terça-feira, 19 de abril de 2022

Attacker Steals $182 Million From Ethereum-based Beanstalk Stablecoin Protocol

By Deeba Ahmed  - April 18, 2022 in Hackread


Money Times


Interestingly, the attacker donated $250,000 of the stolen funds to an address used for raising donations for the Ukrainian government.

According to security firm PeckShield, a credit-focused, Ethereum-based stablecoin protocol known as Beanstalk is the latest target of cybercriminals. The DeFi protocol was exploited this Sunday in a flash-loan attack due to which Beanstalk lost around $182 million in crypto assets.

Resultantly, the market for Beanstalk’s stablecoin, BEAN, collapsed. As per CoinGecko, the token’s market went down by 86% from its $1 peg.

It is worth noting that the incident is the second massive nine-figure DeFi exploit reported in a month. In March, Ronin Blockchain of Axie Infinity was targeted, allegedly by North Korean hackers, causing a loss of $625 million.

How was the Attack Carried Out?

Regarding how the attack was carried out, Beanstalk referred to a post on its Discord server, noting that the exploiter utilized a combination of governance tokens obtained via a flash loan for creating a fake protocol improvement proposal.

The attacker used the proposal to gift funds stored in Beanstalk. When the attacker received voting power from the Stalk tokens, they could drain all protocol funds into their personal Ethereum wallet.

Details of Losses

PeckShield took to Twitter to disclose details of the attack. According to its tweet, the attacker took away at least $80 million in crypto while causing significant losses to the protocol.

Attacker Steals $182 Million From Ethereum-based Beanstalk Stablecoin Protocol.

Reportedly, the attacker obtained 24,830 ETH and 36M BEAN, equivalent to $75.8 to $80 million. The rest of the funds were connected to the protocol’s governance token in the form of drained liquidity. The attacker funneled the stolen $80 million in crypto via Tornado Cash. It is a cryptocurrency mixer protocol that facilitates private transactions.

Funds Donated to Ukraine Relief Fund

Interestingly, the attacker donated $250,000 of the stolen funds to an address used for raising donations for the Ukrainian government.

“The initial funds to launch the hack are withdrawn from @SynapseProtocol and most of the result gains are deposited to @TornadoCash. Currently, 15,154 ETH still stays in the hacker’s account. Note the hacker donates 250k USDC to Ukraine Crypto Donation,” PeckShield tweeted.

Beanstalk didn’t provide more details such as there’s no clarity on whether the protocol will reimburse funds to users or not.

More Cryptocurrency Hacks

  1. Phishing scam: NFTs Worth $1.7M Stolen from OpenSea Users
  2. Ex-Crypto CEO accused of 2016’s $11 billion Ethereum DAO hack
  3. “Ethical Hacker” Stole Half a Million in Crypto Form Elderly Person
  4. HubSpot Data Breach – Major Cryptocurrency Companies Impacted
  5. $3.6 billion worth of Bitcoin seized from crooks tied to 2016’s Bitfinex hack

domingo, 13 de fevereiro de 2022

A good test program Tweakeze

 Itu, February 13, 2022.


I'm testing a program called Tweakeze and anyone who wants to test the link follows below. I would like whoever tested it to give me feedback on what they found.

Here is the definition of the program according to the MajorGeeks website:

"Tweakeze monitors any changes made in your Microsoft Windows file systems, registry databases, and more.


Tweakeze (Tweak Easy) is designed to monitor your machine in real-time and execute pre-defined or custom scripting actions when these events happen. It also includes several junk cleaning options to round its feature set out. You can create custom watchers specifying the triggers, like when an executable starts/stops. It permits you to organize them into neat categories or by name with the corresponding action to be carried out. There is no Help section included, or at the author site, so a bit of trial and error will be needed.

These actions can trigger regular file/folder and Registry operations (i.e., delete, move, copy, set) or run a script to capture changes, filter their execution, or execute a completely different task. All Active Script Languages installed on your machine (i.e., VBScript, Jscript, PHP, etc.) and PowerShell scripting is currently supported.

Tweakeze can also delete browser data, permitting you to remove temp data, history traces, download history, and completed forms history. It can also activate/deactivate the old classic volume control. It will additionally provide you with cursory system information.

Tweakeze is a well-rounded monitoring tool providing you with many valuable options for keeping a handle on what goes on with your machine in real-time.

Tweakeze Features:

  • Keystroke Logger
  • Real-Time Monitoring
  • Keywords Alerts
  • Monitor Multiple PC
  • Message Monitoring

  • https://tweakeze.com/

    terça-feira, 2 de novembro de 2021

    Researcher found 70% Wi-Fi networks in Tel Aviv are hackable

     by Waqason October 28th, 2021 in HackRead


    While examining Wi-Fi networks in Tel Aviv, Israel, 70% or around three-quarters of home and small-scale office Wi-Fi network passwords were vulnerable to hacking using inexpensive hacking tools.

    CyberArk’s security researcher made a startling discovery while examining Wi-Fi networks in Tel Aviv, Israel. According to the researcher Ido Hoorvitch, 70% or around three-quarters of home and small-scale office Wi-Fi network passwords were vulnerable to hacking using inexpensive hacking tools.

    Network Routers Hackable with Inexpensive Tools

    Hoorvitch gathered a sample of 5,000 network hashes from across the city with Wi-Fi sniffing gear to use for this examination. He then identified that the attack could be launched using a laptop and a Wi-Fi signal extender, which cost no more than $50. Moreover, he claims that the full hacking setup can be fitted into a backpack.

    Then, a signal booster is used to run scripts to exploit the vulnerabilities previously identified in the Robust Security Network Information Element (RSNIF), which allowed him to extract hashed Pairwise Master Key Identifier or PMKID network keys without intercepting the traffic.

    SEE: This map shows free WiFi passwords from airports worldwide

    Hence, he could crack the passwords of most of the network router passwords through Wi-Fi sniffing and open-source hacking tools. Some of the other tools Hoorvitch used to hack Wi-Fi network routers include packet capture tools and hardware drivers that enable monitor mode when synced with the signal extender.

     

    How The Hack Works?

    Using the Wi-Fi sniffing setup, the researcher picked up hashed passwords for sampling while wandering across Tel Aviv metropolitan area. According to Hoorvitch, just this area houses over 3.9 million residents, and this indicates the high number of vulnerable devices.

    “You can imagine what the numbers would have been had we not cut our research off at 5,000 Wi-Fi networks. And while this research was conducted in Tel Aviv, the routers that were susceptible to this attack — from many of the world’s largest vendors — are used by households and businesses worldwide,” he explained in a blog post.

    Then the process of decoding the passwords began, which was an easy feat to accomplish since Israeli networks use the owner’s mobile phone number as the router’s password. He passed the hashed passwords with the Hashcat tool and could crack 2,200 passcodes out of 5,000.

    SEE: Tesla cars can be remotely hacked using drone, WIFI dongle

    Another pass allowed him to crack more passcodes, and by the end of the research, Hoorvitch had obtained around 3,559 valid passcodes out of 5,000 sniffed samples.

    Researcher found 70% Wi-Fi networks in Tel Aviv are hackable

    However, he discovered a problem with this attack method- that it worked only when Wi-Fi roaming was enabled on the targeted routers, and not all routers supported this feature. So, such routers weren’t susceptible to the PMKID attack.

    “However, our research found that routers manufactured by many of the world’s largest vendors are vulnerable,” the researcher concluded.

    How to Protect your Network Against PMKID Attack?

    If you want to protect your networks, Hoorvitch suggests following best practices like using a lengthy and complex password and regularly updating the default login settings. In addition to this, you must update router firmware, turn off Wi-Fi Protected Setup, and disable WAP1 and WAP (Wi-Fi Application Protocol) specifications.

    “The bottom line is that in a couple of hours and with approximately $50, your neighbor or a malicious actor can compromise your privacy and much more if you don’t have a strong password.”     

    Trojan Source attack lets hackers exploit source code

     by Waqas on November 1st, 2021 in HackRead



    Trojan Source attack impacts all popular programming language compilers, such as C, C++, C#, Java, JavaScript, Python, Rust, and Go.

    A research paper published by Cambridge University researchers Ross Anderson and Nicholas Boucher, titled “Trojan Source: Invisible Vulnerabilities,” reveals details of a unique class of vulnerabilities that can be exploited to inject malware in the source code without getting detected.

    According to the research, the malware can alter the source code’s defined logic, allowing a range of first-party and supply-chain risks. The issue lies in Unicode, a digital text encoding standard that enables computers to exchange information no matter which language is used.

    Currently, Unicode defines over 143,000 characters in 154 different languages scripts and many non-script character sets like emojis.

     

    About Trojan Source Attacks

    This technique exploits the text-encoding standards’ subtleties, including Unicode, so as to produce a different source code, the tokens of which are logically encoded in a completely different order from the original one. This can create vulnerabilities that human code reviewers cannot perceive directly.

    These vulnerabilities are classified as — CVE-2021-42574 and CVE-2021-42694 impact all popular programming language compilers, such as:

    • Go
    • C#
    • C, C++
    • Rust
    • Java
    • Python
    • JavaScript

    “The fact that the Trojan Source vulnerability affects almost all computer languages makes it a rare opportunity for a system-wide and ecologically valid cross-platform and cross-vendor comparison of responses,” the paper [PDF] read.

    For your information, compiler programs are responsible for interpreting high-level human-readable source code into their lower-level representations that the OS can execute. These include object code, assembly language, and machine code.

    How is Unicode Algorithm Exploited?

    The core issue lies in the Bidi (bidirectional) algorithm of Unicode. This algorithm encourages support for left-to-right and right-to-left languages, such as English and Arabic, respectively. Moreover, it also features Bidi overrides to enable writing of left-to-right words within a right-to-left sentence or vice versa. Hence, it forces the left-to-right text to be used as right-to-left.

    'Trojan Source' Bug Lets Hackers Exploit Source Code

    Unicode directionality formatting characters relevant to reordering attacks.

    But while the compiler’s output is required to implement the source code correctly, any alterations generated by injecting Unicode Bidi override characters into strings and comments can yield a syntactically valid source code where the characters’ display order present a different logic from the actual one.

    The Attack details

    The source code files’ encoding is exploited to create targeted vulnerabilities instead of introducing logical bugs independently. This allows visual reordering of tokens in the source code. When rendered acceptably, the compiler is tricked into processing the code in a novel way, thus modifying the program flow. For instance, it can make a comment appear as a code.

    Therefore, if Program A is anagrammed into Program B, the change in code logic would be subtle enough to remain undetected in further testing as an adversary can introduce targeted vulnerabilities, and these would remain hidden.

    “You can use them in source code that appears innocuous to a human reviewer [that] can actually do something nasty. That’s bad news for projects like Linux and Webkit that accept contributions from random people, subject them to manual review, then incorporate them into critical code. This vulnerability is, as far as I know, the first one to affect almost everything,” wrote Ross Anderson.

    Impact on The Supply Chain

    These encodings can impact the supply chain because when invisible software vulnerabilities are injected into open-source software, it will eventually affect all users. Furthermore, researchers warned that Trojan Source attacks’ impact could be severer if an attacker uses homoglyphs to redefine pre-existing functions within an upstream package, thus, invoking them from a victim program.

    “As powerful supply-chain attacks can be launched easily using these techniques, it is essential for organizations that participate in a software supply chain to implement defenses,” researchers warned.

    quinta-feira, 10 de dezembro de 2020

    New Microsoft Spear-Phishing Attack Uses Exact Domain Spoofing Tactic

    Por David Bisson em 10/12/2020 no site The State of Security.




    Security researchers detected a new spear-phishing attack that’s using an exact domain spoofing tactic in order to impersonate Microsoft.

    On December 7, IRONSCALES revealed that it had spotted the campaign targeting Office 365 users. Those users primarily worked in the financial services, healthcare, insurance, manufacturing, utilities and telecom industries.

    The email security provider took a deep dive into the campaign and found that it was using an exact domain spoofing technique. This means that the campaign’s attack emails used a fraudulent domain that was an exact match to the spoofed entity’s domain.

    For the attack, malicious actors disguised the attack emails so that they appeared to have originated from “Microsoft Outlook” at the email no-reply@microsoft[dot]com.

    A screenshot of one of the attack emails. (Source: IRONSCALES)

    Those emails used the lure of quarantined messages to trick recipients into clicking on a malicious link. If they complied, the campaign redirected the recipients to a fake login page designed to steal their Office 365 credentials.

    Notwithstanding their spoofing techniques, the attack emails failed their Sender Policy Framework (SPF) check. This means that the messages were able to bypass the email gateway and land in users’ inboxes.

    IRONSCALES investigated this issue and arrived at an explanation. As quoted in its blog post:

    Our research found that Microsoft servers are not currently enforcing the DMARC protocol, meaning these exact domain spoofing messages are not being rejected by gateway controls, such as Office 365 EOP and ATP…. It remains unknown as to why Microsoft is allowing a spoof of their very own domain against their own email infrastructure. 

    News of this campaign highlights the need for organizations to defend themselves against phishing attacks. One of the ways they can do this is by educating their workforce about some of the most common types of phishing attacks and techniques that are in circulation today. This resource is a good place to start.

    segunda-feira, 7 de dezembro de 2020

    Por que as empresas estão mudando do TensorFlow para o PyTorch

    Por Scott Carey em 04/12/2020 no site Computerworld 


    Foto: Adobe Stock


    Uma subcategoria do aprendizado de máquina, o aprendizado profundo (também conhecido como deep learning) usa redes neurais em várias camadas para automatizar em escala tarefas que ainda são realizadas com bastante dificuldade por máquinas, como reconhecimento de imagem, processamento de linguagem natural (NPL) e tradução automática. 

    TensorFlow, que surgiu do Google em 2015, tem sido a estrutura de aprendizado profundo de código aberto mais popular para pesquisa e negócios. Mas o PyTorch, que surgiu do Facebook em 2016, rapidamente alcançou essa solução, graças às melhorias conduzidas pela comunidade na facilidade de uso e implantação para uma gama cada vez maior de casos de uso. 

    O PyTorch está tendo uma adoção particularmente forte na indústria automotiva — onde ele pode ser aplicado em sistemas de direção autônoma de empresas como Tesla Lyft, no nível 5 de autonomia automotiva. A estrutura também está sendo usada para classificação de conteúdo e recomendação em empresas de mídia e para ajudar a robôs de suporte em aplicações industriais. 

    Joe Spisak, líder de produto de inteligência artificial no Facebook AI, disse à InfoWorld que, embora tenha ficado satisfeito com o aumento na adoção do PyTorch pelas empresas, ainda há muito trabalho a ser feito para obter uma adoção mais ampla da indústria. 

    “A próxima onda de adoção virá com a habilitação do gerenciamento do ciclo de vida do produto, melhorias no MLOps e pipelines Kubeflow, além da [participação da] comunidade em torno disso”, disse ele. “Para aqueles no início da jornada, as ferramentas são muito boas, usando serviços gerenciados e com código aberto, como o SageMaker da AWS ou Azure ML para começar.” 

    Disney: identificando rostos animados em filmes 

    Desde 2012, engenheiros e cientistas de dados da gigante de mídia Disney vem construindo o que a empresa chama de Genoma de Conteúdo, um gráfico de conhecimento que reúne metadados de conteúdo para alimentar aplicativos de pesquisa e personalização. Tudo feito com base no aprendizado de máquina de toda a enorme biblioteca de conteúdo da Disney. 

    “Esses metadados aprimoram as ferramentas usadas pelos contadores de histórias da Disney para produzir conteúdo; inspirar criatividade iterativa na narração de histórias; melhorar as experiências do usuário através de mecanismos de recomendação, navegação digital e descoberta de conteúdo; e possibilitar a inteligência de negócios ”, escreveram os desenvolvedores da Disney Miquel Àngel Farré, Anthony Accardo, Marc Junyent, Monica Alfaro e Cesc Guitart em postagem de blog feita em julho. 


    Antes que isso pudesse acontecer, a Disney teve que investir em um vasto projeto de anotação de conteúdo, recorrendo a seus cientistas de dados para treinar um pipeline de marcação automatizado. Ao utilizar modelos de aprendizagem profunda para reconhecimento de imagem, ele é capaz de identificar grandes quantidades de imagens de pessoas, personagens e locais. 

    Os engenheiros da Disney começaram experimentando vários frameworks, incluindo TensorFlow, mas decidiram consolidar em torno de PyTorch em 2019. Os engenheiros mudaram de um descritor de recurso de histograma convencional de gradientes orientados (HOG) e o popular modelo de máquinas de vetor de suporte (SVM) para uma versão de arquitetura de detecção de objetos apelidada de regiões com redes neurais convolucionais (R-CNN). Este último foi mais propício para lidar com as combinações de live action, animações e efeitos visuais comuns no conteúdo da Disney. 

    “É difícil definir o que é um rosto em um desenho animado, então mudamos para métodos de aprendizagem profunda usando um detector de objetos e usamos a aprendizagem por transferência”, explicou a engenheira de pesquisa da Disney, Monica Alfaro, à InfoWorld.

    Depois que apenas alguns milhares de faces foram processadas, o novo modelo já estava identificando faces amplamente em todos os três casos de uso. Ele entrou em produção em janeiro de 2020. 

    “Estamos usando apenas um modelo para os três tipos de rosto e isso é ótimo para um filme da Marvel como Vingadores, onde é necessário reconhecer o Homem de Ferro e Tony Stark, ou qualquer personagem usando uma máscara”, disse ela. 

    Como os engenheiros estão lidando com grandes volumes de dados de vídeo para treinar e executar o modelo em paralelo, eles também queriam rodar em GPUs caras e de alto desempenho ao entrar em produção. 

    A mudança das CPUs permitiu que os engenheiros treinassem novamente e atualizassem os modelos com mais rapidez. O modelo também acelerou a distribuição dos resultados para vários grupos da Disney, reduzindo o tempo de processamento de cerca de uma hora para um filme de longa-metragem, para obter resultados entre cinco e dez minutos. 

    “O detector de objetos TensorFlow trouxe problemas de memória na produção e era difícil de atualizar, enquanto o PyTorch tinha o mesmo detector de objetos e Faster-RCNN, então começamos a usar o PyTorch para tudo”, disse Alfaro. 

    Essa mudança de uma estrutura para outra foi surpreendentemente simples para a equipe de engenharia. “A mudança [para PyTorch] foi fácil porque é tudo integrado, você apenas conecta algumas funções e pode começar rápido, então não é uma curva de aprendizado íngreme”, disse Alfaro. 

    Quando eles encontraram quaisquer problemas ou gargalos, a vibrante comunidade PyTorch estava à disposição para ajudar. 

    Blue River Technology: robôs matadores de ervas daninhas 

    Blue River Technology projetou um robô que usa uma combinação inebriante de digital wayfinding  (aquela tecnologia de painéis eletrônicos de shopping que te indica uma direção), câmeras integradas e visão computacional para pulverizar ervas daninhas com herbicida sem incomodar as plantações em tempo quase real, ajudando os agricultores a economizar herbicidas caros e potencialmente prejudiciais ao meio ambiente. 

    A empresa de Sunnyvale, na Califórnia, chamou a atenção da fabricante de equipamentos pesados John Deere em 2017, quando foi adquirida por US$ 305 milhões, com o objetivo de integrar a tecnologia aos seus equipamentos agrícolas. 

    Os pesquisadores da Blue River experimentaram várias estruturas de aprendizado profundo enquanto tentavam treinar modelos de visão computacional para reconhecer a diferença entre ervas daninhas e plantações, um grande desafio quando você está lidando com plantas de algodão, que têm uma lamentável semelhança com ervas daninhas. 

    Agrônomos altamente treinados foram designados para realizar tarefas manuais de rotulagem de imagens e treinar uma rede neural convolucional (CNN) usando PyTorch "para analisar cada quadro e produzir um mapa preciso de pixels de onde estão as plantações e ervas daninhas", afirmou Chris Padwick, diretor de informática visão e aprendizado de máquina na Blue River Technology, em postagem

    “Como outras empresas, testamos o Caffe, TensorFlow e, em seguida, PyTorch”, disse Padwick à InfoWorld. “Para nós, funciona praticamente sozinho. Não tivemos nenhum relatório de bug ou um bug de bloqueio. Em computação distribuída, ele realmente brilha e é mais fácil de usar do que TensorFlow, que era muito complicado para paralelismos de dados.” 

    Padwick diz que a popularidade e a simplicidade da estrutura PyTorch dão ao framework uma vantagem quando se trata de conseguir novas contratações rapidamente. Dito isso, Padwick sonha com um mundo onde “as pessoas se desenvolvam naquilo com que se sentem confortáveis. Alguns gostam de Apache MXNet ou Darknet ou Caffe para pesquisa, mas o desenvolvimento tem que estar em um único idioma e o PyTorch tem tudo o que precisamos para ter sucesso.” 

    Datarock: análise de imagem baseada em nuvem para a indústria de mineração 

    Fundada por um grupo de geocientistas, a startup australiana Datarock está aplicando tecnologia de visão computacional à indústria de mineração. Mais especificamente, seus modelos de aprendizado profundo estão ajudando geólogos a analisar imagens de amostra de núcleo de perfuração mais rápido do que antes. 

    Normalmente, um geólogo examinaria essas amostras centímetro a centímetro para avaliar a mineralogia e a estrutura, enquanto os engenheiros procurariam por características físicas como falhas, fraturas e qualidade da rocha. Esse processo é lento e sujeito a erros humanos. 

    “Um computador pode ver rochas como um engenheiro faria”, disse Brenton Crawford, COO da Datarock à InfoWorld. “Se você pode ver na imagem, podemos treinar um modelo para analisá-lo tão bem quanto um humano.” 

    Semelhante ao Blue River, a Datarock usa uma variante do modelo RCNN em produção, com os pesquisadores voltando-se para técnicas de aumento de dados de forma a reunir dados de treinamento suficientes nos estágios iniciais. 

    “Após o período de descoberta inicial, a equipe começou a combinar técnicas para criar um fluxo de trabalho de processamento de imagem para imagens de núcleo de perfuração. Isso envolveu o desenvolvimento de uma série de modelos de aprendizagem profunda, que poderiam processar imagens brutas em um formato estruturado e segmentar as informações geológicas importantes ”, escreveram os pesquisadores em post

    Usando a tecnologia da Datarock, os clientes podem obter resultados em meia hora, ao contrário das cinco ou seis horas levadas para registrar as descobertas manualmente. Isso libera os geólogos das partes mais trabalhosas, disse Crawford. No entanto, “quando automatizamos coisas que são mais difíceis, obtemos alguma resistência e temos que explicar que eles fazem parte deste sistema para treinar os modelos e fazer com que o ciclo de feedback gire”. 

    Como muitas empresas que treinam modelos de visão computacional de aprendizagem profunda, a Datarock começou com o TensorFlow, mas logo mudou para o PyTorch. 

    “No início, usamos o TensorFlow e ele travava conosco por motivos misteriosos”, disse Duy Tin Truong, líder de aprendizado de máquina da Datarock à InfoWorld. “PyTorch e Detecton2 foram lançados naquela época e se ajustavam bem às nossas necessidades. Então, após alguns testes, vimos que era mais fácil depurar e trabalhar e ocupava menos memória, então convertemos”, disse ele. 

    A Datarock também relatou uma melhoria de 4x no desempenho de inferência do TensorFlow para PyTorch e Detectron2 ao executar os modelos em GPUs - e 3x em CPUs. 

    Truong citou a crescente comunidade de PyTorch, interface bem projetada, facilidade de uso e melhor depuração como motivos para a troca e observou que, embora “sejam bastante diferentes do ponto de vista da interface, se você conhece o TensorFlow, é muito fácil trocar, especialmente se você conhece Python. ”