::Trend Micro Threat Resource Center::

30 September 2014

Apple releases bash patch to plug 'Shellshock' security flaw in OS X Mavericks, Mountain Lion, Lion

As promised, Apple on Monday issued OS X bash Update 1.0 for OS X Mavericks, Mountain Lion and Lion, targeting the recently discovered "Shellshock" security flaw originating in the bash UNIX shell.


Following revelations that Shellshock was in the wild, Apple last Friday said that, while most consumers would go unaffected, it was working to patch the problem. That fix was released today for OS X 10.9 Mavericks, OS X 10.8 Mountain Lion and OS X 10.7 Lion.

"This update fixes a security flaw in the bash UNIX shell."

The bug, dubbed "Shellshock" by the computer security community, is theorized to be built in to every version of bash since the system's inception in 1989. A remote attack, nefarious users could potentially issue commands to an affected computer with the intent of gathering information modifying system files and more.

"With OS X, systems are safe by default and not exposed to remote exploits of bash unless users configure advanced UNIX services," an Apple spokesperson said last week, adding that the company is "working to quickly provide a software update for our advanced UNIX users."

Mac owners running Mavericks can download the 3.4MB patch through Apple Support website, as can users operating Mountain Lion and Lion. For Mountain Lion, the fix comes in at 34.3MB, while the Lion download clocks in at 3.5MB. Alternatively, the patch is available through Software Update.

27 September 2014

What you need to know about Shellshock (a.k.a Bash Bug)

The Shellshock vulnerability (also known as Bash Bug) will have a widespread impact for any organization or user that has Bash enabled on a server, desktop, or device. This includes over 500 million web servers on the Internet today. Shellshock (CVE-2014-6271 and CVE-2014-7169) is found in Bash, the dominant shell for Unix and Linux (default), and can also be found in Mac OS X, some Windows server deployments, and even Android.

It enables remote code injection of arbitrary commands without authentication, which can then allow malicious code execution that could be used to take over an operating system, access confidential data, or set the stage for future attacks.

Simply put, the vulnerability allows attackers to run malicious scripts in systems and servers, which compromises everything in it. It has the potential to do significant widespread damage, since it affects Linux, BSD, and Mac OS X. Linux alone powers a majority of the servers on the Internet and IoT (Internet of Things) devices.

What is the threat extent and who are affected?
Shellshock creates a weak spot that serves as a backdoor for a hacker to carry out commands, take over a machine, dig into servers, steal data and deface websites. Most computers and Internet-enabled home devices such as routers, Wi-Fi radios, and even smart light bulbs running on Linux OS are most likely affected.

Webcams for example, are often Linux-based and these devices can also be hacked and used as infection vectors. This problem extends to smart devices connected to the Internet of Everything, located anywhere and everywhere, including hospitals, energy sectors, and schools. This means even with a minimal vulnerability in a device could open doors for a potential attack.

What can you do?
Be alert and recognize the scope and scale of Shellshock. Whether it’s as notorious as they say or not, having a healthy paranoia can make you more cautious and proactive about interconnected devices that could be vulnerable to possible attacks. Update all firmware and operating systems, and install security updates. Use Shellshock detection tools or plug-ins to scan likely vulnerabilities and exploits. For system admins, patch your systems immediately and closely track your network activity.

Learn more about the Bash Bug on the attached infographic (click to enlarge):


Facebook Messenger has abundance of permissions

Lately, there has been quite a bit of talk about how Facebook Messenger for Android has an abundance of permissions, permissions that may seem out of the spectrum of what a messenger app should need.

Since Facebook no longer allows users to use its flagship Facebook app to send messages, users must now install the new Facebook Messenger app to regain this functionality.

This isn’t the first time questions have risen about Facebook’s long list of permissions. When they first introduced the Facebook app, it came packed with permissions (and it still does).

Let’s first look at the Facebook Messenger app permissions:


In comparison, the Facebook app has all the same permissions, plus Device & app history permissions.

Before you decide to toss Facebook aside and start using Google Hangouts, the messenger for Google Plus, note that it has the same permissions as Facebook Messenger.

The question is whether or not Facebook, Google, or other well-known companies with apps in the Android Play store need the long list of permissions in there apps?

Let’s look at some of the more troubling permissions in Facebook Messenger; location, SMS, Camera/Microphone, and Device ID & call information.


  • Location permissions are used to show the location of where you are sending the message from.  It’s arguable whether this is really necessary, but the function is there.
  • SMS is being used for when you add a phone number to a Facebook messenger account, it can confirm the phone number being used by sending a confirmation code via text message.
  • Camera permissions are so you can use the camera to take a picture to send through messenger, and microphone permissions are used so you can record and send audio.
  • Device ID & call information is used to initiate outgoing calls so you can call friends and family through the messenger app.
  • In other words, Facebook is NOT tracking your every move, NOT looking at your SMS messages, NOT using your camera and microphone to spy on you, and NOT tracking all your call information.

Facebook and other companies are going to continue to come out with feature rich apps, and the more features they have, the more permissions they will need.

Many of these permissions would be a huge red flag that something fishy might be going on. The difference between good apps and bad apps is how the permissions are used in the code.

It’s the code that contains the malicious intent, but it’s not always easy to tell what permissions are legitimately being used, and which are being exploited.

That’s why we are here to make those hard decisions to keep our customers safe.  So yes, it’s a little scary when apps have an overwhelming list of permissions. This is especially true with social media apps that handle content that some may consider “private”.

One more thing worth mentioning: with all these permissions, you want to make sure you have the correct Facebook Messenger app from the Google Play store.

You’ll know it’s the right one when you see the package name “com.facebook.orca” with a large amount of downloads and reviews.  The package name displayed in the URL on the Google Play site after “id=”.  It would be bad news to get a knock off app with this many permissions from a third-party market.  Stay safe out there.

26 September 2014

Cyber attack on Japan Airlines impacts up to 750,000


A phishing attack may have resulted in the theft of personal information belonging to customers of Japan Airlines's frequent flier club.

The leak was due to an 'unauthorised access' to JAL's database by an external server, an airline official told the local news agency Kyodo on Wednesday

The data compromised includes names, addresses, genders and places of work of anywhere between 110,000 and 750,000 members of the program, according to the Japan Times.

Following an investigation – which found that 23 computers contained malware – the airline determined that no credit card or financial information was impacted by the breach. The airline detected the intrusion on Friday and Monday, however, it believes the attacks have gone undetected for more than one month and were introduced to the airline's network via a phishing email.

This incident follows a similar attack on the airline in February, in which hackers penetrated a different program Japan Airlines offers, which allows customers to trade in mileage points for gift coupons.

25 September 2014

NEC, Singapore's Economic Development Board partner for cybersecurity training programme

Somehow, I sense that the Government is getting desperate in trying to recruit qualified cyber security personnel at their disposal, thus the collaboration. The partnership comes in the wake of two security breaches in Singapore:

  • A telco user flagged a security flaw in telco M1's iPhone 6 pre-order page that resulted in one case of unauthorised access to its customer database.
  • A group called The Knowns gained access to karaoke entertainment operator K Box's database and published the personal information of more than 317,000 members online.

Nothing wrong with that, in fact I think it is a good news headline to help create cyber security awareness among its citizens. However, I would not pin high hopes for a short 12 month on-the-job-training stint. Very much still depends on how the training is structured, and what kind of experience is gained via the promised training exposure.

==============================================


The Singapore Economic Development Board (EDB) and NEC Corporation will be partnering in a multi-year agreement to build strategic capabilities in cybersecurity through EDB’s Strategic Attachment and Training (STRAT) Programme.

NEC and EDB will seek qualified cybersecurity professionals and graduates to take part in a comprehensive cybersecurity training programme designed to equip them with the needed skills to counter the latest cyber threats.

The training aims to develop key in-depth skills and cybersecurity capabilities in areas of malware analysis, incident response, intrusion detection, digital forensics and vulnerability assessment.

The STRAT Programme aims to build up Singapore's manpower capabilities in strategic areas and sectors through overseas training and attachment with leading companies, and is open to Singaporean citizens and permanent residents.

The one-year programme will involve cybersecurity training locally, as well as with one of NEC’s Security Operations Centres (SOC) in Japan, which will focus on developing cyber operator, analyst and incident responder skills.

Training options also include working at one of NEC’s Regional Competency Centres or at an international partner agency, which will provide on-the-job-training in technical support for cyber operations, cyber forensics and malware analysis. Trainees will also have the option of working at NEC’s research laboratories on research and development projects.

The global shortage of qualified cybersecurity professionals has been highlighted in numerous reports. According to a Mckinsey and World Economic Forum report, delays in adopting cybersecurity capabilities could result in a loss of US$3 trillion (S$3.75 trillion) in economic value by 2020 globally. A global study by Frost & Sullivan highlights that hacking, cyber-terrorism and hactivism are top concerns identified by organizations, yet more than half feel their security organizations are short-staffed.

The signing ceremony for the partnership between EDB and NEC was held at Governmentware 2014 on 24 September 2014, at the Suntec Singapore International Convention & Exhibition Centre.

“Within a year, trainees will get a unique opportunity to acquire skills in different functions of security operations, research and forensics. This wide exposure will be an invaluable experience for trainees as it will equip them to be proficient for the wide range of job roles within the field of cybersecurity," said Gian Yi-Hsen, Director of Safety & Security Industry Programme Office (SSIPO).

“The demand for skilled talent is critical in the current environment, and we are committed to ensuring our identified trainees receive the relevant training that will broaden their exposure and sharpen their skills to counteract the sophisticated cybersecurity challenges of today,” said Tan Boon Chin, Managing Director, Global Safety Division, NEC Corporation.

Source: http://www.channelnewsasia.com/news/business/edb-nec-partner-up-to/1378456.html

Mozilla fixes "phishing friendly" cryptographic bug in Firefox and Thunderbird

Here's a quick note about an important issue!

Mozilla just patched a bug in its cryptographic library, NSS.

NSS stands for Network Security Services, used by Mozilla products such as Firefox (web browsing), Thunderbird (email) and SeaMonkey (both).

All these products have now been patched, including the Firefox Extended Support Release (ESR) verions.

→ As far as I am aware, Google's Chrome and Chromium browsers, as well as Opera, also use NSS.

The bug is rated "critical" because is deals with the validation of digital signatures in TLS connections.

TLS (Transport Layer Security), often also known by its old name of SSL (Secure Sockets Layer), is the cryptographic protocol that puts the S in HTTPS.

When you use HTTPS, it's not just confidentiality you are after, but also integrity (to stop a crook fiddling with the message in transit) and authenticity (to stop a crook claiming to be your bank).

Without certificate validation, you could easily end up conducting a totally secure and unsniffable interaction...

...with a complete imposter.

Unfortunately, this recently-patched NSS vulnerability affects digital signature verification in all the abovementioned products.

Phishing HTTPS logins
Remember that crooks who have hacked into your Wi-Fi access point – at your local coffee shop, for instance – could sneakily redirect any of your HTTPS logins to to phishing sites instead.

Uusally, however, the crooks can't present a digital certificate to vouch for the fake site they have drawn you into.

Sometimes, the crooks avoid the need for digital certificates altogether by dropping back to a plain old HTTP site that doesn't use encryption at all.

You should be able to spot this sort of ruse due to the absence of any security indicators in the address bar of your browser.



Or the crooks could present a TLS certificate that claims to be from your bank, but which isn't vouched for by any recognised certificate authority.

You should be able to spot this sort of ruse due to an "untrusted connection" warning from your browser.


But if there's a cryptographic vulnerability that can be exploited to make a bogus digital certificate seem valid, then the crooks may be able to redirect you to an imposter site without raising any alarms.

And that could lead to the digital theft of your personal information, including usernames and passwords.

Get the latest update

If you have a software product (e.g. Firefox) that uses NSS, make sure you've got the latest update; for Mozilla software, that means (at 2014-09-24T23:45Z):

  • Firefox 32.0.3
  • Firefox ESR 24.8.1
  • Firefox ESR 31.1.1
  • Thunderbird 31.1.2
  • Thunderbird 24.8.1
  • SeaMonkey 2.29.1

For what it's worth, I'm using Firefox 32 on OS X, and the update was so small I didn't get time to read its size during the download.

Applying the update was quick: less than a second to download the patch, and a few more seconds to restart the browser process.



So my recommendation is, "Just do it."