet Fuels Jump in Spam Email

The volume of spam email has increased significantly this year, being comparable to record levels observed in 2010. Researchers from Cisco Talos believe the increase has been driven mainly from increased activity of the Necurs botnet.

Over the past five years, spam volumes have been relatively low compared to 2010, when they reached an all-time high. However, it appears that this lull might have ended this year, as spam is on the rise once again. Citing data from the Composite Block List (CBL), Cisco Talos researchers note that 2016’s spam volumes are nearly as high as they were back in mid-2010.
Furthermore, the overall size of the SpamCop Block List (SCBL) over the past year shows a spike of more than 450,000 IP addresses in August 2016, although the SCBL size was under 200,000 IPs last year, Cisco says.
The surge in spam email volumes this year, researchers explain, can only mean that dedicated botnets have increased their activity. However, anti-spam systems can usually catch spam campaigns fast because botnets are using a non-targeted/shotgun approach. Even so, researchers say, attacks cannot be predicted before they start.
Responsible for this year’s spike in spam campaigns, Cisco says, might be the Necurs botnet, which was associated only several months ago with the Locky ransomware and the Dridex Trojan. When Necurs suffered an outage in June, Locky and Dridex infections came to a relative stop, but the ransomware returned with a vengeance when the botnet was restored three weeks later.
Both Necurs’ outage and the lack of activity behind Dridex and Locky were supposedly connected to the arrests in Russia related to the Lurk Trojan, which Cisco now confirms. Necurs was only one of the major threats to be silenced following said arrests, but its return also marked a major change in behavior, Cisco says.
“And not only had Necurs returned, but it switched from sending largely Russian dating and stock pump-n-dump spam, to sending malicious attachment-based spam. This was the first time we'd seen Necurs send attachments,” the security researchers say.
Also associated with the Lurk gang, the Angler exploit kit disappeared in June, taking EK traffic down along with it, which has determined threat actors to find new means to deliver their malicious payloads, and spam botnets appear to have become their main choice. Although new anti-spam technologies and high-profile takedowns of spam-related botnets have diminished spam volumes over time, it appears that this attack technique is once again popular among cybercriminals.
According to Cisco, Necurs remains a highly active spam botnet mainly because its operators have found an ingenious method to continue using infected hosts for many years. For that, they only send spam from a subset of infected machines, and then stop using these hosts for several weeks, to draw attention away from them and to trick security personnel into believing that the host has been cleaned.
“Many of the host IPs sending Necurs' spam have been infected for more than two years. To help keep the full scope of the botnet hidden, Necurs will only send spam from a subset of its minions. An infected host might be used for two to three days, and then sometimes not again for two to three weeks,” researchers say. “At Talos, we see this pattern over, and over again for many Necurs-affiliated IPs.”
And because spammers have only a small window of opportunity between the start of a campaign until anti-spam systems are deployed, they try to send as much email as possible to ensure that they can successfully land malicious email into their victims' inboxes.
“Unfortunately there is no silver bullet to defending against a spam campaign. Organizations are encouraged to build a layered set of defenses to maximize the chances of detecting and blocking such an attack. Of course, whenever ransomware is involved, offline backups can be critical to an organization's survival. Restoration plans need to be regularly reviewed and tested to ensure no mistakes have been made and that items have not been overlooked. Lastly, reach out to your users and be sure they understand that strange attachments are never to be trusted,” Cisco says.

Russia? China? Who Hacked Yahoo, and Why?


Yahoo's claim that it is the victim of a gigantic state-sponsored hack raises the question of whether it is the latest target for hackers with the backing of Russia, China or even North Korea, experts say.

The US internet giant was under pressure Friday to explain how it sustained such a massive breach in 2014, which possibly affected 500 million accounts.
Yahoo said the stolen information may have included email addresses and scrambled passwords, along with both encrypted or unencrypted security questions and answers that could help gain access to victims' other online accounts.
Sometimes the link between the target of a hack and a particular state may suggest itself easily.
One of the highest-profile hacks came when North Korea is thought to have targeted entertainment titan Sony in 2014, apparently in revenge for producing the comedy film "The Interview" about a CIA plot to assassinate leader Kim Jong-Un.
More recently, a mysterious group calling itself Fancy Bears hacked the medical records of athletes held by the World Anti-Doping Agency (WADA). It is still dripping the information out.
Commercial motives
Many experts believe that cyberattack was carried out by Russia after its track and field athletes were banned from the Olympics and its entire Paralympics team turfed out of their Games over evidence of state-sponsored doping.
While motivation for those cyberattacks seems clear, it might initially appear less obvious why countries such as Russia, North Korea or even China would target a company like Yahoo.
Chinese hackers have been accused of plundering industrial and corporate secrets and of orchestrating a breach of US government files on its employees that affected more than 21 million people and reportedly led to the hasty withdrawal of US intelligence operatives from China to protect their lives.
But political motives can be as strong as commercial ones, analysts note.
"Would, for example, Russian intelligence wish to conduct a large-scale hack on a major internet company like Yahoo? Absolutely they would," Shashank Joshi, senior research fellow at the London-based Royal United Services Institute, told AFP.
"It is an incredibly valuable commodity. The ability to access email addresses for US persons, perhaps a Russian dissident -- any intelligence agency worth its salt would want that sort of data, although it is very hard to use because of the encrypted passwords," he said.
Julien Nocetti, of the French Institute of International Relations (IFRI), said the hack was too big for an independent group to carry out.
"Given the scale of the revelations about Yahoo, it indicates that a lot of resources, technical equipment and coordination were required -- this definitely comes from a state," he said.
Given the tensions between Russia and the United States over the Syrian war "you could put forward the theory that this could be a Russian attempt to test the Americans' cyber defences", he said.
- Finding the source -
Yahoo has so far given no evidence to support its claim that it has been targeted by a state. RUSI's Joshi said finding the source "is the most fundamental problem when it comes to cyber-attacks".
"This completely bedevils even the most well-resourced people," he said.
However, he believes Yahoo would only have pointed the finger at state involvement if it had some evidence.
"The way you identify responsibility for a hack is to look for signatures that correspond to earlier known facts and then see what you know about them," he said.
For example, in case of the hacking of Democratic National Committee (DNC) emails this year which exposed bias within the party in favour of Hillary Clinton, cyber-security experts found evidence of a so-called Advanced Persistent Threat (APT).
"That is a code word for state hackers who were clearly operating in a system and matched up with earlier such hacks" carried out by Russia's state and military intelligence agencies, Joshi said.
But in Russia, so often accused of state-sponsored hacking, one expert said it was naive to immediately blame a state and scoffed at the suggestion the hackers were sophisticated spies.
"Anyone could have hacked a database of users like Yahoo because it's a classic commercial server," said Oleg Demidov, a consultant at the Moscow-based independent think-tank PIR Center.
"At the moment, this looks like a traditional hack aimed at making money or carving out a reputation by selling a load of personal data," he added.

Popular Posts

Contact

anmol3886@gmail.com