Thursday, July 30, 2015

Expert v/s Non-Expert Advice to stay safe online - In one single graph





A picture is worth a thousand words





For More Information:

TOR needs a fix - New vulnerability can help attacker to ID the website and servers the user is accessing



I hope they fix it soon.


From the Article:

An attacker can figure out which dark web site a user is trying to access by passively monitoring Tor traffic, and even reveal the identity of servers hosting sites on the Tor network.

The attack doesn’t require the decryption of any traffic—only that it be monitored —and the exploit only requires control of a node where users enter the Tor network. 


When you use Tor, your connection gets encrypted and routed through three hops which form a path called a “circuit.” A circuit starts with an entry point called a “guard,” before going back into the regular internet via what are called “exit nodes.” The guard sees your IP address, and the exit node sees where the traffic’s going.

Without controlling an exit node. 88 percent of the time, the researchers were also able to identify which hidden service the user was trying to access.


For More info:
http://motherboard.vice.com/en_uk/read/researchers-unveiled-a-new-serious-vulnerability-in-tor

Wednesday, July 29, 2015

HammerToss Espionage Tool - Using Twitter + Steganoraphy


Hackers always amaze me,
Their ability to adapt and innovate is unbelievable


From the article:

Once APT29 has access to a target network and deems it worthy, it deploys Hammertoss, which communicates through URLs seeded in social media accounts—Twitter in particular—and makes use of steganography in images stored on GitHub or compromised websites to retrieve encrypted instructions.

“It’s unique in its ability to lay low, and thwart defenses.”

“When you look at the flow, from Twitter to GitHub to cloud storage, from a defender’s perspective, that’s not going to look malicious,” said Jordan Berry, threat intelligence analyst at FireEye.

“In this case, there’s no compromised infrastructure to look for and block because they created their own workaround.”



For more info:
https://threatpost.com/new-hammertoss-espionage-tool-tied-to-miniduke-gang/113996

Tuesday, July 28, 2015

Good Article on PKI Trust Models




A Good document on PKI Trust Model from SANS Reading Room

LINK:
https://www.sans.org/reading-room/whitepapers/vpns/pki-trust-models-trust-36112


Oh! now we have "Malicious" text messages and that can affect 950 million Android phones.


One thing common these days whether it is about data breach or jeeps or devices is that they affect millions (users,devices, automobiles)


From the Article

The vulnerability resides in "Stagefright," an Android code library that processes several widely used media formats. The most serious exploit scenario is the use of a specially modified text message using the multimedia message (MMS) format. 

All an attacker needs is the phone number of the vulnerable Android phone. From there, the malicious message will surreptitiously execute malicious code on the vulnerable device with no action required by the end user and no indication that anything is amiss

For more info:

Friday, July 24, 2015

"homograph “spoofing" - ???




Techniques in which the attackers purchase domains and create emails that are similar to the victim and their correspondent. In some cases, the emails may differ by only one letter.


This article is about how Nigerian Scammers work?
Interesting to find out how thorough their planning and executions are.
It is not easy


From the article


To select their victims, the group of fraudsters peruses sites such as Alibaba in an effort to identify potential victims who reside in countries in which they already have existing bank accounts

he scammers also tend to target users who have registered accounts with free email providers, such as Yahoo!, Google and Hotmail.

Once a victim has been chosen, the fraudsters must figure out a way to deliver to them remote access tools (RATs) and other exploits.



For more details:
http://www.tripwire.com/state-of-security/security-data-protection/cyber-security/the-four-cs-of-a-nigerian-payment-diversion-scam/

Smartwatches - Not so-smart when it comes to security


No surprise here, the vendors are in business of selling watches so, why bother about security



From the article:

“We found that smartwatch communications are easily intercepted in 90 percent of cases, and 70 percent of watch firmware is transmitted without encryption,” 


All of the watches that HP evaluated collected personal data in the form of names, addresses, birth dates, weight, gender and heart rate. Yet not one of them had adequate controls in place for ensuring the privacy and security of the collected data either while on the device or in transit.

For instance, every smartwatch that HP tested was paired with a mobile interface that lacked two-factor authentication. None of the interfaces had the ability to lock out accounts after multiple failed login attempts. A significant 40 percent of the tested products used weak cyphers at the transport layer while a full 70 percent had firmware related insecurities.


For more details:
http://www.darkreading.com/endpoint/smartwatches-could-become-new-frontier-for-cyber-attackers/d/d-id/1321452