Monday, October 23, 2017

Have you heard of Windows Defender Exploit Guard (Windows 10 IPS functions)



The four components of Windows Defender Exploit Guard are:

Attack Surface Reduction (ASR): A set of controls that enterprises can enable to prevent malware from getting on the machine by blocking Office-, script-, and email-based threats

Network protection: Protects the endpoint against web-based threats by blocking any outbound process on the device to untrusted hosts/IP through Windows Defender SmartScreen

Controlled folder access: Protects sensitive data from ransomware by blocking untrusted processes from accessing your protected folders

Exploit protection: A set of exploit mitigations (replacing EMET) that can be easily configured to protect your system and applications

More details here:
https://blogs.technet.microsoft.com/mmpc/2017/10/23/windows-defender-exploit-guard-reduce-the-attack-surface-against-next-generation-malware/

Did you know that Windows 10 has a feature that could protect your system from ransomware



Microsoft has now introduced Controlled Folder Access feature in its Windows Defender Security Center that is available for Windows 10 Fall Creators Update (v1709)

By enabling Controlled Folder Access (CFA) on a folder, it will be possible to continuously monitor the changes in the system in real-time and timely identify any unauthorized access. In case an unauthorized process attempts to access that folder, which has been protected with CFA, it will immediately be blocked, and the user will be notified


Follow this How-To Document:
https://www.hackread.com/microsoft-windows-10-anti-ransomware/

Friday, October 20, 2017

Mac Owners - If you installed Elmedia Player or download manager Folx the you should read this



Eltima Software, confessed today the latest versions of those two apps came with an unwelcome extra – the rather horrid OSX.Proton malware

Proton is a remote-control trojan designed specifically for Mac systems. It opens a backdoor granting root-level command-line access to commandeer the computer, and can steal passwords, encryption and VPN keys, and crypto-currencies from infected systems. Its creator also claims that it'll give full access to iCloud, even if two-factor authentication is used and was put on sale in March for $50,000


For More:
https://www.theregister.co.uk/2017/10/20/a_total_system_os_reinstall_is_the_only_guaranteed_way_to_totally_rid_your_system_of_this_malware_this_is_a_standard_procedure_for_any_system_compromise_with_the_affection_of_administrator_account/

Thursday, October 19, 2017

Do you know - Chrome is getting built-in basic antivirus protection for your Windows computer.



ESET scanning engine now built in

"Our engine scans for and cleans potentially harmful applications, specifically the types that negatively impact or target the Chrome browsing experience," said Juraj Malcho, chief technology officer at ESET.

For what it's worth, Chrome, by default, automatically tries to stop software nasties from being accidentally downloaded onto a machine, by checking website URLs against lists of known dangerous and unsafe sites. If you surf to a website known for distributing malware, er, unwanted software, a big red warning will appear in the browser urging you to stop and go back the way you came.

For More Info:
https://www.theregister.co.uk/2017/10/16/chrome_for_windows_malware/

IoT Security - Not many or concerned, For those who are concerned, here a good essay from Mr. Bruce Scheiner



Our biggest IoT security risks will stem not from devices we have a market relationship with, but from everyone else's cars, cameras, routers, drones

Basically, sellers don't compete on safety features because buyers can't efficiently differentiate products based on safety considerations

More here:
https://www.schneier.com/blog/archives/2017/10/iot_cybersecuri.html

Wednesday, October 18, 2017

BoundHook, GhostHook - These are not fishing terms, these are exploits




BoundHook exploits a feature in all Intel chips  -To  cause an exception in a specific memory location in a user-mode context. Next, it is able to catch the exception and gain control over the thread execution used by a specific application. For example, the technique could allow for the interception of a keyboard event message passed between Windows and a specific service, allowing an attacker to capture or manipulate a victim’s keystrokes

GhostHook - Attack method bypassed Microsoft’s attempts to prevent kernel level attacks (via PatchGuard) and used the hooking approach to take control of a device at the kernel level.

Strange but True:
Microsoft and Intel don’t see either as a vulnerability on their end. Both told CyberArk it will not patch the issue because the attack requires that the adversary already has already fully compromised the targeted system


More Here:
https://threatpost.com/boundhook-attack-exploits-intel-skylake-mpx-feature/128517/

Interested in Penetration Testing (I mean Computer related Pen Test ) - Try this site as your starting point


This site has a bunch of

Cheat Sheets
Walk through
Pen Test tools related info


Excellent for Beginers

https://highon.coffee/