Please help to click 1!

Saturday, 14 January 2023

NIST Retires SHA-1 Cryptographic Algorithm

 In illustration featuring a laptop, text with the letters SHA-1 is crossed out, with check marks next to the letters SHA-2 and SHA-3.

The SHA-1 algorithm, one of the first widely used methods of protecting electronic information, has reached the end of its useful life, according to security experts at the National Institute of Standards and Technology (NIST). The agency is now recommending that IT professionals replace SHA-1, in the limited situations where it is still used, with newer algorithms that are more secure.  

SHA-1, whose initials stand for “secure hash algorithm,” has been in use since 1995 as part of the Federal Information Processing Standard (FIPS) 180-1. It is a slightly modified version of SHA, the first hash function the federal government standardized for widespread use in 1993. As today’s increasingly powerful computers are able to attack the algorithm, NIST is announcing that SHA-1 should be phased out by Dec. 31, 2030, in favor of the more secure SHA-2 and SHA-3 groups of algorithms.

“We recommend that anyone relying on SHA-1 for security migrate to SHA-2 or SHA-3 as soon as possible,” said NIST computer scientist Chris Celi. 

SHA-1 has served as a building block for many security applications, such as validating websites — so that when you load a webpage, you can trust that its purported source is genuine. It secures information by performing a complex math operation on the characters of a message, producing a short string of characters called a hash. It is impossible to reconstruct the original message from the hash alone, but knowing the hash provides an easy way for a recipient to check whether the original message has been compromised, as even a slight change to the message alters the resulting hash dramatically.

“We recommend that anyone relying on SHA-1 for security migrate to SHA-2 or SHA-3 as soon as possible.” —Chris Celi, NIST computer scientist

Today’s more powerful computers can create fraudulent messages that result in the same hash as the original, potentially compromising the authentic message. These “collision” attacks have been used to undermine SHA-1 in recent years. NIST has announced previously that federal agencies should stop using SHA-1 in situations where collision attacks are a critical threat, such as for the creation of digital signatures

As attacks on SHA-1 in other applications have become increasingly severe NIST will stop using SHA-1 in its last remaining specified protocols by Dec. 31, 2030. By that date, NIST plans to:

  • Publish FIPS 180-5 (a revision of FIPS 180) to remove the SHA-1 specification.
  • Revise SP 800-131A and other affected NIST publications to reflect the planned withdrawal of SHA-1.
  • Create and publish a transition strategy for validating cryptographic modules and algorithms.  

The last item refers to NIST’s Cryptographic Module Validation Program (CMVP), which assesses whether modules — the building blocks that form a functional encryption system — work effectively. All cryptographic modules used in federal encryption must be validated every five years, so SHA-1’s status change will affect companies that develop modules. 

“Modules that still use SHA-1 after 2030 will not be permitted for purchase by the federal government,” Celi said. “Companies have eight years to submit updated modules that no longer use SHA-1. Because there is often a backlog of submissions before a deadline, we recommend that developers submit their updated modules well in advance, so that CMVP has time to respond.”

Thursday, 5 January 2023

Microsoft Teams

MS Teams Weakness - personal experience only 

- It is buggy (like you didn't know)...
- It wreaks havoc on non windows systems!
- God forbid if you have multiple multimedia devices, it will not only cease to function, but also do its best to sabotage other running processes!!
- It doesn't work with multiple accounts. I'm obviously not a part of your corporate domain. That means I can only join as a guest with very limited options.
- Its synchronization makes no sense and was most likely designed by a drunk person while snorting cocaine in an effort to look like he's not drunk.
- Calling it slow is an understatement.
- In case you didn't get the above point (which you probably didn't, since you like using it), it is slow and laggy.
- It has no sense of integration (OAuth 2.0 anyone?)...
- Its layout is very difficult to use, especially when using multiple screens (I have 7 running simultaneously).
- Video filters and background effects cause multiple crashes... if you can ever get them to work in the first place, especially as a guest.

Thursday, 1 December 2022

JDK 7: The Long Hello and the Long Goodbye

 

On July 7th, 2011, eleven years ago, JDK 7 was released.  In some ways, it was one of the more significant releases of Java.  Indeed, there were some excellent technical features: Project Coin gave us things like try-with-resources, strings in switch and multi-catch. 

However, it was two non-technical aspects of JDK 7 that made it important. 

The first was that it was the first release since Oracle acquired Sun Microsystems.  The Java community had been unsure how Java would fare under Oracle, so this release showed a solid commitment to the platform (which has been maintained since then).

The second was even more important: the fact that a Java SE specification was published through the Java Community Process.  Due to issues around the availability of the TCK and the Apache Harmony project, new versions of OpenJDK had been stalled since December 2006.  To put this into context, the time between JDK 6 and JDK 7 (one release) was one month longer at four years and seven months than between JDK 9 and JDK 18 (nine releases).  Getting things moving again was vital to keeping Java relevant to developers as applications and architectures evolved.

Another significant date for JDK 7 is July 19th this year.  That is when the last update will be made available from Oracle, even for commercially supported users.  It is the end of what Oracle terms Extended Support.

However, it turns out that there are still a significant number of people who are using JDK 7.  In almost all cases, this is not because users don’t want to move to a newer version; they’re just not in a position to be able to do so.  In many ways, this is one of Java’s strengths: you can just keep using an older version because your application doesn’t need features from newer releases.  If you can keep your implementation of JDK 7 updated with relevant security patches and bug fixes, why change?

Extending Support of JDK 7

Fortunately, if you are one of those users who are not in a position to migrate from JDK 7 to a newer release, Azul has a solution for you.  We will continue to provide updates (scheduled quarterly ones and any out-of-bounds) to our Zulu builds of OpenJDK 7 until at least December 2027 (see our Support Roadmap for more information).  Our highly skilled team of Java and JVM engineers will backport all applicable changes from the current release of Java to JDK 7.

That’s another five and a half years without figuring out how to migrate those trusty applications and with peace of mind that your Java runtime is as secure as possible.

Saturday, 5 November 2022

A cybercrime is reported every seven minutes in Australia. How can we protect ourselves?

 Cybercrime ison the rise in Australia, with an incident reported every seven minutes, according to The Australian Cyber Security Centre (ACSC).


The ACSC's Annual Cyber Threat Report has shown the agency received more than 76,000 cybercrime reports in the 2021-22 financial year, an increase of nearly 13 per cent from the previous year.


So how significant is the issue of cybercrime, what can the authorities do about it, and should you be worried?

Defence minister and deputy prime minister Richard Marles told ABC Breakfast on Friday there were many factors driving the increase in cybercrime reports.

"In part we're living more of our lives online, and the pandemic has accelerated that ... but cybercrime is now big business, the average impact for a small business is $40,000 per incident, and something like $88,000 for medium businesses, so you can see there's a lot of money to be made by cyber criminals," he said.

"We're also seeing more state-based actors ... in the murky grey world that is cyberspace, we're seeing a lot of cross-pollination between state actors and cyber criminals and all of this is giving rise to a much more precarious environment for all of us online."

Mr Marles said the Optus data breach was a reminder for both individuals and businesses to be more vigilant.

"That incident [Optus breach] is something of a wake-up call ... in a way, I hope this annual cyber threat report adds to the wake-up call, not just for Optus but for the whole of the corporate sector and for individuals as well," he said.

"Cyberspace is a much more challenging environment ... there are a lot of pickpockets out there, this can be happening on a grand scale, so people do need to be more vigilant at an individual level."

What is the government doing?

Following the Optus and Medibank data breaches, the Albanese government introduced new legislation, increasing penalties on companies for serious or repeated privacy breaches.

Under the new legislation, penalties will rise from $2.22 million to whichever is the greater of $50 million, 30 per cent of the company's turnover in the relevant period, or three times the value of any benefit gained from the stolen data.
 
The deputy prime minister said fines would be "just part of the answer" when it comes to improving cybersecurity around the country.

"It's part of the answer ... I think we do need to be thinking about other ways we can go about this in a regulatory sense," he said.

"We're examining all of those options, I think a lot of this is about making sure that the systems are in place across the private sector, across government, that we are investing a lot more in this space - which we are doing"

How can you protect yourself?

Mr Marles said the release of the report was part of an increase in public messaging around the importance of cyber safety.

When it comes to individual protection, the ACSC recommends setting up secure passwords and setting up multi-step authentication whenever possible.

It also suggests regularly updating apps and systems to ensure you are up-to-date with security upgrades, and backing up files to external devices in case your accounts are ever compromised.
Using browsers with hardened security settings and turning off browsing history and cookies can also be beneficial.

Cyber Security Minister Clare O'Neil said businesses are expected to handle their customer's cyber data better in light of the "concerning" report.

"To big businesses around this country: you have got obligations to Australians, especially if you are collecting and keeping personal information about your customers," she told the Nine Network on Friday.

"I want the corporate sector to step up and do better."

What else did the report find?

The most at risk are Commonwealth and state government systems, making up more than one-third of all cyber incidents.

Health systems were the next big targets, mainly due to cyber criminals attacking vulnerable businesses that are more likely to pay ransoms to access their data back.

The security agency's head Abigail Bradshaw said cyber threats were constantly evolving and targeting the nation's critical infrastructure more frequently.

It blocked more than 24 million malicious domain requests, took down 29,000 attacks against Australian services and responded to 185 ransomware movements, which is a 75 per cent increase.

The agency was also involved in five successful operations taking down online criminal marketplaces and foreign scam networks.

Monday, 17 October 2022

Zimbra Releases Patch for Actively Exploited Vulnerability in its Collaboration Suite

Zimbra

Zimbra has released patches to contain an actively exploited security flaw in its enterprise collaboration suite that could be leveraged to upload arbitrary files to vulnerable instances.

Tracked as CVE-2022-41352 (CVSS score: 9.8), the issue affects a component of the Zimbra suite called Amavis, an open source content filter, and more specifically, the cpio utility it uses to scan and extract archives.


The flaw, in turn, is said to be rooted in another underlying vulnerability (CVE-2015-1197) that was first disclosed in early 2015, which according to Flashpoint was rectified, only to be subsequently reverted in later Linux distributions.

"An attacker can use cpio package to gain incorrect access to any other user accounts," Zimbra said in an advisory published last week, adding it "recommends pax over cpio."

Fixes are available in the following versions -

All an adversary seeking needs to do to weaponize the shortcoming is to send an email with a specially crafted TAR archive attachment that, upon being received, gets submitted to Amavis, which uses the cpio module to trigger the exploit.

Thursday, 6 October 2022

Hackers Exploiting Dell Driver Vulnerability to Deploy Rootkit on Targeted Computers

 Dell Driver Vulnerability

The North Korea-backed Lazarus Group has been observed deploying a Windows rootkit by taking advantage of an exploit in a Dell firmware driver, highlighting new tactics adopted by the state-sponsored adversary.

The Bring Your Own Vulnerable Driver (BYOVD) attack, which took place in the autumn of 2021, is another variant of the threat actor's espionage-oriented activity called Operation In(ter)ception that's directed against aerospace and defense industries.

"The campaign started with spear-phishing emails containing malicious Amazon-themed documents and targeted an employee of an aerospace company in the Netherlands, and a political journalist in Belgium," ESET researcher Peter Kálnai said.


Attack chains unfolded upon the opening of the lure documents, leading to the distribution of malicious droppers that were trojanized versions of open source projects, corroborating recent reports from Google's Mandiant and Microsoft.

ESET said it uncovered evidence of Lazarus dropping weaponized versions of FingerText and sslSniffer, a component of the wolfSSL library, in addition to HTTPs-based downloaders and uploaders.

The intrusions also paved the way for the group's backdoor of choice dubbed BLINDINGCAN – also known as AIRDRY and ZetaNile – which an operator can use to control and explore compromised systems.

But what's notable about the 2021 attacks was a rootkit module that exploited a Dell driver flaw to gain the ability to read and write kernel memory. The issue, tracked as CVE-2021-21551, relates to a set of critical privilege escalation vulnerabilities in dbutil_2_3.sys.

"[This] represents the first recorded abuse of the CVE‑2021‑21551 vulnerability," Kálnai noted. "This tool, in combination with the vulnerability, disables the monitoring of all security solutions on compromised machines."

Named FudModule, the previously undocumented malware achieves its goals via multiple methods "either not known before or familiar only to specialized security researchers and (anti-)cheat developers," according to ESET.


"The attackers then used their kernel memory write access to disable seven mechanisms the Windows operating system offers to monitor its actions, like registry, file system, process creation, event tracing, etc., basically blinding security solutions in a very generic and robust way," Kálnai said. "Undoubtedly this required deep research, development, and testing skills."

This is not the first time the threat actor has resorted to using a vulnerable driver to mount its rootkit attacks. Just last month, AhnLab's ASEC detailed the exploitation of a legitimate driver known as "ene.sys" to disarm security software installed in the machines.

The findings are a demonstration of the Lazarus Group's tenacity and ability to innovate and shift its tactics as required over the years despite intense scrutiny of the collective's activities from both law enforcement and the broader research community.

"The diversity, number, and eccentricity in implementation of Lazarus campaigns define this group, as well as that it performs all three pillars of cybercriminal activities: cyber espionage, cyber sabotage, and pursuit of financial gain," the company said.

Sunday, 2 October 2022

New Microsoft Exchange Zero-Day RCE Bug Actively Exploited by Hackers

 

New zero-day bugs existing in Microsoft Exchange that are not disclosed yet publicly are being exploited by the threat actors in order to perform remote code execution on affected systems.

These attacks are first spotted by security experts at Vietnamese cybersecurity outfit GTSC during a routine security checkup. Microsoft was notified privately three weeks ago of the security vulnerabilities by the researchers through their Zero Day Initiative program.

On compromised servers, the hackers deployed Chinese Chopper web shells by combining two zero-day vulnerabilities. While they deploy the malicious Chinese Chopper web shells for three primary illicit goals:-

  • To gain persistence
  • Data theft
  • Move laterally to other systems

Apart from this, it has been presumed based on the code page of the web shells, the attack is being carried out by a Chinese threat group.

Webshell

In this case, the web shells are installed by Antsword’s user agent. With Web Shell management support, Antsword is an open-source website admin tool that is developed in Chinese.

It is still unclear what Microsoft has done about the two security flaws so far since the company has not yet assigned a CVE ID to any of them to ensure their tracking.

The researchers reported the security vulnerabilities to Microsoft privately three weeks ago through the Zero Day Initiative.

A very limited amount of information has been released about these zero-day flaws by GTSC. However, they did reveal that the attacks that targeted the ProxyShell flaws and the requests used in this exploit chain are completely identical.

Exploit stages

Two stages are involved in the exploit in order to work:-

  • In IIS logs, exploit requests with the same format as the ProxyShell vulnerability have been detected:

autodiscover/autodiscover.json?@evil.com/<Exchange-backend-endpoint>&Email=autodiscover/autodiscover.json%3f@evil.com.

  • It is possible to implement RCE in the backend with the help of the link above which can be operated to access an element in the backend.

Detection

Consequently, GTSC has released guidelines and a tool that can be used to look up IIS log files. This tool can be used to determine if this bug has exploited any Exchange servers or not.

  • First of all, you have to use the Powershell command:

Get-ChildItem -Recurse -Path <Path_IIS_Logs> -Filter “*.log” | Select-String -Pattern ‘powershell.*autodiscover\.json.*\@.*200