Monday, October 26, 2015

October's Patch Tuesday covers Windows, IE, Edge and Office

In October's Patch Tuesday, Microsoft rolled out SIX security bulletins that contain more than 30 vulnerabilities targeting Windows, Internet Explorer, Edge, and Office. Out of 6 bulletins released, 3 of them are rated as 'CRITICAL'. MS15-106 a critical rated bulletin addresses 14 vulnerabilities in the Internet Exlporer. The issues fixed in this bulletin are related to memory corruption, privilege escalation, information disclosure, and VBScript and JScript ASLR bypass issues. Another critical-rated bulletin is MS15-108 that patches various issues related to information disclosure, memory corruption, and ASLR bypass vulnerabilities in the VBScript and JScript scripting engines in Windows. Third and the last critical bulletin addresses a flaw in the Microsoft Windows that allows remote code execution by opening a specially crafted toolbar object in Windows. <more>

Wednesday, September 23, 2015

Apple iOS 9 PATCHES Airdrop flaw

Apple has released an update for iOS 9, fixes a critical security flaw allowing intruders to inject malicious files in iPhones that can be used to hijack victim's phone later on. Security researcher Mark Dowd from Azimuth Security found the issue which affects almost all devices using iOS 7 or later, along with all Mac OS X Yosemite versions. According to PoC where Mark Dowd was forcing crafted files to an iPhone using Apple's AirDrop, even though the request to transfer was denied by the user. AirDrop provides file sharing facility between iOS and OS X devices using WiFi and/or Bluetooth. AirDrop is vulnerable to directory traversal attack allowing intruders to make modification in victim's OS setting and install malicious apps and rest will be done accordingly. All an attacker needs to install a malicious app is to have a legitimate Apple enterprise certificate to validate the app's installation process. <more>

Beware!! Android Lollipop users

Researchers from University of Texas has found a security flaw in the lock screen feature of Android 5.x. According to John Gordon, a network security analyst at the University of Texas, the issue exists in the password field - unable to handle a sufficiently long string while the camera app is active, allowing an attacker to crash the lock screen. From the locked screen, one can easily bypass the security. The potential attacker can open the emergency call window, fill it with characters, then copy those into the password field via the settings option on the locked screen until the user interface crashes. By using USB debugging normally allows access to vulnerable device to execute arbitrary command or gain access to files with full rights. Google was notified about the issue earlier this year and responded swiftly to release a security patch in June to rectify this issue. Google urge users to apply updates on earliest basis. <more>

Monday, September 7, 2015

Google Chrome 45 addresses 29 flaws

Google has released Chrome 45 to address 29 security flaws affecting Windows, Mac, and Linux platforms. According to Google advisory, Six issues are rated as CRITICAL allowing remote code execution. These high-severity issues addressed cross-origin bypass flaws in DOM, covered in CVE-2015-1291 and CVE-2015-1293, where as a cross-origin bypass issue occurs in Service Worker that is covered in CVE-2015-1292. Besides this, multiple use-after-free flaws in Skia (CVE-2015-1294) and Printing (CVE-2015-1295), and a character spoofing bug in the Omnibox address bar (CVE-2015-1296). The latest version also patched medium severity vulnerabilities in WebRequests, extensions and in the Blink web browser engine. Google credits security researchers Mariusz Mlynski, Rob Wu, Alexander Kashev, and experts using the online monikers taro.suzuki.dev, cgvwzq, cloudfuzzer, and zcorpan for finding vulnerabilities in the browser. So far, company has given rewards of $40,500 through bug bounty program. Morever, Google has decided to stop running Flash Ads due to various flaws found in Adobe Flash from time to time. Google is automatically converting most of the Flash ads uploaded to AdWords to HTML5, otherwise it can be done manually using a tool provided by the company. <more>

Bugzilla hack eXposes Firefox 0-day flaw

Mozilla confirmed about Bugzilla breached by an attacker who was able to get access to sensitive information about zero-day flaws in Firefox. According to Mozilla, the intruder was able to breach a high-level user's account who had access to Bugzilla that contains information of non-public zero-day security flaws. Mozilla said attacker took control of the account since September 2013 and accessed approximately 185 vulnerabilities that were non-public, where 53 vulnerabilities considered CRITICAL flaws. However, company claims 43 of the severe flaws had already been patched, but 10 unpatched security flaws are still in the hands of intruder which pose a huge security risk for Firefox users. <more>

Wednesday, August 5, 2015

Not Again !! Another bug puts Android phone @ risk

Earlier it was Zimperium that informed about the Stagefright flaw affecting nearly 950 million (95%) smartphone across the globe, and now its Trend Micro turns to come up with another security flaw in the Android mediaservice which can cause your smartphone to become unresponsive. As compare to Stagefright bug, this new vulnerability affects Android versions 4.3 and above. So statistically 56.8% users are affected to this flaw. According to security researcher from Trend Micro, attackers can exploit the vulnerability using a malicious app installed and running on the user's device, or by accessing a URL where a malformed media file is hosted. For demonstration purpose, researcher choked the mediaserver service using a malformed MKV file. The issue exists in the way mediaserver service reads data from a Matroska media container, which is used with the .mkv extension. <more>

BIND Critical flaw causes Internet outage

Widely used DNS server software - BIND is under attacked to cause disruption in the internet service for many users. The BIND versions 9.1.0 to 9.10.2-P2 are affected and can be exploited to crash DNS servers that are powered by the software. Internet Systems Consortium (ISC) has released a patch to rectify this critical issue that affects both authoritative and recursive DNS servers with a single packet. ISP configures recursive DNS servers for most computers and routers. If those DNS servers becomes unresponsive due to any circumstances, the computers that users that use them will not be able to find websites. According to ISC advisory, patching is the only available option so operators are required to apply the security patch as early as possible. <more>

Tuesday, July 7, 2015

Apple PATCHES OS X and iOS bugs

Apple has releases patches for various security flaws found in its desktop and mobile operating systems. Apple users are waiting for the new releases of iOS 9 and OS X 10.11, but they have to apply security updates for iOS 8 and OS X 10.10. It is believed to be the first major Apple security patch updates since April 8. OS X 10.10.4 security update fixes three vulnerabilities in Apple's Admin framework allowing intruders to get full admin rights.  Apple Type Services also get the fix for four vulnerabilities allowing remote code execution on the compromised systems. Similarly, six security flaws have been fixed in the CoreText library. One fix is for Apple's high-speed Thunderbolt interface that could allow intruders to execute arbitrary code. Intel graphics driver used in OS X is being patched for eight vulnerabilities mostly occur due to buffer overflow. Apple iOS 8.4 addresses 30 vulnerabilities across Safari’s browser engine, the WiFi manager, the SQLite library, Safari, Mail, the OS kernel, FontParser, coreTLS and CoreText. Company urges users to apply the update on earliest basis. <more>

'Selfies' a new authentication method for MasterCard

Taking selfies usually considered by many people as a mental disorder and we have read several reports regarding this, but not anymore now as one of the largest online payment system is going for a trial to take selfies as replacement authentication for passwords. MasterCard said that it will test this new mechanism just to know that how much it will be effective to minimize fraud threats. Facial recognition is not new as several smartphones use this feature to unlock the device. Although security researchers still obscure about the robustness of such authentication system as there are multiple instances in the past where intruders are able to bypass the mechanism. If all goes well, MasterCard plans to integrate facial recognition in smartphone application that initiates when a payment needs to be made, asking for authorization through fingerprint or facial analysis. <more>

Monday, June 29, 2015

ZERO day fix for Adobe Flash Player

Adobe systems has released an out-of-cycle security patch to fix critical zero-day flaw in a Flash plugin that could allow remote code execution on a compromised system. According to advisory, this critical issue is covered in CVE-2015-3113 and affects Flash Player 18.0.0.161 and earlier versions on Windows and Mac, and version 11.2.202.466 and earlier releases on Linux. Adobe credits FireEye security researchers for finding it which was exploited in a phishing campaign. IE for Windows 7 and earlier along with Firefox on Windows XP are considered prime targets. However, Chrome users has not found with such attacks. Company urges users to apply the patch on earliest basis. <more>

HP releases unpatched IE exploit code

Although Microsoft paid a huge amount of $125,000 for finding Address Space Layout Randomisation (ASLR) vulnerability in Internet Explorer 11 to HP's Zero Day Initiative. Company still not eager to release the security patch to address the flaw. After Microsoft refusal, HP has decided to publish Proof-of-Concept code that could be used to exploit the vulnerability. According to HP, they are concerned about users and wanted to inform about the issue and then it's users call whatever they feel appropriate, where as, Microsoft believes that flaw does not affect the default configuration of IE, so there is no need to apply any fix for it. <more>

Tuesday, June 23, 2015

0-day identified in Apple OSX and iOS

Security researchers have spotted 0-day vulnerabilities targeting Apple operating systems, i.e., Mac OS X and iOS. The impact of the issue could allow an intruder to steal sensitive information that can aid further attacks later on. The security flaws presented in a joint research paper entitled 'Unauthorized Cross-App Resource Access on Mac OS X and iOS' by Indiana University's Xiaolong Bai, XiaoFeng Wang and Tongxin Li, with Peking University's Kai Chen and the Georgia Institute of Technology's Xiaojing Liao. The flaw named XARA given by security researchers, target major cross-app resource sharing mechanisms such as keychain and communication channels that includes WebSocket and Scheme - are not properly protected by both the OS and the apps using them and allows attackers to gain knowledge of sensitive user information through a malicious program. Similarly, sandbox mechanism is not reliable enough and can be exploited through malicious app - gaining full access to other apps' directories (called containers). <more>

Samsung Galaxy flaw affects 600M users globally

Most widely used smartphone Samsung Galaxy is feeling the heat these days as approx 600 million Samsung phones may be vulnerable to a serious security flaw. According to security researcher Ryan Welton from NowSecure, it allows hackers to stealthy monitor the camera and microphone, read incoming and outgoing text messages, and install malformed apps on the vulnerable smartphones. The issue exists in the update mechanism of SwiftKey - Smart prediction technology for easier mobile typing, available on the Samsung Galaxy S6, S5, and several other Galaxy models. Actually Samsung hasn't specify a mechanism to encrypt the executable files that could leverage attackers to modify upstream traffic during updates downloading. The intruder sitting on the same Wi-Fi network can replace the actual file with a malicious one. The demo of exploit is presented last Tuesday at the Blackhat security conference in London. <more>

Thursday, June 18, 2015

Critical Updates for Windows and Internet Explorer

A light Patch Tuesday for June has been released by Microsoft that contains security patches for just two 'CRITICAL' and eight 'important' rated vulnerabilities. Critical security updates target Windows and Internet Explorer. Critical issue that affects the Windows operating system is due to an error in the media player that allows remote code execution on the compromised machines. Similarly, IE gets a huge list of memory corruption flaws that allow remote code execution if a user views a specially crafted webpage. The 'important' rated updates plugs security flaws in Windows, Exchange Server and Office allowing intruders to gain elevated privileges or remote code execution depending on the scenario and attack vectors. There is also a minor tweaking about the removal of Windows 10 update reminders after critics last month compared them to adware. Company has reconsidered its policy and remove the reminders. <more>

Kaspersky a victim of a spohisticated cyber-attack

Kaspersky Lab revealed last wednesday that a very sophisticated cyber-attack named Duqu penetrated some of its internal systems by exploiting a zero-day flaw in the Windows Kernel. This APT attack is operating since 2012 that shows how sophisticated Duqu is - even a security giant Kaspersky is unable to figure out its presence for such a long period. A new version dubbed Duqu 2 arised in 2014 and continue its operations in 2015 as well targeting western countries, the Middle East and Asia. According to security researchers initial attempts started in Asia-Pacific region via spear-phishing emails. Several modules have been identified to perform a 'pass the hash' attack target the local network. Duqu 2 uses various strategies to spread on the network. It is confirmed by Kaspersky engineers that the attack was carried out by installing Microsoft Windows Installer Packages (MSI) and then launching it remotely to other hosts. <more>

Tuesday, June 9, 2015

Facebook focuses on message security

Facebook is fully aware about users privacy that's why company has added support for OpenPGP keys used in its email messaging to secure users from cyber criminals. Facebook inform users about this feature used to improve the privacy of email content by rolling out an experimental new feature that allows users to add OpenPGP public keys to their profile. GNU Privacy Guard implementation of OpenPGP is available for Windows, Mac OS and Linux users and performs encryption on emails sent from Facebook to their email accounts. This feature is currently available in desktop machines, but Facebook is committed to make it available for mobile platforms. <more>

Microsoft Windows gets SSH support

Redmond is finally planning to support SSH in Windows and their boffins will take participation in the OpenSSH project. SSH is being widely used by Unix and Linux systems for years to remotely connect to system, but Microsoft has never given SSH by default. As SSH becomes the default standard for secure remote logins, this put onus on Microsoft as its users wanted to have default support for SSH and at last company has given a green signal. "A popular request the PowerShell team has received is to use Secure Shell protocol and Shell session (aka SSH) to interoperate between Windows and Linux - both Linux connecting to and managing Windows via SSH and, vice versa, Windows connecting to and managing Linux via SSH. Thus, the combination of PowerShell and SSH will deliver a robust and secure solution to automate and to remotely manage Linux and Windows systems," Angel Calvo, a group software engineering manager on  Microsoft's PowerShell team said. <more>

Friday, June 5, 2015

iPhone crashes with just a text message

Few days back there was a news regarding iPhone crashes with a specially crafted text. Apple quickly released a workaround for iPhones, iPads and the Apple Watch, also advises the use of Siri can mitigate problems caused by the simple text attack. Company will provide the proper patch to rectify this security flaw once for all but meanwhile Apple urges users to apply workaround to keep them safe. According to firm this issue is quite similar to what they faced in the iMessage so patch will be released soon. This issue was pointed out by Reddit and Twitter users causing iOS-based devices to crash or locking the user out of the messaging application. <more>

Facebook launches new security checkup tool

Facebook rolls out a new feature called Security Check-up that will boost the security of user's account. Facebook is usually a prime target for hackers due to its popularity and widely usage so proper mechanism are in placed by the company to secure user profiles. The Check-up will pop up over the top of the site, prompting users to explore new options in order to increase security. Users prefer to connect to Facebook with its mobile app and on most occasions they have not logged out properly. In case of any mishap like your phone stolen or lost then your facebook account if not properly logged out would a tricky situation for you. To avoid such instances Facebook gives the opportunity to receive login alerts to show the computers logged into different Facebook services. <more>

Tuesday, May 26, 2015

Google Chrome 43 fixes 37 vulns

Google released Chrome 43 that provides patches for 37 security flaws along with numerous improvements across different components of the browser. Google is quite famous for its bug bounty program and this time is no exception as company has given around $40,000 to security researchers. Google awarded the highest amount of $16,337 to an anonymous researcher who has found a CRITICAL vulnerability in the sandbox escape and addressed under CVE-2015-1252. Another anonymous researcher is also given $7,500 for finding high severity cross-origin bypass in DOM covered under CVE-2015-1253. Armin Razmdjou of Rawsec was awarded $3,000 for revealing a cross-origin bypass in Editing covered under CVE-2015-1254. Similarly, Khalil Zhani reported use-after-free issues affecting WebAudio and WebRTC. A reward of $3,000 to Atte Kettunen of OUSPG for a high severity use-after-free flaw in SVG and a medium rated security flaw in PDFium. Besides this, Chrome 43 also come up with a new feature called "Upgrade Insecure Requests" content security policy (CSP) - used to automatically upgrade HTTP requests to HTTPS before they get the response by the browser. <more>