Tag Archive for: hack

DSL modem hack used to infect millions with banking fraud malware

An administration panel of one vulnerable DSL modem.

Millions of Internet users in Brazil have fallen victim to a sustained attack that exploited vulnerabilities in DSL modems, forcing people visiting sites such as Google or Facebook to reach imposter sites that installed malicious software and stole online banking credentials, a security researcher said.

The attack, described late last week during a presentation at the Virus Bulletin conference in Dallas, infected more than 4.5 million DSL modems, said Kaspersky Lab Expert Fabio Assolini, citing statistics provided by Brazil’s Computer Emergency Response Team. The CSRF (cross-site request forgery) vulnerability allowed attackers to use a simple script to steal passwords required to remotely log in to and control the devices. The attackers then configured the modems to use malicious domain name system servers that caused users trying to visit popular websites to instead connect to booby-trapped imposter sites.

“This is the description of an attack happening in Brazil since 2011 using 1 firmware vulnerability, 2 malicious scripts and 40 malicious DNS servers, which affected 6 hardware manufacturers, resulting in millions of Brazilian internet users falling victim to a sustained and silent mass attack on DSL modems,” Assolini wrote in a blog post published on Monday morning. “This enabled the attack to reach network devices belonging to millions of individual and business users, spreading malware and engineering malicious redirects over the course of several months.”

Read 8 remaining paragraphs | Comments


Ars Technica » Technology Lab

Researchers Demo NFC Android Phone Hack – TechWeekEurope UK


TechWeekEurope UK

Researchers Demo NFC Android Phone Hack
TechWeekEurope UK
Android security has come under the spotlight again after the Pwn2Own contest in Amsterdam revealed a hack via a technology that promises easy payments. Using two vulnerabilities in the Samsung Galaxy S3 smartphone, researchers from UK-based

“android security” – read more

Exploit beamed via NFC to hack Samsung Galaxy S3 (Android 4.0.4) – ZDNet


ZDNet

Exploit beamed via NFC to hack Samsung Galaxy S3 (Android 4.0.4)
ZDNet
He said the winning exploited bypassed several Android security mitigations including the limited ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention). Once the mitigations were bypassed, Erasmus and his team installed a
Researchers Demo NFC Android Phone HackTechWeekEurope UK
Galaxy S III hacked via NFC at Mobile Pwn2Own competitionTechHive
Galaxy S III hacked using NFC at Mobile Pwn2Own hacking contestComputerworldUK
Android Authority
all 22 news articles »

“android security” – read more

Researchers devise hack that sneaks Android malware into Google market – Ars Technica


VentureBeat

Researchers devise hack that sneaks Android malware into Google market
Ars Technica
confident that Google will continue to improve and evolve its capabilities," Oberheide wrote in a short blog post. "We've been in touch with the Android security team and will be working with them to address some of the problems we've discovered."
Android's Bouncer malware protection is asleep at the job, researchers sayVentureBeat
Researchers Find Methods for Bypassing Google's Bouncer Android SecurityThreatpost (blog)
Security boffins slip past Google BouncerSC Magazine Australia

all 39 news articles »

“android security” – read more