Delicious Digg Facebook Favorites More Stumbleupon Twitter
Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Tuesday, 26 November 2013

Posted by Unknown 04:52 in , , ,
No comments

Bitcoin Payment Solutions (BIPS) hacked, $1 million stolen 


Danish bitcoin exchange Bitcoin Payment Solutions (BIPS) is the latest victim of Bitcoin website hacks.

The BIPS has temporarily shut down the consumer its consumer wallet initiative after hackers reportedly steal Bitcoins worth more than $1 million(1200+ BTC).

The company says it will consider reintroducing the wallet with a re-architected security model in order to prevent future cyber attacks.

"All existing users will be asked to transfer bitcoins to other wallet solutions, and users affected by the security breach will be contacted" says the company in their official press release.

This is third Bitcoin website's security breach that we are covering in this month.  Earlier this month, we reported that hackers attacked Bitcash.cz and Inputs.io and steal more than $1 in Bitcoins.


Monday, 25 November 2013

Cryptocat  Encrypted  chat vulnerable to simple Brute-Force  Decryption


Cryptocat, an open source encrypted Web-based chat application, is taking heat from numerous places after a vulnerability was discovered that put chats at risk for relatively simple decryption, experts say.
Worse, says researcher Steve Thomas who found the flaw, is that it likely was present in the code base going back to 2011. Cryptocat, meanwhile, says the vulnerability was present between versions 2.0 and 2.0.42—a seven-month timeframe—and urges users to update the app to the 2.1 branch.
“Group conversations that were had during those seven months were likely vulnerable to being significantly easier to crack,” Cryptocat said on its development blog.
Thomas disagrees and says the bug has been present since October 2011, and wrote an app called DecryptoCat that cracks the ECC public keys generated by Cryptocat between versions 1.1.147 and 2.0.41. Using a meet-in-the-middle attack, which reduces the number of brute force attempts needed to crack a target, Thomas said his tool can crack a key in less than two hours of computing time. He added that changes made to the keyspace in Cryptcocat version 2.0.42 raises that timeframe to 1,000 computer years of calculations.
“Decryptocat takes advantage of a meet-in-the-middle attack called baby-step giant-step you can effectively square root the key space. So 2^54.15 turns into 2^27.08 and 2^106.3 to 2^53.15,” Thomas wrote. “For Cryptocat versions before 2.0.42, doing a split of 2*10^9 and 10^7 it takes about a day to calculate data needed to crack any key in few minutes. This only requires tens of gigabytes to store. Doing a 2*10^8 and 10^8 split it will take an hour to generate and half an hour to crack any private key with that data.”
Thomas said on his blog that Cryptocat has tried numerous encryption iterations, including RSA, Diffie-Hellman and ECC, but uses key sizes smaller than the minimums.
“Cryptocat has one mission, to provide secure communication – which is to say, to encrypt data,” wrote security researcher Adam Caudill on his blog. “The most vital step in any crypto system is the key generation; if you get it wrong, nothing else matters. That code should be well reviewed and understood by multiple people. Cryptocat got this wrong.”
Cryptocat is used by privacy-conscious parties to keep online conversations secure. Activists use it to communicate with people living under oppressive regimes to inform and organize activities; journalists use it with sources to keep interactions private; and there are commercial uses as well, for example, conversations between attorneys and clients.
“When you release code like this to the public, and encourage people to use it – especially those that are at higher risk (i.e. activists), you take on a certain responsibility for ensuring that at least the core functionality is doing what’s expected,” Caudill said. “In this case, the team behind Cryptocat failed. For a year, the entire user base was at risk.”
Cryptocat has apologized and clarified too that its SSL keys have not been compromised as had been rumored, and that it has rotated its SSL keys as a precaution.
“Every time there has been a security issue with Cryptocat, we have been fully transparent, fully accountable and have taken full responsibility for our mistakes,” Cryptocat said. “We will commit failures dozens, if not hundreds of times more in the coming years, and we only ask you to be vigilant and careful. This is the process of open source security.”


Saturday, 23 November 2013


UK Bank Computers Become Part of Malicious Conficker Botnet

Computers in many of the UK's biggest banks and building societies have been infected with malware and become part of the malicious Conficker botnet.

Using data collected from three groups, the research project commissioned by the BBC discovered that 20 spam "incidents" had occurred so far this year connected with bank networks.
The project saw the University of Delft in The Netherlands, an unnamed firm running spam traps and security messaging firm Cloudmark contribute data to the project.
A botnet is a large network of computers that have been infected with malware. The cybercriminals who control these botnets use the infected PCs to distribute spam and malware, harvest personal data for sale or to attack websites to take them offline - typically without the victim's knowledge.
The research showed that 2013 has seen the highest number of incidents involving UK bank networks so far, compared with 2011 and 2012.
Conficker
PCs connected to seven corporate bank networks are regularly sending out spam emails, while another five networks have computers that have been enrolled into the six million-strong Conficker botnet which famously brought down email and computer support systems in the UK Defence Ministry, the Greater Manchester Police, the German Armed Forces and the French Navy in 2009.
Eight other networks are regular sources of malicious activity such as distributing malware, phishing scams tricking users into giving away passwords or credit card information, or "pump and dump" scams where users are tricked into visiting sites which can infect their computers with malware.
It is suspected that the banks' computers were compromised when employees accidentally opened malicious email attachments.
Warning
"There should be no spam coming out of these networks," said Delft University's Professor Michel van Eeten told the BBC. "If they are vulnerable to that you have to wonder what else they are vulnerable to. This might show they can fall victim to a targeted attack more easily because those are much harder to avoid falling into."
Since 2011, a cyber war exercise has been created to train staff from a number of UK banks and financial institutions.
This year's game, Waking Shark II, designed by Credit Suisse, is currently ongoing and is overseen by the Bank of England, the Treasury and the Financial Conduct Authority.
A police department in Massachusetts has paid $750 for two bitcoins to release files encrypted by the increasingly pervasive Cryptolocker ransomware


A computer in the police department of Swansea, Massachusetts was hit by the CryptoLocker ransomware on 6 November.
CryptoLocker is a particularly pernicious piece of malware that is typically spread as a malicious attachment in emails which look to come from financial institutions or postal services.
The malware infected the computer in the Swansea police department and encrypted files on the PC's hard drive including "images and word documents" which could include police reports and arrest photos of suspects.
The police department clearly had no backup system in place as it paid the ransom of two bitcoins, despite FBI guidance not to pay the cyber-criminals behind the attack. At the time two bitcoins were worth $750 but if the police had to pay up today, the price would be $1,300 as bitcoin's vlaue has risen considerably in recent weeks.  
Learning experience 
"It was an education for [those who] had to deal with it. [The malware] is so complicated and successful that you have to buy these bitcoins, which we had never heard of," Swansea Police Lt. Gregory Ryan told the Herald News in Massachusetts.
"We've upgraded our antivirus software. We're going to try to tighten the belt, and have experts come in, but as all computer experts say, there is no foolproof way to lock your system down."
Last Friday, the UK's National Crime Agency issued an alert that spam emails appearing to come from banks and financial institutions are being sent to tens of millions of UK consumers. In the US, consumers receive emails claiming to be from FedEx or UPS.
How CryptoLocker works
The ransomware only affects Windows PCs and not Macs, scanning hard drive, attached drives such as USB sticks, and even cloud storage accounts like DropBox, for a wide range of file types.
Once it discovers the files, the malware encrypts them and displays a countdown timer, giving the victim a limited amount of time to pay up or see their files encrypted forever.
The user has 72 hours to pay the ransom fee, using bitcoins, otherwise the files will be deleted permanently, although as of 15 November the malware developers are now accepting late payments of 10 bitcoins after the countdown ends.
Don't pay
Security company Bitdefenders Labs has discovered that over 12,000 victims have been claimed globally in the week between 27 October and 1 November.
The National Crime Agency, like the FBI in the US, does not advise users to pay the ransom, as there is no guarantee that payments will be honoured.

Friday, 22 November 2013

Posted by Unknown 02:52 in , , ,
No comments

More Java-based malware plagues the cross-platform runtime


 The same Java vulnerability used in the infamous Flashback malware is now being used as an attack vector for a single piece of malware that can infect both Windows and Mac OS X computers.

Security vendors have discovered a new piece of malware that attacks both PCs and Macs. It uses the same Java security vulnerability exploited by the Flashback malware that infected hundreds of thousands of Macs. While the attack vector is the same as in Flashback, this Java applet checks which OS it is running on and downloads suitable malware for it.
Malware writers love using a cross-platform plugin as an attack vector because it allows them to target more than one operating system, and thus more potential users. Since Java has been having security problems for a while now, it shouldn't be too much of a surprise it is now being used in an attack targeting both Windows and Mac computers.
This particular malware exploits the Java vulnerability to download further malicious code onto your computer, as you can see above. A backdoor Trojan written in C++ is installed on Windows while a similar Trojan written in Python called update.py (extracted from install_flash_player.py) is installed on Mac OS X.
Both droppers result in a Trojan that opens a back door on the compromised computer, allowing remote hackers to secretly send commands, upload code to the victim's computer, steal files, and run commands without the user's knowledge. The two Trojans are downloaded from the same server.
The Trojan only checks whether it is running on Windows once, but the downloaded Python dropper checks again whether it is running on a Mac or not. If it is running on Linux or some other operating system, the threat does nothing. Python is not often used to write malware, but in this case it works fine on Macs since Python is installed by default.
The Mac one can control how many times it gets commands from the server at certain time intervals (polling times), in order to avoid IDS or IPS detection. The network connection is also encrypted by RC4 or compressed by Zlib. The threat has the following functions: download files, list files and folders, open a remote shell, sleep, upload files.
In addition to using an antivirus, you can check if your Mac is infected by looking for these two files (both can be safely deleted):
/Users/Shared/update.sh (shell script) /Users/Shared/update.py (Python script)
The Windows one sends the following information back to the remote attacker: CPU details, Disk details, Memory usage, OS version, and user name. The Trojan can also download a file and execute it, or open a shell to receive commands.
Patches for this Java vulnerability have been available since February 14 for Windows, Linux, and Unix computers. Apple released a patch in early April, before the Flashback botnet was discovered. Apple has not issued a Java security update for users running versions of Mac OS X prior to 10.6 (Snow Leopard) because it wants to upgrade to a newer version of its operating system. These users can only protect themselves by disabling Java.
If you don't use Java, you also should disable it. Even if you don't have it installed, always get the latest security updates for your operating system and software, whether it's from Microsoft, Apple, or any other company.
For reference, Sophos detects this threat as Mal/20113544-A and Mal/JavaCmC-A. Symantecdetects the Java Applet malware as Trojan.Maljava, the droppers as Trojan.Dropper, and the back door Trojans as Backdoor.Trojan.


Search

Our Sponsors