Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, November 30, 2008

Internet worm exploits Windows vulnerability

A worm dubbed Win32/Conficker.A is making the rounds on Windows machines, exploiting a security hole that Microsoft released a patch for in October, Microsoft said on Wednesday.

The number of attacks have increased over the past couple of days, exploiting a critical vulnerability that was addressed by security update MS08-067.

The malware mostly was spreading inside corporations, but also hit several hundred home PCs, Microsoft said in a posting on the Microsoft Malware Protection Center Blog.

"It opens a random port between port 1024 and 10000 and acts like a Web server. It propagates to random computers on the network by exploiting MS08-067. Once the remote computer is exploited, that computer will download a copy of the worm via HTTP using the random port opened by the worm. The worm often uses a .JPG extension when copied over and then it is saved to the local system folder as a random named dll," the posting said.

"It is also interesting to note that the worm patches the vulnerable API in memory so the machine will not be vulnerable anymore. It is not that the malware authors care so much about the computer as they want to make sure that other malware will not take it over too," Microsoft said.

Most of the infections are in U.S. PCs, but there have been reports from Germany, Spain, France, Italy, Taiwan, Japan, Brazil, Turkey, China, Mexico, Canada, Argentina, and Chile. The worm avoids infecting Ukrainian computers, for some reason, Microsoft said.

Several bots, under the generic name Backdoor:Win32/IRCbot.BH, also are exploiting the security hole. They drop a backdoor Trojan that connects to an IRC server to receive commands.

Resource - C|Net

Thursday, November 13, 2008

Once Thought Safe, WPA Wi-Fi Encryption Is Cracked

Security researchers say they've developed a way to partially crack the Wi-Fi Protected Access (WPA) encryption standard used to protect data on many wireless networks.

The attack, described as the first practical attack on WPA, will be discussed at the PacSec conference in Tokyo next week. There, researcher Erik Tews will show how he was able to crack WPA encryption, in order to read data being sent from a router to a laptop computer. The attack could also be used to send bogus information to a client connected to the router.

To do this, Tews and his co-researcher Martin Beck found a way to break the Temporal Key Integrity Protocol (TKIP) key, used by WPA, in a relatively short amount of time: 12 to 15 minutes, according to Dragos Ruiu, the PacSec conference's organizer.

They have not, however, managed to crack the encryption keys used to secure data that goes from the PC to the router in this particular attack

Security experts had known that TKIP could be cracked using what's known as a dictionary attack. Using massive computational resources, the attacker essentially cracks the encryption by making an extremely large number of educated guesses as to what key is being used to secure the wireless data.

The work of Tews and Beck does not involve a dictionary attack, however.

To pull off their trick, the researchers first discovered a way to trick a WPA router into sending them large amounts of data. This makes cracking the key easier, but this technique is also combined with a "mathematical breakthrough," that lets them crack WPA much more quickly than any previous attempt, Ruiu said.

Tews is planning to publish the cryptographic work in an academic journal in the coming months, Ruiu said. Some of the code used in the attack was quietly added to theAircrack-ng Wi-Fi encryption hacking tool two weeks ago, he added.

WPA is widely used on today's Wi-Fi networks and is considered a better alternative to the original WEP (Wired Equivalent Privacy) standard, which was developed in the late 1990s. Soon after the development of WEP, however, hackers found a way to break its encryption and it is now considered insecure by most security professionals. Store chain T.J. Maxx was in the process of upgrading from WEP to WPA encryption when it experienced one of the most widely publicized data breaches in U.S. history, in which hundreds of millions of credit card numbers were stolen over a two-year period.

A new wireless standard known as WPA2 is considered safe from the attack developed by Tews and Beck, but many WPA2 routers also support WPA.

"Everybody has been saying, 'Go to WPA because WEP is broken,'" Ruiu said. "This is a break in WPA."

If WPA is significantly compromised, it would be a big blow for enterprise customers who have been increasingly adopting it, said Sri Sundaralingam, vice president of product management with wireless network security vendor AirTight Networks. Although customers can adopt Wi-Fi technology such as WPA2 or virtual private network software that will protect them from this attack, there are still may devices that connect to the network using WPA, or even the thoroughly cracked WEP standard, he said.

Ruiu expects a lot more WPA research to follow this work. "Its just the starting point," he said. "Erik and Martin have just opened the box on a whole new hacker playground."

Resource - PC World

Wednesday, November 12, 2008

On Security, Microsoft Reports Progress and Alarm

Microsoft plans to report on Monday that the security of its Windows operating system has significantly improved, while at the same time the threat of computer viruses, frauds and other online scourges has become much more serious.

The company blames organized crime, naïve users and its competitors for the deteriorating situation.

In the latest edition of its twice-a-year “Security Intelligence Report,” Microsoft said that the amount of malicious or potentially harmful software removed from Windows computers grew by 43 percent during the first half of 2008.

The company said improvements in security for its Windows Vista operating system and security updates to the previous Windows XP system had made such software a less attractive target for attackers. Instead they have shifted their attention to security holes in individual programs.

During the first half of the year, 90 percent of newly reported vulnerabilities involved applications, and only 10 percent affected operating systems, according to the report.

Microsoft executives said they were pleased with the progress made since the company was shaken by a series of destructive programs that spread rapidly around the world over the Internet beginning in 2003. But they said that unless software development practices change throughout the industry, any improvements in the security of Windows would be meaningless.

“This story is real,” said George Stathakopoulos, general manager for Microsoft’s Security Engineering and Communications group, referring to the improvement in the company’s engineering practices. “Now we have a third-party problem and it’s something we have to go solve.”

Security researchers said they were sympathetic to Microsoft’s plight.

“The only thing that Microsoft can patch is their own software,” said Patrik Runald, chief security adviser for F-Secure, a computer security firm in Finland. “That’s not what the bad guys are using to get into computers these days. It’s certainly a challenge.”

Microsoft and the computer industry have also been unable to solve the so-called dancing pony problem. That refers to the propensity of many computer users to click on enticing links in their e-mail or to visit seductive but malicious Web sites, leaving them vulnerable to Trojan horse downloads and other infections.

Over the last three years the computer security industry has been fighting a losing battle, as the ability of computer criminals to profit from identity theft and a variety of other scams has led to the development of a robust underground industry generating viruses and other so-called malware.

Microsoft has tried to combat the problem by building a variety of safeguards into its operating systems and its Internet Explorer browser, with mixed success. The User Account Control feature of Windows Vista, which popped up an endless stream of warnings that irritated users, proved to be one of the key factors in the poor reception for Vista. Last week in Los Angeles, the company said it had entirely reworked the user interface of its new Windows 7 operating system to minimize user frustration.

In comparing Web browser vulnerabilities in Windows XP and Windows Vista in the first half of the year, the new report found that while Microsoft could be blamed for half of the top 10 vulnerabilities in Windows XP, the top 10 browser vulnerabilities under Vista all came from third-party add-on software from companies like Apple and RealNetworks.

A companion report published by Jeffrey R. Jones, a Microsoft security director, claims that Microsoft is fixing security-related bugs about three times as fast as three of its rivals: Apple, Ubuntu and Red Hat.

An Apple spokesman, Bill Evans, said Microsoft had previously issued similar reports and declined to comment beyond saying that the data was not supported by users’ experience of infections.

Microsoft has a unique vantage point from which to monitor the world of malware and other threats because it receives automated data both from free software it has given to users, like the Malicious Software Removal Tool, and from specialized Internet reporting systems that monitor threats. It also receives data about crashes on more than a half-billion personal computers.

The current report indicates that malware infection rates are generally higher in developing countries and regions than in developed ones. Infection rates range from 1.8 for every 1,000 computers in Japan to above 76.4 for every 1,000 in Afghanistan. The United States had an infection rate of 11.2 infected computers for every 1,000 scanned, an increase of 25.5 percent in the last six months.
Resource - The New York Times