Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

Wednesday, May 25, 2016

Pastejacking Attack Targetting Users Clipboards Could Allow An Attacker to Execute Malicious Code.


A proof-of-concept (PoC) developed by the expert shows the threat posed by a Pastejacking attack when the user pastes commands copied from the web browser into the terminal. The example provided by Ayrey shows how an attacker can trick the user into thinking that they are copying echo "not evil" when in fact the string that gets copied is echo "evil"\n.


It’s worth noting that Ayrey’s PoC only works if the code is copied using keyboard shortcuts. However, the advantage is that the malicious content is added to the clipboard regardless of what piece of text is copied from the PoC page.


The \n (newline) character ensures that the command is executed automatically when pasted into the terminal without the user having to press the enter/return key. This means that the victim doesn’t get to see what they are pasting before it gets executed.


What's different about this is the text can be copied after an event, it can be copied on a short timer following an event, and it's easier to copy in hex characters into the clipboard, which can be used to exploit VIM.


The attack method does not work against Apple’s Safari browser, and some applications, such as the OS X terminal replacement iTerm and the Windows console emulator Cmder, show warnings when a command containing the newline character is about to be pasted.


Experts demonstrated several years ago that HTML/CSS tricks could be used to add arbitrary content to the clipboard without the user’s knowledge. However, the method detailed by developer and security expert Dylan Ayrey, dubbed “Pastejacking,” relies on JavaScript to accomplish the task.


“This method can be combined with a phishing attack to entice users into running seemingly innocent commands. The malicious code will override the innocent code, and the attacker can gain remote code execution on the user's host if the user pastes the contents into the terminal,” Ayrey said.


Users can avoid Pastejacking attack by disabling JavaScript, the best way to avoid falling victim of Pastejacking attacks is to be cautious when copying & pasting content from questionable sources.


Wednesday, December 23, 2015

A Man Arrested For Hacking Into Email Accounts Of Celebrities.


 In 2012, a man was sentenced to 10 years for breaking into the email accounts of Scarlett Johansson, Christina Aguilera and other celebrities. Last year, authorities arrested a Romanian man, known online as “Guccifer,” for hacking into the accounts of Romanian and U.S. public figures. Even more recently, hackers leaked the private photos and videos of tens of celebrities.

Recently A man from the Bahamas has been charged after allegedly hacking into the email accounts of celebrities in an effort to steal private files, including scripts for movies and TV shows.

The man is accused of stealing personal information, scripts for upcoming movies and TV shows, unreleased music tracks, and sexually explicit videos from victims’ accounts. The personal information stolen by the attacker includes social security numbers and passport copies.

The suspect, 23-year-old Alonzo Knowles, aka “Jeff Moxey,” is said to have used malware and phishing to gain access to the email accounts of individuals working in the entertainment, media and professional sports industries.

“This case has all of the elements of the kind of blockbuster script the defendant, Alonzo Knowles, is alleged to have stolen: hacks into celebrities’ private emails, identity theft, and attempts to sell victims’ information to the highest bidder. Unfortunately, these circumstances are all too real,” said Preet Bharara, the US Attorney for the Southern District of New York.

Law enforcement learned of the hacker attacks after a man identified as Knowles approached a popular radio host offering to sell scripts for an upcoming season of a drama series. The radio host alerted the show’s executive producer and introduced the hacker to an undercover law enforcement agent.

The suspect allegedly told the agent that he possessed a list of phone numbers and email addresses belonging to 130 individuals.

Knowles was arrested in New York on December 21 while trying to sell 15 scripts and the SSNs of three professional athletes and an actress for $80,000 to the undercover agent. The suspect has been charged with one count of felony criminal copyright infringement and one count of identity theft. Each of these offenses carries a maximum sentence of five years in prison.