Tuesday, October 31, 2017

FREE - Want to know if the website you are visiting is vulnerable , then you should get this Chrome extension



Vulners Web Scanner lets you Scan websites while you surf internet!






Get it here
https://chrome.google.com/webstore/detail/vulners-web-scanner/dgdelbjijbkahooafjfnonijppnffhmd

Good news - Firefox (v58 - Jan 2018) will add a new feature - BLOCK canvas-browser-fingerprinting





Mozilla is testing a new feature in the upcoming version of its Firefox web browser that will grant users the ability to block canvas fingerprinting.


(Canvas fingerprinting is one of a number of browser fingerprinting techniques of tracking online users that allow websites to identify and track visitors using HTML5 canvas element instead of browser cookies or other similar means.)

The permission prompt that Firefox displays reads:

"Will you allow [site] to use your HTML5 canvas image data? This may be used to uniquely identify your computer."


Once you get this message, it's up to you whether you want to allow access to canvas fingerprinting or just block it. You can also check the "always remember my decision" box to remember your choice on future visits as well.

For More:
https://thehackernews.com/2017/10/canvas-browser-fingerprint-blocker.html

Monday, October 30, 2017

Bug in the Bug tracker - I mean the the bug tracking software itself had a bug that kind of messed up google.


Alex Birsan, a software developer and hobbyist bug-hunter, collected more than $15,000 in bounties for finding this bug and two other unrelated flaws in the Issue Tracker. The most critical of the three vulnerabilities allowed him to manipulate a request to the system that would elevate his privileges and provide him access to every detail about a particular vulnerability.


For More:
https://threatpost.com/flaw-in-google-bug-tracker-exposed-reports-about-unpatched-vulnerabilities/128687/

Friday, October 27, 2017

Patch...Patch...Patch is the simplest advise to protect against any Malware - Patch CHROME today



Google is urging users to update their Chrome desktop browsers to avoid security issues related to a high-severity stack-based buffer overflow vulnerability. Google issued the alert Thursday and said an update for most browsers has been released.

Google is not releasing any details surrounding this stack buffer overflow vulnerability (CVE-2017-15396) stating, “access to bug details and links may be kept restricted until a majority of users are updated with a fix.

For More:
https://threatpost.com/google-patches-high-severity-browser-bug/128661/

Android Phone users watchout for DoubleLocker - As you guessed it locks (after encrypting your Android phone) and demands Ransom




The ransomware has been named DoubleLocker because it performs a two-way action to lock the phone, that is, it encrypts all the files and changes the PIN as well so that victims run out of options and give in to the ransom demands of hackers. The ransomware is being distributed as a fake update of Adobe Flash while compromised websites are being used to spread it.

The fake Adobe Flash app requests for Google Play Services activation because it needs to exploit the phone’s accessibility services

It then starts exploiting the permissions by retrieving Windows content, enabling advanced web accessibility for installation of scripts and monitoring the text that the victim types. When permissions are granted, the ransomware is installed as the default Home app. This means when the user will visit Home screen the next time the ransom note will be there.

For more info:
https://www.hackread.com/new-android-ransomware-permanently-changes-pin-demand-ransom/

Tuesday, October 24, 2017

Is this a temp solution for "Bad Rabbit" Ransomware ?



Performing the following step seems to work like a vaccine , some brave person tested it with a ransomware sample.

(Don't know if it is really works)

===========================
Create the following files
%windir%\infpub.dat
%windir%\cscc.dat
%windir%\infpub.dat
%windir%\dispci.exe

- remove ALL PERMISSIONS (inheritance)
===========================