Subscribe:

Wednesday, September 14, 2011

She Wore Only Fishnet Stockings. How Much Could She Possibly Hide?

I spent a few hours surfing porn. I didn’t get hot but I sure got bothered.
In a recent survey, 72% of participants admitted they searched for and accessed adult-content sites. On the other hand, an Internet research on the safety of URLs leading to pornographic sites showed that 29 percent of the 1,000 tested links were infected. Simple math says that adult content sites are among the most likely to infect your computer with viruses or other malware.
Just another scary statistic?
I decided to spend a while surfing porn to test it. I started searching for a video that included a “girl” and an “action.” A girl named Suzana was first to answer my query. Wearing nothing but fishnet stockings, she couldn’t possibly have much to hide. Right?
Wrong. Just when Suzana was about to answer my query, in stepped the antivirus software.


 Darling Suzana was hiding a nice piece of malware.
Identified by Bitdefender as a variant of Kazy Trojan, this piece of malicious code injects itself in to the explorer.exe process and opens a backdoor that allows unauthorized access to and control over the affected system.
It also attempts to read the keys and serial numbers of various pieces of software , while also logging the passwords to the victim’s ICQ, Messenger, POP3 mail accounts, and protected storage.
Beginner’s luck? Challenge accepted! Let’s see if Suzana’s really the one and only girl who can make my dreams come true.
So I cast my fishing net farther, with the classic “porn” search word.
Bad luck! (or is it good???) I get deeper into x-rated troubles as that 29 percent of red-light infected links seems comes to ugly reality. Another try and I’m about to bring a whole load of Trojans aboard. It’s that easy!


I rest my case.
In order to stay safe, Bitdefender recommends that you never open files without checking them as well as that you install and update a complete internet security solution.
Stay happy, but safe!

Monday, August 29, 2011

3 Reasons Why Computer Security Fails

Discover the main culprits behind security incidents

Lack of Awareness

In their day-to-day routine, regular users aren't actually aware of computer security implications until something wrong actually happens. To be more specific, you can't realize the magnitude or the impact of cybercrime activities before having your e-mail account hacked or your on-line banking session intercepted and accounts emptied. It's pretty much the same as with car accidents – you hear people talking about them, you see them on TV and read about them in newspapers, but until you are effectively involved in one (God forbid!), you don't know what they’re all about.
Attacks aiming to exploit security breaches are more likely to target public or private organizations, rather than individual users (the stakes are higher with the former). As usually businesses operate with  networks rather than with standalone workstations, the possibility of their being entirely compromised increases in proportion to several factors, some of the most important being: the number of users, users’ degree of computer security literacy, the nature of the defense policies in effect, the architecture of the security strategy at work and, last but not least, the type of organization and its activities. Just open the technology section of any newspaper or search the Internet and you will get a pretty clear picture about…

Misunderstanding Computer Security

Once awareness of today's security risks is raised, the appropriate strategy that matches the specific security needs of the business should be applied next. Technically speaking, there are three major rules of thumb which could offer a good starting point for any company (and individual, for that matter) in tailoring its data security choices. Disregarding any of them means creating the opportunity for a potential breach.
First off, any protection is better than no protection at all. When dealing with e-threats, having no defensive solution installed on a system is like leaving all doors and windows wide open while you are on vacation.
Second, protection should be chosen based on security necessities – that is although they struggle with the same e-threats, home and corporate users may have slightly different expectations in this respect.
Third, there is no such thing as “enough” security. This implies that security is a continuous process, rather than the simple installation of an antivirus on a computer. It’s a permanent application of on-line safety principles as well as the capacity to anticipate and respond to newly emerging e-threats. At least from this point of view, security is a mid- to long term investment and it does not end with the deployment of a simple defensive solution.

Neglecting the Human Factor

Probably the most important reasons of all is the human factor. The reduced level of awareness, the lack of IT&C security education and the absence of security policies reinforcement, especially in the public sector and large corporations are responsible for most of the damages, both in terms of compromising systems and networks, but also when it comes to disclosing sensitive data, information theft and even malware dissemination.


Thursday, August 25, 2011

Illegal Keygen for Reputed Antivirus Comes Bundled with Malware

Care to install a “virused” antivirus?
It is common practice for crooks to use pirated software as a means of disseminating malware. It’s an approach that has been used for years and it still works as a charm. Any new software product launch is awaited and included into this malware distribution cycle. A much anticipated movie or software product becomes the perfect lure for users who are inclined towards piracy rather than legal product or service acquisition.
This is exactly the scenario we spotted last week, when crooks started using the latest Internet Security avtivirus product from Trustport as bait for malware dissemination. They tampered with an illegal keygen (identified by our labs as Application.Keygen.BW) in order to bind it with a piece of backdoor malware  that is also deployed on the users’ systems along with an illegal key for the AV product.
This keygen spreads via P2P sharing services, USB media, instant messaging services or e-mail clients and users may end up downloading serious trouble on their systems as this particular illicit tool does a lot more than it is supposed to do.
The piece of malware inside the keygen is identified by Bitdefender as Trojan.Agent.ASDM and starts its wrongdoing by injecting itself into explorer.exe and adding a list of exceptions to the locally installed firewall. Afterwards, it deploys a keylogger and a backdoor component on the compromised computer. Depending on how you’re using your computer, this piece of malware does the following:
-          steals passwords cached in various web browsers such as Mozilla Firefox or Internet Explorer;
-          spies on the users’ habits and gathering critical information about the compromised computer and, worst of all, showing great interest for all that has to do with e-banking accounts and money transactions;
-          downloading further malware either via internet or from ftp accounts; the sample we analyzed is capable of downloading and installing  Zeus BOT, SpyNet RAT, Bandook RAT, Scwarze Sonne RAT, Apocalypse RAT, Bff BOT, Solitude RAT, PoisonIvy,  Cybergate, which hints to a possible cooperation between Trojan.Agent.ASDMand other cyber-criminal gangs.;
-          captures video and audio  streams from the users’ computer webcams;
-          logs conversations that take place on social networks or instant messenger;
It is safe to say that there’s an extremely high chance that pirated software leads to malware and it’s definitely a risk not worth taking.
This article is based on the technical information provided courtesy of Doina Cosovan, BitDefender VirusAnalyst.
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.

Wednesday, August 24, 2011

Microsoft asks for ban of Motorola's smartphones

Microsoft is presenting a case before the International Trade Commission (ITC) in which they claim Motorola Mobility is using technology in their Android-based smartphones that was derived from Microsoft products. The world’s largest software maker is asking the ITC to halt imports of certain Motorola phones.
Bloomberg reports that the trial began on Monday in Washington and that Microsoft claims Motorola infringed on seven patents. Microsoft singled out the Droid 2, Droid X, Cliq XT, Devour, Backflip and Charm handsets among those guilty of infringement. The ITC does have the ability to halt imports if they feel a product violates US patent rights.
“We have a responsibility to our employees, customers, partners and shareholders to safeguard our intellectual property,” David Howard, Microsoft’s corporate vice president and deputy general counsel for litigation, said in an e-mail. “Motorola is infringing our patents and we are confident that the ITC will rule in our favor.”
Motorola is defending themselves against the patent suit and a company spokeswoman said they have also brought legal actions of their own against Microsoft in the US and Europe for the same reasons.
This is the first of what is likely to be many more lawsuits brought upon Motorola Mobility since Google agreed to buy the company for $12.5 billion last week. The main reason Google made the purchase was to acquire a wealth of patents from Motorola Mobility to protect themselves as well as the Android platform. Interestingly enough, Google isn’t named in the complaint.
The judge in the case is scheduled to make a decision on November 4 and the ITC has until March 5, 2012 to complete their investigation.

Firefox 7 beta now available, final build due next month

A beta version of Mozilla’s Firefox 7 is now available for Windows, Mac and Linux. Despite releasing version 6 of the popular browser earlier this week, it’s the next iteration that many expect to solve persistent memory leak issues that have plagued the software for years.
Firefox 7 will introduce MemShrink, an initiative that began in June to eradicate the browser's memory inconsistencies. Mozilla developer Nicholas Nethercote claims that Firefox 7 uses less memory than the past three versions, between 20 and 50 percent less in some instances.
In addition to MemShrink, the new build also features better Javascript garbage collection. It's said to work more frequently now and should free up more memory when multiple tabs are open. The upcoming browser also implements Azure Direct2D for Canvas which increases canvas-based animations in HTML5.
There are also tools built into Firefox 7 that will help developers measure load times. Synchronization of bookmarks and passwords is said to be faster, too.
Version 7 is part of Mozilla’s recent rapid deployment of browsers. The developer released Firefox 5 in June and earlier this week it quietly launched Firefox 6 a day ahead of the planned release date.
Mozilla’s browser has been criticized for needing large amounts of RAM and then not freeing that memory once windows or tabs have been closed. Nethercote acknowledges these shortcomings, indicating that some versions were more efficient than others. He praised Firefox versions 3, 3.5 and 3.6 but said things deteriorated with version 4 partly because of all its new features, aggressive JavaScript garbage collection and image decoding.
The final version of Firefox 7 should be available by September 27.

Sunday, August 21, 2011

Gaming community highly exposed to bitcoin-mining Trojan

While distributed denial of service and spam sending are still some of the most effective ways of monetizing a large-scale Botnet, cyber-criminal gangs have also turned their attention towards the increasingly popular peer-to-peer currency system known as Bitcoin.
The first week of August brought under our scope a miner Trojan identified by Bitdefender as Trojan.Antiminer.A, that highjacks compromised machines with the purpose of creating a botnet of infected PCs and uses their resources to produce virtual money. The Trojan silently deploys a legit Bitcoin miner that uses the GPU of the machine to compute virtual currency.
Inspired by the fact that the Bitcoin (BTC) parity is one to 15 US dollars, the crooks have laid eyes on computer systems with powerful GPUs to make easy money. The gaming community is therefore highly exposed since the modern games on the market require powerful GPUs to support the latest developments in the visual effects industry.
“If you happen to download cracked games via Torrent or other P2P sharing services, chances are that you may become a victim of this lucrative Trojan bundled with a genuine GPU miner. We advise you to start checking your system for signs of infection, especially if you are constantly losing frames-per-second,” advises Catalin Cosoi, head of BitDefender Threats Lab.  “The Trojan’s mission is dramatically facilitated by the fact that hardcore gamers do not run antivirus solutions as these are traditionally perceived as bottlenecks on high-performance computers,” he continued.
It may be true that a single miner – be it powered by the most advanced GPU on the market – calculates a limited number of Bitcoins per day. That is why the masterminds behind this operation target a large number of compromised computers that act like an extensive capable of processing large amount of hashes that are transformed into Bitcoins. It is obvious that more computers produce more virtual money while, at the same time, increasing statistically the chances of getting the randomly-awarded bounty of 50 coins for participation in the pool’s effort.
If the Bitcoin system needs any clarification at all, then you should know that it is a cryptographic virtual currency meant to help people make transactions over the Internet while keeping the utmost privacy of their identity. These trades can be made under the mask of anonymity, where there’s no real identity associated to the online persona. Plus there is no bank or state authority to govern over the production or use of this digital cash either.
This attack is just one take at the big pot of money that revolves around Bitcoin. There have been a series of incidents in which cyber-criminals tried to tamper with the system to their own advantage and we expect to see increased malicious activity related to Bitcoin mining on the computing resources of unwary users.
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.
Download now the removal tool for Trojan.Antiminer.A!


Worried about your money while on-line? You should be!

10 safety tips for on-line banking and shopping Several years ago, I've worked with a very gifted teacher who wrote a wonderful IT&C manual that I've edited. As we were going through the final revision, she came up with the idea of adding a motto for each chapter. Although I was a bit reluctant at that time, eventually I agreed. And it turned out just fine, as the high school kids that actually used this book liked it too. A week ago, as I was reading an article about e-banking applications that aren't actually working on all types of browsers, I've suddenly remembered two of the most simple and apparently contradicting statements that my author used in her manual. One of them - “If you aren't on-line, you don't exist” - opened the Internet chapter. The other - “The only way to stay safe is off-line” - introduced the Security section. If we play a bit with their meaning and we are (not-so-fallaciously) speculating it, we get the following assertion: “As long as you are on-line, you are in danger”, which makes more sense than the sophism “You're safe if you don't exist”.
However, banks and e-commerce Web sites tell us a different story. That we are effectively safe and secure while we access on-line our deposits and accounts and that we shouldn't worry at all. If you don't trust me, listen to this guy. Fast forward to 15:10 and you will see that even a hacker says so. He's actually kidding and even banks and on-line merchants are partially kidding, no matter how reputable they are, by saying that everything is fine when it comes to e-banking and e-commerce. And mark my words, you shouldn't take that for granted. Why is that? For the same reason that you shouldn't cross a street without looking left, then right (or vice-versa, if you leave in UK and other places where traffic works in reverse), and even if the light is green (or says 'WALK').
If so, what should we do? Not using e-banking or e-commerce at all? It doesn't make any sense, especially for a 21st-century-extremelly-busy-and-technology-dependent-person right? Right. Well, I'm not saying that we shouldn't using them at all. That would be just as locking yourself inside the house and hiding under the bed because there are cars running outside on the same street you are supposed to cross. Just be careful. And here are some tips:
1. Use a dedicated machine. Get a cheap netbook, laptop or desktop configuration and use it solely for e-banking and e-commerce. Password-protect it, so that you limit the access (you wouldn't want kids to mess around with it), and always connect it to the Internet through a wired connection instead of WiFi to avoid traffic interception. Refrain from shopping or banking on-line from public computers or via wireless unsecured network connections, such as those in coffee shops or airports. Also, it would be a good idea not to buy or make any transaction while on bus, subway or any crowded places – one can never tell who's looking over your shoulder.
2. Ideally, your e-commerce/e-banking-dedicated machine should not run Windows – use a Linux distribution or MacOS. Don't get me wrong, I'm no one's advocate here, but as Windows is the most widely-spread operating system in the world, chances to get infected or compromised are higher. If you don't believe me, then read this story. However, if it is more convenient for you to run Windows or MacOS, then installing a security suite with at least a Firewall, Antispyware and Antimalware is a must. Check this out: BitDefender Facebook fans get 6 extra months of protection for free with the best defensive solution currently on the market, BitDefender Internet Security 2011! Pretty cool, isn't it? By the way, no matter what OS is on that machine, update it frequently. Do the same for your browser and for your security suite. It's crucial in keeping malware and attackers away from your system!
3. Beware of phishing or vishing attempts – banks and retailers will never ask you to change login credentials or other important account details on the phone or via e-mail and sms. If you have any suspicion, make a visit to the bank or try to call them back at the number provided in the contract or agreement you signed (for phone calls it will be a good idea to write down the name of the person who called you and ask for him or she, to see if that person actually exists within that organization).
4. As your Internet browser is your gateway to any on-line financial transaction, clean its cache before and after going on-line, regardless of your operating system. Empty cookies and all plug-in data, as well as all automatically filled data it may save. Disable Autocomplete and Save Passwords options. Moreover, you should refrain from storing any transaction details on your computer. Additionally, you may want to add a free cross-browser controller, such as BitDefender TrafficLight extension, to make your Web surfing even safer.
5. Use on-screen keyboard. Search for it in accessibility tools of your OS and click with your mouse the screen instead of typing on your keyboard. It can spare you the trouble of keystrokes being intercepted by keyloggers.
6. Always manually introduce the address of your bank or on-line retailer in the browser's address bar to avoid redirection towards phishing pages mimicking the genuine page. One single misspelled letter and you could end up handling to cybercriminals all your login credentials on a silver plate.
7. Before proceeding, make sure that the Web page where you enter sensitive data (user name, password, transaction confirmation number, credit card number, CVC and other data) is encrypted. Normally, you should see a locked padlock somewhere in your browser and a page prefix that is https:// in the address bar.
8. For e-banking, you should check with your bank for at least a two-factor authentication procedure – usually based on a security-token. As for online shopping, before making any transactions, enroll your credit card in a supplementary verification program, usually provided free of charge, such as 3-D Secure.
9. Add an insurance to your on-line transactions. It could cost you a bit extra, but it's worthing. Better safe than sorry/broke!
10. Always do some reconnaissance before subscribing or buying online. Find out what others have to say about the e-banking service you want to enroll or a Web site you want to shop from. Ask relatives, friends, your lawyer and bank adviser or simply search on the Internet.
 
Safe e-banking and e-commerce everybody!
 
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.

Source: malwarecity.com

Trojan.FakeAV.LVT– Plays You (Like) in Movies

What happens when screenplay writers, social engineers and software developers meet
A video on Facebook is used as vector of infection for a Trojan, the rogue AV component artfully mimics the antivirus you have installed on your system and the downloader adds the compromised PC to a network of infected systems that constantly exchange malware between them.
Exquisite spreading mechanism
Trojan.FakeAV.LVT takes social engineering to a whole new level.  The scenario is extremely complex and efficient: imagine a friend that initiates a conversation with you in a Facebook chat window. The dialogue seems a bit rigid and soon you are teased with questions such as "Hi. How are you?”, “It is you on the video?” or “Want to see?” that introduce a link to nothing else but a movie allegedly starring yourself. Classic you may say; and you wouldn’t be completely wrong. However, the juicy details are yet to come.
First of all, you are shown a Youtube page with a movie that mentions your name in the title, which is, by the way correctly spelled, as it is taken directly from your Facebook profile. At this point, the video is probably gaining your full trust. On top of that, some of your friends (also taken from your Facebook account friends list) appear to have already commented the video, adding thus yet another huge plus to this crafty scam. In short, you have a movie that is allegedly about you and some friends’ comments that either worship you or appear to be utterly disappointed. Wouldn’t you care to see why?
The video file appears to be missing a codec
Well, if the answer is yes, you will be requested to download a new version of Flash Player, because it appears that your version is “outdated”. This should ring a bell that something is “phishy”, but given the fact that it is a message you have seen quite a lot of times on the legit website, you might not even notice it. Once you click the link, you get immediately caught in a scenario that seems to be taken straight from science fiction movies, because what you download is an extremely insidious Trojan.
Act two: behind the closed curtains
While you think that you are downloading a Flash Player, you are in fact welcoming a Trojan on you PC that will shortly start wreaking havoc on your system. The malicious code hides under the innocent name and appearance of a Flash Player. It copies itself as %windir%\services32.exe and as %windir%\update.X\svchost.exe, where update is a hidden directory and X is the version of the malware. After that, it adds a registry key in %SYSTEM% and the malicious code is added thus to the list of authorized applications for the firewall or it disables the firewall altogether.
Then it proceeds to disabling all notifications generated by the firewall, the update module and whatever antivirus it finds installed on the PC. Yes, you’ve got it right, it strips you off whatever protection you have in place.
Act three: the mutant, multi-faceted, rogue AV
One thing I find utterly disappointing with Rogue AV software is the fact that they fail to trick anyone but those who hardly spend any time in front of the computer. Trojan.FakeAV.LVT however has a rogue AV component that is indeed innovative. We all know that fake antivirus solutions trick users into downloading a product by showing alarmist pop-ups claiming that the PC is packed full with malware. This one takes things to a whole new level. It starts by displaying personalized warning message windows that are strikingly similar to the AV solution it finds installed on the system. Yes, it is a chameleon that has a copycat kit for all the important AV products on the market. It goes so far in that it initially determines the AV running on the machine and the interface language selected by you. It will afterwards use the captions, the icons and the messages consistent with the personalized settings of the installed AV.
In order to leave you totally unprotected, the Trojan displays a popup warning and kindly asks you to reboot the system in order to perform the clean-up. But, before that, it queues your antivirus for uninstallation, then uses the genuine Microsoft bcdedit.exe (command line tool for managing BCD (Boot Configuration Data) files) in order to instruct the system to boot in safe mode after restart.
The piece of malware will successfully start in safe mode, as it has created the following Registry key: "HKLM\SYSTEM\ControlSet001\Control\SafeBoot\AlternateShell = %windir%\services32.exe". After it has successfully removed your antivirus, the Trojan uses bcdedit. exe again to execute the following: 'BCDEDIT /deletevalue safeboot /set safebootalternateshell false' and restart the computer in normal mode.

Alert window imitating a genuine product
Now that you have seen how good the “antivirus” is, you are also notified that qualified help could be provided in a couple of hours by a support specialist, if you send them your cell-phone number.
Act four: the tragic ending
The Trojan also packs under its hood a downloader component that fetches files from different URLs depending on the OS of the infected system. The systems running Windows Vista, for instance, will download files from a different location than those running XP. The downloaded file contains a list of IPs saved as %windir%\front_ip_list.txt.
The malware contains a hardcoded list of IPs, as well. These are the IPs of other infected systems which will be used at exchanging malware between them, creating a fully-fledged malware distribution system with peer-to-peer update capabilities. These IP lists are changed regularly and so infected system are always in contact and constantly exchanging malicious code.
Conclusion
Cyber-crooks have given a new dimension to their operations. This carefully-planned “sting operation” hunts the Facebook user down, refers it to a popular video-sharing website where all their friends are laughing at a clip starring themselves, then forces them to download a Trojan. After that, the Trojan ensures that the user gets completely stripped off of their security solution, in order for the malware to take full control of the severely compromised system. What happens then surpasses any reasonable thinking: the computer is used by the cyber-crooks for a wide range of purposes that are constantly expanded through the use of malicious plug-ins. All these happen while you think that you’re completely safe and that nothing can happen to you.
This article is based on the technical information provided courtesy of Doina Cosovan and Răzvan Benchea, BitDefender VirusAnalysts.
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.

Source: malwarecity.com

iPhone 5 rumor roundup for the week ending June 10

In the nick of time, Apple announced iOS 5. Single-handedly, it's saved the increasing stale, desperately-seeking iPhone 5 Rumor Industry from self-extinction. Re-energized, the rumoratchiks are streaming the stuff out: wireless charging, no iPhone 4S, iPhone 4S confirmed, the end of SMS as we know it, two iPhone 5 models, price cuts, 8 megapixel camera, SummerFallWinterSpring announcement date!
It's a great time to be rumoring. Here's the iPhone 5 rumor rollup for the week ending June 10.
MORE IPHONE RUMORS: iPhone 5 rumor rollup for week ending May 27
Delaying iPhone 5 is part of a clever Apple strategy.
The "delay" in announcing iPhone 5 is a Good Thing because it shows Apple is serious about the competition from Google Android and Microsoft, according to ITPortal's Desire Athow. So it's focusing energy on creating really cool software and services.
Athow gets extra points for creating this week's most-labored-analogy: "Announcing the iPhone 5 now would be the sporting equivalent of showcasing a horse for a race without knowing who the jockey will be; Apple needs both the hardware and the software to be ready."
Wireless charging for iPhone 5.
An Apple patent indicates the company could be readying a wireless charging system that would be built into its iMac computers to charge nearby wireless devices, such as a keyboard, mouse, "and -- yes -- iPhones containing the appropriate receivers," according to FoneHome.com, which headlined its story "Wireless iPhone 5 charging patent revealed."
FoneHome had picked up on the patent information posted at World Intellectual Property Organization (WIPO), which of course doesn't mention iPhone 5.
Apple's approach sounds similar to that of MIT researchers (and many others) using electromagnetic resonance between coils to transfer energy without wires and then convert it into power. The MIT team demonstrated a more efficient version of the technology just over a year ago.
Forget the "iPhone 4S."
Beatweek conclusively speculates that all the speculation about a kind of souped-up iPhone 4 model, usually dubbed iPhone 4S, preceding the iPhone 5 is and always was codswallop. "While there's no specific evidence to suggest that the iPhone 4S was 'made up' by folks with any intention to deceive, at the very least the iPhone 4S was indeed a made-up product. In other words, it never existed."
By contrast, Beatweek goes on to conclusively speculate on all we do "know" about the real iPhone 5. Stuff like ... it has an operating system: the just announced iOS 5. And: "We've identified at least two carriers that it'll be on. We know it'll sport an A5 processor."
Wow.
"We learn a little bit more about the iPhone 5 each day, piece by piece, and slowly," according to Beatweek. Sort of like weaving a tapestry of rumors, or like building a smartphone sculpture out of Legos.
There's only one problem with Beatweek's claim that iPhone 4S never existed ...
Sprint has the iPhone 4S. Or something.
"Sources" have told 9to5Mac that a version of the iPhone intended for Sprint is right now in "advanced testing." This is being done in Apple's sinisterly-but-coolly-named "Black Labs," presumably a reference to office space and not dogs.
Could it be the iPhone 5? "The physical design of this device is akin to the iPhone 4 of today, so this might be the iPhone 4S device with support for all carriers that we have been dreaming up and hearing whispers about." Unless you're Beatweek.
But there's more -- a second iPhone for Sprint that will support 4G, however that's defined by this month's TV ads: "Sources also say that talk of a 4G variant of the iPhone for Sprint is moving along, but the first generation Sprint iPhone that is currently in testing does not feature support for 4G bands."
So apparently the first Sprint iPhone will be the iPhone 4S, and the second Sprint iPhone will be the iPhone 4S 4G, which means the third Sprint iPhone will be the iPhone 5, which may or may not be 4G, because that would make it the iPhone 54G.
But there's even more. 9to5Mac linked to another rumor at TalkAndroid, which according to 9to5Mac claims that a Sprint iPhone will include dual-band support for T-Mobile, about which 9to5Mac rhetorically asks, "weird, right?"
It would be, if that's what TalkAndroid actually said. The rumor actually posted is this: "Sprint and T-Mobile will be getting the iPhone 4S. 'It's kind of a leap-frog system where AT&T/Verizon take turns getting the newer model first, then with Sprint/T-Mobile' [the quote is from one of TalkAndroid's sources, who are "some people in the Sprint store"]."
TalkAndroid helpfully explains What It All Means. "What this is basically saying is that the iPhone 5 will probably be out first on AT&T/Verizon, and then Sprint/T-Mobile." In other words, Apple's alleged "leap-frog system" will have future iPhone models being released first on alternating pairs of carriers.
And for the record, TalkAndroid also thinks Sprint is getting something called iPhone 4S.
iPhone 5, and other iOS 5 devices, with iMessage means the end of SMS as we, and the carriers, know it.
"Apple iMessage an unexpected shock to carriers: Goodbye SMS cash-cow" screamed the Slashgear headline. Carriers were "blindsided" by this new messaging feature in iOS 5, the story reports, threatening the carriers' one really profitable revenue stream: SMS and MMS messaging.
The Slashgear "story" is based on one, brief blogpost by John Gruber, who writes the Daring Fireball blog. Gruber's post was a link to a MacRumors story on iMessage, and offered one comment and a parenthetical note. iMessage, Gruber wrote, "means iPhone users with iPhone-using friends and family no longer need SMS. I'll cancel my SMS plan as soon as this ships."
He concluded with a parenthesis that a "well-informed little birdie tells me that Apple's phone carrier partners around the world found out about iMessages when we did: during today's keynote [Monday, June 6, at Apple's Worldwide Developers Conference]."
The next rumor will be: As mobile carriers go bankrupt due to the loss of SMS revenues, Apple plans to deploy and run its own free, nationwide 4G cellular network.
There will be two iPhone 5 models, and two iPad 3 models. And iPhone 5 will be announced in September.
More "sources" spent some time sifting through USB device files in the beta iOS 5 firmware and shared what they what discovered with TUAW.com.
"TUAW sources inspecting the USB device files in yet-unreleased iOS 5 firmware have discovered suggestions of two future iPad 3 models as well as a pair of iPhone 5 models. What's most surprising is a big omission: no mention of an iPod touch 5."
The system files showed declarations referencing "iPad3,1" and "iPad3,2" as well as "iPhone4,1" and "iPhone4,2." Aha, you exclaim. How can the iPhone 5 be an iPhone 4?
TUAW has it figured out. "The iPhone 5 will be a 4th generation unit because the iPhone 3G was technically 1st generation," TUAW says. "This throws off the numbering and confuses everyone, so don't fret if you were confused." Or if, after that, you still are.
No mention of an iPod touch 5 shows the iPhone 5 will be announced in September! Here's the reasoning behind that, from International Business Times' Carl Bagh: "Apple customarily releases the iPod refresh in September. Since the iPod touch is not mentioned in the firmware, it seems the iPod refresh meet will be used by Apple to launch the iPhone 5."
Talk about QED.
iPhone 5 pricing will be the same or lower than iPhone 4.
That welcome rumor comes from OnlineSocialMedia.com, although it's not based on much more than wishful thinking.
This rumorwish notes that the iPhone 4 prices were $199 or $299, depending on storage capacity, subsidized by the carrier (and $499 and $599 for the unsubsidized models).
"We think it's likely then, given Apple's recent efforts to keep prices lower, that the iPhone 5 will be the same price on release as the iPhone 4 was (although it has recently been cut)," according to OSM. "In fact Apple could surprise us further by making prices at least $50 cheaper."
"Bear in mind here that the new Mac OS X Lion that was announced on Monday will have a price of only $29.99, and also Apple's iCloud was unveiled and will be completely free so this also shows that Apple is trying to shed its reputation for high-priced products," OSM confidently concludes.
At this rate, driven inexorably by Moore's Law, Apple will be paying users to buy iPhone 10.
iPhone 5 will unquestionably have an 8 megapixel camera.
The staff at International Business Times knows the difference between a mere rumor and a confirmation. "Now, it looks like the 8 megapixel camera is one feature that's finally confirmed," the site reports. And why? Because DigiTimes reports, citing "market source," that "OmniVision has grabbed a majority of total CMOS image sensor orders placed by Apple for the fifth-generation iPhone."
DigiTimes clearly is still confused about iPhone numerology even after it was explained by TUAW.

Friday, June 3, 2011

MacDefender 'Scareware' Skirts Apple Fix

Authors of the MacDefender malware issued a new version Tuesday that works around an Apple (NSDQ:AAPL) security update designed to block it.
Earlier Tuesday, Apple released a security a update for Mac OS X 10.6.7, update 2011-003, that included malware detection and removal for the MacDefender phishing attack and its variants.
However, by about 9 p.m. PST, a new variant was detected, said Chester Wisniewski, a senior security advisor at U.K.-based Sophos.
"We noticed it in the U.K. and started seeing samples that were not detected in the Apple update,” Wisniewski said. “We weren't surprised because we thought it wouldn’t take the bad guys long to modify the malware.”
The malware is called “scareware” because it tries to frighten users into thinking a virus has invaded their computer, then tricks users into entering their credit card numbers to purchase fake security software.
Wisniewski said he wasn't surprised that Apple’s security update was circumvented. Apple has been targeted less than Microsoft historically and is less experienced at fighting off attacks, he said, adding that Apple is now re-evaluating its security response.
“We are seeing the re-invention of the wheel on the Apple platform for security,” he said. “Clearly the bad guys have been innovating a lot to be able to do this. They must be making money and want to make more. This is the first time criminals have really targeted Apple.
“My advise to all Mac users is to run some antivirus,” Wisniewski added.
Apple representatives could not be reached for comment Wednesday.
However, one Apple managed services provider said MacDefender does not pose a large-scale threat.
Alberto Palacios, systems engineer with Create More Inc., a San Francisco, Calif.-based MSP, said his company has received just one emergency call for help from a home user who then figured out how to remove the malware himself.
“I don’t think [MacDefender] is a big deal because, quite honestly, it’s a user-initiated issue," Palacios said. "You have to click a button that says, ‘Install this on my computer.’
"It’s malware not a virus, so it’s due to bad user behavior. I don’t think it says anything bad about Apple," he added. "We haven’t had any businesses contact us, just home users. It’s relatively easy to take care of. We had one emergency call from a client who was a home user and within five minutes he called back and said, ‘I took care of it myself.’ “

SOURCE

http://www.crn.com/

Google Points To China As Source Of 'Targeted' Gmail Phishing Attack

Chinese officials are on the defensive after Google fingered China as the source of a sophisticated phishing attack targeting many high profile Gmail account holders, including U.S. government officials. But security experts says the attack, if true, continues a growing trend of sophisticated attacks used by nation states for cyber espionage purposes.
In a blog post Wednesday, Google (NSDQ:GOOG) said that it discovered a targeted phishing campaign appearing to be sourced from Jinan, China , affecting hundreds of Gmail users, including senior U.S. government officials, Chinese political activists, officials in South Korea and other Asian countries, as well as military personnel and journalists.
Google said that the phishing campaign, executed by stealing users' passwords, was launched in an effort to infiltrate users' Gmail accounts and monitor their activity.
"The goal of this effort seems to have been to monitor the contents of these users' e-mails, with the perpetrators apparently using stolen passwords to change peoples' forwarding and delegation settings," Google said in a blog post Wednesday.
During that attack, victims were compelled to open an e-mail appearing to come from someone they knew. The e-mail message used social engineering techniques with highly personalized content to entice them to click on links that took them to malicious sites impersonating the Gmail login screen.
"The telltale sign to note here was the fact that it took them back to a Gmail login screen after they were already in their account. That's never a good sign," said Fred Touchette, senior security analyst for AppRiver. "The fake log-in screen in these attacks also had multiple flaws that should have clued the victims to the fact that something was amiss as well."
Google said that it had already "detected and disrupted" the campaign aimed at hacking into military Gmail accounts, adding that the victims and appropriate government authorities have been notified.
China has since emphatically denied Google's allegations that the spear phishing attack originated in the world's most populous country, calling the search giant's claims "unacceptable."
"Blaming these misdeeds on China is unacceptable," said Hong Lei, Chinese foreign ministry spokesman in a news conference, according to The Telegraph .
Meanwhile an editorial, published by, Xinhua, the official Chinese news agency , said that Google's "groundless" accusations were damaging diplomatic relations and trust between the two countries, stating that "it was too imprudent for the online giant to lash out at others without solid proof to support its accusations.
"The chimerical complaints by Google have become obstacles for enhancing global trust between stakeholders in cyberspace," Xinhua said, adding "It is a real pity that Google's baseless complaints have distressed mutual trust and the efforts to establish new global governance in cyberspace, letting real online criminals obtain illegal profits without being punished."
Xinhua said that this was the second time that "Google arbitrarily pointed its finger at China," citing last year's allegations that the Chinese government perpetrated a hacker attack against the search giant, and elicited the help of the U.S. National Security Agency, which Xinxua said was "a serious threat to Internet neutrality.
"It is not appropriate for Google, a profit-first business, to act as an Internet judge," Xinhua said.

However, security experts say that this particular attack is likely continuing a trend of phishing campaigns that are being used as weapons in more comprehensive cyber espionage efforts.
"The espionage angle has been brought to light progressively more lately, which is unsettling to most that it is happening, but unfortunately this isn't all that new either. We're just now starting to find out about them," said Fred Touchette, senior security analyst at AppRiver. "We have seen more and more directed spear phishing attacks against individuals and/or specific companies over the past few years. This is troubling news because they are usually harder to notice due to their customization but in no way will this affect eh cast net style approach of phishing."
Meanwhile, security solution providers say that the Gmail phishing attack doesn't necessarily imply that Google (NSDQ:GOOG) fell short in its security implementations.
"This isn't new. This isn't Google being hacked. This is people hacking themselves. It's just a phishing attack,' said Leo Bletnitsky, CEO of Las Vegas-based Las Vegas Med IT and Desktop Valet. "Nobody should be doing anything confidential over Gmail anyway. You assume that Google is indexing everything anyway."
Bletnitsky said that to prevent becoming the victim of a phishing attack, he regularly tells his customers to check the URLs and avoid clicking unfamiliar links, as well as questioning apps or Web sites that request users to re-enter a password when they're already logged in to a site.
"If something is behaving differently than it did before, you have to question it," he said.
The recent Gmail attack marks another point of contention in a tumultuous history between China and the search giant. Google's relations with China took a nosedive with a massive targeted attack on the search giant in January 2010, known as Operation Aurora , targeting Google source code and intellectual property.
Meanwhile, Touchette said that it was unclear if Google's previous history with China contributed to the swiftness of its public accusations.
"While it is slightly unusual that Google has made public this particular attack, it's hard to tell whether their past issues with China have had a role in the reason they did so," Touchette said. "I don’t think they're personally overhyping the situation, but rather letting everyone else take care of that for them."

SOURCE
www.crn.com

New Microsoft Support Scam Downloads Malware

A new version of the Microsoft Support scam has emerged, attempting to convince users to install a malicious application claiming to "fix" their machines, according to SANS Institute researchers.
The latest version occurs when a scammer calls victims, impersonating Microsoft support personnel, and attempts to get them to directly install a Teamviewer application -- allegedly to fix the machine, but which ultimately takes control of the users' computer and sifts through files for information to steal.
"The scam is obviously still working. It seems they have figured out that users can't be trusted to click a link, but installing remote control software and getting you to install the malware for them is ok,' said SANS Institute researcher Mark Hofman, in a blog post.
In another version of the support con, the scammers on the other end of the phone would attempt to get the victim to click through the event viewer to "find something red." Once a problem was identified, users would be directed by phony support personnel to a Web site where they would be directed to download malware after submitting credit card information.
"Strangely enough there is usually something red in most people's event log log," Hofman said. 'However, do not despair if you don’t have anything red, yellow is just as bad."
While Microsoft support scams have been around for a while, new versions have surfaced in the last six months that actually attempt to download malware by convincing the user to install an application, or bringing them to a malicious link, experts say.
In general, users are told there is something wrong with their computer and are typically taken through various screens indicating various warning and alerts to corroborate the claim, before being swayed to download or update software such as computer care warranties. The victim is then encouraged to submit credit card numbers in order to purchase the phony software, that is either bogus or malicious.
In one instance, reported by the U.K.'s Guardian , the scammer said that she was from "Windows Service Centre" based in East London, and claimed that she had found numerous error reports that had come through the computer causing latency issues.
In previous Microsoft support schemes, scammers call victims claiming to be from the Microsoft support center, and falsely alerting them that their computers are inundated with viruses. The phonyhelp desk personnel would then convince the user to provide credit card information in exchange for bogus helpdesk advice, however no malware would be downloaded.
Meanwhile, Microsoft says that it will never make unsolicited calls or e-mails offering help services in exchange for money.
"We do not send unsolicited email messages or make unsolicited phone calls to request personal or financial information or fix your computer," Microsoft said on its Web site ."If you receive an unsolicited email message or phone call that purports to be from Microsoft and requests that you send personal information or click links, delete the message or hang up the phone."

Source:

http://www.crn.com/

Monday, May 23, 2011

Rogue Apps Might Spoil Your Fun around Champions League Final

Placing a bet in favor of your favorite team around the Champions league final can get real ugly for your bank account
E-mail lotteries, last minute tickets bargains, surprise ticket winnings and promo vacation package for the Champions League final are flooding the Internet this month. It may be difficult for you to be able to filter all that’s coming to you these weeks, since all these scams are ever more perfected as they prove to be extremely rewarding for the crooks.
Taking advantage by the increased search queries placed with popular search engines around highly-mediatized events such as football cup finals, concerts, royal weddings or famous people’s death, cyber-criminals set up both old and new traps for enthusiastic and curious computer users. The Champions League final is no exception to the rule as various baits are thrown at fans who might get lured into taking a costly “opportunity”.
These past years, our labs saw a couple of social engineering-based scams especially crafted to take advantage of fans around important soccer competitions. One of them is the Champions League E-mail Lottery according to which “the Local Organizing Committee of the European Champions League” was “glad to announce to the world the giving away of the sum of SEVEN HUNDRED THOUSAND UNITED STATES DOLLARS to 100 lucky email addresses all over the world.” The users’ e-mails were claimed to have been randomly chosen “through a computer ballot system drawn from over 1,500,000 companies and individual E-mail addresses database”. All they need to do was fill in a form with a lot of sensitive data amongst which name, address, e-mail, occupation, country and credit card info. The crooks were this way able to put their hands on a large amount of info, which later on could be used for malicious activities such as spam, money mulling or impersonations. 
Another malicious initiative spotted around the Champions League final was a spam campaigns meant to target UK-based football fans that were of course eager to get a ticket to the final. The scam ran like this: the users had to send an SMS message to a short telephone number and vote for their favorite team in order to sign-up for a free-ticket lottery. This SMS, however, cost the UK football fans “£5 excluding VAT," which alone brought the crooks a significant gain. Needless to say, that no one ever won a ticket to the final out of that scam.
Euphoria, friends, favorite team might end up badly. For this year, I would like you to imagine the following scenario: it is Saturday, 28th of May and you are with your friends watching the confrontation between FC Barcelona and Manchester United FC. The game turns out to be as you’ve anticipated and you decide even to place a bet. But make sure this bet doesn’t cost you too much in the end. Wi-Fi enabled mobile phones present a high risk with respect to the privacy of your data transfer. The login credentials can be intercepted somewhere in between your smartphone, PC or laptop and the betting website.
The Internet is full of rogue applications containing dodgy code meant to steal sensitive data from your smartphone. All these applications are “malformed” versions of legal apps (such as Photo Editor,Scientific Calculator, Super History Eraser, Super Guitar Solo, APP Uninstaller only to name a few) which could easily make them pass as safe since some of the users have already downloaded a few of the legit ones. This is what we call hiding in plain sight.
Google has banned a lot of these dangerous applications from the Android Market in order to protect the unwary users from becoming targets. However, it is not safe to say that all the malicious apps are out, since around events their number usually starts growing and they become targeted, thus harder to spot. And once downloaded onto the mobiles, these well-disguised spies “agents” start gathering critical data that is immediately sent to crooks while also leaving a backdoor open for future remote wrong-doings.
Some other applications impersonate e-banking or stock manipulation services, but instead they are mere phishing tools that simply deprive you of your credentials first to either rob you or steal your identity later on. So should you decide to place a bet via your smartphone and you are not paying attention to the app you are using in this direction, then you might end up accessing a page that has been spoofed or had been created for such events only that is designed to take your credentials and end up with your money and/or your identity.
Spam and phishing carrying e-mails may also bombard you these days around the Champions league finals. Crooks may feed you either a nice story about you being the lucky winner of a premium ticket to the final at Wembley or links towards your favorite online betting website, where you can make a fortune. But whatever you do, firstly make sure that you land on the right page by checking the browser’s URL bar and also look for the presence of a security certificate. Manually entering the website’s address may prove to be a blessing in this case as compared to taking a chance and clicking a link received through instant messaging services or via mail.
Crooks come up with various scams created to meet the exact need and interest of a variety of computer & smartphone users. That is why you need to proceed with caution when you decide to buy a ticket from eBay, for instance. It is possible that, although advertised, the item doesn’t exist and chances are that you end up paying for something that will never be delivered to you. Moreover, never consider yourself as lucky as to win a ticket if you’ve never signed up for such a contest.
Last, but not least, if you’re a fan of “Artificial Intelligence”-based predictions, be careful as to what prediction software you’re using. Around sports events, malware creators usually come up with rogue “sports prediction software”, which are highly expensive applications that randomly display the “probable” scores. Other such applications which are distributed for free can carry malware, so make sure that you’ve scanned them with an updated antivirus before using them.


http://www.malwarecity.com/blog/rogue-apps-might-spoil-your-fun-around-champions-league-final-1078.html

In front of your computer you should always fasten your seatbelt

Three things that cars and computers have in common – when it comes to security, of course.
Ever since I started dealing with computers I couldn't help noticing that the majority of users actually falls into two large categories, according to their attitude towards computer security: the league of “I don't need an antivirus, what difference does it make anyway?” and the congregation of “I have an antivirus, what else should I care about?”.
Sure, I can see their points, as both societies have enough supportive arguments. However, my daily practice tells me that, actually none of them is completely right. As I enjoy driving a lot, I'll try to use an analogy with a car and its safety system to be more explicit.
You can always drive a car without airbags, seatbelts and other security measures that prevent you from getting hurt in case of an accident. But, as I (unfortunately) know from my own experience, whether you're involved in a frontal collision or a slight bump – God forbid! – it's always better to actually have these protective devices on.
Now try to imagine this scenario: you’re at home, in front of your computer, querying a search engine for breaking news about a recent event. Your TV is running loud, your kids have turned the living room upside-down and your wife is screaming for your help from the kitchen – pretty much the idea of a “quiet evening at home” most of us have. You turn your head because you couldn’t actually understand what she’s saying, your hand slips to the right and your finger accidentally clicks a link displayed on the search results page. Baaang! Your computer just got its frontal impact test by running against a minivan of malware served by poisoned URLs. No security installed onto your system means no seatbelt and no airbags.
Remember that old joke with the guy who had a new car with cruise control, ABS, EBD, ESP – plus other three-or-four-letter-abbreviations of security systems- and crashed it at the first turn right (or was it left?) as he believed his car was supposed to steer by itself with all that stuff on it? Sure thing, you can pack a computer with all state-of-the-art security thinking that you don't need anything else. But the truth is that the human factor is still key, whether we talk about driving or protecting data.
Picture this: you and your laptop are both comfortably nested on the couch and you’re surfing your favorite social networking platform. You've got word from a pal about an app that can spit out the number of people having visited your page and you want to install it too. And, just as, in your car, you hit the gas to get even faster to your favorite holiday resort while simply ignoring all those road signs that warn you about speed limitations, curbs and other dangers, when on your computer, you overlook any clue telling you that the magic app is actually a scam meant to take over your account and hijack your browser. Baaang! You've smashed yourself onto the slope of frauds because you didn't want to be reasonable enough, paid no attention to the road in front of you, and solely relied on your system.
So, what I'm trying to say is that truth is somewhere in between. Overall, there are three little things you should always remember, whether they refer to your car or your computer: Some security is always better than no security at all. No matter how much security you have, you'll never have enough. With your seatbelt fastened, always be alert and watch the road, someone's waiting for you at home (or to get back in front of your computer)!
Safe driving and surfing everybody!

http://www.malwarecity.com/blog/in-front-of-your-computer-you-should-always-fasten-your-seatbelt-1077.html

New malware revives Mac vs. Windows security debate

(Wired.com) -- A new piece of malware has caused an uptick in Apple customers reporting infected machines, renewing a timeless debate on the state of Macintosh security versus Windows.
The trojan horse is called Mac Defender. It's a web pop-up containing a spoof message that tells customers their machines are infected by a virus and they must install anti-virus software. If customers agree to install the software, the program sporadically loads porn websites on their computer.
ZDNet writer Ed Bott was first to spot a long thread of complaints in Apple's support forums related to Mac Defender, with at least 200 posts of customers reporting they've been infected by the malware.
"I've done similar searches in the past ... [and] I have never found more than one or two in-the-wild reports," Bott wrote. "This time, the volume is truly exceptional."
Furthering his case, Bott in a follow-up article quoted an AppleCare technician who claims that phone calls to AppleCare support have grown four to five times recently, and the majority of the calls are related to Mac Defender.
Customers and technology observers have debated for years whether the Mac is truly more secure than a Windows PC.
The general consensus among security researchers is that there's nothing about the Mac that makes it inherently more secure than Windows -- indeed, the Mac platform has been easily penetrated in the Pwn2Own hacking contest in years past. But Windows has always been a juicier target for malicious hackers because it has much larger market share than the Mac.
As a result, when customers switch from a Windows to a Mac, they're often under the impression that they're switching to a more secure, sterile environment where they won't need to install expensive, resource-hogging anti-virus software. While it's not true that the Mac is more secure, theplatform is generally "safer" because fewer people target it, security researchers have told Wired.com in the past.
Bott's discovery renews this debate: A new piece of malware seems to be fooling more Mac customers than past examples. So does this change the scenario? Should Mac customers install anti-virus software by default like most Windows customers do?
Charlie Miller, a security researcher who has repeatedly won the annual Pwn2Own hacking contest by hacking Macs and iPhones, told Wired.com he doesn't think so.
Miller noted that Microsoft recently pointed out that 1 in 14 downloads on Windows are malicious. And the fact that there is just one piece of Mac malware being widely discussed illustrates how rare malware still is on the Mac platform, he said.
And while 200 posts complaining about Mac Defender in Apple's support forums may seem like a lot, that's still a small fraction of the millions of Mac customers in the world.
While Mac Defender does show that the problem is getting worse and people should be more wary about malware, it doesn't necessarily mean that every Mac user today should rush to buy anti-virus software, Miller said.
Ultimately, it's up to the customer because there's a trade-off involved. Anti-virus software will help protect your system from being infected, but it's expensive, uses system memory and reduces battery life.
"Mac malware is still relatively rare, but is getting worse," Miller said. "At some point soon, the scales will tip to installing antivirus, but at this point, I don't think it's worth it yet for most people."
In looking into the effects of Mac Defender, Wired.com's sister publication Ars Technica did a thorough investigation on the state of Mac malware, speaking with 14 Mac support specialists.
"The truth is hard to tease out," ArsTechnica's Jacqui Cheng wrote. "Partly because Mac OS X still makes up a comparatively small percentage of the global OS market share, and partly because Apple itself is a secretive company, it's not easy to find out whether malware on the Mac is indeed becoming more common, or it's simply being reported on more often."
The results were all over the map, with most certified Mac support specialists logging a low number of malware reports. But some Apple Genius Bar technicians noticed an uptick in malware instances, thanks to Mac Defender.
Though the conclusion is unclear, the moral of this story is to be wary that Mac malware is in the wild, and be cautious about installing sketchy software from unfamiliar sources. Mac Defender may be the first wake-up call for people who believed that Macs don't get viruses.
Copyright 2010 Wired.com.

Friday, May 20, 2011

Mac Not Really Safe From 'Viruses' Afterall.

The first advanced DIY (Do-It-Yourself) crimeware kit aimed at the Mac OS X platform has just been announced on a few closed underground forums. Detailed information about this crimeware kit is not being leaked publicly and the authors of the kit are obviously trying to stay below the radar allowing only vetted users of the forums to see most of the content.

Crimeware kits have become a ubiquitous part of the malware scene in the last few years, but they have mainly been confined to the Windows platform. Now, reports are surfacing that the first such kit targeting Apple's Mac OS X operating system has appeared.
The kit is being compared to the Zeus kit, which has been one of the more popular and pervasive crimeware kits for several years now. A report by CSIS, a Danish security firm, said that the OS X kit uses a template that's quite similar to the Zeus construction and has the ability to steal forms from  Firefox.
"The Danish IT-security company CSIS Security Group has just yesterday observed a new advanced Form grabber designed for the Mac OS X operating system being advertised on several closed underground forums. In the same way as several other DIY crimeware kits designed for PCs, this tool consists of a builder, an admin panel and supports encryption," Peter Kruse of CSIS said in a blog post.
"The kit is being sold under the name Weyland-Yutani BOT and it is the first of its kind to hit the Mac OS platform. Apparently, a dedicated iPad and Linux release are under preparation as well. The Weyland-Yutani BOT supports web injects and form grabbing in Firefox; however both Chrome and Safari will soon follow. The webinjects templates are identical to the ones used in Zeus and Spyeye."

In an email exchange, Kruse said that the builder component of the kit runs on Windows machines and the user has the option of specifying that he wants the malware to run on OS X. The builder will then create a Mac binary.
Malware authors and professional attack crews have steered clear of the OS X platform for the most part, for a variety of reasons. One of the main things holding up the development of Mac-specific attack tools, experts say, is the small market share Apple has, particularly in the enterprise. However, that is gradually changing and the attackers are beginning to follow.
In addition to the new crimeware kit, a Mac-specific scareware attack also popped up on Monday, targeting users who searched for some popular terms on Google. The MACDefenderscareware is appearing in search results for images of Osama bin Laden as well as in other places.
"In it's current incarnation, MACDefender shows up in the installed applications list, so can be uninstalled. If you have accidentally installed this, go ahead and uninstall it.  I would not expect this 'uninstall' option to be a good long term protection strategy. I'd suggest that OSX users disable 'Open safe files after downloading', and also invest in a reasonable anti-malware suite. Installing a real anti-malware package is also a good idea," Rob VandenBrink of the SANS Internet Storm Center wrote in an analysis of the scareware.

Thursday, May 19, 2011

Hacking the Car: Modern Vehicles now at the Mercy of Cyber Attacks.

IDG News Service - University researchers have taken a close look at the computer systems used to run today's cars and discovered new ways to hack into them, sometimes with frightening results.
In a paper set to be presented at a security conference in Oakland, California, next week, the security researchers say that by connecting to a standard diagnostic computer port included in late-model cars, they were able to do some nasty things, such as turning off the brakes, changing the speedometer reading, blasting hot air or music on the radio, and locking passengers in the car.
In a late 2009 demonstration at a decommissioned airfield in Blaine Washington, they hacked into a test car's electronic braking system and prevented a test driver from braking a moving car -- no matter how hard he pressed on the brakes. In other tests, they were able to kill the engine, falsify the speedometer reading, and automatically lock the car's brakes unevenly, a maneuver that could destabilize the car traveling high speeds. They ran their test by plugging a laptop into the car's diagnostic system and then controlling that computer wirelessly, from a laptop in a vehicle riding next to the car.
The point of the research isn't to scare a nation of drivers, already made nervous by stories of software glitches, faulty brakes and massive automotive recalls. It's to warn the car industry that it needs to keep security in mind as it develops more sophisticated automotive computer systems.
"We think this is an industry issue," said Stefan Savage, an associate professor with the University of California, San Diego.
He and co-researcher Tadayoshi Kohno of the University of Washington, describe the real-world risk of any of the attacks they've worked out as extremely low. An attacker would have to have sophisticated programming abilities and also be able to physically mount some sort of computer on the victim's car to gain access to the embedded systems. But as they look at all of the wireless and Internet-enabled systems the auto industry is dreaming up for tomorrow's cars, they see some serious areas for concern.
"If there's no action taken on the part of all the relevant stakeholders, then I think there might be a reason to be concerned," Kohno said. Neither he nor Savage would name the maker of the car they conducted their tests on. They don't want to single out any one auto-maker, they said.
That probably comes as a relief to whomever made the car the researchers probed, as they found it pretty easy to hack.
"In starting this project we expected to spend significant effort reverse-engineering, with non-trivial effort to identify and exploit each subtle vulnerability," they write in their paper. "However, we found existing automotive systems—at least those we tested—to be tremendously fragile."

To hack the cars, they needed to learn about the Controller Area Network (CAN) system, mandated as a diagnostic tool for all U.S. cars built, starting in 2008. They developed a program called CarShark that listens in on CAN traffic as it's sent about the onboard network, and then built ways to add their own network packets.
Step-by-step, they figured out how to take over computer-controlled car systems: the radio, instrument panel, engine, brakes, heating and air conditioning, and even the body controller system, used to pop the trunk, open windows, lock doors and toot the horn.
They developed a lot of attacks using a technique called "fuzzing" -- where they simply spit a large number of random packets at a component and see what happens.
"The computer control is essential to a lot of the safety features that we depend on," Savage said. "When you expose those same computers to an attack, you can have very surprising results, such as you put your foot down on a brake pedal and it doesn't stop."
Another discovery: although industry standards say that onboard systems are supposed to be protected against unauthorized firmware updates, the researchers found that they could change the firmware on some systems without any sort of authentication.
In one attack that the researchers call "Self-destruct" they launch a 60 second countdown on the driver's dashboard that's accompanied by a clicking noise, and then finally warning honks in the final seconds. As the time hits zero, the car's engine is killed and the doors are locked. This attack takes less than 200 lines of code -- most of it devoted to keeping time during the countdown.
Hacking a car isn't for the faint-hearted. At several points the team worried it might have come close to permanently damaging the two identical-make cars it experimented with, but that never happened, Kohno said. "You really don't want software to accidentally change critical parts of the transmission," he said.

Sources:
http://www.computerworld.com/s/article/9176778/Car_hackers_can_kill_brakes_engine_and_more?taxonomyId=17&pageNumber=2




Graphics Card Drivers New Target For Cyber Attacks

It seems like nothing is safe from Internet attacks these days after a security consultancy warned that now graphics card drivers could be a new target for cyber hackers. British security consultancy Context disclosed in an advisory Thursday that security issues in WebGL, a browser Web standard designed to bring 3D graphics to Web pages on the Internet could leave users susceptible to denial of service and other cyber attacks.
WebGL is on by default in Firefox 4 and the recently hackable Google Chrome, and can be turned on in the latest versions of Safari.
The security issues enable hackers to execute malicious code on users' computers via a Web browser, which allows attacks on the GPU and graphics drivers that could render the entire machine unusable.
"These issues are inherent to the WebGL specification and would require significant architectural changes in order to remediate in the platform design," security researcher James Forshaw wrote oin the Context advisory.
The problem occurs in the way that the WebGL is implemented, and the way current PC and Graphics Processor architectures are designed, Forshaw said.
Unlike other browser content, WebGL provides direct access to the graphics hardware, employing shader code that's uploaded then executed directly on the system. However, current hardware and graphics pipeline implementations are not designed to maintain security boundaries, experts say.
"Once a display list has been placed on the GPU by the schedule, it can be difficult to stop it, at least without causing obvious, system-wide visual corruption and instabilities," Forshaw wrote.
Subsequently, hackers could obtain access to the hardware drivers by crafting malicious code, and tricking a victim into installing it by opening a malicious Web page or clicking on infected content embedded on a legitimate site.
In addition, the WebGL API's direct access to the hardware also flings the door wide open for denial of service attacks. Unlike typical DoS attacks, in which the user's Web experience is blocked, the WebGL DoS exploit would crash the operating system or prevent users from being able to access their computer.
Windows 7 and Vista are less susceptible to attacks than XP due to the fact that their OS will be forced to reset if the GPU locks up for around two seconds, stopping all applications from using 3D graphics.
In response to Context's advisory, the 3 to 5 Khronos Group, the open standards consortium that maintains WebGL specification, said it has developed a WebGL extension, called OpenGL, GL_ARB_robustness, "specifically designed to prevent denial of service and out-of-range memory access attacks from WebGL content."
Khronos Group says the extension has already been deployed by some GPU vendors, and predicts that it will rapidly gain adoption down the road. "Browsers can check for the presence of this extension before enabling WebGL content. This is likely to become the deployment mode for WebGL in the near future," Khronos Group said on its Web site.
However, Context said that the extension doesn't go far enough to address the issue, noting that resetting the graphics card and driver "should be seen as a crutch to OS stability" and not standard security mechanism.
Ultimately, Context said that WebGL wasn't ready for mass distribution, while recommending that users disable WebGL in their browsers.
"While there is certainly a demand for high-performance 3D content to be made available over the Web, the way in which WebGL has been specified insufficiently takes into account the infrastructure required to support it securely," according to the Context blog. 'Perhaps the best approach would be to design a specification for 3D graphics from the ground up with these issues in mind."



Source:

http://www.crn.com/news/security/229500616/graphics-card-drivers-new-target-for-cyber-atta