Mostrando postagens com marcador Uzair Amir. Mostrar todas as postagens
Mostrando postagens com marcador Uzair Amir. Mostrar todas as postagens

terça-feira, 2 de janeiro de 2018

Smartphone sensors can leak the four-digit PIN code to hackers


Smartphone sensors can leak the four-digit PIN code to hackers
Smartphones have remained the primary domain of experimentation for cybercriminals as they are always finding out ways to exploit and crack smartphones mainly Android devices. Apparently, researchers at Singapore based Nanyang Technology University or NTU Singapore, have identified a brand new way with which cyber-crooks can compromise a smartphone, which involves the use of device’s sensors.
Believe it or not but the very own sensors of a smartphone could provide cyber-criminals the key to cracking your device. Researchers found that 99.5% of the time the method worked and their device got unlocked. It is worth noting that the researchers tested the method thrice and monitored the data from six sensors installed on an Android smartphone. They were able to correctly guess the 4-digit PIN code for the device.
Researchers tried to identify the PIN code through exploiting sensors installed inside Android smartphones by letting three people enter a varied range of 4-digit number sequences (about 70 times) randomly and then applied machine learning to the sequences in order to predict the pin code. The team tested six sensors including the magnetometer, accelerometer, gyroscope, ambient light sensor, barometer and proximity sensor. They noted that when combined with the accelerometer, the gyroscope gave much accurate information and the team hit 10,000 4-digit combos of codes every time. The smartphone they tested had one of 50 most commonly used PIN codes.
Smartphone sensors can leak the four-digit PIN code to hackers
10 records where the keys 0-8-5-2 were pressed for two different sensors. Red
dots signalize the time where the display was touched, while green dots signal the
release. (Screenshot grab: NTU)
Finally, they managed to guess the PIN code with 100% accuracy, which is a ground-breaking discovery since previously in a similar research the Newcastle University, UK, researchers could guess PIN code of a smartphone with 70% accuracy.
The team opined that the discovery highlights a critical flaw in smartphone security that is posed by the built-in sensors. Since the sensors inside the phone do not need user permissions for storing data and are always open for being accessed by apps, therefore, these can easily jeopardize phone’s security.
The researchers believe their work highlights a significant flaw in smartphone security, as using the sensors within the phones require no permissions to be given by the phone user and are openly available for all apps to access.
The project’s lead researcher Shivam Bhasin wrote: “When you hold your phone and key in the PIN, the way the phone moves when you press 1, 5, or 9, is very different. Likewise, pressing 1 with your right thumb will block more light than if you pressed 9.”
Smartphone sensors can leak the four-digit PIN code to hackers
The layout of the app. In the foreground, a user can type in a PIN. In the background, user set the relevant sensors, before measuring. (Screenshot grab: NTU)
The discovery is also alarming since researchers claim that presence of malicious applications on smartphones is an issue of concern because if these apps record sensor data then the information can be used to hack into the device. Therefore, to prevent your smartphone from being hacked, it is recommended by NTU researchers that longer codes must be used instead of 4-digits. Furthermore, a backup system in the device such as a fingerprint or facial recognition is also helpful but in the end, it all depends upon smartphone makers to identify ways of locking down data stored by the sensors.
As researchers wrote in their paper [PDF]:
“Limiting the maximum operating frequency of the sensors can reduce the attack feasibility. Alternatively, disabling sensors while sensitive operations like PIN entry can also prevent such attacks. However, these are just temporary fixes, and sensors access in smartphones must be rethought, in general.”
It was quite amusing that although a different code was entered by every individual on the phone the experiment also proved that the higher data is fed to the algorithm the better would be the success rate. This means, if a malicious app is unable to accurately guess the PIN right after getting installed, it can eventually guess the correct code using machine learning, which would help in learning the PIN entry pattern.
Therefore, Dr. Bhasin urges that mobile operating systems must be modified so that access to these six sensors could be restricted and users are able to choose to give permissions to trusted apps only. Dr. Bhasin and his colleagues Mr. David Berene and Mr. Bernhard Jungk spent 10 months on the research project and published their findings in Cryptology ePrint archive on Dec 6.

terça-feira, 28 de novembro de 2017

Hackers can Exploit Load Planning Software to Capsize Balance of Large Vessels



Resultado de imagem para navio de containers

Ships can be hacked and the reason is its vulnerable messaging system.
It is a fact that ship loading and container stowage plans are created without using a secure messaging system, and there is obviously a lengthy series of electronic messages that are exchanged between the entities responsible for the creation of vessels including shipping lines, terminals, and port authorities. Understandable this flaw can be exploited by malicious threat actors anytime at their will, and this is exactly what security firm Pen Test Partners’ security consultant Ken Munro is concerned about.
On a daily basis, large vessels use a system called BAPLIE to displace thousands of containers some carrying around 200,000 tons’ load. This system informs port authorities where to place every single container, and the ship’s manufacturers very regularly update it. However, if customers do not use its latest version, there is every chance of foul play since criminal hackers would obscure the real contents and weight of the container by altering the information sent to the customs.
Law enforcement authorities cannot examine every cargo and target shipments from countries that are categorized as high-risk. If a hacker alters this information, then investigators won’t be able to detect that a container is marked as high-risk.
In the official blog post, it was revealed that the threat is real and anyone can perform the hack. The vulnerability of messaging system would affect the day-to-day functioning of the ship as instead of completing the job of loading and unloading in 24 to 48 hours; the ship would take weeks for manual re-inventory. Furthermore, the load planning software, which is used for placement of heavy containers at the bottom of the stacks to ensure that gravity center stays low and balance is maintained, can be exploited to disturb this balance.
“How about if a hacker manipulated the load plan to put a ship out of balance deliberately? Disguise the data, so that the loading cranes unintentionally put the heavy containers at the top and on one side? While some balancing actions are automatic, the transfer pumps may not be able to cope with a rapidly advancing, unanticipated out of balance situation,” read the blog post.
Pen Test Partners has warned about the use of USB devices for exchanging data between ship and terminal mainly because of the possibility of inviting malware into the system since the computer having load plan software might also be used for surfing the web or emailing. Researcher claims that interoperability is vital between shipload plan and the various ports that it visits so that the load plan is securely transmitted to the port.
“Simple = USB = vulnerable. This is ripe for attack. The consequences are financial, environmental and possibly even fatal,” states Munro.
Pen Test Partners has urged operators, terminals and ports to conduct a thorough review of their messaging systems so that the threat of tampering is curtailed given that there is already evidence of stealing of valuable items from containers parked at the port probably via insider access.

segunda-feira, 25 de setembro de 2017

New ransomware scam asks for nude pics to unlock files


New ransomware scam asks for nude pics to unlock files

A few months ago, two ransomware scams made news for asking users to play video games in order to get their files back. One of them asked users to play Japanese game while the second one asked users to play “click me” game.
Now, a similar but a perverted kind of ransomware attack has hit the road that does not ask users for a ransom in Bitcoin but to submit their nude pictures, and in return, they might get their files back. Yes, you read that right.
Dubbed nRansomware, the ransomware was identified by a security researcher MalwareHunterTeam who shared the screenshot of the ransom note asking users for their private pictures. The note also displayed a brief message explaining how a victim can send their pictures to the cybercriminal behind this scam.
The note is powered by a theme song of popular HBO TV series  Curb Your Enthusiasm and images of Thomas the Tank Engine character.
“Your computer has been locked. You can only unlock it with the special unlock code,” says the message. It further goes on to tell victims that they need to make a new email address on ProtonMail, an anti-NSA encrypted email service and send at least 10 explicit images of themselves.
“Go to Protonmail.com and create an account. Send an email to 1_kill_yourself_1@protonmail.com. We will not respond immediately. After we reply, you must send at least 10 nude pictures of you.”
Furthermore, it informs victims that their pictures will be verified to ascertain if they belonged to them or not. Once it is done; they will sell their pictures on the Deep Web.
“After that, we will have to verify that the nudes belong to you. Once you are verified, we will give you your unlock code and sell your nudes on the deep web.”

According to the VirusTotel’s sample provided by the security researcher, AegisLab’s anti-virus detected it as “Troj.W32.Inject.tnKf” which is described by Kaspersky as malicious software that “perform actions which are not authorized by the user: they delete, block, modify or copy data, and they disrupt the performance of computers or computer networks.”
However, in a conversation with MotherBoard, the security researcher said that “It is a screen locker, so files aren’t encrypted. “We have no information about anyone getting infected with this.”

Computer malware like nRansomware can be brought in by any means, including spam emails, porn website, or the freeware bundle. Therefore, it is advised never open a spam email, never download attachments or click links from an unknown email and always scan free software you download from a third party website.

sexta-feira, 15 de setembro de 2017

Sex Robots Can Be Hacked To Kill You

By Uzair Amir on   no site HackRead

Imagine a scenario where you want to play with a sex robot, but it plays you before you could figure out what went wrong.
Back in 2015, Dr. Kathleen Richardson of Centre for Computing and Social Responsibility (CCSR) launched a campaign against electronic sex with Robots and warned about the psychological and social dangers of having intercourse electronically with robots. Now in September 2017, it looks like her campaign made sense.
Sex robots can be hacked to kill you
Image credit: Stacy The Artist
Recently, Nick Patterson, a lecturer and cyber security researcher at Deakin University said that sex robots could kill their owners if hackers got their hands on them. That means if hackers exploited critical vulnerabilities in the system it could allow attackers to turn sex robots into a killing machine.
“Hackers can hack into a robot or a robotic device and have full control of the connections, arms, legs and other attached tools like knives or welding devices. “Once a robot is hacked, the hacker has full control and can issue instructions to the robot,” Nick told DailyStar.
The warning is alarming yet considered as over rated by many but at the same time, it’s note worthy since robots use the same operating system like the smartphone or computer system you use. And since sex robots are connected to the Internet, the vulnerable track record of Internet of Things devices (IoT) is known to everyone.
“The last thing you want is for a hacker to have control over one of these robots.” “Once hacked, they could absolutely be used to perform physical actions for an advantageous scenario or to cause damage,” said Nick.
Sex robots can be hacked to kill you
Image credit: Getty
The technology and skills of hackers and security agencies are becoming so sophisticated that to hack a device they don’t even require it to be connected to the Internet. Just like the Vault 7 leaked documents highlighting how the CIA can hack computers not connected to the internet.
Previously, Stuart Russell, a professor at Berkeley University said that killer drones and robots would leave humanity ‘Utterly Defenceless.’ Russell’s findings were also seconded by physicist Professor Stephen Hawking.
While not so long ago in March this year, IOActive researchers discovered that there are some highly critical vulnerabilities which can allow hackers and even state sponsored groups to hack robots and exploit them to kill people and spy on military secrets.
So what would you prefer? Life or death by the hands of a robot while having sex with it?


quarta-feira, 13 de setembro de 2017

Google Chrome will warn users of ‘man in the middle’ attack


Google Chrome will warn users of ‘man in the middle’ attack
It looks like Google is finally taking serious measures to secure its most used product the Chrome web browser. The tech giant has announced that upcoming Chrome 63 browser will be equipped with a new security feature aiming to alert users of ‘man in the middle’ attacks (MitM) in which an attacker intercepts communication between two systems.
Coming this year in December, Chrome 63 will send notifications after detecting a large number of SSL connection errors implying that an attacker is trying to intercept your web traffic. The new security measure will tackle send notifications for malware as well as legitimate applications. That means in case your firewall or anti-virus software fails to detect and notify you or a malware evades anti-virus detection, Chrome 63 will have your back.
The person behind developing this technology is Sasha Perigo‏ who announced the news on Twitter. “Excited to announce my intern project is launching in @GoogleChrome M63! New error pages to help users struggling with MITM software,” tweeted Perigo‏.
Excited to announce my intern project is launching in @GoogleChrome M63! New error pages to help users struggling with MITM software. 🔐✨ pic.twitter.com/qItF3T1K1z
“1 For this error page, we say a user has “misconfigured” software if they don’t have the root required for the MITM program – 2 We check the error code the certificate validator threw, and check fields on the missing cert to see if it’s MITM software – 3 This error page will only be shown to users who were already seeing SSL errors. If you’re not seeing SSL errors right now, you’re all good”, Perigo‏.
Google plans to release the Chrome 63 on December 5 however you can test the feature on Chrome Canary.

Remember, about six months ago; Google introduced “Safe Browsing” feature for macOS that sends notifications to users whenever they visit a malicious website or download a file containing malware. Moreover, Google also launched a bug bounty program for Androidoperating system showing its commitment to a secure its mobile operating system.