Thursday, September 3, 2009

Do you Skype?

Trojan Could Enable Attackers To Eavesdrop On Skype Calls
Exploit saves conversations as MP3 files to make detection more difficult, researchers say

Aug 28, 2009 | 04:55 PM
By Tim Wilson
DarkReading

Security researchers at Symantec have observed the public availability of source code for a Trojan that targets users of the Skype voice over IP service.

The Trojan has the ability to record audio from the computer -- including any Skype calls in progress -- and store the files locally in an encrypted MP3 file, where they can later be transmitted to the attacker.

The Trojan, which Symantec calls Trojan.Peskyspy, can be downloaded to a computer by tricking the user with an email scam or other social engineering tactic, Symantec says. Once a machine has been compromised, the threat can exploit an application that handles audio processing within a computer and save the call data as an MP3 file.

The MP3 is then sent over the Internet to a predefined server, where the attacker can listen to the recorded conversations, Symantec reports. "Recording the call as an MP3 keeps the size of the audio files low and means there is less data to be transferred over the network, helping to speed up the transfer and avoid detection," the company says.

The Trojan targets Windows API "hooks" -- a technique used to alter the planned behavior of an application, which Microsoft designed for use by audio applications. The Trojan compromises the machine and then uses the hooking technique to eavesdrop on a conversation before it even reaches Skype or any other audio application, Symantec says.

"At the moment, the risk posed by this threat is quite low, and Symantec has not seen any evidence of this spreading at this early time," the researchers say. "However, with source code now publicly available, malware writers can incorporate this type of functionality into their own customized threats."

Attack of the Tweets

Attack Of The Tweets: Major Twitter Flaw Exposed
U.K. researcher says vulnerability in Twitter API lets an attacker take over a victim's account -- with a tweet

Aug 27, 2009 | 03:54 PM
By Kelly Jackson Higgins
DarkReading

A newly exposed cross-site scripting (XSS) vulnerability in Twitter lets an attacker wrest control of a victim's account merely by sending him or her a tweet.

U.K. researcher James Slater reported the serious flaw earlier this week, and now says Twitter's fix in response to his disclosure doesn't actually fix the problem. "It seems they've made a pretty amateurish attempt to fix the issue, completely missing the massive problem staring them in the face," Slater said in his blog.

The attack basically exploits an input validation weakness in a field of the form used for adding third-party Twitter clients, such as TweetDeck and Twitterific. The form doesn't fully vet what can go in that box, Slater said, so an attacker can put JavaScript tags there as well as raw HTML code, for instance. "Whatever I type in that box will appear at the end of my tweets," he blogged in a follow-up post. "Anyone who sees that tweet will then be viewing that code."

The embedded code can perform any tasks the Twitter Website can perform, including redirecting a user to another page, sending tweets, changing account information, or adding or deleting followers, he said.

"Simply by seeing one of these tweets, code can be run inside your browser impersonating you and doing anything that your browser can do. Perhaps it may simply redirect you to a pornographic website? Or maybe delete all of your tweets? Send a message to all of your friends? Maybe it would delete all of your followers, or worse still, just send the details needed to log in to your account off to another website for someone to use at their leisure," Slater said.

Twitter's patch basically prevents people from putting spaces in that box, he said, which didn't go far enough. It left the door open for attackers to put any other code there, he said.

The best defense from this attack, he says, is to run a Twitter third-party client rather than logging into Twitter's Website directly, and to "unfollow" people you don't know or don't trust. "If you don't see their tweets they can't harm you," Slater blogged.

Twitter had not responded to media inquiries about the bug as of this posting.

It has been a tough summer for Twitter security-wise. Researcher Aviv Raff hosted the Month of Twitter Bugs in July, aimed at exposing vulnerabilities in third-party Twitter applications. Among other problems, Twitter was hit by a massive DDoS attack earlier this month that knocked the popular microblogging site offline for hours, and then a researcher discovered a Twitter profile being used as the command center for a botnet. The profile was sending updates and malware to bots.

Sears has a problem!

Flaw In Sears Website Left Database Open To Attack
Business-logic flaw in Sears.com Web application could have let hackers brute-force attack the retailer's gift card database

Sep 01, 2009 | 03:49 PM
By Kelly Jackson Higgins
DarkReading

A newly discovered vulnerability on Sears.com could have allowed attackers to raid the retail giant's gift card database.

Alex Firmani, owner of Merge Design and a researcher, this week revealed a major security hole on Sears.com that could allow an attacker to easily steal valid gift cards -- a heist he estimates could be worth millions of dollars. Firmani says he alerted Sears about the flaw, and that Sears has since "plugged" the hole by removing the feature that let customers verify and check their gift-card balances.

The vulnerability was a business logic flaw in a Web application that handles gift card account inquiries; Firmani was able to stage a brute-force attack that could grab all valid, active Sears and Kmart gift cards from the company's database.

Firmani says the site wasn't auditing verification requests, which allowed him to verify gift card and PIN combinations using a homegrown PHP script that automatically submitted the requests. "I wrote a PHP script to hammer their verification server. It happily replied with thousands of verification responses per minute," he says.

The Sears application relied on client-side cookies to halt brute-force verification attempts, which Firmani says wasn't effective. "They should know where the verification requests come from, log them all, and be able to disable the verifications when they have a malicious attack," he says. "It doesn't appear to me that they had any server-side control over how many verifications were done."

Jeremiah Grossman, CTO of WhiteHat Security, says this type of flaw is probably fairly common on retailer Websites. And unlike a cross-site scripting or SQL injection bug, this business logic flaw is different: "It basically lets an attacker defraud Sears.com directly," Grossman says.

Firmani's discovery came on the heels of reports of multiple cross-site scripting (XSS) vulnerabilities on Sears' Web pages that were abused by an attacker to deface the Website.

"I thought this was notable with Sears being a Fortune 50 company," he says. "I have not tested many other large retailers, but I would hope most of them take better care than this. For smaller sites that write their own gift-card verification code, I'd expect just as many are vulnerable."

Firmani, who says he discloses Website flaws to site owners in order to highlight common Web application security issues, suggests that Sears require a valid user account login before allowing a verification request to be sent. "You could then record the number of verification requests and lock out any offending accounts automatically and without relying on client-side cookie," he wrote in his disclosure paper. "Recording requests server-side would be a more reliable way of handling repeat request offenders."

Another option is recording to a server-side database IP addresses of users verifying their gift cards, he said, as well as using a "number-used once" scheme in the verification form or logging all verification requests and using a script to shut down the response server if more than a specifically designated number of requests arrive per minute, he said.

"Security these days is less about what version of Apache you're running and more about custom-written Web applications. With Web apps given unfettered database access, it becomes a simple matter of exploiting less-than-solid Web application programming," Firmani says. "Finding holes in home-brewed Web app code is much easier than exploiting a root-escalation bug on a Linux server, but both often have similar database access."

Facebook troubles??

Facebook scam tricks Missouri woman

Beware scammers posing as friends.

A Missouri woman was tricked into wiring about $4,000 to someone in England after receiving faked messages from a friend on Facebook asking for help.

The Associated Press reports that Jayne Scherrman of Cape Girardeau wired about $4,000 to someone in England in response to faked messages supposedly from a friend on Facebook.

Police think someone took over the Facebook account of another Cape Girardeau County resident, Grace Parry, changed the password so she couldn't get to her account, and send messages saying she and her husband were stranded in London and needed money.

Scherrman, a dentist, said Parry and her minister husband went on mission trips, so she didn't think it unusual that they would be in England, or might need money till they could get home.

Parry, who hadn't traveled to England in years, eventually tried to access her account to warn other friends but couldn't, the AP reported. She asked Facebook to suspend her account, and her husband posted warnings about the scam, including one Scherrman received after she'd sent the money.

The police said people should remember to change their passwords often for Facebook and other online services, and to be careful about posting personal information.
Submitted by Greg Hack on September 3, 2009 - 7:19am.

Wednesday, September 2, 2009

New virus on the net today!

A new virus on the net watch out for an e-mail from DHL do not open that tracking code attachment. The attachment has a virus!

Monday, August 17, 2009

A piano man in Kansas City

Did you know that the fine art of tuning or fixing a piano is one that very few people know how to do. The ability to use your hearing and your touch to fine tune a very expensive and usually beautiful piano is perhaps a dying art.

In Kansas City, one of our customers has learned that art and is a master at it. We created a web page for him but that is secondary to his reputation and his ability. If you have a chance visit our customer at http://www.note2notepiano.com/ please feel free to visit our customer and learn more about him.

A customer using a discussion board

Our customer Lake Mary Center in Paola, Kansas(www.lakemaryctr.org)is using a discussion board we set up for them to share information across their entire area network. The employee board will be used for ideas and for group meetings to share information. The board will save time and money in travel and will make the groups more productive. Please feel free to visit www.lakemaryctr.org for more information about them.