Tuesday, August 1, 2017

USN-3294-2: Bash vulnerability

Ubuntu Security Notice USN-3294-2

1st August, 2017

bash vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 12.04 LTS

Summary

A security issues were fixed in Bash.

Software description

  • bash - GNU Bourne Again SHell

Details

USN-3294-1 fixed a vulnerability in Bash. This update provides the
corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

It was discovered that Bash incorrectly handled the SHELLOPTS and PS4
environment variables. A local attacker could use this issue to execute
arbitrary code with root privileges. (CVE-2016-7543)

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 12.04 LTS:
bash 4.2-2ubuntu2.7

To update your system, please follow these instructions: http://ift.tt/17VXqjU.

In general, a standard system update will make all the necessary changes.

References

CVE-2016-7543



from Ubuntu Security Notices http://ift.tt/2whGROu

Amazon halts Blu phone sales over 'potential security issue'

amazon-blu-r1-hd-4262-006.jpg

The Blu R1 HD, which is available for $60 on Amazon, was singled out by security researchers for harboring Adups software that transmitted users' private data.

Image: Josh Miller/CNET

Blu, the US brand behind a line of cheap and cheery Android smartphones, has been temporarily suspended from selling its devices on Amazon following claims that they contain spyware.

Amazon told ZDNet sister site CNET that it had suspended sales of Blu handsets due to a "potential security issue".

Security firm Kryptowire in November detailed security issues stemming from Blu devices containing a firmware-over-the-air update software from Chinese vendor Shanghai Adups Technology, which was transmitting SMS messages and other private data to a server in China.

Shortly afterwards, Blu announced it had requested Adups to disable the functionality on Blu phones and flagged it would switch to Google's own update software. Adups also said it had fixed the issue.

However, at the Black Hat security conference last week, Kryptowire demonstrated that Adups was still transmitting users' private data and featured a command-and-control server capable of installing apps, taking screen shots, recording the screen, making calls, and wiping devices without the user's permission.

Kryptowire had singled out the Blu R1 HD, which is available for $60 on Amazon, for harboring Adups software.

According to Kryptowire co-founder Ryan Johnson, Adups replaced its firmware with "nicer versions" but said further analysis in May of another Blu model found Adups was still making the same mistakes, describing it as a "huge invasion of privacy".

It was transmitting a list of apps installed, apps used, unique device identifiers, including the MAC address and IMEI number, the phone number, and cell phone tower ID.

"Because security and privacy of our customers is of the utmost importance, all Blu phone models have been made unavailable for purchase on Amazon.com until the issue is resolved," Amazon said in a statement to CNET.

Some Blu models are still available on Amazon at the time of writing.

The incident may have cost Blu its prominent position on Amazon's Prime Exclusive Phones program, which no longer lists the firm's devices.

Blu issued a statement saying Adups software was only on some older devices, and that new devices would use Google's OTA software.

"Blu decided to switch the Adups OTA application on future devices with Google's GOTA. Even though it is Blu's policy to only use GOTA moving forward, some older devices still use Adups OTA," it said.

It also argued that using Adups software was "not an issue", which was merely collecting information that is standard for OTA functionality and consistent with other smartphone brands.

"The issue is exactly what kind of data is actually being collected by this Adups application, and whether it presents a security or privacy risk," it said.



from Latest Topic for ZDNet in... http://ift.tt/2u0g8cy

This Amazon Echo hack can make your speaker spy on you, say security researchers

maxresdefault.jpg

It's possible to turn some version of the Amazon Echo into a covert listening device, say researchers.

Image: Amazon

A vulnerability in older Amazon Echo devices can be used to make the internet-connected speaker and home assistant relay conversations to eavesdroppers while the owner remains none the wiser.

Research by MWR InfoSecurity found it's possible to turn an Amazon Echo into a covert listening device without affecting its overall functionality. One big limiting factor: the process does involve the attacker being able to gain access to the physical unit, but it's possible to tamper with the Echo without leaving any evidence.

The vulnerability comes as a result of two design choices; exposed debug pads on the base of the device and a hardware configuration setting which allows the device to boot from an external SD card. By exploiting these two features, the attacker can access the root shell on the Linux Operating System and perform the attack.

By removing the rubber base of the Amazon Echo, researchers gained access to 18 debug pads which can be used to directly boot into the firmware of the device via an external SD card and install malware enabling access to the root shell and the ability to access to the 'always listening' microphones.

"If you're an attacker, you could build a device, place it onto that pad, give it a minute or so then remove it and you'll have the capability to gain access to the entire operating system running at the highest privileged user you can be at this level," Mark Barnes, security consultant at MWR InfoSecurity told ZDNet.

All of this can be done without leaving any physical evidence as the rubber base of the device can be reattached after the process is complete.

Researchers were able to examine how audio media was processed on the device and then successfully developed scripts which leveraged the functions within the Echo to stream audio to a remote server - all without impacting its functionality.

The eavesdropped audio could then be played back on a remote device, allowing for the listening in of conversations which took place in front of the attacked Echo. Barnes described how he was able to compromised the device.

"First of all I go about installing a remote shell, giving me the command line of the device over to my computer, so it's as if I'm on the computer inside the Echo itself as the boot user," he said.

"Then I worked out how the audio worked in the system, hooked myself in and then I could keep listening to the audio - that could then be sent through to the network and I could listen in through the microphone without the user being aware," Barnes added.

Both the 2015 and 2016 versions of Amazon Echo have been confirmed to be vulnerable to this exploit. The 2017 version and the smaller Amazon Dot can't be attacked in this way.

While the physical effort involved in carrying out this attack means that it's very unlikely that hackers could compromise an Echo in this way - especially when so many other Internet of Things with listening capabilities can be remotely attacked. But IoT devices like this are are becoming more and more common in the home and workplace.

Another feature which limits the impact of the hack is that all Amazon Echos come with a mute button which can turn off the microphone, so anyone concerned about being snooped on can simply turn it off and their conversations won't be able to be heard by the device or anyone who could potentially be listening in.

It's also possible to avoid much of the risk by ensuring any device purchased is bought brand new and from a trusted seller as it avoids the possibility of a previous owner having potentially tampered with the device. Users should also avoid lending out the device and ensure the software is kept up to date.

"Customer trust is very important to us. To help ensure the latest safeguards are in place, as a general rule, we recommend customers purchase Amazon devices from Amazon or a trusted retailer and that they keep their software up-to-date," an Amazon spokesperson told ZDNet.

The findings illustrate how organisations looking to install Internet of Things devices should ensure they have an appropriate security policy to take into account any potential new risks.

"The key takeaway is about ensuring that if you're producing a product that it has adequate security assessments and also if you're planning on buying things and bringing them into your business, you want them in a secure, trusted location," said Barnes.

READ MORE ON CYBERSECURITY



from Latest Topic for ZDNet in... http://ift.tt/2vjmaol

Most Singapore SMBs won't pay ransomware demands

Most small and midsize businesses (SMBs) in Singapore do not believe in paying off ransomware demands, despite one in six having experienced downtime lasting more than 25 hours during such attacks.

Compared to 59 percent globally, 62 percent in Singapore said ransomware demands should never be paid, while the majority of the remaining SMBs here said such demands should be paid only if the encrypted data was of value to the organisation. Some 33 percent of those that opted not to pay lost files as a result, according to a study conducted by Osterman Research and commissioned by Malwarebytes.

The study polled 1,054 SMBs in Singapore, France, Germany, Australia, North America, and the UK, with 174 respondents from Singapore.

Thirty-five percent of SMBs in the city-state revealed they had suffered a ransomware attack over the past year, of which 21 percent had to immediately halt all business operations. Another 11 percent lost revenue as a result of the attack, often from paying off ransomware demands.

Some 53 percent said ransomware demands were less than US$1,000, while 7 percent said such sums totalled more than US$1,000.

Amongst companies affected by ransomware, 61 percent incurred downtime lasting more than nine hours as a result of just one incident. Another 15 percent said a ransomware infection triggered downtime of at least 25 hours. Further, among SMBs that experienced a ransomware attack, 21% reported that they had to cease business operations immediately, and 11% lost revenue.

And while 73 percent ranked the need to address ransomware as high or very high priority, just 9 percent expressed confidence they could stop such attacks. Another 30 percent admitted they were unable to identify how they were infected and 20 percent said such attacks spread to other devices.

"Businesses of all sizes are increasingly at risk for ransomware attacks, [but] the stakes of a single attack for a small business are far different from the stakes of a single attack for a large enterprise," said Jeff Hurmuses, Malwarebytes' Asia-Pacific managing director and area vice president. "SMBs are suffering in the wake of attacks to the point where they must cease business operations. To make matters worse, most of them lack the confidence in their ability to stop an attack, despite significant investments in defensive technologies. "

malwarebytes-sg.png


from Latest Topic for ZDNet in... http://ift.tt/2f3VYba

Singapore may regulate digital tokens where appropriate


The Singapore government says it will step in to regulate the offer or use of digital tokens if these involved products regulated under the country's Securities and Futures Act.

The move was prompted a recent spate of launches in which initial coin offerings (ICOs), or digital tokens, were tapped as a means of raising funds, said Monetary Authority of Singapore (MAS) in a statement Tuesday. It defined digital tokens as "a cryptographically-secured representation of a token-holder's rights to receive a benefit or to perform specified functions". These included virtual currencies, which functioned as a medium of exchange, a unit of account, or a store of value, it said.

Read this

Why Singapore doesn't need Bitcoin

The island will get its first Bitcoin ATM in March, but does it really need another currency which main appeal is the anonymity it offers, especially since Singapore is reportedly susceptible to money laundering?

Read More

The regulator pointed to its previous statement in March 2014 when it said intermediaries in virtual currencies would be regulated against money laundering and terrorist funding risks. These organisations also were required to report suspicious transactions.

Likewise, ICOs were vulnerable to similar risks due to the anonymity involved in such transactions and the ease with which large sums could be raised in a short period of time, MAS said. It added that it currently was evaluating how it should regulate activities involving digital tokens, which did not function solely as virtual currencies, against money laundering and terrorist funding risks.

It noted that while it had taken a position of not regulating virtual currencies, per se, the function of digital tokens had evolved that of a virtual currency.

"For example, digital tokens may represent ownership or a security interest over an issuer's assets or property. Such tokens may, therefore, be considered an offer of shares or units in a collective investment scheme under the Securities and Futures Act," MAS explained, adding that digital tokens also might represent a debt owed by an issuer and be considered a debenture under the act.

Should digital tokens be considered under the act, issuers of such tokens must lodge and register a prospectus with MAS prior to the offer of such tokens, unless officially exempted. These organisations also would have to adhere to licensing requirements as well as other applicable requirements on anti-money laundering and countering the financing of terrorism.

It added that platforms facilitating the trading of digital tokens must be approved by the regulator as an approved exchange or or recognised as a market operator under the Securities and Futures Act.

MAS' announcement came amid recent launches involving local companies that used blockchain to value real estate property. One such company, Reidao, said it was creating digital tokens backed by real estate with its proprietary Token ID for each property listed on its platform.

"Every Token ID will have its own cap of tokens available or created, its own valuation--based on the property that is backing it--and its own track record of price movements, rental income and dividend, and so on," the Singapore company said on its website.

"We want to democratise property opportunities, to be accessible by everyone, wherever they are. By buying and selling these tokens, you are--in a way--buying and selling fractions of the underlying property," it said.

Reidao added that it hoped to operate a "Property Tokens Exchange Board", which would function like a stock exchange, listing "tokenised" properties available globally.

Earlier this week, the first lawsuit involving a bitcoin exchange was filed in Singapore, in which Quoine was alleged to have wrongfully reversed a transaction estimated to worth US$3.78 million. The Singapore-based exchange, which previously raised more than US$20 million in funds, currently processed US$50 million worth of transactions a day.

Filed by electronics maker B2C2, the lawsuit said Quoine had reversed a transaction that had gone through the day before where B2C2 had placed orders to sell Ethereum for bitcoin. Quoine said the trades were executed at an "abnormal rate"--125 times higher than the day's market price of Ethereum--due to a system glitch and, hence, reversed the transaction.

B2C2 said Quoine had "acted fraudulently' since the exchange's trading agreement stated that orders were irreversible once filled. Its lawsuit sought to recover 3084.78582325 bitcoin from Quoine.



from Latest Topic for ZDNet in... http://ift.tt/2w1fysy

Dangerous Mobile Banking Trojan Gets 'Keylogger' to Steal Everything


Cyber criminals are becoming more adept, innovative, and stealthy with each passing day. They have now shifted from traditional to more clandestine techniques that come with limitless attack vectors and are harder to detect.

Security researchers have discovered that one of the most dangerous Android banking Trojan families has now been modified to add a keylogger to its recent strain, giving attackers yet another way to steal victims sensitive data.

Kaspersky Lab's Senior malware analyst Roman Unuchek

spotted

a new variant of the well-known Android banking Trojan, dubbed

Svpeng

, in the mid of last month with a new keylogger feature, which takes advantage of Android's Accessibility Services.

Trojan Exploits 'Accessibility Services' to Add Keylogger

Yes, the keylogger added in the new version of Svpeng takes advantage of

Accessibility Services

— an Android feature that provides users alternative ways to interact with their smartphone devices.

This change makes the Svpeng Trojan able not only to steal entered text from other apps installed on the device and log all keystrokes, but also to grant itself more permissions and rights to prevent victims from uninstalling the Trojan.

In November last year, the Svpeng banking trojan

infected over 318,000 Android devices

across the world over the span of only two months with the help of Google AdSense advertisements that was abused to spread the malicious banking Trojan.

Over a month ago, researchers also discovered another attack taking advantage of Android's Accessibility Services, called

Cloak and Dagger attack

, which allows hackers to silently take full control of the infected devices and steal private data.

If You Are Russian, You Are Safe!

Although the new variant of the Svpeng malware is not yet widely deployed, the malware has already hit users in 23 countries over the course of a week, which include Russia, Germany, Turkey, Poland, and France.

But what's worth noticing is that, even though most infected users are from Russia, the new variant of Svpeng Trojan doesn't perform malicious actions on those devices.

According to Unuchek, after infecting the device, the Trojan first checks the device's language. If the language is Russian, the malware prevents further malicious tasks—this suggests the criminal group behind this malware is Russian, who are avoiding to violate Russian laws by hacking locals.

How 'Svpeng' Trojan Steals Your Money

Unuchek says the latest version of Svpeng he spotted in July was being distributed through malicious websites that disguised as a fake Flash Player.

Once installed, as I have mentioned above, the malware first checks for the device language and, if the language is not Russian, asks the device to use Accessibility Services, which opens the infected device to a number of dangerous attacks.

With having access to Accessibility Services, the Trojan grants itself device administrator rights, displays an overlay on the top of legitimate apps, installs itself as a default SMS app, and grants itself some dynamic permissions, such as the ability to make calls, send and receive SMS, and read contacts.

Additionally, using its newly-gained administrative capabilities, the Trojan can block every attempt of victims to remove device administrator rights—thereby preventing the uninstallation of the malware.

Using accessibility services, Svpeng gains access to the inner working of other apps on the device, allowing the Trojan to steal text entered on other apps and take screenshots every time the victim presses a button on the keyboard, and other available data.

"Some apps, mainly banking ones, do not allow screenshots to be taken when they are on top. In such cases, the Trojan has another option to steal data – it draws its phishing window over the attacked app," Unuchek says. 
"It is interesting that, in order to find out which app is on top, it uses accessibility services too."

All the stolen information is then uploaded to the attackers' command and control (C&C) server. As part of his research, Unuchek said he managed to intercept an encrypted configuration file from the malware's C&C server.

Decrypting the file helped him find out some of the websites and apps that Svpeng targets, as well as help him obtain a URL with phishing pages for both the PayPal and eBay mobile apps, along with links for banking apps from the United Kingdom, Germany, Turkey, Australia, France, Poland, and Singapore.

Besides URLs, the file also allows the malware to receive various commands from the C&C server, which includes sending SMS, collecting information such as contacts, installed apps and call logs, opening the malicious link, gathering all SMS from the device, and stealing incoming SMS.

The Evolution of 'Svpeng' Android Banking Malware

Researchers at Kaspersky Lab initially discovered the Svpeng Android banking malware trojan back in 2013, with primary capability—Phishing.

Back in 2014, the malware was then modified to add a ransomware component that locked victim's device (by FBI because they visited sites containing pornography) and demanded $500 from users.

The malware was among the first to begin attacking SMS banking, use phishing web pages to overlay other apps in an effort to steal banking credentials and to block devices and demand money.

In 2016, cyber criminals were actively distributing

Svpeng via Google AdSense

using a vulnerability in the Chrome web browser, and now abusing Accessibility Services, which makes Svpeng the most dangerous mobile malware family to date.

How to Protect Your Smartphone From Hackers

With just Accessibility Services, this banking Trojan gains all necessary permissions and rights to steal lots of data from the infected devices.

The malicious techniques of the Svpeng malware even work on fully-updated Android devices with the latest Android version and all security updates installed, so it is little users can do in order to protect themselves.

There are standard protection measures you need to follow to remain unaffected:

  • Always stick to trusted sources, like Google Play Store and the Apple App Store, but only from trusted and verified developers.
  • Most importantly, verify app permissions before installing apps. If any app is asking more than what it is meant for, just do not install it.
  • Do not download apps from third party sources, as most often such malware spreads via untrusted third-parties.
  • Avoid unknown and unsecured Wi-Fi hotspots and Keep your Wi-Fi turned OFF when not in use.
  • Never click on links provided in an SMS, MMS or email. Even if the email looks legit, go directly to the website of origin and verify any possible updates.
  • Install a good antivirus app that can detect and block such malware before it can infect your device, and always keep the app up-to-date.


from The Hacker News http://ift.tt/2hjEb0l

Monday, July 31, 2017

USN-3366-2: OpenJDK 8 regression

Ubuntu Security Notice USN-3366-2

31st July, 2017

openjdk-8 regression

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 17.04
  • Ubuntu 16.04 LTS

Summary

USN 3366-1 introduced a regression in OpenJDK 8.

Software description

  • openjdk-8 - Open Source Java implementation

Details

USN-3366-1 fixed vulnerabilities in OpenJDK 8. Unfortunately, that
update introduced a regression that caused some valid JAR files to
fail validation. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that the JPEGImageReader class in OpenJDK would
incorrectly read unused image data. An attacker could use this to
specially construct a jpeg image file that when opened by a Java
application would cause a denial of service. (CVE-2017-10053)

It was discovered that the JAR verifier in OpenJDK did not properly
handle archives containing files missing digests. An attacker could
use this to modify the signed contents of a JAR file. (CVE-2017-10067)

It was discovered that integer overflows existed in the Hotspot
component of OpenJDK when generating range check loop predicates. An
attacker could use this to specially construct an untrusted Java
application or applet that could escape sandbox restrictions
and cause a denial of service or possibly execute arbitrary
code. (CVE-2017-10074)

It was discovered that the JavaScript Scripting component of OpenJDK
incorrectly allowed access to Java APIs. An attacker could use this
to specially craft JavaScript code to bypass access restrictions.
(CVE-2017-10078)

It was discovered that OpenJDK did not properly process parentheses
in function signatures. An attacker could use this to specially
construct an untrusted Java application or applet that could escape
sandbox restrictions. (CVE-2017-10081)

It was discovered that the ThreadPoolExecutor class in OpenJDK did not
properly perform access control checks when cleaning up threads. An
attacker could use this to specially construct an untrusted Java
application or applet that could escape sandbox restrictions and
possibly execute arbitrary code. (CVE-2017-10087)

It was discovered that the ServiceRegistry implementation
in OpenJDK did not perform access control checks in certain
situations. An attacker could use this to specially construct
an untrusted Java application or applet that escaped sandbox
restrictions. (CVE-2017-10089)

It was discovered that the channel groups implementation in
OpenJDK did not properly perform access control checks in some
situations. An attacker could use this to specially construct an
untrusted Java application or applet that could escape sandbox
restrictions. (CVE-2017-10090)

It was discovered that the DTM exception handling code in the
JAXP component of OpenJDK did not properly perform access control
checks. An attacker could use this to specially construct an untrusted
Java application or applet that could escape sandbox restrictions.
(CVE-2017-10096)

It was discovered that the JAXP component of OpenJDK incorrectly
granted access to some internal resolvers. An attacker could use this
to specially construct an untrusted Java application or applet that
could escape sandbox restrictions. (CVE-2017-10101)

It was discovered that the Distributed Garbage Collector (DGC) in
OpenJDK did not properly track references in some situations. A
remote attacker could possibly use this to execute arbitrary
code. (CVE-2017-10102)

It was discovered that the Activation ID implementation in the RMI
component of OpenJDK did not properly check access control permissions
in some situations. An attacker could use this to specially construct
an untrusted Java application or applet that could escape sandbox
restrictions. (CVE-2017-10107)

It was discovered that the BasicAttribute class in OpenJDK did not
properly bound memory allocation when de-serializing objects. An
attacker could use this to cause a denial of service (memory
consumption). (CVE-2017-10108)

It was discovered that the CodeSource class in OpenJDK did not
properly bound memory allocations when de-serializing object
instances. An attacker could use this to cause a denial of service
(memory consumption). (CVE-2017-10109)

It was discovered that the AWT ImageWatched class in OpenJDK did not
properly perform access control checks, An attacker could use this
to specially construct an untrusted Java application or applet that
could escape sandbox restrictions (CVE-2017-10110)

Jackson Davis discovered that the LambdaFormEditor class in the
Libraries component of OpenJDK did not correctly perform bounds checks
in the permuteArgumentsForm() function. An attacker could use this
to specially construct an untrusted Java application or applet that
could escape sandbox restrictions and possibly execute arbitrary
code. (CVE-2017-10111)

It was discovered that a timing side-channel vulnerability existed
in the DSA implementation in OpenJDK. An attacker could use this to
expose sensitive information. (CVE-2017-10115)

It was discovered that the LDAP implementation in OpenJDK incorrectly
followed references to non-LDAP URLs. An attacker could use this to
specially craft an LDAP referral URL that exposes sensitive information
or bypass access restrictions. (CVE-2017-10116)

It was discovered that a timing side-channel vulnerability existed
in the ECDSA implementation in OpenJDK. An attacker could use this
to expose sensitive information. (CVE-2017-10118)

Ilya Maykov discovered that a timing side-channel vulnerability
existed in the PKCS#8 implementation in OpenJDK. An attacker could
use this to expose sensitive information. (CVE-2017-10135)

It was discovered that the Elliptic Curve (EC) implementation
in OpenJDK did not properly compute certain elliptic curve
points. An attacker could use this to expose sensitive
information. (CVE-2017-10176)

It was discovered that OpenJDK did not properly restrict weak key
sizes in some situations. An attacker could use this to specially
construct an untrusted Java application or applet that could escape
sandbox restrictions. (CVE-2017-10193)

It was discovered that OpenJDK did not properly enforce disabled
algorithm restrictions on X.509 certificate chains. An attacker
could use this to expose sensitive information or escape sandbox
restrictions. (CVE-2017-10198)

It was discovered that OpenJDK did not properly perform access control
checks when handling Web Service Definition Language (WSDL) XML
documents. An attacker could use this to expose sensitive information.
(CVE-2017-10243)

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 17.04:
openjdk-8-jre-zero 8u131-b11-2ubuntu1.17.04.3
openjdk-8-jre 8u131-b11-2ubuntu1.17.04.3
openjdk-8-jre-headless 8u131-b11-2ubuntu1.17.04.3
Ubuntu 16.04 LTS:
openjdk-8-jre-zero 8u131-b11-2ubuntu1.16.04.3
openjdk-8-jre 8u131-b11-2ubuntu1.16.04.3
openjdk-8-jre-headless 8u131-b11-2ubuntu1.16.04.3
openjdk-8-jre-jamvm 8u131-b11-2ubuntu1.16.04.3

To update your system, please follow these instructions: http://ift.tt/17VXqjU.

This update uses a new upstream release, which includes additional
bug fixes. After a standard system update you need to restart any
Java applications or applets to make all the necessary changes.

References

LP: 1707082



from Ubuntu Security Notices http://ift.tt/2uPbQDZ