Monday, October 16, 2017

I thought one cannot calculate a private Key from public key. I was wrong



In a nutshell, the bug (in Infineon Technology chipset) makes it possible for an attacker to calculate a private key just by having a target’s public key.


The Infineon flaw is tied to a faulty design of Infineon’s Trusted Platform Module (TPM), a dedicated microcontroller designed to secure hardware by integrating cryptographic keys into devices and used for secured crypto processes.

The currently confirmed number of vulnerable keys found is about 760,000 but possibly up to two to three magnitudes more are vulnerable


For More:
https://threatpost.com/factorization-flaw-in-tpm-chips-makes-attacks-on-rsa-private-keys-feasible/128474/

KRACK ATTACK - Welcome to Monday morning mania




The idea behind a key reinstallation attack can be summarized as follows. When a client joins a network, it executes the 4-way handshake to negotiate a fresh encryption key. It will install this key after receiving message 3 of the 4-way handshake. Once the key is installed, it will be used to encrypt normal data frames using an encryption protocol. However, because messages may be lost or dropped, the Access Point (AP) will retransmit message 3 if it did not receive an appropriate response as acknowledgment. As a result, the client may receive message 3 multiple times. Each time it receives this message, it will reinstall the same encryption key, and thereby reset the incremental transmit packet number (nonce) and receive replay counter used by the encryption protocol.

 We show that an attacker can force these nonce resets by collecting and replaying retransmissions of message 3 of the 4-way handshake. By forcing nonce reuse in this manner, the encryption protocol can be attacked, e.g., packets can be replayed, decrypted, and/or forged. The same technique can also be used to attack the group key, PeerKey, TDLS, and fast BSS transition handshake.

If the victim uses either the WPA-TKIP or GCMP encryption protocol, instead of AES-CCMP, the impact is especially catastrophic. Against these encryption protocols, nonce reuse enables an adversary to not only decrypt, but also to forge and inject packets. Moreover, because GCMP uses the same authentication key in both communication directions, and this key can be recovered if nonces are reused, it is especially affected. Note that support for GCMP is currently being rolled out under the name Wireless Gigabit (WiGig), and is expected to be adopted at a high rate over the next few years


For more info:
https://www.krackattacks.com/

Friday, October 13, 2017

To Trust or NOT to Trust is the dilemma



The Facebook scam abuse “Trusted Contacts, ” a Facebook account recovery feature that sends access codes to a selected list of trusted user’s friends in order to help you regain access to their Facebook account in case you forget your password or lost access to your account.


For More
http://securityaffairs.co/wordpress/64276/cyber-crime/facebook-scam-trusted-contacts.html?

Thursday, October 12, 2017

Did you know GDPR Applies to the entire world , not just Europe



GDPR that goes in effect 25 May, 2018, states that any organization that handles the personally identifiable information of any living EU resident must protect that information. If that information is breached, that organization must report the incident and notify those individuals.



Excellent SANS Doc:
https://www.sans.org/reading-room/whitepapers/analyst/preparing-compliance-general-data-protection-regulation-gdpr-technology-guide-security-practitioners-37667#


For More Info:
https://securingthehuman.sans.org/blog/2017/10/10/hey-america-and-world-gdpr-applies-to-you-to

If you are Netflix subscriber , you may want to read this



It begins with a mail purporting to be from the streaming giant, asking for an account update. Once the victim enters their Netflix credentials on a spoofed website, they are redirected to a second screen, which harvests the victim’s credit card credentials. The final step shows a thank-you message, where clicking the “Get Started” button takes visitor to Netflix.com, meaning that they could remain blissfully unaware that they’ve been phished for quite some time.

PhishMe’s analysis found that the email address associated with the campaign has been involved in the use of five different phishing toolkits since June, targeting customers of Chase Bank, Comcast, Netflix, TD Bank and Wells Fargo. But business users can be at risk as well


More Here:
https://www.infosecurity-magazine.com/news/netflix-phish-corporate-dangers?utm_source=twitterfeed&utm_medium=twitter

New Service from Equifax - Free Flash update Offer (Thanks to Hackers)




Equifax website was compromised (again) to deliver Fraudulent Adobe Flash updates.

Data breach not enough, now they have website compromise.



For several hours on Wednesday, and again early Thursday morning, the site was maliciously manipulated again, this time to deliver fraudulent Adobe Flash updates, which when clicked, infected visitors' computers with adware that was detected by only three of 65 antivirus providers

More Here:
https://arstechnica.com/information-technology/2017/10/equifax-website-hacked-again-this-time-to-redirect-to-fake-flash-update/


Wednesday, October 11, 2017

What could happen when you misconfigure Amazon S3 buckets? - Data Breach - 150K PHI records exposed


New development in "Data Exfiltration" is that there is an increased data staging within cloud infrastructures prior to exfiltration

Imagine a commercial mover putting your furniture into a moving van,” Mayfield explained. “No shock here, that seems like normal asset movement. But then, an accomplice walks up to the fully loaded van, key in the ignition, and drives away. This is not a perfect analogy, but it gets very close to the data staging and exfiltration that happens with cloud infrastructure


For More:
https://www.infosecurity-magazine.com/news/med-records-for-150k-americans