السبت، 27 فبراير 2016

Cyber Hackers Breached 700000 Accounts of US Tax Payers

Cyber Hackers Breached 700000 Accounts of US Tax Payers


Cyber Hackers Breached 700000 Accounts of US Tax Payers


On Friday the tax agency said that hackers got access to personal data of more than 700,000 taxpayer accounts, which was more than double of estimation. It took place in 2015 to the IRS.


The personal information contains the following:

  • Data that cyber thieves could use to impersonate a real taxpayer
  • Birth dates
  • Social Security numbers
  • A false file of federal tax return and collect a refund

Previously, IRS said that around 100,000 taxpayer accounts had been compromised, which in August raised around as many as 334,000. But on Friday's estimation goes up to 700,000. 

IRS also said that more than 500,000 other taxpayer accounts have been tried by the cyber hackers to gain their access. The actual statistics is much higher than the estimated value.

The Treasury Inspector General conducted a nine-month review for Tax Administration, which oversees the IRS. IRS also said that cyber hackers achieved their target and gained access to taxpayer accounts between the month of January 2014 to May 2015.


An audit report will be released by the TIGTA officials based on the findings.

John Koskinen(IRS Commissioner) said that 
"User's whose account showed a sign of suspicious access then for that the agency is planning to mail notifications and assistance. They also get IRS personal identification numbers along with free Equifax identity theft protection product also. Extra scrutiny for taxpayers has been placed by the IRS."

Koskinen said that "The IRS is committed to protecting taxpayers on multiple fronts against tax-related identity theft, and these mailings are part of that effort,"

Seven federal audits and the reports from 2007 to 2014 outlined too many computer dangers because of failures in IRS Database. The IRS inspector general warned in an October 2014 report said that "Computer security has been problematic for the IRS since 1997,"

Due to the hacking activities on R-Utah, Government Operations chairman of the House Committee on Oversight, IRS Rep. Jason Chaffetz and Government Operations accused IRS.

Chaffetz said that "The IRS doesn't have its house in order at any level,"

According to tax agency "For more than 450,000 Social Security number's, e-file personal identification numbers has been unauthorized by the hackers to gain access to it. IRS also said that till January almost 101,000 were succeeded in accessing an e-file ID number, the IRS said.

Image Source: PBS

Baidu Apps Are Spying Personal Data And Leaked Information

Baidu Apps Are Spying Personal Data


Baidu Apps Are Spying Personal Data And Leaked Information


According to a research security, researchers found that thousands of apps are using code from the Chinese net giant Baidu, and are able to collect and transmit the Personal data insecurely.


According to the security experts at the  University of Toronto, they believed that millions of Chinese people have been affected by this issue. Millions of Chinese People affected by the data leaks.

The information included in the data leaks contains:

  • Where the Person Are.
  • Sites Visited by them. 
  • Search Terms.
  • ID numbers of their device too which they own.  

Chinese net giant Baidu said that with the insecure computer code they had tackled the problems.
'Shoddy design'

The software development kit contains the code which can be used in order to create programs for Windows and apps for android phones. That code was also used by the Chinese net giant Baidu, to make web browsers for Android and Windows too. Many firms used the Chinese net giant Baidu web browsers.

The security experts at the University of Toronto, also said that "Hundreds of millions of times, the apps and browsers have been downloaded, which is made using the Baidu Kit."

The Lab has focussed on personal and private data use in China because it is a part of long-running research project. Last year the researchers at Toronto's Citizen The Lab found patches in the Alibaba browser, and now in the Baidu code (several security and privacy shortcomings).

Data like GPS coordinates and Search terms are also sent in a plain text. And unique device IDs can easily be broken. An Attacker can easily get access to a phone and Windows computer, because of the weak protection of apps.

Authors said in their reports that "If the personal data transmission without properly implemented encryption then it can expose a user's data to surveillance, The leakage of such user data is particularly problematic for individuals who use these applications and their devices to engage in politically sensitive communications,"

Ron Deibert(director of the Citizen Lab) told Reuters that "It's either shoddy design or it's surveillance by design,"

Is It Fixed or Not Fixed?

In November last year, Baidu had already patched some of the bugs in the code, said by Citizen Lab. But, still poor encryption scheme was still being used on sensitive data.

Baidu has made so many statements regarding this issue some of them was:

  • For commercial purposes, the data was collected.
  • Once, they said that they shared the data with partners.
  • They also said that the information was not handed over wholesale to the Chinese authorities.
  • They said that "they provide only the lawfully data requested by duly constituted law enforcement agencies."

Image Source: BBC

Firmwalker: A Simple Bash Script

Firmwalker: A Simple Bash Script


Firmwalker: A Simple Bash Script


Definition: A FirmWalker is a simple bash script. FirmWalker is used for searching the extracted or mounted firmware file system. 


The extracted firmware file system includes the things of interest such as: 
  • etc/shadow and etc/passwd
  • etc/ssl directory is listed out
  • SSL related files is being searched such as .pem, .crt, etc.
  • Configuration files search
  • Script files
  • .bin files search
  • find the keywords as admin, password, remote, etc.
  • Common web servers used on IoT devices are search.
  • Common binaries are search such as dropbear, ssh, tftp etc.

You can also reviewed and deleted the data if it is desired from file.

How can you Use it?

'./firmwalker {path to root file system}'
Example: './firmwalker linksys/fmk/rootfs'

Where the script file is created a file "firmwalker.txt" will also be created in same directory, unless a different filename has been specified. If you put the firmwalker.sh file inside the directory to be searched, then the script search it itself and the file chmod 0700 firmwalker.sh is being created.

الجمعة، 26 فبراير 2016

PAN-OS Critical Vulnerabilities Patched By The Palo Alto Networks

PAN-OS Critical Vulnerabilities Patched

PAN-OS Critical Vulnerabilities Patched By The Palo Alto Networks



The Palo Alto Networks have released PAN-OS updates. PAN-OS is the operating system for the enterprise security platform. 


PAN-OS possess many features like:

  • To address the system vulnerabilities.

Vulnerabilities can be categorized into "critical" and "high" severity.

On Wednesday Advisories which were published by the company contain an information about the GlobalProtect portal serious issue that is a critical buffer overflow. The consequences of this vulnerability is that:

  • It caused improper handling of a buffer in SSL VPN request Processor.
  • It can also exploit to cause a denial-of-service (DoS) condition.
  • It can also crash a device even for remote code execution.

Along with that the company (network and enterprise security) also informed users about the consequences of this vulnerability by which malicious actor can easily allow executing arbitrary OS commands by accessing the device management web interface

The company said in the advisory that “Palo Alto Networks PAN-OS implements an API to enable programmatic device configuration and administration of the device. An issue was identified where the management

API incorrectly parses input to a specific API call, leading to the execution of arbitrary OS commands without authentication via the management interface,” There is also the another medium severe flaw issue to the GlobalProtect portal by which unauthenticated attacker can easily crash the portal by remote network access.

It has also published in an advisory by Palo Alto Networks in which they explained about the low severity issue along with their consequences. Low severity flaw allows a authenticated attacker who has administrator rights to execute the commands at the OS level with root privileges.

PAN-OS versions 5.0.17, 6.0.12, 6.1.9, 7.0.4 are the versions that have been affected by the critical and high severity vulnerabilities, but now it has been patched in the PAN-OS versions 5.0.18, 6.0.13, 6.1.10 and 7.0.5.

PAN-OS versions 5.0.17, 6.0.12, 6.1.9, 7.0.5 are the versions affected by the medium severity flaw impacts, but it has been resolved in PAN-OS 5.0.18, 6.0.13, 6.1.10, 7.0.5H2.

PAN-OS versions 5.0.17, 5.1.10, 6.0.12, 6.1.9, 7.0.5 are the versions affected by the low severity issue, and it's fixed in 5.0.18, 5.1.11, 6.0.13, 6.1.10 and 7.0.5H2.

On March 16, When the details of these weaknesses will be disclosed at a conference, prior to that almost many systems will patch by Palo Alto Networks customers.



Felix Wilhelm of German security firm ERNW Research was the one who reported about these vulnerabilities, all the details will be disclosed on March 14-18 in the city of Heidelberg in Germany, during the researcher’s presentation on attacking next-generation firewalls at the company’s TROOPER16 conference

Research: Usage of KeyBase Keylogger Has Been Explodes

Research: Usage of KeyBase Keylogger Has Been Explodes

Research: Usage of KeyBase Keylogger Has Been Explodes 


Palo Alto Networks researchers have found that when the builder of simple keylogger malware has been leaked online last summer, the usage of keylogger has gone or explodes.


KeyBase (a spyware family) that can affect the system by following way:
  • It can capture keystrokes.
  • Written in C# by using .NET Framework.
  • It can also steal data from the user's clipboard. 
  • At regular intervals, it can also take screenshots of the victim's desktop.

When Palo Alto researchers stumbled upon an unprotected server (control panel), at that time this malware was first seen where the screenshots were sending by the KeyBase. This malware was created in February 2015, but now it has been stopped developing by the KeyBase's author from the last summer, they promised that they were not developing it further and they also closed their website where they used to sell this KeyBase for $50 / €45, and they have abandoned the project.

According to the Palo Alto report "At that time around 295 unique KeyBase samples and more than 1,500 different KeyBase connections sending data back to control panels." After that, the builder's of malware has been leaked online on many hacking forums.


New KeyBase wave infected 933 Windows computers:
Eight months later it has been reported by the Palo Alto that hacking community continued to develop KeyBase, after seeing that over 44,200 KeyBase sessions coming from over 4,900 different KeyBase instances.

Along with that the main things that have been discovered by the Researchers were:
Even though the control panel was secured, but the folder that contains the images to sent for storage was not. It means that all the KeyBase panels available online can be found only by put together a simple script.

A simple method has been used by the Palo Alto staff by which they discovered the following:

  • 62 Web domains where the KeyBase control panel was installed.
  • 125,083 screenshots from 933 Windows computers.
  • 82 different control panels.

Out of all the infected computers, 216 were workstations in corporate environments, 75 were personal computers, and 134 were used for both. Among 933 computers 43 included the details from more than one user, it means that they were shared assets, may be used by multiple family members or work colleagues.

Attackers targeted the manufacturing industry:
According to the researchers, most of the KeyBase infected countries are China, South Korea, United Arab Emirates, and India. And they are also confident about managing the narrow down most of the attacks to a few campaigns.

Keybase Geographical view

Attackers targeted the manufacturing industry, but some stood out. The industries were the wholesale and retail industry, manufacturing sector, Transportation company.

Industry sectors  that were affected by KeyBase:
According to the researchers, the screenshots depicting the invoices, blueprints, email inboxes, financial documents, booking software and many more images.

Dummy hackers infected themselves as well:
During the keylogger's tests, the creator of malware's infect himself and his activities recorded through screenshots and then they sent it to Web control panel and the a new wave of KeyBase infections also managed to infect their computers.

As the code of KeyBase is available to anyone, so it is a well-known and easy-to-detect threat. By avoiding unsolicited or spam email(the most common method used by KeyBase to infects victims) also you can stay safe.

الخميس، 25 فبراير 2016

Anonymous Hackers Hacks French Defense Ministry Website To Protest Against Arms Trade

Image Source: militarytimes.com

Anonymous Hackers Hacks French Defense Ministry Website To Protest Against Arms Trade 


The Web Portals of France Ministry of Defense have been hacked by Anonymous hackers in order to protest against the foreign arms trade operations of the country and leaked the database of site. The French Government has been accused by the Anonymous hackers for selling weapons to a country like Saudi Arabia.


Anonymous hackers revealed the incident publically and said that they have targeted the CIMD (Centre d'Identification des Materiels de la Defense) portal, which is a smaller site of Ministry's. Then after the website went down and the users got a message saying that "Our web portal will be temporarily unavailable due to maintenance actions."

Image Source: securityaffairs.co

Database has been leaked and admin panel access has been gained.

Website database has been leaked by Anonymous hackers that contain very important information like (accounts of websites, sessions of PHP, FTP client usernames and army suppliers and partners too). Among them, the sensitive data is only the server usernames (including plain-text passwords) but not all.

Image Source: securityaffairs.co

Apart from this, these Anonymous hackers also revealed the screenshots of the site's admin panel. It was easy to target the French Defense Ministry Website because from past months or year many vulnerabilities have been gathered by the CMSs in droves.

The primary aim was to protest against the France's international arms trade.

Image Source: securityaffairs.co

The data which has been dumped were related to a lucrative arms trade sector and France's weapons industry. The dumb data was made accessible by the Anonymous members, to justify their attack you can easily get the dumb data from many press articles. 

An Amnesty International 2012 article contains some links of dumb data, which was left behind by the hackers that contain the world's second largest arms trader as France. 

"Weapons are selling by France to Saudia Arabia, and they also bought surveillance and spying tools from the firm of Italy (The Hacking Team).

Lazarus Group Was Responsible For The Sony Pictures Hack


Lazarus Group Was Responsible For The Sony Pictures Hack In 2014


In 2014, some anonymous hackers targeted and attacked the Sony Pictures Entertainment, and in order to analyze and disrupt the activities of that threat group, many security firms have teamed up.


On the activities of an actor that they have dubbed the Lazarus Group, a reports have been published by firms like Symantec, Kaspersky Lab, Novetta and AlienVault on Wednesday. According to those reports, more than 45 families of malware's have been analyzed, that helps to easily find a connection between several major attacks by the researchers of the firms.

From the past 2007, The Lazarus Group has conducted so many attacks whose purpose was to destroy the data and disrupt the system and along with that, they have also conducted so many cyber espionage operations.

After the analysis of samples of malware, it has been found that numerous attacks have been conducted by the Lazarus Group. Among them, there was one that shamed and crippled Sony in 2014. Along with that the other attacks including:

  • Attacks on Manufacturing and financial organizations primarily located in South Korea and the United States.
  • Attacks on Military.
  • Attacks on government and media too.
  • Dark Seoul and Operation Troy campaigns. 

In Malaysia, China, India, Taiwan, Brazil, Mexico, Turkey, Saudi Arabia, Iran and Vietnam and in many more countries Victims have been spotted.

Victims of Lazarus Group

According to some factors like similarities in the attackers, code shared between several malicious tools and the methods that has been used by them to wipe and evade detection by security tools, Researchers were able to connect the campaigns to Lazarus.

The links between Destover, the DarkSeoul malware and the wiper used in Sony attack all have been found by the Experts, but they are not able to find any evidence associated with the same malware developers.

According to the researchers, same password has been used by the attackers which is hardcoded inside the dropper in every campaign. And this provided the information to researchers needed for identifying operations of Lazarus.

North Korea has been pointed out by the U.S government behind the Sony attack, but they always denied against such kind of actions. Pyongyang has been blamed by the South Korea for the malicious campaigns that target the country.

According to the reports, it's not directly mentioned that North Korea was responsible, but there are some evidences that shows that probably it was North Korea who was responsible for the Sony attack. Evidences that were mentioned in reports were like that- The working hours in which the threat actors compiled the malicious tools was associated with the GMT+8 and GMT+9 time zones, which matches North Korea. Most of the Lazarus samples have been the PE resource with Korean language.

Jaime Blasco (chief scientist at AlienVault) said that, 
“This actor has the necessary skills and determination to perform cyberespionage operations with the purpose of stealing data or causing damage. Combining that with the use of disinformation and deception techniques, the attackers have been able to successfully launch several operations over the last few years,”

If you want to know more about Technical details then you can go through the reports published by the firm AlienVault, Kaspersky, Symantec and Novetta.