This video presents multiple security vulnerabilities and defense strategies: (1) 80 AT commands can compromise Android phones through USB connections, enabling data extraction and firmware manipulation; (2) Adobe's Creative Cloud had an improper certificate validation vulnerability allowing elevated access; (3) A security flaw in Apple's online store exposed PIN codes for over 72 million T-Mobile customers; (4) Fortnite's use of third-party app stores instead of Google Play Store creates security risks including manual update requirements and bypassed security scanning; (5) Apache Struts contains critical remote code execution vulnerabilities (CVE-2018-11776/11777); (6) A zero-day Windows vulnerability was publicly disclosed on Twitter rather than through responsible channels; (7) Side-channel attacks can extract on-screen content through acoustic emissions from screens, detectable by microphones up to 10 meters away, which can be mitigated by covering screens with tin foil.
Cybersecurity News: AT Commands, Adobe Fix, Fortnite Risks, and Zero-Day Vulnerabilities
Added:this week 80 commands will pawn your phone Adobe gets creative with an update protecting your PIN why companies should use the Google Playstore zero-day vulnerabilities in Windows are disclosed on Twitter of all places and side-channel attacks that can be mitigated with tinfoil I'm telling you I got this one nailed tin foil will save you Jason wood from paladin security joins us for expert commentary on maintaining security at the edge or something completely different you'll just have to stay tuned to this episode of hack making news to find out this is security weekly for security professionals by security professionals [Music] broadcasting live from g-unit studios in Rhode Island it's the show that brings you the security news each week and despite popular belief we do wear pants it's hack Naked News the breach was huge news at the time Linux monitoring tool list of effective devices you can check out the link in the show notes Ars Technica is reporting that hackers have cracked to the Nintendo switch this week tracking people with locations and stuff like that you'll want to be rolling out updates if you're using Lenovo Hardware do you have a website in external presence employees in office any of these things can be compromised and attacked how are you defending your assets have you penetration tested your public assets start 2018 by taking a proactive approach to securing your vulnerable areas Black Hills Information Security has been helping companies find their weaknesses since 2008 email consulting at Black Hills infocomm and see how they can help you sleep better at night welcome everyone to this episode of hack naked news its episode number 186 and it is August 28th 2018 I am still your host Paul acid Orion coming at you live from g-unit Studios in Rhode Island make sure that you register for our webcast with Javelin networks entitled how to get attackers to contain themselves which we're airing this Thursday August 30th from 12 p.m.
to 1 p.m. Eastern Time is security weekly come forward / javelin to sign up today and now on to the security news 80 commands hich leaves Android phones open to attack attackers can use 80 commands to launch several malicious functions on an array of Android devices including extracting data rewriting the smartphone firmware and bypassing Android security measures all they need according to researchers who developed a proof-of-concept attack is the device and it's be connected to a USB connection it'll be interesting if you could make a cable that could send 80 commands to the phone as we talked about in a previous episode of hack naked news so be careful where you plug in your phone Adobe pushes out in unscheduled creative cloud application fix the Creative Cloud desktop application is a centralized place where users could locate and manage all of your Adobe apps the vulnerability which is an improper certificate validation means an attacker could exploit it to gain elevated access to resources normally protected within the application Adobe said that an important categorized floor means exploitation would result in compromised data security or potential allowing access to confidential data of course you have to assign your own risk score to this one and not go by what Adobe is classifying as risk or or not this is also important related to this article while the vulnerability CVE 2018 one to eight to nine was rated important Adobe acknowledged on Tuesday that is aware of a publicly available proof-of-concept code that exists to exploit this flaw security flaws inadvertently left t-mobile and AT&T customers pins exposed Apple's online store contained the security flaw that inadvertently exposed over 72 million t-mobile customer account pins the website for assure Eon the insurance company that AT&T primarily uses I had a separate vulnerability that exposed the passwords of pass codes of assurance AT&T customers Apple and a sherry on fixed the vulnerabilities after BuzzFeed news shared the security researchers findings this is of course in my mind extremely bad I have not completely digested all the researchers findings however pin codes that protect your cellular accounts your cell phone via your provider are extremely important as criminals have been known to social engineer your carrier in order to access your account which could hold two-factor authentication codes that are texted to the number so those are just a couple of examples of attacks that in several more examples exist in our show archives so I thought the disclosure of these pins was pretty significant the Fortnight installer vulnerabilities highlight mobile app store risks or lack thereof being in the App Store that poses a risk the discovery of a high-profile flaw in the world's most popular Gamze highlights why you should stick to open apps in Google Play Epic Games fortnight of course is played by millions of players around the world on different platforms including android fortnight however isn't available on the Google Play Store for Android rather epic games decided to bypass Google and use a third-party store to deliver its game likely my speculation is to avoid fees from Google although there's a lot of speculation as to why they did this it's problematic really for three reasons one if you have to enable the installation of third-party apps on your device desk opens up a security risk if you have to do that and I'm not sure with fortnight or any other third-party apps what the requirement is I'm not sure that's the case for fortnight but it could in other third-party apps in any case number two I have to either manually update this new application or game or trust in this case that epic games have some kind of automatic update feature that provides the security integrity that the Google Play Store provides and that the automatic update feature actually works and lets me schedule and have it have it be automatic number three the app will not be scan by Google Play stores checks for integrity or security which is kind of an issue a speculation is out there and I'm curious to this flaw in fortnight wouldn't have been caught by Google Play stores automatic checks for code integrity and security but because they chose to put it outside that didn't happen so I think some really interesting discussions about the third-party app stores insecurity that surrounds this recent thing the other twist in the story is Google actually found that the vulnerability in formats code already proof of concept has been released for a new Apache struts vulnerability the link in the article goes to the code they actually proof of concept code so make sure you check it out also there is another link that I put in the show notes that goes to the original announcement from Cemil regarding CVE 2018 11776 which states the Apache Software Foundation announced a critical remote code execution vulnerability in a Pachi struts of course the popular open-source framework for developing applications in java programming languages now unquote so what Keith Odin and I talked about his framework is he thought was a bad word he thought library was probably more specific and it we talked about it in the light of being at an included library so begin quote again applications developed using Apache struts are potentially vulnerable the vulnerability in is CBE 2018 11776 11777 all security research team which works to find and report vulnerabilities in widely used open source software so if you're trying to well if you want more about this particular story have a listen to the latest episode of application security weekly what Keith Holden and I talked about remediations processes that might exists to detect and fix this vulnerability in your environment a hacker discloses an unpatched windows erode a flaw with a proof of concept on Twitter the security researcher publicly disclosed an unknown zero day vulnerability in the Microsoft Windows operating system that could help a local user or malicious program obtain system privileges on the targeted machine and guess what the zero day flaw has been confirmed as working on a fully patched 64-bit Windows 10 system I'm really confused as to why it was disclosed in this way what prompted the researcher to do this type of disclosure rather than responsibly disclose it to Microsoft sell it on the black market sell it to a company that's more legit and buys these type of exploits or go through a bug bounty program whether direct through Microsoft or a bug bounty provider that Microsoft I believe Microsoft programs are direct with Microsoft but you know a bug bounty of any kind is also an alternative I don't know the answer I couldn't find it if you know please please write in apparently this Twitter account like came and went dropped O'Day and then went away a side channel attack a rat allows remote listener to hear on-screen images according to a team of academic researchers from Columbia University the University of Michigan the University of Pennsylvania and Tel Aviv University inaudible acoustic noises emanating from within computer screens can be used to detect the content displayed on those screens this includes the text on the screen of a computer or website content the user may have opened on their desktop it can also be used to monitor users input into on-screen virtual keyboards this can all be detected and recorded by the microphones built into laptops in webkinz the subtle acoustic signals also can be recorded by a smartphone or speaker placed on a decks desk next to the screen or from as far as 10 meters away using a parabolic microphone so my solution is we can just put tinfoil over our screens and we're all safe and problem solved with that we'll take a short break come back with the expert commentary from none other than Jason blood today's determined attackers easily bypass even the most advanced network defenses trying to ramp up staff to detect their backdoors can cost thousands of dollars and take months even years with active countermeasures AI hunter we enabled junior analysts to detect even the most advanced backdoors in a matter of hours sign up for a demo and purchase our product today by visiting active countermeasures com /h NN active countermeasures make every analyst a hunter welcome back everyone to hack naked news so I you know I think that the advantage of tin foil Jason is that I don't then have to read all those emails that come into my inbox every day either which is a nice byproduct of the tin foil how you doing Jason fantastic I gotta go to the store get some tin foil so I can wrap all my screens in it that sounds useful yeah so today so we are talking about security on the edge of software and new releases that are coming out I want to talk a little bit I don't normally I've not don't think I've ever talked about product on hack making news but I wanted to I ran across something that was really interesting last week we mentioned burp suite 2.0 Pro is coming out and we talked about some of that in security weekly right I happen to check the blog again and I noticed that they're they're releasing a new version called burp Enterprise which caught my attention because what the heck is that and it looks like burp is releasing an enterprise version or ports or rather releasing an enterprise version of burp where we're gonna have a server with a REST API and a web interface and turns out that it has the ability to deploy agents throughout your environment perform automated scanning which sounds pretty cool I've worked so I were done penetration testing for a number of years working on distributed teams and one of the things we always have to deal with was the idea you know well I know what I'm doing but I have no idea necessarily what my counterpart is doing except for you know through us talking about it sharing informations a little bit of a pain you know is your your your sending it for me screen caps or maybe session data back and forth for each other to see what the other ones doing is that what it's for Jason is it for pen testers you see that's like one of the questions I have about it they'd still don't have very information very much information up because the agent the agent conversation is interesting we actually I'd talked about this a little bit on application security weekly but so Acunetix used to have an agent because no one's paying us for their segments so we're gonna mention everyone in the space that's right this is this totally unpaid that's just interesting on our part a kinetics a couple years ago had an agent that I tested out specifically I tested the PHP one so basically when you're about to do with Dynamics cam rather than have your scanner work really hard to crawl the website and then work really hard to figure out what all the parameters are and work really hard to scan it and understand what was successful and what wasn't which are all some of the major challenges when you develop a dynamic web application scanning solution you put in agent or some kind of hook into the application I think library like it depends on there's all different methods for basically I'm placing a piece of software on the target that I'm scanning right and then I communicate with that software which is giving my scanning software telemetry and intelligence about the application so that when my tests run I'm doing that with the telemetry intelligence is being fed to me by some piece of software and again some people call it a lot like in rasp it's a library you got to compile into your web apps in most cases in container space like you can hook the container with just a small library or Linux program agent so I think the the days of heavy agent when we talk about an application are gone in a kinetics case it was a small little PHP script that I included in my application rapid7 is working on they are a sponsor ah dan Kuykendall from rapid7 who was anti objectives spider I figured what does rapid7 call their product it Dan's gonna be mad at me they rebranded it essentially it's an awesome web application scanner the mud just saying that cuz they're our sponsor I actually tested it before rapid7 made the acquisition and really liked it the engineering that dan now leads it rapid7 is great and he is very much actively researching how can I utilize the rapid7 agent which is a multi function agent it provides inventory tracking logging vulnerability data and he's working on carving out a space in that agent to say give me some telemetry and information about the web application that's running in integrating that into the scanner which is awesome I love that now it sounds like burp suite is almost following suit again this is technology Jason I have not seen really heavily used in practice it's something I've always wanted in a big way yeah and so in this case from what I'm reading about their agents it sounds like this is more like what we would expect inside of or Pro or we you know we tell it to go to an active scan of this app it's not deploying into the software like you're referring to it was a kinetics you said [Music] so in is it's almost like it's just farming out that work and distributing it throughout the network so when I'm picturing from what they're describing is we want to do web app testing throughout our environment let's deploy these agents out and here they all point back to the central console that's where the testers or the engineering team or whoever it is it's using this thing interacts with it and yeah I mean agent goes out and actually does the work of doing the scanning you don't have to have sure I mean that one central box with access to everything in the network and that lets you scan internal web applications from the outside more easily which is probably the problem that that particular feature sets trying to solve that was a feature that kind of lagged behind and a lot of the cloud-based scanning applications such as Detective Phi or tin foil tin foil I believe had a solution for that there are a lot more developer focused dynamic web app scanner and you could like deploy that proxy into your network so that all your testers would log into the cloud or if it was in your continuous integration and development platform conceivably an API reaches out to the cloud that says scan my web app it talks to an agent or some process internally it scans the web app and then returns it back up to the cloud I don't know if net sparker I'll research that one and get and get back to you I don't know I was thinking about Nets Nets program I remember having the conversation with Farrah I don't remember if the solution was implemented in that way however Farrah is very heavy on getting in that continuous integration and development process which is one of the reasons why I like Nets Parker who is a sponsor I should disclose that and one of the reasons I liked their solution I tested it I thought it worked really well I mean I tested the crap out of it and then signed them as a sponsor because I'm like your product is awesome and but nets Parker will actually do that incremental scan and which is why they want to integrate with the DevOps tile environments so like they'll do the full deep scan first and discover everything and then they'll the next scan they will just do a quick scan and see if anything has changed it was anything new and the only test what's new right or what's changed yeah that's awesome I think yeah and that was that sounds pretty cool to me because one of the thoughts I had as I was reading this release or some of post by courts where they're talking about also having hooks into continuing a CI CD yeah processes and one of the thoughts I had there was well how are they doing this I mean cuz you can't watch a full scan every time you'll slow things down too much they'll never get used if they don't have a differential scan like that it's pretty much useless to use in your in your DevOps environment because the scans won't complete fast enough exactly and so that was that was kind of that caught my attention unfortunate we don't have any information about that at all yet except that they're working you know that that feature set is gonna be part of it one of the thoughts I had about this though as I'm looking at it and I could see people getting really excited and want to deploy something like this you know because we you know have no idea what the price point is going to be on it or anything like that at this point but let's say that it's it's less expensive maybe than some of the other products are out there people start jumping on it you still needs to go through the full review process I mean we all like ports wigger and burp suite but you know we're talking about deploying server applications out into our environment with web interfaces and REST API s and communication between agents back and forth and storing data that's you know we're talking about how we hack websites and stuff like that and what we're doing here and vulnerability information so you know if you start looking at this you know if anybody starts looking at this and testing it you still want to run it through the full full process of reviewing their security controls their architecture how they do things how they handle encryption authentication between the agents and the the the main server you know what else storage of data at rest what privileges that could need to run all of that stuff you know those are all questions that that are going to need to review and check just because we've got a lot of good experience with a client base tool doesn't mean that we we run out there and deploy something like this on the fly so I'm really curious to see what they've got going on I liked something I'd like to take a look at myself and and see how they do things how it works but you know at the same time I'll say you know I'm curious what they wrote it in I mean we're sitting there just talking earlier about patchy struts and it's like well man I hope this thing isn't built on anything related to that well cuz burp is written in Java absolutely whole thing's and we're launching a jar right and so I could see them using Java because that's theirs yeah I have all their expertise and their code sure so yeah I think there's a lot of questions about that sure I it's probably something like a glorified proxy server of some kind I mean it has to proxy the traffic at the end of the day yeah something that just made it easier to deploy proxies for testers I think the more exciting use case when we talk about agents in dynamic scanning is you know actually having some insights into the application which I think some vendors have tried especially in the rasp and they they call it I asked or interactive application security testing largely I think that's a buzzword I I haven't seen it in by all means if you know technology that you're using that this really works on let us know but yeah cool yeah so interesting news coming out of burp suite or port swagger I just wanted to highlight it here and some things to address if you're looking at it and Paul thanks for all the information you provided about the other you know how this is handled and stuff like that yet a lot of information I didn't have so it's cuz I cheated because you cheated all right well that's what we do in this industry right that's right hello thanks so much Jason and thank you everyone for listening in watching it is this edition of impact Naked News see you next time
Up Next

Introduction to Peer-to-Peer Networks | Lecture 01
@IITKanpurNPTEL
3.9K views•2020-08-31

BitTorrent Protocol Explained: Piece Selection & Peer Choking
@StevenGordonAU
481 views•2013-02-22

HTTP Requests Explained: GET, POST, PUT, DELETE
@codecademy
103.1K views•2021-10-07

Enigma Machine Mechanics: WWII Encryption Explained
@JaredOwen
13.2M views•2021-12-11
Related Study Plans & Knowledge Roadmaps
Structured learning paths in Computer Science






































