Ads 468x60px

12/11/2011

New study - Chrome is number One !

     New study shown That, Google Chrome is The most Secured Browser, Followed by Internet Explorer, and Last Firefox.


     Google Chrome offers more protection against online attacks than any other mainstream browser, according to an evaluation that compares exploit mitigations, malicious link detection, and other safety features offered in Chrome, Internet Explorer, and Firefox.

    The 102-page report, prepared by researchers from security firm Accuvant, started with the premise that buffer overflow bugs and other security vulnerabilities were inevitable in any complex piece of software. Rather than relying on metrics such as the number of flaws fixed or the amount of time it took to release updates, the authors examined the practical effect protections included by default in each browser had on a wide class of exploits.

    Their conclusion: Chrome is the most secured browser, followed closely by Microsoft IE. Mozilla's open-source Firefox came in third, largely because of its omission of a security sandbox that shields vital parts of the Windows operating system from functions that parse JavaScript, images and other web content.
"We found that Google Chrome did the most sandboxing," Chris Valasek, who is a senior research scientist for Accuvant, told The Register. "It restricted the movements more than any other browser. Internet Explorer came up a close second because it implemented a sandbox where you could do certain things but you were allowed to do more things than you could in Chrome. Lastly, Firefox came in last because it didn't implement a sandbox yet."

    The report was commissioned by Google, but the authors insist they had complete autonomy in deciding what metrics to use and what conclusions they made. The researchers have released more than 20MB worth of data, software tools, and methodology so peers may review or build upon the research. The study focused solely on the security offered by Chrome, IE, and Firefox, which when combined account for more than 93 percent of web users, according to the report. All three browsers tested were run on Windows 7.
Their finding is backed up by anecdotal evidence, as well. Chrome has emerged unscathed during the annual Pwn2Own hacker contest  for three years in a row, something no other browser entered has done. Reports of in-the-wild exploits that target the browser are also extremely rare.

Not all sandboxes are equal

In much the way traditional sandboxes prevent sand from mixing with grass on a playground, security sandboxes isolate application code inside a perimeter that's confined from sensitive OS functions. By placing severe restrictions on an application's ability to read and write to the hard drive and interact with other peripheral resources, sandboxes are designed to lessen the damage attackers can do when they successfully exploit a vulnerability in the underlying code base.

The so-called token in the Chrome sandbox, for instance, doesn't allow browser processes to access files outside of an extremely limited set of directories. It also forbids them from creating connections known as network sockets to communicate directly with servers over the internet. The sandbox in IE, by contrast, allows browser resources to read almost all parts of a hard drive and puts few restrictions on the creation of network sockets, the researchers said.

As a result, attackers who exploit a vulnerability in the Microsoft browser will have an easier time accessing contacts, documents, and other data stored on the hard drive of a targeted computer and uploading it to a command and control server.

"The Google Chrome token is far more restrictive," said Accuvant Chief Research Scientist Ryan Smith, who compared tokens to a driver's license that spells out what vehicles a holder is permitted to drive and other conditions, such as whether eyeglasses are required. "It's more like a learner's permit, whereas the Internet Explorer token is more like a Class C regular driver's license."

The researchers analyzed each browser's ability to read files, write files, and perform 13 other actions. As indicated in the graphic below, Chrome blocked all but two of them. Of those, one known as "system parameters" was partially blocked. IE, meanwhile, completely blocked only two actions, and partially blocked seven more actions. Seven additional actions, including the ability to read files, access networks, and create processes, were completely unrestricted.

In last place was Firefox, which allowed nine actions and partially blocked the remaining six actions.

                                                                             (click on the picture to see it in real size)

Sin of omission

The report refers to sandboxing as a "standard best practice within many popular applications." Chrome implements sandboxes in versions that run on Windows, Mac OS X, and Linux. Microsoft deployed sandboxing more than five years ago, starting when users ran IE version 7 on Windows Vista or later versions of Windows. Even Apple, which commands a tiny fraction of the browser market, implemented a robust sandbox in versions of Safari that run on Lion, the latest release of OS X.
In this context, the continuing failure of Firefox to offer sandboxing features is hard to excuse.
In a statement issued prior to the release of Accuvant's report, Johnathan Nightingale, Mozilla's director of Firefox engineering, said:

"Firefox includes a broad array of technologies to eliminate or reduce security threats, from platform level features like address space randomization to internal systems like our layout frame poisoning system. Sandboxing is a useful addition to that toolbox that we are investigating, but no technology is a silver bullet. We invest in security throughout the development process with internal and external code reviews, constant testing and analysis of running code, and rapid response to security issues when they emerge. We're proud of our reputation on security, and it remains a central priority for Firefox.

Reining in add-ons

The researchers also gave Chrome high marks for the strict limitations it places on software add-ons that extend the things users can do with the browser. As a result, attackers who manage to exploit extension bugs or trick victims into installing malicious add-ons are severely limited in the damage they can do. By comparison, IE and Firefox give extensions much wider latitude. IE add-ons, for instance, have the ability to create processes and to access the Windows clipboard, which can be a means of funneling malicious data from one application to another.

The other area where Chrome outflanked its rivals was its offering of what's known as JIT hardening. Short for just in time, JIT refers to code that's compiled on the fly and executed inside the browser. Attackers have long relied on JIT techniques to convert JavaScript into malicious machine code that bypasses exploit mitigations such as ASLR.

JIT hardening in Chrome, and to a lesser extent in IE, counteract JIT attacks by compiling JavaScript in an unpredictable way that makes it hard for attackers to control. Mozilla developers have yet to implement the feature in Firefox.
                                                                             (click on the picture to see it in real size)

Besides ranking the security of the top three browsers, the paper argues that many of the metrics regularly used to gauge how well software stands up to hack attacks are unreliable. One such metric is the number of vulnerabilities patched, based on the assumption that more bugs indicate poorer-quality code than programs with fewer bugs. Other frequently cited factors include how quickly bugs are fixed and the severity of the bugs.

In the end, a browser will either succumb to a given exploit or it won't, and that's all that mattered to the paper's authors.

"We really didn't believe those [metrics] had much merit because it's really hard to correlate those things, especially between browsers and vendors," said Valasek, who along with Smith, was assisted by Accuvant colleagues Joshua Drake, Paul Mehta, Charlie Miller, and Shawn Moyer. "So we decided: Let's focus this paper on exploitation mitigation technology to show how these actually stand up against attackers when they find a vulnerability."

hacking 150 Subway shops by Four Romanians

     Four Romanian Hackers were charged with Stealing millions of dollars by hacking into the credit card processing systems of more than 200 businesses.
 

     The men remotely accessed point-of-sale systems of 150 Subway sandwich shops and 50 unnamed retailers and stealing credit card data for more than 80,000 customers, according to a federal indictment unsealed earlier this week. They used the stolen account information to make unauthorized purchases worth millions of dollars, prosecutors said.

     The men allegedly scanned the internet to identify POS terminals that used certain remote desktop software applications and then gained unauthorized access to them by guessing or brute forcing passwords.

    The indictment, filed in US District Court in New Hampshire, named Adrian-Tiberiu Oprea, 27, Iulian Dolan, 27, Cezar Iulian Butu, 26, and Florin Radu, 23. They were each charged with four counts, including conspiracy to commit computer fraud, wire fraud, and two counts of conspiracy to commit fraud in connection with access device.

12/07/2011

DDoS attack heats Korean election !

 A political scandal in Republic of  Korea over alleged denial of service attacks against the National Election Commission (NEC) website.


     Police have arrested the 27-year-old personal assistant of ruling Grand National Party politician Choi Gu-sik over the alleged cyber-assault, which disrupted a Seoul mayoral by-election back in October.
However, security experts said that they doubt the suspect, identified only by his surname "Gong", had the technical expertise or resources needed to pull off the sophisticated attack. Rather than knocking the NEC website offline, the attack made a portion of the website – offering information on voting booth locations – inaccessible.

      Despite this issue resembling a technical fault rather than a DDoS attack, the incident is being treated as a criminal attack by the police, who have arrested Gong and charged him along with three others.
Police said that the "attack", which lasted for more than two hours, was launched using a total of 10 wireless internet connections, including five T-Login and five WiBro connections. Police speculated that this was either a way of making it harder to thwart the attack or an attempt to complicate police efforts to investigate the assault. A police official told Korean daily newspaper The HankYoreh: “This went beyond simply using zombie PCs and wireless internet to launder IP addresses. It was a sophisticated attack.”

      Opposition groups argue that the early morning timing of the attack was carefully designed to disrupt the voting of young commuters, who are more likely to vote for opposition (liberal) candidates. They want to force a parliamentary audit or special prosecutor’s investigation if the police investigation fails to get to the bottom of the attack.

       Gong continues to protest his innocence, a factor that has led opposition politicians to speculate that he is covering up for higher-ranking officials who ordered the attack.
Democratic Party politician Baek Won-woo told The HankYoreh: “We need to determine quickly and precisely whether there was someone up the line who ordered the attack, and whether there was compensation.”

Hackers :Facebook security hole exposes Mark Zuckerberg's privates !!!

      A security error on Facebook Social Network has been exposing private pictures of countless users, including the Facebook's founder and CEO Mark Zuckerberg.
      
      A photo pilfering exploit posted to bodybuilding.com forum on Monday included step-by-step instructions for viewing pictures designated as private by the Facebook users who posted them. It worked by manipulating a feature that allows people to report inappropriate profile pictures to Facebook officials. The routine allowed snitches to report additional pictures, even when designations made the images off-limits to all but a select set of friends.
     Not all the participants in the forum reported success. It would appear that those located in the US got better results than others. Several hours after the disclosure vulnerability was reported, 13 images purportedly lifted from Zuckerberg's account were posted below a headline that read: “It's time to fix those security flaws Facebook...”
    They show Zuck wining and dining with friends, chatting with President Barack Obama, and holding what appears to be a freshly slaughtered chicken, in keeping with a recent predilection to eat only meat he has killed himself.
In a statement, Facebook officials said:
Earlier today, we discovered a bug in one of our reporting flows that allows people to report multiple instances of inappropriate content simultaneously. The bug allowed anyone to view a limited number of another user's most recently uploaded photos irrespective of the privacy settings for these photos. This was the result of one of our recent code pushes and was live for a limited period of time. Upon discovering the bug, we immediately disabled the system, and will only return functionality once we can confirm the bug has been fixed. The privacy of our user's data is a top priority for us, and we invest significant resources in protecting our site and the people who use it. We hire the most qualified and highly-skilled engineers and security professionals at Facebook, and with the recent launch of our Security Bug Bounty Program (http://www.facebook.com/whitehat/ ), we continue to work with the industry to identify and resolve legitimate threats to help us keep the site safe and secure for everyone.
     It's not the first time someone has figured out how to bypass Facebook permissions designed to give users tight control over who gets to see images and announcements posted to their pages. In 2008, a Canadian computer technician was able to view private photos of Paris Hilton, Zuckerberg, and others by guessing the ID of the photo. Last year, the social network was caught exposing the name and photo of all 500 million of its users when their email addresses were typed in to the log-in page.

     Monday's discovery of yet another hole in Facebook's safety net is the latest reminder that the only way to be sure something doesn't get published to world+dog is to keep it off the internet in the first place. Permission systems such as those on Facebook and other sites may make users feel better, but they have little effect on hackers with enough determination or time on their hands.

12/03/2011

Yahoo! Zero-day(0day)! status! updates! exploit! hijacks!

     New unpatched flaw in yahoo is causing trouble for thier client and thier users!!



   Security researchers have discovered an unpatched flaw in Yahoo! Messenger that allows miscreants to change any user's status message.

     Hijacked status updates are a handy way to persuade a victim's contacts to click on a link and lead them to a dangerous website. Worse still, the bug in version 11.x of the Messenger client requires minimal user interaction to work, unlike previous exploits that relied on coning prospective marks.

    The attacker sends a supposed file to a target that is actually an iframe that swaps the status message for the attacker's customised text, as explained in a blog post by net security firm BitDefender here. The message might be, and in most attack scenarios would be, sent firm outside a targeted user's contact list.

    If successfully executed, a victim will have no indication that his or her status message has been rewritten. The ruse might be used to gain affiliate incomes by promoting dodgy sites as well as directing users towards sites loaded with exploits or scareware scams.

     Bitdefender said it has notified Yahoo about the vulnerability. Attacks based on the as yet unfixed flaw have already been detected in the wild, the Romanian security firm warns.

    It advises users to change the setting of their IM client to “ignore anyone who is not in your Yahoo! Contacts" (which is off by default) as a precaution pending the release of a patch. In addition, some security suites include a web filter function that ought to defend users from this attack.

12/02/2011

Duqu attackers: Linux rookies, master coders, Amateurs Mistakes

      The malware attack that've been targeted many companies, including Iran's nuclear program. Speculation. so what is this malware attack ?

 
      The Duqu* malware that targeted industrial manufacturers around the world may have been spawned by a well-funded team of competent coders, but their command of Linux led to some highly amateur mistakes.
 
       According to a report published on Wednesday by researchers from Kaspersky Lab, the unknown attackers attempted a global cleanup on a dozen or more hacked Linux servers they used to control systems infected with Duqu. The mass purge on machines running CentOS 5.x came on October 20, two days after researchers publicly compared Duqu to the Stuxnet worm that sabotaged Iran's nuclear program. Speculation is the operators were trying to cover their tracks.

      In their haste, the attackers appear to have made some critical mistakes. Servers in Vietnam and Germany contained partial logs of the hackers' SSH and bash sessions that remained on the / partition.
“This was kind of unexpected and it is an excellent lesson about Linux and the ext3 file system internals,” Kaspersky researcher Vitaly Kamluk wrote. “Deleting a file doesn't mean there are no traces or parts, sometimes from the past. The reason for this is that Linux constantly reallocates commonly used files to reduce fragmentation.”

      The sshd.log files show the attackers logging into the Vietnam-based machine in July and in October just prior to mass purge. The Germany-based system also showed evidence of being accessed on November 23, 2009 and the user receiving error messages indicating that attempts to redirect traffic on ports 80 and 443 had failed. The breadcrumbs may have been few, but they were enough to show that the servers weren't true command and control channels, but rather proxies designed to conceal the attackers' true origin.
Using similar techniques, the Kaspersky researchers unearthed evidence that every hacked server had its OpenSSH 4.3 application upgraded to version 5.8. A recovered bash history on the machine in Germany also showed the attackers needed refreshers in basic Linux administration. At one point, they referenced the sshd_config manual, and at another juncture, they needed to check documentation for the Linux ftp client. They also botched the command line syntax for the Linux iptables.

       The attackers also left behind traces of changes they made to the sshd-config file. One of them speeds up port directions over tunnels, which is simple enough change to understand. The other enabled Kerberos authentication. The Kaspersky researchers still aren't sure what the motive is for the latter modification.
So far, the researchers say, they've analyzed only a fraction of compromised servers, which among other places, were located in Singapore, Switzerland, the UK, the Netherlands, Belgium, and South Korea. It will be interesting to see what evidence they're able to exhume from additional machines. In the meantime they're hoping Linux admins can help them ponder a few questions, including:
  • Why the preoccupation with updating OpenSSH 4.3 to version 5.8 as soon as a machine had been commandeered?
and
  • Is there any relationship between the updates and the modification to “GSSAPIAuthentication yes” made to the sshd-config file?
“We hope that through cooperation and working together we can cast more light on this huge mystery of the Duqu trojan,” Kamluk wrote. Tipsters can reach his team at “stopduqu AT Kaspersky DOT com.”

(* Duqu : Duqu is a malicious computer virus that is designed to gather intelligence data from entities such as industrial control manufacturers in order to be able to launch a future attack on an industrial control facility.)

Source : The Register.

12/01/2011

Nearly half of the attacks exploit vulnerabilities in Java default updates !!

         Nearly half of the attacks exploit vulnerabilities in Java default updates, according to the Microsoft Security Intelligence Report.
        The exploits against computer security in the first half of 2011 were largely associated with the vulnerabilities of the family of Java products, technology maintained by Oracle.
    The report Security Intelligence of Microsoft said indeed a record: one-third to half of the exploits are due to flaws in the runtime environment (JRE) Virtual Machine (JVM) and the JDK.
      Oracle does not unduly slow to offer patches, the problem lies in their spread, diagnostic Tim Rains, director of Trustworthy Computing at Microsoft.
     "Many of the faults most commonly used Java is old, and had had security updates for years." Thus, the solutions used by the attackers are long, because the attackers who develop, or redeem kits hackers continue to get a positive return on investment, observes Tim Rains.
      For example, the most exploited vulnerability (CVE-2010-0840, affecting the JRE) was revised in March 2010 and waited until the last quarter of that year to gain popularity among malicious hackers.
     The problem is further exacerbated as often, several major versions of the runtime language coexist on the same machine (based solutions that require their presence).
The report from Microsoft based on the number of exploits arrested by the anti-malware solution, blocked with 27.5 million of attacks over the past 12 months.

     If Tim Rains prefers to emphasize the need for updates to users and sysadmins, Chester Wisniewski of Sophos will immediately advise to switch to Java: "Most people do not use Java nowadays and it [does not install Java] reduces the attack surface from the Internet, "says he.


     *Download The rapport


Source : Blog officiel de la sécurité Microsoft.