=======================
= End-of-Shift report =
=======================
Timeframe: Donnerstag 05-01-2017 18:00 − Montag 09-01-2017 18:00
Handler: Stephan Richter
Co-Handler: n/a
*** Upcoming Security Updates for Adobe Acrobat and Reader (APSB17-01) ***
---------------------------------------------
A prenotification Security Advisory (APSB17-01) has been posted regarding upcoming releases for Adobe Acrobat and Reader scheduled for Tuesday, January 10, 2017. We will continue to provide updates on the upcoming releases via the Security Advisory as well as the...
---------------------------------------------
https://blogs.adobe.com/psirt/?p=1434
*** Great Misadventures of Security Vendors: Absurd Sandboxing Edition, (Fri, Jan 6th) ***
---------------------------------------------
Like many security researchers, I employ a variety of OPSEC techniques to help detect if I have been targeted by something for whatever reason. One of those techniques I use in Virustotal is basically a vanity Yara rule that looks for a variety of strings that would indicate malware was specifically targeting me or some data was uploaded that references me. Virustotal Intelligence is a useful too for doing that and many researchers have paid for access which allows you to also download samples...
---------------------------------------------
https://isc.sans.edu/diary.html?storyid=21895&rss
*** Using Security Tools to Compromize a Network, (Sat, Jan 7th) ***
---------------------------------------------
One of our daily tasks is to assess and improve the security of our customers or colleagues. To achieve this use security tools (linked to processes). With the time, we are all building our personal toolbox with our favourite tools.Yesterday, I read an interesting blog article about extracting saved credentials from a compromised Nessus system[1]. This in indeed a nice target forthe bad guy! Why? Such security tools deployed inside a network have interesting characteristics: They have...
---------------------------------------------
https://isc.sans.edu/diary.html?storyid=21903&rss
*** Erpressertrojaner griffen kürzlich mehr als 10.000 Datenbanken an ***
---------------------------------------------
Schwachstellen bei MongoDB ausgenutzt, Sicherheitsforscher sprechen von Angriffswelle
---------------------------------------------
http://derstandard.at/2000050382671
*** Sicherheitsupdates: LibVNCServer gegen Speicherfehler gerüstet ***
---------------------------------------------
Seit über zwei Jahren hat die Programmbibliothek keine Updates spendiert bekommen. Nun schließen die Entwickler zwei Schwachstellen.
---------------------------------------------
https://heise.de/-3591417
*** 11 Steps to Improve Your Public Wi-Fi Security [Updated] ***
---------------------------------------------
A day without Wi-Fi is a day not fully lived. We're (somewhat) exaggerating, but it's fair to say Wi-Fi has become a staple of the modern life.
---------------------------------------------
https://heimdalsecurity.com/blog/11-security-steps-public-wi-fi-networks/
*** SWIFT speaks on fraudulent messages and the security moves the cooperative is making to assist its customers ***
---------------------------------------------
The February 2016 attack on Bangladesh Bank which involved the sending of fraudulent SWIFT messages from the bank's environment, was followed by a number of other attacks on banks using the SWIFT network. The criminal hackers' intention is to compromise the banks' environments in order to gain their SWIFT credentials, send fraudulent messages and route payments to themselves. Since that time, the SWIFT cooperative has instituted measures ultimately designed to help their...
---------------------------------------------
http://www.cio.com/article/3155253/security/swift-speaks-on-fraudulent-mess…
*** FTC Takes D-Link to Court Because of Insecure Routers and Cameras ***
---------------------------------------------
The US Federal Trade Commission (FTC) has filed a lawsuit against D-Link, a Taiwanese hardware manufacturer, for misrepresentations about the security of various devices it sold in the US, and for failing to take action and secure devices when security flaws were reported. [...]
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ftc-takes-d-link-to-court-be…
*** WordPress, Joomla, and Magento Continue to Be the Most Hacked CMSs ***
---------------------------------------------
Based on statistical data gathered by Sucuri from 7,937 compromised websites, WordPress, Joomla, and Magento, in this order, continued to be the most hacked CMS platforms in the third quarter of 2016 (months of July, August, and September). [...]
---------------------------------------------
https://www.bleepingcomputer.com/news/security/wordpress-joomla-and-magento…
*** DFN-CERT-2017-0027: OpenSSL: Eine Schwachstelle ermöglicht das Ausspähen von Informationen ***
---------------------------------------------
Eine Schwachstelle in OpenSSL sowie den Derivaten wie z.B. LibreSSL und BoringSSL ermöglicht einem lokalen, nicht authentisierten Angreifer das Ausspähen von privatem Schlüsselmaterial.
Die Entwickler von OpenSSL stellen bislang noch keine Sicherheitsupdates zur Verfügung.
OpenBSD stellt Source Code Patches für die Versionen OpenBSD 5.9 und 6.0 als Sicherheitsupdates bereit.
---------------------------------------------
https://portal.cert.dfn.de/adv/DFN-CERT-2017-0027/
*** NETGEAR ProSAFE Firewall Bug Lets Remote Users Traverse the Directory to View Files on the Target System ***
---------------------------------------------
http://www.securitytracker.com/id/1037548
*** IBM Security Bulletins ***
---------------------------------------------
*** IBM Security Bulletin: Fixes for Multiple Security Vulnerabilities in IBM Security Identity Manager Virtual Appliance available ***
http://www-01.ibm.com/support/docview.wss?uid=swg21996761
---------------------------------------------
*** IBM Security Bulletin: Security vulnerabilities in IBM Java Runtime and Apache Tomcat affects IBM RLKS Administration and Reporting Tool Admin (CVE-2016-5597, CVE-2016-3092) ***
http://www-01.ibm.com/support/docview.wss?uid=swg21995448
---------------------------------------------
*** IBM Security Bulletin: Vulnerabilitiy in OpenSSL affect IBM Storwize V7000 Unified ***
http://www.ibm.com/support/docview.wss?uid=ssg1S1009699
---------------------------------------------
*** IBM Security Bulletin: IBM InfoSphere DataStage is vulnerable to Cross-Frame Scripting issue (CVE-2016-9000) ***
http://www-01.ibm.com/support/docview.wss?uid=swg21995257
---------------------------------------------
*** IBM Security Bulletin: IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability (CVE-2016-8999) ***
http://www-01.ibm.com/support/docview.wss?uid=swg21995155
---------------------------------------------
*** IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect Rational Service Tester (CVE-2016-5597) ***
http://www.ibm.com/support/docview.wss?uid=swg21995687
---------------------------------------------
*** IBM Security Bulletin: Security vulnerabilities in IBM SDK for Node.js might affect IBM Business Process Manager (BPM) Configuration Editor ***
http://www-01.ibm.com/support/docview.wss?uid=swg21995758
---------------------------------------------
*** IBM Security Bulletin: IBM Cognos Business Intelligence Server 2016Q4 Security Updater : IBM Cognos Business Intelligence Server is affected by multiple vulnerabilities. ***
http://www-01.ibm.com/support/docview.wss?uid=swg21995691
---------------------------------------------
*** IBM Security Bulletin: Vulnerabilities in 64-bit block ciphers affects IBM License Metric Tool and IBM Tivoli Asset Discovery for Distributed (CVE-2016-2183, CVE-2016-6329) ***
http://www.ibm.com/support/docview.wss?uid=swg21993665
---------------------------------------------
*** IBM Security Bulletin: Apache Xerces-C vulnerabilities (XML4C) affects IBM Cloud Manager with OpenStack (CVE-2016-0729) ***
http://www.ibm.com/support/docview.wss?uid=isg3T1024708
---------------------------------------------
=======================
= End-of-Shift report =
=======================
Timeframe: Mittwoch 04-01-2017 18:00 − Donnerstag 05-01-2017 18:00
Handler: Stephan Richter
Co-Handler: n/a
*** E-Banking-Trojaner: Über 100.000 Euro Schaden ***
---------------------------------------------
Eine E-Banking-Schadsoftware hat bei einer Netzwerktechnikfirma in der Stadt Salzburg über 100.000 Euro Schaden angerichtet. Mehrere Überweisungen wurden auf ein slowakisches Konto umgeleitet.
---------------------------------------------
http://salzburg.orf.at/news/stories/2818225/
*** Microsoft kills off security bulletins - for good ***
---------------------------------------------
Microsoft's last ever security bulletin is next week - so has the manual bulletin had its day?
---------------------------------------------
https://www.htbridge.com/blog/microsoft-kills-off-security-bulletins-for-go…
*** VB2016 paper: Open Source Malware Lab ***
---------------------------------------------
At VB2016, ThreatConnect Director of Research Innovation Robert Simmons presented a paper on setting up an open source malware lab. Today, we share the accompanying paper and video.
---------------------------------------------
https://www.virusbulletin.com/blog/2017/01/vb2016-paper-open-source-malware…
*** What Hack? Burlington Electric Speaks Out ***
---------------------------------------------
Burlington Electric Department general manager Neale Lunderville speaks out about last weeks incident and response to reports the electric grid had been hacked.
---------------------------------------------
http://threatpost.com/what-hack-burlington-electric-speaks-out/122860/
*** Hackers could turn your smart meter into a bomb and blow your family to smithereens - new claim ***
---------------------------------------------
And before that, pwn your IoT gadgets via power supply gear Smart meters are "dangerously insecure," according to researcher Netanel Rubin - who claimed the gear uses weak encryption, relies on easily pwned protocols, and can be programmed to explode.
---------------------------------------------
http://go.theregister.com/feed/www.theregister.co.uk/2017/01/04/smart_metre…
*** FireCrypt Ransomware Comes With a DDoS Component ***
---------------------------------------------
A new ransomware family named FireCrypt will encrypt the users files, but also attempt to launch a very feeble DDoS attack on a URL hardcoded in its source code.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/firecrypt-ransomware-comes-w…
*** Emsisoft releases a decryptor for version 3 of the Globe Ransomware ***
---------------------------------------------
Fabian Wosar of Emisoft has released a decrypter for version 3 of the Globe Ransomware. This decryptor will decrypt the Globe Ransomware variants that commonly append the .decrypt2017 and .hnumkhotep extensions to encrypted files.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/emsisoft-releases-a-decrypto…
*** Mixed Messages : Novel Phishing Attempts Trying to Steal Your E-mail Password Goes Wrong, (Wed, Jan 4th) ***
---------------------------------------------
A writer wrote in to send us an interesting phishing attempt they had received at their organization. An email from a school domain that purported to be VetMeds send an encrypted PDF that required a user-name and password to log in to. The subject of the email was Assessment document. The PDF itself was created with Microsoft Word and included a link that suggested it was a locked document and you needed to click a link to unlock it which pointed to chai[.]myjino[.]ru and gave a screen with a...
---------------------------------------------
https://isc.sans.edu/diary.html?storyid=21881&rss
*** KillDisk Ransomware Now Targets Linux, Prevents Boot-Up, Has Faulty Encryption ***
---------------------------------------------
Researchers have discovered a Linux variant of the KillDisk ransomware, which itself is a new addition to the KillDisk disk wiper malware family, previously used only to sabotage companies by randomly deleting data and altering files. [...]
---------------------------------------------
https://www.bleepingcomputer.com/news/security/killdisk-ransomware-now-targ…
*** [R1] Nessus 6.9.3 Fixes One Vulnerability ***
---------------------------------------------
Tenable Nessus was found to be impacted by an authenticated stored cross-site scripting (XSS) issue.
---------------------------------------------
https://www.tenable.com/security/tns-2017-01
*** HPSBGN03688 rev.1 - HPE Operations Orchestration, Remote Code Execution ***
---------------------------------------------
A potential security vulnerability has been identified in HPE Operations Orchestration. The vulnerability could be remotely exploited to allow remote code execution.
---------------------------------------------
http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05361944
*** Google Nexus Qualcomm GPU Driver CVE-2016-8434 Privilege Escalation Vulnerability ***
---------------------------------------------
Google Nexus is prone to a privilege-escalation vulnerability. Attackers can exploit this issue to execute arbitrary code with elevated privileges within the context of the kernel.
---------------------------------------------
http://www.securityfocus.com/bid/95257
*** Atlassian Confluence 5.9.12 Cross Site Scripting ***
---------------------------------------------
Topic: Atlassian Confluence 5.9.12 Cross Site Scripting Risk: Low Text: ==[ Tempest Security Intelligence - ADV-3/2016 CVE-2016-6283 ] == Persisted Cross-Site Scripting (XSS) in Confluence J...
---------------------------------------------
https://cxsecurity.com/issue/WLB-2017010029
*** ShoreTel Mobility Client iOS 9.1.2.101 SSL Man-In-The-Middle ***
---------------------------------------------
Topic: ShoreTel Mobility Client iOS 9.1.2.101 SSL Man-In-The-Middle Risk: Medium Text:ShoreTel Mobility Client iOS Application - MITM SSL Certificate Vulnerability (CVE-2016-6562) Overview "The Mobility Clie...
---------------------------------------------
https://cxsecurity.com/issue/WLB-2017010028
*** Doubleclick for Publishers (DFP) - Moderately Critical - Multiple vulnerabilities - SA-CONTRIB-2017-002 ***
---------------------------------------------
Advisory ID: DRUPAL-SA-CONTRIB-2017-002Project: Doubleclick for Publishers (DFP) (third-party module)Version: 7.xDate: 2017-January-04Security risk: 10/25 ( Moderately Critical) AC:Complex/A:User/CI:None/II:None/E:Exploit/TD:AllVulnerability: Cross Site ScriptingDescriptionThis module enables you to to place advertisements on your site that are served by Googles DFP (Doubleclick for Publisher) service.The module has multiple Cross Site Scripting (XSS) vulnerabilities due to not sufficiently...
---------------------------------------------
https://www.drupal.org/node/2841114
*** Permissions by Term -- Critical - Multiple vulnerabilities - SA-CONTRIB-2017-001 ***
---------------------------------------------
Advisory ID: DRUPAL-SA-CONTRIB-2017-001Project: Permissions by Term (third-party module)Version: 8.xDate: 2017-January-04Security risk: 15/25 ( Critical) AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypass, Information DisclosureDescriptionThe Permissions by Term module extends Drupal functionality by restricting access to single nodes via taxonomy terms. Taxonomy terms are part of the Drupal core functionality. Taxonomy term permissions can be coupled to specific...
---------------------------------------------
https://www.drupal.org/node/2841094
*** IBM Security Bulletins ***
---------------------------------------------
*** IBM Security Bulletin: Vulnerability in HTTP request processing affects IBM License Metric Tool v9 and IBM BigFix Inventory v9 (CVE-2016-8977) ***
http://www-01.ibm.com/support/docview.wss?uid=swg21995014
---------------------------------------------
*** IBM Security Bulletin:IBM SDK, Java Technology Edition Quarterly CPU Oct 2016 Includes Oracle Oct 2016 CPU affect Content Collector for Email ***
https://www-01.ibm.com/support/docview.wss?uid=swg21995468
---------------------------------------------
*** IBM Security Bulletin: vCenter password disclosure via application tracing in IBM Tivoli Storage Manager Client and IBM Tivoli Storage Manager for Virtual Environments:Data Protection for VMware (CVE-2016-6110) ***
http://www.ibm.com/support/docview.wss?uid=swg21996198
---------------------------------------------
*** IBM Security Bulletin:Vulnerabilities in Apache Tomcat and OpenSSL affect Rational BuildForge ***
http://www-01.ibm.com/support/docview.wss?uid=swg21995528
---------------------------------------------
*** IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter systems ***
https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5099526
---------------------------------------------
*** IBM Security Bulletin: Vulnerability in OpenSSL affects IBM Advanced Management Module (AMM) for BladeCenter systems ***
https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5099528
---------------------------------------------
*** IBM Security Bulletin: IBM Tivoli Common Reporting (TCR) 2016Q4 Security Updater : TCR is affected by multiple vulnerabilities. ***
http://www-01.ibm.com/support/docview.wss?uid=swg21996032
---------------------------------------------
*** IBM Security Bulletin: Vulnerability in DHCP affects IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter systems ***
https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5099529
---------------------------------------------
*** IBM Security Bulletin: Vulnerabilities in GNU C Library affect IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter systems ***
https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5099524
---------------------------------------------
*** IBM Security Bulletin: Apache Xerces-C vulnerabilities affects IBM Cloud Manager with OpenStack (CVE-2016-4463) ***
http://www.ibm.com/support/docview.wss?uid=isg3T1024585
---------------------------------------------
Next End-of-Shift report: 2017-01-09
=======================
= End-of-Shift report =
=======================
Timeframe: Dienstag 03-01-2017 18:00 − Mittwoch 04-01-2017 18:00
Handler: Alexander Riepl
Co-Handler: n/a
*** Technical details on the Fancy Bear Android malware (poprd30.apk) ***
---------------------------------------------
Background Recently, Crowdstrike has published details about a malicious Android APK file, named poprd30.apk or Попр-Д30.apk. It seems that the malware was created by the Fancy Bear group for tracking Ukrainian field ..
---------------------------------------------
http://blog.crysys.hu/2017/01/technical-details-on-the-fancy-bear-android-m…
*** Remote Code Execution in third party library swiftmailer ***
---------------------------------------------
https://typo3.org/news/article/remote-code-execution-in-third-party-library…
*** Real World FSociety Malware Is Giving Mr. Robot a Bad Name ***
---------------------------------------------
In the past few weeks, more or less talented malware authors have resorted to naming their newly launched threats using the "FSociety" brand, made famous by the Mr. Robot TV series.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/real-world-fsociety-malware-…
*** Microsoft to Add Bitcoin Support to Excel Later This Year ***
---------------------------------------------
https://www.bleepingcomputer.com/news/software/microsoft-to-add-bitcoin-sup…
*** Campaign Evolution: pseudo-Darkleech in 2016 ***
---------------------------------------------
Darkleech is long-running campaign that uses exploit kits (EKs) to deliver malware. First identified in 2012, this campaign has used different EKs to distribute various types of ..
---------------------------------------------
http://researchcenter.paloaltonetworks.com/2016/12/unit42-campaign-evolutio…
*** The Download on the DNC Hack ***
---------------------------------------------
Over the past few weeks, Ive been inundated with questions from readers asking why I havent written much about two stories that have consumed the news media of late: The alleged ..
---------------------------------------------
https://krebsonsecurity.com/2017/01/the-download-on-the-dnc-hack/
*** l+f: Russische Hacker aus der postapokalyptischen Strahlenwüste ***
---------------------------------------------
https://heise.de/-3587018
*** Eindringling nimmt offenbar MongoDB-Datenbanken als Geisel ***
---------------------------------------------
Ein unbekannter Angreifer soll ungeschützte MongoDB-Datenbanken leeren und den Eigentümern eine Erpresser-Botschaft hinterlassen.
---------------------------------------------
https://heise.de/-3587479
*** Sicherheitslücke: Kaspersky schlampt bei TLS-Zertifikatsprüfung ***
---------------------------------------------
Die Antivirensoftware von Kaspersky liest bei TLS-Verbindungen mit und sorgt nebenbei dafür, dass die Zertifikatsprüfung ausgehebelt wird. Wieder einmal konnte Tavis Ormandy von Google damit zeigen, wie löchrig sogenannte Sicherheitssoftware ist.
---------------------------------------------
http://www.golem.de/news/sicherheitsluecke-kaspersky-schlampt-bei-tls-zerti…
*** Gefälschte Erste Bank/Sparkasse-Mail: Bestätigung erforderlich ***
---------------------------------------------
Mit einer gefälschten Erste Bank/Sparkasse-Nachricht wollen Kriminelle OnlineBanking-Zugangsdaten von Kund/innen stehlen. Damit sie das Ziel erreichen, behaupten sie in dem ..
---------------------------------------------
https://www.watchlist-internet.at/phishing/gefaelschte-erste-banksparkasse-…
*** Programmiersprachen: Sicheres NTP könnte von C auf Rust oder Go wechseln ***
---------------------------------------------
Mit NTPsec erstellt ein Team um den Open-Source-Pionier Eric S. Raymond eine sichere Implementierung für NTP. Das Team überlegt, sich komplett von dem C-Code zu trennen und stattdessen eine sichere Programmiersprache wie Rust oder Go zu verwenden.
---------------------------------------------
http://www.golem.de/news/programmiersprachen-sicheres-ntp-koennte-von-c-auf…
*** BlackBerry, Google und LG patchen unter anderem abermals kritische Stagefright-Lücke ***
---------------------------------------------
Bereits seit Juni 2015 kämpft Google gegen kritische Schwachstellen in Multimedia-Komponenten von Android. Der alleinige Empfang einer MMS kann ein Gerät schachmatt setzen. Nun liefern verschiedene Hersteller erneut Sicherheitsupdates.
---------------------------------------------
https://heise.de/-3587867
=======================
= End-of-Shift report =
=======================
Timeframe: Montag 02-01-2017 18:00 − Dienstag 03-01-2017 18:00
Handler: Alexander Riepl
Co-Handler: n/a
*** Aus der Filterbubble #33c3 zurück in die Realität ***
---------------------------------------------
Der 33. Chaos Communication Congress war mein erster. Was mich am meisten beeindruckt hat. Und wie es ist, wieder im Alltag anzukommen.
---------------------------------------------
https://futurezone.at/myfuzo/blog/aus-der-filterbubble-33c3-zurueck-in-die-…
*** Mac Malware of 2016 ***
---------------------------------------------
Lets analyse the malware that appeared in 2016, discussing the infection vector, persistence mechanism, feature, and disinfection for each.
---------------------------------------------
https://objective-see.com/blog/blog_0x16.html
*** Website Malware Targets Mobile Platforms ***
---------------------------------------------
Navigating the web on a mobile device can be tricky even when you’re browsing clean sites. If hackers are involved, the frustration of a pop-up can turn into the dangerous possibility ..
---------------------------------------------
https://blog.sucuri.net/2017/01/website-malware-targets-mobile-platforms.htm
*** Android tops 2016 vuln list, with 523 bugs ***
---------------------------------------------
Google joins Microsoft, Apple, Adobe in top of the pops Of any single product, CVE Details reckons, Android had the most reported vulnerabilities in 2016 – but as a vendor, Adobe still tops the list.
---------------------------------------------
www.theregister.co.uk/2017/01/03/android_tops_2016_vuln_list_with_523_bugs/
*** Lauri Love: Love gegen die Vereinigten Staaten von Amerika ***
---------------------------------------------
Der Anonymous-Aktivist und Hacker Lauri Love soll an die USA ausgeliefert werden. Dort drohen ihm wegen des unberechtigten Veränderns von Webseiten und Hacking fast 100 Jahre Haft. Wenn wir Lauri nicht retten können, können wir uns auch nicht selbst retten, warnen Aktivisten.
---------------------------------------------
http://www.golem.de/news/lauri-love-love-gegen-die-vereinigten-staaten-von-…
*** libpng-Entwickler schließen 21 Jahre alte Sicherheitslücke ***
---------------------------------------------
Praktisch alle Versionen der Programmbibliothek libpng sind verwundbar. Über eine Schwachstelle könnten Angreifer Systeme lahmlegen. Abgesicherte Versionen sind verfügbar.
---------------------------------------------
https://heise.de/-3585996
*** Top Secret -cleared SOCOM staff in 11GB Govt contractor breach ***
---------------------------------------------
Dismissed hacker calls US Govt buddy to nix exposed database A Pentagon subcontractor has exposed the names, locations, Social Security Numbers, and salaries of Military Special ..
---------------------------------------------
www.theregister.co.uk/2017/01/03/top_secret_cleared_socom_staff_in_11gb_gov…
*** Deprecation of Insecure Algorithms and Protocols in RHEL 6.9 ***
---------------------------------------------
Cryptographic protocols and algorithms have a limited lifetime—much like everything else in technology. Algorithms that provide cryptographic hashes and encryption as well as ..
---------------------------------------------
https://access.redhat.com/blogs/766093/posts/2787271
*** Doch keine Spur nach Russland nach Angriff auf US-Stromversorger ***
---------------------------------------------
Ermittler fanden keine Indizien – Mitarbeiter hatte mit eigenem Laptop Mails aufgerufen
---------------------------------------------
http://derstandard.at/2000050193323
=======================
= End-of-Shift report =
=======================
Timeframe: Freitag 30-12-2016 18:00 − Montag 02-01-2017 18:00
Handler: Alexander Riepl
Co-Handler: n/a
*** Sundown Exploit Kit now leverages on the steganography ***
---------------------------------------------
A new variant of the Sundown exploit kit leverages on steganography to hide exploit code in harmless-looking image files. Security experts from Trend Micro have spotted a new version of the Sundown exploit kit .. ---------------------------------------------
http://securityaffairs.co/wordpress/54886/cyber-crime/sundown-exploit-kit-2…
*** Russische Cyberattacken gegen USA: Junge Hackerin als Mastermind verdächtigt ***
---------------------------------------------
Soll Geheimdienst unterstützt haben – Alisa Schewtschenko sieht sich als Sündenbock in Konflikt zwischen Obama und Putin
---------------------------------------------
http://derstandard.at/2000050064533
*** Grizzly Steppe: Russischer Schadcode bei US-Stromversorger gefunden ***
---------------------------------------------
Zum Glück war es kein Steuerungsrechner: Ein US-Elektrizitätsversorger hat in einem Computer Schadcode gefunden, der von Grizzly Steppe stammen könnte. Die US-Behörden wollen jetzt untersuchen, ob weitere Versorgungsunternehmen betroffen sind.
---------------------------------------------
http://www.golem.de/news/grizzly-steppe-russischer-schadcode-bei-us-stromve…
*** DSA-3750 libphp-phpmailer - security update ***
---------------------------------------------
Dawid Golunski discovered that PHPMailer, a popular library to sendemail from PHP applications, allowed a remote attacker to executecode if they were able to provide a crafted Sender address.
---------------------------------------------
https://www.debian.org/security/2016/dsa-3750
*** Creepy Site Claims To Reveal Torrenting Histories ***
---------------------------------------------
Slashdot reader dryriver writes: The highly invasive and possibly Russian owned and operated website IKnowWhatYouDownload.com immediately shows [a] bittorent download history for ..
---------------------------------------------
https://yro.slashdot.org/story/16/12/31/0214203/creepy-site-claims-to-revea…
*** Zend Framework Input Validation Flaw in zend-mail Lets Remote Users Execute Arbitrary Code on the Target System ***
---------------------------------------------
http://www.securitytracker.com/id/1037539
*** Linux Kernel sg_write() and bsg_write() Functions Let Local Users Obtain Root Privileges ***
---------------------------------------------
http://www.securitytracker.com/id/1037538
*** E-Mail-Dienst Lavabit kehrt zur Trump-Angelobung zurück ***
---------------------------------------------
Der ehemalige E-Mail-Anbieter, den Edward Snowden nutzte, könnte ausgerechnet zur Trump-Inauguration zurückkommen.
---------------------------------------------
https://futurezone.at/digital-life/e-mail-dienst-lavabit-kehrt-zur-trump-an…
*** Nach stundenlangem Ausfall: Bankomatkassen wieder in Betrieb ***
---------------------------------------------
Technische Probleme der Schweizer Firma SIX Payment Service behoben – Bankomaten nicht betroffen
---------------------------------------------
http://derstandard.at/2000050083333
*** Firefox 52 more privacy oriented with a Tor protection mechanism ***
---------------------------------------------
Mozilla development team announced a new privacy protection mechanism that will come with Firefox 52, it aims to prevent websites from fingerprinting users. Mozilla announced the introduction of a new privacy protection ..
---------------------------------------------
http://securityaffairs.co/wordpress/54938/digital-id/firefox-52-privacy.html
*** Thunderbird: Mozilla schließt mit Sicherheitsupdate kritische Lücken ***
---------------------------------------------
In Thunderbird klaffen mehrere Sicherheitslücken, deren Bedrohungsgrad Mozilla mit 'kritisch' und 'hoch' einstuft. Eine abgesicherte Version ist verfügbar.
---------------------------------------------
https://heise.de/-3583472
*** Erpresser-Botschaft in Dauerschleife: Smart TV von LG mit Ransomware infiziert ***
---------------------------------------------
Bisher warnten Sicherheitsforscher nur davor, dass Erpressungs-Trojaner auch Smart TVs mit Android-Betriebssystem befallen könnten. Nun ist es offensichtlich zu einer ersten dokumentierten Infektion gekommen.
---------------------------------------------
https://heise.de/-3584043
*** l+f: Lesen statt Lösegeld ***
---------------------------------------------
Ein Erpressungs-Trojaner zwingt seine Opfer, sich in puncto Computer-Sicherheit weiterzubilden.
---------------------------------------------
https://heise.de/-3585353
*** Russische Hacker nutzten laut FBI für Angriffe auch Rechner in Wien ***
---------------------------------------------
Server des Vereins "Funkfeuer" findet sich auf von US-Behörden veröffentlichter Liste an Angriffscomputern
---------------------------------------------
http://derstandard.at/2000050143907
=======================
= End-of-Shift report =
=======================
Timeframe: Donnerstag 29-12-2016 18:00 − Freitag 30-12-2016 18:00
Handler: Robert Waldner
Co-Handler: Alexander Riepl
*** Session Stealer Script Used In OpenCart ***
---------------------------------------------
With so many open-source ecommerce platforms available in the market, selling online is an appealing and easy option for any store owner. In a few clicks you can set up an online storefront and sell your products. While the process to get the site up may be simple, there are .. ---------------------------------------------
https://blog.sucuri.net/2016/12/session-stealer-script-used-opencart.html
*** Recent Spam Runs in Germany Show How Threats Intend to Stay in the Game ***
---------------------------------------------
In early December, GoldenEye ransomware (detected by Trend Micro as RANSOM_GOLDENEYE.A) was observed targeting German-speaking users—particularly those belonging to the human ..
---------------------------------------------
http://blog.trendmicro.com/trendlabs-security-intelligence/recent-spam-runs…
*** Grizzly Steppe: FBI nennt 900 IP-Adressen russischer Hackerangriffe ***
---------------------------------------------
Nach den Sanktionen folgen die Indikatoren: Die US-Regierung veröffentlicht ihre Analyse zu den angeblich russischen Hackerattacken auf weltweite Institutionen. Auch über IP-Adressen aus Deutschland sollen die Angriffe gelaufen sein.
---------------------------------------------
http://www.golem.de/news/grizzly-steppe-fbi-nennt-900-ip-adressen-russische…
*** Apples iMessage anfällig für manipulierte Kontaktdateien ***
---------------------------------------------
Eine manipulierte vCard, die aktuell per iMessage und MMS im Umlauf ist, kann die Nachrichten-App auf dem iPhone oder iPad des Empfängers zum Absturz bringen – und komplett lahmlegen. Es gibt aber einen Ausweg.
---------------------------------------------
https://heise.de/-3582980
*** Vuln: Lenovo Transition CVE-2016-8227 Local Privilege Escalation Vulnerability ***
---------------------------------------------
http://www.securityfocus.com/bid/95159
*** More on Protocol 47 denys ***
---------------------------------------------
Following up on yesterdays diary on an increase in Protocol 47 traffic. Thanks to everyone who sent the ISC PCAPs and more information. Current speculation is the Protocol 47 uptick is backscatter from a DDOS containing GRE traffic and using ..
---------------------------------------------
https://isc.sans.edu/diary.html?storyid=21867&rss
*** Cyber-Angriffe: Die schwierige Spurensuche ***
---------------------------------------------
Vorwürfe eher auf Basis eines Motivs denn auf Basis technischer Hinweise oder Beweise
---------------------------------------------
http://derstandard.at/2000050034274
*** Dell SonicWALL Secure Mobile Access SMA 8.1 XSS And WAF CSRF ***
---------------------------------------------
SonicWALL SMA suffers from a XSS issue due to a failure to properly sanitize user-supplied input to several parameters. Attackers can exploit this weakness to execute arbitrary HTML and script code in a users browser session. The WAF was bypassed via form-based CSRF.
---------------------------------------------
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5393.php
*** Dell SonicWALL Network Security Appliance NSA 6600 Reflected XSS ***
---------------------------------------------
SonicWALL NSA suffers from a XSS issue due to a failure to properly sanitize user-supplied input to the curUserName GET parameter in the appFirewallSummary.html script. Attackers can exploit this weakness to execute arbitrary HTML and script code in a users browser session.
---------------------------------------------
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5391.php
*** Dell SonicWALL Global Management System (GMS) 8.1 Adobe Flex SOP Bypass ***
---------------------------------------------
Dell SonicWALL GMS versions 8.1 and below are compiled with a vulnerable version of Adobe Flex SDK allowing for same-origin request forgery and cross-site content hijacking.
---------------------------------------------
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5390.php
*** Dell SonicWALL Global Management System GMS 8.1 XSS Vulnerabilities ***
---------------------------------------------
Dell SonicWALL GMS suffers from multiple reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a users browser session in context of an affected site.
---------------------------------------------
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5389.php
*** Dell SonicWALL Global Management System GMS 8.1 Blind SQL Injection ***
---------------------------------------------
Dell SonicWALL GMS suffers from multiple SQL Injection vulnerabilities. Input passed via the GET parameters searchBySonicwall, firstChangeOrderID, secondChangeOrderID and coDomainID is not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
---------------------------------------------
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5388.php
=======================
= End-of-Shift report =
=======================
Timeframe: Mittwoch 28-12-2016 18:00 − Donnerstag 29-12-2016 18:00
Handler: Robert Waldner
Co-Handler: Alexander Riepl
*** 33C3: Türsprechanlagen sind des Hackers fette Beute ***
---------------------------------------------
Immer mehr Hersteller von Sprechanlagen für Firmen- und Privathäuser setzen zur Kommunikationsübertragung auf den Mobilfunk statt leitungsgebundene Technik. Hackern wird es damit möglich, Türen zu öffnen oder Premiumnummern anzuwählen.
---------------------------------------------
https://heise.de/-3582807
*** IBM Security Bulletin: Multiple security vulnerabilities affect IBM WebSphere Application Server for Bluemix (CVE-2016-5573, CVE-2016-5597, CVE-2016-8934) ***
---------------------------------------------
There are multiple vulnerabiltities in the IBM® SDK Java™ Technology Edition that is shipped with IBM WebSphere Application Server. These issues were disclosed as part of the IBM SDK for Java updates in October ..
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg21995995
*** IBM Security Bulletin: GNU C library (glibc) vulnerabilities affect IBM Security Network Active Bypass (CVE-2016-3706, CVE-2016-4429) ***
---------------------------------------------
GNU C library (glibc) vulnerabilities were found that affect IBM Security Network Active Bypass. CVE(s): CVE-2016-3706, CVE-2016-4429 Affected product(s) and affected version(s): IBM Security ..
---------------------------------------------
http://www-01.ibm.com/support/docview.wss?uid=swg21996174
*** IBM Security Bulletin: Vulnerabilies (17 total), in Oracle Outside In Technology (OIT) affect FileNet Content Manager, and IBM Content Foundation ***
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg21988553
*** IBM Security Bulletin: Vulnerability in Apache PDFBox affects FileNet Content Manager and IBM Content Foundation (CVE-2016-2175) ***
---------------------------------------------
Security vulnerabilitiy exists in Apache PDFBox that affects IBM FileNet Content Manager and IBM Content ..
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=swg21987188
*** 33C3: Bitcoin-Automaten sind noch kein lohnendes Angriffsziel ***
---------------------------------------------
Sicherheitsexperten haben auf dem Hamburger Hackertreffen beklagt, dass bei klassischen Geldautomaten weiterhin große Sicherheitslücken bestehen. Bitcoin-Tauschmaschinen hingegen seien für Kriminelle noch uninteressant.
---------------------------------------------
https://heise.de/-3582875
=======================
= End-of-Shift report =
=======================
Timeframe: Dienstag 27-12-2016 18:00 − Mittwoch 28-12-2016 18:00
Handler: Robert Waldner
Co-Handler: Alexander Riepl
*** Bugtraq: PHPMailer < 5.2.20 Remote Code Execution PoC 0day Exploit (CVE-2016-10045) (Bypass of the CVE-2016-1033 patch) ***
---------------------------------------------
http://www.securityfocus.com/archive/1/539967
*** Security Advisory - FRP Bypass Vulnerability in Huawei Smart Phones ***
---------------------------------------------
http://www.huawei.com/en/psirt/security-advisories/2016/huawei-sa-20161228-…
*** Android Trojan Switcher Infects Routers via DNS Hijacking ***
---------------------------------------------
A new Android Trojan, Switcher, uses victims devices to infect WiFi routers and funnel users of the network to malicious sites.
---------------------------------------------
http://threatpost.com/android-trojan-switcher-infects-routers-via-dns-hijac…
*** Security Advisory - Input Validation Vulnerability in Huawei VRP Platform ***
---------------------------------------------
http://www.huawei.com/en/psirt/security-advisories/2016/huawei-sa-20161228-…
*** 33C3: Bluetooth-Schlösser: Smart, aber nicht sicher ***
---------------------------------------------
App statt Schlüssel: Immer mehr Hersteller bieten Schlösser mit Cloud-Anbindung an. Doch Lockpicker können die teuren Geräte ohne große Probleme knacken.
---------------------------------------------
https://heise.de/-3582323
*** IT-Sicherheit im Jahr 2016: Der Nutzer ist nicht schuld ***
---------------------------------------------
Geht es um IT-Sicherheitsprobleme, wird gern über die Nutzer geschimpft. Und auch wenn viele Nutzer tatsächlich Fehler machen, liegt die Verantwortung für Sicherheitslücken, Botnetze und mangelnden Datenschutz meist bei anderen.
---------------------------------------------
http://www.golem.de/news/it-sicherheit-im-jahr-2016-der-nutzer-ist-nicht-sc…
*** Bugtraq: [CVE-2016-8741] Apache Qpid Broker for Java - Information Leakage ***
---------------------------------------------
http://www.securityfocus.com/archive/1/539968
*** Using Guzzle and PHPUnit for REST API Testing ***
---------------------------------------------
APIs are increasingly becoming the backbone of the modern internet - whether youre ordering ..
---------------------------------------------
https://blog.cloudflare.com/using-guzzle-and-phpunit-for-rest-api-testing/
*** Vuln: Multiple Samsung Devices OTP Service Remote Heap Buffer Overflow Vulnerability ***
---------------------------------------------
http://www.securityfocus.com/bid/95134
*** IBM Security Bulletin: IBM Security Guardium Database Activity Monitor is affected by OS Command Injection (CVE-2016-6065) ***
---------------------------------------------
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root. IBM Security Guardium Database Activity ..
---------------------------------------------
http://www-01.ibm.com/support/docview.wss?uid=swg21995657
*** Hacker-Angriff auf OSZE in Wien: Daten gestohlen ***
---------------------------------------------
Die OSZE mit Sitz in Wien wurde Anfang November Ziel einer Hackerattacke. Daten und die Integrität des Netzwerkes der OSZE waren gefährdet, sagte eine Sprecherin.
---------------------------------------------
https://futurezone.at/netzpolitik/hacker-angriff-auf-osze-in-wien-daten-ges…
*** Reverse Engineering: Sicherheitsforscher öffnen Threema-Blackbox ***
---------------------------------------------
Zwei Sicherheitsforscher haben auf dem 33C3 einen genauen Blick in die innereien des Messengers Threema geworfen. Ihre Ergebnisse sind bei Github dokumentiert - und sollen sich für die Entwicklung von Bots eignen.
---------------------------------------------
http://www.golem.de/news/reverse-engineering-sicherheitsforscher-oeffnen-th…
=======================
= End-of-Shift report =
=======================
Timeframe: Freitag 23-12-2016 18:00 − Dienstag 27-12-2016 18:00
Handler: Robert Waldner
Co-Handler: Alexander Riepl
*** NetApp Snap Creator Framework Flaw Lets Remote Users Obtain Potentially Sensitive Information on the Target System ***
---------------------------------------------
http://www.securitytracker.com/id/1037530
*** BMC Remedy Action Request System Password Reset Flaw Lets Remote Users Modify Passwords on the Target System ***
---------------------------------------------
http://www.securitytracker.com/id/1037529
*** Netgear-Router N300 mit massiver Sicherheitslücke ***
---------------------------------------------
Netgears Router N300 (Modell WNR2000) weist eine Schwachstelle auf, über die Angreifer Zugriff auf die Admin-Funktionen des Geräts erlangen können. Ein ..
---------------------------------------------
http://derstandard.at/2000049819772
*** [local] - OpenSSH < 7.4 - UsePrivilegeSeparation Disabled Forwarded Unix Domain Sockets Privilege Escalation ***
---------------------------------------------
This issue affects OpenSSH if privilege separation is disabled (config option UsePrivilegeSeparation=no). While privilege separation is enabled by default, it ..
---------------------------------------------
https://www.exploit-db.com/exploits/40962/
*** ZyXEL and Netgear Fail to Patch Seven Security Flaws Affecting Their Routers ***
---------------------------------------------
Router manufacturers such as Netgear and ZyXEL have failed to address seven security flaws reported ..
---------------------------------------------
https://www.bleepingcomputer.com/news/security/zyxel-and-netgear-fail-to-pa…
*** DFN-CERT-2016-2141/">Exim: Zwei Schwachstellen ermöglichen das Ausspähen von Informationen und die Eskalation von Privilegien ***
---------------------------------------------
Ein entfernter, nicht authentifizierter Angreifer kann sensitive Informationen ausspähen und möglicherweise weitere Angriffe ausführen, wenn Exim unter bestimmten Bedingungen kompiliert wurde und ausgeführt wird. Dazu muss ..
---------------------------------------------
https://portal.cert.dfn.de/adv/DFN-CERT-2016-2141/
*** 33C3: CCC-Kongress beginnt in Hamburg ***
---------------------------------------------
Unter dem Motto "Works for me" hat der Kongress des Chaos Computer Clubs in Hamburg begonnen. Vier Tage lang beschäftigen sich die 12.000 Teilnehmer mit Hacks, Politik und alternativen Lebensentwürfen.
---------------------------------------------
https://heise.de/-3582149
*** Vuln: PyCrypto cryptmsg.py Buffer Overflow Vulnerability ***
---------------------------------------------
http://www.securityfocus.com/bid/95122
*** IBM Security Bulletin: Vulnerabilities in Bind affect IBM SmartCloud Entry (CVE-2016-2776 CVE-2016-2848 ) ***
---------------------------------------------
IBM SmartCloud Entry is vulnerable to bind vulnerabilities. Remote attackers could exploit the vulnerabilities to trigger an assertion failures and make named ..
---------------------------------------------
http://www.ibm.com/support/docview.wss?uid=isg3T1024649
=======================
= End-of-Shift report =
=======================
Timeframe: Donnerstag 22-12-2016 18:00 − Freitag 23-12-2016 18:00
Handler: Alexander Riepl
Co-Handler: n/a
*** Litauen entdeckt russische Spionage-Software auf Regierungsrechnern ***
---------------------------------------------
Schadsoftware wurde offenbar mittels infizierter USB-Sticks auf die Computer eingebracht
---------------------------------------------
http://derstandard.at/2000049749836
*** So somebody is throwing HTML at your sshd. What to do? ***
---------------------------------------------
Yes, its exactly as wrong as it sounds. Heres a distraction with bizarre twists for the true log file junkies among you. Happy reading for the holidays!As will probably not surprise ..
---------------------------------------------
http://bsdly.blogspot.com/2016/12/so-somebody-is-throwing-html-at-your.html
*** Cerber Ransomware Doesnt Delete Shadow Volume Copies Anymore, Prioritizes Office Docs ***
---------------------------------------------
Recent versions of the Cerber ransomware are behaving somewhat different from older variants, with the ransomware ..
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cerber-ransomware-doesnt-del…
*** Before You Pay that Ransomware Demand… ***
---------------------------------------------
A decade ago, if a desktop computer got infected with malware the chief symptom probably was an intrusive browser toolbar of some kind. Five years ago you were more likely to whacked ..
---------------------------------------------
https://krebsonsecurity.com/2016/12/before-you-pay-that-ransomware-demand/
*** Steganalysis, the Counterpart of Steganography ***
---------------------------------------------
In my last blog post I discussed the art of embedding secret messages in any file so that only the sender and the receiver ..
---------------------------------------------
https://www.trustwave.com/Resources/SpiderLabs-Blog/Steganalysis,-the-Count…
*** New Guide to Fixing Google Blacklist Warnings ***
---------------------------------------------
One of the worst experiences a website owner can have is being blacklisted by Google. If you are one of the 10,000 websites that has been slapped with a ..
---------------------------------------------
https://blog.sucuri.net/2016/12/guide-to-fix-site-warnings.html
*** Fidelix FX-20 Series Controllers Path Traversal Vulnerability ***
---------------------------------------------
This advisory contains mitigation details for a path traversal vulnerability in Fidelix FX-20 series controllers.
---------------------------------------------
https://ics-cert.us-cert.gov/advisories/ICSA-16-357-01
*** WAGO Ethernet Web-based Management Authentication Bypass Vulnerability ***
---------------------------------------------
This advisory contains mitigation details for an authentication bypass vulnerability in WAGO’s Ethernet Web-based Management products.
---------------------------------------------
https://ics-cert.us-cert.gov/advisories/ICSA-16-357-02
*** Your password expiry policy may have reached its expiry date ***
---------------------------------------------
In cyber security as much as anywhere else, its important to use the right tools for the job at hand. However, sometimes we can get a bit too attached to particular tools, ..
---------------------------------------------
https://www.ncsc.gov.uk/blog-post/your-password-expiry-policy-may-have-reac…
*** As Bitcoin Price Surges, Phishing Attacks on Cryptocurrency Wallets Intensify ***
---------------------------------------------
Bitcoin price surge reverberates through cybercriminal landscape, as cyber-criminals ramp up phishing attacks ..
---------------------------------------------
https://www.bleepingcomputer.com/news/security/as-bitcoin-price-surges-phis…
*** Using Monitor Resolution as Obfuscation Technique ***
---------------------------------------------
A quick blog post about a malicious VBScript macro that I analysed. Bad guys have always plenty of ..
---------------------------------------------
https://blog.rootshell.be/2016/12/23/using-monitor-resolution-obfuscation-t…
*** Keine Belege für geplante russische Cyberangriffe auf die Bundestagswahl ***
---------------------------------------------
http://derstandard.at/2000049777463
*** Drastische Warnungen vor dem "Internet der Dildos" ***
---------------------------------------------
Neue Gruppe will auf Gefahren durch smarte Sexspielzeuge aufmerksam machen
---------------------------------------------
http://derstandard.at/2000049785388
*** Alle Jahre wieder: Netgear-Router N300 / WNR2000 angreifbar ***
---------------------------------------------
Eine Zero-Day-Lücke plagt mal wieder Router von Netgear. Das verwundbare Modell ist in der Vergangenheit auch schon Opfer gravierender Lücken geworden.
---------------------------------------------
https://heise.de/-3581275
*** Koolova Ransomware Decrypts for Free if you Read Two Articles about Ransomware ***
---------------------------------------------
A new in-development variant of the Koolova Ransomware has been discovered that will decrypt your ..
---------------------------------------------
https://www.bleepingcomputer.com/news/security/koolova-ransomware-decrypts-…
Aufgrund des Feiertages am Montag, den 26.12.2016, erscheint der nächste End-of-Shift-Report erst am Dienstag, den 27.12.2016