Language Selection

English French German Italian Portuguese Spanish

Microsoft

Proprietary and Openwashing: Facebook. Skype, LinkedIn, Talend, and Slack

Filed under
Microsoft

Angelfire

Filed under
Microsoft
Security

Today, August 31st 2017, WikiLeaks publishes documents from the Angelfire project of the CIA. Angelfire is an implant comprised of five components: Solartime, Wolfcreek, Keystone (previously MagicWand), BadMFS, and the Windows Transitory File system. Like previously published CIA projects (Grasshopper and AfterMidnight) in the Vault7 series, it is a persistent framework that can load and execute custom implants on target computers running the Microsoft Windows operating system (XP or Win7).

Solartime modifies the partition boot sector so that when Windows loads boot time device drivers, it also loads and executes the Wolfcreek implant, that once executed, can load and run other Angelfire implants. According to the documents, the loading of additional implants creates memory leaks that can be possibly detected on infected machines.

Keystone is part of the Wolfcreek implant and responsible for starting malicious user applications. Loaded implants never touch the file system, so there is very little forensic evidence that the process was ever ran. It always disguises as "C:\Windows\system32\svchost.exe" and can thus be detected in the Windows task manager, if the operating system is installed on another partition or in a different path.

BadMFS is a library that implements a covert file system that is created at the end of the active partition (or in a file on disk in later versions). It is used to store all drivers and implants that Wolfcreek will start. All files are both encrypted and obfuscated to avoid string or PE header scanning. Some versions of BadMFS can be detected because the reference to the covert file system is stored in a file named "zf".

The Windows Transitory File system is the new method of installing AngelFire. Rather than lay independent components on disk, the system allows an operator to create transitory files for specific actions including installation, adding files to AngelFire, removing files from AngelFire, etc. Transitory files are added to the 'UserInstallApp'.

Read more

Bugs? What bugs? Microsoft sees no evil.

Filed under
Microsoft

On Aug. 23, Microsoft released Windows 10 Fall Creators Update Build 16273. This late beta doesn’t introduce new features. It’s all about stabilizing the next Windows 10 update before releasing it to the public. In short, it’s a bug-fix version — with a twist. While Microsoft tells us which bugs have been fixed in this build, it doesn’t say anything about new bugs, or old bugs that haven’t been fixed.

Read more

Microsoft Openwashing of Visual Studio and LinkedIn

Filed under
Microsoft

Desktop: Entroware's New GNU/Linux Laptop, Microsoft Caught Red-handed

Filed under
GNU
Linux
Microsoft

Openwashing: Oracle, Mono, Microsoft and Red Hat

Filed under
Microsoft
  • Oracle Open Source Library now available to C and C++ developers [Ed: openwashing of a link to Oracle's proprietary lockin]

    The production release of the Oracle Database Programming Interface for C (ODPI-C), which gives more streamlined access to C and C++ developers to Oracle Database, has been launched on GitHub.

    The open-source wrapper is aimed primarily at language interface developers, allowing users to quickly call more common features of the Oracle Call Interface (OCI), the main C API for Oracle Database. But the company says that its conciseness makes it a flexible and accessible tool.

  • Mono 5.2 Released With Various Changes [Ed: Microsoft lockin painted as "open"]
  • Microsoft's .NET Core 2.0: What's new and why it matters
  • Microsoft Launches .NET Core 2.0 With Better Linux Support
  • Tips for finding partners open enough to work with you

    Imagine I'm working on the front line of an open organization, and I'm committed to following principles like transparency, inclusivity, adaptability, collaboration, community, accountability, and commitment to guide that front-line work. A huge problem comes up. My fellow front-line workers and I can't handle it on our own, so we discuss the problem and decide that one of us has to take it to top management. I'm selected to do that.

    When I do, I learn there is nothing we can do about the problem within the company. So management decides to let me present the issue to outside individuals who can help us.

    In my search for the expertise required to fix the problem, I learned that no single individual has that expertise—and that we must find an outside, skilled partner (company) to help us address the issue.

Slackware Security and Windows Insecurity

Filed under
Microsoft
Security
Slack
  • OpenJDK7 and Flash Player security updates (Aug ’17)

    On the blog of IcedTea release manager Andrew Hughes (aka GNU/Andrew) you can find the announcement for IcedTea 2.6.11 which builds OpenJDK 7u151_b01. This release includes the official July 2017 security fixes for Java 7. Note that the security updates for Java 8 were already pushed to my repository some time ago.

  • Kremlin's hackers 'wield stolen NSA exploit to spy on hotel guests in Europe, Mid East'

    Miscreants are using various techniques, including the leaked NSA EternalBlue exploit also wielded by the WannaCry malware, to hack into laptops and other devices used by government and business travelers, FireEye researchers declared on Friday.

Microsoft Hardware Woes

Filed under
Hardware
Microsoft

Dumbo

Filed under
Microsoft
Security

Today, August 3rd 2017 WikiLeaks publishes documents from the Dumbo project of the CIA. Dumbo is a capability to suspend processes utilizing webcams and corrupt any video recordings that could compromise a PAG deployment. The PAG (Physical Access Group) is a special branch within the CCI (Center for Cyber Intelligence); its task is to gain and exploit physical access to target computers in CIA field operations.

Dumbo can identify, control and manipulate monitoring and detection systems on a target computer running the Microsoft Windows operating sytem. It identifies installed devices like webcams and microphones, either locally or connected by wireless (Bluetooth, WiFi) or wired networks. All processes related to the detected devices (usually recording, monitoring or detection of video/audio/network streams) are also identified and can be stopped by the operator. By deleting or manipulating recordings the operator is aided in creating fake or destroying actual evidence of the intrusion operation.

Dumbo is run by the field agent directly from an USB stick; it requires administrator privileges to perform its task. It supports 32bit Windows XP, Windows Vista, and newer versions of Windows operating system. 64bit Windows XP, or Windows versions prior to XP are not supported.

Read more

Syndicate content

More in Tux Machines

Qt/KDE: Qt5 in Debian and Slackware, QtCreator on Android, KDE Discover, and Plasma's 10th Anniversary

  • moving Qt 4 from Debian testing (aka Buster): some statistics, update II
    We started filing bugs around September 9. That means roughly 32 weeks which gives us around 5.65 packages fixed per week, aka 0.85 packages per day. Obviously not as good as we started (remaining bugs tend to be more complicated), but still quite good.
  • [Slackware] Plasma5 – April 18 edition for Slackware
    The KDE-5_18.04 release of ‘ktown‘ for Slackware-current offers the latest KDE Frameworks (5.45.0), Plasma (5.12.4) and Applications (18.04.0). The Qt5 was upgraded to 5.9.5. Read the README file for more details and for installation/upgrade instructions. Enjoy the latest Plasma 5 desktop environment.
  • Perfect Debugging Experience with QtCreator on Android
    While I was working on a yet-to-be-announced super secret and cool Qt on Android project, I had to do a lot of debugging. This way I found that debugging Qt apps on Android using QtCreator was ok, but it had some issues, which was kinda frustrating.
  • Discover – Easily Install Software on KDE Neon Desktop
    KDE Discover is an Open Source GUI app installer that comes packaged with KDE Neon. It was particularly built from the ground up to be compatible with other modern Linux distros with emphasis on beauty and convenience. KDE Discover was also designed to allow for an intuitive User Experience as it features a clean and clear layout with a high readability value which makes it easy to browse, search for, install, and uninstall applications.
  • Almost 10 years of Plasma-Desktop
    Last week I was at work and start to listen my boss said: “We need to show this to our director”. So I went to my coworker table to see what was happening. So they were using Gource to make a video about the git history of the project. Gource is a software version control visualization tool. So that triggered in my mind some memories about a friend talking about Python and showing how the project as grow in this past years, but I never discovered about the tool that made that amazing video. So well, I started to make some Gource videos, and because my love about KDE Community, why not make one about it?

GNOME: Getting Real GNOME Back in Ubuntu 18.04, Bug Fix for Memory Leak

  • Getting Real GNOME Back in Ubuntu 18.04 [Quick Tip]
    Ubuntu 18.04 uses a customized version of GNOME and GNOME users might not like those changes. This tutorial shows you how to install vanilla GNOME on Ubuntu 18.04. One of the main new features of Ubuntu 18.04 is the customized GNOME desktop. Ubuntu has done some tweaking on GNOME desktop to make it look similar to its Unity desktop. So you get minimize options in the windows control, a Unity like launcher on the left of the screen, app indicator support among some other changes.
  • The Infamous GNOME Shell Memory Leak
    at this point, I think it’s safe to assume that many of you already heard of a memory leak that was plaguing GNOME Shell. Well, as of yesterday, the two GitLab’s MRs that help fixing that issue were merged, and will be available in the next GNOME version. The fixes are being considered for backporting to GNOME 3.28 – after making sure they work as expected and don’t break your computer.
  • The Big GNOME Shell Memory Leak Has Been Plugged, Might Be Backported To 3.28
    The widely talked about "GNOME Shell memory leak" causing excessive memory usage after a while with recent versions of GNOME has now been fully corrected. The changes are currently staged in Git for what will become GNOME 3.30 but might also be backported to 3.28. Well known GNOME developer Georges Stavracas has provided an update on the matter and confirmed that the issue stems from GJS - the GNOME JavaScript component - with the garbage collection process not being fired off as it should.

Graphics: AMDVLK, XWayland and Vulkan

  • AMDVLK Vulkan Driver Stack Gets Updated With More Extensions, Optimizations & Fixes
    AMD developers maintaining their official Vulkan cross-platform driver code have pushed their end-of-week updates to their external source repositories for those wanting to build the AMDVLK driver on Linux from source. This latest AMDVLK push updates not only their PAL (Platform Abstraction Layer) and XGL (Vulkan API Layer) components but it also updates their fork of the LLVM code-base used for their shader compilation.
  • EGLStreams XWayland Code Revised Ahead Of X.Org Server 1.20
    It's still not clear if the EGLStreams XWayland support will be merged for xorg-server 1.20 but at least the patches were revised this week, making it possible to merge them into this next X.Org Server release for allowing the NVIDIA proprietary driver to work with XWayland.
  • Vulkan 1.1.74 Released With Minor Fixes & Clarifications
    Vulkan continues sticking to the "release early, release often" mantra with the availability today of Vulkan 1.1.74.

Xfce Releases/Updates

  • Xfce Settings 4.12.3 / 4.13.2 Released
    Fixes galore! Xfce Settings 4.12.3 and 4.13.2 were released on March 18th with several improvements, feature parity, and translations.
  • Xfce PulseAudio Plugin 0.4.0 (and 0.4.1) Released
    Stable as a rock. Xfce PulseAudio Plugin hit a new stable milestone with the 0.4.0 release. This release wraps up the awesome development cycle we’ve had on this over the last few months and is recommended for all users.
  • Xfce Settings Update Brings Better Multi-Monitor Support
    While still waiting on the long-awaited Xfce 4.14, out this weekend is an Xfce Settings 4.14.2 preview release as well as an Xfce Settings 4.12.3 stable series update. Both of these Xfce Settings updates bring better multi-monitor support, including visualization of all display configuration states, visually noting if two displays are mirrored, always drawing the active display last so it's on top, and a number of fixes pertaining to the multi-monitor display handling from this Xfce desktop settings agent.