Friday, May 29, 2015

Create a Ransomware in three easy steps - No knowledge of hacking (or even programming) is needed.



Apparently it is free ( I wonder why? )

It is called TOX


From the Article:

  • Tox is free. You just have to register on the site.
  • Tox is dependent on TOR and Bitcoin. That allows for some degree of anonymity.
  • The malware works as advertised.
  • Out of the gate, the standard of antimalware evasion is fairly high, meaning the malware’s targets would need additional controls in place (HIPS, whitelisting, sandboxing) to catch or prevent this.


Once you register for the product, you can create your malware in three simple steps.
  1. Enter the ransom amount. (The site takes 20% of the ransom.)
  2. Enter your “cause.”
  3. Submit the captcha.


Follow this link for more information:

Tuesday, May 26, 2015

Have you ever used words "MOOSE" and "WORM" in a single sentence - Now you can "Moose - Router Worm"



Interesting, it can even eradicate existing Malware 
I remember this use to happen during the "virus era"

Good news is it exploits the lazy users meaning,  poor configuration / weak credentials.





From the Article:

Moose worm does not rely upon amy underlying vulnerability in the routers – it is simply taking advantage of devices that have been weakly configured with poorly chosen login credentials.

The principal victims are likely to be routers – with devices from Actiontec, Hik Vision, Netgear, Synology, TP-Link, ZyXEL, and Zhone already identified as vulnerable

ESET’s team observed the worm creating bogus accounts on sites such as Instagram, and automatically following users. In many cases the rise in followers was carefully staggered over some days, seemingly to avoid raising alarms in automated systems built by the social networks to identify suspicious behaviour.

As well as social networking fraud, ESET’s paper considers that the malware could potentially be used for other activities – such as distributed denial-of-service attacks, targeted network exploration (where it works hard to dig deep past firewalls) and eavesdropping and DNS hijacking (which could lead itself to phishing and further malware attacks).


More here

Thieves steal tax info from IRS



Anyone surprised?

Testing the software/code is more important than writing code.
(Anyone listening?)



From the Article:

In a statement Tuesday, the IRS said the thieves accessed a system called "Get Transcript." In order to access the information, the thieves cleared a security screen that required knowledge about the taxpayer, including the Social Security number, date of birth, tax filing status and street address.





More here

Security Researcher detects vulnerability - And Starbucks considers it FRAUD?


But, it also claims that it fixed this issue after being informed by this researcher.


From the Article:

Egor Homakov of the Sakurity security consultancy found a weakness known as a race condition in the section of the Starbucks website responsible for checking balances and transferring money to gift cards. To test if an exploit would work in the real world, the researcher bought three $5 cards. After a fair amount of experimentation, he managed to transfer the $5 balance from card A to card B, not just once as one would expect, but twice. As a result, Homakov now had a total balance of $20, a net—and fraudulent—gain of $5.

The researcher went on to visit a downtown San Francisco Starbucks location to make sure his attack would actually work. He used the two cards to make a $16.70 cent purchase. He went on to deposit an additional $10 from his credit card "to make sure the US justice system will not put us in jail over $1.70," he explained in a blog post.


"It was just completely uncalled for claiming that I committed fraud," Homakov said of the latter call. "It made me angry."

More here

Friday, May 22, 2015

DOJO - Free web Application Security penetration testing. Tools + Targets + documentation (what els do you need? free beer, maybe)




What more can you ask for

This removes the possibility of remote attack on the targets, which are insecure by design. The Dojo contains everything needed to get started – tools, targets, and documentation.



Everything You need is here
https://www.mavensecurity.com/web_security_dojo/

Thursday, May 21, 2015

Information beloging to Million+ customers handed over to hackers ( I mean not voluntarily) - I think I have heard this name (Blue Cross Blue Shield) name a few times before



Of course, if handed over voluntarily , it would be called insider theft.
If the external part gets hold of it , it would be called "being hacked". However, the word "hacked" somehow implies that the data was stolen by passing some complicated security controls.

Could it be that the company had shabby Security

OR

Just spent  a lot of money without having a "common sense" security approach?



However , there is one small gain
CareFirst is offering two years of free credit monitoring so, if you are one of the affected ones, take advantage of this offer.


From the Article

Attackers gained access to a single company database containing the sensitive and personal information of more than a million of its current and former health insurance customers. 


In an effort to downplay the attack, CareFirst CEO Chet Burrell and other spokespersons are claiming that Social Security numbers, medical claims, employment, payment card and financial information were not exposed in the breach. 

CareFirst claims it initially detected the attack but incorrectly believed it had contained the attack and prevented the attackers from accessing any information. It only became aware of the full scope of the attack after hiring an incident response firm to perform a network analysis 


For more info:

Wednesday, May 20, 2015

Patch Your Watch - Does it sound funny?



Not if you are wearing a computer that calls itself a watch


From the Article

Among the other bugs fixed in Watch OS 1.01 are eight separate kernel vulnerabilities. A couple of those flaws can allow an attacker to cause a DoS, while others can give an attacker elevated privileges. There also is a potential code-execution vulnerability in the kernel.



For more details:
https://threatpost.com/apple-releases-patches-for-a-watch/112920