Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Dec 30, 2010

Trojan attacks were mobile Android.


Recent news reports. Blog of Lookout Inc. the official U.S. warning users to beware virus "Trojan, " the recently discovered called Geinimi the target to the platform, mobile (smart phone, tablet, etc.) using the system. The origins of the Android operating Geinimi Trojan from China and malware that Android is the most complex work ever found.

Reports from Lookout company security experts on a smart phone indicates Geinimi Trojan to access personal information on the Android smart phone users, including executing malicious code. Equipment attached to it to be controlled by the server of Trojan is a fully connected through the Internet. But the point of scary. And to alert the user is Geinimi Trojan Virus will lie within the application is open for download right now is the Apple Store in China, which are mostly games like Money Jump 2, President vs. Aliens, City Defense. And Baseball Superstars 2010.
 
However, the Lookout was updated de Phoenix Partnership said the virus. To help protect users from applications that come with these viruses. For more information, please visit the blog Lookout best way is to download the app from the Android Marketplace is better.

Information from : ARIP, Lookout.

PS3 hacked to use non-USB.


PS3 Slim, after removing the support to Linux. Hackers around the world is interested in PS3 hacking increasingly in 27C3 fail0verflow team also announced that the team is key to decrypt the signature to verify the accuracy of the software that runs on the PS3 will be successful.

Team found that the encoding parameters for a number of Sony to live. Code should be a random number to a fixed number. Enables teams to remove the key equations and default should be kept only in the Sony.

Fail0verflow team can not demonstrate the functionality of this bug at this time. Because software problems that have not already. If this vulnerability is real. It will open the way for a PS3 Slim to Linux or any other software. The Sony can not update to solve the problem and does not require any additional hardware.

Source - Blognone, PSGroove.


Dec 29, 2010

McAfee 2011, the threat alert: Mobile, Apple began target.


McAfee released its report 2011 Threat Predictions Report (PDF) predicted global threats on IT next year. Divided into the following issues.

Social Media.

2010, the threat of spam has decreased. Because people turn to each other using social media instead of the target next year is like a second.

    * Short URL Service: Current Use of a short URL link to a fake and then some. But next year we will see more disasters like this. Including a post with a short URL threat to service other than with social media.
    * Please note their location service: whether it is a Foursquare, Gowalla, Facebook Places, if not being aware of opportunities out there.

      Mobile.

The threats came through on the phone not much Neu (such as Android or rootkit on the vulnerability of the jailbreak on the iPhone), but McAfee predicted that the year 2011 will be a major turning point. And we see the threat of a new mobile. Pop up a lot.

Apple

In the past, Mac OS X platform is not very targeted. But when the user base more. As well as other products like the iPad and Apple's iPhone will make their products more at risk. By bringing iPad / iPhone to use in-house. That may be very little impact if critical information out to.

Applications.

New products like Google TV app may be secretly pulling some important information or personal information. And the app used to control devices or systems. Remote is the most security vulnerabilities. Apple to accelerate the development of the market may cause security issues as well.

And more complex threats.

    * We will see the fake hide file signed by the same file more genuine.
    * Techniques to steal a key or a new fake keys.
    * "Friendly fire" or that someone being pierced friends and then reconcile the social network.
    * "Smart bomb" attack that will only occur in an environment where the only

Botnet.

Originally botnet to borrow another machine to use as a base to shoot, but collapsed this year, McAfee expects to remove the botnet machines that stick it out with Although officials will use those laws more, but let botnet botnet will be developed to circumvent the measures themselves as well as the combination of the two botnet name is Zeus and SpyEye.

Last botnet uses social network such as the base for a spread.

The hacking system

We will see that hacking is motivated more by politics. Including the hackers gathered independently Not under the influence of a particular country as the government's case and Anonymous WikiLeaks.

The trend of hackers to go from working alone. A loose organization (eg, common shot DDoS) and developed a hierarchical organization with clear

Advanced Persistent Threats.

Advanced Persistent Threats or APT is the name for a new threat that has been supported by a particular country is a clear example of Operation Aurora that Google had collapsed this year. Organizations with high data security. (May include the law firm of large multinational companies) have to be careful with this type of attack.

Source - Blognone, McAfee Labs.


Apple being sued for alleged release was as an iPhone / iPad personal information to use


Was an issue, mobile access to personal information without permission. It is in the news ever. Apple said last being Jonathan Lalo in Los Angeles a lawsuit that the iPhone and iPad UDID only a number in each device. Allows advertisers to "track" the behavior of each user has.

Mention in the complaint, Apple pulled the 4 profile to include Pandora, Paper Toss, the Weather Channel, and Dictionary.com. The developer of this app is a co-defendant with Apple.

Source - Blognone, BusinessWeek.

Dec 21, 2010

Android engineer said, "We are intending to be the Root device Nexus S".


Nick Kralevich engineer security response team out Android News Nexus S is the root of Engadget, which commented that the root Nexus S because the safety of Android is not good enough.

Nick Kralevich posted via Android Developers Blog, and that the Nexus S Nexus One is designed to install firmware from other easily, just add only fastboot oem unlock it successfully. So do not think of Android security problems at all.

He also said that now there is no way that meet the needs of the network lock without root machine and called the hardware manufacturer and service provider networks. Developing better ways to present more.

Source - Blognone, Android Developers Blog

Dec 17, 2010

Disclose the password of the popular Web site Gawker network that was hacking out and then be published.


After news sites Gizmodo and Gawker network being pierced and password for all users than 188,279 accounts have been published to the Internet.

Later, the Wall Street Journal has compiled statistics of the most popular password that accompanies your username. (often used to duplicate the code) out by 50 combinations of passwords is the most popular are.

* 3000 user account password 123456 as well.
* 2000 user account using the word password as the password.
* 1000 user account password 12345678 as well.
* 1000 user account password lifehack as well.
* 500 user account password qwerty as well.
* 5000 user account password abc123 as well.

There are other statistics. More relevant. See the link for the source.

Source - Blognone, Wall Street Journal via Socialtimes.