Anything can go here, in any language... except my native language Sinhala. Be cool... anybody is warmly welcomed! :)

Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Viral Apps on Facebook | Would you let them to use you?

Recently I saw some videos spreading on Facebook. 'Spreading', in the sense that people watch and share. What so special with these videos was, their thumbnails had that "Youtube feel", but seemed bit different. Also, most of these had eye-catching titles (in Sinhala), and eye-catching thumbnails (For example, a girl changing her dress... ;-) ).

I actually clicked on one of these to play the video. Then it took me to a Facebook application page where it prompted me to grant permissions to a Facebook app called "Gindara videos". Why would I ever let a Facebook app to access my personal information when I have dozens of better ways to anonymously watch video on the Internet? As a matter of fact, I stopped there. Access denied, Gindara videos go fly a kite, please.

Few days back I saw a girl has shared another video of the same type. She is a fun person I know, but it was bit of odd thing that she would share such a thing publicly. So I left a chat message to her jokingly, "what are these things you post on fb? :P", and she replied, "seriously i didn't know. :'(".

Then I wanted to have a close look at the phenomenon. "Gindara videos" is a malware hosted on a Sri Lankan website called tharunaya.co.uk. This is not the only such malware seen on the Internet. Even years ago, there have been many of this type. But I feel this particular malware remained on Facebook for sometime longer than the previous ones, totally because people's ignorance. Their targeted victims seemed to be Sri Lankans and that may be the reason for such long lasting. If it ever had a 'global presence', not very long time it takes to vanish from Facebook.

Whenever you spot that kind of video or any malicious post on Facebook, take a moment to report them for spam. It's more of a civic duty. After reading the story below this picture, you'll better understand why you should report them.

Just report it for Spam


I did a piece of Holmes stuff and found out that these guys are using tool called "Facebook Viral Videos App With Auto Share" from a vendor called Appstico. As the name says, it's a 'viral' app which can automatically share videos on Facebook. Now, look at my friend's reply above again... she didn't know that she has shared a video on Facebook.

I don't want to promote Appstico's blackmarket stuff here, but just putting a nofollow hyperlink for you to go through it as understand what these guys do with YOUR personal information that YOU allow them to see.
http://appstico.com/facebook-viral-videos-app-with-auto-share/

This is what exactly tharunaya.co.uk/Gindara all about. In short, here's how it works.
  1. There's a bunch of bad guys who want few more visitors coming into their website.
  2. They deploy a virus. A social virus which uses human mind as its career and people's curiosity as the exploit.
  3. Misled people just want to watch something that is rarely or never seen for real. No time to worry about privacy!
  4. The video hyperlink on Facebook actually directs the victim to the bad guys' website.
  5. It doesn't stop there. Without victim's knowledge, it posts a video hyperlink to the victim's Facebook timeline, which can be seen by other people.
  6. They get more traffic, more traffic is more profit, and target accomplished. And the poor victim even doesn't know that someone has used him/her until a friend pokes.
Let's have a look at the 2nd step above. These 'Tharunaya' guys do business and their sole purpose is to increase their business. Who has time to learn how to make a virus from A to Z? So they outsource it to another party. And that another party is Appstico.

(click to enlarge)
Appstico also does is business, and knows that there are many bunches of bad guys who want more business coming in. So Appstico makes a package for everyone, and sell it to the bad guys just for one hundred US dollars. Bad guys just rename it to "Gindara videos" and make use of it. How clever is that?

Would you still let them to use you? Myself, I wouldn't. The more you report these malicious activities for spam, less they get spread. Eventually the viral app will be taken out by Facebook. And as I said above, it's a civic duty to report malicious things, as it helps to keep Facebook clean and safe place for people.

It doen't cost much time - usually lesser than to watch a video :-)


Theoretically this entire blog post is all about a separate area in Internet security called "Social Engineering". To end this blog post, I'll leave that for your further reading:
http://en.wikipedia.org/wiki/Social_engineering_%28security%29

Thanks for reading!

* If anyone is interested, I have proof of what I speak.

Be Aware of Social Engineering | Know Your Weaknesses


Email account hacked? Somebody has accessed your personal email?? If you have experienced this before, surely this blog post will be useful. Today I'm writing this note for those who do not have much experience with the Internet and WWW.

First of all, we'll follow up a small hypothetical case. Suppose I am a novice computer user; like one of the most of our community. I have a Facebook account. One day, a nice lady appears in... violah! She wants to be my friend!! Of course I don't know her... but who cares? She's at my doorstep, knocking my door. Accepted! (And she's here for a Relationship, Dating,.... blah blah)

After some time... it looks like something has gone wrong... I can't login to my Facebook account!!! Oh Jeasus..! Some weird status updates on my wall.... :( What on Earth is happening?

May be resetting my Facebook password may work. So I'm trying the “Forgot password” link. OMG!!! I can't access my email account...!! It's HACKED!!! O_o

(phone rings)

Hello, is this J?

“Yes, Speaking...

Idiot! What's the meaning of that $#$%# email you have sent to me????

Hey I'm sorry; I'm really sorry... my email account was hacked by someone. I didn't send that by myself... somebody has taken over.... believe me,.. sorry..........!!!!

(conversation continues, and so and so)



Fine. The story is enough for us. Let us see what has really happened. The nice lady is actually an online predator. In reality, 'she' might potentially be 'he'. Remember the second training that Morpheus gives to Neo in the movie Matrix? Yes, the lady in red dress!

The very first advice that I might give you is, do not accept friend requests from unknown people on whatever social networking website you are using. It's always better to limit your connections to those who you know in reality. If the lady is too cute to be denied, you can just ask somebody and find out who she really is.

Then, how was (s)he able to hijack your all the accounts? I'm making one assumption here, that the victim in the above example is bit lazy in remembering passwords. So he uses his birthday as the email password!

(S)he just looks at your Facebook profile info, and then finds the victim's email and birthday on it. Suppose it's 06 July 1988. The predator might try 880706 on his/her first attempt. May be (s)he will fail. There is a second attempt... and of course subsequent attempts. So (s)he may re-attempt with,
060788
070688
07061988
19880706


… and so on...

If the victim has set one of those as the email password, and if our 'nice lady' has been able to match it, accidentally or somehow... what will happen?

You might have used your email account to create accounts/ profiles on various web-based services such as Facebook and Twitter. Almost all of them have the 'password reset' (or 'forgot password') feature, directly associated with your email accont. This means your email account is the one that you should keep eye on most. It's like the queen bee in a population. Once somebody has access, they can do almost anything.

So, now in our case, not only the email but also,
  • (S)he can overtake victim's Facebook account
  • (S)he can overtake victim's eBay Account
  • (S)he can overtake victim's Paypal Account
Panic!!

Then, my next point goes like this,...
Never use your sensitive personal information to fomulate passwords. May be your birthday, name of the spouce, phone number, national ID card/ social security number – avoid useing them in passwords.

Those who know your personal information can GUESS your password. And that's what we call “Social Engineering”!

A good password should consist of capital letters, simple letters, numbers, and punctuation. Also, it should not be less than 8 characters. Preferred length for a stong password is 14 characters and as mentioned above.

Finally, see it... You do “Social Networking”; and they do “Social Engineering”... Be aware..!



The above case was not something that I have experienced in my real life, but I can show you dozens of people who have had this real world nightmare.

So, thanks for reading... take your time and think... it's about your privacy. Ciao.........!!!!!! :-)

Is it a legit Facebook app?

Hi folks, just a small story with four screenshots...

If you use Facebook, you might have got game/application requests from  your 'friends'. But, did you know that some of those requests are actually not made by your friend? He/she might even doesn't know. They just add the application, and then the application automatically sends requests to each friend. And you think that they might get upset, and Allow the app.

In some cases, the application can even steal our privacy. So who do we get aware? Just go through the following screenshots:
(please click on each screenshot if you can't read them properly)


Note the fake application icon, and five-star rating.
Click on the application's name (that I've highlighted) to learn more about the application...

Look carefully, the app holds the Facebook logo as it's logo, but, this is NOT developed by Facebook! (see the left side pane)

Go to the Reviews tab and see the comments from the community. The TRUTH!!!

And finally, you might want to Block the application, so you won't get requests anymore... :-)




After Facebook has introduced their new privacy model, things have become ever worst. They have made some limits on capability of blocking stuff, and eventually we get addicted. Facebook is marketing our privacy. All they want us to spend more on Facebook. We fools trap in their strategies - they make profit - and we make loss to our boss.


So think wisely. USE FACEBOOK, BUT DON'T LET FACEBOOK TO USE YOU!

And finally I must say,.... I willingly misspell Facebook founder's name,... SUCKERberg!!! :-)

Attack and the Defence




Hi dear readers! First of all, I WISH YOU A HAPPY AND PROSPEROUS NEW YEAR WITH LOT OF ACHIEVEMENTS, GLORY AND JOYNESS!! Anyway, 2012 is also approaching.. :D (just kidding)

After a long long time, I've got an interesting problem to solve. I'm not an expert. I'm just writing my own way that I followed in the situation.

This happened during the Christmas days in 2009, and after all, I feel it like a Christmas gift, seriously! :-) I wrote two blog posts in my native language, I you can read, just visit the following links. You'll find it more interesting than this one if you can read. :)
  1. http://blog.shaakunthala.com/2009/12/hacker.html
  2. http://blog.shaakunthala.com/2009/12/bash.html
Alright, then... I'm responsible for the administration of several websites. As I feel, an administrator's job is very much similar to the job of a sea captain. He has to look after the system, like his own... be vigilant of the attacks and other problems,.. and many more work.

Recently, I've been notified that one of my sites is down. An empty page with an error message is displayed when the site is visited, and according to that error message, there's an error on index.php, line 38 and the character < is the cause. This is the way how PHP shows error messages. As my immediate actions, I logged on to the FTP server where our website is hosted and opened the index.php

The website was developed using a CMS. The code looked some kind of strange for me because it had no corresponding ?> tag for its beginning <php tag. An unknown HTML/ Javascript code snippet has appended at the end of the file.

Yes, that's the cause of that error. Somebody has injected a malicious code snippet at the end of the index document, and the PHP engine on the server side has tried to interpret it as PHP. As this has caused a syntax error in PHP, the whole site has gone down as the final result.

Here's the structure of index.php :

<?php
/* PHP
codings of
CMS */

<script> // The foreign Javascript code snippet </script>

What I did is, just copy-pasted the code into a separate text file (for analyzing), and cleaned index.php. Then everything looked normal, but sooner I got to know, actually it is not.

I've never experienced such a situation before. I didn't know where to start, and what to do. But I wanted to find out what the code says. It was some kind of scary and big JavaScript code in a single line. However, it's not so scary!


Okey,... a closer look...


Right... and this is our troublemaker...


Just see carefully,.. you don't need to be a JavaScript guru. :-)


It's not a big deal to identify such big codes. Vigilance is what matters here. They have used the replace () method in JavaScript. See... strategically hiding text by just randomly mixing punctuation, retrieving the original text at run time. Wow!

Finally, it's this:


Looks like it has been created for phishing purposes... but I'm not sure exactly. However, this URL points to an empty page. What I expected was a JavaScript code, but this resulted nothing... I don't know a reason. :-/

Within few hours after fixing the issue, I got to know that our website is down again. The same thing has happened, same style, but the malicious code resulted a different URL. I fixed it again, and started thinking... what on earth could be happened here? :-O

Whoever the attacker has done is injecting some malicious code into the index document, and letting it execute at the client's (browser) end. However, as the code has blindly appended at the end of the file despite the structure of it, I came to a conclusion -- definitely this is done by a bot / script or some other automated mechanism.

So, I did the same operation as before for cure, and then tried to find some solution. Yes, it's gonna be a new experience. To prevent further attacks, I put the following line at the end of the index.php file. It prevented interpreting any code below the line. When I say die!, no further interpretation of code at all. Hence, the site is safe from being down, but the risk is still their till I find where the attack comes from and where the security hole is.

die ();

I tried to find any clue on site logs,.. but no luck. If this attack was carried out through HTTP, site logs (not the CMS logs) should indicate that. What I suspect is, somebody has gained access to the server, and executed a script. By adjusting file permissions on the index document, I found out that the malicious script on the server (or bot) has gained the root access.

Later, I got to know, this has recursed into directory hierarchy through the entire site. And also, I saw that some JavaScript files are also infected. It was shocking! Everything throughout the site can be potentially infected with malicious code and hence unsafe for visitors!! I didn't know how serious the attack was. I have never faced such a situation before, and as the responsible personnel, I have to fix this as soon as possible, with my best efforts.

According to all observations, my conclusion was, this is happened due to the fault of the web hosting provider. I know that CMS' sometimes can contain security holes, but if it was, there should be at least something on the site logs.

All of the above is the summary of my first blog post, mentioned at the top of this post. The next few paragraphs in this post explain how I performed the disinfection.

 ---

The only backup we had was bit old, so I forget the idea of restoring from a bacup archive. The challenge was to find out how serious the attack was, and to disinfect everything.

What I suspect so far:
Every JavaScript file and index document is infected -- but not sure about other text-based file formats.

So I have to check each file for malicious code, and then clean them.

First, I thought of writing a PHP script for the purpose. But, PHP is bit insecure with this work. I know, it's not a big deal to fix the security with PHP, but, I was more interested in bash scripting. As a daily Linux-only computer user, I am very familiar with bash, and feel more reliability with that.

Luckily, the web hosting service provider has offered remote access through ssh. Yes, that's great! I was very keen, the rest's gonna be a party!! ;)


Here's the match highlights... :P

Access through ssh, compress the entire site, and then download it. This is necessary because the safe way is to keep a backup + do a testing when doing something serious. One mistake, could ruin everything!!

Here we go, ssh
$ ssh user@mysite.com

Create an archive, (make it tar.bz2 for higher compression ratio -- easy to download). Then exit ssh.
$ tar cvfj mysite.tar.bz2 mysite/
$ exit

Download the backup, through ssh copy.
$ scp user@mysite.com:/home/user/mysite.tar.bz2 /home/shaakunthala/

Unpack on my computer, to be tested with the script.
$ tar xvjf mysite.tar.bz

Now, next step is to write the script. Fired up my favourite vim editor, and then started thinking. ;) Before writing the script it's necessary to exactly identify the nature of the malicious code. Here's what I've identified:
  • If a file is infected, the malicious code is at the end of the file.
  • The foreign code snippet is different from point to point. But, following text portions can be recognized as a common pattern.
    • GNU GPL
    • window.onload
    • .replace
  • Although it seemed like the infection is only with JavaScript and index documents, I refused to accept that. Also, as we didn't have any gigantic files with our website, I decided the script to test all files throughout the site.
Although it was such an easy task to write a script for malware removal, I had to separate the program into two scripts because find -exec does not recognize functions in bash. So, here's what I wrote:

sitefix.sh
#!/bin/bash
# Author: Sameera Shaakunthala

rm fixlog.txt
rootdir=`pwd`/mysite/
sup=`pwd`"/fixfile.sh"
find $rootdir -exec $sup {} \;
echo "JOB DONE!"

fixfile.sh
#!/bin/bash
# Author: Sameera Shaakunthala

echo "Processing file: "$1
code=`tail --lines=1 $1 | grep "GNU GPL" | grep window.onload | grep .replace`
l=`echo $code | wc -m | awk '{ print $1 }'`

if [ $l -ne 1 ]
then
 lc=`wc -l $1 | awk '{ print $1 }'`
 lc=`expr $lc - 1`
 head $1 -n $lc > tempfile.tmp
 mv tempfile.tmp $1
 echo "File "$1" has been fixed!" | tee -a fixlog.txt
fi

Now, the next task is the test run on my local machine. If this succeeds, it is safe to run the script on the server.

$ chmod +x sitefix.sh fixfile.sh
$ ./sitefix.sh

After execution, I checked the fixlog.txt, which is the output log of the script. OMG! 602 infected files!! :-O I vigorously checked some randomly selected files, they were clean, and as everything seemed to be clean, I uploaded the script to the server, and then executed. :)

$ scp sitefix.sh fixfile.sh user@mysite.com:/home/user
$ ssh user@mysite.com
$ chmod +x sitefix.sh fixfile.sh
$ ./sitefix.sh

Finally, we have set this as a cron job, till we find the actual security hole.

The final result was, the disinfection of the entire website, within few minutes. As I got to know that virus scanners no longer block our website, it was confirmed that the site is clean. Just see the spirit of Linux bash scripting! :)

Hallelujah!

Finally, I put a link to a shocking article that must be read... Just click and see! :(

Finally, captain Shaakunthala saved the day, with the support of other captains and sailors, yeah it's an amazing Christmas gift for a newbie administrator! :D

A Childish Attempt Made to Hijack my Gmail Account


Today, I've received an email from Google (accounts-noreply@google.com) subjecting Google Password Assistance. Google sends this email when somebody has made an attempt to reset the particular Gmail account's password. But, this request is not initiated by me.

Google password reset process works as follows:
  1. User enters the Gmail address into the password reset form.
  2. Using CAPTCHA, Google verifies that the request is not made by truly a human.
  3. Google uses either of the following methods to verify the account ownership.
  • If the Gmail account was inactive during the past 24 hours, Gmail asks for the security question which the account owner has provided during sign up.
  • If the Gmail account was not inactive, it sends an email to the secondary address that is provided during sign up.
  1. After the verification of account ownership, it enables the user to choose a new password.
In my case, somebody has made the attempt, and Google has sent me the password reset email. Well, I have reset my password -- I periodically do so. :) So thanks to the poor guy who made the attempt. :P

Anyway, how do we prevent such vulnerabilities? Here's what I think:
  • Use at least two email accounts. Use each other to receive password reset emails. Eg: set your Yahoo! address as your Google account's secondary address and set your Gmail address as your Yahoo! account's secondary address.
  • Try to access those accounts frequently.
  • Use ambiguous Q/A pair as the security question and answer. Use your own tunes with creativity. I know, this can go INSANE!!! Eg: Q - Where did you spend your honeymoon? A - Cloud #9

OK. Anything else does not come to my mind this time. May be later I might add more. By the way,....... who might want to hijack my Gmail account? I still don't have an answer. :-?




Well, there might be several bloggers who want to do this adventure. :D

Thank for reading!

Disk Maintenance with Ubuntu Live


Well, I thought of writing about some disk management which you can do with just using an Ubuntu Live CD.

First thing is, we don't need the GUI. Forget it. The text mode works considerably faster. After loading the initial screen of the Ubuntu Live CD, select the language, then press F6. You get a line that can be edited, and ends with the following parameters:

initrd=/casper/initrd.gz quiet splash --

Replace quiet splash with this:

ro single

And press Enter. Now the system boots into the single user mode. In other words, you are taken into the text mode. In later versions of Ubuntu, you get a menu. Just select root and you'll become root user! You can backup your disks, partition disks, file system check and many more!

Partitioning disks:
Just use either parted or fdisk. Personally I would prefer fdisk.
# fdisk -l (to list all filesystems)
# fdisk /dev/sda (to partition the first disk which is SCSI)
# parted /dev/sda (to partition the first disk which is SCSI)

Dont panic! Help is provided inside these commands. You just need to know plain English and the way that a partition table is structured (theory). :)

Format disks:
# mke2fs /dev/sda1 (format the partition as ext-2)
# mke2fs -j /dev/sda1 (format the partition as ext-3)
# mkntfs /dev/sda1 (format the partition as ntfs)
# mkdosfs /dev/sda1 (format the partition as FAT12/ FAT16 or FAT32)
# mkswap (format as swap)

Filesystem check:
# fsck /dev/sda1 (check and repair Linux filesystem on the drive, the partition should be unmounted first!!!)
# dosfsck /dev/sda1 (check FAT12/16/32 filesystem)

Tune Filesystem:
# tune2fs /dev/sda1 (tune adjustable parameters on a Linux filesystem)
Linux filesystems are periodically checked for  consistency during boot. You can adjust that time period with this tool.
# tune2fs -c 60 /dev/sda1 (set fsck to be executed on /dev/sda1 once a two months)

Backup your data into another drive:
Just execute the following commands one by one. Please refer this thread for a broader discussion.
# mkdir /source
# mount /dev/sda1 /source; mount /dev/sdb1 /mnt
# cd /mnt
# tar cvpzf backup.tgz --exclude=/source/lost+found --exclude=/mnt /source

To restore later (assume the backup archive is located at /dev/sdb1),
# mkdir /mnt/backup /mnt/restore
# mount /dev/sda1 /mnt/restore; mount /dev/sdb1 /mnt/backup
# cd /backup
# tar xvpfz backup.tgz -C /restore

Repair GRUB bootloader:
I got to know about this from here. Not everybody can access that site, so I'll put the whole thing here. Enter the following commands one by one.
# grub
/find/grub/stage1 (find the corresponding values for x and y for the next step)
root(hdx,y)
setup(hdx)

Execute binaries on an existing Linux installation:
# mount /dev/sda1 /mnt; chroot /mnt
You can change the root password too!!! :-O

Wanna see how NTFS is supported on Ubuntu?
Just type ntfs at the root shell prompt and press the Tab twice. I'm not gonna put it here.

If you think I might have forgotten anything to put here, don't hesitate to share it here... Thanks for reading!

A Hackers' Session -- from a Campus Kuppi

"Machan, I need some help"

"Yh, what sort of?"

"A Kuppi. Can you prove how SSL is gonna be secure?"

I explaind him the theories of public key cryptography and he had nicely understood them. At the end of the day we both are happy :) . Now, it's time to play with some tools.

"OK, here's my SLTnet prepaid account which I have been using before getting this mobile broadband package. You can see their web site doesn't support SSL enabled login. I don't use this account anymore."

"Yes machan, what are you gonna do?"

"I'm turning on the network protocol analyzer, and entering shaakunthala as username, 123456 as the password coz I don't remember my password."

"OK, show me how to get the password."

"Viola! Here it is, 123456!!"

"Yes, then you say, it's not possible when SSL is enabled?"

"Not actually, but it is not possible to sniff the passwords using regular methods when using SSL"

"OK, show me practically" "Here's Gmail -- close your eyes ;) I'm entering my real username and R-E-A-L password!"

"Are you crazy!? What if I see your password?"

"You won't. Try it yourself."

My friend, tired spending few minutes struggling with the protocol analyzer logs,..

"OK men.. I give up.. you win... and thank you for your time"

"That's okey dude! :) "

***

* Characters: Me and one of my best friends -- At University of Colombo School of Computing open canteen a.k.a. Bhawana (බවන). ;)

* Kuppi (කුප්පි): A Sinhala word for vial. But, in university students' subculture, a Kuppi is the act of a student helping his own colleague(s)
who haven't been able to understand the lectures completely or partially.

Followers

Subscription Options

 Subscribe in a reader

or

Enter your email address:

and
to inscrease

and make me happy. :)

Other Blogs by the Author

The Author

www.flickr.com
ශාකුන්තල | Shaakunthala's items Go to ශාකුන්තල | Shaakunthala's photostream
free counters
TopOfBlogs
Related Posts with Thumbnails