Thursday, December 14, 2017

what is wrong with this web page belonging to NatWest Bank

 (Hint - Starts with "Not")




For More:
http://www.bbc.co.uk/news/technology-42353478

Have you enabled MFA for your account? - Because, someone found 1.4 billion usernames and passwords in clear text


The collective database contains plain text credentials leaked from Bitcoin, Pastebin, LinkedIn, MySpace, Netflix, YouPorn, Last.FM, Zoosk, Badoo, RedBox, games like Minecraft and Runescape, and credential lists like Anti Public, Exploit.in.


"None of the passwords are encrypted, and what's scary is that we've tested a subset of these passwords and most of the have been verified to be true," Casal said


For More:
https://thehackernews.com/2017/12/data-breach-password-list.html

ROBOT attack? - Not the Isaac Asimov Kind, its around Encryption



ROBOT - Return of Bleichenbacher’s Oracle Attack

Bleichenbacher’s attack was first discovered in 1998

Studies uncover that probably the most well-known sites on the Internet, including Facebook and Paypal, are influenced by the ROBOT attack.


For More:
http://www.hackersnewsbulletin.com/2017/12/robot-attacks-rediscovered.html

Friday, December 8, 2017

Is it Cayla doll or should we call it Creepy doll?




It turns out that anybody located within nine meters of the toys, outside a building, can wirelessly pair a mobile phone to the toys through Bluetooth, without having to log in. It can be done without inputting a PIN code, and you don’t have to press any kind of button on the toy

Apparently, if you then make a call to the phone that’s sneakily paired with the toy, what you say into the calling phone will be relayed to the toy by the called phone, which effectively gives two-way conversation.


For More:
https://nakedsecurity.sophos.com/2017/12/06/cayla-doll-too-eavesdroppy-to-put-under-the-christmas-tree-says-france/

Thursday, December 7, 2017

What the security folks always feared - Memory based Malware (No Files) - Process Doppelgänging (poc)



Process Doppelgänging -  Works on All Windows Versions

Attack works on all modern versions of Microsoft Windows operating system, starting from Windows Vista to the latest version of Windows 10.

According to the researcher, Process Doppelgänging is a fileless attack and works in four major steps as mentioned below:


  1. Transact—process a legitimate executable into the NTFS transaction and then overwrite it with a malicious file.
  2. Load—create a memory section from the modified (malicious) file.
  3. Rollback—rollback the transaction (deliberately failing the transaction), resulting in the removal of all the changes in the legitimate executable in a way they never existed.
  4.  Animate—bring the doppelganger to life. Use the older implementation of Windows process loader to create a process with the previously created memory section (in step 2), which is actually malicious and never saved to disk, "making it invisible to most recording tools such as modern EDRs."



For More:
https://thehackernews.com/2017/12/malware-process-doppelganging.html

Bank Of America, HSBC or TunnelBear customers may want to take a look at this


Researchers from the UK have uncovered a serious vulnerability in the way nine banking and VPN apps handle encrypted communication that puts tens of millions of users at risk of man-in-the-middle (MitM) attacks

"Our tests find that apps from some of the world's largest banks contain the flaw, which if exploited, could enable an attacker to decrypt, view and modify traffic - including log-in credentials - from the users of the app," write Chris Mcmahon Stone, Tom Chothia, and Flavio Garcia of University of Birmingham

For More:
https://www.darkreading.com/mobile/man-in-the-middle-flaw-in-major-banking-vpn-apps-exposes-millions/d/d-id/1330586?_mc