Showing posts with label Bugs and Hacks. Show all posts
Showing posts with label Bugs and Hacks. Show all posts

Thursday, 10 April 2014

How to protect yourself from the 'Heartbleed' bug

A new security bug means that people all across the Web are vulnerable to having their passwords and other sensitive data stolen. Here's what consumers can do to protect themselves.



Heartbleed security vulnerability

A major new security vulnerability dubbed Heartbleed was disclosed Monday night with severe implications for the entire Web. The bug can scrape a server's memory, where sensitive user data is stored, including private data such as usernames, passwords, and credit card numbers.

It's an extremely serious issue, affecting some 500,000 servers, according to Netcraft, an Internet research firm. Here's what you can do to make sure your information is protected.

Do not log into accounts from afflicted sites until you're sure the company has patched the problem. If the company hasn't been forthcoming -- confirming a fix or keeping you up to date with progress -- reach out to its customer service teams for information, said John Miller, security research manager for TrustWave, a security and compliance firm.

Some Web sites that appeared to have been affected included Yahoo and OKCupid, though the companies have said their sites are all or partly fixed (see below for details). You can check sites on an individual basis here, though caution is still advised even if the site gives you an "all clear" indication. If you're given a red flag, avoid the site for now.

The natural response might be to want to change passwords immediately, but security experts suggest waiting for confirmation of a fix because further activity on a vulnerable site could exacerbate the problem.

Once you've got confirmation of a security patch, change passwords of sensitive accounts like banks and email first. Even if you've implemented two-factor authentication -- which, in addition to a password asks for another piece of identifying information, like a code that's been texted to you -- changing that password is recommended.

Don't be shy about reaching out to small businesses that have your data to make sure they are secure. While the high-profile companies like Yahoo and Imgur certainly know about the problem, small businesses might not even be aware of it, said TrustWave's Miller. Be proactive about making sure your information is safe.

Keep a close eye on financial statements for the next few days. Because attackers can access a server's memory for credit card information, it wouldn't hurt to be on the lookout for unfamiliar charges on your bank statements.

Even after following these guidelines, there is still some riskiness in surfing the Web in the aftermath of the bug. Heartbleed is even said to affect browser cookies, which track users' activity on a site, so even visiting a vulnerable site without logging in could be risky. The Tor Project, which stresses anonymity and privacy, wrote in a blog post that users with those needs "might want to stay away from the Internet entirely for the next few days while things settle."

Yahoo seems to be the most major Web to site have been vulnerable to the bug (preliminary tests for Facebook, Google, and Twitter's Web sites said they appear to be safe). The company said that it has "successfully made appropriate corrections" to the main Yahoo properties: Yahoo Homepage, Search, Mail, Finance, Sports, Food, Tech, Flickr and Tumblr. Still, a Yahoo spokesperson said the company is still working to make the fix across the rest of the Yahoo sites.

"I encourage users to not log in into [Yahoo] and other services that are affected since the credentials could have been leaked if they used the service," said Jaime Blasco, director of AlienVault Labs, a security research firm. "As soon as Yahoo solves the issue, it will be helpful if users change their password just in case."

Yahoo has been stressing authentication of late, so that the company would be able to provide a more personalized experience to users, a drum CEO Marissa Mayer has been beating almost since she took over the company. Yahoo provides services like email and fantasy sports, requiring passwords to get access to the applications.

The company has already had some trouble in the security arena. In January, the company had to reset the passwords of some email users after an attempted attack on a third-party's database. In response to the Heartbleed bug, some users have already expressed their outrage on Twitter. Brandon Oxford, from Royal, Ark., wrote: "After this I'm officially done with Yahoo email. I've now set up a Gmail. They seem to be more on top of stuff than Yahoo."

Other companies that were said to be affected chimed in as well. Imgur, the photo-sharing site popular with Reddit users, said: "[We] invalidated sensitive data such as cookies and session IDs, just to be on the safe side. We're proceeding with caution, since the nature of the attack makes it hard to detect, but we have no reason to believe it has been used against Imgur." OKCupid said, "The fix is now fully live on OKCupid."

The question in the aftermath of something like this is whether Web companies will reform their security practices. There has been a move toward Perfect Forward Secrecy (PFS) by many of the major Web companies, but not all of them have implemented the practice. PFS means essentially that encryption keys get a very short shelf life, and are not used forever. "People should want their communications to be secure as possible. PFS is one thing they can push for in the future," said Miller.

Article by Richard Nieva

Friday, 21 March 2014

Mt. Gox finds 200,000 missing bitcoins in unused wallet

Discovery reduces the number of bitcoins believed stolen in fraudulent withdrawals from 850,000 to 650,000.
Bitcoins(Credit: Bitcoin)

 

Mt. Gox has discovered 200,000 missing bitcoins in a wallet no longer in use, the troubled Bitcoin exchange announced Thursday, reducing the number of missing bitcoins from 850,000 to 650,000.

"We believed there were no bitcoins left in old wallets, but found 199,999.99 bitcoins on March 7," Mt. Gox Chief Executive Officer Mark Karpeles said in a document (PDF) released Thursday. Mt. Gox said it reported the discovery to attorneys on March 8 and moved the newfound bitcoins to offline storage.

Once one of the largest and most popular Bitcoin exchanges, Mt. Gox filed for bankruptcy last month, saying it had lost nearly 750,000 customer bitcoins, as well as 100,000 of the exchange's own bitcoins, as a result of a security lapse. The discovery of the overlooked bitcoins apparently occurred before hackers hijacked and defaced Karpeles' Reddit account and personal blog with charges of fraud earlier this month.

Hackers accused the exchange of secretly keeping some of the coins allegedly stolen in the fraudulent withdrawals and posted data allegedly lifted from Mt. Gox servers they said backed up their claims. The data purportedly showed that 951,116 bitcoins had been deposited with the exchange, more than 100,000 more than Mt. Gox claimed to have lost.

The troubled exchange suspended customer withdrawals on February 7, claiming a fundamental flaw existed in Bitcoin that affected all transactions. Not long afterward, the exchange shut down altogether. Although Mt. Gox later apologized for the issue and said it had developed a workaround that would allow it to resume service, customers are still unable to make withdrawals.

Article by Steven Musil

 

 

Thursday, 20 March 2014

Sophisticated malware finally discovered after 7 years, likely created by a nation-state



Security firm Kaspersky Labs recently released a research paper that uncovers the existence of a piece of highly complex malware that's been in circulation for almost seven years. It's called "The Mask," which is a rough English translation of Careto, a Spanish word for "ugly face" that was found in the malware's code. Aimed at high-level targets such as government institutions, embassies and large energy corporations, Kaspersky says "The Mask" has already claimed nearly 380 unique victims (with more than 1,000 IPs) in 31 countries that include China, France, Germany, the UK and the US. Kaspersky first spotted it in a spear phishing email campaign that entices the recipient over to malicious websites disguised as news sites like The Guardian and the Washington Post.

Kaspersky reports that the malware is extremely sophisticated, with a set of tools that include a rootkit, a bootkit, versions that'll affect 32- and 64-bit Windows, Mac OS X, Linux and possibly even mobile operating systems like Android and iOS. Once it gets its hooks into your system, it can be used to hijack all your communication channels and snatch everything from Skype conversations to sensitive encryption keys. It's also very difficult to detect. Due to the level of finesse found in the malware, Kaspersky concludes that "The Mask" was very likely created by a nation-state, much like Stuxnet and Duqu. As to which nation-state that is, the security firm doesn't know, but says it's probably one that is Spanish-speaking based on the code's language. Intrigued? Go on and hit the PDF link here to get the full rundown of what Kaspersky discovered.

Artilce by Nicolee Lee

Hackers transform EA Web page into Apple ID phishing scheme

One of the game maker's servers is breached -- allowing hackers to create a phony Apple log-in screen that prompts users for personal information. EA says it now has the situation under control.
The fake Apple log-in screen set up by hackers on one of EA's Web pages.

Using some trickery, hackers were able to breach Electronic Arts' Web site and transform one of its pages into a bogus Apple log-in screen. Once users logged on to the fake site, they were prompted to input their credit card numbers, date of birth, and other personal information.

Security firm Netcraft discovered the breach and notified EA on Tuesday. The game maker told CNET that it investigated Netcraft's claims and as of Wednesday the phishing page is gone.

"We have found it, we have isolated it, and we are making sure such attempts are no longer possible," EA spokesman John Reseburg told CNET. "Privacy and security are of the utmost importance to us."

The way the hackers created the fake Apple screen was by accessing one of EA Games' servers, according to Netcraft. The server hosted an outdated calendar that had several vulnerabilities and was likely the way the hackers got into the system to set up the phishing page.

"The phishing site attempts to trick a victim into submitting his Apple ID and password," Netcraft wrote in a blog post. "It then presents a second form which asks the victim to verify his full name, card number, expiration date, verification code, date of birth, phone number, mother's maiden name, plus other details that would be useful to a fraudster. After submitting these details, the victim is redirected to the legitimate Apple ID Web site."

This isn't the first time EA has been the victim of hackers. Years ago, a malicious attack on one of EA's servers led to the inaccessibility of its online Scrabble game. And in 2011, another of the company's servers, which hosted its BioWare Neverwinter Nights forum, was breached and some customer information was stolen.

In this latest hack, it's unclear if user data was stolen. However, according to Netcraft, it's unlikely because the security firm added the phishing page to a blocking list that is provided to major Web browsers.

Article by Dara Kerr