LHC HACKED,BEFORE IT COULD DESTROY THE EARTH

On 10 September 2008, a group identifying as the Greek Security Team managed to hack a computer system of the Large Hadron Collider charged to analyze the data from the Compact Muon Solenoid detector.In a web page of the CERN site, they described the technicians responsible for computer security as “schoolkids” and also expressed that they had no intention to disrupt the scientists’ work.

The hackers reportedly mounted an attack on the Large Hadron Collider, which has raised eyebrows over the security of this historic experiment in the world, as it surpasses a vital milestone.

Scientists say that it was a competition between two hacker groups - known in hacking circles as 2600 and 1337, that led them to break into the experiment just before it was to begin.

2600, also known as the Greek Security Team broke into the experiment and left a message saying, “We are 2600.. don’t mess with us…” The scientists who were behind the mammoth experiment had received threatening emails prior to the start.

Scientists working at Cern, the organisation that runs the vast smasher, were worried about what the hackers could do because they were ‘one step away’ from the computer control system of one of the huge detectors of the machine, a vast magnet that weighs 12,500 tons, measuring around 21 metres in length and 15 metres wide/high.

It appears that none of the experiments were adversely impacted by the security breach. But with “more than 110 different control systems” in place that run everything from building heating to radiation protection to the particle accelerators themselves, the idea of a security breach can seem frightening. Cern’s own Computing and Network Infrastructure for Controls group had previously produced a document that said, “recent events show that computer security issues are becoming a serious problem also at Cern.” The team refused to comment, however, on this week’s security breach.

Fortunately, only one file was damaged but one of the scientists firing off emails as the CMS team fought off the hackers said it was a “scary experience”. The hackers breached the CMSMON system, which monitors the CMS software system. CMS takes vast amounts of data during collisions.

[Source:rparmanik]

Browser Wars 2.0: Firefox scrambles to add ‘private mode’ browsing

Firefox private (porn) mode browsing comingAt Black Hat last month, when I spoke to Mozilla security chief Window Snyder, she made it clear that Private Browsing would not make it into the next revision of Firefox.

Today, the open-source group all but announced that the privacy feature, which puts the browser into a temporary state where no information about the user’s browsing session is stored locally, will definitely make it into Firefox 3.1 due sometime next month.

Why the sudden time line change? Welcome to Browser War 2.0.

[ SEE: Talking Firefox security with Mozilla’s Window Snyder ]

During our Black Hat conversation, Snyder stressed that Mozilla wanted to implement the feature in a way that offered true private mode instead of simply clearing the browser cache or removing temporary internet files. “We could implement private browsing in some fashion right now but, to do it properly, we will need to do some complex re-architecting,” Snyder explained.

Browser Wars 2.0: Firefox scrambles to add 'private mode' browsingNow, it appears that the buzz around Google Chrome and Internet Explorer 8 shipping with privacy-mode features has forced Mozilla to rush out its own implementation just to keep pace with competitors. Apple also a “private browsing” feature in its Safari browser.

[ SEE: Google Chrome, the security tidbits ]

Mozilla has thinking about Private Mode for a long time but software engineers have struggled to determine exactly how to offer real privacy to end users. Based on the back-and-forth in Bug 248970, it looks like Firefox 3.1 will:

  • Discard all cookies acquired during the private session.
  • Not record sites visited to the browser’s history.
  • Not autofill passwords, and not prompt the user to save passwords.
  • Remove all downloads done during the session from the browser’s download manager.

[ SEE: Microsoft confirms ‘InPrivate’ IE 8 ]

According to the Current Status page, this implementation makes the following components aware of the private browsing mode by preventing them from writing anything to disk in this mode:

  • Cache service
  • Cookies service
  • Permissions manager
  • SSL Certificate exception manager
  • History service
  • Form/Search bar auto-complete history manager
  • Download manager
  • Login manager
  • Content-specific preferences manager
  • Session restore service
  • Error console service
[Source: zdnet]

Apple plugs iPhone code execution holes

Apple plugs iPhone code execution holesApple’s long-awaited iPhone 2.1 software update was released today with patches for at least eight security vulnerabilities, some of which could lead to remote code execution attacks.

The most serious of the documented flaws affect the built-in Safari browser and could lead to code execution if an iPhone user is tricked into surfing to a booby-trapped Web site.

[ SEE: iPhone passcode lock rendered useless ]

The update also fixes the previously reported passcode lock weakness and an issue in mDNSResponder that puts users at risk of DNS cache poisoning attacks.

Here’s the skinny on the security patches in iPhone 2.1:

  • Application Sandbox (CVE-2008-3631): The Application Sandbox does not properly enforce access restrictions between third-party applications. This may allow a third-party application to read files in another third-party application’s sandbox, and lead to the disclosure of sensitive information.
  • CoreGraphics (CVE-2008-1806, CVE-2008-1807, CVE-2008-180): Multiple vulnerabilities exist in FreeType v2.3.5, the most serious of which may lead to arbitrary code execution when accessing maliciously crafted font data.
  • mDNSResponder (CVE-2008-1447): mDNSResponder provides translation between host names and IP addresses for applications that use its unicast DNS resolution API. A weakness in the DNS protocol may allow a remote attacker to perform DNS cache poisoning attacks. As a result, applications that rely on mDNSResponder for DNS may receive forged information.
  • Networking (CVE-2008-3612): TCP initial sequence numbers are sequentially generated. Predictable initial sequence numbers may allow a remote attacker to create a spoofed TCP connection or insert data into an existing TCP connection.
  • Passcode Lock (CVE-2008-3633): The Passcode Lock feature is designed to prevent applications from being launched unless the correct passcode is entered. An implementation issue in the handling of emergency calls allows users with physical access to an iPhone to launch an application without the passcode by double clicking the home button in emergency call.
  • WebKit (CVE-2008-3632): A use-after-free issue exists in WebKit’s handling of CSS import statements. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved handling of document references.

ALSO SEE: AT&T iPhones exposed to DNS cache poisioning? Or not? and Apple caught neglecting iPhone security

[Source: zdnet]

Secunia launches pay-as-you-go exploit shop

Secunia launches pay-as-you-go exploit shopDanish security research firm Secunia has launched a pay-as-you-go vulnerability analysis service aimed at providing technical details, exploits and proof-of-concept code to security software vendors.

The new Binary Analysis Service is billed as a one-stop-shop for indepth analysis of the “worst and most interesting vulnerabilities” affecting widely deployed software products. It will include exploits and proof-of-concepts for verification purposes and is available only for “certain types of vendors and governments.”

Secunia CTO Thomas Kristensen said the service is strictly “defensive in nature” with a goal to provide reliable intelligence for security vendors — especially anti-virus and IDS/IPS companies that rely on flaw data to create rules and signatures. It is also being marketed to corporate and national entities that have the technical capacity to create custom rules in-house for their IDS/IPS products.

[ SEE: Microsoft makes daring vulnerability sharing move ]

The company says it will strictly monitor access to the new service.

All the security vendors and other companies, who are approved, will get access to buy the Binary Analyses on a “pay as you go” basis or as an annual subscription, which gives unlimited access to the historical analyses and approximately 200 new analyses per year.

The company has already released free sample analyses with information on serious security vulnerabilities in Microsoft GDI+, Microsoft Word, Microsoft Windows OLE automation, Samba and Adobe Flash.

Secunia rolls out one-stop exploit shop

During the past 2 years we have serviced a few selected AV and IDS/IPS vendors with this intelligence, however, we have also realized that far too many of the other AV and IDS / IPS vendors — including the major ones — fail to detect many attacks utilising critical vulnerabilities simply because they too often create payload based signatures rather than vulnerability based signatures, Kristensen said.[ SEE: Secunia: 28% of all installed apps are insecure ]

The Secunia move follows news from Microsoft that it will start sharing details on software vulnerabilities with security vendors ahead of Patch Tuesday. The new Microsoft Active Protections Program (MAPP), which launches in October, will give anti-virus, intrusion prevention/detection and corporate network security vendors a headstart to add signatures and filters to protect against Microsoft software vulnerabilities.

The idea is to provide detection guidance ahead of time to help security vendors reproduce the vulnerabilities being patched and ship signatures and detection capabilities without false positives.

Some criteria for participants in MAPP include:

  • Members must offer commercial protection features to Microsoft customers against network- or host-based attacks.
  • Members must provide protection features to a large number of customers.
  • Members may not sell attack-oriented tools.
  • Protection features provided by members must detect, deter or defer attacks.

* Image sources: Secunia and HorseHats.com.

[Source: zdnet]

NoScript mitigates HTTPS cookie hijacking attacks


NoScript mitigates HTTPS cookie hijacking attacksThe invaluable NoScript for Firefox plug-in just got a tad better.

According to Giorgio Maone, the developer behind the popular browser extension, a new experimental feature called “Forced Secure Cookies” has been added to NoScript v1.8.0.5 to mitigate the HTTPS cookie hijacking attack vector discussed at DEFCON 16 last month.

Enabled by default, [the new feature] can be disabled either globally, by toggling the noscript.secureCookies about:config preference, or for specific domains only, by listing them (space or comma separated) in the noscript.secureCookiesException about:config preference.

[ GALLERY: 10 free security utilities you should already be using ]

Maone described the new feature as a countermeasure against Mike Perry’s automated HTTPS cookie-hijacking attack (see CookieMonster tool) that’s unobtrusive and non-interactive:

NoScript 1.8.0.5 just intercepts the “Set-Cookie” headers which are being sent over encrypted connections and are not flagged as “Secure” yet, adding the missing attribute on the fly before the cookie is stored.
This way, only those cookies actually created in the context of an encrypted transaction are forcibly switched to “Secure”, and therefore sites having lower security requirements and needing insecure cookies to work as a non-sensitive persistence mechanism are less likely to break.
Obviously those sites creating session-identifier cookies over insecure channels and recycling them after secure authentication won’t be helped by this implementation, but it’s apparently not the case of GMail, for instance.
However, should that prove itself to be such a common pattern to be worth protecting, a check on HTTP/HTTPS switching could be added to erase any previously set domain cookie.

[ SEE: DEFCON 16: List of tools and stuff released ]

NoScript blocks malicious scripts and allows JavaScript, Java and other potentially dangerous content only from sites you trust. It is also used by Firefox browser users to blocks blocks Flash and other potentially exploitable plugins and provides powerful Anti-XSS protection.

[Source: zdnet]

Apple plugs gaping QuickTime security holes

Code execution holes haunt QuickTimeApple today released a major makeover to its iTunes and QuickTime software products, fixing at least 11 documented security vulnerabilities that could lead to Mac and PC takeover attacks.

QuickTime 7.5.5, which should be considered an “extremely critical” update, address nine different vulnerabilities that could cause some serious damage if a Windows or Mac OS X user is tricked into viewing a rigged movie file. The iTunes 8 update addresses two separate bugs that could put users at risk of information disclosure.

Full details on the vulnerabilities and patches:

QUICKTIME 7.5.5

  • CVE-2008-3615: An uninitialized memory access issue exists in the third-party Indeo v5 codec for QuickTime, which does not ship with QuickTime. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Affects Windows Vista, XP SP2 and SP3
  • CVE-2008-3635: A stack buffer overflow exists in the third-party Indeo v3.2 codec for QuickTime. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Affects Windows Vista, XP SP2 and SP3.
  • CVE-2008-3624: A heap buffer overflow exists in QuickTime’s handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR file may lead to an unexpected application termination or arbitrary code execution. Affects Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3.
  • CVE-2008-3625: A stack buffer overflow exists in QuickTime’s handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR file may lead to an unexpected application termination or arbitrary code execution.
    Available for Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3
  • CVE-2008-3614: An integer overflow exists in QuickTime’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution. Affects Windows Vista, XP SP2 and SP3.
  • CVE-2008-3626: A memory corruption issue exists in QuickTime’s handling of STSZ atoms in movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Available for Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3
  • CVE-2008-3627: Multiple memory corruption exist in QuickTime’s handling of H.264 encoded movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Available for Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3
  • CVE-2008-3628: An invalid pointer issue exists in QuickTime’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution. Available for Windows Vista, XP SP2 and SP3.
  • CVE-2008-3629: An out-of-bounds read issue exists in QuickTime’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination. Affects Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3.

iTunes 8

  • CVE-2008-3634: When the firewall is configured to block iTunes Music Sharing and the user enables iTunes Music Sharing in iTunes, a warning dialog is displayed which incorrectly informs the user that unblocking iTunes Music Sharing doesn’t affect the firewall’s
    security. Allowing iTunes Music Sharing or any other service through the firewall inherently affects security by exposing the service to
    remote entities. This update addresses the issue by refining the text in the warning dialog. Available for Mac OS X v10.4.11, Mac OS X Server v10.4.11.
  • CVE-2008-3636: A third-party driver provided with iTunes may trigger an integer overflow, and could allow a local user to obtain system privileges. Available for: Windows XP or Vista.
[Source: zdnet]

Google closes hole in Single Sign-On service


Google plugs Single Sign-On HoleGoogle has fixed an implementation flaw in the single sign-on service that powers Google Apps follow a warning from researchers that remote attackers can exploit a hole to access Google accounts.

The vulnerability, described in this white paper (.pdf), affects the SAML Single Sign-On Service for Google Apps.

This US-CERT notice describes the issue:

A malicious service provider might have been able to access a user’s Google Account or other services offered by different identity providers.

Google has addressed this issue by changing the behavior of their SSO implemenation. Administrators and developers were required to update their identity provider to provide a valid recipient field in their assertions.

To exploit this vulnerability, an attacker would have to convince the user to login to their site.* Hat tip: Heise Security.

[Source: zdnet]