Showing posts with label Vulnerabilities. Show all posts
Showing posts with label Vulnerabilities. Show all posts

Sunday, 28 September 2014

Shellshock bug could threaten millions as Compared to Heartbleed ~ Hack4friends


A programming flaw dubbed the “Bash Bug,” or more ominously “Shellshock,” is being described as potential threat to millions of computers, servers, medical devices, power plants and municipal water systems and even common objects such as refrigerators and cameras.
                                                              Image: just representation of shellshock                                    It is being compared to Heartbleed, a flaw in security software used by most of the Internet which allowed hackers to steal data such as passwords. Shellshock is similarly widespread and can be used to wreak more havoc. It allows hackers to take control of a vulnerable machine, steal data, shut down networks and cause other problems.
It was discovered Sep. 12 by Unix specialist Stéphane Chazelas and revealed on Wednesday.
According to Ars Technica, the bug is already being used to exploit Web servers. The initial fix for the bug was incomplete. Hours after news of the bug went public, security researchers detected evidence of hackers trying to exploit it.
The flaw affects a commonly used, free software system called Bash that has been around since 1989. According to the New York Times, it is built into 70 percent of machines that connect to the Internet.
Software-savvy people call it a “command shell.” It interprets instructions from users and programs so the computer knows what to do.
According to reports, it could affect your computer even if you’ve never heard of it. Bash is used in most Linux or Unix-based operating systems, including Apple’s Mac OS X, according to an alert from the Department of Homeland Security’s Computer Emergency Readiness Team (US-CERT).
The National Institute of Standards and Technology rated Shellshock a 10 on a 10-point severity scale. Heartbleed was rated five. Both flaws were rated low in terms of complexity, which means they can be easily exploited.
Discovered last spring, Heartbleed was a flaw in security technology used by thousands of Web sites that exposed passwords and other personal data to hackers for two years before it was discovered.
Shellshock has existed for 22 years, the Times noted. It doesn’t just expose your password — hackers can exploit the flaw to hijack your computer. Heartbleed only affected servers, while Shellshock affects many Internet-connected devices.
However, Shellshock could be harder to exploit, Christopher Budd, global threat communications manager at security firm Trend Micro, told theAssociated Press. Not all machines running Bash can be exploited. It’s not enough for Bash to be installed on your system; you have to be using it for a hacker to exploit the bug.
An Apple spokesman told the Web site iMore OS X systems are safe unless the user configured advanced UNIX services, something only advanced users would know how to do. If your Mac is vulnerable, you only have to worry if you are on a public WiFi network, according to the Times.
According to cybersecurity reporter Brian Krebs, the flaw does not affect Microsoft Windows. But the Times said it can affect Android phones.
The flaw affects embedded devices and systems. That includes things like digital watches, MP3 players and traffic lights. “In some areas this will be a challenge to fix, as many embedded devices are not designed with regular updates in mind and will never be able to be patched,” Joe Hancock, a cybersecurity expert with insurer AEGIS in London said in a statement reported by Reuters.
The bug could be exploited to take control of a Web server and steal passwords, Joe Siegrist, CEO of LastPass, a service that stores and protects passwords, told the AP. Though he said the threat of that happening is lower than with Heartbleed.
Shellshock is particularly dangerous because its “wormable,” a term that refers to self-replicating attacks that spread across devices and systems like a viral pandemic.
Power plants and water systems are less threatened if they have followed the advice of security experts and remain disconnected from the internet to avoid such risks, the AP reported.
“Who is at risk” is an open question, however. “Bash is embedded and accessed in so many ways that we cannot fully understand its depth of use,”wrote Securosis analyst and CEO Rich Mogull. “We cannot possibly understand all the ways an attacker could interact with Bash to exploit this vulnerability.”
There’s reportedly not much you can do about it, except check for software updates on the Web sites of companies that make your computer, router and other Internet-connected equipment. An open-source software company called Red Hat released a partial patch for Linux. Apple iscurrently working on a fix.
Google is also working on a fix, Reuters reported.
Five years after Bash was created by a programmer named Brian J. Fox, another programmer named Chet Ramey took over the job of maintaining the software in his free time, when he wasn’t working at his day job as a senior technology architect at Case Western Reserve University in Ohio, the Times reported.
Ramey told the Times he thinks he introduced the bug in a new Bash feature in 1992. After Chazelas, the security researcher that discovered it, contacted him on Sept. 12, they collaborated with other people who work with open-source security to create a patch within a few hours. They discreetly tipped off the major software makers so they could address the problem before hackers found out and exploited the bug.

Courtsey:WashingtonPost

Friday, 14 February 2014

Flappy Bird fakes are hatching Android malware ~ Hack4friends

Flappy Bird fakes are hatching Android malware ~ Hack4friends

Flappy Bird's takedown by its creator has given malware creators a new outlet to exploit unsuspecting users.
According to security firm Sophos, it has discovered several applications claiming to be Flappy Bird in third-party Android app marketplaces. The trouble, however, is that the games in some cases contain malware and in others force users to send a text message to a given number, effectively giving the malware creators all they need to potentially exploit users.


Another security firm, Trend Micro, also chimed in on the issue, saying that it has discovered "a bunch of fake Android Flappy Bird apps spreading online." Every one of those it has discovered so far are "apps that send messages to premium numbers, thus causing unwanted changes to victims' phone billing statements."
Flappy Bird has become a hot-button issue in the mobile world after the game soared to popularity and was subsequently taken down by its creator, Dong Nguyen. That was the opening malware creators needed, the security firms say, to take advantage of users who didn't have a chance to try out the game and want to see what all the hype is about.
Both Trend Micro and Sophos said that users shouldn't attempt to download anything calling itself Flappy Bird, since the original version is "dead." They also warned users to "be wary of apps from alternative markets."

Team hack4friends,
E-hackers

Snapchat hack spams users with smoothie photos ~ Hack4Friends

Snapchat hack spams users with smoothie photos ~ Hack4Friends

Snapchat is combating yet another security issue, and it's a juicy one.
In a story posted late Tuesday, Wired editor Joe Brown said his Snapchat friends were asking why he was sending them messages with photos of fruit smoothies. That was a surprise to Brown because he hadn't sent any such messages. Other Snapchatters have since complained about receiving these same messages, according to a Twitter search.
The messages serve up a URL for a company called Snapfroot, which then redirects the recipient to an AllRecipes.com page for a "Berry Delicious" smoothie. The spam outbreak so far seems innocuous, albeit annoying, but it does point to yet another vulnerability for the photo-sharing site.

Snapchat


Snapchat told Brown that these messages have been bouncing around the past couple of days.
"It's mostly cases where someone has your e-mail address and password and gets in on the first try," an anonymous Snapchat spokesperson told Wired. "We're not seeing any evidence of brute-force tactics."
Snapchat is trying to plug the leak. In the meantime, site users may want to change their passwords. The spokesperson also advised people to stay away from third-party apps that ask for your Snapchat username and password.
"Yesterday a small number of our users experienced a spam incident where unwanted photos were sent from their accounts," a Snapchat representative told Reuters. "Our security team deployed additional measures to secure accounts. We recommend using unique and strong passwords to prevent abuse."

Team Hack4friends,
E-hackers

Saturday, 8 February 2014

Adobe issues emergency Update for flash (Windows & MAC)

Adobe issues emergency Update for flash (Windows & MAC)

Adobe is recommending that users update their Flash Players immediately -- especially those who frequent Google Chrome and Internet Explorer. The company released an emergency security bulletin on Tuesday that addresses vulnerabilities in Flash, which could be exploited by hackers.


hack4friends, flash player

"This vulnerability could allow an attacker to remotely take control of the affected system," Adobe wrote in a blog post. "Adobe is aware of reports that an exploit for this vulnerability exists in the wild, and recommends users apply the updates referenced in the security bulletin."
Adobe assigned a Priority 1 rating to the vulnerabilities being exploited on Windows and Macintosh and advised users of both operating systems to install the update. That rating -- Adobe's highest threat level -- identifies "vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild." The bulletin also said that the Flash vulnerability faced by Linux users rated a Priority 3, which refers to "a product that has historically not been a target for attackers."
Adobe recommends users update to the latest versions:
Users of Adobe Flash Player 12.0.0.43 and earlier versions for Windows and Macintosh should update to Adobe Flash Player 12.0.0.44.
Users of Adobe Flash Player 11.2.202.335 and earlier versions for Linux should update to Adobe Flash Player 11.2.202.336.
Adobe Flash Player 12.0.0.41 installed with Google Chrome will automatically be updated to the latest Google Chrome version, which will include Adobe Flash Player 12.0.0.44 for Windows, Macintosh and Linux.
Adobe Flash Player 12.0.0.38 installed with Internet Explorer 10 will automatically be updated to the latest Internet Explorer 10 version, which will include Adobe Flash Player 12.0.0.44 for Windows 8.0.
Adobe Flash Player 12.0.0.38 installed with Internet Explorer 11 will automatically be updated to the latest Internet Explorer 11 version, which will include Adobe Flash Player 12.0.0.44 for Windows 8.1.

You can update your flash player from here Officially 

Team hack4friends,
E-hackers

Friday, 27 December 2013

Researchers report security flaw in Samsung's Galaxy S4

Researchers report security flaw in Samsung's Galaxy S4

 Here's some Grinchy news for those of you who put Samsung's Galaxy S4 on your holiday wish list: Israeli researchers have identified a vulnerability in the smartphone that allegedly allows a hacker to easily intercept secure data.

We did not immediately hear back from Samsung with a response to the reported flaw, but the company has told The Wall Street Journal and other news outlets that it's looking into the issues and thus far doesn't believe the problem is as serious as the researchers present in their findings.

The report comes not only as many Galaxy S4 phones sit wrapped up under Christmas trees, but also as Samsung pitches its new Knox security platform, used in the device, to federal agencies like the Department of Defense.
 The Knox software offers high-level encryption, a VPN feature, and a way to separate personal data from work data. It also enables IT administrators to manage a mobile device through specific policies, and Samsung hopes it will appeal to security-sensitive clients as a replacement for BlackBerry devices. Knox-enabled devices have already been approved by the Pentagon for government use.

The alleged vulnerability was discovered earlier this month by researchers at Ben-Gurion University's Cyber Security Labs. Specifically, they say while the Knox is the most advanced security-driven infrastructure for mobile phones, the alleged flaw enables malicious software to track e-mails and record data communications. The flaw was uncovered by Ph.D. student Mordechai Guri during an unrelated research task.

"Knox has been widely adopted by many organizations and government agencies and this weakness has to be addressed immediately before it falls into the wrong hands," he said. "We are also contacting Samsung in order to provide them with the full technical details of the breach so it can be fixed immediately." 

via Online Sources
Team- Hack4friends

Friday, 15 November 2013

Security holes found in D-Link Routers - Security Researchers

A new spate of vulnerabilities have been found in a D-Link router, a security researcher said Monday.
The D-Link 2760N, also known as the D-Link DSL-2760U-BN, is susceptible to several cross-site scripting (XSS) bugs through its Web interface, reported ThreatPost. 

Liad Mizrachi, the researcher who discovered the bugs, said he notified D-Link about the bugs in August, September, and October, but D-Link did not respond.
The report follows a more serious backdoor bug found in the following D-Link routers: DIR-100, DIR-120, DI-524UP, DI-604S, DI-604UP, DI-604+, DI-624S, and the TM-G5240. D-Link told ThreatPost in October that it was working on a patch to the backdoor bug.
Jacob Holcomb, a security researcher who uncovered widespread vulnerabilities in popular routers earlier this year, told media that he wasn't surprised by the backdoor bug, and wished that manufacturers would do more to fix security problems when found in embedded devices such as cameras and routers.
"Code written for these devices continues to provide inadequate security for today's digital society, and manufacturers should be held accountable for the implementation of code that intentionally circumvents security," he said.
D-Link told media that the router is not sold in the US and that the company is working on a solution that will be published on their support site when it's ready. D-Link did not offer a timeline for when that might be, though. 

Source - Online Media 

Team- Hack4friends
  

*****************************Thanks for Your kind Visit****************************

Receive All Free Updates Via Facebook.