Pages

Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Thursday, 23 April 2015

Hackers Can Continuously Restart Your iOS Device Thanks to New Exploit

Hackers Can Continuously Restart Your iOS Device Thanks to New Exploit
Security researchers have discovered a vulnerability in Apple’s iPhone and iPad operating system that could let a hacker continuously crash either device as many times as they want.
Discovered by researchers at mobile security firm Skycure, the vulnerability is activated when you connect to an unknown open Wi-Fi hotspot (something you should never do in the first place), which the the hacker can then use to take control of several functions on your device. 
Once you’re on the network, a hacker sends your iOS device an SSL certificate, which allows a device to talk with an app or website securely. Think of an SSL as something that lets your phone communicate with an app’s servers without anyone listening in.
In this instance, though, the SSL is purposely flawed, letting the hacker use their exploit to force any app using SSL to crash for no apparent reason.
The researchers at Skycure soon realized that they could crash not only apps, but also entire iPhones or iPads, causing the devices to enter a seemingly endless restart cycle that prevents you from either device at all.
The researchers said they were also able to combine the SSL certificate vulnerability with another hack that forces iOS users to automatically connect to specific Wi-FI networks. 
In this instance, a hacker could force your iPhone to connect to their network and then start using the SSL certificate vulnerability to keep shutting down and restarting your iPhone.
The Skycure researchers refer to this practice as creating a “no iOS zone,” since any iOS device within range could be impacted. The only way to stop the cycle would be to leave the malicious network’s Wi-Fi range.
Skycure says the easiest way to avoid this issue is to stay away from unknown Wi-Fi networks and make sure you’re always running the latest iOS updates. Though they said they’ve reached out to Apple to let them know about the issue, Skycure says they still haven’t received a response.
This isn’t the first vulnerability discovered in Apple’s iOS, which execs have often boasted is far more secure than competitor Android. In the past, the software has been found to other security issues, though Apple is always quick to address them.
In this case, Apple will likely fix the vulnerability and move on.
Seriously though, the best thing you can do is stay away from connecting to any free Wi-Fi networks you aren’t familiar with. In addition to opening you up to a silly vulnerability like this, free, open Wi-Fi connections can also let hackers see much of what you’re doing on your iOS device.
Just stick to the networks you know and trust.

Friday, 13 February 2015

In shift, hackers want your identity, not just your credit card

150212g.jpg
A staggering figure for those who seek greater security for their personal information.Gemalto
Stealing your identity is a key reason hackers break in to corporate networks, according to a new study.
The world was hit by more than 1,500 data breaches in 2014, leading to 975 million data records being lost or stolen during the year, Netherlands-based security firm Gemalto reported on Thursday (PDF). Data breaches were up 49 percent in 2014 versus the prior year, and the number of lost or stolen records was up 78 percent.
And in a change of strategy, hackers are actively targeting individuals, with 54 percent of data-hacking incidents focused on identity theft, the Gemalto report said. Just 17 percent of hacks were designed to access financial information, while 11 percent sought account access. According to Gemalto, hacking identities rather than financial information provides a long tail of benefit to hackers, rather than a short-term spending spree.
"We're clearly seeing a shift in the tactics of cybercriminals, with long-term identity theft becoming more of a goal than the immediacy of stealing a credit card number," Tsion Gonen, Gemalto's vice president of strategy for identity and data protection, said in a statement. "Identity theft could lead to the opening of new fraudulent credit accounts, creating false identities for criminal enterprises, or a host of other serious crimes. As data breaches become more personal, we're starting to see that the universe of risk exposure for the average person is expanding."
The Gemalto report comes just days after US health-insurance provider Anthem announced a security breach that resulted in the exposure of up to 80 million records. The hackers used a stolen password to break in to the Anthem network and steal everything from names to medical IDs to Social Security numbers.
The Anthem hack was just the latest in a string of attacks on companies. In a little over a year, hackers have stolen 56 million credit card numbers and 53 million email addresses from Home Depot; contact information for 76 million households and 7 million small businesses from JPMorgan's vaults; and 40 million credit and debit card numbers and personal information on 110 million customers from Target.
The hacks didn't stop there. Arts and crafts chain Michaels and restaurant chain P.F. Chang's also suffered embarrassing data thefts last year. In November, Sony Pictures suffered its worst hack in history, as hackers accessed private e-mails and copies of upcoming films.
A Pew Research study conducted last year found that 18 percent of consumers have had their credit card, bank account, or Social Security numbers stolen. A report just six months prior to that one found that 11 percent of consumers had been subject to such theft. Last December, H.D. Moore, chief research officer at security firm Rapid7, said the issue might be even more widespread than Pew believed.
"It'd be hard to find anybody in the US who hasn't had a credit card affected," said Moore.
While the risk of falling victim to a data breach appears high around the world, so far the vast majority of hacks -- 1,164 -- have occurred in North America. In addition, Gemalto's study shows that 58 percent of stolen records have come from retail, followed by the financial industry at 21 percent.
Acknowledging the impact that data breaches have on the US, and the sometimes patchwork efforts that go into securing networks, President Barack Obama's administration last month proposed a new law, called the Personal Data Notification and Protection Act, that would create a basic set of rules for how companies must safeguard customer information. If passed, the law would also criminalize the international trade of stolen personal identity information.
The law would in some ways complement regulations already in place for data theft in 47 states in the Union. However, many of the states have different requirements on data theft and hacking. Obama's law would codify the handling of customer information on a national level, so it's the same across the states.
Despite those efforts, it seems unlikely that customers will feel safe anytime soon.
"Not only are data breach numbers rising, but the breaches are becoming more severe," Gemalto's Gonen said. "Being breached is not a question of 'if' but 'when.' Breach prevention and threat monitoring can only go so far and do not always keep the cybercriminals out."

Sunday, 25 January 2015

Google leaves most Android users exposed to hackers

People using phones and tablets running Android 4.3 Jelly Bean or older will be left exposed to a security flaw in the default, unbranded browser app.CNET
People with Android smartphones and tablets running older versions of the mobile operating system -- around 60 percent of all Android users -- are going to have to live with a security flaw Google has decided not to fix.
A known security bug in the default, unbranded Web browser for Android 4.3 Jelly Bean and older versions of Google's mobile OS will go unpatched, Google's chief of security for Android wrote in aGoogle+ post on Friday.
"Keeping software up to date is one of the greatest challenges in security," Adrian Ludwig wrote. Because the browser app is based on a version of the WebKit browser engine that's now more than two years old, fixing the vulnerability in Android Jelly Bean and earlier versions is "no longer practical to do safely," he wrote.
Google confirmed on Saturday that Ludwig's post is the company's official position on the matter.
The company's decision has upset security experts, who worry hackers will be able to easily target the hundreds of millions of people using phones and tablets that run older versions of Android. Ludwig contends the number of people potentially affected by the vulnerability is "shrinking every day." But for security professionals, it's just not shrinking fast enough.
According to Google's own Android usage numbers, 39.1 percent of its smartphones and tablets run a newer, unaffected version of Android: 4.4 KitKat. The most recent version of the operating system, Android 5.0 Lollipop released in November, makes up less than one-tenth of 1 percent of Android devices in use. That means about 60 percent of Android devices run versions of the OS that included the susceptible browser by default.
The consequence of having so many people running so many different versions of the same operating system is that it becomes far more complicated to protect them, wrote Tod Beardsley, an engineering manager at security firm Rapid7. "Unfortunately, this is great news for criminals for the simple reason that, for real bad guys, pretty much everything is in scope," he wrote in a blog post.
Upgrading to a new Android phone or tablet isn't an option for many people, Beardsley said, because while the latest Nexus phone running the latest version of Android retails for $649.99, Amazon sells new, out-of-the-box Android phones running older versions of the operating system for one-tenth the price.
Ludwig recommends people on Android 4.3 or older use a different Web browser. He suggests Google Chrome, which works on Android 4.0 Ice Cream Sandwich and newer, or Mozilla Firefox, which works on Android 2.3 Gingerbread and newer. However, switching browsers won't fully address the flaw since it affects the part of the default browser that apps tap into to display websites. Ludwig asks app developers to restrict loading content in their apps that doesn't come from the Android device itself, or over a secure connection.
Beardsley said he empathizes with Google's decision because of the difficulties in updating old computer code. But he said he hopes the company revisits its decision in light of the huge number of people who depend on Android "to manage and safeguard the most personal details of their lives."

Friday, 6 September 2013

Why hackers attack your smartphone?

NEW YORK — Your smartphone is probably a much more tempting target for cybercriminals than your desktop computer, and unless you take proper precautions, it's easier to hack as well.
Think of it this way: Your computer might have sensitive work documents, banking information or personal records, but there are only a few ways people can access those files — in person, via a network or over the Internet.
Your smartphone is almost always on, connected to the Internet, logged into your email and social media, and likely has at least a username stored for your bank account. Your smartphone contains as much sensitive information as your wallet does — more, if you count the contact information for your family and friends.
A smartphone is a whole different beast, said Yuval Ben-Itzhak, the chief technology officer of AVG Technologies, an American subsidiary of the Czech security firm Grisoft. At an AVG event here on Sept.4, Ben-Itzhak explained that the average smartphone has several avenues of attack.
Smartphones can access the Internet, which puts them at risk for a variety of malware and compromising exploits, but malware can come via almost any phone function. Text messages are easily exploitable, especially since an average text-messaging app takes no security precautions. They open automatically and load as soon as your phone connects to a network; in effect, they can't be blocked.
At the Black Hat 2011 security conference in Las Vegas, researchers even demonstrated a proof-of-concept that infected iPhones with malware via charging stations. Although they did not distribute any harmful software, they showed that this behavior, called "juice jacking," could be a threat. If a malicious hacker ever implemented a scheme like this, he or she could conceivably infect hundreds of phones each day.
Hackers also monetize these hacks in fairly subtle ways. Rather than stealing credit card information to buy themselves luxury yachts or scads of DVDs on Amazon, tangible goods that are extremely easy to track, they often subscribe users to premium texting services, which often cost as little as $3 per month.
These scams are much more common in Eastern Europe, where users get charged for premium texts on-the-spot rather than monthly.
Many (but not all) users will catch the extra charge on their phone bills, cancel the service and prevent the malefactors from ever getting their money. But an enterprising hacker can nickel-and-dime his or her way into relative richness.
Hackers do not represent the only mobile threat, either. Leaving your Wi-Fi and Bluetooth functionality activated when you don't need to do so represents a considerable privacy risk. Phones broadcast signals that reveal their model number and location information, and some malls are now leveraging this feature.
Video
How an IPhone Charger Opens Your Phone to Hackers
View Video


By tracking phones, malls can get a good idea of their shoppers' demographics (even though there's no way to identify users, phone preference varies by age, sex and race), which shops their patrons visit and how the two correspond. If users download retail-specific apps, stores can also track when users enter and leave their premises and communicate accordingly, but downloading an app at least allows the user to choose whether or not to participate.
Retailers are not the only entities interested in aggregating mobile data. Up until recently, recycling bins in London had the same functionality. The City of London wanted to gather data on cellphone usage without any apparent end goal in mind, and walking by a recycling bin while your cellphone's Wi-Fi is active would transmit your phone's build and location information directly to the British government.

In order to keep your mobile information private and safe, keep Wi-Fi and Bluetooth turned off unless you need them, and install a mobile security suite on your phone. Ben-Itzhak also recommended disabling or uninstalling social media apps — the HTML versions of Facebook and Twitter are more secure, and much easier on a phone's battery life.Public outcry put an end to the invasive bins, but while the City of London — which represents only a small, somewhat separate financial hub in London, not the larger city — was the first government entity to try such a tactic, it probably will not be the last.