::Trend Micro Threat Resource Center::

20 October 2010

The rise of Java exploits

Sifting through the data collected and analyzed in order to compile the latest Microsoft Security Intelligence Report, senior program manager Holly Stewart came to an interesting conclusion: Java exploits have become way more popular with hackers than the Adobe-related ones:


This enormous jump is, according to Stewart, due to the fact that three particular vulnerabilities are being constantly exploited. Brian Krebs offers his own explanation: Java exploits have been incorporated into a number of popular exploit packs (Eleonore, Crimepack, SEO Sploit Pack, Blackhole).

These vulnerabilities have been patched for a while, but the problem is that users fail to update Java on their system. "Java is ubiquitous, and, as was once true with browsers and document readers like Adobe Acrobat, people don't think to update it. On top of that, Java is a technology that runs in the background to make more visible components work. How do you know if you have Java installed or if it's running?" says Stewart.

Given that Oracle has recently issued a Java security update that patches nearly 30 vulnerabilities, this would be a good time for all users to update the program or check for its existence on their systems and then update it. And while they're at it, they could configure the built-in updater to check for new versions every week.

19 October 2010

South Korea's Power Structure Hacked, Digital Trail Leads to China

South Korean intelligence claims China-based hackers stole confidential material from the country's diplomatic and security services throughout 2010. If a new report is correct, hackers inside the People's Republic of China gained access to personal computers and PDAs belonging to much of South Korea's power structure.

South Korea's primary intelligence agency is claiming that China-based hackers stole confidential material from the country's diplomatic and security services throughout the past year. If the new report by the National Intelligence Service is correct, hackers inside the People's Republic of China gained access--via malware--to personal computers and PDAs belonging to much of South Korea's power structure.

The booty? Sweet, sweet defense documents.


Read more info here.

15 October 2010

Facebook Adds Extra Layer Of Security

Facebook, the giant of the social media networks, has added extra security to user accounts. This security comes in the form of three new features that are available now for most users.

According to Jake Brill in The Facebook Blog, the first feature that has been introduced is an option to receive a one time use, temporary password for your account. According to Brill, "Simply text "otp" to 32665 on your mobile phone (U.S. only), and you'll immediately receive a password that can be used only once and expires in 20 minutes. In order to access this feature, you'll need a mobile phone number in your account." I can see this being useful in the case that your account has been compromised and your password has been changed by whoever accessed it. You would then be able to get into your account to create a new password that only you know. Of course, in the case of a lost or stolen phone, this policy works against you.

This next feature I am actually glad for. It is a remote sign-out feature that lets you sign off your account from any computers it is active on. It can also show you where you account is being accessed from, so you can tell if someone who shouldn't be on your account is. This is a feature that has been available for other services, such as Gmail, for a long time now, and I'm glad Facebook has finally caught up.

Finally, Facebook will begin prompting you more often for security updates. From Brill, "when people log in to Facebook we will regularly prompt them to keep their security information updated. If you ever lose access to your account, having this information helps us verify who you are and get you back into your account quickly." This is nice for the people who have a hard time remembering to update this kind of information frequently enough.

Overall, I see these new features as two steps forward, and one step back for Facebook security. The step back is only in the case that your phone is lost or stolen, as whoever is in possession of your phone is now in possession of your Facebook account.

12 October 2010

Ubuntu 10.10 desktop, netbook and server editions released


Ubuntu 10.10, codenamed "Maverick Meerkat", is now available for download.

Ubuntu 10.10 introduces an array of online and offline applications to Ubuntu Desktop Edition with a particular focus on the personal cloud. Ubuntu Netbook Edition users will experience an all-new desktop interface called ‘Unity’ - specifically tuned for smaller screens and computing on the move.

Ubuntu One, the personal cloud service for Ubuntu users, includes new services and expanded features, significant performance enhancements and interoperability with other operating systems including Google’s Android, Apple’s iPhone and Microsoft Windows.

Already one of the most popular operating systems on Amazon EC2, Ubuntu 10.10 Server Edition gets kernel upgrades, more configuration options at boot time, and the ability to run the AMI (Amazon Machine Image) off-line on a KVM-virtualised machine. The latter feature means users can test and develop on local servers before pushing to the public cloud - true hybrid cloud computing.


Ubuntu 10.10 extends ‘CloudInit’, a configuration tool that allows users of Ubuntu on the cloud to set a default locale, set the hostname, generate and set up SSH private keys, and set up mount points. Users can also run custom commands and scripts on initial startup or on each reboot. The technology was recently adopted by Amazon itself.

Additionally in Ubuntu 10.10, Ubuntu Enterprise Cloud adds virtio support, a new interface for administrators, eased deployment for developers and the ability to run UEC from a USB stick. Eucalyptus 2.0, the latest version of the core cloud technology in UEC, has been included.

GlusterFS and Ceph have been integrated into the core product and the groundwork has been laid for many cloud-focused enterprise-scale applications to be introduced over the life cycle of Ubuntu 10.10 and the current LTS version (10.04) of Ubuntu Server

RIM averts BlackBerry ban in UAE

Research In Motion and the United Arab Emirates have reached an agreement to call off a BlackBerry ban that was scheduled to start Monday.

Today's press release (Google Translate version) from the Telecommunications Regulatory Authority (TRA), which regulates telecommunications for the UAE, confirmed that all BlackBerry services will continue as usual and not be suspended on October 11.

The agency said that BlackBerry services are now compatible with the UAE's regulatory framework and added that RIM had cooperated in offering a compatible solution. Beyond that, the agency offered no details as far as specific actions or measures that RIM may have taken to avert the ban.

In a response to news of the agreement with the UAE, a RIM spokesperson e-mailed CNET the following statement dated today:

"RIM cannot discuss the details of confidential regulatory matters that occur in specific countries, but RIM confirms that it continues to approach lawful access matters internationally within the framework of core principles that were publicly communicated by RIM on August 12."

A UAE BlackBerry ban would have affected around 500,000 customers in the region and hit both local residents and foreign visitors.

In early August, the UAE announced that it would shut down e-mail, instant messaging, and Web browsing for BlackBerry devices on the October 11 deadline due to RIM's failure to meet the emirates' regulatory requirements. The UAE had been putting pressure on the BlackBerry maker to open up the security on its networks so that local officials could monitor and access customer data for what they see as national security reasons.

RIM had run into similar problems with India and Saudia Arabia, both of which were also demanding access to the corporate data flowing over the company's networks. On its end, the company had insisted from the start that the information on its networks is encrypted and that it does not hold the encryption keys, therefore it can't comply with regulations to make that data available.

With international pressure mounting, RIM fought back at first. At one point, the company's co-CEO Michael Lazaridis said in a Wall Street Journal interview that if these countries can't deal with the Internet, then they should shut it off. More recently, the company's other CEO, Jim Balsillie, suggested that governments that need to monitor BlackBerry corporate data should ask the corporations themselves for access since they're the ones that hold the keys.

But faced with potential bans from multiple countries, RIM was forced to compromise. In August, the company was able to strike agreements with both India and Saudi Arabia to avert their announced bans. The accords reached in those two cases reportedly involved setting up local BlackBerry servers in those countries through which the governments will be able to access their data directly.

09 October 2010

Free iPhone rogue applications on Facebook

Sophos is warning Facebook users about messages currently circulating on the social network claiming that friends have received free iPhones.


These messages, which have been spreading widely since Sunday, invite others to participate in the scheme, however the messages are being sent by rogue applications that users have allowed to access their profiles and post messages to their walls.

Messages appear as status updates and many read:

“Just testing Facebook for iPhone out :P Received my free iPhone today, so happy lol... If anyone else wants one go here:

Or:

“Anyone want my old phone? Claimed my free iPhone today, so happy lol... If anyone else wants one go here:”

Facebook users who click on the link advertised by their friends are then asked if they want to “Allow” this application to access their basic information. Participants who allow this are then redirected to a web page which will earn commission for the spammers behind the scam.

“If you’ve fallen for this trick, I wouldn’t hold your breath waiting for a new iPhone,” said Graham Cluley, senior technology consultant at Sophos. “Facebook users need to learn to think before they “like” and “share” suspicious pages on Facebook. Just because something appears on a friend’s wall, it doesn’t mean that it is from a reliable source, and by giving unknown applications access to your Facebook page, you could unknowingly continue to help to spread scams and earn cash for the spammers.”

Impacted users should delete references to the free iPhone scam from their wall, and remove the offending application from Account/Application Settings.