Showing posts with label security news. Show all posts
Showing posts with label security news. Show all posts

Sunday, 28 September 2014

Shellshock bug could threaten millions as Compared to Heartbleed ~ Hack4friends


A programming flaw dubbed the “Bash Bug,” or more ominously “Shellshock,” is being described as potential threat to millions of computers, servers, medical devices, power plants and municipal water systems and even common objects such as refrigerators and cameras.
                                                              Image: just representation of shellshock                                    It is being compared to Heartbleed, a flaw in security software used by most of the Internet which allowed hackers to steal data such as passwords. Shellshock is similarly widespread and can be used to wreak more havoc. It allows hackers to take control of a vulnerable machine, steal data, shut down networks and cause other problems.
It was discovered Sep. 12 by Unix specialist Stéphane Chazelas and revealed on Wednesday.
According to Ars Technica, the bug is already being used to exploit Web servers. The initial fix for the bug was incomplete. Hours after news of the bug went public, security researchers detected evidence of hackers trying to exploit it.
The flaw affects a commonly used, free software system called Bash that has been around since 1989. According to the New York Times, it is built into 70 percent of machines that connect to the Internet.
Software-savvy people call it a “command shell.” It interprets instructions from users and programs so the computer knows what to do.
According to reports, it could affect your computer even if you’ve never heard of it. Bash is used in most Linux or Unix-based operating systems, including Apple’s Mac OS X, according to an alert from the Department of Homeland Security’s Computer Emergency Readiness Team (US-CERT).
The National Institute of Standards and Technology rated Shellshock a 10 on a 10-point severity scale. Heartbleed was rated five. Both flaws were rated low in terms of complexity, which means they can be easily exploited.
Discovered last spring, Heartbleed was a flaw in security technology used by thousands of Web sites that exposed passwords and other personal data to hackers for two years before it was discovered.
Shellshock has existed for 22 years, the Times noted. It doesn’t just expose your password — hackers can exploit the flaw to hijack your computer. Heartbleed only affected servers, while Shellshock affects many Internet-connected devices.
However, Shellshock could be harder to exploit, Christopher Budd, global threat communications manager at security firm Trend Micro, told theAssociated Press. Not all machines running Bash can be exploited. It’s not enough for Bash to be installed on your system; you have to be using it for a hacker to exploit the bug.
An Apple spokesman told the Web site iMore OS X systems are safe unless the user configured advanced UNIX services, something only advanced users would know how to do. If your Mac is vulnerable, you only have to worry if you are on a public WiFi network, according to the Times.
According to cybersecurity reporter Brian Krebs, the flaw does not affect Microsoft Windows. But the Times said it can affect Android phones.
The flaw affects embedded devices and systems. That includes things like digital watches, MP3 players and traffic lights. “In some areas this will be a challenge to fix, as many embedded devices are not designed with regular updates in mind and will never be able to be patched,” Joe Hancock, a cybersecurity expert with insurer AEGIS in London said in a statement reported by Reuters.
The bug could be exploited to take control of a Web server and steal passwords, Joe Siegrist, CEO of LastPass, a service that stores and protects passwords, told the AP. Though he said the threat of that happening is lower than with Heartbleed.
Shellshock is particularly dangerous because its “wormable,” a term that refers to self-replicating attacks that spread across devices and systems like a viral pandemic.
Power plants and water systems are less threatened if they have followed the advice of security experts and remain disconnected from the internet to avoid such risks, the AP reported.
“Who is at risk” is an open question, however. “Bash is embedded and accessed in so many ways that we cannot fully understand its depth of use,”wrote Securosis analyst and CEO Rich Mogull. “We cannot possibly understand all the ways an attacker could interact with Bash to exploit this vulnerability.”
There’s reportedly not much you can do about it, except check for software updates on the Web sites of companies that make your computer, router and other Internet-connected equipment. An open-source software company called Red Hat released a partial patch for Linux. Apple iscurrently working on a fix.
Google is also working on a fix, Reuters reported.
Five years after Bash was created by a programmer named Brian J. Fox, another programmer named Chet Ramey took over the job of maintaining the software in his free time, when he wasn’t working at his day job as a senior technology architect at Case Western Reserve University in Ohio, the Times reported.
Ramey told the Times he thinks he introduced the bug in a new Bash feature in 1992. After Chazelas, the security researcher that discovered it, contacted him on Sept. 12, they collaborated with other people who work with open-source security to create a patch within a few hours. They discreetly tipped off the major software makers so they could address the problem before hackers found out and exploited the bug.

Courtsey:WashingtonPost

Sunday, 10 August 2014

Google preferring HTTPS over HTTP in google ranking (SEO) ~ Hack4friends

Google announced that websites using HTTPS, the secure version of HTTP, will have a better chance of ranking well in Google searches than those that don't.

In the vernacular, HTTPS is now a ranking signal for SEO (Search Engine Optimisation). It could be an inflection point for web security.

Security is a top priority ... over the past few months we’ve been running tests taking into account whether sites use secure, encrypted connections as a signal in our search ranking algorithms. We've seen positive results, so we're starting to use HTTPS as a ranking signal.

By making HTTPS something that impacts search results Google are applying the stick to an enormous security push that's been all carrots up to now.

Everywhere you look, from better SSL to the tricky business of end-to-end email security, Google are busy rolling out encryption or giving people ways to encrypt things.

Anyone who doubts the energy and seriousness that Google applies to this kind of thing or the effect that it can have need only wind the clock back five years.

In 2009, Google announced they wanted to make the web faster.

Google HTTPSIt wasn't a soundbite, a speech, a project or a campaign - it was a sea change.

Since then Google has created, amongst many other things, a fast public DNS service, a faster web protocol, tools to speed up websites, tools to make code smaller, an image format to make images download faster and a global content distribution network for commonly used code.

They even built their own web browser with a very fast javascript engine and spent millions and millions of dollars banging on about how fast it was.

Most importantly of all they made speed a ranking signal for SEO.

Making speed a ranking signal punished slowness. It's what made organisations care.

To understand why, you need to understand a little of how search engines work and how companies approach getting their websites noticed.

Google uses computer programs (referred to as spiders) to read the world's web pages and index them. The spiders try to determine the subject and quality of each page by measuring a multitude of different factors, known as signals.

The strength of the signals determines where those pages will rank when somebody types a search into the Google search engine.

Good signals means high rankings, more traffic and more revenue. Poor signals can put you out of business.

There are hundreds of signals but they aren't all equally important - some have far more impact than others. To prevent people from gaming their system Google is deliberately vague about how many signals it cares about, what they are and how much each one matters.

Thanks to a lot of research and some vague pronouncements from Google we have a pretty good idea of what some of the signals are and some idea of their weighting.

According to their blog, HTTPS will start off as a weak signal:

For now it's only a very lightweight signal — affecting fewer than 1% of global queries, and carrying less weight than other signals such as high-quality content — while we give webmasters time to switch to HTTPS. But over time, we may decide to strengthen it, because we’d like to encourage all website owners to switch from HTTP to HTTPS to keep everyone safe on the web.

In reality, in my experience at least, even low strength signals get plenty of attention.

Because Google is cagey about what signals are worth, because organisations can't easily test and isolate their website's signals and because there is intense competition for good Google rankings those that care about SEO will generally act on any ranking factors that are well defined, regardless of how small their effect.

Companies like nothing better than lists with ticks next to them so if a ranking factor comes down to a simple yes or no choice it gets done.

Before Google made site speed a ranking factor I hardly ever had conversations with organisations about how fast their websites were. Now we always talk about it.

From now on they'll have something else to talk about - a simple binary choice: "Does our website use HTTPS?"

Increasingly the answer will be yes.

Source: compiled from online sources

Friday, 14 February 2014

Flappy Bird fakes are hatching Android malware ~ Hack4friends

Flappy Bird fakes are hatching Android malware ~ Hack4friends

Flappy Bird's takedown by its creator has given malware creators a new outlet to exploit unsuspecting users.
According to security firm Sophos, it has discovered several applications claiming to be Flappy Bird in third-party Android app marketplaces. The trouble, however, is that the games in some cases contain malware and in others force users to send a text message to a given number, effectively giving the malware creators all they need to potentially exploit users.


Another security firm, Trend Micro, also chimed in on the issue, saying that it has discovered "a bunch of fake Android Flappy Bird apps spreading online." Every one of those it has discovered so far are "apps that send messages to premium numbers, thus causing unwanted changes to victims' phone billing statements."
Flappy Bird has become a hot-button issue in the mobile world after the game soared to popularity and was subsequently taken down by its creator, Dong Nguyen. That was the opening malware creators needed, the security firms say, to take advantage of users who didn't have a chance to try out the game and want to see what all the hype is about.
Both Trend Micro and Sophos said that users shouldn't attempt to download anything calling itself Flappy Bird, since the original version is "dead." They also warned users to "be wary of apps from alternative markets."

Team hack4friends,
E-hackers

Snapchat hack spams users with smoothie photos ~ Hack4Friends

Snapchat hack spams users with smoothie photos ~ Hack4Friends

Snapchat is combating yet another security issue, and it's a juicy one.
In a story posted late Tuesday, Wired editor Joe Brown said his Snapchat friends were asking why he was sending them messages with photos of fruit smoothies. That was a surprise to Brown because he hadn't sent any such messages. Other Snapchatters have since complained about receiving these same messages, according to a Twitter search.
The messages serve up a URL for a company called Snapfroot, which then redirects the recipient to an AllRecipes.com page for a "Berry Delicious" smoothie. The spam outbreak so far seems innocuous, albeit annoying, but it does point to yet another vulnerability for the photo-sharing site.

Snapchat


Snapchat told Brown that these messages have been bouncing around the past couple of days.
"It's mostly cases where someone has your e-mail address and password and gets in on the first try," an anonymous Snapchat spokesperson told Wired. "We're not seeing any evidence of brute-force tactics."
Snapchat is trying to plug the leak. In the meantime, site users may want to change their passwords. The spokesperson also advised people to stay away from third-party apps that ask for your Snapchat username and password.
"Yesterday a small number of our users experienced a spam incident where unwanted photos were sent from their accounts," a Snapchat representative told Reuters. "Our security team deployed additional measures to secure accounts. We recommend using unique and strong passwords to prevent abuse."

Team Hack4friends,
E-hackers

Tuesday, 24 December 2013

MacBook Webcams can be used to covertly spy on people -- With proof

MacBook Webcams can be used to covertly spy on people -- With proof

Imagine going about your daily life and then one day receiving photos of yourself from inside your home. Sound spooky? Well, this really happened to a woman named Cassidy Wolf, according to the Washington Post. And, to make matters worse, she was nude in the photos.

How did this happen?
Apparently, there's a way for hackers to spy on people via their iSight Webcams in older Apple MacBooks. Typically, when the camera is on a little light is also set off. But, in a newly discovered workaround, this light can be deactivated -- meaning unsuspecting victims have no clue they're being watched.
The Washington Post revealed this new research by Johns Hopkins computer scientist Stephen Checkoway, which shows how people can be spied on with MacBooks and iMacs released before 2008. Using proof-of-concept software, called Remote Administration Tool or RAT, Checkoway was able to reprogram the iSight camera's micro-controller chip so that the light doesn't turn on.

While it could be feasible to do this trick on newer Apple computers or laptops by other brands, it hasn't yet been proven possible.
In the case of Wolf, who was Miss Teen USA, the person spying on her was her high school classmate Jared Abrahams. The FBI was able to nab Abrahams, who pleaded guilty to extortion in October.
In another report by the Washington Post, the former assistant director of the FBI's Operational Technology Division Marcus Thomas said the FBI has been activating computer cameras without turning on the warning lights for years.

This is not the first time someone has been remotely spied on with a Webcam, but it is the first known time that it's been done without the warning light being triggered.

Team Hack4friends

Sunday, 1 December 2013

Google upgraded its web security certificate to 2048-bit encryption

Google upgraded its web security certificate to 2048-bit encryption

Never again are you going to get a Google Web site whose security certificate is protected with comparatively weak 1,024-bit encryption.
The Net giant has secured all its certificates with 2,048-bit RSA encryption keys or better, Google security engineer Dan Dulay said in a blog post Monday. Certificates are used to set up encrypted communications between a Web server and Web browser.
That means two things. First, traffic will be harder to decrypt since 1,024-bit keys aren't in use at Google anymore. Second, retiring the 1,024-bit keys means the computing industry can retire the technology altogether by declaring such keys untrustworthy.

Click to enlarge this image

Google has been aggressively moving to stronger encryption because of U.S. government surveillance by the National Security Agency. According to documents leaked by former NSA contractor Edward Snowden, the agency gathered bulk data off Internet taps, including unencrypted data sent between company data centers on its own network, and actively worked to undermine encryption.
Google said it beat its internal end-of-year deadline for the 2,048-bit move. It's also moved to encrypt its internal data transfer between data centers, a move that Yahoo also is making.
In other words, the Net's technology giants are working actively to make surveillance, authorized or not, significantly harder.
"Worry in Silicon Valley/Puget Sound: furor over NSA will cost billions cuz foreign customers fear US companies can't guarantee security," tweeted Strobe Talbott, president of analyst firm Brookings Institution, referring to the geographic regions where tech powers such as Google, Facebook, Yahoo, Microsoft, Twitter, Apple, LinkedIn, and Amazon are located.
There's a lot of work to be done yet, though.Google also supports a standard called "forward secrecy," which uses different keys for different sessions so that decrypting a single message doesn't mean previous messages can likewise be decrypted using the same key. But many other Net giants don't support forward secrecy -- though that's changing, too.
Source -Online media
Team Hack4friends
If you little like our posts/article then share them with your friends and other people to spread our voice throughout the world.

*****************************Thanks for Your kind Visit****************************

Receive All Free Updates Via Facebook.