Monthly Archives: October 2014
Counter surveillance tech – can gadgets spy-proof your life?
Over the past few years, counter surveillance gadgets which might have been the preserve of secretive government departments a decade ago have suddenly hit mainstream shops – from Mission Impossible-stlye self-destructing drives to some rather eerie counter-surveillance masks.
The post Counter surveillance tech – can gadgets spy-proof your life? appeared first on We Live Security.
![]()
CVE-2014-7298 (centrify_suite, directcontrol)
adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX allows local users to read arbitrary files with root privileges by leveraging improperly protected setuid functionality.
CVE-2014-8346 (findmymobile, mobile)
The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic.
MyBB MyBBlog 1.0 Cross Site Scripting
MyBB MyBBlog plugin version 1.0 suffers from a cross site scripting vulnerability. Note that this finding houses site-specific data.
The 3 most common questions about Clickjacking
This procedure is called Clickjacking and it is one of the most used techniques by hackers trying to gain access over your accounts or obtain private data.
How does clickjacking work?
It all starts with a user receiving an e-mail that mimics perfectly the messages usually sent by a company he is a client of. This e-mail would have to include a fake link for the user to reset the password used on the real company website when he would actually be providing the hackers access to his account. Knowing both the e-mail address and the associated password, they can now extract all the personal information they need and take over the specific account.
Practically, once the customer clicks on the button in the e-mail, he will end up on the hacker’s website. There, the latter will attempt to make an http/https call to the real company’s API’s/forms to reset the user’s password/e-mail address and take over his account.
When does clickjacking this work?
In order for clickjacking to work, the user had to be previously logged in the account that he owns on the real company website. Also, if no CSRF protection is activated on the company’s end and official website/API accepts calls from other domains with no filtering, chances are that the operation becomes successful.
Clickjacking can also work locally (on your machine) when you manually create an iFrame and inject the company’s forms. This however doesn’t impact the end user/ customer because it only takes place on the hacker’s computer.
How can I be sure that I am not a victim of clickjacking?
We recommend all companies to implement the 2 following methods to keep safe from this kind of attacks:
- Do not accept requests from other websites (domains). If possible, use the x-frame-options header and set it to SAMEORIGIN so that other domains cannot access the methods/ API on your company’s end (this header should not be accessible / usable in all browsers).
- Implement CSRF token validation making sure that for each form display page there is an uniquely assigned CSRF token to the customer. The CSRF token can only be obtained by logging in as the real customer.
The post The 3 most common questions about Clickjacking appeared first on Avira Blog.
Vulnerability in Microsoft OLE Could Allow Remote Code Execution
Microsoft has issued security advisory 3010060 to identify a vulnerability in OLE that could allow remote code execution. This vulnerability, CVE-2014-6352, is present in all supported versions of Microsoft Windows, excluding Windows Server 2003.
Vuln: Centreon and Centreon Enterprise Server CVE-2014-3828 Multiple SQL Injection Vulnerabilities
Centreon and Centreon Enterprise Server CVE-2014-3828 Multiple SQL Injection Vulnerabilities
Vuln: Apple Mac OS X CVE-2014-4391 Security Bypass Vulnerability
Apple Mac OS X CVE-2014-4391 Security Bypass Vulnerability
Vuln: Ecava IntegraXor Account Information Disclosure Vulnerability
Ecava IntegraXor Account Information Disclosure Vulnerability