Sunday, 12 February 2012

Google users warned of threat to smartphone wallets


Google users warned of threat to smartphone wallets

Users of Google smartphone wallets were being warned that there is a way to crack pass codes
Users of Google smartphone wallets were being warned on Friday that there is a way to crack pass codes intended to thwart thieves from going on illicit 

shopping sprees.
Zvelo Labs researcher Joshua Rubin was featured in a video at the company's website demonstrating software that quickly figures out a Google Wallet personal identification number (PIN), provided the crook has the smartphone.
Rubin said that Google has been alerted to the vulnerability and is moving swiftly to fix it. He has not made his wallet "Cracker" application public.
"Google Wallet allows only five invalid PIN entry attempts before locking the user out," Rubin said in a blog post.
"With this attack, the PIN can be revealed without even a single invalid attempt," he continued. "This completely negates all of the security of this mobile phone payment system."
Google declined an AFP request for comment.
"Once attackers get your PIN, they have full access to any credit card information stored in the app and they can use your phone to make purchases," McAfee security firm researcher Jimmy Shah said in a blog post.
"As a user of Google Wallet, the main security you see is the PIN," McAfee added.
"What makes Wallet easy for you to use now makes it easy for attackers to use; they can now spend your money and credit just as if your phone were an ATM card."
Rubin dismissed the threat of hackers picking Google Wallets remotely, explaining that physical access is needed to get priority access to controls in a process called "rooting."
Security specialists advise Google Wallet users not to "root" smartphones, and to enable security features such as full-disk encryption and screen locks.
Google Wallet is available only on Nexus S and Galaxy Nexus smartphones. Google said it planned to expand the feature to more Android phones.
Google Wallet uses a near field communication (NFC) chip embedded in a phone to allow a user to "tap-and-pay" for purchases at a checkout register equipped with the PayPass system from CitiMasterCard.
Customers can also use a Google Prepaid card to pay for purchases, topping up the Google card with any payment card, and take advantage of Google Offers, the Mountain View, California-based company's online discount coupon program.
In addition to allowing for mobile payments, Google Wallet allows consumers to pay using gift cards and to redeem promotions such as discounts or coupons.

Sunday, 29 January 2012

Facebook Security Phishing Attack In The Wild


Facebook Security Phishing Attack In The Wild

By David Jacoby
David JacobyAt the time of writing there is a new Facebook phishing attack going on. It will not just try to steal your Facebook credentials; it will also try to steal credit card information and other important information such as security questions.
This Facebook phishing attack is pretty interesting because it does not just try to trick the victim into visiting a phishing website. It will reuse the stolen information and login to the compromised account and change both profile picture and name. The profile picture will be changed to the Facebook logo and the name will be translated to “Facebook Security” but containing special ascii characters replacing letters such as “a” “k” “S” and “t”.
Once an account is compromised it will also send out a message to all contacts of the compromised account. The message looks like this:
Facebook
"Last Warning: Your Facebook account will be turned off Because someone has reported you. Please do re-confirm your account security by: => http://apps-xxxx-xxxxx-user.de.vuThank you. The Facebook Team"/
When clicking on the link you will be redirected to a website which looks very similar to Facebook, and asks you for personal information such as: Name, Email, Password, Webmail system, Password to email etc. When submitting this form the details will be sent to the attacker, and they can automatically login to your Facebook account and compromise it.
Facebook
After the victim submitted the information another webpage will appear, this page states that you need to confirm your identify with a payment and asks for your Card Number.
Facebook
The last page of the phishing scam will try to confirm your Credit card information including CSC/CVV code.
Facebook
These scams are just getting more popular and we really recommend not giving out personal information, especially not email, password and credit card information over social medias. It is also recommend that you contact your security vendor and the social media vendor if you encounter these sites.

Saturday, 24 December 2011

Watch out for fake virus alerts


Watch out for fake virus alerts

Example of a warning from a rogue security program known as AntivirusXP
Rogue security software, also known as "scareware," is software that appears to be beneficial from a security perspective but provides limited or no security, generates erroneous or misleading alerts, or attempts to lure users into participating in fraudulent transactions.


How does rogue security software get on my computer?

Rogue security software designers create legitimate looking pop-up windows that advertise security update software. These windows might appear on your screen while you surf the web.
The "updates" or "alerts" in the pop-up windows call for you to take some sort of action, such as clicking to install the software, accept recommended updates, or remove unwanted viruses or spyware. When you click, the rogue security software downloads to your computer.
Rogue security software might also appear in the list of search results when you are searching for trustworthy antispyware software, so it is important to protect your computer.

What does rogue security software do?

Rogue security software might report a virus, even though your computer is actually clean. The software might also fail to report viruses when your computer is infected. Inversely, sometimes, when you download rogue security software, it will install a virus or other malicious software on your computer so that the software has something to detect.
Some rogue security software might also:
  • Lure you into a fraudulent transaction (for example, upgrading to a non-existent paid version of a program).
  • Use social engineering to steal your personal information.
  • Install malware that can go undetected as it steals your data.
  • Launch pop-up windows with false or misleading alerts.
  • Slow your computer or corrupt files.
  • Disable Windows updates or disable updates to legitimate antivirus software.
  • Prevent you from visiting antivirus vendor websites.
Rogue security software might also attempt to spoof the Microsoft security update process. Here's an example of rogue security software that's disguised as a Microsoft alert but that doesn't come from Microsoft.

Example of a warning from a rogue security program known as AntivirusXP.
For more information about this threat, including analysis, prevention and recovery, see the Trojan:Win32/Antivirusxp entry in the Microsoft Malware Protection Center encyclopedia.
Here is the legitimate Microsoft Windows Security Center:
Screenshot of legitimate Microsoft Windows Security Center
Screenshot of legitimate Microsoft Windows Security Center.

To help protect yourself from rogue security software:

  • Install a firewall and keep it turned on.
  • Use automatic updating to keep your operating system and software up to date.
  • Install antivirus and antispyware software such as Microsoft Security Essentials and keep it updated. For links to other antivirus programs that work with Microsoft, see Microsoft Help and Support List of Antivirus Vendors.
  • If your antivirus software does not include antispyware software, you should install a separate antispyware program such asWindows Defender and keep it updated. (Windows Defender is available as a free download for Windows XP and is included in Windows Vista.)
  • Use caution when you click links in email or on social networking websites.
  • Use a standard user account instead of an administrator account.
  • Familiarize yourself with common phishing scams.

If you think you might have rogue security software on your computer:

Scan your computer. Use your antivirus software or do a free scan with the Microsoft Safety Scanner. The safety scanner checks for and removes viruses, eliminates junk on your hard drive, and improves your PC's performance.
Get help from a Microsoft partner. If you have trouble removing the software yourself, you can enter your zip code to find experts in your area

Thursday, 15 December 2011

Facebook virus alert


Facebook virus alert: Worm hidden in image of two blondes

By  | November 29, 2011, 1:55pm PST
Summary: A new worm is spreading on Facebook: once downloaded, it tempts the user into opening it by masquerading as a screensaver with a thumbnail image of two blonde women.
A new piece of malware is spreading across Facebook by leveraging either stolen account credentials or possibly a rogue app. This one is a worm that is being shared via malicious links on the social network, according to the Danish website CSIS, which listed the following domains as sources for the malware:
vinamost.net
ferry.coza
maximilian-adam.com
bacolodhouseandlot.com
servi ceuwant.com
centralimoveisbonitoms.com.br
weread.in.th
villamatildabb.com
fionagh-bennet-music.co.uk
ukseikatsu.com
bzoe-salzkammergut.at
delicescolres.com
dekieviten.nl
If one of your Facebook friends has had his or her account compromised, you may be tempted to click on a link seemingly posted by them. What appears to be a screensaver, with a thumbnail image of two blonde women, will be downloaded onto your computer.
This is in fact a worm: do not download it and do not open it. If you think you have been affected, please read Facebook virus or account hacked? Here’s how to fix it.
When the file is opened, it attempts to download further malware, including a popular Trojan called Zeus. This type of malware can take over your computer and/or attempt to steal your banking information.
The malware’s code is written in Visual Basic 6.0 and includes ways of tricking users on virtual machines. The source appears to be a compromised Israeli website, which is no longer hosting the file in question. Still, hackers can always use additional websites to continue spreading their malware.
As a general word of caution, don’t click on everything your Facebook friends share on the social network. I have contacted Facebook to learn if it has blocked any unusual activity related to this latest worm and if it has any more information to offer.
Update: “Almost all of the domains listed in the article were already blocked by our mitigation efforts, however, we are constantly monitoring the situation and are in the process of blocking domains as we discovered them,” a Facebook spokesperson said in a statement. “We have internal systems in place configured specifically to monitor for variations of the spam and are working with others across the industry to pursue both technical and legal avenues to fight the bug.

Patch Tuesday December 2011


Patch Tuesday December 2011

Kurt Baumgartner
Kaspersky Lab Expert
Posted December 14, 13:10  GMT
Tags: Microsoft WindowsMicrosoft Internet ExplorerMicrosoft,Vulnerabilities and exploits
0.4
 

Microsoft finishes out this year of patching with a heavy release that's all over place. While techs were notified of an anticipated 14 bulletins, 13 were released for the month of December. Headline grabbing events and code are addressed in one of them, and while fewer are labelled "Critical", are they any less important?
Many speculative bits have been spilled on the group behind Stuxnet and its precursor Duqu, with our own researchers posting at least a half dozen Securelist writeups on Duqu findings alone. MS11-087 patches up the delivery vector for Duqu itself. This kernel mode vulnerability was publicly identified and confirmed at the beginning of November, but could well have been used quietly in attacks around the world for a year or more.
The targeted functionality provides TrueType font parsing capabilities for the OS, and the group abused these components by delivering exploits in the form of Word Documents attached to emails interesting to their individual victims, a technique known as spear-phishing. The flawed code has been known to impact only a very select set of systems throughout the world.
The other headline grabbing event and code that was anticipated to be released is known as the SSL BEAST vulnerability. We covered the potential hysteria surrounding the Ekoparty conference demo in Argentina a couple of months ago, where a researcher demonstrated SSL being cracked on a Windows system. There were no public reports whatsoever of this flaw being attacked, and Microsoft is delaying its release to ensure that its browser cannot be hacked in this way without compatibility issues, following the lead of Google Chrome and Firefox.
A slew of other patches were released this time around, with Internet Explorer, Powerpoint, and other components, including the Chinese font producing Pinyin IME component, all being updated. It's interesting that even Microsoft considers exploit code likely to be published for at least a dozen of them, but does not consider many of them critical for admins to patch. One that stands out as a candidate for "Critical" in my book is the Active Directory problem. Organizations that have been under persistent targeted attacks may consider this one to be very urgent, with Domain Controllers and Active Directory of high interest to their adversaries in past attacks.