Contact Me By Email

Showing posts with label Uniform Resource Locator. Show all posts
Showing posts with label Uniform Resource Locator. Show all posts

Monday, February 28, 2011

Closing backdoor threats in OS X | MacFixIt - CNET Reviews

Closing backdoor threats in OS X | MacFixIt - CNET Reviews

by Topher Kessler

A "back door" in computing terms is a method that hackers use to circumvent a system's authentication features and gain access without being detected. Usually this involves taking advantage of bugs in the built-in sharing services and OS features, but it also can happen if a user inadvertently installs some malware that provides a path around the system's security.

Anytime you start a sharing service on your computer, be it for files, screen sharing, chatting, or printers, you are technically opening a door for a client application running on remote system to connect and change or use aspects of your system. For instance, when you enable Web sharing, then a Web browser client on another computer can connect and read HTML Web pages that the server has made available. These sharing services run as background tasks and usually first authenticate and authorize users and connections based on the system's security measures (recognizing accounts and permissions limits).
While these services are built to be legitimate and productive features of an OS, bugs in them may provide a route that hackers can take to open back doors in the system's security and gain access to the system. These holes are rare and are usually patched quickly by Apple or legitimate third-party developers when found, but besides taking advantage of built-in services one method that hackers can use is to trick users into installing a malware service that runs hidden in the background and allows the hacker entry into the system.

A new Trojan horse security threat has recently surfaced that has been described as a backdoor Trojan for OS X. The malware allows an attacker to connect to a system using a client application and perform tasks like shutting it down, restarting it, creating files on the desktop, opening URLs in a Web client, requesting administrative passwords, and messaging the current user.

As with any Trojan horse program, the user inadvertently installs the application thinking it is a legitimate package, but instead of being a standalone program that alters configurations (like the DNSChanger Trojan) or sends data to remote systems (like a botnet hack), this Trojan installs a server on your system that allows a hacker to connect and administer the system with a small remote client program (called a remote administration tool, or RAT). The hacker enters your IP address into his client, connects
With the Trojan installed, a hacker can use an RA T client program to connect and send commands to the affected system. This is the RAT interface for the newly discovered malware. (Credit: Sophos) to the malware service installed on your system, and can then send remote commands to your system using the RAT system.
This malware is very similar to the age-old NetBus and Sub7 RATs for Windows, and can ultimately be characterized more as a prank application than anything else (though there are legitimate RAT services, including Apple's Server Admin tools). Nevertheless, it does still pose a security risk if installed because users can be tricked into supplying their administrative passwords to the hacker, among other things.
Does this change the nature of OS X security? Absolutely not, and given the measures required to install and enable this threat, it is ultimately a very low risk. While there is always concern that OS X's security features can be circumvented and result in malware being automatically installed, so far this malware, as with most other Trojans, requires you to manually run an installer to load a separate standalone program. The supplied OS features and services are not touched and their security measures are left intact.

Because you need to install the program to put your system at risk, the simplest and easiest way to avoid it and other similar Trojan threats is to never run an installer or other program unless you know exactly where it came from. Depending on your familiarity with computers this may be difficult to tell, so your next-best bet is to keep away from underground Web sites and any online deals that seem to be too good to be true, especially if the sites require a program to be installed to view their offerings.
If you are uncertain about your ability to identify hack attempts, install a malware scanner and have it watch your Downloads folder so any new files added to this folder are immediately scanned. Also go to Safari's General settings and uncheck the option to open "safe" files after downloading, and set your browsers to download files into the watched downloads folder. Some antivirus tools have on-access scanning features, but these are likely not yet necessary for OS X and may cause compatibility and performance problems. Therefore, disable these features unless you specifically need them, and then set them up to watch or manually scan a common Downloads folder. See this article for a list of antivirus software recommendations for OS X.

Disabling Safari's option to open 'safe' files will prevent programs disguised as documents from being opened.

In addition to scanning with a robust and updated malware scanner, there are other ways to protect your system. Because this malware appears to be a standard client-server program that uses basic IP connectivity, even if it is running on your system it will be nearly impossible for a hacker to use if your system is behind a properly configured network firewall. Most modern home and workplace routers have robust NAT firewalls with numerous extra security features (such as stealth modes and flood detection), so be sure your network is protected by one. Additionally, check your router and disable any unused ports and DMZ hosting.
Lastly, be sure to enable the OS X firewall and regularly clear the list of applications allowed through the firewall (found in the Security system preferences in the Firewall tab). This will ensure you only allow the programs you currently use through the firewall, and are notified of other, less common ones that might be requesting network access. In addition, while the built-in firewall blocks incoming traffic, it does not block outgoing traffic, so you might consider installing a program like Little Snitch to detect when applications on your system send information out to the Internet.

Monday, October 25, 2010

Iranian Cyber Army Moves Into Botnets - PCWorld

Iranian Cyber Army Moves Into Botnets - PCWorld
A group of malicious hackers who attacked Twitter and the Chinese search engine Baidu are also apparently running a for-rent botnet, according to new research.
The so-called Iranian Cyber Army also took credit last month for an attack on TechCrunch's European website. In that incident, the group installed a page on TechCrunch's site that redirected visitors to a server that bombarded their PCs with exploits in an attempt to install malicious software.
Researchers with a security startup called Seculert have traced the malicious server behind those attacks and found indications that the Iranian Cyber Army may also be running a botnet.
They've found an administration interface where people who want to rent the botnet can describe the machines they would like to infect and upload their own malware for distribution by the botnet, said Aviv Raff , CTO and co-founder of Seculert. The company runs a cloud-based service that alerts its customers to new malware, exploits and other cyber threats.
"You provide the number of machines and their region," Raff said. "You then provide the malware download URL, and they will do the malware installation for you."
There are many computer crime gangs that create botnets, or networks of compromised computers, that can then be rented to other players in the cybercrime industry, such as spammers.
Raff said Seculert was able to see the administration panel as it was left unprotected. His company has since notified the provider where the page is hosted and contacted law enforcement.

Thursday, July 29, 2010

BBC News - Facebook data harvester speaks out

BBC News - Facebook data harvester speaks out

Facebook torrent

The torrent is attracting hundreds of downloads. The man who harvested and published the personal details of 100m Facebook users has spoken out about his motives.

Ron Bowes, a security consultant, used a piece of code to scan Facebook profiles, collecting data not hidden by the user's privacy settings.

The list, which contains the URL of every searchable Facebook user's profile, name and unique ID, has been shared as a downloadable file.

Mr Bowes told BBC News that he did it as part of his work on a security tool.

"I'm a developer for the Nmap Security Scanner and one of our recent tools is called Ncrack," he said.

"It is designed to test password policies of organisations by using brute force attacks; in other words, guessing every username and password combination."

By downloading the data from Facebook, and compiling a user's first initial and surname, he was able to make a list of the most common probable usernames to use in the tool.

The three most common names, he found, were jsmith, ssmith and skhan.

In theory, researchers could then combine this list with a catalogue of the most commonly used passwords to test the security of sites. Similar techniques could be used by criminals for more nefarious means.

Mr Bowes said his original plan was to "collect a good list of human names that could be used for these tests". "Once I had the data, though, I realised that it could be of interest to the community if I released it, so I did," he added. I am of the belief that, if I can do something then there are about 1,000 bad guys that can do it too”

Mr Bowes confirmed that all the data he harvested was already publicly available but acknowledged that if anyone now changed their privacy settings, their information would still be accessible.

"If 100,000 Facebook users decide that they no longer want to be in Facebook's directory, I would still have their name and URL but it would no longer, technically, be public," he said.

Mr Bowes said that collecting the data was in no way irresponsible and likened it to a telephone directory.

"All I've done is compile public information into a nice format for statistical analysis," he said

Simon Davies from the watchdog Privacy International told BBC News it was an "ethical attack" and that more personal information had not been included in the trawl.

"This is a reputational and business issue for Facebook, for now," he said

"They can continue to ride the risk and hope nothing cataclysmic occurs, but I would argue that Facebook has a special responsibility to go beyond doing the bare minimum," he added.

100M Facebook Profiles Now Available For Download - PCWorld

Facebook logoImage via Wikipedia
100M Facebook Profiles Now Available For Download - PCWorld

One hundred million Facebook user profiles containing personal information such as e-mail addresses and phone numbers, are now available as a 2.8GB torrent download. Ron Bowes of Skull Security created the torrent using a Web crawler program, harvesting data from public profiles of users who have chosen not to change their privacy settings.

The file contains information for 1 in every 5 Facebook users, all those who are currently listed in the Facebook open access directory. Nothing is illegal about the torrent, because it simply uses data that is available to the public. Even those who have secured their own Facebook page may not be completely out of the clear. In a statement on his website Bowes said:

"...this is a scary privacy issue. I can find the name of pretty much every person on Facebook...Once I have the name and URL of a user, I can view, by default, their picture, friends, information about them, and some other details. If the user has set their privacy higher, at the very least I can view their name and picture. So, if any searchable user has friends that are non-searchable, those friends just opted into being searched, like it or not! "
Enhanced by Zemanta