There's no any particular cpm rate, all the rates are highly dynamic and different for each site and user. tech news: security  
lasted technology news
news...
 
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, July 18, 2017

Hacker steals $7.4 million in ethereum during CoinDash ICO launch


screen-shot-2017-07-18-at-08-41-51.jpg
As reported my Motherboard, the hacker took the opportunity to disrupt the Initial Coin Offering (ICO) of CoinDash, a trading platform for cryptocurrencies.
On Monday, CoinDash held its Token Sale event, in which investors were meant to be able to fund apps in development with virtual currency in return for a stake in such applications in an event similar to a crowdfunding campaign.

The CoinDash ICO, like many others in which cryptocurrency "tokens" (CDT) were exchanged for shares in a project, was keenly anticipated by investors.
However, this time, something went terribly wrong.
In a statement on its website, the platform apologized, admitting that a "hacking attack" took place during the event by an unknown perpetrator, resulting in the loss of millions in ethereum, also known as ether (ETH).
Rather than conduct a complex attack on trading itself, however, the hacker employed a simple tactic.
At the time of the ICO, in which CoinDash posted a string of characters which represented its wallet address for investors to send funds to, it appears that the hacker compromised the website and changed this text to a wallet they control.
It was a matter of minutes before the platform realized the security breach had taken place and warned investors, but it was too late -- and now the stolen funds intended for CoinDash are simply sitting in a walletawaiting collection.
CoinDesk has pleaded with traders not to send any cryptocurrency as the Token Sale has been canceled, and the organization considers itself "still under attack."
Some investors, however, are speculating that there may have been ulterior motives relating to the incident. On Twitter, traders vented their frustration, and on Reddit, some contributors have suggested that the platform is linked to a previously known scam.
The organization, however, has promised that investors involved in the apparent cyberattack will be given tokens reflecting their pledges, as long as the transactions took place before the website was shut down.
"This was a damaging event to both our contributors and our company but it is surely not the end of our project," CoinDash says. "We are looking into the security breach and will update you all as soon as possible about the findings. The CoinDash vision, product and team will continue to live on. We will be fast to recover and we will create the future of trading."
Last week, Bitcoin community Bitcoin.org that network disruption isexpected in the coming weeks which, if traders are not careful, could result in the loss of their Bitcoin.
As updates to blockchain infrastructure are pushed through, it is possible a "chain split" will occur -- an event in which some Bitcoin nodes will run on software that other nodes are suddenly not compatible with for a time.

Tuesday, June 20, 2017

A Decade recent Unix/Linux/BSD Root Privilege-Escalation Bug Discovered « Back


Security researchers have discovered over a decade-old vulnerability in many Unix-based operational systems — together with UNIX system, OpenBSD, NetBSD, FreeBSD and Solaris — which may be exploited by attackers to intensify their privileges to root, probablyresulting in a full system takeover.
Dubbed Stack Clash, the vulnerability (CVE-2017-1000364) has been discovered within the approach memory was being allotted on the stack for user area binaries.
Exploiting Stack Clash Bug to realize Root Access
The explanation is simple: every program uses a special memory region known as the stack, that is employed to store short-runknowledge. It expands and contracts mechanically throughout the execution of any program, relying upon the wants of that program.
According to researchers at Qualys, WHO discovered and rumored this bug, a computer program will conceive to use a lot ofmemory area than on the market on the stack, that might overflow the memory, inflicting it to collide or clash with near memory regions and write their content.
Moreover, the Stack Clash exploit may bypass the stack guard-page, a memory management protection introduced in 2010, once this issue was exploited in 2005 and 2010.
"Unfortunately, a stack guard-page of a couple of kilobytes is insufficient: if the stack-pointer 'jumps' over the guard-page—if it moves from the stack into another memory region while not accessing the guard-page—then no page-fault exception is raised and also the stack extends into the opposite memory region," AN consultatory printed by Qualys browse.
The Stack Clash vulnerability needs native access to the vulnerable system for exploitation, however researchers same it might beexploited remotely relying upon the applications.
For example, a malicious client with low privilege account with an online hosting company, running vulnerable system, might exploit this vulnerability to realize management over alternative websites running on a similar server, in addition as remotely gain root access and execute malicious code directly.
Just yesterday, we tend to rumored that however an online hosting company fell victim to an analogous attack wont to infect UNIX system servers with a ransomware malware, inflicting the corporate to pay over $1 Million in ransom to urge back their files.
Attackers may mix the Stack Clash bug with alternative vital vulnerabilities, just like the Sudo vulnerability recently patched, and so runarbitrary code with the best privileges, same Qualys researchers.
7 Proof-of-Concept Exploits
The researchers same they were able to develop seven exploits and 7 proofs of idea (PoCs) for the Stack Clash vulnerability, that works on UNIX system, OpenBSD, NetBSD, FreeBSD and Solaris on 32-bit and 64-bit x86 processors.
However, the researchers haven't nonetheless printed the exploits and proofs of idea, giving users and admins enough time to patch their systems before they're going into the Stack Clash exploits public.
The PoCs follow four steps, that embrace 'Clashing' the stack with another memory region, running the stack pointer to the stack’s begin, 'Jumping' over the stack guard-page and 'Smashing' the stack or the opposite memory regions.
Among distros and systems laid low with Stack Clash include:
Sudo on Debian, Ubuntu, and CentOS
ld.so and most SUID-root binaries on Debian, Ubuntu, Fedora, and CentOS
Exim on Debian
rsh on Solaris eleven so on
Red Hat Enterprise
The company conjointly believes that alternative operational systems, together with Microsoft's Windows, Apple's OS X/macOS and Google's Linux-based robot OS might even be prone to Stack Clash, although it's nonetheless to be confirmed.
Patch Available; Update currently
Many affected vendors have already issued security patches for the bug, thus users and directors ar suggested to put in patches abefore long as attainable.
If security patches from your trafficker ar nonetheless to be discharged, {you will|you'll|you'll be able to} resuscitate your systems or can manually apply stack limits to native users' applications. Simply, set the exhausting RLIMIT STACK and RLIMIT_AS of native users and remote services to a coffee price.
It is conjointly suggested to recompile all userland code (ld.so, libraries, binaries) with the –fstack-check feature. this might stop the stack pointer from stepping into another memory region while not accessing the stack guard-page and would kill Stack Clash dead.
article source : zd.net

Sunday, June 18, 2017

What Is a usb Rubber Ducky and How Is It Used?





What Is a USB Rubber Ducky and How Is It Used?
When it comes to simplicity, keystroke injection attacks are ideal. With the tools available in today’s cybersecurity market, the execution of a keystroke injection attack is both easy and effective. The most popular and easily retrieved tool on the market is Hack5’s USB Rubber Ducky.
Masked as the average flash drive, USB Rubber Ducky is recognized on devices as a generic keyboard. With this identification, the USB Rubber Ducky can perform keystroke injection attacks via accepting preset keystroke payloads. The device can even go as far as 1000 WPM when executing.
Hakshop’s official website describes the USB Rubber Ducky’s payload operation:
“Payloads are crafted using a simple scripting language and can be used to drop reverse shells, inject binaries, brute force pin codes, and many other automated functions for the penetration tester and systems administrator.”
Despite its primary purchase use, USB Rubber Ducky can also be used for targeting vulnerable systems or programming processes and save times.
 
The implementation of USB Rubber Ducky is basic and easy to follow. If you find yourself getting lost, thorough guides on the device’s set up and use can be found online.
A downside to USB Rubber Ducky might be its slow functionality on certain operating systems. The issue was widely reported and even discussed on forums like Reddit and 4chan.
A reddit user further described the speed issues and overall potential on a /r/HowToHack post,
“In short, it is a very promising and effective tool, but seriously lacks versatility. In some machines it may take 5 seconds to load the drivers, in others maybe longer than 60. Then you have to account for how long it will take to deliver your payload in accordance to how fast the machine can handle keystrokes.
This becomes a huge bummer during official penetration testing scenarios where you are required to enter the office physically, because the variety of machine setups can be drastically different. Otherwise, exactly what it says on the tin: emulates a keyboard and mouse set up to deliver instructions.”

Web application attacks: Remote code execution





























Remote Code Execution Vulnerability

PHP provides different functions which when called allow shell code execution on the server. This is a list of functions which are used for shell command execution:
– system: Executes a command and returns its output
– shell_exec: Executes a command and displays the output immediately
– passthru: Executes a command and displays the raw output –
– backtick operator (“): Executes contents inside the backtick as a shell command
– popen: Executes a command and returns a pointer
– exec: Executes a command and returns the last line of the output
– pcntl_exec: Executes a command or a program
– proc_open: Similar to popen()

Remote Code Execution (RCE) or also known as Command injection in terms of the web application attacks, can be possible to a certain website accepts added strings of characters or arguments; the inputs are used as arguments for performing the command in the website’s hosting server.
This vulnerability is one of the common web application vulnerabilities that enables an attacker to perform arbitrary codes in the system. The RCE also included in OWASP (Open Web Application Security Project) Top Ten Web Application Security Risks.
In the event where code evaluation is necessary, it is important for any user input to be very heavily validated, with as many limitations as possible on the inputted data.

Vaping, e-Cigarettes Can Be Used to Hack Computers

https://assets.infosecurity-magazine.com/webpage/feat/99f3c323-18f9-4402-8955-924737aae477.jpg
Giving up smoking is a good thing to do, but e-cigarettes and vaping present a whole new set of dangers: The smoking-cessation aids can actually be used to hack computers.
Security researcher Ross Bevington showcased a presentation at BSides London, reported by Sky News, that revealed how an e-cigarette could be used to intercept network traffic or control the computer by making it think the e-cig is a keyboard.
Many e-cigarettes can be charged over USB, and Bevington said that takes just a few simple tweaks to the vaporizer to turn it into a weapon that can download malicious payloads from the web.
The situation is further proof that a connected-everything world presents staggering cybersecurity ramifications, according to Cesare Garlarti, chief security strategist at prpl Foundation.
"The security of the internet of things is fundamentally broken,” he said over email. “Developers and manufacturers understandably are eager to get their new high-tech devices to market, and unfortunately often overlook security. Interoperable open standards are the key requirement if we’re to improve IoT security even in the smallest of connected devices—they will reduce that complexity by effectively outsourcing the trickiest security work to the subject-matter experts."
A saving grace is that e-cigs don’t have that much memory, so complex code is a no-go. “This puts limitations on how elaborate a real attack could be made,” said Bevington, speaking to Sky News. “The WannaCry malware for instance was 4 to 5 MB, hundreds of times larger than the space on an e-cigarette. That being said, using something like an e-cigarette to download something larger from the internet would be possible.”
Many enterprises today block the use of USB ports, which would prevent an attack like this—but some do not, so users should beware.
"Last year the University of Illinois and University of Michigan published research that showed if a hacker deliberately dropped a USB stick (which could have malware on it) there was a 50% chance that someone would pick it up and plug it into a computer,” said Adam Brown, manager of security solutions at Synopsys, via email. “As Bevington's recent research shows, a vape pipe could easily be modified to work as any kind of peripheral device when plugged in, and so could be used in a similar way to either deliver a payload or perform some other malicious activity while plugged in. Potentially, a vape pipe given away would very likely end up plugged into a computer for charging and so would be an effective device for a targeted attack on a known vaper.”
He added, “health risks to the body from vaping may not be fully known; however, it seems the health risks to your information or cybersecurity could be disastrous."

Friday, June 16, 2017

British defence giant BAE allegedly sold cyber-tools which could threaten UK security


BAE Systems is alleged to have sold sophisticated decryption and cyber-surveillance tools to nations across the Middle East, including repressive regimes, according to a new investigation undertaken by BBC Arabic and a Danish newspaper.

The in-depth investigation, which ran for a year, involved speaking with insiders from BAE and the British government as well as former intelligence operatives, and found that the tools being sold included decryption software and systems designed to facilitate mass surveillance. The former could potentially be used against the UK (or indeed other nations) in order to crack encrypted communications.

The BBC notes that officially, these sales are legal, but the investigation found plenty of evidence showing cyber-surveillance tools actively being used to crush any dissent or opposition in some Arab states.

For example, in Oman, human rights activists have been jailed and had their network destroyed, and cyber-security experts that the Beeb talked to said it was ‘highly likely’ this was a direct result of the Omani regime’s mass surveillance system.

Evident evidence

The investigation found that ETI, a cyber-intelligence firm acquired by BAE back in 2010, sold a mass surveillance system called ‘Evident’ to the Tunisian government, who subsequently used it to repress their opponents in the first uprising of the ‘Arab Spring’.

The BBC spoke to a former Tunisian intelligence operative who said: “ETI installed it and engineers came for training sessions. [It] works with keywords. You put in an opponent's name and you will see all the sites, blogs, social networks related to that user.”

Furthermore, according to documents obtained from the Danish government, ETI has apparently also sold sophisticated decryption tools to a number of nations: Oman, Qatar, UAE, Algeria and Morocco.

BAE refused to speak directly to the BBC during the course of the investigation, but the company did issue a statement to say: “Our technology plays a crucial role in enabling the UK and its allies to combat the threat of international terrorism. BAE Systems is committed to operating ethically and responsibly.

“We have robust policies and procedures in place to ensure that our international exports to overseas governments are all fully compliant with international export regulations as well as our own strict criteria to evaluate every potential contract.”

Wednesday, June 14, 2017

House pushes bill to demand notice when Pentagon uses cyberweapons



The Pentagon would have two days to inform congressional oversight committees.

A new bill would require the Defense Depadrone.jpgrtment to inform congressional overseers within two days of launching a cyberweapon.
The measure, proposed by leading lawmakers on the House Armed Services Committee, would apply to both offensive and defensive operations launched by the Pentagon to "defeat an ongoing or imminent threat," according to the text of the six-page bill.
The draft law allows two exceptions -- if the cyberweapons are launched during a training exercise, or authorized under covert action.
Presumably, operations that are highly sensitive and intelligence-led would not be revealed until they are completed.
"While there are programs that must necessarily remain classified to keep the country safe," said Mac Thornerry (R-TX), chairman of the House Armed Services Committee, in a statement, "Congress still has a responsibility to conduct appropriate oversight in order to protect our security and our essential freedoms at the same time. This proposal to enhance congressional oversight of sensitive military cyber operations and cyber weapons will help achieve that balance by promoting greater transparency and accountability for some of the most classified elements of our national defense."
The previous Obama-led government only recently confirmed its use of cyberweapons, such as exploits and technologies used at disrupting the activities of the so-called Islamic State, other terrorist groups, and also including some hostile nation states.
But their efficacy has long been called into question. A report by The New York Times this week, which cited former US officials, said that the government's cyberweapons have largely led to "disappointment."