Mostrando postagens com marcador HackHead. Mostrar todas as postagens
Mostrando postagens com marcador HackHead. Mostrar todas as postagens

domingo, 11 de outubro de 2020

55 Apple vulnerabilities risked iCloud account takeover, data theft

 Por SudaisAsif em 09/10/2020 no site HackHead





Bug bounty programs happen to be effective as they offer independent ethical hackers the motivation to help companies find vulnerabilities.

A recent case is a testimony to this where a team of cyber security researchers has succeeded in finding a total of 55 vulnerabilities in Apple’s networks over a course of 3 months. The names and Twitter handle of researchers participated in Apple’s bug bounty program are:

Meanwhile, the 55 vulnerabilities were classified as the following:

  • 11 as critical due to the extreme threat they posed of user data theft and access to Apple’s main network
  • 29 as high severity
  • 13 as medium severity
  • 2 as low severity 

All of these distributively include remote code execution, memory leaks, SQL injections & cross-site scripting (XSS) attacks, the details of which are available on the researchers’ official blog post.

Elaborating a bit on the consequences of the vulnerabilities, there were many. First, the iCloud accounts of users could be accessed using a worm leading to a serious privacy breach and potential phishing attacks.

Secondly, not only could Apple’s proprietary source code of its projects be exposed but the user sessions of Apple employees could also be taken over resulting in the attacker’s control “management tools and sensitive resources”.

Thirdly, Apple uses industrial control warehouse software which would also have been compromised. The following list comprises of first 10 vulnerabilities reported by the researchers:

  • Remote Code Execution via Authorization and Authentication Bypass
  • Authentication Bypass via Misconfigured Permissions allows Global Administrator Access
  • Command Injection via Unsanitized Filename Argument
  • Remote Code Execution via Leaked Secret and Exposed Administrator Tool
  • Memory Leak leads to Employee and User Account Compromise allowing access to various internal applications
  • Vertica SQL Injection via Unsanitized Input Parameter
  • Wormable Stored XSS allows Attacker to Fully Compromise Victim iCloud Account
  • Wormable Stored XSS allows Attacker to Fully Compromise Victim iCloud Account
  • Full Response SSRF allows Attacker to Read Internal Source Code and Access Protected Resources
  • Blind XSS allows the Attacker to Access Internal Support Portal for Customer and Employee Issue Tracking.

The full list of vulnerabilities and technical details are available on the researchers’ blog post.

Currently, the security researchers have been paid a total of $288,500 but more payments are expected to come in which may go up to $500,000.

On the other hand, all the disclosed vulnerabilities have been fully fixed by 6th October which can put users at ease as their data is no more at risk. Nevertheless, credit also goes to Apple since they responded to every vulnerability report in a time span of 4-48 hours which shows a sense of responsibility by the tech giant.

For the future, other companies should learn from this incident and implement vulnerability disclosure and bug bounty programs along with dedicated cybersecurity professionals to handling such reports. This can go a long way in mitigating the effects of such an incident.

domingo, 7 de junho de 2020

Scammers using voicemail email phishing scam to steal data

Por Waqas em 06/06/2020 no site HackHead

Would a scammer voice call you on Hangouts? - Quora
Quora

Scammers are taking advantage of COVID-19 pandemic to spread a voicemail email phishing scam when most users across the globe are working from home.

The COVID-19 pandemic has changed the way we live, communicate, and work. Workforces across the world are currently relying on digital communication platforms like ZoomMicrosoft Teams, Slack, and Private Branch Exchange (PBX) to perform their day-to-day official duties and work remotely.
However, malicious threat actors are also aware of this fact and are trying their level best to benefit from the current situation. 
According to email security firm IronScales, companies using PBX telephone systems to enable communication and information sharing between their employees are the prime targets of sophisticated phishing attacks that can evade email security quite convincingly.   
IronScales identified around 100,000 new phishing campaigns in May 2020 delivering fake PBX notifications to steal login credentials. These campaigns are targeting “hundreds of enterprises” from almost every sector including engineering, real estate, IT, oil & gas, health care, financial services, and IT, etc.
PBX is a handy tool that sends voice message recordings directly to an employee’s email account and eliminates the need to access official landlines. Employees can retrieve important voicemails by integrating PBX with their company’s email client. 
Exploiting this mechanism, attackers are sending malicious emails under the guise of PBX voice notifications featuring custom subject lines containing the name of the company or employee name to pass the authenticity test.   
Here are two screenshots shared by IronScales showing how the email looks like:
 Through such subject lines, attackers are trying to bypass email defenses like SEGs, Reporting and Conformance system, and the Domain-based Message Authentication (DMARC). Since there is no attachment in the email, the messages do not raise an alarm and are freely allowed through.
The main objective behind this campaign is to obtain PII (personally identifiable information), login credentials, and critically important business data. It is very important that employees are trained to identify a phishing email, and companies should implement such security systems that can recognize phishing scams.

"If your organization automatically sends voicemails to workers inboxes, then your company is at risk of falling victim to this scam. As we know, if an email looks real then someone will fall for it, the company warned in its blog post."

segunda-feira, 25 de maio de 2020

Hackers leak data of 29 million Indian job seekers for download

Por Waqas em 23/05/2020 no site HackHead 

Falha no WhatsApp: saiba como se proteger de hackers | 33 Giga | ND

India has a huge job market and the same goes for those seeking jobs. Now, hackers have taken advantage of the opportunity and leaked a treasure trove of data belong to millions of Indian job seekers across the country, Hackread.com has learned.
The data was identified by Cyble, a cyber threat intelligence company, and noted personal details of around 29 million job-seeking Indians from different states dumped on the dark web and hacker forms for anyone to download.
Hackers leak data of 29 million Indian job seekers for download
Screenshot of the leaked data (Image: Cyble)
The original leak, according to Cyble, appears to be from a resume (CV) aggregator service that collects data from different job portals in India. Hackread.com has seen the data and also witness hundreds of threat actors downloading it at the time of publishing this article.
In its official press release, Cyble stated that a threat actor has posted approximately 2.3 GB of data in a zipped file on a hacking forum operating on the dark web, and this particular file belongs to the resume aggregator service.
According to the company, the data contains sensitive data of Indian job seekers including personal details like educational qualification, email IDs, phone numbers, work experience, and home address, etc. Here are some of the screenshots acquired from the leaked data:
Threat actors playing around Indian data is nothing new. In October 2019, more than 1.3 million credit and debit cards were dumped online. The data almost entirely (98%) belonged to Indian banking customers while the rest of the data belongs to banks in Columbia.
In February 2020, hackers were offering more than 461,976 payment card records stolen from some of the largest banks in India. Each card was being sold for just $9.
As for the current story, the incident is developing news and an in-depth investigation of the matter is ongoing. This article will be updated with new information. Stay tuned!

segunda-feira, 27 de abril de 2020

Vulnerability allowed hijacking of Microsoft Teams account with a GIF

by  on 
Microsoft Teams será liberado gratuitamente devido ao coronavírus ...

Zoom video conferencing tool has been facing security and vulnerability issues since the beginning of the Coronavirus pandemic but this time Microsoft’s very own Microsoft Teams service was exposed to account take over vulnerability.
Microsoft Teams is a workplace collaboration and communication platform that allows organizations to communicate via video conferencing, store files, initiate chat, and integrate applications simultaneously. It has emerged as a very useful and productive medium of communication in recent times, specifically nowadays when the world is held hostage to the COVID-19 pandemic.
However, this very aspect is in itself a great threat to organizational data safety as none of the applications currently available are free from security loopholes, and the same is the case with Microsoft Teams. 
Reportedly, CyberArk’s researchers identified a worm-like vulnerability in Microsoft Teams, which hackers could exploit to hijack an entire roaster of MS Teams accounts at an organization by sending malicious URLs or GIF images to Teams users. 
The vulnerability is related to the way MS Teams processes authentication access tokens and passes them to resources containing images. If an attacker manages to create a GIF file or URL, Teams will send the authentication token to the attacker’s server while processing it. 
 <script async src="//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js"></script>
<!-- Custom size sqare ad -->
<ins class="adsbygoogle"
     style="display:inline-block;width:300px;height:250px"
     data-ad-client="ca-pub-3675825324474978"
     data-ad-slot="3421156210"></ins>
<script>
(adsbygoogle = window.adsbygoogle || []).push({});
</script>  <script async src="//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js"></script>
<!-- Text Link Ad -->
<ins class="adsbygoogle"
     style="display:inline-block;width:200px;height:90px"
     data-ad-client="ca-pub-3675825324474978"
     data-ad-slot="5266209419"></ins>
<script>
(adsbygoogle = window.adsbygoogle || []).push({});
</script>  <script async src="//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js"></script>
<!-- Text Link Ad -->
<ins class="adsbygoogle"
     style="display:inline-block;width:200px;height:90px"
     data-ad-client="ca-pub-3675825324474978"
     data-ad-slot="5266209419"></ins>
<script>
(adsbygoogle = window.adsbygoogle || []).push({});
</script>
To successfully pull off the attack via sending links, the victim should click on the link; but in the case of GIF image, the attack can be successful if the user views the image in Teams chat. Once the image is viewed or URL clicked, the attacker receives the token. 
Using this token, an attacker can hijack the victim’s Teams account by exploiting its API interfaces, and can access victim’s data on Teams, send messages, create and delete groups on the victim’s behalf, or modify a group’s permissions. 
The automated nature of this attack makes organizations most vulnerable to exploitation as the attacker can send malicious GIF files to other employees using a hijacked account, and may access sensitive data, login credentials, business strategies/plans, and meeting schedules. 

Attack’s workflow:

Vulnerability allowed hijacking of Microsoft Teams account with a GIF
CyberArk researchers’ assessed that an attacker can carry out a variety of attacks after receiving the token. Such as:
It is possible to send false information to employees to cause reputational or financial damage, direct data leakage, install malware, lure an employee to reset the password by impersonating as a team member, or contact the CEO after hijacking Teams account of another executive to obtain confidential financial data.
However, they believe that sending out infected images or links is quite easy but the other steps are rather complex, and novice or amateur hackers cannot easily pull it off. 

Watch how it’s done:

Microsoft has already addressed the flaw with the help of researchers under CVD (Coordinated Vulnerability Disclosure). The company claims that the vulnerability wasn’t yet exploited by hackers, and now that it has been fixed, there is no threat to the users of Microsoft Teams. 

domingo, 23 de fevereiro de 2020

Federal Agency that maintains secure communication for Trump got hacked

Por Deeba Ahmed em 22/02/2020 no site HackHead

Resultado de imagem para federal agency hack
The Daily Wire

The United States’ federal defense agency responsible for ensuring safe communications with many high profile personalities including President Donald Trump, national leaders, and military operations, admitted experiencing a security breach.
The data breach occurred at Defense Information Systems Agency (DISA) in 2019, however, it is yet unclear whether or not the entire data belonged to DISA.
The unknown attackers managed to hack Personally Identifiable Information (PII) including Social Security Numbers of approx. 200,000 individuals, as per the revelation from the Department of Defense’ spokesperson Chuck Prichard. 
In a letter sent by DISA to the affected individuals and mainstream news agencies on February 11, 2020, it was explained that the cyberattack took place between May and July 2019, and that the system hosted by DISA was affected by the security breach.
It is clearly written in the letter that there is no indication of the misuse of PII. 
Federal Agency that maintains secure communication for Trump got hacked
Source: Reuters
It is worth noting that DISA has a policy under which the agency is liable to inform individuals if their personal data has been compromised. Furthermore, the agency has offered credit card monitoring of the affected individuals free of charge.
Prichard stated that the department has chosen not to reveal the actions taken to mitigate the vulnerabilities or risks because of operational security reasons.
DISA is responsible for providing IT support and direct telecom facility to President Trump, Vice President Mike Pence, the US Secret Service, staff of the president, the chairman of the Joint Chiefs of Staff and senior officers from the military. 
Interestingly, in a report published in June by the Senate Homeland Security and Governmental Affairs’ Subcommittee, it was noted that as many as seven out of eight federal agencies offered insufficient protection to PII. Though DISA’s name wasn’t included in the agencies reviewed by the subcommittee, the hack does reveal shortcomings in its data protection methods.

terça-feira, 18 de fevereiro de 2020

Latest LokiBot malware variant distributed as Epic Games installer

Por Deeba Ahmed em 18/02/2020 no site Hack Head

Resultado de imagem para lokibot-malware

The new variant of the notorious LokiBot malware is more sophisticated and effective than its previous versions.

Discovered originally in 2015; LokiBot malware is extremely popular among cybercriminals because of its multitasking abilities. The malware is capable of converting itself into full flagged ransomware and harvests almost every type of data from login IDs and passwords to banking data and crypto wallets contents, which it does by using keyloggers that monitor user activities on the device and the browser.

According to Trend Micro researchers, the newly discovered variant of LokiBot malware is being distributed as a popular game launcher for Epic Games, the same developer behind the massively popular online game Fortnite, to trick users so that they execute it on their devices.
Detected as Trojan.Win32.LOKI; this campaign has a rather peculiar installation routine in which a C# code file is dropped to infect the device. The user believes that this file is Epic Games store installer, and executes it without suspecting any foul play. 

As per Trend Micro’s blog post, this installer is created by using the authoring tool called Nullsoft Scriptable Install System or NSIS installer. The NSIS Windows installer uses the original logo of Epic Games for deceiving users, and as soon as the file is executed two more files are dropped.

https://www.hackread.com/wp-content/uploads/2020/02/lokibot-malware-variant-epic-games-installer-2.jpg

One of them is a C# source code file while the other is a .NET executable found in the infected device’s “%AppData% directory.” The .NET executable contains so many junk codes that its reverse-engineering becomes extremely difficult. The purpose of this file is to read and compile the C# code file titled MAPZNNsaEaUXrxeKm.


After compilation, the binary activates the EventLevel function from the C# code file via the InvokeMember function, which decrypts and enables the encrypted assembly code already embedded in the file. Afterward, the LokiBot payload is executed. Using the C# source code helps in preventing detection from the device’s defense mechanisms.

Researchers believe that the malware is distributed via phishing emails being sent out in huge numbers to claim as many targets as possible. Nonetheless, the discovery reinstates the fact that LokiBot malware continues to remain the preferred Trojan of scammers and they might continue to tweak it further in the future.