My employees keep abusing social networks while at work (facebook, whatsapp, youtube). Is there a tool that I can install on all workstations and monitor or possibly block all that activity? Thank you.
🗣zzizourm
The company I work for makes software for employee monitoring/internet filtering that is sold by the license. To avoid potentially breaking rule 5 (" Do not ask for or offer services or products ") I won't mention my company specifically, but a Google search for "employee internet monitoring will give you some results you can look into.
My personal recommendation is to go the monitoring route vs blocking some websites entirely -- a reasonable level of "Cyberloafing" can help employees blow off some steam between tasks and help with their wellbeing/productivity in the long run. Using monitoring instead of filtering can help you keep it at a manageable level and prevent employees from feeling resentful, just make sure they're aware they're being monitored.
👤TransientWonderboy
OpenDNS for direct site blocking or you could look into Application Awareness in a next gen firewall. Basically you set the rules as time of access or if you want to allow just view and not allow them to post.
👤MikePencesBurnerAct
OpenDNS: will block all of that
https://www.opendns.com/
How many employees?
Who does your IT?
👤bbsittrr
🎖@malwr
🗣zzizourm
The company I work for makes software for employee monitoring/internet filtering that is sold by the license. To avoid potentially breaking rule 5 (" Do not ask for or offer services or products ") I won't mention my company specifically, but a Google search for "employee internet monitoring will give you some results you can look into.
My personal recommendation is to go the monitoring route vs blocking some websites entirely -- a reasonable level of "Cyberloafing" can help employees blow off some steam between tasks and help with their wellbeing/productivity in the long run. Using monitoring instead of filtering can help you keep it at a manageable level and prevent employees from feeling resentful, just make sure they're aware they're being monitored.
👤TransientWonderboy
OpenDNS for direct site blocking or you could look into Application Awareness in a next gen firewall. Basically you set the rules as time of access or if you want to allow just view and not allow them to post.
👤MikePencesBurnerAct
OpenDNS: will block all of that
https://www.opendns.com/
How many employees?
Who does your IT?
👤bbsittrr
🎖@malwr
reddit
My employees keep abusing social networks while at work (facebook,...
Posted in r/AskNetsec by u/zzizourm • 1 point and 0 comments
About Jeff Bezos' phone hacking
How a video can be delivered through "an encrypted downloader hosted on WhatsApp’s media server" ?
I read all the report on VICE and I found it very interesting.
I don't understand however how it was possible through whatsapp, sending the video via "an encrypted downloader hosted on WhatsApp’s media server".
I mean, what's the difference to just directly send a video file or via this encrypted downloader ?
This is what VICE writes (and report too):
"They did not find any malicious code embedded in the video file, but discovered that the video was delivered via an encrypted downloader hosted on WhatsApp’s media server."
Thanks for an explanation
🗣AnotherRedditUsr
My guess is that a well resourced attacker purchased a 1 click exploit and used CVE-2019-11932 to get access to Bezo's phone.
👤darknetj
In the PDF below it says the encrypted file was slightly larger than the video itself
https://assets.documentcloud.org/documents/6668313/FTI-Report-into-Jeff-Bezos-Phone-Hack.pdf
"Encrypted" is probably because all WhatsApp communications are encrypted
The video wasn't just a video file but an exploit + a video file (hence the diff in file size).
The "hosted on WhatsApp media server" probably just means that all data sent on WhatsApp goes through their infrastructure.
See "zero click" exploits https://threatpost.com/apple-imessage-remote-attackersread-iphone-messages/146789/ and https://media.ccc.de/v/36c3-10497-messenger\_hacking\_remotely\_compromising\_an\_iphone\_through\_imessage
👤octave1
/u/bnimblebquick has a good explanation, and a good level of salt grains. But, as a further point, the golden rule is “authenticate before you operate”. As a total guess, maybe that didn’t happen here.
It seems like one could assume the internal services of WhatsApp may have been vulnerable to /something/ in the media call - either at the start or end of the upload. This would leave the file benign but could introduce a vector for compromise based on a trust relationship with the client (ie Jeff’s WhatsApp binary).
It’ll be interesting to see if the hacking claim is proven true, and secondarily what the postmortem reveals, if anything.
Lastly, Facebook is a company that actively makes money by harvesting and reselling personal information. They’ve also actively claimed “privacy needs to go away”. (Randi Zuckerberg, Marketing ‘Director’ and coincidentally family member of another infamous Zuckerberg who works at Facebook. Entirely a coincidence, I’m sure.)
This is important as it seems likely the assumptions on their WhatsApp implementation by the public will be wrong. For example, they’ve made a few claims that seem contradictory about how it operates: “it uses the Signal Protocol” vs “We can uniquely identify content to stop spam messages”. All bets are off in terms of attack vectors. There’s no implementation verification, no OSS of their use case, etc. If they’re going to be caught doing something bad, again, it seems likely they’ll simply I’m stop this investigation.
👤i_build_minds
🎖@malwr
How a video can be delivered through "an encrypted downloader hosted on WhatsApp’s media server" ?
I read all the report on VICE and I found it very interesting.
I don't understand however how it was possible through whatsapp, sending the video via "an encrypted downloader hosted on WhatsApp’s media server".
I mean, what's the difference to just directly send a video file or via this encrypted downloader ?
This is what VICE writes (and report too):
"They did not find any malicious code embedded in the video file, but discovered that the video was delivered via an encrypted downloader hosted on WhatsApp’s media server."
Thanks for an explanation
🗣AnotherRedditUsr
My guess is that a well resourced attacker purchased a 1 click exploit and used CVE-2019-11932 to get access to Bezo's phone.
👤darknetj
In the PDF below it says the encrypted file was slightly larger than the video itself
https://assets.documentcloud.org/documents/6668313/FTI-Report-into-Jeff-Bezos-Phone-Hack.pdf
"Encrypted" is probably because all WhatsApp communications are encrypted
The video wasn't just a video file but an exploit + a video file (hence the diff in file size).
The "hosted on WhatsApp media server" probably just means that all data sent on WhatsApp goes through their infrastructure.
See "zero click" exploits https://threatpost.com/apple-imessage-remote-attackersread-iphone-messages/146789/ and https://media.ccc.de/v/36c3-10497-messenger\_hacking\_remotely\_compromising\_an\_iphone\_through\_imessage
👤octave1
/u/bnimblebquick has a good explanation, and a good level of salt grains. But, as a further point, the golden rule is “authenticate before you operate”. As a total guess, maybe that didn’t happen here.
It seems like one could assume the internal services of WhatsApp may have been vulnerable to /something/ in the media call - either at the start or end of the upload. This would leave the file benign but could introduce a vector for compromise based on a trust relationship with the client (ie Jeff’s WhatsApp binary).
It’ll be interesting to see if the hacking claim is proven true, and secondarily what the postmortem reveals, if anything.
Lastly, Facebook is a company that actively makes money by harvesting and reselling personal information. They’ve also actively claimed “privacy needs to go away”. (Randi Zuckerberg, Marketing ‘Director’ and coincidentally family member of another infamous Zuckerberg who works at Facebook. Entirely a coincidence, I’m sure.)
This is important as it seems likely the assumptions on their WhatsApp implementation by the public will be wrong. For example, they’ve made a few claims that seem contradictory about how it operates: “it uses the Signal Protocol” vs “We can uniquely identify content to stop spam messages”. All bets are off in terms of attack vectors. There’s no implementation verification, no OSS of their use case, etc. If they’re going to be caught doing something bad, again, it seems likely they’ll simply I’m stop this investigation.
👤i_build_minds
🎖@malwr
reddit
About Jeff Bezos' phone hacking
How a video can be delivered through "an encrypted downloader hosted on WhatsApp’s media server" ? I read all the report on VICE and I found it...
Working malware samples site
If y'all are interested in downloading some malware samples, I'd recommend some sites. This site may not have all the latest malware, but it works. Y'all can go take a look at it. When yall download the zip file, the password for it is infected
https://www.tutorialjinni.com/
🗣LMJR500Army
Ok thanks
👤1711frgtn
🎖@malwr
If y'all are interested in downloading some malware samples, I'd recommend some sites. This site may not have all the latest malware, but it works. Y'all can go take a look at it. When yall download the zip file, the password for it is infected
https://www.tutorialjinni.com/
🗣LMJR500Army
Ok thanks
👤1711frgtn
🎖@malwr
Tutorial Jinni
Tutorial Jinni | Hub of Tutorials
Huge Collection of free ebooks, java tutorials, php tutorials, database tutorials , ajax tutorials, jquery tutorial, extjs tutorial, video tutorials and seo tutorials with free code samples and now with free tools online
Cisco Warns of Critical Network Security Tool Flaw
https://threatpost.com/cisco-critical-network-security-tool-flaw/152131/
Cisco advisory: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200122-fmc-auth
🗣BorrowedCommonSense
🎖@malwr
https://threatpost.com/cisco-critical-network-security-tool-flaw/152131/
Cisco advisory: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200122-fmc-auth
🗣BorrowedCommonSense
🎖@malwr
Threat Post
Cisco Warns of Critical Network Security Tool Flaw
The critical flaw exists in Cisco's administrative management tool, used with network security solutions like firewalls.
GitHub - reemertastic/infosec-spam-list: List of unwarranted sales email domains you can add to your junk mail filter
🗣Reemertastic
I somehow got signed up for a conference and had my email get put on a list a few years back, so I've been adding domains to my Outlook junk mail list for a while. I figured others probably have the same issue, so I might as well share it. I could unsubscribe from the emails, but I don't want to fall victim to any phishing campaigns (especially when I've used that tactic for some of our phishing campaigns).
👤Reemertastic
🎖@malwr
🗣Reemertastic
I somehow got signed up for a conference and had my email get put on a list a few years back, so I've been adding domains to my Outlook junk mail list for a while. I figured others probably have the same issue, so I might as well share it. I could unsubscribe from the emails, but I don't want to fall victim to any phishing campaigns (especially when I've used that tactic for some of our phishing campaigns).
👤Reemertastic
🎖@malwr
GitHub
reemertastic/infosec-spam-list
Contribute to reemertastic/infosec-spam-list development by creating an account on GitHub.
Malicious redirects hit over 2000 WordPress websites; Routed via Simple Fields, CP Contact Form with PayPal
🗣BhaswatiGuha19
🎖@malwr
🗣BhaswatiGuha19
🎖@malwr
International Business Times
Malicious redirects hit over 2000 WordPress websites; Routed via Simple Fields, CP Contact Form with PayPal
Experts at Sucuri have seen over 2000 new infected sites since they started tracking the WordPress infection
The U.S. Cybersecurity and Infrastructure Security Agency on Wednesday warned that it's seen a surge in targeted attacks using a sophisticated strain of malware called Emotet.
🗣Spectrumsploit
Emotet is a well know plague
👤3mt3toss
Timely, emotet has been around for many years now.
👤easy-to-type
🎖@malwr
🗣Spectrumsploit
Emotet is a well know plague
👤3mt3toss
Timely, emotet has been around for many years now.
👤easy-to-type
🎖@malwr
Bankinfosecurity
Emotet Malware Alert Sounded by US Cybersecurity Agency
Emotet malware alert: The U.S. Cybersecurity and Infrastructure Security Agency says it's been "tracking a spike" in targeted Emotet malware attacks. It
Ticket resellers infected with a credit card skimmer
🗣ThisIsLibra
Great write up! Really informative
👤naraaz
🎖@malwr
🗣ThisIsLibra
Great write up! Really informative
👤naraaz
🎖@malwr
Microsoft has released an open source tool to analyze source code for vulnerabilities in almost any modern language:
https://github.com/Microsoft/ApplicationInspector/wiki
🎖@malwr
https://github.com/Microsoft/ApplicationInspector/wiki
🎖@malwr
GitHub
Home
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a j...
Analyzing Modern Malware
Techniques
Part1: https://0x00sec.org/t/analyzing-modern-malware-techniques-part-1/18663
Part2: https://0x00sec.org/t/analyzing-modern-malware-techniques-part-2/18765
🎖@malwr
Techniques
Part1: https://0x00sec.org/t/analyzing-modern-malware-techniques-part-1/18663
Part2: https://0x00sec.org/t/analyzing-modern-malware-techniques-part-2/18765
🎖@malwr
0x00sec - The Home of the Hacker
Analyzing Modern Malware Techniques - Part 1
Analyzing Modern Malware Techniques Fileless malware - Self Loading Technique Fileless malware is nothing new, but is very much used today. The idea is to load a payload into memory and to leave as much as little evidence as possible on the hard drive of…
Another WordPress site management plugin (wpCentral) is vulnerable to authentication issues.
🗣ded1cated
🎖@malwr
🗣ded1cated
🎖@malwr
WebARX
Multiple Vulnerabilities in WordPress Plugin wpCentral - WebARX
The wpCentral plugin allows you to manage your sites on a single panel to login to any website, install/delete/activate plugins, upload files and more.
Unconfirmed Solarwinds Zero Day
Taken from another group - Thanks to Thomas F.
A security researcher has found a 0-day in N-central. Solarwinds has not replied in the 90 day window and it was released last night on PacketStorm (since removed until a patch is released).
According to the post, this was after the 90 day disclosure window lapsed. Huntressabs has confirmed the vulnerability, which passes default site credentials (domain administrator in most cases) in clear text: https://www.youtube.com/watch?v=YAEqkZSv6XI
There were ready-made tools already posted to Github that allowed anyone to take advantage of the exploit.
Solarwinds says they are working on a fix to be released today.
Immediate mitigation can be achieved by removing the default appliance credentials from each location in N-Central.
🗣RobMSP
It's confirmed - even SW posted on it
https://success.solarwindsmsp.com/forum-post/X0D51T00007EEKLMSA5/
👤madra05
The irony that SW had 90 days to address but didn't. We departed ncentral this summer because they promised improvements to report manager for over two years that never came. Just shows that lack of action in one area is a pretty good sign of a rotted culture.
👤iloveurarse
Ouch
👤SAL10000
🎖@malwr
Taken from another group - Thanks to Thomas F.
A security researcher has found a 0-day in N-central. Solarwinds has not replied in the 90 day window and it was released last night on PacketStorm (since removed until a patch is released).
According to the post, this was after the 90 day disclosure window lapsed. Huntressabs has confirmed the vulnerability, which passes default site credentials (domain administrator in most cases) in clear text: https://www.youtube.com/watch?v=YAEqkZSv6XI
There were ready-made tools already posted to Github that allowed anyone to take advantage of the exploit.
Solarwinds says they are working on a fix to be released today.
Immediate mitigation can be achieved by removing the default appliance credentials from each location in N-Central.
🗣RobMSP
It's confirmed - even SW posted on it
https://success.solarwindsmsp.com/forum-post/X0D51T00007EEKLMSA5/
👤madra05
The irony that SW had 90 days to address but didn't. We departed ncentral this summer because they promised improvements to report manager for over two years that never came. Just shows that lack of action in one area is a pretty good sign of a rotted culture.
👤iloveurarse
Ouch
👤SAL10000
🎖@malwr
The DGA of a Monero Miner Downloader
https://johannesbader.ch/blog/the-dga-of-a-monero-miner-downloader/
🎖@malwr
https://johannesbader.ch/blog/the-dga-of-a-monero-miner-downloader/
🎖@malwr
Johannes Bader's Blog
The DGA of a Monero Miner Downloader
This blog posts deals with a domain generation algorithm (DGA) with exotic top levels like .tickets, .blackfriday or .feedback. Among others, Bert Hubert noticed the DGA domains and posted them on Twitter:
VB2019 paper: Spoofing in the reeds with Rietspoof
https://www.virusbulletin.com/virusbulletin/2020/01/vb2019-paper-spoofing-reeds-rietspoof/
🎖@malwr
https://www.virusbulletin.com/virusbulletin/2020/01/vb2019-paper-spoofing-reeds-rietspoof/
🎖@malwr
Virusbulletin
Virus Bulletin :: VB2019 paper: Spoofing in the reeds with Rietspoof
Rietspoof is a piece of malware that is multi-staged, using different file types throughout its infection chain. It contains several types of stages – both extractors and downloaders; the fourth stage also contains support for remote-control commands. Initially…