Showing posts with label Australia. Show all posts
Showing posts with label Australia. Show all posts

Friday, April 21, 2017

Beware! Dozens of Linksys Wi-Fi Router Models Vulnerable to Multiple Flaws


Thursday, April 20, 2017 Swati Khandelwal



Bad news for consumers with Linksys routers: Cybersecurity researchers have disclosed the existence of nearly a dozen of unpatched security flaws in Linksys routers, affecting 25 different Linksys Smart Wi-Fi Routers models widely used today.

IOActive's senior security consultant Tao Sauvage and independent security researcher Antide Petit published a blog post on Wednesday, revealing that they discovered 10 bugs late last year in 25 different Linksys router models.

Out of 10 security issues (ranging from moderate to critical), six can be exploited remotely by unauthenticated attackers.

According to the researchers, when exploited, the flaws could allow an attacker to overload the router, force a reboot by creating DoS conditions, deny legitimate user access, leak sensitive data, change restricted settings and even plant backdoors.



Many of the active Linksys devices exposed on the internet scanned by Shodan were using default credentials, making them susceptible to the takeover.

Researchers found more than 7,000 devices impacted by the security flaws at the time of the scan, though this does not include routers protected by firewalls or other network protections.

"We performed a mass-scan of the ~7,000 devices to identify the affected models," IOActive says. "We found that 11% of the ~7000 exposed devices were using default credentials and therefore could be rooted by attackers."IOActive made Linksys aware of the issues in January this year and is working "closely and cooperatively" with the company ever since to validate and address the vulnerabilities.


Here's How critical are these Flaws:
The researchers did not reveal more details about the vulnerabilities until the patch is made available to users, although they said two of the flaws could be used for denial-of-service attacks on routers, making them unresponsive or reboot by sending fraudulent requests to a specific API.

Other flaws could allow attackers to bypass CGI scripts to collect sensitive data such as firmware versions, Linux kernel versions, running processes, connected USB devices, Wi-Fi WPS pins, firewall configurations, FTP settings, and SMB server settings.

CGI, or Common Gateway Interface, is a standard protocol which tells the web server how to pass data to and from an application.



Researchers also warned that attackers those have managed to gain authentication on the devices can inject and execute malicious code on the device's operating system with root privileges.

With these capabilities in hands, attackers can create backdoor accounts for persistent access that are even invisible in the router smart management console and so to legitimate administrators.

However, researchers did not find an authentication bypass that can allow an attacker to exploit this flaw.


List of Vulnerable Linksys Router Models:
Here's the list of Linksys router models affected by the flaws:

EA2700, EA2750, EA3500, EA4500v3, EA6100, EA6200, EA6300, EA6350v2, EA6350v3, EA6400, EA6500, EA6700, EA6900, EA7300, EA7400, EA7500, EA8300, EA8500, EA9200, EA9400, EA9500, WRT1200AC, WRT1900AC, WRT1900ACS, and WRT3200ACM.

The majority of the exposed devices (nearly 69%) are located in in the United States, and others are spotted in countries including Canada (almost 10%), Hong Kong (nearly 1.8%), Chile (~1.5%), and the Netherlands (~1.4%).

A small percentage of vulnerable Linksys routers have also been spotted in Argentina, Russia, Sweden, Norway, China, India, UK, and Australia.


Here's How you can Mitigate Attacks originating from these Flaws:
As temporary mitigation, Linksys recommended its customers to disable the Guest Network feature on any of its affected products to avoid any attempts at the malicious activity.

The company also advised customers to change the password in the default account in order to protect themselves until a new firmware update is made available to patch the problems.

Linksys is working to release patches for reported vulnerabilities with next firmware update for all affected devices. So users with Smart Wi-Fi devices should turn ON the automatically update feature to get the latest firmware as soon as the new versions arrive.

Monday, November 14, 2016

Pregnant woman in Sydney suffers second degree burns because of charging iPhone 7

apple iphone
iPhone 7 charging

By 
A pregnant woman in western Sydney went to sleep with an iPhone 7 charging on her arm, and woke up to second degree burns on her hand. On visiting the doctor, she was advised a visit to the hospital. Apple has sent the phone for testing by a senior technician in California. Apple has confirmed to News.com.au that it is investigating the matter with Pelaez.
Apple also offered Ms Tan Pelaez a replacement iPhone, but she did not want it as she had lost faith in the company. Pelaez has been a long time Apple user and has not previously faced any problems with products by the company.
On returning the phone, Apple executives had said that the source of the burn injuries could not have been the phone as the phone was designed to cut off power on overcharging. Pelaez has visited the emergency room in the hospital twice because of the burns, and is exploring the option of plastic surgery to fix the scarring.
This is the second such incident from Sydney, Australia in recent memory. A biker had to punch the phone off his leg after the device burst into flames following a fall. An Apple iPhone 7 had reportedly exploded in China three days ago, after a 50 centimetre fall. For those fearing a repeat of the Samsung Galaxy Note 7 Fiasco, there were reports of over 30 Note 7 devices exploding over a course of a week.

Monday, October 24, 2016

Banks uses blockchain to the make first cross-border international trade transaction

Banks uses blockchain  to the make first cross-border international trade transaction

Image Credit: Commonwealth Bank of Australia
The first cross-border transaction between banks using multiple blockchain applications has taken place, Commonwealth Bank of Australia and Wells Fargo & Co said on Monday, resulting in a shipment of cotton to China from the United States. Australian cotton trader Brighann Cotton Marketing bought the shipment bound for the port city Qingdao from U.S. division Brighann Cotton in Texas, the companies and their banks said in a joint statement. The blockchain trade, for 88 bales, totalled $35,000, Commonwealth Bank told Reuters.
Blockchain is a web-based transaction processing and settlement system whose efficiency banks say could slash costs. It creates a “golden record” of any given set of data that is automatically replicated for all parties in a secure network, eliminating any need for third-party verification. “Existing trade finance processes are ripe for disruption, and this proof of concept demonstrates how companies around the world could benefit from these emerging technologies,” Michael Eidel, Commonwealth Bank’s executive general manager for cash flow and transaction services, said in the statement.
The transaction is not the first involving the decentralised database, used since 2009 for the digital currency bitcoin. But it is a milestone for the traditional banking industry which at first shied away from the technology, partly because it makes money flows harder for law enforcement agencies to track.
Led by a consortium of over 70 of the world’s biggest financial institutions – called R3 – the banking industry has been researching ways to harness the speed, accuracy and efficiency afforded by blockchain. One of its benefits is removing people from transaction processing. That has been seen as especially appealing for cross-border trades, which are typically held up by duplication of payment processing and time zone differences.
R3 has been researching ways to expand the use of blockchain to include “smart contracts”, or payments triggered when certain conditions are met. The cotton transaction, for instance, involved automatically making payments when the shipment reached certain geographic locations, the statement showed. The shipment is currently between Singapore and Hong Kong, and is due to arrive in early November, Commonwealth Bank said. The bank also said that R3 – of which it and Wells Fargo are members – did not play a part in the trade.
Brighann Cotton was not available for comment when contacted by Reuters. Wells Fargo’s head of international trade services, Chris Lewis, said in the statement that his bank was committed to new technology. He also said, “significant regulatory, legal and other concerns remain to  be addressed.”
Reuters

Wednesday, October 19, 2016

Google updates AdWords to let businesses chat with customers through advertisements

Google updates AdWords to let businesses chat with customers through advertisements

By 
Messaging is a convenient platform for both businesses and customers to interact.Facebook, Google and Microsoft have all promoted the untapped potential of conversations during developer conferences held over the course of this year.
For businesses, it gives a direct line of communication with the customer. The customer can participate whenever they can afford the time and attention, and continue the conversation later.
Google has announced a new feature for advertisements shown in search results, that allows businesses to chat with their customers. For those businesses that use the feature, there will be a messaging option shown below the calling option attached to the advertisements. On tapping the chat bubble icon, a pre-generated text message selected by the business opens the conversation.
Google consumer surveys conducted in US, Canada, Australia and UK show that sixty five percent of consumers are open to the idea of texting with a business to get information or schedule an appointment.
The new feature is called click-to-message ads. A select few partners are already using the service. Gavin Chan, Digital Marketing Manager of AnyVan says “Click-to-message is a useful tool that allows consumers to engage with our business in a way that’s comfortable and efficient for them. They could be on their commute or in a rush, so they can text us quickly through click-to-message. It’s also a good medium to get questions answered that aren’t addressed on our website, or to reach us during hours when our office is closed.”
Gavin Parker, Paid Search Manager, Auto & General says “The results from click-to-message have been phenomenal and we’ve seen a 80 percent higher conversion rate when compared to other similar channels. We can now tap into an important consumer base that prefers to use SMS to learn more about our insurance products.”
Businesses can integrate chat with their advertising by setting up message extensions. The feature is expected to roll out over the course of the next few weeks. The click-to-message feature will be available to advertisers at no extra cost.
The problem with the feature as of now is that it triggers an SMS interaction. A better implementation is to integrate with the more common instant messaging applications such as Telegram, WhatsApp and Messenger. The feature could potentially tie into existing chatbots by the businesses on these platforms. SMS is an outdated and expensive form of chatting, and is bound to be less engaging as an instant messaging application.

Related Posts Plugin for WordPress, Blogger...