Saturday, July 1, 2017

The $18 'key' that will protect your Facebook and Google account, log you into your PC or Mac, and more


If you're looking for a quick, easy, and affordable way to protect your Google account, Facebook, GitHub, Dropbox, Salesforce admin account (and much more), or looking for a way to harden your Mac or Windows login credentials, then you need to take a look at YubiKey.

Must read: Best Raspberry Pi alternatives, starting at only $5

OK, first off, what is YubiKey?

YubiKey is a small authentication key manufactured by Yubico that can be used to securing access to a wide range of applications, including remote access and VPN, password managers, computer login, FIDO U2F login (Gmail, GitHub, Dropbox, etc.) content management systems, popular online services, and much more.

Basically, Yubikey gives you a way to activate two-factor authentication on your accounts without having to mess about with text messages or third-party authenticator apps. You just plug the Yubikey into a USB port, tap the button, and you're authenticated. You still require a username and password, but the key gives you the second-step and added security.

The wide range of support makes YubiKey a great choice for personal use, business, enterprise, or even developers.

Physically the YubiKey looks like a small USB flash drive, although there is one that also incorporates NFC for use with Android devices. The keys range in price from $18 for the basic FIDO U2F key (which will work with online services that support FIDO U2F, which include Facebook and Google), to $50 for keys that in addition to FIDO U2F also feature strong crypto, touch-to-sign, plus one-time-password, and smart card.

A chart detailing the available keys along with their specific functionality can be found here.

Now, rather than outlining how you protect your accounts with YubiKey (the instructions on the Yubico website are detailed and will guide you through the myriad different services you can secure with your YubiKey more efficiently than I can) I'm going to look at the pros and cons of that I've come across over the past few months.

Pros:

  • Cheap (starting at $18)
  • Easy to use (if you can figure out two-factor authentication, you can understand YubiKeys)
  • Keys are incredibly robust and totally waterproof (one of mine lives on my keyring and gets bashed about a lot, the other I wear around my neck on a chain most of the time)
  • Pretty indistinguishable from USB flash drives so the keys don't attract attention
  • Scalable (customization tools and custom programming options available for business)
  • Support for Open PGP encryption and code signing
  • Offers a really easy way to secure a Windows, Mac or Linux computer

Cons:

  • Ideally, you need two keys in case one gets lost, stolen, or damaged in some way.
  • Not all browsers support U2F so you must be running Google Chrome version 38 or later, or Opera version 40 or later (this is not a YubiKey limitation but a FIDO U2F limitation)
  • No iOS support, which means having to fall back on other two-factor authentication methods
  • Big gaps in services that use FIDO U2F (no support for Yahoo!, Microsoft online services, PayPal, banks, etc.)
  • Some of the documentation can be a little intimidating

See also:

This USB thumb drive is one serious and secure business tool:



from Latest Topic for ZDNet in... http://ift.tt/2tAUlrw

WordPress Plugin Used by 300,000+ Sites Found Vulnerable to SQL Injection Attack


A SQL Injection vulnerability has been discovered in one of the most popular Wordpress plugins, installed on over 300,000 websites, which could be exploited by hackers to steal databases and possibly hijack the affected sites remotely.

The flaw has been discovered in the highly popular

WP Statistics

plugin, which allows site administrators to get detailed information related to the number of users online on their sites, the number of visits and visitors, and page statistics.

Discovered by

Sucuri

team, WordPress plugin WP Statistics is vulnerable to SQL Injection flaw that allows a remote attacker, with at least a subscriber account, to steal sensitive information from the website's database and possibly gain unauthorized access to websites.

SQL Injection is a web application bug that allows hackers to inject malicious Structured Query Language (SQL) code to web inputs in order to determine the structure and location of key databases, which eventually allows stealing of the database.

The SQL injection vulnerability in WP Statistics plugin resides in multiple functions, including

wp_statistics_searchengine_query()

.

"This vulnerability is caused by the lack of sanitization in user-provided data," researchers said. "Some attributes of the shortcode wpstatistics are being passed as parameters for important functions and this should not be a problem if those parameters were sanitized." 
"One of the vulnerable functions wp_statistics_searchengine_query() in the file 'includes/functions/functions.php' is accessible through WordPress' AJAX functionality thanks to the core function wp_ajax_parse_media_shortcode()."

This function does not check for additional privileges, which allows website subscribers to execute this shortcode and inject malicious code to its attributes.

The researchers at Sucuri privately disclosed the flaw to the WP Statistics team and the team had patched the vulnerability in its latest version WP Statistics version 12.0.8.

So, if you have a vulnerable version of the plugin installed and your website allowing user registration, you are definitely at risk, and you should install the latest version as soon as possible.



from The Hacker News http://ift.tt/2taZxiJ

Friday, June 30, 2017

Wikileaks Reveals CIA Malware that Hacks Linux Computers


WikiLeaks has just published a new batch of the ongoing

Vault 7 leak

, this time detailing an alleged CIA project that allowed the agency to computers running the Linux operating systems.

Dubbed

OutlawCountry

, the project allows the CIA hackers to redirect all outbound network traffic on the targeted computer to CIA controlled computer systems for exfiltrate and infiltrate data.

The OutlawCountry Linux hacking tool consists of a kernel module, which the CIA hackers load via shell access to the targeted system and create a hidden Netfilter table with an obscure name on a target Linux user.

"The new table allows certain rules to be created using the "iptables" command. These rules take precedence over existing rules, and are only visible to an administrator if the table name is known. When the Operator removes the kernel module, the new table is also removed," CIA's leaked user manual reads.

Although the installation and persistence method of the OutlawCountry tool is not described in detail in the document, it seems like the CIA hackers rely on the available CIA exploits and backdoors to inject the kernel module into a targeted Linux operating system.

However, there are some limitations to using the tool, such as the kernel modules only work with compatible Linux kernels.

"OutlawCountry v1.0 contains one kernel module for 64-bit CentOS/RHEL 6.x; this module will only work with default kernels. Also, OutlawCountry v1.0 only supports adding covert DNAT rules to the PREROUTING chain," WikiLeaks says.

Previous Vault 7 CIA Leaks

Last week, WikiLeaks dumped a classified CIA malware that tracks geo-location of targeted PCs and laptops running the Microsoft Windows operating system.

Dubbed

ELSA

, the malware captures the IDs of nearby public hotspots and then matches them with the global database of public Wi-Fi hotspots' locations.

Since March, the whistleblowing group has published 14 batches of "

Vault 7

" series, which includes the latest and last week leaks, along with the following batches:

  • Brutal Kangaroo – a CIA tool suite for Microsoft Windows that targets closed networks or air-gapped computers within an enterprise or organization without requiring any direct access.
  • Cherry Blossom – a CIA's framework, generally a remotely controllable firmware-based implant, used for monitoring the Internet activity of the target systems by exploiting flaws in WiFi devices.
  • Pandemic – a CIA's project that allowed the spying agency to turn Windows file servers into covert attack machines that can silently infect other computers of interest inside a targeted network.
  • Athena – an agency's spyware framework that has been designed to take full control over the infected Windows machines remotely, and works with every version of Microsoft's Windows operating systems, from Windows XP to Windows 10.
  • AfterMidnight and Assassin – Two apparent CIA's malware frameworks for the Microsoft Windows platform that is meant to monitor and report back actions on the infected remote host computer and execute malicious code.
  • Archimedes – A man-in-the-middle attack tool allegedly built by the spying agency to target computers inside a Local Area Network (LAN).
  • Scribbles – A piece of software reportedly designed to embed 'web beacons' into confidential documents, allowing the CIA hackers to track insiders and whistleblowers.
  • Grasshopper – A framework that allowed the CIA to easily create custom malware for breaking into Microsoft's Windows and bypassing antivirus protection.
  • Marble – The source code of a secret anti-forensic framework, primarily an obfuscator or a packer used by the spying agency to hide the actual source of its malware.
  • Dark Matter – Hacking exploits the agency designed and used to target iPhones and Mac machines.
  • Weeping Angel – Spying tool used by the CIA to infiltrate smart TV's, transforming them into covert microphones in target's pocket.
  • Year Zero – CIA hacking exploits for popular hardware and software.


from The Hacker News http://ift.tt/2usy2AD

With a single wiretap order, US authorities listened in on 3.3 million phone calls

(Image: file photo)

NEW YORK, NY -- US authorities intercepted and recorded millions of phone calls last year under a single wiretap order, authorized as part of a narcotics investigation.

The wiretap order authorized an unknown government agency to carry out real-time intercepts of 3.29 million cell phone conversations over a two-month period at some point during 2016, after the order was applied for in late 2015.

The order was signed to help authorities track 26 individuals suspected of involvement with illegal drug and narcotic-related activities in Pennsylvania.

The wiretap cost the authorities $335,000 to conduct and led to a dozen arrests.

But the authorities noted that the surveillance effort led to no incriminating intercepts, and none of the handful of those arrested have been brought to trial or convicted.

The revelation was buried in the US Courts' annual wiretap report, published earlier this week but largely overlooked.

"The federal wiretap with the most intercepts occurred during a narcotics investigation in the Middle District of Pennsylvania and resulted in the interception of 3,292,385 cell phone conversations or messages over 60 days," said the report.

Details of the case remain largely unknown, likely in part because the wiretap order and several motions that have been filed in relation to the case are thought to be under seal.

It's understood to be the largest number of calls intercepted by a single wiretap in years, though it's not known the exact number of Americans whose communications were caught up by the order.

We contacted the US Attorney's Office for the Middle District of Pennsylvania, where the wiretap application was filed, but did not hear back.

One former law enforcement official, who applied and carried out wiretaps as part of narcotics investigations, was surprised by the numbers. "It's way too much," said the former official, who did not want to be named.

Albert Gidari, a former privacy lawyer who now serves as director of privacy at Stanford Law School's Center for Internet and Society, criticized the investigation.

"They spent a fortune tracking 26 people and recording three million conversations and apparently got nothing," said Gidari. "I'd love to see the probable cause affidavit for that one and wonder what the court thought on its 10 day reviews when zip came in."

"I'm not surprised by the results because on average, a very very low percentage of conversations are incriminating, and a very very low percent results in conviction," he added.

When reached, a spokesperson for the Justice Department did not comment.

Contact me securely

Zack Whittaker can be reached securely on Signal and WhatsApp at 646-755–8849, and his PGP fingerprint for email is: 4D0E 92F2 E36A EC51 DAAE 5D97 CB8C 15FA EB6C EEA5.



from Latest Topic for ZDNet in... http://ift.tt/2svmZFu

Vulnerability Spotlight: Dell Precision Optimizer and Invincea Vulnerabilities


Vulnerability Spotlight: Dell Precision Optimizer and Invincea Vulnerabilities

Talos are releasing advisories for vulnerabilities in the Dell Precision Optimizer application service software, Invincea-X and Invincea Dell Protected Workspace. These packages are pre-installed on certain Dell systems. Vulnerabilities present in these applications could allow attackers to disable security mechanisms, escalate privileges and execute arbitrary code within the context of the application user.



from Cisco Blog » Security http://ift.tt/2suTR19

French authorities close Windows 10 privacy investigation

Data-protection authorities in France have officially closed an investigation into Microsoft's data collection practices for Windows 10.

The French National Data Protection Commission (CNIL) had issued a formal notice against Microsoft in July 2016, ordering that the company "stop collecting excessive data and tracking browsing by users without their consent."

Yesterday's formal notice of closure notes that "violations had ceased [and] the company had complied with the French Data Protection Act." In addition, it notes that "the company has implemented several measures in order to comply with the requirements stated in the formal notice."

Via email, a Microsoft spokesperson provided the following comment:

We are committed to protecting our customers' privacy and putting them in control of their information. We appreciate the French data protection authority's decision and will continue to provide clear privacy choices and easy-to-use tools in Windows 10.

Specifically, the notice calls out the following changes in Windows 10:

On the irrelevant or excessive character of collected data:

The company has nearly reduced by half the volume of collected data within the "basic" level of its telemetry service which is capable of identifying the system's functional issues and solving them. It has restricted its collection to the sole data strictly necessary for maintaining the proper functioning of its operating system and applications, and for ensuring their security.

On the lack of data subjects' consent:

Users are now informed, through a clear and precise information, that an advertising ID is intended to track their web-browsing in order to offer them personalized advertising. Furthermore, the installation procedure of Windows 10 has been modified: users cannot complete this installation unless they have expressed their choice regarding activation or deactivation of the advertising ID. Moreover, they can reverse this choice at any time.

On the lack of security:

The company has strengthened the robustness of the PIN code allowing users to authenticate to all company's online services, and more specifically to their Microsoft account: too common PIN code combinations are now forbidden. Moreover, in case of incorrect input, the company has set up a delay for authentication (a temporary suspension of access whose duration increases as the number of attempts rises).

The original complaint criticized Microsoft for its cookie-handling policy. The notice of closure acknowledges that "most" Windows 10-related websites now obtain proper consent, with all Microsoft websites scheduled to be in compliance by September 30, 2017.

CNIL notes that Microsoft has also joined Privacy Shield and is no longer transferring French Windows users' data to the U.S. That practice was banned by a decision issued by the Court of Justice of the European Union on October 6, 2015.

In May 2017, French authorities fined Facebook 150,000 Euros for "massive compilation of personal data [and] browsing " without the knowledge or consent of users, following a similar complaint in February 2016.

Google received its own complaint in 2013, with another "compliance package" proposed in 2014.



from Latest Topic for ZDNet in... http://ift.tt/2sZ3CYY

IBM Security Bulletin: Vulnerability in IBM HTTP Server affects Netezza Performance Portal (CVE-2015-8743)

IBM HTTP Server is used by IBM Netezza Performance Portal. IBM Netezza Performance Portal has addressed the applicable CVE.

CVE(s): CVE-2016-8743

Affected product(s) and affected version(s):

IBM Netezza Performance Portal 1.0 – 2.1.1.4

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2u7eAtJ
X-Force Database: http://ift.tt/2kVn2H9

The post IBM Security Bulletin: Vulnerability in IBM HTTP Server affects Netezza Performance Portal (CVE-2015-8743) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2u7eAKf