Showing posts with label attack. Show all posts
Showing posts with label attack. Show all posts

Top server host OVH warns of 'multi-stage' hacking attack

'Higher level of paranoia' suggests EU and US users should change passwords

French-based server host OVH has warned that its systems have been penetrated in a multi-stage attack that leaves US and European customers at risk.
http://www.theregister.co.uk/2013/07/23/top_server_host_ovh_warns_of_multistage_hacking_attack/
OVH warns of "multi-stage" hacking attack
In an advisory on its forum board, the company warned that an attacker had gained control of a system administrator's account, and used that to gain access to a VPN account of one of the firm's backoffice staff. This was used to get the personal data of customers in Europe and from a hosting firm in Canada.

"Overall, in the coming months the back office will be under PCI-DSS which will allow us to ensure that the incident related to a specific hack on specific individuals will have no impact on our databases," the company said.

"In short, we were not paranoid enough so now we're switching to a higher level of paranoia. The aim is to guarantee and protect your data in the case of industrial espionage that would target people working at OVH."

European customers' surname, first name, nic, address, city, country, telephone, fax, and encrypted password are all open to the attackers, and customers of the firm's Canadian hosting company have ben advised to change SSH keys to ensure a secure connection.

Dissecting a WordPress Brute Force Attack

http://blog.sucuri.net/2013/07/dissecting-a-wordpress-brute-force-attack.html
WordPress Brute Force attack
Over the past few months there has been a lot of discussion about WordPress Brute Force attacks. With that discussion has come a lot of speculation as well. What are they doing? Is it a giant WordPress botnet? Is it going to destroy the internet? Well, as you would expect of any good geeks we set out to find a way to find out.

This is not to be exhaustive case study or meant to be a representative sample of what all attacks look like, but it does have similar characteristics to the types of attacks and infections we deal with on a daily basis.

In this post, my goal is to highlight a hack that occurred this weekend, July 20th to be exact, against one of our several honeypots. In this specific instance, it was setup and configured approximately 2 months ago. It had been hacked about a month and a half ago and silly me I forgot to configure what I needed to do real forensics, oops. In any event, everything was cleared and pushed out again to see what happened, it was nothing more than a matter of sitting back and waiting.

Sony to pay £250,000 fine for PlayStation Network breach

http://nakedsecurity.sophos.com/2013/07/16/sony-to-pay-250000-fine-for-playstation-network-breach/
Sony to pay for PlayStation network breach
Sony has thrown in the towel on its appeal of a £250,000 fine ($377,500) imposed after its PlayStation Network was hacked in April 2011.

The UK Information Commissioner's Office (ICO) imposed the fine in January after an investigation showed that the attack could have been prevented if Sony's software had been up to date.

On top of that, the ICO, finding that technical developments led to passwords not being secure, also charged Sony with negligence for failing to protect PlayStation Network (PSN) users.

What's It Take To Trust A Digitally Signed Program?

http://www.darkreading.com/attacks-breaches/whats-it-take-to-trust-a-digitally-signe/240157741
Opera Software
The Opera Software breach that came to light last week after attackers compromised Opera's network in order to steal an expired certificate and use it to sign malware for distribution dredges up some serious concerns from security professionals about the amount of trust that organizations put into legitimately signed programs.

In particular, the attack brought up fears about auto-updating processes given that this particular strike used Opera's updating infrastructure to automatically push out updates to customers.

"Attacks that subvert the methods used to validate programs and their updates are very troubling," says Jean Taggart, senior researcher at Malwarebytes. "They serve as a strong reminder to practice defense in depth."

The Opera attack is hardly an exception in today's malicious hacking standard operating procedures.



Attackers gain access to Ubisoft customer data

Unknown attackers have gained access to Ubisoft's systems. The company has informed its customers and requested that they change their passwords. In the message to its customers, Ubisoft says that the attackers harvested users' account details including names, email addresses and encrypted passwords. The company said that payment information such as customers' bank details and credit card data was not affected by the attack because it isn't stored on Ubisoft's system.

http://www.h-online.com/security/news/item/Attackers-gain-access-to-Ubisoft-customer-data-Update-1910357.html
Attackers gain access to Ubisoft

The customer alert email initially caused confusion among recipients as its poor wording caused users to believe that it was a phishing attempt; howe ver, the emails genuinely originated from Ubisoft. The H's associates at heise Security are communicating with Ubisoft representatives, and further details will be provided as soon as they become available.

Attackers gain access to Ubisoft customer data | The H Security

KeyBoy, Targeted Attacks against Vietnam and India

India and Vietnam
In our never-ending quest to spot and expose the nastiest of the Internet, me and Mark this time incidentally stepped into a targeted attacks campaign apparently directed at a distributed and diversified base of victims. In this blog post we'll analyze two specific incidents apparently targeting victims in Vietnam and in Indiaand we'll describe the capabilities of the custom backdoor being used that for convenience (and to our knowledge, for a lack of an existing name) we call KeyBoy, due to a string present in one of the samples.

We'll describe how the attackers operate these backdoors, provide some scripts useful to further investigate the campaign as well as meanings to detect infections or scout for additional samples.