Monday, October 30, 2017

Wait, Do You Really Think That’s A YouTube URL? Spoofing Links On Facebook


While scrolling on Facebook how you decide which link/article should be clicked or opened?

Facebook timeline and Messenger display title, description, thumbnail image and URL of every shared-link, and this information are enough to decide if the content is of your interest or not.

Since Facebook is full of spam, clickbait and fake news articles these days, most users do not click every second link served to them.

But yes, the possibility of opening an article is much higher when the content of your interest comes from a legitimate and authoritative website, like YouTube or Instagram.

However, what if a link shared from a legitimate website lands you into trouble?

Even before links shared on Facebook could not be edited, but to stop the spread of misinformation and false news, the social media giant also removed the ability for Pages to edit title, description, thumbnail image of a link in July 2017.

However, it turns out that—spammers can spoof URLs of the shared-links to trick users into visiting pages they do not expect, redirecting them to phishing or fake news websites with malware or malicious content.

Discovered by 24-year-old security researcher

Barak Tawily

, a simple trick could allow anyone to spoof URLs by exploiting the way Facebook fetch link previews.

In brief, Facebook scans shared-link for Open Graph meta tags to determine page properties, specifically 'og:url', 'og:image' and 'og:title' to fetch its URL, thumbnail image and title respectively.

Interestingly, Tawily found that Facebook does not validate if the link mentioned in 'og:url' meta tag is same as the page URL, allowing spammers to spread malicious web pages on Facebook with spoofed URLs by just adding legitimate URLs in 'og:url' Open Graph meta tag on their websites.

"In my opinion, all Facebook users think that preview data shown by Facebook is reliable, and will click the links they are interested in, which makes them easily targeted by attackers that abuse this feature in order to perform several types of attacks, including phishing campaigns/ads/click fraud pay-per-click," Tawily told The Hacker News.

Tawily reported the issue to Facebook, but the social media giant refused to recognise it as a security flaw and referred that Facebook uses "Linkshim" to protect against such attacks.

If you are unaware, every time a link is clicked on Facebook, a system called "Linkshim" checks that URL against the company's own blacklist of malicious links to avoid phishing and malicious websites.

This means if an attacker is using a new domain for generating spoofed links, it would not be easy for Linkshim system to identify if it is malicious.

Although Linkshim also uses machine learning to identify never-seen-before malicious pages by scanning its content, Tawily found that the protection mechanism could be bypassed by serving non-malicious content explicitly to Facebook bot based on User-Agent or IP address.

Tawily has also provided a demo video to show the attack in action. You can watch the video above.

Since there is no way to check the actual URL behind a shared link on Facebook without opening it, there is a little user can do to protect themselves except being vigilant.



from The Hacker News http://ift.tt/2iMr6xQ

Microsoft to add free premium features to Outlook.com for Office 365 consumer subscribers

Microsoft is starting to roll out to Office 365 Home and Office 365 Personal subscribers some premium capabilities for their Outlook.com accounts for free.

outlookcompremiumbenefitsforo365consumers.jpg

Among the features that these users of Microsoft's consumer-focused Office 365 users are getting right off the bat are ad-free Outlook.com inboxes, enhanced malware and phishing protection for Outlook.com, larger Outlook.com mailbox sizes and free premium customer support.

In order to qualify for these new benefits, Outlook.com users must also be subscribers to either Office 365 Home or Personal. The rollout already has begun but may take about a month for everyone who qualifies to get the new features, according to Microsoft.

For those Outlook.com users who also are Office 365 Home/Personal subscribers, Outlook.com will now be free of banner ads, as well as ads in the message list (a k a "native ads").

Office 365 Home and Personal subscribers also will automatically will have their Outlook.com attachments scanned for potential malware threats, as well as links checked to try to head off fake sites downloading viruses or malware. One caveat: Users with Connected Accounts that add access to an @gmail.com, @yahoo.com or other third-party account from Outlook.com won't have these advanced security features applied to these additional accounts.

In terms of mailbox storage limits, Outlook.com users currently get 15 GB of email storage; Office 365 Home and Personal users get 50 GB. Now storage limits will go up to 50 GB for Outlook.com users with mailbox sizes of 12 GB or larger, according to Microsoft's October 30 blog post announcing all these changes.

Outlook.com users also will get free technical support if they also are Office 365 Home/Personal users.

There's an accompanying article about these changes with some frequently asked questions (FAQs). Among those questions is a note that anyone who cancels or lets expire an Office 365 Home/Personal subscription will cease getting these premium benefits for their Outlook.com accounts.

Also: These new premium features will not be added to users' Outlook.com accounts if they are Office 365 business subscribers. This is for Outlook.com users who are Office 365 Personal and Home users only. (Microsoft officials said last week there are currently 28 million active monthly users of Outlook 365 Home and Personal combined.) Office 365 Home, which is for households with one to five usrs, costs $100 per year; Office 365 Personal (for one user) costs $70 per year.

On a related note, the Outlook.com Premium subscription offer is currently closed to new subscribers, but current subscribers are eligible to renew their subscriptions.

These new free Outlook.com services will be made automatically for anyone who signed up for Office 365 Personal Home using addresses ending in @outlook.com, @hotmail.com, @live.com and/or @msn.com. More, unspecified premium features are coming to this group of Outlook.com users in the future, officials said.



from Latest Topic for ZDNet in... http://ift.tt/2hnqYBi

​A flaw in Google's bug database exposed private security vulnerability reports

(Image: file photo)

A series of flaws in Google's internal bug tracker let a security researcher gain access to some of the company's most critical and dangerous vulnerabilities.

The company's internal bug reporting system, known as the Issue Tracker (or the "Buganizer"), is used by security researchers and bug finders to submit issues, problems, and security vulnerabilities with Google's software, services and products.

Most ordinary users have very little access to the bug tracker. But a security researcher found that by spoofing a Google corporate email address, he was able to gain access to the back-end of the system, and to thousands of bug reports -- some of them marked as "priority zero," the most severe and dangerous vulnerabilities, with which a hacker could do untold damage.

Alex Birsan, who discovered the flaws, told ZDNet that an attacker could have discovered and exploited submitted vulnerabilities to target and potentially compromise Google accounts.

Worse, an attacker could've used a vulnerability to infiltrate Google's internal network.

Birsan explained in a write-up of his findings that he created a Gmail account which, prior to verifying the new account by email, would let a user change their email address to any email address, including Google corporate accounts.

Although Birsan's newly-created fake Google account wouldn't give him direct access to the company's network, it was enough to trick the Issue Tracker into thinking he was an employee, giving him elevated privileges to view and interact with bug reports, such as receive notifications and updates on issues.

From there, he was able to send altered requests to the Issue Tracker server, letting him read any bug he wanted -- including the most sensitive vulnerabilities -- because of a failure to properly validate the logged-in user's permissions against each report.

Or, as Birsan described it, the "holy grail of Google bugs."

"Even worse, I could exfiltrate data about multiple tickets in a single request, so monitoring all the internal activity in real time probably wouldn't have triggered any rate limiters," he explained.

After he reported the bugs, his access was revoked and the vulnerability fixed within the hour.

Birsan didn't underestimate the severity of the vulnerabilities, but hedged his findings with a key caveat. The bigger the vulnerability, the quicker it gets fixed by Google, he explained. "So even if you get lucky and catch a good one as soon as it's reported, you still have to have a plan for what you do with it."

"That being said, I believe you'd have a pretty good chance of compromising Google accounts if you had a few specific targets and threw every attack at them," he said.

But a large-scale attack that puts hundreds of thousands of accounts at risk was less likely, he said. "All in all, it depends entirely on what other people report while you're eavesdropping," he added.

Given that thousands of internal issues were added each hour, he said, "Who knows what kind of juicy information could be found in there?"

In all, Birsan was awarded a little over $15,600 in bug bounties from Google for the three bugs.

He was also given $3,133 as an additional grant to continue research on vulnerabilities with the Issue Tracker.

When reached, a Google spokesperson said: "We appreciate Alex's report. We've patched the vulnerabilities that he reported, as well as their variants."

Contact me securely

Zack Whittaker can be reached securely on Signal and WhatsApp at 646-755–8849, and his PGP fingerprint for email is: 4D0E 92F2 E36A EC51 DAAE 5D97 CB8C 15FA EB6C EEA5.

Read More



from Latest Topic for ZDNet in... http://ift.tt/2zj0208

USN-3459-2: MySQL vulnerabilities

Ubuntu Security Notice USN-3459-2

30th October, 2017

mysql-5.5 vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 12.04 LTS

Summary

Several security issues were fixed in MySQL.

Software description

  • mysql-5.5 - MySQL database

Details

USN-3459-1 fixed several vulnerabilities in MySQL. This update
provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.

MySQL has been updated to 5.5.58 in Ubuntu 12.04 ESM.

In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.

Please see the following for more information:
http://ift.tt/2xhVmTF
http://ift.tt/2ihu78W

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 12.04 LTS:
mysql-server-5.5 5.5.58-0ubuntu0.12.04.1

To update your system, please follow these instructions: http://ift.tt/17VXqjU.

In general, a standard system update will make all the necessary changes.

References

CVE-2017-10268, CVE-2017-10378, CVE-2017-10379, CVE-2017-10384



from Ubuntu Security Notices http://ift.tt/2gZq4hf

IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Content Collector for SAP Applications

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Java™ Version 6 and Java™ Version 7 that is used by IBM Content Collector for SAP Applications. These issues were disclosed as part of the IBM Java SDK updates in Jul 2017.

CVE(s): CVE-2017-10115, CVE-2017-10116, CVE-2017-10108, CVE-2017-10109, CVE-2017-10053

Affected product(s) and affected version(s):

IBM Content Collector for SAP Applications 3.0
IBM Content Collector for SAP Applications 4.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2A10I7e
X-Force Database: http://ift.tt/2xsr7ZC
X-Force Database: http://ift.tt/2wyaY8O
X-Force Database: http://ift.tt/2vff6pW
X-Force Database: http://ift.tt/2vEvu3j
X-Force Database: http://ift.tt/2wEhie8

The post IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Content Collector for SAP Applications appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2xAfcJW

IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Tivoli Monitoring

There are several vulnerabilities in IBM® SDK Java™ Technology Edition that is shipped as part of multiple IBM Tivoli Monitoring (ITM) components.

CVE(s): CVE-2017-10125, CVE-2017-10067, CVE-2017-10115, CVE-2017-10090, CVE-2017-10096, CVE-2017-10101, CVE-2017-10116, CVE-2017-10102, CVE-2017-10087, CVE-2017-10089, CVE-2017-10107, CVE-2017-10110, CVE-2017-1376, CVE-2017-10105, CVE-2017-10053, CVE-2017-10108, CVE-2017-10109, CVE-2017-10243

Affected product(s) and affected version(s):

The following components of IBM Tivoli Monitoring (ITM) are affected by this bulletin:

-Java (CANDLEHOME) ITM 6.2.3 Fix Pack 1 (JRE 1.6) through 6.3.0 Fix Pack 7 (JRE 7) (CVE-2017-10102, CVE-2017-10116, CVE-2017-10115, CVE-2017-10243)
-Java (Tivoli Enterprise Portal client browser or webstart) ITM 6.2.3 Fix pack 1 through 6.3.0 Fix Pack 7 (All CVE’s listed)

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2xz64VO
X-Force Database: http://ift.tt/2vfEyLU
X-Force Database: http://ift.tt/2x4YZ1U
X-Force Database: http://ift.tt/2xsr7ZC
X-Force Database: http://ift.tt/2x52Goj
X-Force Database: http://ift.tt/2x4LWxw
X-Force Database: http://ift.tt/2x4P6Bt
X-Force Database: http://ift.tt/2wyaY8O
X-Force Database: http://ift.tt/2veVuCa
X-Force Database: http://ift.tt/2x52GEP
X-Force Database: http://ift.tt/2vEW7Fc
X-Force Database: http://ift.tt/2vECPQw
X-Force Database: http://ift.tt/2x4P64r
X-Force Database: http://ift.tt/2vfk1Hi
X-Force Database: http://ift.tt/2x588Yf
X-Force Database: http://ift.tt/2wEhie8
X-Force Database: http://ift.tt/2vff6pW
X-Force Database: http://ift.tt/2vEvu3j
X-Force Database: http://ift.tt/2vQ1oZY

The post IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Tivoli Monitoring appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2A10Fby

USN-3464-2: Wget vulnerabilities

Ubuntu Security Notice USN-3464-2

30th October, 2017

wget vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 12.04 LTS

Summary

Several security issues were fixed in Wget.

Software description

  • wget - retrieves files from the web

Details

USN-3464-1 fixed several vulnerabilities in Wget. This update
provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

Antti Levomäki, Christian Jalio, and Joonas Pihlaja discovered that Wget
incorrectly handled certain HTTP responses. A remote attacker could use
this issue to cause Wget to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2017-13089, CVE-2017-13090)

Dawid Golunski discovered that Wget incorrectly handled recursive or
mirroring mode. A remote attacker could possibly use this issue to bypass
intended access list restrictions. (CVE-2016-7098)

Orange Tsai discovered that Wget incorrectly handled CRLF sequences in
HTTP headers. A remote attacker could possibly use this issue to inject
arbitrary HTTP headers. (CVE-2017-6508)

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 12.04 LTS:
wget 1.13.4-2ubuntu1.5

To update your system, please follow these instructions: http://ift.tt/17VXqjU.

In general, a standard system update will make all the necessary changes.

References

CVE-2016-7098, CVE-2017-13089, CVE-2017-13090, CVE-2017-6508



from Ubuntu Security Notices http://ift.tt/2zhS2wm