Thursday, September 3, 2009

Attack of the Tweets

Attack Of The Tweets: Major Twitter Flaw Exposed
U.K. researcher says vulnerability in Twitter API lets an attacker take over a victim's account -- with a tweet

Aug 27, 2009 | 03:54 PM
By Kelly Jackson Higgins
DarkReading

A newly exposed cross-site scripting (XSS) vulnerability in Twitter lets an attacker wrest control of a victim's account merely by sending him or her a tweet.

U.K. researcher James Slater reported the serious flaw earlier this week, and now says Twitter's fix in response to his disclosure doesn't actually fix the problem. "It seems they've made a pretty amateurish attempt to fix the issue, completely missing the massive problem staring them in the face," Slater said in his blog.

The attack basically exploits an input validation weakness in a field of the form used for adding third-party Twitter clients, such as TweetDeck and Twitterific. The form doesn't fully vet what can go in that box, Slater said, so an attacker can put JavaScript tags there as well as raw HTML code, for instance. "Whatever I type in that box will appear at the end of my tweets," he blogged in a follow-up post. "Anyone who sees that tweet will then be viewing that code."

The embedded code can perform any tasks the Twitter Website can perform, including redirecting a user to another page, sending tweets, changing account information, or adding or deleting followers, he said.

"Simply by seeing one of these tweets, code can be run inside your browser impersonating you and doing anything that your browser can do. Perhaps it may simply redirect you to a pornographic website? Or maybe delete all of your tweets? Send a message to all of your friends? Maybe it would delete all of your followers, or worse still, just send the details needed to log in to your account off to another website for someone to use at their leisure," Slater said.

Twitter's patch basically prevents people from putting spaces in that box, he said, which didn't go far enough. It left the door open for attackers to put any other code there, he said.

The best defense from this attack, he says, is to run a Twitter third-party client rather than logging into Twitter's Website directly, and to "unfollow" people you don't know or don't trust. "If you don't see their tweets they can't harm you," Slater blogged.

Twitter had not responded to media inquiries about the bug as of this posting.

It has been a tough summer for Twitter security-wise. Researcher Aviv Raff hosted the Month of Twitter Bugs in July, aimed at exposing vulnerabilities in third-party Twitter applications. Among other problems, Twitter was hit by a massive DDoS attack earlier this month that knocked the popular microblogging site offline for hours, and then a researcher discovered a Twitter profile being used as the command center for a botnet. The profile was sending updates and malware to bots.

Sears has a problem!

Flaw In Sears Website Left Database Open To Attack
Business-logic flaw in Sears.com Web application could have let hackers brute-force attack the retailer's gift card database

Sep 01, 2009 | 03:49 PM
By Kelly Jackson Higgins
DarkReading

A newly discovered vulnerability on Sears.com could have allowed attackers to raid the retail giant's gift card database.

Alex Firmani, owner of Merge Design and a researcher, this week revealed a major security hole on Sears.com that could allow an attacker to easily steal valid gift cards -- a heist he estimates could be worth millions of dollars. Firmani says he alerted Sears about the flaw, and that Sears has since "plugged" the hole by removing the feature that let customers verify and check their gift-card balances.

The vulnerability was a business logic flaw in a Web application that handles gift card account inquiries; Firmani was able to stage a brute-force attack that could grab all valid, active Sears and Kmart gift cards from the company's database.

Firmani says the site wasn't auditing verification requests, which allowed him to verify gift card and PIN combinations using a homegrown PHP script that automatically submitted the requests. "I wrote a PHP script to hammer their verification server. It happily replied with thousands of verification responses per minute," he says.

The Sears application relied on client-side cookies to halt brute-force verification attempts, which Firmani says wasn't effective. "They should know where the verification requests come from, log them all, and be able to disable the verifications when they have a malicious attack," he says. "It doesn't appear to me that they had any server-side control over how many verifications were done."

Jeremiah Grossman, CTO of WhiteHat Security, says this type of flaw is probably fairly common on retailer Websites. And unlike a cross-site scripting or SQL injection bug, this business logic flaw is different: "It basically lets an attacker defraud Sears.com directly," Grossman says.

Firmani's discovery came on the heels of reports of multiple cross-site scripting (XSS) vulnerabilities on Sears' Web pages that were abused by an attacker to deface the Website.

"I thought this was notable with Sears being a Fortune 50 company," he says. "I have not tested many other large retailers, but I would hope most of them take better care than this. For smaller sites that write their own gift-card verification code, I'd expect just as many are vulnerable."

Firmani, who says he discloses Website flaws to site owners in order to highlight common Web application security issues, suggests that Sears require a valid user account login before allowing a verification request to be sent. "You could then record the number of verification requests and lock out any offending accounts automatically and without relying on client-side cookie," he wrote in his disclosure paper. "Recording requests server-side would be a more reliable way of handling repeat request offenders."

Another option is recording to a server-side database IP addresses of users verifying their gift cards, he said, as well as using a "number-used once" scheme in the verification form or logging all verification requests and using a script to shut down the response server if more than a specifically designated number of requests arrive per minute, he said.

"Security these days is less about what version of Apache you're running and more about custom-written Web applications. With Web apps given unfettered database access, it becomes a simple matter of exploiting less-than-solid Web application programming," Firmani says. "Finding holes in home-brewed Web app code is much easier than exploiting a root-escalation bug on a Linux server, but both often have similar database access."

Facebook troubles??

Facebook scam tricks Missouri woman

Beware scammers posing as friends.

A Missouri woman was tricked into wiring about $4,000 to someone in England after receiving faked messages from a friend on Facebook asking for help.

The Associated Press reports that Jayne Scherrman of Cape Girardeau wired about $4,000 to someone in England in response to faked messages supposedly from a friend on Facebook.

Police think someone took over the Facebook account of another Cape Girardeau County resident, Grace Parry, changed the password so she couldn't get to her account, and send messages saying she and her husband were stranded in London and needed money.

Scherrman, a dentist, said Parry and her minister husband went on mission trips, so she didn't think it unusual that they would be in England, or might need money till they could get home.

Parry, who hadn't traveled to England in years, eventually tried to access her account to warn other friends but couldn't, the AP reported. She asked Facebook to suspend her account, and her husband posted warnings about the scam, including one Scherrman received after she'd sent the money.

The police said people should remember to change their passwords often for Facebook and other online services, and to be careful about posting personal information.
Submitted by Greg Hack on September 3, 2009 - 7:19am.

Wednesday, September 2, 2009

New virus on the net today!

A new virus on the net watch out for an e-mail from DHL do not open that tracking code attachment. The attachment has a virus!

Monday, August 17, 2009

A piano man in Kansas City

Did you know that the fine art of tuning or fixing a piano is one that very few people know how to do. The ability to use your hearing and your touch to fine tune a very expensive and usually beautiful piano is perhaps a dying art.

In Kansas City, one of our customers has learned that art and is a master at it. We created a web page for him but that is secondary to his reputation and his ability. If you have a chance visit our customer at http://www.note2notepiano.com/ please feel free to visit our customer and learn more about him.

A customer using a discussion board

Our customer Lake Mary Center in Paola, Kansas(www.lakemaryctr.org)is using a discussion board we set up for them to share information across their entire area network. The employee board will be used for ideas and for group meetings to share information. The board will save time and money in travel and will make the groups more productive. Please feel free to visit www.lakemaryctr.org for more information about them.

Sunday, August 16, 2009

A new Rossini.com option

RMS now offers a content management package. What will this do for you or can do for you:

If you can hand code HTML you can build custom content management systems... no programmer required!

Save time by updating some of your own content

Be more efficient by being faster and having the ability to react faster by making your own changes.

These are just a few of the features available, call us today at 913-533-4098 and we will tell you more about this new and outstanding tool.