Showing posts with label Security flaws. Show all posts
Showing posts with label Security flaws. Show all posts

Saturday, 19 April 2014

Heartbleed Bug Week Two: Affected Website Testing and 'The Other Shoe'

--

[UPDATED 2014-04-18 ~11:30 AM ET. AgileBits has created a lovely Heartbleed testing page I recommend. It offers advice as well as results. Thanks to my friendly colleague Al Varnell for pointing it out!]

[UPDATED 2014-04-17 ~11:00 AM ET. A link to Mashable's list of affected websites was added.]


This is week two of the Heartbleed bug and its ramifications. A lot has been learned. A lot is still happening. A lot more problems are still to come.


I'm extremely disappointed that few websites have directly addressed this problem and kept their customers informed. Apparently, security is still considered a minor inconvenience to website administrators, with a wide variety of responses to the Heartbleed security hole, as you'll see ahead.


TEST PAGES


Thankfully, there are now some very good resources for finding out whether specific websites remain affected. Here is a list of six pages I know of where you can test any website against the Heartbleed bug. Try them in the order of usefulness I've provided below. If one test errors out, try the next one.


http://watchtower.agilebits.com

https://www.ssllabs.com/ssltest/


http://www.digicert.com/help/


http://heartbleed.criticalwatch.com


https://lastpass.com/heartbleed/


Thanks to Brian Krebs for getting the ball rolling collecting these sites. I'll add more to this list as I find them. Note that using these test pages can be annoying and disconcerting. On some test pages, I ran into errors of various sorts about 50% of the time.


TEST RESULTS


Fortunately, lists of FAILed websites are showing up on the net, saving us some time and trouble. Here is one at Github, listing affected websites as of April 8th, 2014, the day after the SSL security hole was made public. Scroll down its page to 'Overview' to see the list:


https://github.com/musalbas/heartbleed-masstest


NOTE: Many of the sites on this out-of-date list have now been patched! Yahoo, for example, made a big deal out of patching its website in a hurry.


Mashable has also provided a listing of affected websites here. Note that it is also out-of-date:


http://mashable.com/2014/04/09/heartbleed-bug-websites-affected/


At the time I wrote this article, many sites had still not been patched. Here's one unhappy example: 



hypovereinsbank.de


This bank kindly patched their German website, but NOT their Turkish website! Ouch!

And so forth.


NOW WHAT?


So! Are we ready to change our passwords at all the websites that verify as having patched their OpenSSL implementations?


Yes! Do it!


But! There's another problem! Remember how I pointed out last week that phishing is going to result from the Heartbleed bug? The phishing problem may become doubly bad:



THE OTHER SHOE DROPS


Because, as I pointed out last week, Heartbleed can allow the cleartext robbery of website security certificates, ALL security certificates at affected sites MUST BE REVOKED and REPLACED.


Why? Because with a stolen SSL security certificate, a hacker can pretend to 'officially' BE the website from which the certificate was stolen! That's VERY bad and will lead to lots of troubles. It's also ignorant, lazy and cheapskate of the website's administrators.


It turns out that remarkably few websites have so far revoked their potentially stolen security certificates! Welcome to our modern world of bad biznizz. :-P Insert your favorite expletives here: [_____]


Let's use an example!


HAPPY RESULTS


Use a GOOD web browser that actually CHECKS Internet security certificates for credibility. One such browser is good old AppleSafari! Bravo Apple! Each time you visit a website, Safari checks the security certificate for that website against a number of factors. One of them is whether that certificate is on aCertificate Revocation List (CRL). 


http://en.wikipedia.org/wiki/Revocation_list


When you visit a website that has had its security certificate revoked, you get a message in Safari!


This past week, mentor Steve Gibson very kindly set up the perfect place to show what it looks like when you run into a revoked security certificate. Travel here to see Steve's demonstration:


https://www.grc.com/revocation.htm


In a box, slightly down the page, you'll see his test page link. Click on it:


https://revoked.grc.com


What you'll see in Safari is:




"Invalid"

If you then click on the 'Show Certificate' button, you will see this:




"Revoked"

Therefore, you hit the 'Cancel' button and leave the site. There's something profoundly wrong with it, danger, danger. Do not go there. Thank you Safari!


SAD RESULTS

Let's say we live in Turkey and get an email we believe is from the Istanbul branch of  HypoVereinsbank, where we have all our life savings stored. The email message says something like:

Dear Valued Customer, 

We are offering a new 5% back on purchases feature to select account holders. To sign up for this new perk, please log into yourHypoVereinsbank.co.tr account and click the 'Join the 5% Back Club' button on the  page.

Hurry now! Limited time offer! Don't let this deal pass you by! Prices do not include shipping and handling.
Great! A deal! They offered up the link to their website within the message! How convenient.

[If you check out the actual web address behind 'HypoVereinsbank account', you'll find that I've faked a different IP address that is NOT HypoVereinsbank! In reality, I've provided a LAN IP link that goes nowhere on the Internet, making in innocuous. But I could put anything there. Note that I am NOT picking on HypoVereinsbank in Turkey. I'm only using them as a valid example of a bank that had not patched the Heartbleed bug at the time of this writing.]


So we click the link to HypoVereinsbank.co.tr. We're sent to the FAKE website for the bank. We're presented with everything looking just perfect and fine. Safari sees NO problems! The stolen, unrevoked certificate is presented to Safari, all his happy.


UH OH.


Then we log in, our ID and password are stolen, we possibly get asked a bunch of other personal identity questions in order to sign up for the FAKE 5% Back Club offer. We have been PWNed.


THEREFORE:


It's important that ALL Heartbleed bug affected websites revoke their old security certificates and get new certificates. ALL.


Enough of that nightmare for today.



CONCLUSION, for now:


1) Check out what websites have been affected by the Heartbleed bug.


2) Check out whether those websites are NOW patched.


3) Change your password there ASAP.


4) Keep an eye out for potential phishing scams using stolen security certificates.



THE FUTURE


Hopefully we'll see forced revocation of security certificates via certificate authorities against all websites that have been affected by the Heartbleed bug. That move would save we Internet users a lot of grief.

Tuesday, 18 February 2014

Denies Hacker Removed Mark Zuckerberg’s Cover Photo

An Egyptian hacker claims to have removed the cover photo from the profile of Facebook Founder and CEO Mark Zuckerberg. Facebook says there’s no evidence of suspicious activity on the account.
According to The Hacker News, the cover photo from Zuckerberg’s official account was missing at some point. The Egyptian hacker, called “Dr.FarFar,” claims to have used the “I don’t like a photo I’m tagged in” feature with a request edited in the Fiddler debugging tool.
He has also published a video to demonstrate that the profile image from Zuckerberg’s account was gone at some point.
The cover photo from Zuckerberg’s profile was missing for a few hours on Saturday, but there’s no evidence that the hacker is responsible for it.
Facebook representatives have told The Hacker News that “there is no merit to this claim.”
“We have confirmed there was no suspicious activity on the account,” they said.

Monday, 17 February 2014

Kickstarter Stealing User Data

Kickstarter, a web site that serves as a funding platform for creative projects, said on Saturday that malicious hackers gained unauthorized access to its systems and accessed user data.
“On Wednesday night, law enforcement officials contacted Kickstarter and alerted us that hackers had sought and gained unauthorized access to some of our customers' data,” Yancey Strickler, Kickstarter’s CEO, wrote in a security notice. “Upon learning this, we immediately closed the security breach and began strengthening security measures throughout the Kickstarter system.”
According to Strickler, customer information accessed by the attacker(s) included usernames, email addresses, mailing addresses, phone numbers, and encrypted passwords.
Security“Actual passwords were not revealed, however it is possible for a malicious person with enough computing power to guess and crack an encrypted password, particularly a weak or obvious one,” Strickler said.
The company said via Twitter that "old passwords used salted SHA1, digested multiple times. More recent passwords use bcrypt."
Strickler said that no credit card data was accessed by the attackers, and that so far only two Kickstarter user accounts have seen evidence of unauthorized activity.
Kickstarter did not say how many user accounts were affected in the breach, but the company says that since launching in 2009, more than 5.6 million people have pledged $980 million, funding 56,000 creative projects through its platform.
“As a precaution, we strongly recommend that you create a new password for your Kickstarter account, and other accounts where you use this password,” the advisory suggested.
“We have since improved our security procedures and systems in numerous ways, and we will continue to do so in the weeks and months to come,” Strickler wrote. “We are working closely with law enforcement, and we are doing everything in our power to prevent this from happening again.”
*Updated with additional details on password encryption.