Showing posts with label UK. Show all posts
Showing posts with label UK. Show all posts

Friday, April 21, 2017

Beware! Dozens of Linksys Wi-Fi Router Models Vulnerable to Multiple Flaws


Thursday, April 20, 2017 Swati Khandelwal



Bad news for consumers with Linksys routers: Cybersecurity researchers have disclosed the existence of nearly a dozen of unpatched security flaws in Linksys routers, affecting 25 different Linksys Smart Wi-Fi Routers models widely used today.

IOActive's senior security consultant Tao Sauvage and independent security researcher Antide Petit published a blog post on Wednesday, revealing that they discovered 10 bugs late last year in 25 different Linksys router models.

Out of 10 security issues (ranging from moderate to critical), six can be exploited remotely by unauthenticated attackers.

According to the researchers, when exploited, the flaws could allow an attacker to overload the router, force a reboot by creating DoS conditions, deny legitimate user access, leak sensitive data, change restricted settings and even plant backdoors.



Many of the active Linksys devices exposed on the internet scanned by Shodan were using default credentials, making them susceptible to the takeover.

Researchers found more than 7,000 devices impacted by the security flaws at the time of the scan, though this does not include routers protected by firewalls or other network protections.

"We performed a mass-scan of the ~7,000 devices to identify the affected models," IOActive says. "We found that 11% of the ~7000 exposed devices were using default credentials and therefore could be rooted by attackers."IOActive made Linksys aware of the issues in January this year and is working "closely and cooperatively" with the company ever since to validate and address the vulnerabilities.


Here's How critical are these Flaws:
The researchers did not reveal more details about the vulnerabilities until the patch is made available to users, although they said two of the flaws could be used for denial-of-service attacks on routers, making them unresponsive or reboot by sending fraudulent requests to a specific API.

Other flaws could allow attackers to bypass CGI scripts to collect sensitive data such as firmware versions, Linux kernel versions, running processes, connected USB devices, Wi-Fi WPS pins, firewall configurations, FTP settings, and SMB server settings.

CGI, or Common Gateway Interface, is a standard protocol which tells the web server how to pass data to and from an application.



Researchers also warned that attackers those have managed to gain authentication on the devices can inject and execute malicious code on the device's operating system with root privileges.

With these capabilities in hands, attackers can create backdoor accounts for persistent access that are even invisible in the router smart management console and so to legitimate administrators.

However, researchers did not find an authentication bypass that can allow an attacker to exploit this flaw.


List of Vulnerable Linksys Router Models:
Here's the list of Linksys router models affected by the flaws:

EA2700, EA2750, EA3500, EA4500v3, EA6100, EA6200, EA6300, EA6350v2, EA6350v3, EA6400, EA6500, EA6700, EA6900, EA7300, EA7400, EA7500, EA8300, EA8500, EA9200, EA9400, EA9500, WRT1200AC, WRT1900AC, WRT1900ACS, and WRT3200ACM.

The majority of the exposed devices (nearly 69%) are located in in the United States, and others are spotted in countries including Canada (almost 10%), Hong Kong (nearly 1.8%), Chile (~1.5%), and the Netherlands (~1.4%).

A small percentage of vulnerable Linksys routers have also been spotted in Argentina, Russia, Sweden, Norway, China, India, UK, and Australia.


Here's How you can Mitigate Attacks originating from these Flaws:
As temporary mitigation, Linksys recommended its customers to disable the Guest Network feature on any of its affected products to avoid any attempts at the malicious activity.

The company also advised customers to change the password in the default account in order to protect themselves until a new firmware update is made available to patch the problems.

Linksys is working to release patches for reported vulnerabilities with next firmware update for all affected devices. So users with Smart Wi-Fi devices should turn ON the automatically update feature to get the latest firmware as soon as the new versions arrive.

Wednesday, November 16, 2016

Google announces major investment in London assuring commitment to post-Brexit UK

Google announces major investment in London assuring commitment to post-Brexit UK

Image Credits: Reuters
Google delivered a vote of confidence in London’s future as a technological hub after the Brexit vote on Tuesday by announcing plans for a new building in the King’s Cross area of the city that will house thousands of extra engineers. Google’s Chief Executive Sundar Pichai said computer science had a great future in Britain, citing the talent pool, educational institutions, and passion for innovation present in the country.
“That’s why we are investing in London in both engineering talent and infrastructure,” he said. The 10-storey building, Google’s first wholly owned and designed outside the United States, will increase its presence in King’s Cross to more than 1 million square feet, enough for more than 7,000 employees in total, the company said.
Google has 5,700 employees and contractors in the UK, including about 2,000 engineers housed in the recently opened building in King’s Cross where Pichai announced the expansion. Pichai, who became CEO in October 2015 when parent company Alphabet Inc was created, said he was optimistic about Britain’s future, despite the uncertainty caused by June’s vote to leave the European Union.
“Historically, the UK has been an open and connected economy, and like a lot of businesses we are proud of and rely on the fact that we recruit the best talent from around world,” he said. “We are optimistic that this situation will continue.” “We understand there is uncertainty and even concerns about topics like Brexit and the pace of technological change in our times, but we know for certain that web and digital technology will be an engine of growth for the UK for years to come.”
British Finance Minister Philip Hammond said the investment showed leading firms were still choosing to invest in Britain, while the Mayor of London Sadiq Khan said inflows remain “robust” post-Brexit. “London isn’t just the tech capital of Europe, we are on the shoulder of New York and we are catching up with Silicon Valley,” Khan said at the event.
“Investment into the capital post-Brexit remains robust, so Google’s expansion will further strengthen our city’s reputation as a global leader in digital technology.” Pichai made reference in his speech to another event that exposed a division in a western society: the U.S. election. “Recent events, including the election in the U.S., have clearly surfaced challenges with inequality and people feeling marginalized,” he said.
These were “long-term and difficult” problems to solve, he said, but it was his hope that Google would play a constructive role in addressing some of these challenges. The company, along with Facebook, on Monday announced measures aimed at halting the spread of “fake news” on the internet by targeting how some purveyors of phony content make money: advertising. The shifts comes as Google, Facebook and Twitter Inc face a backlash over the role they played in the U.S. presidential election by allowing the spread of false and often malicious information that might have swayed voters toward Republican candidate Donald Trump, who won the Nov. 8 vote.
Reuters

Friday, October 28, 2016

Facebook announces Masks, an AR overlay feature for Live similar to Snapchat Lenses

Facebook announces Masks, an AR overlay feature for Live similar to Snapchat Lenses

By 
Facebook has announced augmented reality realtime overlays to Live videos. The feature is called Masks, and is similar to Snapchat Lenses. The immediate roll out is for iOS users in US, UK and New Zealand. However, over the course of a few months, the feature will be making it to Android devices on more countries. Public figures using Facebook Mentions will also have access to the Masks feature, so fans can see their favorite celebrities using Masks in their Lives.
facebook-masks-2
The Masks feature is launched just in time for Halloween, and there are a few limited edition Masks that will be available only for a short time. The limited edition masks are a pumpkin and a witch. The skull, evil queen and other masks will be available for use in Facebook Lives even after Halloween is over. Other options include a clown, a panda, and a flower in your hair Mask.
facebook-masks-1
Once a user goes live, a magic wand icon appears on the top right of the screen. Tapping on it opens up a creative tools tray which includes filters, drawing and now, Masks. The masks can be scrolled through, and switched in realtime. Tapping on the close icon on the top right of the screen stops the creative tools overlay. The first Mask, at the very right of the Mask list, is a no Mask option.
facebook-halloween-reactions
Facebook is also introducing a limited edition reactions bar just for Haloween. This replacement will occour in only some countries. The Like button shows an animated skeletal hand. The Love reaction shows the heart being chomped by mysterious invisible teeth. The laughter reaction shows a laughing witch. The wow button is a floating ghost. Frankenstein sheds a tear instead of the sad animated emoji. Finally, there is an angry pumpkin with red glowing eyes. Check out the animations.
The announcements are the latest in a series of steps Facebook has taken to openly imitate Snapchat features. Facebook is obsessed with owning a Snapchat like app. Facebook has been testing an photo uploader for iOS with Snapchat styled filters. In Brazil and Canada, Facebook had been testing a Snapchat style homescreen on its Facebook App. Most of the home screen is taken up by the view from the selfie camera, with an option for applying realtime filters similar to Snapchat Lenses.

Monday, October 24, 2016

Microsoft enterprise products to get costlier in UK after pound falls

Microsoft enterprise products to get costlier in UK after pound falls

Microsoft Corp said it will be increasing pricing for its enterprise software and cloud services in the UK in the wake of the sterling’s plunge since Britons voted to leave the EU. The price increase, from Jan. 1 2017, will be 13 percent for its enterprise software and 22 percent for its enterprise cloud services, it said.
Pricing changes will not apply to consumer software or consumer cloud services, the company said in a blog post. The vote to leave the EU took many investors and company executives by surprise, triggering the biggest one-day fall in sterling against the dollar. The pound’s fall has affected profitability for many companies, as imported goods have become even more expensive.
Recently, Britain’s biggest grocery chain, Tesco, pulled dozens of Unilever brand products from its website after a disagreement over prices, in the wake of a the slump in the British currency. Unilever had been trying to raise the prices it charges Britain’s big four supermarkets – Tesco, Sainsbury’s, Asda and Morrisons – across a wide range of goods by about 10 percent, saying it needs to offset the higher cost of imported commodities.
Reuters

Wednesday, October 19, 2016

Google updates AdWords to let businesses chat with customers through advertisements

Google updates AdWords to let businesses chat with customers through advertisements

By 
Messaging is a convenient platform for both businesses and customers to interact.Facebook, Google and Microsoft have all promoted the untapped potential of conversations during developer conferences held over the course of this year.
For businesses, it gives a direct line of communication with the customer. The customer can participate whenever they can afford the time and attention, and continue the conversation later.
Google has announced a new feature for advertisements shown in search results, that allows businesses to chat with their customers. For those businesses that use the feature, there will be a messaging option shown below the calling option attached to the advertisements. On tapping the chat bubble icon, a pre-generated text message selected by the business opens the conversation.
Google consumer surveys conducted in US, Canada, Australia and UK show that sixty five percent of consumers are open to the idea of texting with a business to get information or schedule an appointment.
The new feature is called click-to-message ads. A select few partners are already using the service. Gavin Chan, Digital Marketing Manager of AnyVan says “Click-to-message is a useful tool that allows consumers to engage with our business in a way that’s comfortable and efficient for them. They could be on their commute or in a rush, so they can text us quickly through click-to-message. It’s also a good medium to get questions answered that aren’t addressed on our website, or to reach us during hours when our office is closed.”
Gavin Parker, Paid Search Manager, Auto & General says “The results from click-to-message have been phenomenal and we’ve seen a 80 percent higher conversion rate when compared to other similar channels. We can now tap into an important consumer base that prefers to use SMS to learn more about our insurance products.”
Businesses can integrate chat with their advertising by setting up message extensions. The feature is expected to roll out over the course of the next few weeks. The click-to-message feature will be available to advertisers at no extra cost.
The problem with the feature as of now is that it triggers an SMS interaction. A better implementation is to integrate with the more common instant messaging applications such as Telegram, WhatsApp and Messenger. The feature could potentially tie into existing chatbots by the businesses on these platforms. SMS is an outdated and expensive form of chatting, and is bound to be less engaging as an instant messaging application.

Related Posts Plugin for WordPress, Blogger...