Showing posts with label Security Vulnerability. Show all posts
Showing posts with label Security Vulnerability. Show all posts

Wednesday, 27 May 2015

Crash iPhones by a specific text message

A new bug has been discovered in the Messages app, allowing a string of characters sent to a person via iMessage or SMS to crash an iPhone and cause the Messages app to crash after being opened. The bug, which requires a specific string of symbols and Arabic characters to be sent.

The bug is related to the Messages app and the notification system used by iPhone and iPad devices and appears to work only if there is iPhone to iPhone communication.When the user receives the message, he is not able to reopen the Messages app without reboot the mobile device. The only way to stop the problem is to get the sender of the malicious text message to send another message or wait for someone else to send a new one.
Since the string of characters is so specific, most users are unlikely to stumble across the bug.The sting that crashes the iPhone is" Power لُلُصّبُلُلصّبُررً ॣ ॣh ॣ ॣ 冗.
However, there are several workarounds that can undo the damage. The effect can be undone by sending another message (any normal text) to the person who sent you the malicious string, canceling out the initial strand.
Another option is to send the person who sent the the string a message using the share sheet by simply pressing the "share" button in other apps, or send yourself a message via Siri, or ask Siri to "send a message" to whoever sent it.



Wednesday, 20 May 2015

Logjam: A new encryption vulnerability

Researchers just discovered an online vulnerability currently being called LogJam - and it's believed to be affecting 8% of the world's biggest websites. What makes it so severe, however, is that the vulnerability stems from the type of technology most websites use to keep our personal information safe as it travels throughout the Web.

The bug affects an algorithm called the “Diffie-Hellman key exchange” which allows protocols such as HTTPS, SSH, IPsec, SMTPS to negotiate a shared key and create a secure connection.
Attack can only be possible if the attacker is sharing the same Wi-Fi network as you, it's extremely difficult to perform this attack unless your part of a large-scale surveillance program backed by millions of dollars.
All the same, the ramifications are still palpable. LogJam creates the sort of encryption backdoor at which state sponsored surveillance rings would salivate.
You can check whether your browser is vulnerable by clicking here. At the time of writing, some major browsers are still vulnerable to the Logjam attack. However, Google security team is already working to increase the SSL requirement in Chrome to 1024 bit.
So what to do? If you're an admin or the owner of a web or mail server, you'll want to check the researchers' guide to fixing it, which involves changing Diffie-Hellman cipher settings. If you just want to surf safely, check that you have the latest version of your browser installed -- Google Chrome, Mozilla Firefox, Microsoft Internet Explorer and Apple Safari are all releasing patches.

Millions of routers and other embedded devices are affected by Critical flaw in NetUSB driver

According to researcher Stefan Viehbock from SEC Consult Vulnerability Lab, the vulnerability, CVE-2015-3036, allows for an unauthenticated attacker on a local network to trigger a kernel stack buffer overflow which causes denial-of-service or permits remote code execution. In addition, some router configurations may allow remote attacks.

The vulnerability is located in a service called NetUSB, which lets devices connected over USB to a computer be shared with other machines on a local network or the Internet via IP (Internet Protocol). The shared devices can be printers, webcams, thumb drives, external hard disks and more.
NetUSB is a Linux kernel module that allows for users to flash drives, plug printers and other USB-connected devices into their routers so that they can be accessed over the local network.
NetUSB component is integrated into modern routers sold by some major manufacturers including D-Link, Netgear, TP-Link, ZyXEL and TrendNet.
We are recommending to disable the service (if supported by the vendor) and block port 20005 with a firewall. For Netgear devices there is no workaround according to the vendor – there is no possibility to disable the service or block the port with an integrated firewall. Hence an additional firewall would be needed
You should keep an eye out for patches too and update your devices as soon as patches are made available in order to prevent any possibility of NetUSB exploits.

Monday, 18 May 2015

VENOM (CVE-2015-3456):Security Vulnerability in Virtual Floppy Drive Code


VENOM, stands for Virtualized Environment Neglected Operations Manipulation, is a virtual machine security flaw uncovered by security firm CrowdStrike that could expose most of the data centers to malware attacks.
VENOM, CVE-2015-3456, is a security vulnerability in the virtual floppy drive code used by many computer virtualization platforms. This vulnerability may allow an attacker to escape from the confines of an affected virtual machine (VM) guest and potentially obtain code-execution access to the host. Absent mitigation, this VM escape could open access to the host system and all other VMs running on that host, potentially giving adversaries significant elevated access to the host’s local network and adjacent systems.

 According to the security advisory, the attackers can trigger the VENOM vulnerability by sending commands and specially crafted parameter data from the guest system to the vulnerable Floppy Disk Controller to cause the data buffer overflow and execute arbitrary code in the context of the host’s hypervisor process. The flaw is very dangerous because attackers could exploit it against a wide array of virtual machines, it is triggerable on default configurations, and would allow the arbitrary code execution.When considering on Linux guest machine, an attacker would need to have either root access or elevated privilege. However on Windows guest, practically anyone would have sufficient permissions to access the FDC.

Experts consider VENOM different from other vulnerabilities in the past that effect virtualized environments, since it exists in the hypervisor’s codebase it is independent from the specific host operating system (Linux, Windows, Mac OS, etc.).

The experts urge the administrators of a system running Xen, KVM, or the native QEMU client, to assess their system and apply the latest patches provided by their vendors. It is important to operate following the instructions provided by vendors verifying the application for the last VENOM patch.

Prevention Techniques: Cross-site request forgery (CSRF)

1. The best defense against CSRF attacks is unpredictable tokens, a piece of data that the server can use to validate the request, and wh...