If you use Gmail, eBay, MySpace, or any one of dozens of other web-based services, the United States Computer Emergency Readiness Team wants you to know you're vulnerable to a simple attack that could give an attacker complete control over your account.
US CERT warned that Google, eBay, MySpace, Yahoo, and Microsoft were vulnerable, but that list is nowhere near exhaustive. It said the world's biggest websites have yet to fix the gaping security bug, which can bite even careful users who only log in using the secure sockets layer protocol, which is denoted by an HTTPS in the beginning of browser address window. Just about any banking website, online social network or other electronic forum that transmits certain types of security cookies is also susceptible.
The vulnerability stems from websites' use of authentication cookies, which work much the way an ink-based hand stamp does at your favorite night club. Like the stamp, the cookie acts as assurance to sensitive web servers that the user has already been vetted by security and is authorized to tread beyond the velvet rope.
The thing is just about every website transmits these digital hand stamps in the clear, which leaves them wide open to snoops monitoring public Wi-Fi traffic or some other type of network. Once attackers have the cookie, they gain complete access to the victim's account, and depending on the way many cookies are crafted, those privileges may continue in perpetuity - even if the victim changes the account password.
Indeed, awareness of this man-in-the-middle vulnerability is by no means new. For more than a decade people have known that authentication cookies could be manipulated, but somehow it took the folks at Errata Security to make a presentation at Black Hat to remind the world that the risks continue.
If you're waiting for a fix, we recommend you pack a very large lunch. And beyond that, where possible you might switch to Google, which has already gone a long way to closing the hole.
As the only web-based email service we know of that offers a start-to-finish SSL session, the service is among the most resilient to cookie hijacking. Unfortunately, Gmail doesn't enable persistent SSL by default, and has done little to educate its users about its benefits.
The company also offers SSL for its calendar, search history, documents and reader services, and a Google spokesman said security engineers "are actively working to expand capacity to enable HTTPS encryption for all users."
In the meantime, a Firefox extension called CustomizeGoogle provides a simple way to ensure that all sessions with the above-mentioned Google services are automatically protected by SSL.
Cyber Security Tips N Tricks describes various tips and tricks about cyber security, safe surfing, ethical hacking, network security, Internet, news related to software, hacking, security breaches, vulnerabilities, phishing, google, yahoo, CERT, US CERT, security agencies, etc.
Showing posts with label wi-fi. Show all posts
Showing posts with label wi-fi. Show all posts
Tuesday, September 18, 2007
Tuesday, July 24, 2007
iPhone Hacked Successfully - Security Firm Says
iPhone Hacked Successfully - Security Firm Says
A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.
Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks. However, this is the first major exploitation of an iPhone security flaw.
The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.
1. An attacker controlled wireless access point:
The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.
2. A misconfigured forum website:
A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.
3. A link delivered via e-mail or SMS:
A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.
The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.
Source: nytimes
A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.
Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks. However, this is the first major exploitation of an iPhone security flaw.
The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.
1. An attacker controlled wireless access point:
The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.
2. A misconfigured forum website:
A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.
3. A link delivered via e-mail or SMS:
A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.
The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.
Source: nytimes
iPhone Hacked Successfully - Security Firm Says
iPhone Hacked Successfully - Security Firm Says
A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.
Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks other than AT&T Inc.'s. However, this is the first major exploitation of an iPhone security flaw.
The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.
1. An attacker controlled wireless access point:
The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.
2. A misconfigured forum website:
A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.
3. A link delivered via e-mail or SMS:
A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.
The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.
Source: nytimes
A vulnarabilty has found in the Apple Inc.'s iPhone handset that can help an attacker to gain access to the private data stored on it. This flaw has found by a team of security expert of Independent Security Evaluators (ISE). Hackers could gain access to the iPhone through a wireless access point or through a website controlled by the attacker. This was the first major security incident reported.
Numerous hackers have been working to gain access to the iPhone in order to activate certain features or to allow it to be used on cellular networks other than AT&T Inc.'s. However, this is the first major exploitation of an iPhone security flaw.
The expolit is delivered via a malicious web page opened in the Safari browser on the iPhone, ISE said on its Website. There are several methods that an attacker utilize to get a victim to open such a webpage.
1. An attacker controlled wireless access point:
The iPhone connects to wireless Internet access networks, such as Wi-Fi, an attacker could create a network with the same name and encryption method as one the handset already uses. The attacker could then substitute a Web page with exploit code to gain access to the phone.
2. A misconfigured forum website:
A link planted on an unedited or unmoderated online forum, an attacker could cause the exploit to run in any iPhone browser that viewed the thread.
3. A link delivered via e-mail or SMS:
A link sent by SMS or e-mail to use make use of the flaw and gain access to the handset.
The ISE said that when the iPhone's Safari browser opens a malicious Web page, malicious code can be run on the phone via the flaw, allowing the attacker to read the iPhone's SMS log, address book, call history, and voicemail information, which are also then sent to the attacker. It could send the user's mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.
Source: nytimes
Subscribe to:
Posts (Atom)