Language Selection

English French German Italian Portuguese Spanish

Security

Security Leftovers

Filed under
Security
  • 66% of USB Flash Drives infected – don’t trust a stray [Ed: Windows]

    The problem is that the OS will automatically run a program that can install malware from a USB stick.

  • Dental Assn Mails Malware to Members

    The domain is used by crooks to infect visitors with malware that lets the attackers gain full control of the infected Windows computer.

  • Slack bot token leakage exposing business critical information

    Developers are leaking access tokens for Slack widely on GitHub, in public repositories, support tickets and public gists. They are extremely easy to find due to their structure. It is clear that the knowledge about what these tokens can be used for with malicious intent is not on top of people’s minds…yet. The Detectify team shows the impact, with examples, and explains how this could be prevented.

Security Leftovers

Filed under
Security
  • Friday's security updates
  • Hacking Slack accounts: As easy as searching GitHub

    A surprisingly large number of developers are posting their Slack login credentials to GitHub and other public websites, a practice that in many cases allows anyone to surreptitiously eavesdrop on their conversations and download proprietary data exchanged over the chat service.

    According to a blog post published Thursday, company researchers recently estimated that about 1,500 access tokens were publicly available, some belonging to people who worked for Fortune 500 companies, payment providers, Internet service providers, and health care providers. The researchers privately reported their findings to Slack, and the chat service said it regularly monitors public sites for posts that publish the sensitive tokens.

  • Time for a patch: six vulns fixed in NTP daemon
  • NTP Daemon Gets Fixes for Vulnerabilities Causing DoS and Authentication Bypass
  • Cisco Spots New NTP Bugs
  • Network Time Keeps on Ticking with Long-Running NTP Project [Ed: corrected URL]
  • Open Source Milagro Project Aims to Fix Web Security for Cloud, Mobile, IoT

    As the Internet continues to both grow in size and widen in scope, so do demands on the supporting infrastructure. The number of users and devices, amount of activity, internationalization of the web, and new devices that range from mobile apps and cloud instances to "Internet of Things," put strain on the system. Not just for bandwidth or service availability, but also on the assurance of trust -- trust that the entities at each end are who (or what) they say they are, and that their communications are private and secure.

  • M2Mi Obtains DHS Open-Source Cryptographic Tool Development Funds

    Machine-to-Machine Intelligence Corp. has been awarded $75,000 in funds by the Department of Homeland Security‘s science and technology directorate to create a deployable cryptographic protocol for an Internet of Things security initiative.

  • Encrypted Network Traffic Comes at a Cost

    The use of encryption over the Internet is growing. Fueled by Edward Snowden's revelations on the extent of NSA and GCHQ content monitoring, encryption is now increasingly provided by the big tech companies as part of their standard product offerings. It's effectiveness can be seen in the continuing demands by different governments for these same tech companies to provide government backdoors for that encryption. Encryption works: it safeguards privacy.

    Against this background, the use of Secure Sockets Layer (SSL) or Transport Layer Security (TLS) to encrypt network traffic is likely to grow dramatically. Google is encouraging this. It already uses HTTPS as a positive weight for web sites in its search algorithm, while current rumors suggest it will soon start to place a warning red X in the URL bar of sites that do not use it. Taken together, these are strong incentives for businesses that don't currently use SSL/TLS to start doing so. Some predictions believe that almost 70% of network traffic will be encrypted by the end of this year.

  • Raptor Engineering Updates Details On Their POWER8-Based Talos Secure Workstation

    Raptor Engineering has published new information around their proposed high-performance Talos Secure Workstation that for around $3k is a high-end POWER8 motherboard.

Security Leftovers

Filed under
Security
  • The road to hell is paved with SAML Assertions

    A vulnerability in Microsoft Office 365 SAML Service Provider implementation allowed for cross domain authentication bypass affecting all federated domains. An attacker exploiting this vulnerability could gain unrestricted access to a victim's Office 365 account, including access to their email, files stored in OneDrive etc.

  • Cisco Finds Backdoor Installed on 12 Million PCs

    Cisco started analyzing Tuto4PC’s OneSoftPerDay application after its systems detected an increase in “Generic Trojans” (i.e. threats not associate with any known family). An investigation uncovered roughly 7,000 unique samples with names containing the string “Wizz,” including “Wizzupdater.exe,” “Wizzremote.exe” and “WizzInstaller.exe.” The string also showed up in some of the domains the samples had been communicating with.

  • The "Wizzards" of Adware [Ed: unsurprisingly Windows]
  • All About Fraud: How Crooks Get the CVV

    A longtime reader recently asked: “How do online fraudsters get the 3-digit card verification value (CVV or CVV2) code printed on the back of customer cards if merchants are forbidden from storing this information? The answer: If not via phishing, probably by installing a Web-based keylogger at an online merchant so that all data that customers submit to the site is copied and sent to the attacker’s server.

  • Why We Should Be Worried About Ancient Viruses Infecting Power Plants [Ed: unsurprisingly Windows again]

    The reasons these patients are vulnerable to viruses like W32.Ramnit and Conficker is because they run legacy systems that haven’t been patched or updated for a decade. And that’s fine as long as the operators of the plant keep them isolated and assume they are insecure, hopefully keeping the more critical parts of the network away safer.

  • Magical Thinking in Internet Security

    Increased complexity without corresponding increases in understanding would be a net loss to a buyer. At scale, it's been a net loss to the world economy.

  • Edward Snowden: The Internet Is Broken

    In 2013, a now-infamous government contractor named Edward Snowden shined a stark light on our vulnerable communications infrastructure by leaking 10,000 classified U.S. documents to the world.

    One by one, they detailed a mass surveillance program in which the National Security Administration and others gathered information on citizens — via phone tracking and tapping undersea Internet cables.

    Three years after igniting a controversy over personal privacy, public security, and online rights that he is still very much a part of, Snowden spoke with Popular Science in December 2015 and shared his thoughts on what's still wrong and how to fix it.

Security Leftovers

Filed under
Security

Security Leftovers

Filed under
Security
  • Security advisories for Wednesday
  • German nuclear plant infected with computer viruses, operator says

    A nuclear power plant in Germany has been found to be infected with computer viruses, but they appear not to have posed a threat to the facility's operations because it is isolated from the Internet, the station's operator said on Tuesday.

    The Gundremmingen plant, located about 120 km (75 miles) northwest of Munich, is run by the German utility RWE (RWEG.DE).

    The viruses, which include "W32.Ramnit" and "Conficker", were discovered at Gundremmingen's B unit in a computer system retrofitted in 2008 with data visualization software associated with equipment for moving nuclear fuel rods, RWE said.

    Malware was also found on 18 removable data drives, mainly USB sticks, in office computers maintained separately from the plant's operating systems. RWE said it had increased cyber-security measures as a result.

  • Death of the enterprise VPN - if remote access is not secure what comes next? [iophk: "Spam. Besides, if an app cannot be put on the net without a VPN then it does not belong on the net in the first place."]

    VPNs are the backbone of enterprise remote access and yet their security limitations are starting to pile up. The problem is that the very thing that once made them so useful, network access, is now their biggest weakness. As the 2014 attacks on retailers Target and Home Depot painfully illustrate, this architecture can easily be exploited by attackers armed with stolen credentials to move around networks from within in ways that are difficult to spot until it’s too late.

GNOME Software Bug Doesn't Let Ubuntu 16.04 LTS Users Install Third-Party Debs

Filed under
GNOME
Security
Ubuntu

We've been tipped earlier by one of our readers that there's a bug in the GNOME Software (Ubuntu Software) package manager which doesn't let users install third-party .deb files in Ubuntu 16.04 LTS.

Read more

Security Leftovers

Filed under
Security

Security support for Wheezy handed over to the LTS team

Filed under
Security
Debian

As of 25 April, one year after the release of Debian 8, alias "Jessie", and nearly three years after the release of Debian 7, alias "Wheezy", regular security support for Wheezy comes to an end. The Debian Long Term Support (LTS) Team will take over security support.

Read more

Also: Debian GNU/Linux 7 "Wheezy" Has Become an LTS Release, Supported Until May 2018

Security Leftovers

Filed under
Security

Security Leftovers

Filed under
Security
  • Friday's security updates
  • Why I gave your paper a Strong Reject

    Writing a bunch of wordy bullshit that doesn't mean anything. Trust me, you're not going to wow and amaze the program committee by talking about dynamic, scalable, context-aware, Pareto-optimal middleware for cloud hosting of sensing-intensive distributed vehicular applications. If your writing sounds like the automatically-generated, fake Rooter paper ("A theoretical grand challenge in theory is the important unification of virtual machines and real-time theory. To what extent can web browsers be constructed to achieve this purpose?"), you might want to rethink your approach. Be concise and concrete. Explain what you're doing in clear terms. Bad ideas won't get accepted just because they sound fancy.

  • Computer System Security Policy Debate (Follow-up)

    The challenge is that political people see everything as a political/policy issue, but this isn’t that kind of issue. I get particularly frustrated when I read ignorant ramblings like this that dismiss the overwhelming consensus of the people that actually understand what needs to be done as emotional, hysterical obstructionism. Contrary to what seems to be that author’s point, constructive dialogue and understanding values does nothing to change the technical risks of mandating exceptional access. Of course the opponents of Feinstein-Burr decry it as technologically illiterate, it is technologically illiterate.

Syndicate content

More in Tux Machines

ownCloud Desktop Client 2.2.4 Released with Updated Dolphin Plugin, Bug Fixes

ownCloud is still alive and kicking, and they've recently released a new maintenance update of the ownCloud Desktop Client, version 2.2.4, bringing some much-needed improvements and patching various annoying issues. Read more

Early Benchmarks Of The Linux 4.9 DRM-Next Radeon/AMDGPU Drivers

While Linux 4.9 will not officially open for development until next week, the DRM-Next code is ready to roll with all major feature work having been committed by the different open-source Direct Rendering Manager drivers. In this article is some preliminary testing of this DRM-Next code as of 29 September when testing various AMD GPUs with the Radeon and AMDGPU DRM drivers. Linux 4.9 does bring compile-time-offered experimental support for the AMD Southern Islands GCN 1.0 hardware on AMDGPU, but that isn't the focus of this article. A follow-up comparison is being done with GCN 1.0/1.1 experimental support enabled to see the Radeon vs. AMDGPU performance difference on that hardware. For today's testing was a Radeon R7 370 to look at the Radeon DRM performance and for AMDGPU testing was the Radeon R9 285, R9 Fury, and RX 480. Benchmarks were done from the Linux 4.8 Git and Linux DRM-Next kernels as of 29 September. Read more

How to Effectively and Efficiently Edit Configuration Files in Linux

Every Linux administrator has to eventually (and manually) edit a configuration file. Whether you are setting up a web server, configuring a service to connect to a database, tweaking a bash script, or troubleshooting a network connection, you cannot avoid a dive deep into the heart of one or more configuration files. To some, the prospect of manually editing configuration files is akin to a nightmare. Wading through what seems like countless lines of options and comments can put you on the fast track for hair and sanity loss. Which, of course, isn’t true. In fact, most Linux administrators enjoy a good debugging or configuration challenge. Sifting through the minutiae of how a server or software functions is a great way to pass time. But this process doesn’t have to be an exercise in ineffective inefficiency. In fact, tools are available to you that go a very long way to make the editing of config files much, much easier. I’m going to introduce you to a few such tools, to ease some of the burden of your Linux admin duties. I’ll first discuss the command-line tools that are invaluable to the task of making configuration more efficient. Read more

Why Good Linux Sysadmins Use Markdown

The Markdown markup language is perfect for writing system administrator documentation: it is lightweight, versatile, and easy to learn, so you spend your time writing instead of fighting with formatting. The life of a Linux system administrator is complex and varied, and you know that documenting your work is a big time-saver. A documentation web server shared by you and your colleagues is a wonderful productivity tool. Most of us know simple HTML, and can whack up a web page as easily as writing plain text. But using Markdown is better. Read more