Pages

Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Tuesday, February 14, 2012

SSL Traffic Analysis Reveals What You Are Looking At On Google Maps

The general consensus is that https connections to web sites protect your data from being spied at by users in the same network. That’s why all major web services such as Facebook, Twitter or Google have started to enforce the use of https on their websites.

Most users do not know that it may still be possible to find out what a user is looking at on a specific website, even if https is enabled.

Shuo Chen, Rui Wang, XiaoFeng Wang, and Kehuan Zhang of Microsoft research released a paper titled Side-Channel Leaks in Web Applications: a Reality Today, a Challenge Tomorrow back in 2010 that mentioned this threat to user privacy.

Vincent Berg a few days ago published a proof of concept demonstration (in form of a video) on the IOActive Labs Research that showed how Google Maps was vulnerable to SSL Traffic Analysis.

He first analyzed the JavaScript used by Google Maps using Firefox and the excellent Firebug extension to discover that google Maps was using “a grid system in which PNG images are laid out”. These PNG images had different file sizes which were added to a database.

Vincent Berg then built a tool that was able to approximate the sizes of images by monitoring the encrypted traffic. The software then tried to match the estimated size with the size in the database to find a matching region in the world. Several city profiles were created, as it was not realistically possible to create database information for all map tiles.

The video below demonstrates the workings of the tool on the right side, and the user actions on Google Maps on the left. It basically shows how both Paris and Berlin were identified correctly by the program.

Not all web applications can by analyzed with SSL Traffic Analysis, but those that do can pose a privacy and maybe even security risk for users thinking they are safe since they are connecting to the service via https.

Users could protect their connection by connecting to an encrypted virtual private network like VyprVPN. Even that may however be prone to analysis according to the author of the blog post.



Wednesday, February 8, 2012

Symantec’s pcAnywhere Source Code Published

Back in 2006 hackers managed to download source codes of Symantec software after successfully gaining access to Symantec’s infrastructure. The hackers managed to obtain Norton Antivirus Corporate Edition, Norton Utilities, Norton GoBack, pcAnywhere and Norton Internet Security source codes during the operation.

The incident came to light only recently, when hackers started to upload code sneak peeks and information to the Internet.

Symantec by then asked users of pcAnywhere to stop using the software to analyze and mitigate any arising risks. Symantec later on released a security recommendations whitepaper that described possible risk scenarios.

  • The encoding and encryption elements within pcAnywhere are vulnerable, making users susceptible to man-in-the-middle attacks, depending on the configuration and use of the product. If a man-in-the-middle attack should occur, the malicious user could steal session data or credentials.
  • A secondary risk: If a malicious user obtains the cryptographic key, they can launch unauthorized remote control sessions and thus access systems and sensitive data.
  • If the cryptographic key itself is using Active Directory credentials, it is also possible for attackers to perpetrate other malicious activities on the network.
  • In an internal pcAnywhere environment, if a network sniffer was in place on a customer’s internal network and the attacker had access to the encryption details, the pcAnywhere traffic could be intercepted and decoded. This implies that a customer either has a malicious insider who planted the network sniffer or has an unknown Botnet operating in their environment. As always, security best practices are encouraged to mitigate this risk.
  • Since pcAnywhere exchanges user login credentials, the risk exists that a network sniffer or Botnet could intercept this exchange of information, though it would still be difficult to actually interpret the data even if the pcAnywhere source code is released.
  • For environments with remote users, this credential exchange introduces an additional level of exposure to external attacks.

These information where later removed from the whitepaper after a patch had been issued.

The hackers in the meantime have released email correspondence on PasteBin. Here it gets a bit blurry as both sides apparently tried to broker a deal that would prevent the source codes from being released to the public. According to Symantec, it was a sting operation from the very beginning. The hackers on the other hand stated that they tried to “humiliate them” further.

A torrent of the source code has since then been released on the popular Bittorrent indexing site The Piratebay where it quickly climbed into the top 5 seeded files of the Misc category.

symantec pc anywhere source code

The hackers have already announced that they will also release the Norton Antivirus source code.

Should Norton and Symantec customers be worried about the source code release? Symantec stated that user’s who have upgraded the products to the latest version have nothing to worry about.



Saturday, January 21, 2012

Web Hoster Dreamhost Hacked, Asks Users To Change Passwords

After a relatively quite holiday period attacks on popular services on the Internet seem to have picked up again. After the Zappos incident a few days ago, it is now the popular web hoster Dreamhost who noticed unauthorized activity within one of the company’s databases. Dreamhost is not going into further detail but mentions that they do not have evidence that customer login information or passwords have been dumped by the attackers.

The company nevertheless decided to reset all FTP and shell user access passwords for all Dreamhost users. This should not be confused with the account password used to log into the Dreamhost site itself though. Dreamhost customers who are using the same passwords for multiple services should change passwords on all of them to eliminate the possibility of unauthorized access to those accounts.

Dreamhost furthermore notes that users should also be changing email passwords of all Dreamhost managed email addresses as soon as possible.

dreamhost

We have been sending out update emails to every account owner we have, letting them know what happened, and how to proceed from here on out. As a precaution, we advise every user to change all email passwords as well. We are not forcing this change, however, so make sure you take care of that ASAP.

Shell and ftp passwords can be changed in the Manage Users interface which is accessible here. Dreamhost customers need to click on the edit button next to the ftp or shell user to change the log in password for that account.

A company representative noted that neither credit card data nor web panel logins were accessed by the attackers. If you read through all of the 270 or so comments on the Dreamhost blog, you will notice that many customers were quite infuriated about the level of information they received. Web panel access was not available at all times due to users trying to change their passwords, and rumors spread that Dreamhost was storing passwords in plain text (which was later refuted by a Dreamhost employee who stated that they were hashed).

Lets take a look at what Dreamhost customers need to do right now:

  • Log into the web panel and change FTP, SFTP, MYSQL, Email and other account passwords. Some passwords have been reset automatically by Dreamhost which means that they need to be changed anyway to regain access.
  • Change passwords on other accounts if the same password was used for access.

Passwords with a reasonable length should be safe, but it is nevertheless better to make the changes to be certain that the attackers cannot use successfully decrypted passwords to gain account or service access. A password manager like KeePass can aid in the creation of secure passwords.

Are you a Dreamhost customer? If so, when did you receive notification about the security incident and what did you experience afterwards?



Monday, January 16, 2012

Zappos Hacked, Security Email Asks Users To Change Passwords

Zappos yesterday notified all of their employees and customers that a company server has been compromised. The email, accessible online only for visitors from the US, indicates that the attackers may have gotten hold of part or all of the customer account database of Zappos.com. Information that may have been retrieved by the attacker include customer names, email addresses, billing and shipping addresses, phone numbers, the last four digits of the credit card number and encrypted passwords.

Tony Hsie, Zappos’ CEO, notes that the credit card and payment database has not been affected or accessed by the attacker.

While not in immediate danger, customers are asked to change their account passwords at the next possible moment to protect their accounts from unauthorized access. If the attackers managed to dump the account username and password, they have likely started to decrypt the passwords with the help of dictionary lists and brute forcing. The attackers cannot use the information directly on the Zappos site though, as passwords have been reset by the company. Customers are asked to create a new password by “clicking on the “Create a New Password” link in the upper right corner of the web site and follow the steps from there”. It is alternatively possible to open the Password Change page right away on the website which leads to the create a new password page.

zappos

Zappos notes that users should change passwords on other websites if they have used the same password for accounts on those sites. If the attackers manage to decrypt the passwords, they could try to log into email accounts or other popular web services.

We also recommend that you change your password on any other web site where you use the same or a similar password. As always, please remember that Zappos.com will never ask you for personal or account information in an e-mail. Please exercise caution if you receive any emails or phone calls that ask for personal information or direct you to a web site where you are asked to provide personal information.

Resetting more than 24 million customer passwords must have not been an easy decision for the company CEO. Other hacked companies have reacted differently in the past, for instance by only emailing their customers about the breach and asking them in the email to change their account passwords. The better safe than sorry approach seems to be better suited for these kind of situations. What’s your take on the news, and do you think that Zappos made the right move?



Monday, November 28, 2011

Researchers Successfully Hack HDCP High-Def Copy Protection

Ever since the Blu-Ray video format was first announced, it has been claimed that the copy-protection on the system was uncrackable.  This is because is uses technology in your HDMI port to determine the authenticity of the video source.  Without this technology built into the port’s circuitry Blu-Ray video simply won’t work, which caused problems with some early HDMI-equipped computer monitors.

Even when the HDCP (High bandwidth Digital Content Protection) master key, which is a core element of the encrytion, was leaked last year the standard has still not been cracked because using it to build an decryption chip is very difficult and costly.

Any technology saying something is uncrackable however is just an invitation for most people to try, and not professor Tim Güneysu and Benno Lomb, a PhD student from the Ruhr University in Germany have used a “man in the middle” approach to crack the encryption for just $350.

Instead of designing and creating an HDCP-capable chip, the two men built a standalone hardware solution that is based on an inexpensive FPGA (Field Programmable Gate Array) board that contains an HDMI port and an RS232 Serial port.  These boards are programmable and designed to be configured by the user.

The purpose of the research was not to crack the HDCP encryption they said.

“Our intention was rather to investigate the fundamental security of HDCP systems and to measure the actual financial outlay for a complete knockout. The fact that we were able to achieve this in the context of a PhD thesis and using materials costing just €200 is not a ringing endorsement of the security of the current HDCP system”

The board modifies all the communications between the Blu-Ray player and a flat screen TV without the interruption being detected.  This is something that some set-top-boxes are already able to do and some boxes that can remove HDCP data from HD video have been available since shortly after the HDMI standard was introduced.  These boxes allow otherwise encrypted high-definition content that is broadcast to be compressed and recorded to disc or a hard drive.

At the moment pirates are using these boxes to copy high-definition content, admittedly in a compressed form.  But there is currently no way for them to intercept the uncompressed raw data from a Blu-Ray disc.

This solution then isn’t much use for pirates at the moment then as what would really be required is a software solution, much in the way DVD John did in 1999 when he and two friends released the DeCSS software that decrypted DVDs.  This hardware solution doesn’t offer anything that’s really useful for pirates, especially as the researchers aren’t saying how they did it.

It does prove though that with some know how and determination anything is crackable, and with a software emulated version of the hardware board a possibility in the future, encrypted Blu-Ray discs could still come under attack from pirates, not to mention the threat this poses to encrypted high-definition digital video downloads in the future.

Where this is of interest is the ease with which the researchers were able to do this and the affordability of the overall parts involved.  To claim something is uncrackable unless significant volumes of money are spent designing a new silicon chip overlooks the fact that much existing technology can emulate this process, providing anybody with full and unfettered access to unencrypted video.


© Mike Halsey (MVP) for gHacks Technology News | Latest Tech News, Software And Tutorials, 2011. | Permalink |
Add to del.icio.us, digg, facebook, reddit, twitter
Post tags: , , , ,



Friday, November 11, 2011

Steam Forum Hacked, Time To Panic?

The Steam forums were for a time not accessible a few days ago. What felt like a hardware or software issue at that time was actually more serious than this. Users who visit the Steam forums today see an announcement on the first page that informs them that the Steam forum and Steam databases have been attacked. Among the stolen information are Steam user names, encrypted passwords, game purchases, email addresses, billing addresses and even encrypted credit card information.

Valve at this point in time has no evidence that the intruders were able to crack or access credit card numbers or user passwords.

steam hacked

The forums have been taken offline for the time being until the investigation ends. Forum users will be asked to change their password the next time they log into the forums once they are accessible again.

Steam accounts do not seem to be affected according to Valve as forum accounts and Steam accounts are not identical.

Users who have a Steam forum account should do the following:

  • Change Steam account and other passwords if it is the same as the forum account password.
  • Monitor their Credit Card statements if they have ever paid by Credit Card on Steam.
  • Be aware of the possibility of targeted phishing attacks, e.g. disguising as Valve.

It is unlikely that attackers will be able to decrypt the credit card information or passwords. What they may do however is to run a dictionary of the top 1000 passwords against all user accounts to get full access to those accounts. Users who have used weak passwords for their Steam forum account need to change the password as soon as the forums come back up. They also need to make 100% sure that the password is not used for any other services, e.g. their email address or social networking sites. It is recommended to change the password on those sites and services right away to avoid further damage.


© Martin Brinkmann for gHacks Technology News | Latest Tech News, Software And Tutorials, 2011. | Permalink |
Add to del.icio.us, digg, facebook, reddit, twitter
Post tags: , , ,



Friday, October 7, 2011

HackNotifier, Check If Online Accounts Have Been Compromised

News about big hacks and the publication of user databases have slowed down considerably in past months. Before that reports of hacks were nearly daily in the news with companies like Sony, Gawker or Ashampoo the target. Many user databases that the hackers dumped during the hack were published on the Internet afterwards. Not all listed unencrypted passwords but some did and even though companies did ask users to change – all of their – online account passwords, it is likely that some users may have missed those announcements completely.

The free online service HackNotifier is more or less a frontend that users can use to search for email addresses that were leaked in hacking attempts. You basically enter your email address – or the email address of someone else into the form on the main page to see if it was listed in one of the hacked user databases.

hacknotifier

You then get to review your status on the next page. The service lets you know immediately if your account is insecure and if it has been compromised.

accounts insecure

HackNotifier lists the company that was compromised and the day it happened. A link points to third party websites that offer additional information about the hack. It then asks you to change your account passwords if you have not already done so.

Users can sign up for the company’s service to receive notifications when their email account gets hacked again. This obviously is only effective if the hackers publish the user database on the Internet. The service at the time of writing has information about 20 leaks and almost 1.5 million accounts in their database.

HackNotifier assures that they do not save email addresses that users enter on their front page to check whether the account has been compromised.

Probably the biggest issue is that most hackers do not dump user databases publicly. It can still be frightening to see your email address listed as compromised on the results page.

You can check out HackNotifier here. A similar service is Should I Change My Password.


© Martin Brinkmann for gHacks Technology News | Latest Tech News, Software And Tutorials, 2011. | Permalink |
Add to del.icio.us, digg, facebook, reddit, twitter
Post tags: , , , ,



Wednesday, October 5, 2011

How Much Is A Hacked PayPal Account Worth?

We all know that you can practically buy anything on the Internet, from bulk email accounts over credit card information and even PayPal accounts. Brian Krebs in a post on the Krebs on Security blog sheds some light on the latter. He identified websites were PayPal account data, and sometimes linked email account information, were sold in bulk.

According to his information, PayPal accounts are sold for as little as $50 per 100 unverified accounts. 50 cents per account may not seem like much, but you need to consider that unverified means that the original owner has not linked the account to a bank account or credit card. This limits what can be done with the account (while it is possible to use it to move money, it cannot be used to make purchases if the PayPal balance is not sufficient).

Verified accounts on the other hand start at prices of $2.50 for PayPal accounts with a balance of up to $10, and more if the balance is larger. You see a larger account with a balance of more than 1000 Dollars go for $45 at the site selling those hacked accounts.

hacked paypal accounts

It is rather interesting that the site not only lists the account balance, first name address and type of account but also much of the user’s email address. Registration at the site is closed and only possible by contacting a site operator over ICQ.

Considering that email addresses are listed, it would make sense of PayPal to try and get an account to block all hacked accounts before third parties can use them for illegal activities.

Brian believes that the majority of accounts for sale have been collected via phishing attacks, but that trojans on user computers have also been used considering that some of the PayPal accounts are sold with linked email account log ins.

It feels kinda strange that a site like this can operate for a relatively long time without being taken down by the authorities. I won’t link directly to the site, but you find the link and a sister site mentioned in Brian’s article.

I personally would have expected the accounts to be sold at higher prices. This can either mean that demand is not high, or that the site operators have access to a lot of hacked PayPal accounts.

What’s your take on this?


© Martin Brinkmann for gHacks Technology News | Latest Tech News, Software And Tutorials, 2011. | Permalink |
Add to del.icio.us, digg, facebook, reddit, twitter
Post tags: , , , ,