::Trend Micro Threat Resource Center::

03 April 2013

Think twice before you rush to post your PII for that freebie on Facebook!

Looks like any other product Facebook page? Think again.
Click to enlarge

Another case of misuse of social media, by consumers - that is case study worthy.
I was alerted of people posting their personal particulars (or commonly known as PII in US) on Loreal Singapore's facebook wall in exchange for potential freebies. Read POTENTIAL.

Don't believe how crazy can that be? Here's proof:

Click to enlarge

There's just so much private data there waiting to be mined. The PII have been sanitized to protect their privacy, but I'm thinking my attempts will prove to be futile as the Facebook page is accessible by the general public even without logging in. 

26 March 2013

Apple adds two-step verification option to iCloud accounts

Apple has finally introduced a two-step verification feature that will allow its users to secure their iCloud (Apple ID) accounts, 9 to 5 Mac reports.

The option is currently available only to users based in the US, UK, Australia, Ireland, and New Zealand, and is definitely an improvement over the previous additional protection mechanism that included security questions.



Users can set up the feature in the "Password and Security" settings in their Apple accounts, and will be required to add (if they haven't already) the number of the phone(s) to which Apple will be sending the verification code.

They will also be given a recovery key to use in case they lose the device or forget their password, and are advised not to store it on the device or computer in case they are compromised.

Apple has also decided to prevent their support personnel falling for social engineering attacks such as those that led to the unfortunate compromise and trashing of Mat Honan's Twitter, Google and iCloud accounts by making it impossible for anyone but the account owner to reset their password, manage their trusted devices, or create a new recovery key once 2-step verification is turned on.

"You must be responsible for remembering your password, keeping your trusted devices physically secure, and keeping your Recovery Key in a safe place," the Apple FAQ page additionally warns. "If you lose access to two of these three items at the same time, you could be locked out of your Apple ID account permanently."

24 March 2013

Ten simple things you should do this Data Privacy Day



When was the last time you ran a search on your own name – do you know if someone has been pretending to be you, or if unwanted eyes have easy access to your personal details?

Don’t stand idly by as the trail you leave online gets larger – be vigilant and take steps to protect your own information. In line with Data Privacy Day on January 28, here are ten simple things you can do to better protect
the information you share online.

1. Password protect your mobile devices – only 6 in 10 Singaporeans use passwords on their mobile device. Leaving your devices unprotected is equivalent to leaving your home or car unlocked. If you’re lucky, no one will take advantage of the access. If not, you might find yourself at the mercy of cyber risks and fraud.

2. Run a search on yourself – it’s not narcissistic, and is an easy way to stay on top of what’s available about you online. You never know who might be assuming your identity or sharing your private information.

3. Be stingy with your personal details
– some websites will prompt you for information such as your email, address or phone number. Be cautious as this information might end up being used in unexpected ways.

4. Mobile security software can add another layer of protection
– yes it exists, and yes it works.

5. Unknown sources are usually bad news
– emails and text messages that contain links or ask for information might do you more harm than good. Make sure you know who the sender is before opening these messages.

6. Be in charge of your privacy settings
– some social networks and applications can share your personal information and location with strangers. You should only share personal details with those you trust.

7. Download apps from reliable sources
– mobile malware is spreading via fake app markets. Be mindful of what apps you’re downloading and where you’re downloading them from.

8. Keep your apps updated
– security patches exist for a reason, use them when available.

9. Log off and log out
– unless you want others to have easy access to your accounts, you should always log out after use.

10. Stay informed
– keep up to date with the latest mobile threats and dangers by visiting websites such as MobileSecurity.com, which has the latest news on all things related to protecting yourself and your mobile devices.

22 March 2013

Researcher points out critical Samsung Android phone vulnerabilities

Tired of waiting for Samsung to fix a string of critical flaws in their smartphones running Android, Italian security researcher Roberto Paleari has decided to inform the public about the seriousness of the matter and maybe make

matter and maybe make the company pick up the pace.



Mindful of the danger that the vulnerabilities present to the users if they are exploited by malicious individuals, he decided not to share any technical details, but to just give a broad overview of what their misuse would allow:

•a silent installation of highly-privileged applications with no user interaction
•SMS sending and changing of various phone settings without the app requiring the permission to do so
•an app performing almost any action on the victim's phone.

"All these issues were caused by Samsung-specific software or customizations," he noted. "All the vulnerabilities I reported can be exploited from an unprivileged local application. In other words, no specific Android privileges are required for the attacks to succeed. This allows attackers to conceal the exploit code inside a low-privileged (and apparently benign) application, distributed through Google Play or the Samsung Apps market."

He admits at being surprised at the length of time it takes for Samsung to patch the vulnerabilities, especially because he believes they are easily fixed. The company replied to him that "any patches [Samsung] develops must first be approved by the network carriers."

In the meantime, UK blogger Terence Eden has demonstrated another lock screen bypass flaw he found on Samsung Android phones, which allows anyone to completely disable the lock screen and get access to any app.

The lock screen bypass flaw he discovered earlier this month has still not been patched by Samsung, but Bkav has released a patch that not only fixes the flaw, but also takes a photo of anyone trying to misuse the flaw and emails it to the phone's owner.

UPDATE (March 22): Bkav has developed a patch for the Samsung lock screen flaw disclosed by Eden.

21 March 2013

Android, iOS bugs expose phones to voyeurs, data thieves

The first line of defense against smartphone snoops is a handset's lock screen, but the two largest smartphone makers are having trouble keeping them secure.

Bugs were discovered Wednesday in both Android and Apple smartphones.

A bug discovered by Android researcher Terence Eden allows anyone to bypass the security measures in place at a phone's lock screen and gain total access to the contents of a handset.

Eden outlined the method for bypassing the lock screen in his personal blog. The technique exploits the 911 feature of a phone, which allows emergency calls to be made whether a phone is locked or not.

The researcher noted that he found his attack to work only on a Samsung version of Android. It does not work on phones running a stock version of Android from Google.

He tested the attack on a Galaxy Note II from Samsung, but he predicted it would also work on a Samsung Galaxy III, as well as other Samsung devices, too.

Samsung did not respond to a request for comment for this story.

Eden explained that he reported the bug to the company in February, and that he expected a bug fix to be issued shortly.

Meanwhile, another lock screen bug was discovered in Apple's iPhone. The bug was discovered less than a day after Apple began pushing a version of its iOS operating system, version 6.1.3, to address a lock screen flaw discovered several seeks ago.

The bug was revealed by a reader of the Cult of the Mac website. It uses an iPhone's control feature to bypass the lock screen. However, the exploit appears to only work on iPhone 4's.

When a call is voice dialed, the publication explained, if the phone's SIM card is ejected during the dial-up, the phone will display its recent call log. From that screen, a peeper can browse and edit contacts and add pictures to the phone.

Both the Android and Apple bugs are similar, according to Diogo Monica, a security engineer with Square, a mobile payments company in San Francisco.

"They both exploit the emergency call system," he said in an interview. "When an emergency call is made, it allows a logic bug to be exploited and let you access the screen without authentication."

Once the lock screen is bypassed, not only can the information in it be eyeballed, but it can be copied, too. If your phone is unlocked, it can be connected to a computer and its contents dumped to the device, Monica explained.

He estimated that all the important data in a phone can be siphoned into a computer in a couple of minutes. A complete data dump of everything in a phone would take a maximum of 15 minutes.

Faulty lock screens would create serious concerns for corporations, maintained Glenn Chisholm, CSO and vice president of Cylance, a cyber security firm in Reston, Va.

"When you try to access your corporate mail, it usually forces you to enable your lock screen," he explained  in an interview. "If the corporation can't trust a lock screen to protect their corporate information ... that's a big problem."

Another big problem for corporations is lost or stolen smartphones, added Giri Sreenivas, vice president and general manager of mobile for Rapid7.

To mitigate those risks, companies require their employees to secure their phones with a PIN. "These vulnerabilities allow those controls to be bypassed," he said in an interview.


A video run through of the issue:

18 March 2013

Hackers launch DDoS attack on security blogger's site, send SWAT team to his home





Thankfully, award-winning US computer security reporter Brian Krebs is safe.

Nobody was harmed. But they could have been.

Given a DOSed website, a fake and libelous FBI letter sent to his website host, and a dinner party delayed by a SWAT team training guns on him and ordering him to "Put your hands in the air!", Krebs last week surely endured the most dramatic retribution ever meted out to a security blogger.

Krebs has a good idea of the specific criminal element behind the trio of attacks. Since the dramatic events of Thursday, he's traced the denial-of-service attack to a common operator who apparently launched a similar attack on Ars Technica following its coverage of Krebs's victimization.

As described by his fellow security scribe Dan Goodin at Ars Technica, Krebs is known for work that includes:
In short, Krebs has enemies.

Last week, one or more of those enemies targeted him, likely in retaliation for his most recent investigation.

What actually went on? Full report here.