Latest: Digital For Tech News Click Here


Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Tuesday, 15 April 2014

How Heartbleed Bug Exposes Your Passwords to Hackers

0 comments
How Heartbleed bug Exposes Your Passwords to HackersAre you safe from the critical bug Heartbleed?? OpenSSL- the encryption technology used by millions of websites to encrypt the communication and is also used to protect our sensitive data such as e-mails, passwords or banking information. But a tiny, but most critical flaw called "Heartbleed" in the widely used OpenSSL opened doors for the cyber criminals to extract sensitive data from the system memory.SSL and TLS are known to provide communication security and privacy over the Internet for applications such as websites, email, instant messaging (IM), including some virtual private networks (VPNs).Heartbleed is a critical bug (CVE-2014-0160) is in the popular OpenSSL cryptographic software library, that actually resides in the OpenSSL's implementation of the TLS (transport layer security protocols) and DTLS (Datagram TLS) heartbeat extension (RFC6520).This bug was independently discovered by a team of security engineers (Riku, Antti and Matti) at Codenomicon, while improving the SafeGuard feature in Codenomicon's Defensics security testing tools, and Neel Mehta of Google Security, who first reported it to the OpenSSL team.Software vulnerabilities may come and go, but this bug is more critical as it has left the large number of private keys and other secrets exposed to the Internet. The heartbleed bug can reveal the contents of a server's memory, where the most sensitive data is stored, including the private data such as usernames, passwords, and credit card numbers. This could allow attackers to retrieve private keys and ultimately decrypt the server's encrypted traffic or even impersonate the server.
“The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.”
OpenSSL is most widely used cryptographic library for Apache and nginx Web servers, which handles a service of Transport Layer Security (TLS) called Heartbeat, an extension added to TLS in 2012. The combined market share of just those two, Apache and nginx, out of the active sites on the Internet is over 66% according to Netcraft's April 2014 Web Server Survey.Moreover, OpenSSL is used to protect email servers (SMTP, POP and IMAP protocols), chat servers (XMPP protocol), virtual private networks (SSL VPNs), network appliances and wide variety of client side software. Many large consumer sites are also saved by their conservative choice of SSL/TLS termination equipment and software. OpenSSL is also very popular in client software and somewhat popular in networked appliances which have most inertia in getting updates.

Security researcher 'Robert Graham' scanned the Internet and found that more than 600,000 servers are vulnerable to heartbleed flaw, including Yahoo.com, imgur.com, flickr.com, hidemyass.com. [List]

Because of Heartbleed bug, the Canada Revenue Agency was forced to shut down its electronic tax collection service yesterday and apparently, World's biggest audio platform SoundCloud also logged out its users for fixing this flaw.How Heartbleed bug Exposes Your Passwords to HackersYahoo, which has more than 800 million users around the world, also has been exposed by the bug.
How Heartbleed bug Exposes Your Passwords to Hackers
HOW HEARTBLEED WORKS?It is not a problem with the TLS/SSL technologies that encrypt the Internet, neither with how OpenSSL works. It is just a dumb coding mistake.

Using Heartbeats extension two computers make sure the other is still alive by sending data back and forth to each other. The client (user) sends its heartbeat to the server (website), and the server hands it right back. If by chance anyone of them goes down during the transaction, the other one will know using heartbeat sync mechanism.


When that heartbeat is sent, a small amount of the server’s short-term memory of about 64 kilobytes comes in reply from server and an attacker is supposed to grab it, that can leak sensitive data such as message contents, user credentials, session keys and server private keys. By sending heartbleed requests multiple times, an attacker is able to fetch more memory contents from the server.

This means, everything and anything in the memory such as SSL private keys, user keys used for your usernames and passwords, instant messages, emails and business critical documents and communication, and many more is vulnerable to cyber criminals. At this phase, you have to assume that it is all compromised.

About two-thirds of web servers rely on OpenSSL, means the information passing through hundreds of thousands of websites could be vulnerable.


So far, Security experts have found no direct evidence that anyone has managed to use the bug to steal information. The vulnerability has been fixed in OpenSSL v1.0.1g.


Major websites, including Gmail and YouTube, Facebook, Tumblr, Yahoo and Dropbox have fixed the problem, but there are still thousands of websites who are yet to fix the problem. Users are advised to change their passwords on only those affected websites, that tell you they've fixed the problem. READ MORE on how to protect yourself from Heartbleed bug.

Continue reading →

Securing Passwords with Bcrypt Hashing Function

1 comments

Securing Passwords with Bcrypt Hashing Algorithm


Passwords are the first line of defense against cyber criminals. It is the most vital secret of every activity we do over the internet and also a final check to get into any of your user account, whether it is your bank account, email account, shopping cart account or any other account you have.We all know storing passwords in clear text in your database is ridiculous. Many desktop applications and almost every web service including, blogs, forums eventually need to store a collection of user data and the passwords, that has to be stored using a hashing algorithm.Cryptographic hash algorithms MD5, SHA1, SHA256, SHA512, SHA-3 are general purpose hash functions, designed to calculate a digest of huge amounts of data in as short a time as possible.


Hashing is the greatest way for protecting passwords and considered to be pretty safe for ensuring the integrity of data or password.The benefit of hashing is that if someone steals the database with hashed passwords, they only make off with the hashes and not the actual plaintext passwords. But why do we always hear about passwords being cracked? There are some weaknesses in cryptographic hash algorithm that allows an attacker to calculate the original value of a hashed password, as explained below:


PROBLEMS WITH CRYPTOGRAPHIC HASH ALGORITHMBrute Force attack: Hashes can’t be reversed, so instead of reversing the hash of the password, an attacker can simply keep trying different inputs until he does not find the right now that generates the same hash value, called brute force attack.General-purpose hash function designed for speed,because they are often used to calculate checksum values for large data sets and files, to check for data integrity. Using a modern computer one can crack a 16 Character Strong password in less than an hour, thanks to GPU.


Hash Collision attack: Hash functions have infinite input length and a predefined output length, so there is inevitably going to be the possibility of two different inputs that produce the same output hash. MD5, SHA1, SHA2 are vulnerable to Hash Collision Attack i.e. two input strings of a hash function that produce the same hash result.Salting your password may foil dictionary attacks, but an attacker can still use a wordlist to crack the hashes. So, what exactly could be a good for securing your passwords with hashing?BCrypt, IT's SLOW AND STRONG AS HELLTo overcome such issues, we need algorithms which can make the brute force attacks slower and minimize the impact. Such algorithms are PBKDF2 and BCrypt, both of these algorithms use a technique called Key Stretching.Bcrypt is an adaptive hash function based on the Blowfish symmetric block cipher cryptographic algorithm and introduces a work factor (also known as security factor), which allows you to determine how expensive the hash function will be.This work factor value determines how slow the hash function will be, means different work factor will generate different hash values in different time span, which makes it extremely resistant to brute force attacks. When computers become faster next year we can increase the work factor to balance it out i.e. to make the attack slower.This hashing algorithm is implemented in a number programming languages like PHP, Java, Ruby, C#, C etc. If you are a PHP developer, you can simply use the crypt() function with a Blowfish required salt.


// Generate a password using a random salt password_hash($password, PASSWORD_BCRYPT);// Generate a password with a known saltpassword_hash($password, PASSWORD_BCRYPT, array("salt" => $salt));// This will cause crypt to generate a bcrypt hash$salt = '$2y$10$' . mcrypt_create_iv(22);$salted_password = crypt($password, $salt)
This method of hashing passwords is solid enough for most web applications that stores users’ passwords and other sensitive data.
Continue reading →

Wednesday, 9 April 2014

18 Million E-mail Account Passwords Stolen in Germany

0 comments
 https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjH-wje6jiYePUbYQ0D4ZNA69f0ZRewmA97Y8_KJwlrNFTo8RUaGti_CEW76DOEKnALL4onHlEd57z0giU2F4EUTYtJsq_vBQ5SYwwCScnxWJP074u918DkGRNXNWfcLzhOjC0lZerEMGs/s1600/hacked.png

German newspaper The Local quotes German authorities saying that they are investigating a major mass theft of 18 million email passwords that had affected all the ISPs in Germany.

 Prosecutors tell that they are determining how these passwords were stolen. The prosecutor told media that compromised email accounts are being used online for making online purchases.

 Also the other online accounts, whose users had put same passwords as that of their email's, have been hacked. 

According to Der Spiegel, at least 3 million of the stolen accounts belonged to German citizens. 

This is the second major breach of e-mail account information in Germany this year -- in January, Germany's Federal Office for Information Security announced that 16 million stolen e-mail addresses and passwords had been found during an analysis of botnets.
Continue reading →

Hackers Can Unlock Tesla Cars by Stealing Owners’ Passwords

1 comments
http://www.teslasociety.com/pictures/global_warming/tesla_roadster.jpg 


Corporate security consultant and Tesla owner Nitesh Dhanjani said that hackers can potentially unlock Tesla cars by stealing owner's password. Tesla cars are password protected. When a customer buys the car he will be required to obtain a password from Tesla's official website.
 The password that’s set by Tesla owners when they create an account is six characters long, and it must contain at least one number and one letter. This makes the password easy to obtain with brute-force attacks. Since it’s only 6 characters long, it’s not difficult to crack. 
Furthermore, there are no account lockout policies for incorrect login attempts. Nitesh Dhanjani says hackers can also employ certain other methods to obtain the password which may include phishing and social engineering. Nitesh said the if hackers get access to password they can lock and unlock the car can steal valuables placed inside. 
Hacker can also flash lights and can remotely locate the cars. Nitesh has submitted the findings to the company. Tesla assured that it will consider all possible risk and take the necessary measures accordingly.
Continue reading →

Hackers Target Al Arabiya, Leak Passwords After Exploiting Zimbra Vulnerability.

0 comments
http://www.debbieschlussel.com/archives/alarabiya2.jpg 

Hackers associated with notorious LullzCrew are back in public stunts. Yesterday they targeted Al Arabia, Saudi owned Tv Channel, and leaked its sensitive data. Lullz Crew says it's back again and now it has teamed up with Horsemen of Lullz, another hacktivist group, to launch a massive operation against the system. Lullz Crew had been in news for attacking largest media organization before. 

This time too, they have targeted Al Arabia, the leading media franchise in Middle East. The hackers wrote in a statement next to the data they leaked, " Al Arabiya is the second largest news agency in the Middle East. 

Considering we've been targeting large media corporations? Well, it falls right into our range; So, without further ado. NullCrew and The Horsement Of Lulz persent to you? The candies,” The hackers exploited the vulnerability in email and web client software Zimbra to gain access to data. LullzCrew told Softpedia that they have got access to a huge amount of data , “Do we plan to release more? It all depends on how much use it holds to us, things of particular use can be used over, and over again. We treat certain data the same way we treat 0day. Why leak it when it can be used properly down the road?” they told in a Twitter message.
Continue reading →

Monday, 7 April 2014

Worst Data Breach in German History, 18 Million Email Passwords Compromised

0 comments

Worst Data Breach in German History, 18 million Email Passwords Compromised


Germany has confirmed its biggest Data theft in the country's history with usernames and passwords of some 18 million email accounts stolen and compromised by hackers.The Story broke by the German press, Der Spiegel on Thursday, when German Authorities revealed another mass hacking of private data belonged to German citizens and major Internet companies both in Germany and abroad.Authorities in the northwestern city of Verden unearthed a treasure of personal information, a list of about 18 million stolen email addresses and passwords, and seized it just after only two months from the previous major data breach, when researchers came across 16 million compromised email accounts of German users while conducting research on a botnet, a network of computers infected with malware. The accounts were compromised by hackers in the mid of January, and Der Spiegel suggests that the same group of hackers is responsible for both thefts and that they may be based in one of the Baltic countries.MILLION ON SPAM .. SHOP... THEFTAccording to Investigators, some of the accounts are used to send spam emails and some combinations of email and password are used for online shopping portals, as these mass of stolen personal information could also be used to obtain the financial details of users account. To help in securing the Internet users, German authorities warned to take additional security measures to prevent cyber criminals using their data while shopping online."It is suspected that these stolen records are being actively misused," said Lutz Gaebel, spokesman of the prosecutor's office in Verden.


SOURCE OF DATA

Till now, It has not been revealed by the investigators that how much they know about this massive data Breach and How the attackers get their evil hands on the personal data of over 18 million users. Lutz Gaebel declined to give more information due to the ongoing investigation. It is estimated that at least three million of the accounts belonged to German citizens and some of the compromised email accounts have international domain extensions such as ‘.COM’. But in real, the number could be much larger than the visible one as the investigation is ongoing.The German prosecutor investigating the latest major data theft informed the country's IT watchdog, Federal Office for Information Security (BSI), to introduce additional security measures to help the Internet users.
Continue reading →
 
Copyright © 2013 MyBloggerBlog Template All Right Reserved
Designed by MyBloggerBlog | Powered by Blogger