TECHZIE.BLOGSPOT.COM

Your TECH GADGET GURU



Apple’s newest iPhone devices have been hacked with a zero-day font vulnerability in the latest iteration of the JailbreakMe.com project.
The JailbreakMe.com exploit allows the automated jailbreaking of iPhone/iPad/iPod Touch devices from a specially created Web site.
It is essentially a drive-by download attack that exploits the way Apple’s mobile operating system processes certain fonts.  Technical details of the vulnerability are not yet know.
It is likely being combined with a second privilege escalation bug to escape the iOS sandbox, much like the first version of the jailbreakexploit.   According to “Comex,” the hacker behind the site, the exploit defeats ASLR (Address Space Layout Randomization), a key anti-exploit mechanism.
Along with the jailbreak exploit, “Comex” also released a patch for the main vulnerability.
“Due to the nature of iOS, this patch can only be installed on a jailbroken device.   Until Apple releases an update, jailbreaking will ironically be the best way to remain secure,” he explained.
On the issue of releasing exploit for zero-day flaws, here’s a note from the site’s FAQ:
I did not create the vulnerabilities, only discover them.  Releasing an exploit demonstrates the flaw, making it easier for others to use it for malice, but they have long been present and exploitable.  Although releasing a jailbreak is certainly not the usual way to report a vulnerability, it still has the effect of making iOS more secure in the long run.



Apple is rushing to fix a security hole found in its iOS mobile software following a stern warning from a German IT security department.
The Associated Press is reporting that Germany’s Federal Office for Information Security found that flaw stems from clicking on an infected PDF file, which “is sufficient to infect the mobile device with malware without the user’s knowledge.” That opens the door for the user’s passwords, emails, text messages, emails and almost anything else stored on the iPhone, iPad or iPod touch in question.
Apple’s response:
Apple Inc. spokeswoman Bethan Lloyd said Thursday the company is “aware of this reported issue and developing a fix that will be available to customers in an upcoming software update.”
Apparently this is damaging on “several versions” of iOS, but not all. The Guardian has cited specifics:
The problem may occur on iPhone 3GS, iPhone 4, iPad, iPad 2 and the iPod Touch with software versions including iOS 4.3.3, and it “cannot be excluded” that other iOS versions – including the iOS 5 due in September – have the same weakness, said the Bonn-based federal bureau.
The security gap was originally uncovered by a group of hackers trying to jailbreak an iPhone. Some third-parties who produce jailbreaking software have already posted patches. However, it appears that this problem, related to PDF files, is different from the recent zero-day font vulnerability found in JailbreakMe.com. That doesn’t necessarily mean they are unrelated, but just different.
Adrian Kingsley-Hughes reports, there is a debate over whether or not jailbroken iPhones and other iOS devices are actually safer or not. But a patch from Apple for this specific problem is still needed immediately.
All of this follows the recent discovery that Apple could also be a target of the AntiSec campaign, adding fuel to the theory that the Cupertino, Calif.-based company could be the “Holy Grail” for hackers.



Apple is rushing to fix a security hole found in its iOS mobile software following a stern warning from a German IT security department.
The Associated Press is reporting that Germany’s Federal Office for Information Security found that flaw stems from clicking on an infected PDF file, which “is sufficient to infect the mobile device with malware without the user’s knowledge.” That opens the door for the user’s passwords, emails, text messages, emails and almost anything else stored on the iPhone, iPad or iPod touch in question.
Apple’s response:
Apple Inc. spokeswoman Bethan Lloyd said Thursday the company is “aware of this reported issue and developing a fix that will be available to customers in an upcoming software update.”
Apparently this is damaging on “several versions” of iOS, but not all. The Guardian has cited specifics:
The problem may occur on iPhone 3GS, iPhone 4, iPad, iPad 2 and the iPod Touch with software versions including iOS 4.3.3, and it “cannot be excluded” that other iOS versions – including the iOS 5 due in September – have the same weakness, said the Bonn-based federal bureau.
The security gap was originally uncovered by a group of hackers trying to jailbreak an iPhone. Some third-parties who produce jailbreaking software have already posted patches. However, it appears that this problem, related to PDF files, is different from the recent zero-day font vulnerability found in JailbreakMe.com. That doesn’t necessarily mean they are unrelated, but just different.
As ZDNet’s Adrian Kingsley-Hughes reports, there is a debate over whether or not jailbroken iPhones and other iOS devices are actually safer or not. But a patch from Apple for this specific problem is still needed immediately.
All of this follows the recent discovery that Apple could also be a target of the AntiSec campaign, adding fuel to the theory that the Cupertino, Calif.-based company could be the “Holy Grail” for hackers.


Microsoft today announced plans to patch 22 serious security vulnerabilities in its Windows operating system and Office productivity suite.
As part of the July Patch Tuesday releases, Microsoft will ship four bulletins.  One of the bulletins will carry a “critical” rating because of a high risk of remote code execution attacks.
Three of the four bulletins will address security holes in Windows, the company’s flagship operating system. Affected Windows versions include Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7 and Windows Server 2008 R2.
The Microsoft Office update will ship patches for security problems in Microsoft Visio 2003 Service Pack 3.
The bulletins are slated for release on July 12th at 10:00 a.m. PDT.


The hacker group Lulz Security may have announced its farewell, but aNew York Times report noted on Sunday that the threat of attack is far from over.
Well, duh.
According to “security experts” quoted in the article, major cyberattacks — such as on the websites of the C.I.A., U.S. Senate or global tech company Sony — will continue as splinter groups and copycats try to emulate LulSec’s “revolution.”
Sound familiar? Trade the name “LulzSec” for “Al Qaeda” and you can accurately describe the American military campaign in Afghanistan: a ragtag group of government irritants that fragments and heads underground, creating an environment that can only be described as “Whack-a-Mole.”
Most reports I’ve read about the LulzSec incidents demonstrate that there exists concern that a single actor could take down a system — no organized group necessary.
But let’s get real: has that ever not been the case?
It’s clear to me that headlines screaming about the goose chase surrounding LulzSec or the larger group Anonymous hide two real stories:
  1. Many large security systems are not robust enough to withstand the efforts of a determined professional;
  2. Large companies don’t want to admit this fact.
The first point is one of concern for any tech professional working at a major company; after all, security measures should be as robust as the data they’re protecting is sensitive.
But the second point is provocative because, as we’ve seen thus far, most LulzSec attacks are somewhat politically motivated — that is, they’re always trying to make a point, and not just rifling through people’s digital homes for the sake of it.
On more than one occasion, LulzSec has indicated post-hack that it was doing so only to draw attention to easily compromised security systems that supposedly protect sensitive data. Think about it: rarely is the data itself of concern. It’s always about who was sleeping on the job.
While the media and law enforcement feed the frenzy to identify and capture the hackers, perhaps we ought to pause for a moment and consider the message: if you’re willing to take ownership of private data in the 21st century, you’re also implicitly agreeing to protect it. Too many organizations are willing to do the former without taking enough steps to satisfy the latter.
source: Zdnet

What’s a virus, anyway?
I’ve been writing about Windows security since before the turn of the millennium. Every edition in the Windows Inside Out series of books, starting in 2001, has had a lengthy section on security. Back in 2002, I co-wrote Microsoft Windows Security Inside Out for Windows XP and Windows 2000.
In every previous edition, the section on malicious software started with a lengthy glossary, explaining the differences between viruses, worms, Trojans, spyware, and other esoteric terms.
For the Deluxe Edition of Windows 7 Inside Out that went to the printer this week, I ditched that section completely. In 2011, those lines have become so blurred as to be practically meaningless.
Microsoft’s most recent security report lists threat categories by family. (The totals add up to more than 100% because some variants fall into multiple categories.)
Category% Detected
Misc Trojans31.6%
Misc Potentially Unwanted Software25.5%
Worms24.4%
Trojan Downloaders and Droppers20.1%
Adware17.4%
Password Stealers & Monitoring Tools11.7%
Exploits7.1%
Backdoors6.6%
Viruses5.9%
Spyware0.6%
You’ll find viruses down at the bottom of the list, just above spyware, which was a very big deal in 2005 but is practically nonexistent now.
I asked Microsoft for details on what exactly was included in the Viruses category, and they were kind enough to provide a list that wasn’t in the original report. Interestingly, the two entries at the top of the category were already on the top 10 list. Some variations of the Alureon and Frethog Trojans can be technically classed as viruses, because they inject code into system files as part of the infection process.
I found the last entry on the Top 10 Viruses of 2010 list even more interesting. Microsoft’s virus encyclopedia goes on for page after page with variants of malware in the Delf family. It starts withAdware:Win32/Delf and continues over 40 pages untilWorm:Win32/Delf.ZAB. That’s 2,359 variations from a single obscure family, covering just about every category in the malware universe.
And there’s the numbers game in a nutshell. I saw a headline from someone today marveling at the fact that there are 67,000 new threats aimed at Windows every day. Well, that’s only sorta kinda true. Most of those “new threats” are microscopic variations on an existing one, cranked out on the fly by automated malware toolkits that have learned how to slide past signature-based antivirus software.
And so we come full circle. Although it’s an odd way to look at things, malware is actually a market. An unfortunately healthy, thriving market. On the PC side, it’s large and mature, with reasonably skilled coders cranking out malicious product quickly, and an army of white hats well equipped to deal with them.
In the Mac universe (and in Android-land too), the malware market has only just begun to take off. The opportunities for malware developers on new platforms are practically endless. So, unfortunately, are the challenges for those who have to fight them off.
The good news about the bad guys is that they’ll be using a very predictable playbook. Those in the Mac security business who are willing to learn hard-won lessons from their PC counterparts will find life considerably easier. Those who insist that Macs and PCs are fundamentally different are in for a rude shock.
Related : PART - 2



Where does malware come from?
On Windows machines, some malware comes from drive-by downloads. You visit a website, you get infected by a piece of script that triggers a buffer overflow that allows the malware to stealthily install.
If you keep your system fully patched, you are almost certainly not that victim. Those types of attacks are typically successful only with PC owners who haven’t installed the latest security updates. Most such exploits, in fact, target vulnerabilities that were patched years earlier. A 2009 Kaspersky report concluded, “With very few exceptions, the exploits in circulation target software vulnerabilities that are known – and for which patches are available.”
The number of drive-by installations is small. So how does the majority of malware get on a PC or Mac? Most attacks today succeed by convincing the victim to do the actual work.
A 2010 study by Bruce Hughes of AVG Technologies, says “Social engineering trumps a zero-day every time.” It concludes that “users are four times more likely to come into contact with social engineering tactics as opposed to a site serving up an exploit.”
How do those big numbers translate into the actual families of malware that end up on user’s machines? You can get a pretty good idea by looking at data from Microsoft’s most recent Security Intelligence Report. The report contains two interesting top 10 lists representing threats faced by consumer and enterprise populations, respectively. In all, this combined list accounts for between 54% and 56% of all malware that was detected on Windows PCs by any Microsoft security product in 2010.
Let’s go through the list (note that because of overlap between the consumer and enterprise lists there are fewer than 20 entries here).
The biggest infection of 2010, by far, was Conficker. This is a worm that spreads via file shares, mostly on corporate networks. At its peak, it represented 22% of all infections detected on domain-joined computers.
Conficker’s means of propagation is a vulnerability in the Windows Server service. This vulnerability was fixed in October 2008 by Security Bulletin MS08-067, which patched Windows 2000, XP, Vista, Server 2003, and Server 2008. (Windows 7 was never affected.)  There’s no excuse for that patch not being installed nearly two years later, in 2010.
The lists contain multiple families classed as Trojans, which typically rely on social engineering to spread:
  • Frethog and Taterf are password-stealing Trojans that show up in both the consumer and enterprise populations. They were originally identified in May and June 2008, respectively.
  • Alureon (aka Zlob) is a data-stealing Trojan found mostly in the enterprise space. It dates all the way back to March 2007.
  • Renos is a family of fake security software that’s classified as a Trojan Downloader & Dropper, much like Mac Defender. It dates back to April 2007. FakeSpypro, a more recent variant, was originally identified in May 2010.
RealVNC, a legitimate remote terminal program, also made it on the list, under the category Potentially Unwanted Software. If it’s installed by an intruder, it can be used for malicious purposes. It was detected on more than 5% of domain-joined PCs.
In the consumer populations, four browser-based families of threats—not malicious, just annoying—made the Top 10 list. All are typically installed by means of social engineering.
  • Adware:JS/Pornpop.A, added to the encyclopedia in August 2010, isn’t a piece of software at all. It’s a snippet of script from a web page that is activated within an iFrame in any browser. Microsoft’s security software usually picks up on this one when it scans the browser’s cache.
  • Zwangi is a browser hijacker, first spotted in October 2009.
  • Hotbar, which has been around as long as I can remember, is an annoying adware program.
  • ClickPotato is a relatively new family of “multi-component adware” that displays pop-ups and ads. It often tags along with Hotbar.
The latter three programs are typically installed along with smileys and other bits of fluffy software aimed at noobs and rubes.
Finally, there are a family of interesting Trojans that combine social engineering with the AutoRun feature of USB drives and file shares:
  • Autorun is a generic worm that attempts to copy itself to mapped drives, then writes an autorun configuration file (Autorun.inf) pointing to the executable file. It’s usually accompanied by other malware variants
  • Rimecud is a backdoor that spreads by way of removable drives and instant-messaging programs.
  • Hamweq is an IRC-based backdoor program that spreads via flash drives.
The AutoRun feature doesn’t actually install the malware. Instead, it uses the AutoRun feature to open a dialog box that tries to trick the user into running an installer.
The behavior that made this social engineering possible was changedbefore Windows 7 was released. The behavior was modified in the same fashion for Windows XP and Windows Vista by means of Optional updates that were published in February 2009 (KB967940) and August 2009 (KB971029). As of February 2011, they are delivered as Important updates through Windows Update.
So add it all up. Among the top 10 threats in both the consumer and enterprise populations, one exploited a vulnerability that had been patched more than a year earlier, and the rest consisted of Trojans and worms that relied on social engineering to land on a victim’s PC.

Related : PART - 1  , PART - 3

Place an Ad