Showing posts with label Pen Testing And Exploit Research. Show all posts
Showing posts with label Pen Testing And Exploit Research. Show all posts

Beware of Unpatched Backdoor in Atlassian Crowd Authentication Service

Jun 30, 2013 | comments


Over 25,000 companies from all over the world rely on Atlassian’s solutions, including organizations from the automotive, consulting, education, engineering, entertainment, government, health and other industries.

According to the advisory published by Command Five, Crowd users should update their installations as soon as possible because an exploit for a vulnerability discovered in 2012 has become widely available.

The security hole can be leveraged by an attacker to retrieve data and files from the Crowd server by crafting entity URLs. In addition, the flaw can be leveraged for denial-of-service (DOS) attacks.

“If a hacker uses the vulnerability to retrieve a file containing credentials, they can then authenticate with the Crowd server directly, or use the exploit again to bypass trusted proxy/remote address validation as described above,” the advisory reads.
“Successful exploitation of this vulnerability can (but does not necessarily) lead to a hacker taking full control of an organization single sign­ on service, potentially resulting in a catastrophic security event. Regardless, successful exploitation is likely to enable high velocity lateral movement within the targeted organization,” researchers explain.

However, the patched vulnerability is not the main concern. Command Five says there is at least one critical vulnerability in Crowd that hasn’t been patched.

The flaw can be exploited by an unauthenticated remote attacker to take full control of any Crowd server they can connect to.
  Cyber criminals can compromise application credentials, user credentials, data storage, configured directories and dependent secure systems.

Sweet Orange Exploit Kit

Dec 19, 2012 | comments

Malware is a business; people make their living writing and distributing it. Exploit kits are an effective and streamlined methodology of distributing malware; they allow the Bad Guys to distribute payloads at a higher level than we have seen in the past. For this reason we've seen exploit kits grow in popularity over the last few years.

Sweet Orange Exploit Kit

BlackHole is the most famous and the most utilized exploit kit these days, but that doesn’t mean there aren’t others that have the potential to compete with it. One of them is the Sweet Orange exploit kit, which is presumably capable of some impressive things.

Developers of Sweet Orange boast that their creation has a small footprint, a high infection rate, and the ability to drive 150,000 unique daily visitors to a website.

They claim that around 10% to 25% of those who land on the malicious website will be infected, meaning that at least 15,000 bots should be added to the botnet each day.

So far, experts have managed to identify 45 different IP addresses and 367 domains utilized by Sweet Orange, which makes the 150,000 unique daily visitors forecast sound valid.

 



 

Necurs : A Multipurpose Trojan

Dec 10, 2012 | comments

Necurs a multipurpose trojan is a prevalent threat in the wild at the moment - variants of Necurs were reported on 83,427 unique machines during the month of November 2012.





Necurs is mostly distributed by drive-by download. This means that you might be silently infected by Necurs when you visit websites that have been compromised by exploit kits such as Blackhole.

Necurs Trojan is capable of:

  • Modifying the computer's registry in order to make itself start after every reboot.
  • Dropping additional components that prevents a large number of security applications from functioning correctly, including the ones manufactured by Avira, Kaspersky Lab, Symantec and Microsoft. According to Microsoft's researchers, Microsoft Security Essentials' real time protection option is often turned off after an infected computer has been rebooted.
  • Disabling the running firewall
  • Contacting a remote host for command and control instructions via HTTP port 80, and sometimes downloading and installing additional malware (mostly rogue AVs) and loading a malicious DLL component that allows attackers to send out spam via Gmail.
  • Creating a permanent backdoor into the system, which allows attackers to gain complete control of the affected computer.
In addition Necurs contains backdoor functionality, allowing remote access and control of the infected computer. Necurs also monitors and filters network activity and has been observed to send spam and install rogue security software. Nefariousness aplenty.Necurs uses MD5 and SHA1 to encrypt its network traffic data when sending or receiving, and contains a regularly updated driver that protects every Necurs component from being removed .


Air Canada Order Confirmation Email Contains Malicious URL

Dec 5, 2012 | comments

Fake Air Canada emails with order confirmation contains URL that downloads malicious ZIP file, email is send from the spoofed address “Air Canada <tickets@aircanada.com>” and has the following body:

Dear Customer,
Your order has been successfully processed.
FLIGHT NUMBER TB8696CA
ELECTRONIC 75267302
DATE & TIME / DECEMBER 5, 2012, 10:30 AM
DEPARTING / Toronto
TOTAL PRICE / 375.12 CAD

Please download and print your ticket from the following URL : http://www.aircanada.com/aco/manageMyBookings.do?tid=TB7392CA&ticket_number=75267302
For more information regarding your order, contact us by visiting , visit : http://www.aircanada.com/en/customercare/index.html?orderid=75267302&ssid=1866
Thank you
Air Canada.
The embedded URL does not points the browser to the real web site address but to hxxp://air-canada.org/tickets/ticketTB7392CA.zip. Once this file is extracted you will have the 175 kB large file ticketTB7392CA.scr.

The trojan is known as Trojan-Spy.Win32.Zbot.gtvm, Trojan.Zbot or Trojan.Agent/Gen-Festo.

 


RapidFAX And eFax Inbound Fax Emails Attached ZIP File Contains Trojan

| comments

Inbound Fax,RapidFAX: Inbound Fax,RapidFax: New Inbound Fax

ALERT : If you come across an email entitled “Inbound Fax,”eFax, “RapidFAX: Inbound Fax” or “RapidFax: New Inbound Fax” in your inbox, don’t open the attachment it contains since it hides a new variant of a Trojan.

The messages, which purport to come from reports@rapidfax.com, contain information such as MCFID, the time at which it was received, fax number, ANI, number of pages, CSID, and the fax status code.
They only inform recipients that “a fax have been received” and urge them not to reply to the email.

The attached ZIP file has the name rapidfax-E4C935577EDD.zip and contains the  117 kB large file RapidFAX_MCID_000_LOTS_OF_NUMBERS__13341.pdf.exe.

Malware is identified as TR/Dldr.Kryptik.H, Trojan.Generic.8337227, Win32/Kryptik.APZB or Trojan-PSW.Win32.Tepfer.cqaj, depending on the antivirus vendor. 
The trojan is also known as UDS:DangerousObject.Multi.Generic or Trojan.Lameshield.

                                                Virus Total Analysis Here



This isn’t the only spam campaign that relies on bogus fax messages. Emails pretending to come from eFaxCorporate are also making the rounds these days.

eFax email,eFax attached ZIP file contains trojan


The emails appear to come from messages@inbound.efax.com (the default eFax account) and they’re entitled “Corporate eFax message – (xyz) pages .

Dockster: New Mac Trojan OSX/Dockster Targets gyalwarinpoche.com Website Related To Dalai Lama

Dec 4, 2012 | comments

A website related to the Dalai Lama is hosting attack code that attempts to surreptitiously install OS X-based spy software on the Macs of people who visit.

This malware is now known to be in the wild and the remote address contacted by the backdoor is now active. The Java-based exploit uses the same vulnerability as "Flashback", CVE-2012-0507. Current versions of Mac OS X and those with their browser's Java plugin disabled should be safe from the exploit. The malware dropped, Backdoor:OSX/Dockster.A, is a basic backdoor with file download and keylogger capabilities.

If it’s executed, the trojan deletes itself from the location where it was run and installs itself in the user’s home directory with the filename .Dockset. The file is not visible through Finder; however, if it’s running, it can be seen within OS X’s Activity Monitor.  It creates a launch agent called mac.Dockset.deman so that the trojan will restart each time an affected user logs in. Once the trojan is active, it tries to contact the remote address itsec.eicp.net to await instructions. At the time of writing, this address is not registered, which indicates the sample may be intended simply as a test rather than an active threat.

 In the case of Flashback, which was also discovered by Intego, reported 600,000 Macs were affected before both Apple and Oracle released a Java patches to remove the malware and protect against future attacks.

Although the newly-found Dockster takes advantage of an already fixed weakness, users who haven't yet updated their Macs or are running older software may still be at risk.

Tumblr Suffering From a Viral Hack

Dec 3, 2012 | comments

tumblr hack

Tumblr seems to be suffering from a viral hack at the moment, as several blogs appeared to have been compromised and are now displaying a message from the notorious troll organization GNAA.
The problem seems to be with Tumblr, which has acknowledged it, so account credentials probably haven’t been compromised.

“There is a viral post circulating on Tumblr which begins ‘Dearest ‘Tumblr’ users.’ If you have viewed this post, please log out of all browsers that may be using Tumblr immediately. Our engineers are working to resolve the issue as swiftly as possible,” Tumblr explained.

A coding tag contained in the post linked to malicious code on another website. The JavaScript exploit, which was included in an iframe tag that pointed to an outside website, used what is known as base-64 encoding. It's a technique that uses printable ASCII characters to represent large chunks of binary data and has the benefit of making it harder to know exactly how a script will behave when executed.

There’s no way to know how many blogs have been affected so far and the only way to avoid your blog being taken over is to not use Tumblr and log out of your account. Not the greatest of fixes, but it’s all that works for now.

The exploit through which all of this was accomplished is unknown for now, the speculation is that the hackers were able to use a bug in Tumblr’s embedding system and get their scripts to run from there.

The malicious posting can be easily removed from infected accounts using the Tumblr mass editor. The site also recommends affected users change their account password, a measure that's probably not necessary, but wise considering Tumblr researchers have yet to offer a complete analysis of the attack.

Session Riding Vulnerability In Instagram 3.1.2 For iOS

Dec 1, 2012 | comments

Following my latest report on Instagram ,Instagram 3.1.2 for iPhone (released on Oct 23, 2012) is vulnerable to a session riding attack that could lead an attacker on the same network to gain access to the victim’s account.

In this PoC exploit an attacker on the same LAN of the victim could launch a simple ARP spoofing attack to trick mobile devices into directing port 80 traffic through the attackers machine. When the victim starts the Instagram app and performs any action that requires authentication, such as liking or unliking pictures, a plain text cookie is sent to the Instagram server, once the attacker gets the cookie he is able to login into the user’s account via web and perform a variety of actions.

The compromise uses a method called ARP (Address Resolution Protocol) spoofing,
an ARP spoofing attack redirects Instagram requests from the iPhone into a custom hyperfox proxy, when the proxy detects an Instagram cookie, a file cookie/$IP_ADDRESS.txt is created containing the cookie value.
After the attacker gets a cookie, he could use a plugin like Modify Headers on Firefox to sign in as the user on the secure URL https://instagram.com/accounts/edit/ where he could change personal data, such as the user’s e-mail address, and compromise the account., Reventlov wrote.


Credit  : The attack was developed by a security researcher Carlos Reventlov


Instagram vulnerability :Media Information Disclosure Security Issue

Nov 30, 2012 | comments

Instagram 3.1.2 For iOS, Plaintext Media Information Disclosure Security Issue
Facebook's Instagram photo-sharing service that could allow a hacker to seize control of a victim's account. The attack was developed by Carlos Reventlov around a vulnerability he found within Instagram in mid-November. He notified Instagram of the problem on Nov. 11, but as of last Tuesday, it had not been fixed.

The vulnerability is in the 3.1.2 version of Instagram's application, released on Oct. 23, for the iPhone. Reventlov found that while some sensitive activities, such as logging in and editing profile data, are encrypted when sent to Instagram, other data was sent in plain-text. He tested the two attacks on an iPhone 4 running iOS 6, where he first found the problem.
"When the victim starts the Instagram app, a plain-text cookie is sent to the Instagram server," Reventlov wrote. "Once the attacker gets the cookie he is able to craft special HTTP requests for getting data and deleting photos."
The plain-text cookie can be intercepted using a man-in-the-middle attack as long as the hacker is on the same LAN (local area network) as the victim. Once the cookie is obtained, the hacker can delete or download photos or access the photos of another person who is friends with the victim.

Details

The Instagram app communicates with the Instagram API via HTTP and HTTPs connections.
Highly sensitive activities, such as login and editing profile data, are sent through a secure channel. However, some other request are sent through plain HTTP without a signature, those request could be exploited by an attacker connected to the same LAN of the victim’s iPhone.
The only authentication method for some HTTP calls is an standard cookie that is sent without encryption when the user starts the Instagram app.
An attacker on the same LAN of the victim could launch a simple arpspoofing attack to trick the iPhones into passing port 80 traffic through the attackers machine. When the victim starts the Instagram app a plain text cookie is sent to the Instagram server, once the attacker gets the cookie he is able to craft special HTTP requests for getting data and deleting photos.

Suggested fix


  • Use HTTPs for all API requests that could contain sensitive data, such as photo URLs.
  • Use a body signature for unencrypted requests.

Trading Forex Website Targeted

Nov 28, 2012 | comments

A FOREX trading website called "Trading Forex," located at hxxp://tradingforex.com has been contaminated with a malicious Java applet that is designed to install malware on the systems of visiting surfers. 

FOREX is the foreign exchange market where international currencies are traded, and nowadays, it's used by millions of people around the world. 

The backdoor planted on Trading Forex is written in Visual Basic.Net and requires the Microsoft's .NET framework to be successfully installed and running on a victim's computer. This is an unusual approach.

Hackers intent on distributing malware through compromised websites often use pre-packaged tools, available through underground forums, most notably the widely used Blackhole Exploit kit.




Java Zero-Day Exploit on Sale

Nov 26, 2012 | comments

Miscreants in the cyber underground are selling an exploit for a previously undocumented security hole in Oracle’s Java software that attackers can use to remotely seize control over systems running the program, KrebsOnSecurity has learned.
The flaw, currently being sold by an established member of an invite-only Underweb forum, targets an unpatched vulnerability in Java JRE 7 Update 9, the most recent version of Java (the seller says this flaw does not exist in Java 6 or earlier versions).
According to the vendor, the weakness resides within the Java class “MidiDevice.Info,” a component of Java that handles audio input and output. “Code execution is very reliable, worked on all 7 version I tested with Firefox and MSIE on Windows 7,” the seller explained in a sales thread on his exploit. It is not clear whether Chrome also is affected. “I will only sell this ONE TIME and I leave no guarantee that it will not be patched so use it quickly.”

New Malware Targeting SQL Db's In Iran

Nov 23, 2012 | comments

iran malware
Security firm Symantec has discovered a specialised worm called W32.Narilam that can compromise SQL databases. Symantec reports that the malware "speaks" Persian and Arabic and appears to target mainly companies in Iran. Narilam is, therefore, reminiscent of Stuxnet and its variants.

Narilam spreads via USB flash drives and network shares. Once inside the system, the worm searches for SQL databases that are accessible via the Object Linking and Embedding Database (OLEDB) API. Rather than steal found target data for intelligence purposes, the worm proceeds to modify or delete the data and can, says Symantec, cause considerable damage. Stuxnet similarly served no intelligence purpose and was designed to sabotage its target – an uranium enrichment facility in Natanz, Iran.
 
**Narilam affects almost exclusively "corporate users"**
 

The purpose of Narilam, or that of the worm's authors, remains unknown. However, Symantec says that its analysis suggest that the saboteurs appear to have targeted corporate data records. 

Apparently, the worm's translated instructions include object names such as "sale", "financial bond" and "current account". Due to the malware's level of specialisation, Symantec rates the infection risk as low. The security firm notes that current analysis results indicate "that the vast majority of users impacted by this threat are corporate users."

Some of the worm was written in the Delphi programming language. Symantec says that the worm takes its name from its own attributes, because it searches for SQL databases with three specific names: alim, shahd and maliran. 
Source: Symantec 

Latest Linux malware Doing iFrame Injections

Nov 21, 2012 | comments (3)

malware

  

                New Linux malware can automatically hijack websites

       

 A few days ago, an interesting piece of Linux malware came up on the Full Disclosure mailing-list. It's an outstanding sample, not only because it targets 64-bit Linux platforms and uses advanced techniques to hide itself, but primarily because of the unusual functionality of infecting the websites hosted on attacked HTTP server - and therefore working as a part of drive-by download scenario.  It can automatically hijack websites hosted on compromised servers to attack web surfers with drive-by-downloads.

The software nasty targets machines running 64-bit GNU/Linux and a web server, and acts like a rootkit by hiding itself from administrators. A browser fetching a website served by the compromised system will be quietly directed via an HTML iframe to malicious sites loaded with malware to attack the web visitor's machine.

The malware module was specially designed for the kernel version 2.6.32-5-amd64, which happens to be the latest kernel used in 64-bit Debian Squeezy. The binary is more than 500k, but its size is due to the fact that it hasn't been stripped (i.e. it was compiled with the debugging information). Perhaps it's still in the development stage, because some of the functions don’t seem to be fully working or they are not fully implemented yet. 

The Linux malware is designed to load itself into memory on startup before hooking itself into kernel functions. Rootkit Linux Snakso-A, as Kaspersky Lab dubs the software, uses various ninja-style tricks to hide itself before crafting network data packets containing the HTML iframes; these are then tucked into the server's output to visiting web browsers. The malicious payload delivered to surfers through these iframes is pulled from a mastermind's command-and-control server.
An excellent, detailed analysis of this rootkit was recently posted on CrowdStrike blog .

AT&T iPad Data Slurp

| comments

A 27 year old  hacker Andrew Auernheimer from new york has been found guilty of breaching AT&T's site security to obtain iPad customer data.

According to the government, the men used an "account slurper" that was designed to match email addresses with "integrated circuit card identifiers" for iPad users, and which conducted a "brute force" attack to extract data about those users, who accessed the Internet through AT&T's network.

The case is been closely watched in the information security community because Auernheimer recovered the data from the AT&T website without bypassing any security controls. The appeal will therefore focus on whether the Computer Fraud and Abuse Act offences were committed by Auernheimer, an important point of law that has implications for both penetration testing and the reporting of security vulnerabilities.

.Eu Domains Are Being Used To Infect PCs

Nov 20, 2012 | comments

Some malicious .eu domains have been registered during November which are being used to infect PCs with malware via the Blackhole exploit kit. 

For example :

owzshm.eu
mpxuth.eu

ngpsjy.eu

wlwhhz.eu

jhzopj.eu

jqwwgm.eu

pmgugq.eu

jkiwhy.eu

nrxpxq.eu

vjtjpy.eu

xzjvhs.eu

xipuww.eu

kngipu.eu

ptkqzo.eu

pyrhox.eu


This type of tactic is pretty common, used by many threats in their attempts to evade security filtering.And what of this IP address,It has something of a long history of questionable activity, extending over many months. It currently hosts over 100 domains, whose purpose ranges from porn site gateways (referenced in spam) through to exploit sites.

 

Smartcard Malware

| comments

Smartcard Malware Can Share a Smartcard Over The Internet

indiatriks.blogspot.com

                                       S8UK3FT4BKJW

Security researchers have developed proof-of-concept malware that allows attackers to obtain remote access to smart card readers attached to compromised Windows PCs.A team of researchers has created a proof-of-concept piece of malware that can give attackers control of USB smart card readers attached to an infected Windows computer over the Internet.

In the case of USB smart card readers, the attacker can use the middleware software provided by the smart card manufacturer to perform operations with the victim's card as if it was attached to his own computer, said Paul Rascagneres, an IT security consultant at Luxembourg-based security auditing and consulting firm Itrust Consulting, on Thursday. Rascagneres is also the founder and leader of a malware analysis and engineering project called malware.lu, whose team designed this USB sharing malware.

Smart cards are used for a variety of purposes, but most commonly for authentication and signing documents digitally. Some banks provide their customers with smart cards and readers for secure authentication with their online banking systems. Some companies use smart cards to remotely authenticate employees on their corporate networks. Also, some countries have introduced electronic identity cards that can be used by citizens to authenticate and perform various operations on government websites.

Rascagneres and the malware.lu team tested their malware prototype with the national electronic identity card (eID) used in Belgium and some smart cards used by Belgian banks. The Belgian eID allows citizens to file their taxes online, sign digital documents, make complaints to the police and more.

However, in theory the malware's USB device sharing functionality should work with any type of smart card and USB smart card reader, the researcher said.

In most cases, smart cards are used together with PINs or passwords. The malware prototype designed by the malware.lu team has a keylogger component to steal those credentials when the users input them through their keyboards.
 However, if the smart card reader includes a physical keypad for entering the PIN, then this type of attack won't work, Rascagneres said.

The drivers created by the researchers are not digitally signed with a valid certificate so they can't be installed on versions of Windows that require installed drivers to be signed, like 64-bit versions of Windows 7. However, a real attacker could sign the drivers with stolen certificates before distributing such malware.

In addition, malware like TDL4 is known to be able to disable the driver signing policy on 64-bit versions of Windows 7 by using a boot-stage rootkit -- bootkit -- component that runs before the operating system is loaded.
The attack is almost completely transparent to the user, since it won't prevent them from using their smart card as usual,The only giveaway might be the blinking activity led on the smart card reader when the card is accessed by the attacker.

Cracking WPA2 Password Of Belkin Routers

| comments

WPA2 Password Cracking
A number of Belkin wireless routers are shipped with a default WPA2 password to protect network connections. The apparently random passwords are printed on a label that’s on the bottom of the router.
Although this approach should be, in theory, more secure, because the password is likely stronger than what many users would set themselves, it turns out that the random passphrases aren’t so random.

The researchers have determined that the password is based on the device’s WAN MAC address, and since this information is not so difficult to obtain, a remote attacker could easily hack into a targeted network – given that the default configuration is used.

The default password is made of 8 characters which can be determined by replacing each hex-digit of the WAN MAC address with another value from a static substitution table.
Several device models are affected, including Belkin N450 Model F9K1105V2 and Belkin Surf N150 Model F7D1301v1.

The experts claim to have contacted Belkin back in January, but since they haven’t received any response, they’ve made their findings public. In the meantime, they advise users to change their default passphrases to something stronger and, implicitly, more secure.

Vulnerability :

Having a preconfigured randomly generated WPA2-PSK passphrase for wireless routers is basically a good idea since a vendor-generated passphrase can be much more secure than most user-generated passwords. However, in the case of Belkin the default password is calculated solely based on the mac address of the device. Since the mac address is broadcasted with the beacon frames sent out by the device, a wireless attacker can calculate the default passphrase and then connect to the wireless network.
Each of the eight characters of the default passphrase are created by substituting a corresponding hex-digit of the wan mac address using a static substitution table. Since the wan mac address is the wlan mac address + one or two (depending on the model), a wireless attacker can easily guess the wan mac address of the device and thus calculate the default WPA2 passphrase.

Moreover, the default WPA2-PSK passphrase solely consists of 8 hexadecimal digits, which means that the entropy is limited to only 32 bits (or 33 bits since some models use uppercase hex digits). After sniffing one successful association of a client to the wireless network, an attacker can carry out an offline brute-force attack to crack the password. The program oclhashcat-plus can try 131,000 passwords per second on one high end GPU (AMD Radeon hd7970) [Link]. Doing a full search of the 32-bit key space takes about 9 hours at this rate.

An attacker can exploit this vulnerability to calculate the WPA2-PSK passphrase of a wireless network. This allows sniffing and decrypting all wireless traffic in a purely passive attack given that the attacker has also sniffed the association.

Affected device :  

 

Belkin Surf N150 Model F7D1301v1
Belkin N900 Model F9K1104v1
Belkin N450 Model F9K1105V2

Belkin N300 Model F7D2301v1

How To Secure Yourself : 

Users of potentially affected wireless routers should change the wireless passphrase to something more secure.

Windows 8 Pro Free

| comments

free download microsoft windows 8

 Pirates Exploit a weakness in Microsoft’s Key Management Service (KMS) To Get Windows 8 Pro Free Copies: When a better lock’s built, folks just devise new ways to pick it. It’s pretty much a fact of life. So it’s not surprising that folks have already pirated Windows 8. If anything, it was probably expected. What is surprising, however, is that Microsoft’s just unintentionally legitimized pirated copies of Windows 8 Pro through a Windows Media Center upgrade.

The Media Center upgrade, which Microsoft is offering through January 31, 2013, includes Microsoft’s tools for watching and recording live TV. However, applying the upgrade has an unintended side effect: It permanently activates the copy of Windows 8 that you’ve applied it to.

Exploit allows all those pirates currently using the KMS exploit to suddenly grant themselves a complete copy. Since KMS installs basically expire after 180 days .


 

FreeBSD Project Server Hacked

| comments

                       Two FreeBSD Project Servers Hacked

Hackers broke into two FreeBSD project servers using an SSH authentication key* and login credentials,Venerable BSD-based operating system FreeBSD has announced a smallish system compromise.
The FreeBSD administrators took a bunch of servers offline to investigate, and published a blow-by-blow account of what they know about the breach so far.
FreeBSD isn't the first open source operating system to suffer an intrusion on its core servers.
The Linux developers famously suffered both a malware attack and a server compromise last year that saw kernel.org vanish offline for over a month.

No Trojanised packages have been uncovered, at least as yet. But FreeBSD users have been urged to carefully check third-party packages installed or updated between 19 September and 11 November nonetheless, as a precaution.
The FreeBSD.org team has promised to tighten up security, in particular by phasing out legacy services such as the distribution of FreeBSD source via CVSup, in favour of the more robust Subversion, freebsd-update, and portsnap distribution methods". The hack was "not due to any vulnerability or code exploit within FreeBSD .


Malware Using Google Docs As Proxy

| comments

Security researchers from antivirus vendor Symantec have uncovered a piece of malware that uses Google Docs, which is now part of Google Drive, as a bridge when communicating with attackers in order to hide the malicious traffic.

The malware -- a new version from the Backdoor.Makadocs family -- uses the Google Drive "Viewer" feature as a proxy for receiving instructions from the real command and control server. The Google Drive Viewer was designed to allow displaying a variety of file types from remote URLs directly in Google Docs.

Backdoor.Makadocs is distributed with the help of Rich Text Format (RTF) or Microsoft Word (DOC) documents, but does not exploit any vulnerability to install its malicious components, Katsuki said. "It attempts to pique the user's interest with the title and content of the document and trick them into clicking on it and executing it.
 
Support : INDIATRIKS
Copyright © 2011. INDIATRIKS - All Rights Reserved
Template Edited By Indiatriks
Proudly Powered By Blogger