Sunday, September 18, 2011

Windows 8 to have built-in anti-virus - there's good and bad news



Microsoft will ship Windows 8 with built-in anti-virus software.
That's the big news that is no doubt being discussed furtively at the watercoolers of computer security companies around the world today.
What will it mean to them? A quick glance at Twitter reveals that some people already have pretty good ideas about how the news might have been received..

Jason Hughey
Microsoft announces Windows 8 has anti-virus/anti-malware built in. Loud screams are heard from Symantec/Norton and McAfee headquarters!
But seriously, is this good news for the existing anti-virus companies and - more importantly - consumers?
Microsoft Security EssentialsMicrosoft has been making a free anti-virus software available for a couple of years, in the form of Microsoft Security Essentials. But you had to download it from the internet - it wasn't bundled with Windows itself.
Microsoft has been bundling a program called Windows Defender with Windows 7, Windows XP and Vista, but it doesn't really compare to a proper anti-virus product.
With Windows 8, it sounds as if Windows Defender will be beefed up to incorporate the functionality of Microsoft Security Essentials. Effectively, Windows 8 users will be getting out-of-the-box protection against malware, as well as a firewall and parental controls.
So, it's a case of good news and bad news.

Good news for..

Consumers. Anything which encourages Joe User to run up-to-date anti-virus software has to be a positive thing. There are too many poorly protected home computers out there, which have been commandeered into botnets.
Windows Defender running on Windows 8
But at the same time it's also good news for..
Malware authors. You don't think they're going to ignore this development, do you? If most budget-conscious home users stick with Microsoft's built-in offering, then surely the first thing the bad guys will do is make sure their latest creation can slip past Microsoft's scanner.
No doubt they'll have a new template for their fake anti-virus alerts too.

Bad news for..

Security vendors. It's bad news for those security vendors who rely heavily on consumer sales of their software. It's questionable as to whether many home users will want to reach into their pockets and pay for security from them if there's already one built into Windows 8.
Frankly, it's their own fault. The two big security hippopotamuses have had years of opportunity to gobble up the end-user market, and yet still millions of home users were infected by malware, spyware and pop-ups each year.
It's understandable that Microsoft want to clean up the image of Windows - and if commercial anti-virus vendors haven't managed to do the job, then why shouldn't they do it themselves?
Microsoft's plans for Windows 8 might mean knee jerk reactions from some vendors, and even perhaps more price-cuts and giveaways in an already aggressive market.
I wouldn't be surprised if the legal eagles at rival security firms accused Microsoft of anti-competitive practices, and forced the software giant to offer users security products from a selection of different vendors, just
just as happened in the case of Internet Explorer.
Browser choice screen
But it's not just some security vendors who may struggle, with Microsoft's decision. There's another group who may find life isn't too rosey in the Windows 8 world..
Consumers. Yes, it could be bad news for users too. At least some of them. The thought of running the same anti-virus product as every other home user on the planet, gives me shivers. A security monoculture is not a good thing.
Clued-up folks may well choose to use a non-Microsoft anti-virus (either free or commercial) just to not go with the crowd.
We certainly live in interesting times.
Me? I welcome Microsoft doing more to protect home users from the huge problem of malware, but at the same time I'm pleased to say I don't work for a company which relies on anti-virus sales to home users.

Will Windows 8's new interface herald full-screen scareware?



Microsoft has designed a new user interface for Windows 8, with an emphasis on bright colours and friendliness.
Personally, the interface (dubbed "Metro") reminds me of a child's toy.
Windows 8 and Simon toy
One of the interesting features of the Metro user interface is that apps are designed to be full-screen, without any surrounding furniture. That means you won't see scroll bars and the like, unless you interact with the interface.
One has to wonder whether this will lead to a wave of new scareware/fake anti-virus attacks.
Currently, malicious hackers poison webpages to display what appears to be a warning about malware found on your computer - tricking users into downloading software. The initial alert pops up in your web browser.
Fake anti-virus alert on older version of Windows
These phony alerts have proven to be a very effective way for cybercriminals to fool users into installing their malicious scareware. And it's very likely we'll continue to see hackers trick your browser into displaying bogus warning messages
But, with Windows 8, these browser-based fake anti-virus warnings will be shown full-screen, without the tell-tale visible signs that you're in a browser.
That means it may be even easier to convince a victim into believing they are viewing a genuine security alert from the operating system rather than simply a webpage pretending to be one.
Some will argue, no doubt, that Window 8's Metro simplistic interface is a sign of progress, making the use of computers less threatening to those who are currently put off by complicated GUIs.
The view may be that people get confused between operating systems, apps and browsers - why not make them all look the same?
But these are the very people who are, perhaps, most likely to be tricked into believing that a fake anti-virus alert is genuine and blindly do whatever the computer screen is advising them to do.
It will certainly be interesting to see how cybercriminals evolve their social engineering attacks to take advantage of a Windows 8 Metro-interfaced world.

Blue screens, cute screens

One thing we've already seen is how Microsoft has - after many years - revamped their infamous blue screen of death. Now it's a cute screen of death instead (and a slightly different shade of blue).
Blue screen of death - is this progress?
Wow, that's real progress..
One wonders if the blue screen itself will become an attractive disguise for scammers and malicious hackers.
Will they attempt to duplicate the look of the now oh-so-friendly blue screen of death by popping it up in full screen browser sessions, tricking users into making bad decisions?
One thing we can be sure of - if the bad guys think they will make money effectively this way, they'll do it.

Fake FBI Anonymous psychological profile: a lesson to all internet users



The faceless power of Anonymous rages on.
Like headless horsemen, they gallop across the internet, intent on causing massive headaches and embarrassment for some, while keeping their fans and the media informed via social media.
Sounds even too good for a Hollywood movie plot. You couldn't make it up.
But it turns out that someone did make up the recently disclosed FBI document 'Psychological Profile of the Anonymous Key Personalities'[PDF].
And the story was covered by several reputable media outlets, though admittedly some voiced skepticism.
On September 8, Anonymous used Twitter and Tumblr to distribute the fake document.
The question is why did anyone ever think it was real?
  • Why would Anonymous leak a document that would put their esteemed leaders at risk?
  • Why would the FBI actually use Wikipedia as their sole information source for Anonymous's background?
  • The codename for the field informant is Marotte (which means prop stick, dummy head or fad)
  • Looking at the copious typos and grammar glitches in the document, would the FBI have a profiler without a basic grasp of written communication?
Fake FBI profile of Anonymous
So all this made us at Naked Security a bit suspicious at the time. So no surprise that this so-called FBI document turns out that it is a fake.
The thing is though, it does make for interesting lunchtime reading. I absolutely love some of the profiles in this faux document.
It defines "Kayla" as a violent, amoral bisexual with an inferiority complex, and "Topiary" as a youthful, obsessive idealist, possibly afflicted with Aspergers.
Forgive the quasi-psychology here - couldn't a fake document, if indeed it is written by the Anonymous leaders, be used to help the FBI and other authorities better understand the collective? What seems like nonsense to its authors could accidentally reveal some interesting insights for those that analyse and pigeon-hole personalities.
That said, some of you might remember that great article by Malcolm Gladwell where he concludes that criminal profiling isn't all that helpful to the capture of wanted criminals.
So what is the upshot? Whoever is involved in writing this didn't waste the FBI's time with this forgery, because they must have been aware from the get-go that this did not originate from their internal team.
Those responsible for the document did however manage to get the internet, media and bloggers yacking about it. Yes, even me. Anonymous have notoriety because many people have written about it. And if Anonymous did indeed pull this together, they have just lied to their online followers. tsk tsk.
Please, can we all make sure we take this collective's word with a grain of salt next time?

SpyEye targeting Android users - just a copy of Zeus's strategy?

In the world of Windows malware, SpyEye is a widespread malicious toolkit for creating and managing botnets. It is designed primarily for stealing banking credentials and other confidential information from infected systems.
SpyEye is a major competitor of the infamous Zeus toolkit.
Zeus (also known as ZBot) generated a lot of interest in the mobile security community a couple of months ago when an Android version was discovered.
Of course, we did not have to wait long before a version of SpyEye targeting Android was also developed, and sure enough a malicious SpyEye Android app was discovered a few days ago.
The functionality of Zeus and SpyEye on Windows is quite similar, so I was curious as to how similar their respective Android versions would be.
Zeus for Android purports to be a version of Trusteer Rapport security software. This social engineering trick is used in an attempt to convince the user that the application they are installing is legitimate.
SpyEye for Android, now detected by Sophos products as Andr/Spitmo-A, uses a slightly different but similar social engineering technique.
When the user of a PC infected by the Windows version of SpyEye visits a targeted banking website, and when the site is using mobile transaction authorization numbers, the SpyEye Trojan may inject HTML content which will instruct the user to download and install the Android program to be used for transaction authorisation.
The SpyEye application package does not show up as an icon in the "All apps" menu, so the user will only be able to find the package when the "Manage Applications" is launched from the mobile device's settings.
The application uses the display name "System" so that it seems like a standard Android system application.
SpyEye for Android installed
When installed, Zeus for Android displayed a fake activation screen, and Spitmo is again very similar.
However, Spitmo uses different tactics to convince the user that it is a legitimate application.
It applies for the following Android permissions:
android.provider.Telephony.SMS_RECEIVED
android.intent.action.NEW_OUTGOING_CALL
This allows the malware to intercept outgoing phone calls.
When a number is dialed, the call is intercepted before the connection is made and the dialed phone number is matched to a special number specified by the attacker in the alleged helper application installation instructions.
If the number matches, Spitmo displays a fake activation number, which is always 251340.
SpyEye for Android - fake activation
Once installed, the functionality of Zeus and SpyEye are pretty much the same.
A broadcast receiver intercepts all received SMS text messages and sends them to a command and control server using an HTTP POST request. The submitted information includes the sender's number and the full content of the message.
So far, it does not seem that this attack is widespread, but it shows that the developers of major malicious toolkits are closely watching their competition and matching the latest features.
It also seems that support for Android is increasingly becoming an important part of their product strategy.

Oracle issues rare out-of-band update for Apache DDoS vulnerability



Oracle, the giant enterprise database company - and, of course, owner of the erstwhile Sun Microsystems - has just published an out-of-band security update.
This is only the fifth time Oracle has issued an alert outside its routine quarterly patch cycle since introducing its own version of Patch Tuesday at the start of 2005.
The update introduces an updated version of the Apache web server, httpd, to Oracle's Fusion Middleware and Application Server products. The former product includes Apache httpd 2.2; the latter includes Apache httpd 2.0.
Apache httpd was recently discovered to be vulnerable to an easily-exploiteddenial of service attack. The vulnerability, CVE-2011-3192, allowed even a single web client to trigger a huge number of simultaneous requests for large amounts of data. The flaw was exploited by sending a request for multiple parts of the same file at the same time.
(The Range feature of the HTTP protocol was intended to make it easy for web clients to restart interrupted downloads where they left off, or to permit large files to be fetched piecemeal and stitched together later. Apache httpd made it easy to misuse this feature by tolerating redundant Range requests which asked for many large and overlapping parts of a single file.)
Oracle doesn't say on its public-facing web pages exactly how it patched the flawed Apache versions in its products.
The Apache Software Foundation has actually issued two official patches for httpd 2.2 relevant to the so-called byte-range flaw. Version 2.2.20 came out at the end of August, but that patch was recently superseded by 2.2.21, which is effect a patch for the 2.2.20 patch. Apache describes 2.2.21 as "[including] fixes to the patch introduced in release 2.2.20 for protocol compliance, as well as the MaxRanges directive."
It's not clear whether Oracle's out-of-band fix includes the patch-to-the-patch, which appeared only three days ago.
And the previous official Apache httpd version, 2.0, hasn't been patched since May, when 2.0.64 came out. Oracle, one assumes, has done its own back-port of the fix it applied to 2.2.
The fact that a patch-to-the-patch was necessary will no doubt cause more conservative IT administrators to say, "See. I told you that patches should never be rushed."
In this case, however, I consider the glass half-full, not half-empty. I'd argue that the first patch greatly improved the situation, despite being imperfect. The second patch simply improved the improvement further.
However conservative you might be, if you're an Oracle user, this patch is definitely recommended in a hurry. The general unwillingness of Oracle to deviate from its once-every-three-months patch cycle spells one word, "Importance."
As Oracle itself points out, in bold characters:
Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Security Alert fixes as soon as possible.
Sysadmins, there you have it. A little something for the weekend!

Monday, September 5, 2011

SSL certificate debacle includes CIA, MI6, Mossad and Tor

SpyLast week I wrote about the compromise of digital certificate authority DigiNotar. While the idea of over 250 false certificates being issued was scary, the number has grown to 531, including what could be intermediate signing certificates.
This is really bad news. As DigiNotar is a "root" certificate, they can assign authority to intermediaries to sign and validate certificates on their behalf.
It appears the attackers signed 186 certificates that could have been intermediate certificates. These certificates masqueraded as well-known certificate authorities like Thawte, Verisign, Comodo and Equifax.
The expanded list of domains for which fraudulent certificates were issued includes Facebook, Google, Microsoft, Yahoo!, Tor, Skype, Mossad, CIA, MI6, LogMeIn, Twitter, Mozilla, AOL and WordPress. A complete list can be downloaded from the Tor website.
The attackers also issued themselves certificates for *.*.com and *.*.org. I am not sure if a multi-wildcard certificate like this is valid, but if so it could allow them to impersonate anything.
Tor logoAccording to the blog post on the Tor project's website, they also left a message in Farsi. Loosely translated, it reads "great cracker, I will crack all encryption, i hate/break your head."
This incident makes me feel more justified than ever in my distrust of the certificate system. While Mozilla, Google and others have been quick to permanently remove DigiNotar as a trusted authority, in this case it is too little, too late.
Currently computer users of IE and Safari on Windows 7/Vista/2008/2008R2, or Chrome and Firefox on any platform, are protected against exploitation as long as they are fully patched.
Mac OS X users using the latest Chrome and Firefox (6.0.2) versions are fine, but Safari and OS X itself have not been patched. There are instructions on doing so on the ps | Enable blog, although it is non-trivial.
More concerning is that mobile users are being left in the dark. There have been no updates, and no manual removal method for Android or iPhone/iPad/iPod Touch users who haven't jailbroken/rooted their devices.
Tap, tap, tap... Hello, Apple? Are you there? Your competitors (Microsoft, Google, Mozilla) are protecting their customers promptly and openly. I know you don't like to talk about security, but now would be a great time to show you care.

DNS hack hits popular websites: Daily Telegraph, The Register, UPS, etc

Popular websites including The Register, The Daily Telegraph, UPS, and others have fallen victim to a DNS hack that has resulted in visitors being redirected to third-party webpages.
Web security tester Paul Mutton managed to capture a screenshot of what visitors to The Register saw:
Message seen by visitors to www.theregister.co.uk. Image credit @paulmutton
Part of the message reads:
TurkGuvengligi
"Gel Babana"
HACKED
"h4ck1n9 is not a cr1m3"
"4 Sept. We TurkGuvenligi declare this day as World Hackers Day - Have fun ;) h4ck y0u"
The phrase "Gel Babana" is Turkish for "Come to Papa", and "Guvenligi" is Turkish for "Security".
Further websites which have been affected by the DNS hack include National Geographic, BetFair, Vodafone and Acer.
It's important to note that the websites themselves have *not* been hacked, although to web visitors there is little difference in what they experience - a webpage under the control of hackers.
Instead of breaching the website itself, the hackers have managed to change the DNS records for the various sites affected.
PhonebookDNS records work like a telephone book, converting human-readable website names like nakedsecurity.sophos.com into a sequence of numbers understandable by the internet. What seems to have happened is that someone changed the lookup, so when you entered telegraph.co.uk or theregister.co.uk into your browser you were instead taken to a website that wasn't under the control of those websites.
Because of the way that DNS works, it may take some time for corrected DNS entries for the affected websites to propagate worldwide - meaning there could be problems for some hours ahead. If you're in the habit of visiting and logging into the affected sites, you might be wise to clear your cookies so the hackers aren't able to steal any information from you.
In many ways we have to be grateful that the message displayed appears to be graffiti, rather than an attempt to phish information from users or install malware.
The question now is how did the hackers manage to change the DNS records for these sites?
Here's a statement The Register published about the incident:
Statement from The Register
Image credit: @paulmutton.
Update: The Register has tweeted that its DNS records have been returned to normal.

The Register
So our DNS records have been restored to normality. Still no word from our provider.
As noted above, however, it may take some hours before the fix propagates around the net.