Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

Alert

NEWS - January 25, 2013

Jan 25, 2013 12:53AM PST
Web server hackers installing rogue Apache modules and SSH backdoors

"Original SSH binary files get replaced with credential-stealing versions, researchers warn"

A group of hackers that are infecting Web servers with rogue Apache modules are also backdooring their Secure Shell (SSH) services in order to steal login credentials from administrators and users.

The hackers are replacing all of the SSH binary files on the compromised servers with backdoored versions that are designed to send the hostname, username and password for incoming and outgoing SSH connections to attacker-controlled servers, security researchers from Web security firm Sucuri said Wednesday in a blog post.

"I saw some SSHD [SSH daemon] backdoors in the past in very small scale or part of public rootkits, but not like this one," Daniel Cid, Sucuri's chief technology officer, said Thursday via email. "They do not only modify the ssh daemon, but every ssh binary (ssh, ssh-agent, sshd) and their main goal is to steal passwords."

Continued : http://news.techworld.com/security/3422504/web-server-hackers-installing-rogue-apache-modules-ssh-backdoors/

Related: SSH Backdoor Linked to Linux Rootkits

Discussion is locked

- Collapse -
Chrome update closes holes and fixes mouse wheel issues
Jan 25, 2013 12:56AM PST

Google has released Chrome 24.0.1312.56 to the stable update channel of the open source browser. The new update closes five security holes, three of which are high severity, and fixes problems with mouse wheel scrolling.

Atte Kettunen of the Oulu University Secure Programming Group in Finland received $1000 for the discovery of a high severity use-after-free vulnerability in the font handling of the HTML5 canvas. Ted Nakamura of the Chromium development community found a Mac OS X-only crash problem with unsupported RTC sampling rates, also rated with a high severity. The last of the high-severity-rated holes, an unchecked array in Chrome's content blocking, was fixed by the Chrome Security Team. Two medium severity issues were also fixed.

The mouse wheel scrolling problem fixed in this update concerned situations where the browser would scroll one pixel per mouse wheel interaction when it was actually set to scroll one screen at a time. Install problems for multiple user setups under Windows when Chrome was installed with administrator privileges have also been remedied.

Chrome 24.0.1312.56 is available for Windows, Mac OS X and Linux, and as the Chrome Frame plugin for Microsoft's Internet Explorer browser. All versions of Chrome should update themselves automatically; on some mobile platforms the user will be prompted to perform the update. Chrome is built from the open source Chromium browser project run by Google.

http://www.h-online.com/security/news/item/Chrome-update-closes-holes-and-fixes-mouse-wheel-issues-1791381.html

- Collapse -
Silly gits upload private crypto keys to public GitHub proje
Jan 25, 2013 1:04AM PST

Scores of programmers uploaded their private cryptographic keys to public source-code repositories on GitHub, exposing their login credentials to world+dog. The discovery was made just before the website hit the kill switch on its search engine or, more likely, the service collapsed under the weight of curious users trawling for the sensitive data.

The ability to search for private Secure Shell (SSH) keys on the popular open-source code haven came to light yesterday in tweets and other messages on social networks. At least some of the credentials can still be found using Google and other external web crawlers.

GitHub has more than 2 million users but only a minuscule proportion made the daft mistake of uploading their private instead of just their public crypto keys. Private keys reportedly exposed included the SSH login for a major website in China.

Continued : http://www.theregister.co.uk/2013/01/25/github_ssh_key_snafu/

Related:
GitHub search exposes uploaded credentials
GitHub Search Makes Easy Discovery of Encryption Keys, Passwords In Source Code
Do programmers understand the meaning of PRIVATE?

- Collapse -
Inside the Gozi Bulletproof Hosting Facility
Jan 25, 2013 1:18AM PST
Nate Anderson at Ars Technica has a good story about how investigators tracked down "Virus," the nickname allegedly used by a Romanian man accused by the U.S. Justice Department of running the Web hosting operations for a group that created and marketed the Gozi banking Trojan. Turns out, I've been sitting on some fascinating details about this hosting provider for many months without fully realizing what I had.

On Wednesday, federal prosecutors unveiled criminal charges against three men who allegedly created and distributed Gozi. Among them was Mihai Ionut Paunescu, a 28-year-old Romanian national accused of providing the gang "bulletproof hosting" services. Bullproof hosting is an Underweb term for a hosting provider that will host virtually any content, from phishing and carding sites to botnet command centers and browser exploit kits. After I read the Ars story, I took a closer look at the Paunescu complaint (PDF), and several details immediately caught my eye. [Screenshot]

Continued : http://krebsonsecurity.com/2013/01/inside-the-gozi-bulletproof-hosting-facility/
- Collapse -
U.S. homeland chief: cyber 9/11 could happen "imminently"
Jan 25, 2013 2:35AM PST

Homeland Security Secretary Janet Napolitano warned on Thursday that a major cyber attack is a looming threat and could have the same sort of impact as last year's Superstorm Sandy, which knocked out electricity in a large swathe of the Northeast.

Napolitano said a "cyber 9/11" could happen "imminently" and that critical infrastructure - including water, electricity and gas - was very vulnerable to such a strike.

"We shouldn't wait until there is a 9/11 in the cyber world. There are things we can and should be doing right now that, if not prevent, would mitigate the extent of damage," said Napolitano, speaking at the Wilson Center think tank in Washington and referring to the September 11, 2001, attacks.

Napolitano runs the sprawling Homeland Security Department that was created 10 years ago in the aftermath of September 11 and charged with preventing another such event.

Continued : http://www.reuters.com/article/2013/01/24/us-usa-cyber-threat-idUSBRE90N1A320130124

- Collapse -
Anonymous hackers jailed for cyber attacks
Jan 25, 2013 2:35AM PST

"Two men jailed for carrying out cyber attacks, including one online assault that cost payments giant PayPal at least £3.5m"

A student and a church volunteer have been jailed for carrying out cyber attacks with the hacking group Anonymous, including one online assault that cost the payments giant PayPal at least £3.5m.

Christopher Weatherhead, a Northampton University student, was sentenced to 18 months in prison on Thursday for his part in distributed denial of service (DDoS) attacks on PayPal, Visa and Mastercard in December 2010.

The 22-year-old, who used the online alias "Nerdo", was found guilty in December of playing a leading role in several cyber attacks by Anonymous.

Weatherhead was impassive as his punishment was delivered by the Southwark crown court judge, who was earlier warned that his "nerdiness" would make him a vulnerable target in prison.

Continued : http://www.guardian.co.uk/technology/2013/jan/24/anonymous-hackers-jailed-cyber-attacks

Also:
Anonymous conspirator gets 18-month jail term
2 Anonymous Hackers from the UK Sentenced to Jail for Cyberattacks on PayPal
Brit mastermind of Anonymous PayPal attack gets 18 months' porridge

- Collapse -
When the FBI comes knocking, don't hide laptops in your ..
Jan 25, 2013 2:35AM PST
... mom's dishes

Barrett Brown, the former self-proclaimed Anonymous spokesperson, has been charged for the third time in four months on federal criminal charges.

Brown was arrested and taken into custody in September after allegedly threatening an FBI agent. In December 2012, he was indicted by a federal grand jury for trafficking "stolen authentication features," as well as "access device fraud" and "aggravated identity theft."

On Wednesday, Brown was hit with one count of "concealment of evidence," and one count of "corrupting concealing evidence."

The indictments allege that on March 6, 2012, Brown concealed "two laptop computers," in an apparent attempt to evade a federal investigation. Last October, the Dallas Observer cited a "source," who said Brown's laptop was hidden among his mother's dishes. The new indictment also points to someone who seems to have "aided and abetted" this concealment, under the initials "KM."

Continued : http://arstechnica.com/tech-policy/2013/01/when-the-fbi-comes-knocking-dont-hide-laptops-in-your-moms-dishes/

Related:
Feds Pile On More Charges Against Anonymous Agitator Barrett Brown
Anonymous spokesman Barrett Brown indicted for a third time by feds