Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, October 16, 2008

Malware authors targeting web 2.0 sites

A new malware is doing the rounds of the Internet. Nothing new? Except that, this one uses some nice tricks to try and fool even the most discerning of users. The latest example of a visual social-engineering spam, this e-mail poses as a legitimate Hi5 friend request and is even spoofed to appear as if it has really been sent from the Hi5 domain.

This particular e-mail though is in Spanish. There are various malicious links embedded in the email, which if clicked on, will download a Trojan to your PC and steals confidential logins for a popular Mexican bank. AV detection of this Trojan is very low and hence it is advisable that users keep a close watch ion any such requests they may receive. While this one has only been seen in Spanish, an English version might not be very far off. With the Facebook friend request spam e-mail issue being witnessed just a month ago, it is now clear that Web 2.0 sites too are being increasingly targeted by malware authors.

Via: Websense SecurityLabs

Techtree Link

Saturday, October 4, 2008

Isexplayer & Ipornplayer: Share your story


It's been quite a while since I have written about this topic. But here's why I am going on about this once again. I have seen many hits to this blog of mine with people querying for Ipornplayer and Isexplayer ending up here. I am still wondering why no other web site has covered this rather important piece of news. This also makes me wonder whether what I experienced was just specific to my phone and connection only?

What I wish to know are the real user experiences after they install this suspect piece of software. No doubt, it's NOT a malware, but it sure does trick you in to installing it and all you need to do is "run" it and lo, you're automatic phone calls to unknown international destinations start. At least that is what happened to me -TWICE.

The first time, thanks to my adventurous friend, and the second time for testing purposes. I incurred call charges of more than 25USD just to pay for the services I never availed. Last time I checked, opening an application is NOT accessing a service! Thats correct, I had just opened the application - did not click on any of the links but still, they wanted me to "pay"! And what a nice way to extort money! Call an international premium rate sex line while you're taking a nap. I had as many as 13 calls made in a span of 24 hours before the alarm bells rang and I uninstalled the software.

For those who are not aware of what exactly had happened, my earlier two stories on this piece of software could help. Here are the links for the previous articles.

Initial report

Ipornplayer Update!

I would also like to hear from people who have had this installed and have experienced something weird. I am sure this does not happen with everyone who has this software installed. A friend from Malaysia tried it on his phone and nothing happened. If you have been affected in anyway by this either Isexplayer or the Ipornplayer, please post away your comments or just Shout! using the shoutbox you see on the right.

I would like people to come forward with their experiences with these software. I know it's still out there, Earlier, under the name iSexplayer which disappeared after I broke the story and Ipornplayer making an innocuous come-back just a few days later. What was your experience with Isexplayer/Ipornplayer? Post away!

Tuesday, September 23, 2008

Hack-proof your Network!


Wireless communication is truly getting vulnerable to network hackers. If recent incidents are to go by, terrorists have (mis)used this common vulnerability to safely send their message across -- thanks to an unsecured network waiting to be hacked into. Some tips to keep your network safe from "prying eyes"!


Wireless communication is getting quite vulnerable to network snoopers who capture user IDs, passwords, and other data transmitted across the network. Wi-Fi networks needs to be properly secured to avoid illegal piggybacking of internet services.

An average PC user needs nothing too complicated, no extra features but a real solution that is effective and simple to operate. And it really is simple to "secure" your wireless network. All you need to do is to properly secure your Wi-Fi network through encryption, which encodes the data transmitted between your PC and your wireless router.

It’s a fact that almost all of us may have jumped onto someone else's unsecured Wi-Fi network consciously or inadvertently. It does not make any difference if you're just an scrupulous soul looking out for an Internet connection.However, if you're the owner of an unsecured network, you should be aware that the world's not made up of ethical souls and it's easy for the devious ones to find out what you're doing on your network. Does sound scary, doesnt it? So here's how to fix the problem.

Encryption

The first line of defense for your Wi-Fi network is encryption, which encodes the data transmitted between your PC and your wireless router. Sadly, most routers ship with encryption turned off, and many users don't turn it on, leaving themselves completely exposed. If you haven't already, enable your router's encryption, and use the strongest form supported by your network. The Wireless Protected Access (WPA) protocol and more recent WPA2 have supplanted the older and less-secure Wireless Encryption Protocol (WEP).

Go with WPA or WPA2 if at all possible, since WEP is relatively easy to crack. (You have to use the same form on all devices on your network; you can't mix WEP and WPA.) The keys used by WPA and WPA2 change dynamically, which make them nearly impossible to hack. Use a strong password for your encryption key, such as a combination of letters and numbers of 14 characters or more.

If you have an older router that supports WEP only, you'll be safest if you use 128-bit WEP keys--but also check the manufacturer's Web site for a firmware update that will add WPA support. If it doesn't look like an update is likely, consider replacing old adapters and routers with newer models that support WPA. Look for a router that supports the hybrid WPA + WPA2 mode, which lets you use the stronger WPA2 encryption with adapters that support it, while still maintaining compatibility with WPA adapters.

Make sure you change the default network name and password on your router. Doing so will make it much more difficult for hackers to break into your router and commandeer its settings.

The firewall built into your router prevents hackers on the Internet from getting access to your PC. But it does nothing to stop people in range of your Wi-Fi signal from getting onto your network--and with the latest high-performance equipment, your Wi-Fi signal could reach clear down the block. Without encryption and other protective measures, anyone can use readily available tools to see all your Wi-Fi traffic.

For extra protection, run software firewalls on the individual PCs on your network. Examples include software like Zone Labs' ZoneAlarm, available as a free download..

Since public hotspots generally don't use encryption, you should assume that anyone can see your Internet traffic unless you take precautions. Make sure it's a legitimate hotspot. There are several nefarious types who have set up pirate routers with familiar SSID names like "wayport" or "t-mobile," and then use them to capture unsuspecting users' log-on information and other private data.
Verify that your PC's software firewall is turned on, and that Windows' file-sharing feature is off; it's off by default in Windows XP with Service Pack 2. To check this setting, open Control Panel and choose Windows Firewall (you may have to click Security Center first in XP or Security in Vista). In XP, select the Exceptions tab, and look in the Programs and Services to make sure file and printer sharing is unchecked. In Vista, click Change settings, then select the Exceptions tab and follow the instructions for XP.

The Basics

Never send bank passwords, credit card numbers, confidential e-mail, or other sensitive data unless you're sure you're on a secure site: Look for the padlock icon in the bottom-right corner of your browser, as well as a URL in the address bar that begins with https. Such sites build in their own encryption.

Always turn your Wi-Fi radio off when you're not at a hotspot: Hackers can use it to create peer-to-peer Wi-Fi connections with your computer and access it directly. That should keep your network safe for the time being.

EDIT: Source


Palin hacker Cornered!


Last week, I did blog about Ms .Palins account hack and how easy it turned out to be. Today we have news coming in that the "hacker" turned out to be the one David Kernell who well, happens to be the son of a Tenessee State representative, Mike Kernell.
So thats it. If this is proved, the chaps career, and not to mention, his fathers political career could come to an abrupt halt! Luckily for David, no criminal charges have been filed as yet. The FBI did search Davids room and have questioned his room mates as well. Now you know why you don't want to be a hackers friend! To be frank, I do feel pity for the poor chap.. the dude just chose the wrong ID to hack. Sigh!

Thursday, August 14, 2008

Suburban ticketing system hacked: Security concerns loom

In this age of terrorism and cyber crime, here is one more news that could send security analysts and researchers in a tizzy.

A bunch of young researchers at Radboud University Nijmegen, Netherlands have managed to crack the ticketing system used by major suburban transportation systems around the world. The chip in question is called the “MiFare” and is manufactured by NXP Semiconductors. Generally considered very safe, the system is being used by transit solutions in cities around the world – including Delhi, where it is used in the Metro Railway. Apart from suburban rail networks, MiFare cards are also to control access to buildings.

The researchers claim that the proprietary CRYPTO1 encryption system used by these cards can be easily retrieved, especially when a common key is used for all RFID (Radio-frequency identification) readers and cards. Common keys are used on a large scale in large buildings and organizations. The hack itself is a simple affair, at least theoretically. What the hack does is to retrieve the secret key from the Mifare reader, which takes a while. Once the key is retrieved, the data is taken offline and then decrypted -once this is done, the cracked key can be used to predict other random keys as well. The retrieved cryptographic key can provide various possibilities for abuse depending on the situation. For example, if all the cards share the same key, the card of a genuine employee/personnel can be cloned just by close contact and the affected person might not be even aware that his identity has been stolen.In case different keys are used, things become a lot more safer – but it still remains vulnerable.


Earlier, two German researchers Karsten Nohl en Henryk Plötz had also reported security flaws with the technology. These two had actually managed to reconstruct CRYPT01 and had announced about the same at a hackers conference back in 2007. The Dutch team however did not replicate the encryption system – they simply exploited the weaknesses in the armour. This had happened in March 2008, and the news was immediately not revealed owing to concerns regarding security. The Dutch Government was involved and and kept in the loop. Later, the Dutch General Intelligence and Security Service confirmed that the hack was as effective as an attack. Post this, the companies involved; NXP and Trans Link Systems were briefed and technical representatives from the company are working with the researchers to analyse the impact of the security breach – and to develop countermeasures to patch the weaknesses.

The researches cited security concerns for the delay in reporting this security flaw. They also wanted to ensure basic steps are taken to counter the vulnerability before the flaws are discussed in the open.

More on this can be read here



A video by the team:

Friday, July 25, 2008

First Isexplayer. Now Ipornplayer

If you folks recall, I did report about the Isexplayer here earlier. It is the first software exhibiting malware like behavior for Series 60 third edition devices. A software which dials premium rate phone numbers automatically taking advantage of a well hidden license agreement where it does says it will make calls.

Interestingly, after the story broke, the sisx version of the file disappeared from the website and only a java version was available for download. This version is supposedly safer than its symbian counterpart. Now, it seems the sis version is back –albeit under a new name Ipornplayer. The older (Java) version is still available for download on the same URL as earlier. The new Sis file is however on a different – but identical looking URL.

At this moment, I cannot confirm if the application behaves as it used to earlier. It does however have the same license agreement so I do think it’s the same thing repackaged.

Some Screenshots.. er I have edited the images on the screenshot of the webpage for obvious reasons.



EDIT: Removed a screenshot as it showd the link.


UPDATE:Had asked one of my friends to check if the behaviour persists. He tested it for two days and found nothing wrong. Installed the software earlier today on my phone and the first automatic call was made a few minutes ago. So as far as I am concerned the threat sill exists. The license agreement clearly states the call will be made. So they are legally correct.

Further investigation revealed that there are various versions of this software going by the MD5 values. Some thing certainly sounds fishy!


A screenshot of the call log: