FN SECURE: Cyber Threat

Call Us For Workshops Or Seminars.. In Your University, Colleges, or Schools.
Email Us At : vicky@globallyunique.in

Save as PDF
Showing posts with label Cyber Threat. Show all posts
Showing posts with label Cyber Threat. Show all posts

More than 24 News websites Hacked Today : 30 March

youtube-image.n.jpg (370×277)


Wow What a Day It was!!
And suddenly You get up and hear a news that more than 24 news websites have been hacked Tonight!!

Its a group of Pakistani hackers, who pretends to be tired of having repeted news from Indians professional and other students.

"They pretend to carry on hacking all the major news website of India. And tend to go for more extended and powerful Targets Like "NDTV India, AAJ",etc.

Read more

Facebooks' Current Threats..


This is a very serious threat that one has implemented with a use of php and a perl script, since php script is obviously hidden into the server, it is hard to check what the programmer has actually done, so that facebook owner can rectify and block this as soon as possible.
If Any one of you find anythin like this, please report it to the facebook report abuse terms.

Read more

Manila AT&T hackers linked to 26/11 Mumbai terror attack



Police in the Philippines working with the US Federal Bureau of Investigation have arrested four people over a premium-line phone scam that targeted customers of the American telecommunications giant AT&T to funnel money to a Saudi-based militant group.

These four suspected hackers accused of funnelling profits from attacking corporate telephone networks to an Islamic terrorist group blamed for the attacks on Mumbai three years ago. The four suspects allegedly targeted PBX systems maintained by AT&T and gained access to corporate phone lines that they resold at a profit to call centres. The low-level scam resulted in estimated losses of $2m and ran between at least October 2005 and December 2008, and possibly earlier.The operation was allegedly financed by Jemaah Islamiyah, a proscribed Pakistani terrorist organisation blamed for the terrorist attack in Mumbai, India, in November 2008.

FBI declined to give official details of how the group took the money, one person familiar with the situation said that the hackers broke into the phone systems of some AT&T customers and made calls to international premium-rate services whose payments would be diverted.

The four allegedly worked for a group originally run by Muhammad Zamir, a Pakistani arrested by the FBI in 2007 who was associated with Jemaah Islamiah, a Southeast Asian militant group with links to Al Qaeda."Zamir's group, later tagged by the FBI to be the financial source of the terrorist attack in Mumbai, India, on November 26, 2008, is also the same group that paid Kwan's group of hackers in Manila," Police Senior Superintendent Gilbert Sosa said in the statement.

Reuters also reported the Philippine police had said last month that weak laws against cyber crime and poor technical capabilities had made the country an attractive base for organized crime syndicates involved in online pornography, sex dens, illegal gambling, credit card fraud and identity theft.

Read more

New Apache Reverse Proxy Flaw Allows Access to Internal Network



Apache acknowledged another reverse proxy issue (CVE-2011-4317) which was discovered by Apache developer from Red Hat while creating a QualysGuard vulnerability signature for an older problem CVE-2011-3368. Depending on the reverse proxy configuration, the vulnerability could allow access to internal systems from the Internet.

In order to set up Apache HTTPD to run as a reverse proxy, server administrators use specialized modules like mod_proxy and mod_rewrite. Apache developers are working on a fix of a flaw in its web server software that creates a possible mechanism to access internal systems.The zero-day vulnerability only rears its ugly head if reverse proxy rules are configured incorrectly and is far from easy to exploit, but it is nonetheless nasty.

The problem isn't new and a vulnerability that allowed similar attacks was addressed back in October. However, while reviewing the patch for it, Qualys researcher Prutha Parikh realized that it can be bypassed due to a bug in the procedure for URI (Uniform Resource Identifier) scheme stripping. The scheme is the URI part that comes before the colon ":" character, such as http, ftp or file.One relatively common rewrite and proxying rule is "^(.*) http://internal_host$1", which redirects the request to the machine internal_host. However, if this is used and the server receives, for example, a request for "host::port" (with two colons), the "host:" part is stripped and the rest is appended to http://internal_host in order to forward it internally.The problem is that in this case, the remaining part is ":port", therefore transforming the forwarded request into http://internal_host:port, an unintended behavior that can result in the exposure of a protected resource.In order to mitigate the problem server administrators should add a forward slash before $1 in the rewrite rule, the correct form being "^(.*) http://internal_host/$1", Parikh said.

Parikh has published a detailed explanation of the flaw alongside proof of concept code in a post on the Qualys blog here. A possible patch for the vulnerability was suggested by an Apache developer from Red Hat on Wednesday but has yet to be fully tested.

Read more

Your Android Phone is Spying On You, Use custom ROM To Protect your Privacy






In this digital age, privacy is more important than ever. Just because you “don’t have anything to hide,” does not mean that you shouldn’t value your privacy or fight for it when companies do things like this, especially with something as personal as your cell phone.





An Android developer recently discovered a clandestine application called Carrier IQ built into most smartphones that doesn't just track your location; it secretly records your keystrokes, and there's nothing you can do about it. Is it time to put on a tinfoil hat? That depends on how you feel about privacy. In the nearly 20-minute video clip, Eckhart shows how software developed by mobile-device tracker Carrier IQ logs each keystroke and then sends them off to locations unknown. In addition, when Eckhart tried placing a call, Carrier IQ's software recorded each number before the call was even made.

What is Carrier IQ, exactly?

The software is hidden inside phones there is little you can do to detect that it’s even installed, let alone remove it, and it tracks everything. Keystrokes, browsing and surfing habits, Google searches, and basically every single thing that you are doing on your phone and every button that you press is logged by this software. Jump to 9:00 in the YouTube video below for the proof this is basically a keylogger running on your phone that you didn’t know about.


The company that’s creating this software claims that the point of the software is to deliver “analytics” about devices to the carriers to help them provide better service to their users. But is recording every keystroke really necessary for that information? Does not telling the users about this and making it near-impossible to opt out seem a bit fishy to anybody else? This software is on almost all Android phones made by the big names (HTC, Samsung, Motorola), and is even on BlackBerries and Nokia devices, as well.



"Our action was misguided and we are deeply sorry for any concern or trouble that our letter may have caused Mr. Eckhart," the company said in response to the EFF's letter. "We sincerely appreciate and respect EFF's work on his behalf, and share their commitment to protecting free speech in a rapidly changing technological world."


But Eckhart's new video seems to refute at least some of those claims. In one part of the clip, he shows how an entire SMS message--"hello world"--was recorded by Carrier IQ's software. In another example, he demonstrates how a Google search, his location, and other key information is recorded by Carrier IQ's application, even though he was on Wi-Fi and a page secured by HTTPS.



HTTPS? Nothing Is Safe From Carrier IQ
For those unaware, the S in HTTPS stands for secure. It's what keep your passwords and other sensitive data safe when sent across the web. It's provides encryption for said information, so whilst it's traveling through the airwaves, it's safe and snuggly, away from the awful people who want to steal your info.



Just because a website is using a secure connection doesn't mean it's one-hundred percent safe from end-to-end, though. You see, some information, including usernames and passwords, can still be sent plain text. For example, the username and password can be used in the address of the site, like www.mysite.com?username=MYNAME&password=MYPASS (Trev's example). Sure, it's encrypted while going down the tunnel, but guess who gets to see the raw link? Did you guess Carrier IQ? If so, go get yourself a cookie. You earned it. [Source]


Carrier IQ says in this public statement that it is “not logging keystrokes or providing tracking tools” and that its software is used to track performance, but the video proves entirely otherwise: this app is sitting in between you and the Android OS and is making a note of everything you do. Secure websites don’t help. Even using Wi-Fi doesn’t help. Your phone use is being logged by this software, and there is no way to easily opt out.

Devices Without a Cellular Network Aren't Safe, Either
Let's think about the name of this thing for a minute - Carrier IQ. So, it's probably safe to say that this is all about the carriers, right? If that were true, then why would CIQ remain active once a device no longer has carrier service?


Let me back up for one second, CIQ claims that its services are stopped the second the SIM card is removed from the device, which is all fine and dandy... if you're on a GSM network. Those of us on CDMA networks aren't so lucky, though, because we don't use SIM cards. Thus, even when a device is deactivated from its network, it continues to send data back to the carrier, CIQ, and whoever else whenever you're on a Wi-Fi connection.


Ensure your Privacy : Use custom ROM To Protect your Privacy
Unfortunately, there is no easy way to protect yourself. There’s no switch that you can turn off in the settings of your phone or software that appears in your app drawer that you can simply uninstall. As far as the GUI of your phone is concerned, Carrier IQ isn’t even there. But it is there, hiding in the background, making sure that you don’t even know it exists. And for many, that’s just not cool. Your phone is a deeply personal device and contains lots of things (emails, photos, text messages) that many would consider totally private. Why should this company have access?



Best way, root your phone and there are many guides available for the different devices. The best place to look for information on rooting is the XDA Forum. Search on the page for your phone name and go to the “General” forum for the device. There, you should find threads with guides on how to root and get the phone ready to install custom ROMs. The process varies widely phone by phone, so we can’t give you a definitive guide here, but XDA is generally on top of the best rooting processes for the major devices.The next step is to find a ROM that supports your device that does not have Carrier IQ installed on it. Your best bet is to look for “AOSP” or “Vanilla” ROMs. These are versions of Android that have built entirely from the open source code for Android that’s released by Google each time a new version comes out. These ROMs will be free from carrier and device manufacturer tinkering, and won’t have Carrier IQ hiding in the background.

Another great custom ROM solution is Cyanogenmod. Cyanogenmod has some nice additional tweaks and features above stock Android, and is definitely the most well respected and most frequently updated custom ROM out there. Additionally, it’s available on most popular Android devices out there. The developers are even working hard on the next version, based on Android 4.0, Ice Cream Sandwich.

A simple Guide : How To Install CyanogenMod 7 On Samsung Galaxy S II Using ROM Manager is Available here.

Read more

Android facial recognition based unlocking can be fooled with photo





Another Android Feature Exploited, Funny that Android facial recognition based unlocking can be fooled with photo . Check out the video below, courtesy of Malaysia’s SoyaCincau :

He said "While some of you think that it is a trick and I had set the Galaxy Nexus up to recognise the picture, I assure you that the device was set up to recognise my face. I have a few people there watching me do the video and if any one of them is watching this video I hope you can confirm that this test is 100% legit.".

Read more

myOpenID XSS : One of the Largest OpenID provider is Vulnerable




One of the One of the Largest Independent OpenID provider "myOpenID" is Vulnerable to Cross Site Scripting (XSS) ,Discovered by "SeeMe" - Member of Inj3ct0r Team. Cross Site Scripting (or XSS) is one of the most common application-layer web attacks.


What Hacker can do - "The attackers can steal the session ID of a valid user using XSS. The session ID is very valuable because it is the secret token that the user presents after login as proof of identity until logout. If the session ID is stored in a cookie, the attackers can write a script which will run on the user's browser, query the value in the cookie and send it to the attackers. The attackers can then use the valid session ID to browse the site without logging in. The script could also collect other information from the page, including the entire contents of the page".

Proof Of Concept - Click Here

Read more

Most advanced and dangerous malware for Apple products - Why you should be concerned !




Indian security researcher from MalCon has created an advanced and dangerous malware for Apple products which can not only compromize your privacy but also steal important data and let hackers control your device by simple text messages.

If you are using any Apple product such as iPhone, iPad or iPod, then you shuuld be concerned. Indian security researcher from MalCon, Atul Alex has created an advanced malware for the Apple products which can not only intercept calls of users, steal data, but also provide a reverse VNC to see remotely all the actions of the victim.
The malware can be deployed remotely over the web and is supposed to work on the latest iOS 5. Atul Alex, Technical director of MalCon said "Apple products are extremely secure by design. The malware works on jailbroken devices - something which over 90% of users have. If your device is not jailbroken, you have nothing to worry about!".

However, over 90% of users normally jailbreak their devices. iOS jailbreaking, or simply jailbreaking, is the process of removing the limitations imposed by Apple on devices running the iOS operating system through use of custom kernels. Such devices include the iPhone, iPod Touch, iPad, and 2nd Gen Apple TV. Jailbreaking allows users to gain root access to the operating system, allowing iOS users to download additional applications, extensions, and themes that are unavailable through the official Apple App Store. A jailbroken iPhone, iPod Touch, or iPad running iOS can still use the App Store, iTunes, and other normal functions, such as making telephone calls.

The malware malware boasts of the following features:
• Control devices by SMS
• Invisible Malware
• VNC Server to view remote screen
• Record and listen to all calls remotely
• Upload / Download user Data
• Access all mails and texts

The Malware will be demonstrated next month at the upcoming International Malware Conference, MalConin Mumbai, India. The researcher Atul Alex has previously coded and demonstated a custom malicious firmware for Symbian last year.

Read more

Win32/EyeStye


 
Alert level 

Win32/EyeStye 


Aliases
  • SpyEye (other)

Alert Level 
Severe 

Antimalware protection details
Microsoft recommends that you download the latest definitions to get protected.



Summary

Win32/EyeStye is a family of trojans that attempts to steal sensitive data, such as login credentials, and sends it to a remote attacker. In order to perform this payload it utilizes a method known as "form grabbing". Win32/EyeStye may also download and execute arbitary files, such as updates of its components and may utilize  a rootkit component in order to hide its malicious activity from the affected user.

Symptoms

System changes
The following system changes may indicate the presence of this malware:
  • The presence of the following files:

    cleansweep.exe
    windowseep.exe
    collectors.txt
    webinjects.txt
  • The presence of the following registry modifications:

    In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
    Sets value: "EnableHttp1_1"
    With data: "1"
    In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    Sets value: "1409"
    With data: "3"
    In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
    Sets value: "1409"
    With data: "3"
    In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
    Sets value: "1409"
    With data: "3"
    In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
    Sets value: "1409"
    With data: "3"
    In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
    Sets value: "1409"
    With data: "3"
    In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
    Sets value: "1406"
    With data: "0"
    In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
    Sets value: "1406"
    With data: "0"
    In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
    Sets value: "1406"
    With data: "0"
    In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
    Sets value: "1406"
    With data: "0"
    In subkey: HKCU\Software\Microsoft\Internet Explorer\PhishingFilter
    Sets value: "EnabledV8"
    With data: "0"
    In subkey: HKCU\Software\Microsoft\Internet Explorer\Recovery
    Sets value: "ClearBrowsingHistoryOnExit"
    With data: "0"
Technical Information (Analysis)
Prevention
Win32/EyeStye is a family of trojans that attempts to steal sensitive data, such as login credentials, and sends it to a remote attacker. In order to perform this payload it utilizes a method known as "form grabbing". Win32/EyeStye may also download and execute arbitary files, such as updates of its components and may utilize a rootkit component in order to hide its malicious activity from the affected user.
Installation
This malware may be installed by TrojanDropper:Win32/EyeStye. When run, the trojan creates one of the following mutex names to ensure only one instance of the malware executes:
  • __SPYNET__
  • __CLEANSWEEP__
In the wild, we have observed the trojan dropping files in the directory in which it is executed. It may create a hidden top-level directory, using the following format:
  • \<file name>\<file name>.exe
Where <file name> may be, but is not limited to, the following:
  • cleansweep.exe
  • windowseep.exe
For example, cleansweep\cleansweep.exe.
The registry is modified to run the malware at each Windows start.
In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Sets value: "<Win32/EyeStye file name>" (for example "syscheckrt.exe")
With data: "<path and file name of Win32/EyeStye>" (for example "c:\syscheckrt\syscheckrt.exe")
or
In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Sets value: "<random key>"
With data: "<path and file name of Win32/EyeStye>" (for example "c:\syscheckrt\syscheckrt.exe")
The trojan also creates an encrypted configuration data file named "config.bin" in the malware folder. The configuration file contains the following files:
  • collectors.txt - contains the IP address of the remote server used to collect captured data
  • webinjects.txt - contains rules on how web traffic should be filtered
The configuration data file may also contain various "plugins" that are utilized to make up the malware's payload. This may include, the following:
  • Backdoor functionality (either through RDP or a Socks5 proxy) allowing unauthorized access and control of the affected computer
  • Jabber notification to the malware author of new infections
  • Specific connections to use for transmission of stolen information to a remote attacker
  • The ability to grab certificates from Firefox
  • FTP functionality
Win32/EyeStye injects its payload into all currently running processes while avoiding the following processes:
  • smss.exe
  • csrss.exe
  • services.exe
  • System
  • <Win32/EyeStye process>
Payload
Lowers browser security zone settings
The malware modifies registry data that lowers browser security for Internet Explorer:
In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
Sets value: "EnableHttp1_1"
With data: "1"
In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
Sets value: "1409"
With data: "3"
In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
Sets value: "1409"
With data: "3"
In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
Sets value: "1409"
With data: "3"
In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
Sets value: "1409"
With data: "3"
In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
Sets value: "1409"
With data: "3"
In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
Sets value: "1406"
With data: "0"
In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
Sets value: "1406"
With data: "0"
In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
Sets value: "1406"
With data: "0"
In subkey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
Sets value: "1406"
With data: "0"
In subkey: HKCU\Software\Microsoft\Internet Explorer\PhishingFilter
Sets value: "EnabledV8"
With data: "0"
In subkey: HKCU\Software\Microsoft\Internet Explorer\Recovery
Sets value: "ClearBrowsingHistoryOnExit"
With data: "0"
Modifies Mozilla Firefox settings
The malware modifies the following settings for the web browser Mozilla Firefox:
  • Disables safe browsing
  • Disables malware blacklist check for downloads
  • Disables alerts
  • Disables clearing cookies and sessions
Uses stealth
Win32/EyeStye hooks the following APIs to prevent affected users from seeing malware files or system modifications with Windows Explorer, within a command prompt, or within the registry:
  • NtEnumerateValueKey
  • ZwEnumerateValueKey
  • NtQueryDirectoryFile
  • ZwQueryDirectoryFile
  • NtVdmControl
  • ZwVdmControl
Exports imported certificates
The malware hooks the "crypt32.dll" API "PFXImportCertStore" to make all imported certificates exportable.
Captures sensitive information
Win32/EyeStye hooks the following Windows APIs to steal authentication information and alter web content presented to the user:
  • HttpAddRequestHeadersA
  • HttpOpenRequestA
  • HttpSendRequestW
  • HttpQueryInfoA
  • InternetQueryDataAvailable
  • InternetReadFile
  • InternetReadFileExA
  • InternetCloseHandle
  • InternetQueryOptionA
  • InternetWriteFile
The following Firefox APIs are also hooked for the same purpose:
  • PR_Read
  •  PR_Write
  •  PR_Close
  •  PR_OpenTCPSocket
  •  PR_GetSocketOption
  •  PR_SetSocketOption
  •  PR_GetError
  •  PR_SetError
It hooks the following APIs to take screenshots of the affected computer:
  • GdipSaveImageToStream
  • GdipSaveImageToFile
  • GdipCreateBitmapFromHBITMAP
  • GdiplusShutdown
  • GdiplusStartup
Bypasses SSL
Win32/EyeStye hooks the API "CryptEncrypt" to intercept SSL traffic. If the security program Trusteer Rapport is running, the malware returns an error "NTE_NO_MEMORY" so that plain authentication is used.
Sends captured data to a remote server
The trojan attempts to send captured data via HTTP post to a remote server. In the wild, we have observed this trojan connecting to the following remote servers:
  • microsoft-windows-security.com (not a Microsoft.com domain)
  • vinodelam.net
  • overclock.osa.pl
  • qualitaetvorun.org
  • svetodioduk.net
  • rtjhteyjtyjtyj.orge.pl
  • airiston.net
  • superboy999.ru
  • vertime.ru
  • bettasbreed.co.cc
  • nusofttechnologies.info
  • svetodioduk2.com
  • fieldsoflove.cc
  • fightforce.cc
  • totalhidden.cc
  • feldmar.ru
  • lyambosok.ru
  • picomarkets.ru
  • primedyl.com
  • domain391.org
  • securegateonline.com
  • reg.kygalu.ru
  • domain191.org
  • black-hosting.ru
  • hfhfhfhfee.com
While sending captured data, it may include the following additional information:
  • "Bot guid" - unique identifier associated with the trojan
  • User name
  • Computer name
  • Volume serial number
  • Process name associated with captured data
  • Name of hooked API function (for example PR_Write)
  • Captured raw data
  • Keys, logged keystrokes
  • Other information specific to computer locale such as:
  • Local time
  • Time zone
  • Operating system version
  • Language


 
Take the following steps to help prevent infection on your computer:
  • Enable a firewall on your computer.
  • Get the latest computer updates for all your installed software.
  • Use up-to-date antivirus software.
  • Limit user privileges on the computer.
  • Use caution when opening attachments and accepting file transfers.
  • Use caution when clicking on links to webpages.
  • Avoid downloading pirated software.
  • Protect yourself against social engineering attacks.
  • Use strong passwords.
Enable a firewall on your computer
Use a third-party firewall product or turn on the Microsoft Windows Internet Connection Firewall.

Read more

Save this Page

Download as PDF