Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, 22 September 2014

Check if your Android device is affected by the vulnerability SOP

 Android deviceA quarter of users with devices Android, uses the latest Android 4.4 version. All others use older versions.

The systems have not been upgraded since the manufacturers of the devices can not provide timely updates to devices. So often created security problems. A security flaw recently discovered in Android Browser reminds us why the difficulties manufacturers provide updates is an important problem. The Android Browser is the default web browser for Android devices. This changed after the release Android 4.2 when the default browser Google Chrome.
The Google Chromium changed in the Android 4.4 and this means that whoever does not use version 4.4 is exposed to the bug.

What causes the vulnerability 
When you visit a website, you can expect to provide you with fast content. A script (script) running on the site should, for example, may not be able to modify the contents of another site. This defect is found to occur in the Android Browser.

The Same Origin Policy (SOP) (or Greek Same Origin Policy) is a safety device designed to prevent the JavaScript to be executed from a web page to another. JavaScripts running in malicious sites will not be able to recover data from "good» sites.

This is the Android Browser when the browser is used by applications that could potentially steal sensitive data. Data such as cookies can be stolen by this vulnerability.

Check your device 
To check if your device is vulnerable visit the following website and click test to find out if you are affected.

http://ejj.io/SOP.php

If you get a popup message that your browser is vulnerable, be sure to immediately change browser.

The problem 
The Google is working on a patch to correct the problem. Placing the patch but the end user will be complicated. The main reason is that these kinds of updates responsibility lies with the manufacturer of the device.

Given that support devices usually ends after two years, it is unlikely that all vulnerable devices will receive the update.

To make things even worse, the switch to another browser like Firefox or Chrome the affected devices only solves part of the problem. Although the browser is safe, the applications running on the device can still use the default browser is of course the Android Browser.

Google ads with malware! million computers with malicious software

Google ads with malware!
Google ads with malware! Yes you read that right. Yesterday evening, researchers Malwarebytes noticed a strange behavior on sites like Last.fm, The Times of Israel and the newspaper Jerusalem Post. The ads served these websites were unusually aggressive, causing warnings from anti-virus systems and Malwarebytes. 

After much research, the security researcher Jerome Segura realized that the problem stems from the ad networks of Google, DoubleClick and popular Zedo. Both networks promoted malicious ads that are designed to distribute Zemot malware. A Google spokesman confirmed the problem, saying: "Our team is aware of the problem and has taken the necessary to eliminate it." 

The Malware served by ad networks (or «malvertising») is nothing new, but this incident is noteworthy because of the unusually wide range of attack. 

"He was active, but not visible for several weeks until we started to see popular sites to" fly »flags on our honeypots," says Segura. 
"Then we thought, that something is happening." Early indications came in late August, and today millions of computers likely to have been exposed to Zemot, and people with antivirus is not updated at risk. "

The Zemot focuses on computers with Windows XP, although it can also infect and modern operating systems that run on x86 and 64bit. The Zemot designed to bypass the security of a system before infecting with additional malware. 
"Even though there were only 5% of vulnerable systems," says Segura «expect a very large number of infections."

Wednesday, 10 September 2014

Security measures in iCloud with delay

Security measures in iCloud
The trick that resulted in leaks photos of celebrities, led Apple to implement a stricter security policy delivery push notifications, users using iCloud. 

Apple CEO Tim Cook announced some new measures on Friday in an interview with the Wall Street Journal and said that will be implemented in two weeks. 

Earlier this month, if someone has the user name iCloud for a new device to ignore. 

However, new measures have been implemented, at least in part, by far, the account owner will receive a notification if someone has access to the service web browsers. 

Email notice Apple is very clear and says "Apple ID you use to log into iCloud via a web browser." 

The e-mail had at least ten minutes to take note that informed our Apple ID was used. That time is over-sufficient for an attacker to make changes to our account. 

You can try it for yourself to see the 'immediacy' warning Apple. Of course, if it happens to some really should immediately change your password to your account.

27 Year old arrested for sending a threatening message on Facebook

From the Department of Electronic Crime file a case formed post messages to the social networking site, where there was talk of threats against persons in the prefecture of Ilia. 
Facebook

Case formed file against domestic 27 years old, who was identified as a manager and owner of the "profile" of social networking, through which the issue had been hanging. 

It emerges from the above, through the website and Facebook in particular through "personal profile" which managed, sent a "page-group 'of the site, threatening message when firefighters and police officers who served or are serving in Services of Ilia. 

To clarify the matter, the Department of Electronic Crime contacted directly by the company and after a thorough investigation identified the digital internet connection used to send the message, which, as noted, came from Internet - cafe.

Step the police Cyber ​​Crime went yesterday (07/09/2014) morning in the area of Elis, which identified the 27-year old actor, who admitted that he sent the message in question, but claimed that he had no intention to carry out the threats.

The papers formed on the case will be submitted to the competent Prosecutor Athens.

Tuesday, 9 September 2014

How to check a suspicious link before clicking on it

Have you ever been in front of a link, do not inspire confidence? We all know the dangers that can result in a fatal one click. 
Secure HTTPS

There are warning signs that may indicate that the link can infect your computer or send it to a phishing website; 

Below we will describe how to identify malicious links and how you can check whether it is safe or not without their visit. 

Some warning signs of possible malicious links: 
Access services like bitly links (and many others) are popular choices for anyone trying to fit a link to the limits of a Twitter message. The iGuRu.gr use the service, for the same reason. Unfortunately, this method links and shortcut phishers and malware distributors is also used to hide the actual address. 

Obviously a shortened link, which helps identify a malicious link, but there are tools that let you see the real destination without clicking. 

Strange links in unsolicited email 
Very suspicious. If you received a spam email that is supposedly from your bank asking you to "verify your information" then it is likely to be a target of phishing attack. 

Even if the connection to your bank for email seems normal, you should not click as it could be a very well disguised to connect to the database phishing.Gia link, use a new browser window. All you need to enter yourself to face directly in your browser or using a bookmark that you created yourself. Be wary of links in emails, pop-ups, etc. Of course, if the bank check online is secure (https) green. 

Link contains unusual characters 
Malware distributors are constantly trying to hide the destination of links containing malware, or that lead to phishing sites. One of the ways they are using and URL encoding. For example, the letter "A" encoded in a URL will appear as "41%". 

The use of encryption can cover destinations, orders and other unpleasant things through a link, so no one can read it in advance. If you see this type of character in a bond, it would be nice to see. 

How to check a suspicious link without clicking it. 

Expand shortened links 
You develop a brief online using services like Untiny, or by installing a plug-in for your browser, which will show the destination of a shortened connection with a right-click. Some sites let you know if there is a link to a list of known malicious sites. 

Scan this link to connect the scanner 
There are several tools available that can test the security of the link before clicking on it. Visit the Norton SafeWeb, URLVoid, ScanURL and test the link. 

Select the antimalware software analysis in "real time" use. 
To have the best chance to detect malware before it infects your computer, it should benefit from the protection function has enough real-time antimalware. You may use more system resources, but protection is better. 

Keep your antivirus and antimalware used to date. 
If your security software does not have the latest virus definitions, which are not secure. Make sure your software is configured to automatically update periodically. 

Get a second opinion from a second scan of malware 
A second opinion from a different malware scanner offers extra protection. There are some malware that hassle and provide additional security.

Thursday, 4 September 2014

The nude photos of celebrities catapulted the share of Apple!

Can the loss of nude photos of beautiful women and famous as Jennifer Lawrence, Rianne, Ariana Grande, Kate Upton, Kim Kardashian and many others to be shocked on the other side of the Atlantic, but this does not apply to Apple itself. 
The stock of the company when it was announced that the issue has been resolved, jumped to a record 103, $ 74, an increase of 1%, despite the fact that the reported loss caused by the accounts of certain names in iCloud. 

According to the results of the internal investigation of the technology giant, which lasted 40 hours, this "targeted attack" exposed to risk accounts only some names but not detected signs of tampering on the storage system iCloud. 

A virus of 2009 has found the "backdoor" of the system 

The problem, according to experts presumably caused by the virus called "ibrute" who took a weakness in the "Find my iPhone". 

The iBrute created in 2009, when he lost 32 million usernames and passwords up to the creators to reach the 500 most common combinations that published in the particular websites. 

Probably, therefore, what they had achieved so far unknown hackers using virus was to find the appropriate codes constantly looking for new "solutions" possible to find a fair and gain access to personal photos of actors and other celebrities as well. 

E 'possible to use absolute immunity? 
As he wrote in Time magazine presents "the only effective way to protect yourself 100% on the internet is not to use it" But because we are in the 21st century and this is nearly impossible, experts conclude in five basic steps for protection. : 

  • Use unique passwords and different on all devices 
  • Use your choice of identification in two phases, if available. This option exists in iCloud from Apple, Google and Gmail, Dropbox, Facebook, Twitter, and Microsoft PayPayl. 
  • Turn off automatic "upload" photo. 
  • Especially for the iCloud the only safe procedure requires first of "close" a service for iPhone, namely the substance is not used. Then you need to delete the folder of photos from photos you do not want to be exposed. The next step is to "close" a pc in iCloud clearing these services does not want to "share" the internet. 
  • Turn the locking services on the mobile phone and the bills 

The operating system of the phone as well as companies such as Apple continually progresses "corrections" that protect against such problems.

Protect Nude pictures in the internet

The Cryptolocker is a ransomware known to have been used in many Internet attacks, at times, with the United States government to finally halt the activities of hackers.

However, a clone Cryptolocker has emerged called Cryptowall and has already been used in attacks that have already damaged thousands of computers.

Until now infected 625,000 computers have been committed by hackers amounted to 5.25 billion files, just like the Cryptolocker work, but with the difference that the Cryptowall can infect files on cloud servers such as Dropbox and Google Drive.

The way it works is that Cryptowall each file it infects, and it incorporates a different decryption key, so that only he knows the keys (ie the attacker) is able to unlock the current file.

This, in simple terms means that users unlucky to release their records should make Bitcons authors of the value of $ 500 in real money.

The techniques that activate the Cryptowall, varied as they may be through spam or through contaminated sites from which unsuspecting users download files carrying dangerous ransomware.

To protect users must install an antivirus program, a firewall to be turned on and be very careful with e-mails from unknown senders.

Friday, 29 August 2014

TrueNorth Computers come with Brain Synapses

Computers come with Brain Synapses
TrueNorth: The IBM recently unveiled what it calls the first nefrosynaptiko computer chip in the world, a processor that mimics the capabilities of the human brain and energy efficiency. 

The chip of IBM is known as TrueNorth, and could strengthen the forces of a supercomputer with a microprocessor th the size of a postage stamp. Instead of solving problems through brute-force mathematical calculations, as do today's processors, designed to understand the environment, to clarify the ambiguity, and take action in real-time animation in this context. 

A computer "dresses» TrueNorth is configured as the human brain. The chip TrueNorth incorporates 5.4 billion transistors, most of which has never been used in an IBM chip. It also features programmable one million neurons and 256 million programmable synapses. Of course the numbers are much lower than the 100 billion neurons and 100 trillion to 150 trillion synapses are beginning to be rather several. The chip is the core element of cognitive computer programs of IBM, known as Synapse. 

It is still under investigation, and the announcement says the second generation design. The IBM released the first generation a year ago. While still in prototype stage, could after two or three years to have our first commercial use. Experts believe that an innovation like the TrueNorth Synapse could help to overcome the performance limits of architecture von Neumann, the mathematical system kernel based almost every computer that was built from 1948 onwards. 

The new technique does not rely on the von Neumann architecture could one day give us devices that understand the world through sight, smell, hearing, just understand him and feel a man. 
The IBM plans to make the TrueNorth - along with a new custom programming language - first in universities and later to business customers. 

Imagine what risks can hide such a project. 
Future computers surpass humans in intelligence, has already been the subject of films Hollywood. Trying to create computers that think and feel the same way you think a human brain, we could expect autonomous vehicles working in warehouses, or robots to ensure security at home or in the city. 

The project is one of the most important of IBM, which spends $ 6 billion a year on research. In 2011, the supercomputer Watson beat the best players of «Jeopardy», an impressive display of computing power. 

But imagine that Watson is the most powerful engine made ​​the architecture of von Neumann. Requires more electricity than any home and technology ... considered outdated.

What is Public Key Pinning (PKP) coming in Firefox 32

To Public Key Pinning (PKP) is an extension of the HTTP protocol that controls the state of the Internet Engineering Task Force (IETF).
Public Key Pinning (PKP)

It allows web services to reduce the number of authorities that can validate a website instructing customers (clients) to use only a specific subset of principles, rather than accept any certificate that is served from the browser. 

The technique is designed to reduce the likelihood of attacks man in the middle (MITM) under certain conditions and protect against false certificates. 

The safety feature works only the second visit to the site and not the first, as the information provided by the website for certificate authorities submitted to the client on the first visit. This is called trust on first use or trust on first use (TOFU). 

This means that the technique can not help if you have already visited a website and you have received a fake certificate from scammers or if an attack happens man in the middle at that time. 

With the new version of Firefox 32, Mozilla's browser will support the Public Key Pinning. The Firefox 32 is already available as a beta version and will be released in the final version of the September 2, 2014 (maybe sooner for readers iGuRu.gr). 

O new Firefox will display a lock icon to indicate when a website is secure and will reject websites it deems unsafe. The latter is the case, ie if a fail safe link will display the error to the browser. 
Public Key Pinning 

It should be mentioned that the new feature of Firefox is not so new for Google Chrome that already. 

Pinning (Public Key Pinning) is enabled by default in Firefox 32 and subsequent versions of the browser.

How to protect your PIN from the thermal cameras

You can protect your PIN from a new enemy is in the hands of crooks? The technology is evolving and with it and the methods used for each kind of theft. Let's talk about thermal cameras used to be expensive and bulky. So very few people were able to get their hands on. In the new part of the iPhone FLIR, your device turns into a thermal imaging camera. The device is very affordable and incredibly discreet. Somewhere it all begins here ... 

How to protect your PINFor this reason it has been in use since many course of several criminals are aiming to steal credit card PIN. 

The former engineer of NASA JPL Mark Rober with a video explains very simply, how can one criminal to steal your PIN you from the heat leave your fingers on the keys, a machine. 

Since I now know the trick of fraudsters is very easy to protect yourself, simply by touching more keys than you use to register your PIN. Alternatively, when you are done typing, you can put your whole palm on the keyboard in order to warm up all the buttons. You can also type using a pen or any other object that will not transfer heat. 

The good news is that they usually do not have to worry about the keyboards that are made ​​of metal. The metal keyboards reflect heat like a mirror. 

Attention So now you know, and of course there is no excuse.

Wednesday, 27 August 2014

Orlando Jones a Defiant Message to the ice bucket challenge

Orlando Jones
While politicians and celebrities bougainvillea the last two weeks for charity,actor Orlando Jones, thought something more challenging. 

Emptied over his head a bucket filled with bullets, following the viral trend. In this way the actor complains about the disturbing news coming from Ferguson, afterthe murder of unarmed teenager Michael Brown. 

The Jones does not degrade the ice bucket challenge and supports ALS (senthis check to charity), but decided to use the time to complain. The actor says in the video: 

My "bullet bucket challenge" is to show the finger and not because I'm angry.Each shell of this bucket represents the life you lost someone fighting for civil rights and human dignity. We will not stand idly by while others violate civil and human rights within the coverage of the authorities. 

Since its release, the video became viral with more than 1 million 100 thousandvisits.

Tuesday, 26 August 2014

The Largest Student Hacking Contest Started, Entries are Open

Student Hacking Contest
Registration for the annual student hacking contest hosted by the Faculty of Engineering of New York (NYU Polytechnic School of Engineering), is open to participants from across the globe. 

The final tournament Cyber ​​Security Awareness Week (CSAW) will be held on November 13-15. Pet contestants from high schools and doctoral programs, who will have to compete in six preliminary rounds for a place in the final. 

Prizes will be several scholarships and awards. Apart from six matches, and the contest is Capture the Flag, which aims to find ways to breach system security and theft of protected data. This is the most popular events of the competition by qualifying round which will be held between 19-21 September. 

There is also a category for forensic analysis, for high school students as well as a section for hackers hardware (hardware). The notice of registration to the event The organizers reported that added a new competition for public policy developed by students. 

This year, the Chief Information Security Officer of Yahoo, Mr. Alex Stamos (obviously Greek origin), will provide the keynote presentation, entitled "Shaping the Future: espionage, cyber crimes, and your career" on November 13, when reception of finalists. 

According to the announcement from the university, last year's event brought together more than 15,000 students, shows that there is growing interest among participants. 

This year's competition is supported by a total of 20 organizations, gold sponsor is the U.S. Department of Homeland Security (DHS). The Yahoo is the silver sponsor (2nd) competition, and the list of donors includes copper big names like Facebook, the National Security Agency (NSA), NCC Group North America.

Additional companies that offer support are FireEye, the Intel, the Microsoft, the MIT Lincoln Laboratory and Service United States Secret Service.

Kaspersky Lab Back to School Safely

Kaspersky Lab: The end of the summer holidays approaching, signaling the start of the new school year. Soon the kids will leave the beaches to come back in front of their computers and start using again tools like tablet and smartphone in order to prepare their work. In fact, apart from a wide variety of useful educational materials, children can easily meet and unwanted content on the Internet, such as pornography, violence, and websites that focus on drug use and even suicide.
Kaspersky Lab

For this reason, parents need to pay particular attention to the online activity of their children. The Kaspersky Lab specialists advise parents who want to protect their children in cyberspace:

Limit the Children Time on Internet
Children are good to spend some time on the internet, searching educational information, playing games or even talking to their friends on Facebook. However, everyone will agree that most children probably spend too many hours online. This requires parents to adopt strict rules on the time children spend in front of a computer. Before setting these new standards, parents should be careful to make a frank discussion with their child, explaining why these limits are important. Otherwise, it can be seen as an arbitrary punishment, creating problems in the relationship of parents with their children.

Check the contents 
It is important to explain to children what they can and can not do on the internet and set clear rules. As children grow older, these rules should be reviewed. To ensure that children respect the rules you set, we recommend that you use the Parental Control offers Kaspersky Internet Security - Multi-Device, allowing parents restrict the time that children use the Internet, to prevent access to inappropriate websites and games and to prevent the disclosure of personal data to third parties. The websites and games are divided into categories according to their content and the age of the children. Also, parents can easily see detailed reports record all online activities of their children.

Advise your children 
Talking with children about the new rules, it is good for parents to share some tips with them. In this way, they will help their children to be protected against online threats while showing them that trust.

  • Do not disclose publicly or to foreign intelligence, such as the address, location, your school, etc..
  • Do not accept invitations to meet anyone you do not know.
  • Do not give anyone your phone or email and you do not post this information on your pages to social media.
  • Do not open links from strangers.
  • Do not trust any kind of seductive messages - free offers, discounts, or increase the reputation of likes on a carrier etc. Just delete these messages and do not open any of the link it contains.

If anything happens that makes you feel uncomfortable or if you start receiving messages from third parties that worry you, tell your parents and ask for their help to troubleshoot the problem.

Try to locate a key problem
Parents should remember that children remain connected to the Internet even when you close the computer, using tablets, smartphones and other devices. If children immediately start looking for another gadget just find that the computer is not available, parents must ensure that these devices are protected against digital threats. See why your kids prefer the digital world rather than meet their friends in real life.

This lack of social opportunities or the need for more physical activity? In each case, the parents have to focus their attention on activities for the whole family not related to computers to ensure that their children enjoy a healthy and balanced life.