Showing posts with label vulnerabilities. Show all posts
Showing posts with label vulnerabilities. Show all posts

Tuesday, May 2, 2017

Insecure Apps that Open Ports Leave Millions of Smartphones at Risk of Hacking



The University of Michigan team says that the actual issue lies within apps that create open ports — a known problem with computers — on smartphones.

So, this issue has nothing to do with your device's operating system or the handset; instead, the origin of this so-called backdoor is due to insecure coding practices by various app developers.


The team used its custom tool to scan over 100,000 Android applications and found 410 potentially vulnerable applications — many of which have been downloaded between 10 and 50 Million times and at least one app comes pre-installed on Android smartphones.

Here I need you to stop and first let's understand exactly what ports do and what are the related threats.

Ports can be either physical or electronic in nature. Physical ports are connection points on your smartphones and computers, such as a USB port used to transfer data between devices.

Electronic ports are those invisible doors that an application or a service use to communicate with other devices or services. For example, File Transfer Protocol (FTP) service by default opens port 21 to transfer files, and you need port 80 opened in order to connect to the Internet.

In other words, every application installed on a device opens an unused port (1-to-65535), can be referred as a virtual door, to communicate for the exchange of data between devices, be it a smartphone, server, personal computer, or an Internet-connected smart appliance.

Over the years, more and more applications in the market function over the Internet or network, but at the same time, these applications and ports opened by them can be a weak link in your system, which could allow a hacker to breach or take control of your device without your knowledge.

This is exactly what the University of Michigan team has detailed in its research paper [PDF] titled, "Open Doors for Bob and Mallory: Open Port Usage in Android Apps and Security Implications."

According to the researchers, the major issue is with the apps like WiFi File Transfer, which has been installed between 10 million and 50 million times and allows users to connect to a port on their smartphone via Wi-Fi, making it easy to transfer files from a phone to a computer.

But due to insufficient security, this ability of the apps is apparently not limited to merely the smartphone's owner, but also malicious actors.

However, applications like WiFi File Transfer pose fewer threats, as they are designed to work over a local network only, that requires attackers to be connected to the same network as yours.

On the other hand, this issue is extremely dangerous in the scenarios where you connect to a public Wi-Fi network or corporate network more often.

To get an initial estimate on the impact of these vulnerabilities, the team performed a port scanning in its campus network, and within 2 minutes it found a number of mobile devices potentially using these vulnerable apps.
"They manually confirmed the vulnerabilities for 57 applications, including popular mobile apps with 10 to 50 million downloads from official app marketplaces, and also an app that is pre-installed on a series of devices from one manufacturer," the researchers say.

"The vulnerabilities in these apps are generally inherited from the various usage of the open port, which exposes the unprotected sensitive functionalities of the apps to anyone from anywhere that can reach the open port."
No doubt, an open port is an attack surface, but it should be noted that port opened by an application can not be exploited until a vulnerability exists in the application, like improper authentication, remote code execution or buffer overflow flaws.

Besides this, an attacker must have the IP address of the vulnerable device, exposed over the Internet. But getting a list of vulnerable devices is not a big deal today, where anyone can buy a cheap cloud service to scan the whole Internet within few hours.

However, smartphones connected to the Internet via wireless network behind a router are less impacted by this issue, because in that case, attackers would need to be on the same wireless network as the victim.

To prove its point, the team of researchers has also demonstrated various attacks in a series of videos, posted below:

1. Using an app's open ports to steal photos with on-device malware

2. Stealing photos via a network attack

3. Forcing the device to send an SMS to a premium service

The team says these vulnerabilities can be exploited to cause highly-severe damage to users like remotely stealing contacts, photos, and even security credentials, and also performing sensitive actions such as malware installation and malicious code execution.

The easiest solution to this issue is to uninstall such apps that open insecure ports, or putting these applications behind a proper firewall could also solve most of the issues.

Wednesday, November 30, 2016

Deutsche Telekom attack part of global campaign on routers

Deutsche Telekom attack part of global campaign on routers

Representational Image
A cyber attack that infected nearly 1 million routers used to access Deutsche Telekom internet service was part of a campaign targeting web-connected devices around the globe, the German government and security researchers said on Tuesday.
The revelation from the German Office for Information Security, or BSI, stoked fears of an increase in cyber attacks that disrupt internet service by exploiting common vulnerabilities in widely used routers, webcams, digital video recorders and other web-connected devices.
Security researchers said the infections spread to countries including Brazil, Britain and Ireland using a technique similar to one that stopped millions of people in the United States and Europe from reaching websites including PayPal Holdings Inc , Twitter Inc and Spotify on Oct. 21.
The BSI said that German government networks were also targeted in Sunday’s attack on Deutsche Telekom customers, though authorities said they succeeded in keeping systems online.
Deutsche Telekom, Germany’s largest telecom company, said internet outages hit as many as 900,000 of its users, or about 4.5 percent of its fixed-line customers.
Deutsche Telekom and the German government did not identify other victims, though cyber security firm Rapid7 Inc said it observed the attackers trying to infect routers across the globe.
Irish telecom operator Eir and Vodafone Group Plc in Britain use routers that were vulnerable to same kind of attack, said Rapid7 security research manager Tod Beardsley.
Flashpoint, a second U.S. cyber security research firm, said it routers were infected in Brazil, Britain and Germany.
Eir said in a statement it was aware of potential vulnerabilities in broadband modems from Taiwan’s ZyXel Communications Corp used by about 30 percent of Eir customers.
“We have deployed of a number of solutions both at the device and network level which will remove this risk,” Eir said. It reported the incident to Irish regulators.
Vodafone declined to comment on whether it customers had been infected, but said it was aware of a vulnerability in routers that enables attackers to mount denial-of-service attacks.
The Brazilian National Computer Emergency Response Team told Reuters it was analyzing the impact of the attack on Brazil, but declined to say how many computers had been infected.
Mirai Botnet
The attacks were launched with software known as Mirai that seeks out vulnerable connected devices, then turns them into remotely controlled “bots” for mounting large-scale attacks that disrupt access to websites and computer systems.
Deutsche Telekom executives apologized for the outages, saying the company had provided details about the attack to other network operators and security agencies.
Security experts said the problem affected Deutsche Telekom customers using three types of routers manufactured by Taiwan’s Arcadyan Technology, which created a software patch that was pushed out to users on Monday.
Arcadyan did not reply to Reuters’ requests for comment.
Security experts said attributing blame for the attacks may prove impossible because the Mirai software had been released on the internet. It is relatively easy to use, which means hackers with relatively few technical skills could be to blame for follow-on attacks, they said.
Reuters

Tuesday, September 27, 2016

Senators demand answers from Yahoo over delay in reporting hack attack

Senators demand answers from Yahoo over delay in reporting hack attack
manded that Yahoo Inc explain why hackers’ theft of user information for 500 million accounts two years ago came to light only last week and called the company’s handling of the breach “unacceptable.”
The lawmakers, all Democrats, said they were “disturbed” that the 2014 intrusion, which was disclosed by the company on Thursday, was detected so long after it occurred.
“That means millions of Americans’ data may have been compromised for two years,” the senators wrote in a letter to Yahoo Chief Executive Marissa Mayer. “This is unacceptable.”
A Yahoo spokesman said the company would respond in a “timely and appropriate manner” to the letter, which was signed by Senators Patrick Leahy, Al Franken, Elizabeth Warren, Richard Blumenthal, Ron Wyden and Edward Markey.
The top US stock market regulator said separately that prompt disclosure by companies of “cyber events” is a priority. Securities and Exchange Commission Chair Mary Jo White, asked about Yahoo, said she could not comment specifically on it.
She earlier said at a conference that SEC examiners in recent months have been checking that companies comply with 2011 agency guidance stressing the need to disclose hacks.
Yahoo has faced mounting questions about exactly when it knew about the 2014 cyber attack that exposed the email credentials of users, a critical issue for the company as it seeks to prevent the breach from affecting a pending takeover of its core business by Verizon Inc.
The internet firm has said it detected the breach this summer after conducting a security review prompted by an unrelated hacking claim that turned out to be meritless. Yahoo has not given a precise timeline explaining when it was made aware of the 2014 attack, or if it knew of the breach before announcing the deal with Verizon in late July.
In a Senate hearing on Tuesday, Federal Trade Commission Chairwoman Edith Ramirez said her agency supported quick disclosures although she declined to say if the FTC was investigating Yahoo.
“In our view, approximately 30 to 60 days (after a breach is discovered) might be appropriate,” she told the Senate Commerce Committee. “It is necessary for consumers to be notified so they can take appropriate steps to protect themselves.”
In their letter, the senators requested Yahoo brief them on the company’s investigation, cooperation with authorities and plans to protect affected users.
The senators asked Mayer for a timeline of the hack and discovery as well as Yahoo’s steps to prevent another breach.
Yahoo’s shares closed up 2.5 percent at $43.37 each in a broadly bullish market on Tuesday.
The letter came a day after Democratic Senator Mark Warner asked the U.S. Securities and Exchange Commission to investigate whether Yahoo and its senior executives fulfilled obligations to inform investors and the public about the hacking attack, which Yahoo has blamed on a “state-sponsored actor.”
The SEC has guidance for companies on reporting hacks, but companies that have experienced breaches often omit details from regulatory filings, a 2012 Reuters investigation found.(reut.rs/2dblx5S)
Reuters

Critical DoS Flaw found in OpenSSL How It Works


openssl-ddos-attack
The OpenSSL Foundation has patched over a dozen vulnerabilities in its cryptographic code library, including a high severity bug that can be exploited for denial-of-service (DoS) attacks.

OpenSSL is a widely used open-source cryptographic library that provides encrypted Internet connections using Secure Sockets Layer (SSL) or Transport Layer Security (TLS) for the majority of websites, as well as other secure services.

The vulnerabilities exist in OpenSSL versions 1.0.1, 1.0.2 and 1.1.0 and patched in OpenSSL versions 1.1.0a, 1.0.2i and 1.0.1u.

The Critical-rated bug (CVE-2016-6304) can be exploited by sending a large OCSP Status Request extension on the targeted server during connection negotiations, which causes memory exhaustion to launch DoS attacks, the OpenSSL Project said.

What is OCSP Protocol?


OCSP(Online Certificate Status Protocol), supported by all modern web browsers, is a protocol designed to perform verification and obtain the revocation status of a digital certificate attached to a website.

OCSP divided into client and server components. When an application or a web browser attempts to verify an SSL certificate, the client component sends a request to an online responder via HTTP protocol, which in turn, returns the status of the certificate, valid or not.

Reported by Shi Lei, a researcher at Chinese security firm Qihoo 360, the vulnerability affects servers in their default configuration even if they do not support OCSP.
"An attacker could use the TLS extension "TLSEXT_TYPE_status_request" and fill the OCSP ids with continually renegotiation," the researcher explained in a blog post.

"Theoretically, an attacker could continually renegotiation with the server thus causing unbounded memory growth on the server up to 64k each time." 

How to Prevent OpenSSL DoS Attack


Administrators can mitigate damage by running 'no-ocsp.' Furthermore, servers using older versions of OpenSSL prior to 1.0.1g are not vulnerable in their default configuration.

Another moderate severity vulnerability (CVE-2016-6305) that can be exploited to launch denial of service attacks is fixed in the patch release, affecting OpenSSL 1.1.0 that was launched less than one month ago.

The team has also resolved a total of 12 low severity vulnerabilities in the latest versions of OpenSSL, but most of them do not affect the 1.1.0 branch.

It is worth noting that the OpenSSL Project will end support for OpenSSL version 1.0.1 on 31st December 2016, so users will not receive any security update from the beginning of 2017. Therefore users are advised to upgrade in order to avoid any security issues.
Related Posts Plugin for WordPress, Blogger...