Friday, May 12, 2017

Some HP PCs may be logging user's keystrokes

 The software logging keystrokes has been found on HP PCs so far but to be safer check for a file:

C:\Users\Public\MicTray.log

If found remove this file.  The application that does this key logging is designed to control audio features. Not a good idea and the application appears to be poorly designed and not malware.
HOWEVER malware may use the key strokes logged in this file for nefarious purposes.

To keep the application running and protect yourself, remove the file, create a new file with the same name and set permissions for more restricted access.


Cyber Security SIG Presentation 05/04/2017


MacOS users - Have you seen or done an update to Adobe Flash

 If you have seen this on your MacOS systems recently and have clicked through the update

You may have installed a backdoor malware that have infected Windows and Linux machines in the past. Flash is installed or updated along with the malware strain known as Snake, Turla, or Uroburos.
The malware install obtains the administrator password then is able to steal data like account usernames and passwords. The signing certificate was revoked, but a new certificate is a possibility now that the malware has been modified to infect MacOS. Users who ignore the certificate error will be infected.
 MalwareBytes can detect and remove the infection.  Use the Sun City Computer Club MALWARE HELP link then the MAC MALWARE PREVENTION/REMOVAL instructions or the Sun City Computer Club Help Center. I have seen this often the past few days on my MACs and it has been around on Windows and Linux in the past.
 It is good practice to have applications updated along with the operating system. If possible have application updates Ask before applying updates and DO NOT click through certificate errors.

Thursday, May 4, 2017

Do MACs need anti-virus?

 In the Mac Users Group (MUG) SIG meting today  5/4/17 a video was played. As a cyber security professional I agree with every point made in the video.

 The issue in my mind is semantics. Word meanings. What is a computer virus? In a human analogy a computer virus "injects" or "infects" a running process or application. A virus is just one type of computer malware. Others include worms, trojans, denial of service, etc. A too long list. Most anti-virus products have morphed to anti-malware suites with anti-virus protections a part of the suite.
 I could argue the first discovered virus had MACs as its target.

 MacOS and Windows have different qualities for applications. MacOS is based on Linux/UNIX and has cheap process creation. To develop an application each function feeds its output to another function. Thus each function calls or creates a new process. Windows is more developer friendly. Applications inject code into other applications to make application development easier. In a human analogy: A police investigation application. MacOS the details of the investigation needed to be worked by another person/department is sent to that person/department. The results are sent back of or to the next person/department until the process is complete. In windows the person/department is asked to sit at the desk of the current investigator and use that desk/resource pool to process the investigation. Thus code injection is how Windows works. So virus on Windows in common and needs anti-virus. Anti-virus can be based on a "signature" or heuristics.

 Another point made "There are currently no known MAC viruses". Again semantics. A more accurate statement "There are no known unpatched MAC viruses".

 To prevent infections by any new MAC viruses the video advised to keep patches current (excellent) and to keep up with security news so you can take actions before the virus infects. The latter is almost impossible.

 Are anti-virus only applications for MAC unnecessary? Probably if they cost money. Are anti-malware suites/applications unnecessary? In my opinion NO.

 The recent security incident this week OSX/Dok worked by:
 1) Clicking on a link in a phishing email or in a WEB page visited. Anti-malware suites can contain both white listed and black listed WEB sites and email addresses.
 2) Dokument as an application was loaded. At first the application was signed by an Apple issued certificate. No defense in that regard.
 3) Apple revoked the signing certificate for the application. Both anti-malware and MacOS warned the user of the signing certificate problem. If the used clicked the Open button the application was loaded. Please do not do that. The warning is there for a reason.
 4) A zip archive then loaded a lot of Linux/UNIX utilities. Some anti-malware would have caught this and issued a warning.
 4) the current logged in user was made an Administrator if they were not already. Again, some vendors will warn, others not.
 5) the sudo file was modified to allow further infections to proceed. Some suites will alert.
 6) An overlay page that is an exact copy of the Apple update page is displayed while the rest of the exploit is loaded.
 7) The page asks for the administrator password. That password is sent to the attacker
 8) A command line tool loads TOR and SOCAT. Some vendors may alert.
 9) a rogue root level certificate is installed.
10) The system sets up a proxy so all WEB based traffic can be sent to the attacker's system. At his point all traffic/communications are able to be viewed AND modified by the attacker.
TO BE CLEAR all encrypted traffic  to your bank, broker, shopping, etc can be captured and/or modified. Account names, passphrases, ALL Traffic.

 Would anti-malware suites prevent this infection. Probably not at the time the infection was first deployed. Most suites might have alerted on several of the trip points, but the user would have to recognize and taken actions.

 There are several ransomware strains that infect MacOS. One is very bad since it never gets to send the encryption key back to the attackers so users will never get the key even after paying the ransom.

Most ransomware signatures are in good anti-malware suites for MacOS.

Wednesday, May 3, 2017

GMAIL Massive attack underway today

 Mostly hitting GMAIL email accounts, but other WEB mail users are being targeted as well.

If you get an email with a link to Google Docs  DO NOT click on the link.

If you have clicked on the link, or suspect you have   go to Google's My Account page and remove the Google Doc application

Google and personal privacy

https://myaccount.google.com/activitycontrols

 If you have not visited the above site/page at google you should. By default Google logs and stores every place you have been when interacting with google, every application run on your android phone, everything you have dictated or asked by voice (hey, google    and   dictation of emails, texts, etc.), every YouTube search AND videos watched and more.

You can not turn this collection off. Only Pause.

The site indicates the collections help Google make your experience better. The site indicates only you (and Google) can see the data in all of these collections. Only you and anyone who guesses your password/passphrase.Only you and anyone who resets your password/passphrase. Only you and anyone who uses your logged in sessions anywhere.

If you wish to turn any of these collections off  (Pause is the only available option) you will need to check every device you use to interact with Google.
To "Pause" move the slider to "Off"

THEN to remove all past history of data in these collections Click on MANAGE ACTIVITY.
Click on the "DELETE ACTIVITY by" link
Now select "All time"

Some may argue "I have nothing to hide" and this history of Google interactions may be useful.
If not, use the site to suit your personal privacy desires.
.
This information is what Google discloses.


Monday, May 1, 2017

MacOS Newly discovered malware allows attackers access to victim communications

A zip archive named Dokument.zip was signed by Apple 21-Apr-2017, since revoked.
Now the warning:
If the user opens the application anyway
according to blog post from Checkpoint. If the fake OS X update is installed the user is infected with TOR and SOCAT. From that point on the attacker can control the victim's communications.
 If you have been so infected take action via posts from Malwarebytes or Checkpoint