Wednesday, November 1, 2017

D-Link MEA Site Caught Running Cryptocurrency Mining Script—Or Was It Hacked?


Last month the popular torrent website The Pirate Bay caused some uproar by adding a Javascript-based

cryptocurrency miner

to its site with no opt-out option, utilizing visitors' CPU power to mine Monero coins in an attempt to gain an extra source of revenue.

Now D-Link has been caught doing the same, although there's high chance that its website has been hacked.

D-Link's official website for Middle East (www.dlinkmea.com) has been found secretly adding a JavaScript-based cryptocurrency miner, according to a blog post

published

by security firm Seekurity on Tuesday.

Seekurity team was made aware of the issue after Facebook user Ahmed Samir reported that visiting on D-Link Middle East website caused his web browser utilizing a "super high CPU" power usage.

As shown in the screenshot below, a separate domain was loaded using a hidden iFrame for each page view, which included the cryptocurrency mining script.

Five days after Seekurity team reported the issue to D-Link, the company took down the website and redirected it to D-Link USA website (us.dlink.com), without responding to the security firm.

Since the company redirected the whole website to another domain instead of just removing a single line of hidden iFrame code, there are high chances that D-Link has recently been a victim of cyber attack.

Anyways, cryptocurrency mining has become a competitive revenue stream these days, and it is trending among hackers as well.

So, it would be no surprise if hackers compromise popular websites and embed their cryptocurrency miners to harness visitor's system computing power in an attempt to mine digital coins.

Just yesterday it was

reported

that more than 200 of the top 100,000 websites on the web were found hosting suspicious code from CoinHive and JSEcoin, two popular cryptocurrency mining services, forcing their visitors to run miner code on their computers unknowingly.

If you are using a good antivirus solution, like Malwarebytes and Kaspersky, then you are protected, as most security solutions have already started blocking cryptocurrency mining scripts to prevent their customers from unauthorized mining and extensive CPU usage.



from The Hacker News http://ift.tt/2ikELrZ

This destructive wiper ransomware was used to hide a stealthy hacking campaign

ransomware.jpg Nawadoln, Getty Images/iStockphoto

Ransomware is being used to hide an elaborate, targeted hacking campaign which went undetected for months before the attackers pulled the plug and encrypted hundreds of machines at once in an effort to remove stolen data while also covering their tracks.

The campaign targeted several Japanese organisations in attacks which lasted from three to nine before a ransomware attack used a wiper on compromised machines in an effort to hide the operation.

Forensic investigation of the infected machines by researchers at Cybereason has led them to the conclusion that the attacker made the attempt to wipe evidence of the operation and destroy any traces of attack.

The name of the ransomware comes from the .oni file extension of encrypted files as well as the email address in the ransom note, which translates to "Night of the Devil" - the name researchers have given to the operation. Researchers note that ONI shares much of its code with GlobeImposter ransomware.

Attacks using ONI ransomware have been carried out against Japanese targets for some time, but the investigation into the latest wave of attacks uncovered a new variant, MBR-ONI, a form of the ransomware which comes equipped with bootkit features.

The new bootkit ransomware is based on DiskCryptor, a legitimate disk encryption tool, the code of which has also been found in Bad Rabbit ransomware.

While MBR-ONI bootkit ransomware was used against a controlled set of targets, such as Active Directory server and other critical assets, ONI was used against the rest of the endpoints in an infected network.

See also: Ransomware: An executive guide to one of the biggest menaces on the web

The ONI-based attacks all begin in the same way, with spear-phishing emails distributing malicious Office documents which drops the Ammyy Admin remote access tool.

Once inside the system, attackers map the internal networks, harvesting credentials and moving laterally through the system - researchers suspect that the leaked NSA SMB exploit EternalBlue plays a role in enabling the attackers to spread through the network.

Ultimately compromise critical assets including the domain controller to gain full control of the network and the ability to exfiltrate any data deemed important.

Once the attackers are done with the infected network, ONI and MBR-ONI ransomware was run.

While ONI does provide a ransom note and the prospect of recovering encrypted data, researchers believe MBR-ONI is designed to never provide a decryption key, but rather as a wiper to cover the attackers' footprints and conceal the true goals of the attack: espionage and removing data over a period of months.

During investigations of targeted organisations, it was found that some had been compromised since December 2016, indicating long-term planning and sophistication on behalf of the attackers.

While ONI and the newly discovered MBR-ONI exhibit all the characteristics of ransomware, our analysis strongly suggests that they might have actually been used as wipers to cover an elaborate scheme," said Assaf Dahan, director of advanced security services at Cybereason

"The use of ransomware and/or wipers in targeted attacks is not a very common practice, but it is on the rise. We believe 'The Night of the Devil' attack is part of a concerning global trend in which threat actors use ransomware/wipers in targeted attacks," he added.

Other known examples of campaigns using ransomware in destructive, targeted attacks include Mamba, Stonedrill, Shamoon - and most infamously, NotPetya, which wreaked global havoc earlier this year.

READ MORE ON CYBER CRIME



from Latest Topic for ZDNet in... http://ift.tt/2h0juqQ

Cisco Expands Its Multicloud Security Portfolio

Oracle pushes out emergency fix for remote system hijack vulnerability

screen-shot-2017-11-01-at-09-44-04.jpg File Photo

Oracle has broken its usual quarterly Critical Patch Update (CPU) cycle to release an emergency fix for a vulnerability which allows attackers to access enterprise software remotely without authentication.

The vulnerability, CVE-2017-10151, can result in a "complete compromise of Oracle Identity Manager via an unauthenticated network attack," according to the company.

The bug has been issued a CVSS score of 10, the highest in severity possible.

Attackers can remotely take over the software without prior authentication, and so no valid user account credentials are required. Connections to vulnerable software can be made over HTTP.

According to NIST, the vulnerability is "easily exploitable"

Oracle Identity Manager is a component found in Oracle Identity Management which manages and validates user identities and access to enterprise systems.

The bug impacts Oracle Identity Manager versions 11.1.1.7, 11.1.1.9, 11.1.2.1.0, 11.1.2.2.0, 11.1.2.3.0, and 12.2.1.3.0.

However, Oracle says that products which are not under Product Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by the advisory, and "it is likely that earlier versions of affected releases are also affected by these vulnerabilities."

"While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products," NIST says.

Oracle has implored IT admins to apply the patch "without delay" due to the severity of the issue.

See also: Oracle CEO Mark Hurd: AI shouldn't be a standalone application

Last month, Oracle patched a total of 252 vulnerabilities in the firm's latest quarterly patch update. Oracle Fusion Middleware, Oracle Hospitality, Oracle MySQL, and PeopleSoft received the most fixes -- and Java, naturally, was present too -- to resolve problems including remote code execution bugs, Persistent Cross Site Scripting (XSS) flaws, and SQL injection vulnerabilities.

The next Oracle patch update outside of emergency fixes is expected to land on January 16, 2018.

Previous and related coverage



from Latest Topic for ZDNet in... http://ift.tt/2gRKmW8

Circle with Disney web filter riddled with vulnerabilities

screen-shot-2017-11-01-at-08-09-57.jpg Circle Media

Cisco Talos researchers have discovered 23 vulnerabilities in Circle with Disney monitoring software which could be used to hijack full families of devices.

Circle with Disney is touted as "the smart way for families to manage content and time online, on any device." The $99 Android and iOS-compatible product pairs wirelessly and can be used to create a network of devices, including smartphones, tablets, and smart TVs, monitoring Internet use and websites visited.

Aimed chiefly at parents, owners can set up 'bedtimes' which close down Internet access, "pause" access, and set up filtering to prevent children from visiting websites they shouldn't.

In a world fuelled by the Internet and social media, it's easy to see why such products appeal.

However, on Monday, the Talos security team disclosed a set of serious vulnerabilities which gives attackers the opportunity to tap into every family member's activities and spy on every device -- or worse.

"Through these exploitable vulnerabilities a malicious attacker could gain various levels of access and privilege, including the ability to alter network traffic, execute arbitrary remote code, inject commands , install unsigned firmware, accept a different certificate than intended, bypass authentication, escalate privileges, reboot the device, install a persistent backdoor, overwrite files, or even completely brick the device," said the researchers.

The worst of the bugs, CVE-2017-12087, received the highest CVSS score possible of 10.0 in severity.

The exploitable heap overflow vulnerability exists in the mdnsd daemon and can force Circle to overwrite information on the heap with attacker controlled values, as long as the hacker has network connectivity to the Circle.

Another vulnerability, CVE-2017-2917, was rated at 9.9 by CVSS.

"An exploitable vulnerability exists in the notifications functionality of Circle with Disney," the team says. "Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request trigger this vulnerability."

In addition, CVE-2017-2898 allows attackers to use crafted network packets to install unsigned firmware and perform remote code execution, CVE-2017-2865 can be exploited to monitor and tamper with network traffic, CVE-2017-2864 can be harnessed to circumvent authentication token functionality and the rather nasty CVE-2017-12084 can be exploited to install a persistent backdoor into the Circle device.

When exploited, other vulnerabilities found by the researchers can result in command injections, remote code execution, memory corruption, forced device reboots, and even utilize the Disney cloud infrastructure to attack other devices.

The vulnerabilities are serious, especially as the device is aimed at use concerning children. However, Talos says the Circle Media security team have been "exemplary to work with" and have worked with Talos to mitigate these vulnerabilities after they were discovered and have pushed out automatic security updates to customers.

Previous and related coverage



from Latest Topic for ZDNet in... http://ift.tt/2huapDF

Microsoft Engineer Installs Google Chrome Mid-Presentation After Edge Kept Crashing


Ever since the launch of Windows 10, Microsoft has been heavily pushing its Edge browser, claiming it to be the best web browser over its competitors like Mozilla Firefox, Opera and Google Chrome in terms of speed and battery performance.

However, Microsoft must admit that most users make use of Edge or Internet Explorer only to download Chrome, which is by far the world's most popular internet browser.

Something hilarious happened recently during a live demonstration when a Microsoft engineer caught on a video switching from Edge to Chrome after the default Windows 10 browser stopped responding in the middle of the presentation.

That is really embarrassing.

The incident happened in the middle of a Microsoft Ignite conference, where the Microsoft presenter Michael Leworthy was demonstrating how to one can migrate their applications and data to Microsoft Azure cloud service.

See what happens in the video below:

However, Leworthy was forced to pause his Azure presentation in the middle of live demo session to download and install Google's Chrome because the company's Edge browser kept on crashing.

Guess what? This somewhat embarrassing and somewhat hilarious incident was recorded and uploaded to YouTube by Microsoft itself. You can check out the video yourself.

"I love it when demos break," Leworthy said. "So while we’re talking here, I’m gonna go install Chrome," he continued and started laughing, with many people in the audience giggling and cheering.

"And we're not going to make Google better," Leworthy added as he refused to check the box that sends crash reports and statistics back to Google.

Although Internet Explorer has long been considered to be "the best browser to download Google Chrome," Microsoft Edge came out to be a competent successor to do the same thing even faster, as Leworthy took less than a minute to download and install Chrome.



from The Hacker News http://ift.tt/2lzK0sF