Saturday, February 2, 2013

Ars Technica's Useful Article:
The Basics On Malware

--

February 1, 2013, Jon Bordkin of Ars Technica posted a useful article about malware, well worth reading. It is entitled:

Viruses, Trojans, and worms, oh my: The basics on malware
Mobile malware may be trendy, but PC malware is still the big problem.

Here are my notes relating to the article:


A) Backups: Note how the #1 Rule of Computing: Make-A-Backup, saves your hide in nearly all cases of malware infection. That's why I also call it The #1 Rule Of Computer Security. I especially enjoy the ability to access a backup in the case of ransomware. Some malware rat is holding your computer hostage! And you don't care! You've got backups.


B) Multi-Malware: Note how viruses (as a form of malware) are essentially defunct in our modern era. They're old sentimental tech. Instead, everything else is being used in a variety of mix-and-match combinations. It is increasingly harder to define malware as just one form or another.


C) Social Engineering: Note how Social Engineering is being tied into just about all malware infection strategies. This is because the single least secure part of ANY system involving humans is: Humans. It's The LUSER Factor upon which the malware rats are depending. You get fooled, the rats PWN you. Therefore, software solutions are no longer enough. These days, training computer users is MORE important. That's one reason I write this blog.


D) ECMAScript: I take exception with the chart that lists "HTML/JavaScript". The conclusions of the chart are correct, except this specific malware vector is mislabeled.
  1. There is no such thing as HTML malware. HTML is entirely benign and hopefully will stay that way. It's the other code embedded inside the HTML that's dangerous, NOT the HTML.
  2. 'JavaScript' is a quaint misnomer these days. It is now adequately referred to only as ECMAScript. Actual JavaScript, that inanely named web scripting language created by Netscape, is only one part of ECMAScript. The two other major components are ActionScript, perpetrated by Macromedia (now Adobe), and JScript, perpetrated by Microsoft. ECMAScript is continuing to expand and include other forms of Internet scripting as well. The term 'JavaScript' isn't disappearing. But keep in mind that it is an outdated and inadequate term that actually refers to ECMAScript.
Therefore, the chart term "HTML/JavaScript" actually refers to ECMAScript.


E) Malware Rats: Replace the phrase "cat-and-mouse game" with "cat-and-rat game". Mice are too cute to refer to malware perpetrators.
;-)


F) FUD Alert! Replace the ignorant phrase "Apple's Mac computers, long seen as safe havens because of their low market share..." with "Apple's Mac computers, long seen as safe havens because of their superior UNIX OS security...". That's the fact of the matter.

Jon Bordkin is sadly only reciting disproven mythological FUD. I have personally disproved 'Security Through Obscurity' FUD, as applied to Macs, on several occasions. You'll find I did so years back on this blog. You won't ever find anyone proving the Mac STS FUD to have any basis in fact because there aren't any supporting facts. Instead, you will find that all BSD based UNIX OSes are consistently found to be the most secure operating systems available, as determined by both reputation and testing. That includes OS X, which is certified UNIX.

If anyone would like me to rip the ignorant 'Security Through Obscurity' bullshit to shreds again with contemporary data, just let me know. I'll even let you provide the data, as long as its factual and current. That's a dare. (^_^)


G) Bad Code: My personal phrase about modern software development is: Modern code development is well beyond the comprehension of any one human being. This unfortunate fact is proven every day.

One fun ramification of this problem is that if we ever do create an actual 'Artificial Intelligence' (AI) system, we can be certain that it will be severely deranged. IOW: SkyNet would be buggy-as-hell and extremely self-destructive. Whether SkyNet would be capable of cleaning up its own coding bugs is another matter. ;-)


H) Rootkits: OS X hasn't had any rootkits worth noting. However, there IS anti-rootkit software available for OS X, if you're interested! Rootkits may well be worth our attention in time. Here is where you can read about and download the latest version of RootKit Hunter:

http://rkhunter.sourceforge.net

If rootkits become of concern to Mac users, expect me to provide articles about how to install, use and interpret RootKit Hunter. For now, my writing about rootkits would only add unnecessary concern and confusion.

~~~~~~~~~~~~~

Also of interest:

Andrew Cunningham at Ars Technica has written an earlier companion article, also worth reading. It is entitled:

Keep it secret, keep it safe: A beginner's guide to Web safety
Understanding encryption is key to protecting yourself on the Web.

If readers are interested in me writing about encryption software for Macs, please let me know.

:-Derek



Apple Releases Java 6u39
for OS X 10.6 Snow Leopard

--
Today Apple released their Java update for users of OS X 10.6 Snow Leopard. It is listed as 'Java for Mac OS X 10.6 Update 12'. The version of Java provided is 6u39, AKA Java 1.6 Update 39.

Apple's Java update is available via Software Update from within OS X 10.6.

For the moment, you can also download 10.6 Update 12 at the link below. HOWEVER, please note that ALL the information on the page is WRONG and out-of-date. (0_o) Hopefully this will be corrected by the time you visit the page. For now, only use the page for the download link! Ignore everything else and just click the 'download' button:

http://support.apple.com/kb/DL1573

At this time, there is no security information available about this update at Apple's website. Apple has so far failed to update their 'Apple security updates' page with this update. (0_o) Hopefully they will have caught up with themselves by the time you visit their security page:

http://support.apple.com/kb/HT1222

Thankfully, Apple has emailed the security details about this update, which I have provided below:
APPLE-SA-2013-02-01-1 Java for Mac OS X v10.6 Update 12
Java for Mac OS X v10.6 Update 12 is now available and addresses thefollowing: 
Java 
Available for:  Mac OS X v10.6.8, Mac OS X Server v10.6.8Impact:  Multiple vulnerabilities in Java 1.6.0_37Description:  Multiple vulnerabilities exist in Java 1.6.0_37, themost serious of which may allow an untrusted Java applet to executearbitrary code outside the Java sandbox. Visiting a web pagecontaining a maliciously crafted untrusted Java applet may lead toarbitrary code execution with the privileges of the current user.These issues are addressed by updating to Java version 1.6.0_39.Further information is available via the Java website at: 
http://www.oracle.com/technetwork/java/javase/releasenotes-136954.html 
CVE-ID 
CVE-2012-3213
CVE-2012-3342
CVE-2013-0351
CVE-2013-0409
CVE-2013-0419
CVE-2013-0423
CVE-2013-0424
CVE-2013-0425
CVE-2013-0426
CVE-2013-0427
CVE-2013-0428
CVE-2013-0429
CVE-2013-0432
CVE-2013-0433
CVE-2013-0434
CVE-2013-0435
CVE-2013-0438
CVE-2013-0440
CVE-2013-0441
CVE-2013-0442
CVE-2013-0443
CVE-2013-0445
CVE-2013-0446
CVE-2013-0450
CVE-2013-1473
CVE-2013-1475
CVE-2013-1476
CVE-2013-1478
CVE-2013-1480
CVE-2013-1481

Java for Mac OS X 10.6 Update 12 may be obtainedfrom the Software Update pane in System Preferences orApple's Software Downloads web site: 
http://www.apple.com/support/downloads/ 
The download file is named: JavaForMacOSX10.6.dmg 
Its SHA-1 digest is: 0c790491ca22ee009086ee1ec1f1b358024dd83e
Information will also be posted to the Apple Security Updatesweb site: 
http://support.apple.com/kb/HT1222 
This message is signed with Apple's Product Security PGP key, and details are available at:
https://www.apple.com/support/security/pgp/

________________________________ 
Security-announce mailing list
(Security-announce@lists.apple.com)
--


Oracle Java 7u13 Released


Oracle has patched a huge slew of security holes in their JRE, releasing Java 7u13 (aka v1.7 Update 13). A total of 50 CVE security holes have been patched.

You can download the latest Oracle release of Java for Mac here:

http://www.java.com/en/download/mac_download.jsp

You can read about the security patches in 7u13 and related information here:

http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

Be sure to use Oracle's web page, linked above, for downloading Java. Today I ran into a Mac software download site that was linking to Java 7u11, NOT 7u13, a deadly error. (Ahem CNET!).

The 'user' and 'system' checkboxes inside Oracle's Java 'Control Panel' still don't work! You still can't turn off Java except in your web browsers. This is IDIOTIC. I continue to hate you Oracle, you lazy lousy developers.

If you dare to use Java, at least jam the "Security Level" up to 'Very High' until you're already at a trusted website that requires Java. Lower the security level to whatever works on that page after it is reloaded. Remember to jam the security level back up to 'Very High' again before you leave the page. OR alternatively, turn Java entirely off inside each web browser.

I fully expect Java to demonstrate more dangerous security holes leading to more zero day exploits. The Java sandboxing system is a FAILure, is broken and has NOT been replaced. Java remains the single most DANGEROUS software you can install and run on your Mac if you use the Internet. Please be careful. Please don't be a 'LUSER'.

Java requires two things:

1) A total rewrite of its sandboxing system so that it actually works.

2) The donation of the entire Java project to OPEN SOURCE.

I don't trust Oracle. I suggest you don't trust them either. Open source isn't perfect. But there remain a lot of Java enthusiasts out in the world who would LOVE to rewrite and repair the Java JRE and language into something that once again deserves respect. I don't believe that's ever going to happen in Oracle's hands.

Watch for my upcoming tips on ideal Java 'Control Panel' Advanced settings.

Monday, January 28, 2013

Just Turn Java Off:
'Very High' Security Setting
NOT EFFECTIVE!

--
[Updated 2012-01-29. Thank you to my net pal Al for editing corrections and inspiring me to document the difference between old Mozilla browsers and new.]

Is there a smiley for rolling one's eyes? Maybe this will do: (@_@)

Stupid, lazy, incompetent Oracle:
MAKE JAVA OPEN SOURCE NOW NOW NOW!

The open source community couldn't do any worse than Oracle's worthless support for Java.

Go and read this NOW:

Java’s new “very high” security mode can't protect you from malware

by Dan Goodin - Jan 28 2013, 1:55pm EST
Security researchers have uncovered a newly discovered bug in Oracle's Java framework that allows attackers to bypass important security protections designed to prevent malware attacks. . .
The security bypass was only tested on Windows. But expect it to be fully functional on Mac Java as well.
Oracle representatives didn't immediately respond to an e-mail seeking comment for this post. In addition to shoring up the quality of the Java code base, many security professionals have called on Oracle to communicate more quickly and effectively when it learns of new vulnerabilities in recent versions of its software.
What a concept: Oracle caring and reacting effectively in a timely manner. We can dream.

Just Turn Java Off

That means turn Java OFF, and leave it off, in ALL your web browsers until you have ALREADY loaded a website where you require Java. At that point you can reload the web page for full Java plugin functionality. Then remember to turn Java OFF again BEFORE you leave that website.

Other ways to Just Turn Java Off :

The quick and dirty reversible method is to:

A) Quit all your web browsers.
B) Go here: /Library/Internet Plug-ins/
C) Find 'JavaAppletPlugin.plugin' AND 'JavaEmbeddingPlugin.bundle' (if present).
D) Toss them somewhere else to disable them from loading into your web browsers. This will require an Administrator password. (Be certain you've actually MOVED the plugin files, not simply copied them!) I keep the Java files in a folder inside /Library I have named 'Internet Plug-Ins (Disabled)'. I can move them back into /Library/Internet Plug-ins/ whenever I like in order to restore functionality.
E) At that point you can boot your web browsers and damnable Java can't load, so you're safe.

The PERMANENT method for removing Java (except for Firefox) is to:

Go here and follow Oracle's instructions:

Or, if you would like more complete instructions, there is one added file you can remove at your discretion:

A - D) As above. Except toss the Java files into your Trash and empty it, as found in Oracle's instructions.
E) Go here: /Library/PreferencePanes/
F) Find the alias file labeled 'JavaControlPanel.prefpane' and trash it. It's left over refuse of no worth to anyone.

Stop there. You're done.

Yes, there are other Java files on your Mac, but they are from Apple. Don't touch them. This includes the 'Java' folder inside /Library and the other files aliased from that folder. Apple and other apps use Java within your Mac's operating system. (Java isn't just for the Internet), None of these apps and services are affected by Oracle and their continuing circus of blundering and carelessness. You're safe.

BTW: I still cannot turn Java off via the 'checkbox' provided in Oracle's 'Control Panel' for 7u11. It is permanently ON. I've tested it on 10.7.5, 10.8.2 and the 10.8.3 beta. It's broken under both the 'User' tab and the 'System' tab. Oracle know it. Their workaround for 10.8.2 FAILed for me. Therefore, the only solution is to turn Java off in all your web browsers or simply remove the plugin from your /Library/Internet Plug-ins/ folder and restart your web browsers.

IASSOTS

Stupid, lazy, incompetent Oracle. (0_o)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

ADDENDUM

Firefox and other Mozilla related apps: 

Summary: All of the above instructions still apply, as long as you are using the most current version of Firefox.

However, some people still use older versions of Mozilla apps AND Firefox still links to old, wrong, out-of-date instructions for updating Java. Therefore, I've added this addendum to help prevent confusion:

Old (less secure) versions of Mozilla applications embedded Java plugins within the applications themselves. Updates were required from the SourceForge.net website.

Current and recent versions of Mozilla applications now access the same Java plugin installed into OS X via the Oracle Java installer. IOW: There is no longer any separate version of the Java plugin used by Mozilla apps. 

You can access Mozilla's current Java instructions here:

Remaining Confusion: Unfortunately, if you go into the current version of Firefox (v18.0.1), check the Add-Ons Manager and open the Plugins tab, you'll find WRONG instructions (linked to 'Check to see if your plugins are up to date') for updating the Java Embedding Plugin. Firefox v18.0.1 says it includes Java Embedding Plugin v1.0-JEP-0.9.7.3 while the most recent version at SourceForge is v0.9.7.5. Ignore this. There is no actual way to update to v0.9.7.5 AND it doesn't matter. Instead, follow Mozilla's instructions linked above. That is all.

Just make certain that Firefox's Java Embedding Plugin is 'disabled' in Add-Ons Manager. You can 'enable' it again when you want to use Java on a specific website. Disable it again before you leave that website, the same as usual.




--

iOS 6.1: BIG Security Fixes

--

iOS 6.1 was posted today. It contains BIG security fixes which I consider to be critical. This update is available for iPhone 3GS through iPhone 5; iPod Touch 4 through iPod Touch 5; iPad 2 through iPad 4. (Sorry iPad 1 users!).

If you check out the notes provided in iTunes, you'd never know about any security fixes unless you clicked the link at the end of Apple's brief notes:
For information on the security content of this update, please visit this website:
http://support.apple.com/kb/HT1222
Which then provides a link to here:
About the security content of iOS 6.1 Software Update 
There are, according to my count, 28 security patches. MANY of them are critically dangerous.

Thankfully, Apple provide nice summaries of the CVE issues involved (as opposed to our pals at Oracle regarding Java :-P).

My quick list of problems fixed by iOS 6.1, 
with my comments in [brackets]:

~~~~~~~~~~~

Identity Services: Bypass of certificate authorization of an AppleID.

International Components for Unicode: Malicious website cross-site scripting attack.

Kernel: Faulty kernel memory access.

Security: Interception of user credentials and further information due to bad TURKTRUST issued security certificates. [DC- Oh look, yet-another BAD security certificate authority]

StoreKit: Smart App Banner automatic re-enablement of user disabled JavaScript.

WebKit Memory Corruption: 20 memory corruption flaws allowing unexpected application termination or arbitrary code execution. [DC- IOW, potential PWNing of your WebKit browser]

WebKit Content Pasting Validation: Pasting of content onto malicious websites leading to cross-site scripting attack.

WebKit Frame Elements: A cross-site scripting issue in the handling of frame elements leading to cross-site scripting attack.

WiFi: Temporary disablement of WiFi by a remote attacker on the same WiFi network. Caused by Broadcom's BCM4325 and BCM4329 firmware reading out of bounds when handling 802.11i information elements.

~~~~~~~~~~~

No surprise, the majority of issues involve memory management flaws, the continuing plague of modern programming languages and methods.

I suggest updating ASAP. It's always a good idea to have some free space available on your iOS device, especially when updating iOS.

Today I thankfully have not run into any bogged down access to the update. But my iPod Touch 4 booted five times before the update was complete. There is also a new setup process for iCloud required after the update. All went well.

Oh and BTW: The number of malware affecting iOS remains at zero.
(Unless of course you've cracked your iOS device. Then you're on your own. The number of affecting malware is unknown.)

:-Derek
--

Friday, January 18, 2013

Java Security Tips @ MacFixIt

--
[Updated 2012-01-20]

My Mac security friend Topher Kessler has posted a great article at MacFixIt with some tips about keeping your computer safe from the ongoing Java lunacy.


With the latest security holes coming to light, many are recommending removing Java entirely from your system. If you don't want to go that far, here are some things you can do.
Lately Java has been getting a bit of bad press, thanks to several consecutive security holes that have been exploited by malware developers. One notable occurrence was the Flashback malware threat that affected a number of OS X users, which (though due in part to Apple's negligence about Java upkeep) was rooted in the Java runtime. More recently, Java 7 has seen a new zero-day vulnerability that has been circulating in exploit kits. 
In response to these threats, many in the tech community have recommended that people uninstall Java altogether. However, this can be impractical for some, as many people need Java to run applications, including Web apps and a number of technical and creative development tools. . . .
For Safari users, one of Topher's ideas is superior to simply turning off Java in the Safari Preferences. It's the add-on ClickToPlugin. It allows you to turn on or off any Internet plug-in for Safari:


What is useful about this option is that ClickToPlugin doesn't just shut down Java. Instead, it (usually) provides you the ability to click on Java content in order to allow it to run. I'm finding this method of Java control to be a bit messy. But it's another option if you don't want to have to sit-and-wait for the goofy/buggy Java 'Control Panel' to load so you can change security modes.

NEW: As you'll see in my added comment below (read for details), the ClickToPlugin add-0n for Safari is NOT adequate for blocking Java applets from running in the browser.

Therefore, I cannot recommend bothering with ClickToPlugin for blocking Java. So it's back to the mantra:

Just Turn Java Off


:-Derek
--

Tuesday, January 15, 2013

Red October LUVS Java,
A Match Made In Hell

--

It turns out that the Red October malware racket, started in 2007, has been doing its dirty work thanks to Oracle's crap attention to Java security. I hate you Oracle. I hate you very much.

Unearthed attack site reveals some inner workings of espionage malware.
Attackers behind a massive espionage malware campaign that went undetected for five years relied in part on a vulnerability in the widely deployed Java software framework to ensnare their victims, a security researcher said.
The unknown attackers infected computers operated by the Russian Federation, Iran, the US, and at least 36 other countries. They used highly targeted malware to collect what's believed to be hundreds of terabytes of sensitive data, according to researchers from antivirus provider Kaspersky Lab. The success of the covert operation is largely the result of malware and phishing e-mails that were highly customized for each victim.  
Now, Aviv Raff, CTO of Israel-based Seculert, said he has uncovered a website used to infect some of the victims of Operation Red October (as the campaign has been dubbed). The website exploited a critical Java vulnerability identified as CVE-2011-3544, allowing the attackers to surreptitiously execute malicious code on visitors' computers. Although Oracle developers patched the bug in October of 2011, the malicious Java archive file was compiled the following February. . . .
CVE-2011-3544 affects Mac OS X 10.6 through 10.7.2.

The best description of CVE-2011-3544 is at SecurityTracker.

SecurityFocus lists the vulnerable operating system versions.


ADVICE:

In general, if you are and administering Macs with potential LUSER Factor problems:

1) Always force your users to have Standard accounts, never Admin accounts.
2) Lock the Java settings to the minimum required to run the Java apps required.
3) Unless you know your users require Java, it's a great idea to simply uninstall Java.
4) Keep your potential LUSER machines up-to-date; No slacking allowed on your part.

Ideally, if you are working with Macs running OS X 10.6 - 10.7.2, uninstall Java in order to remain safe.

In any case, if you're not at a trusted website:


Just Turn Java Off.

--