Tuesday, October 13, 2015

It's Adobe Critical Updates Day!
Flash & AIR have 13 CVE patches,
Acrobat & Reader have 51 patches!!!

--

[URGENT UPDATE: These new, current versions of Adobe Flash and AIR have a zero-day vulnerability out-in-the-wild! DO NOT USE FLASH AT ALL at this point in time! Seriously! I'm going to post an article after this one that provides some information. In the meantime: UNINSTALL FLASH NOW please!

Uninstall instructions from Adobe:

Uninstall Flash Player | Mac OS

Removing Adobe AIR

After uninstalling Flash and AIR, RESTART your running web browsers,

Please do this RIGHT NOW. If you have more than one Mac, be certain to dump Flash and AIR there as well. 

More to follow.]
~ ~ ~ ~ ~

It's the second-Tuesday-of-the-month, which means it's time for a bombardment of Adobe security patches! This month's pile of patches is truly astonishing. Keep in mind that this isn't the only day of the month Adobe provides security updates. This past month, Adobe pushed out two separate groups of security updates.

Here are today's Adobe security bulletins:


Adobe Flash and AIR


Adobe Acrobat and Reader


Here are the linked Adobe updates:


Adobe Flash, Desktop v19.0.0.207

Adobe Flash, Extended Support v18.0.0.252 (Scroll down to 'Flash Player Archives')

Adobe AIR v19.0.0.213


Adobe Acrobat DC and DC Reader 'Continuous' v2015.009.20069

Adobe Acrobat DC and DC Reader 'Classic' v2015.006.30094
Adobe Acrobat and Reader XI Desktop v11.0.13
Adobe Acrobat and Reader X Desktop v10.1.16

CVE Patches:

[I'm not linking the listed CVEs (Common Vulnerabilities and Exposures) this month as the list is massive and I'm rather busy at my end at the moment. The link to look up CVEs is at the right of this page.]


Adobe Flash and AIR
Vulnerability Details

These updates resolve a vulnerability that could be exploited to bypass the same-origin-policy and lead to information disclosure (CVE-2015-7628).

These updates include a defense-in-depth feature in the Flash broker API (CVE-2015-5569).

These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-7629, CVE-2015-7631, CVE-2015-7643, CVE-2015-7644).

These updates resolve a buffer overflow vulnerability that could lead to code execution (CVE-2015-7632).

These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-7625, CVE-2015-7626, CVE-2015-7627, CVE-2015-7630, CVE-2015-7633, CVE-2015-7634).
Adobe Acrobat and Reader
Vulnerability Details

These updates resolve a buffer overflow vulnerability that could lead to information disclosure (CVE-2015-6692).

These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-6689, CVE-2015-6688, CVE-2015-6690, CVE-2015-7615, CVE-2015-7617, CVE-2015-6687, CVE-2015-6684, CVE-2015-6691, CVE-2015-7621, CVE-2015-5586, CVE-2015-6683).

These updates resolve heap buffer overflow vulnerabilities that could lead to code execution (CVE-2015-6696, CVE-2015-6698).

These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-6685, CVE-2015-6693, CVE-2015-6694, CVE-2015-6695, CVE-2015-6686, CVE-2015-7622).

These updates resolve memory leak vulnerabilities (CVE-2015-6699, CVE-2015-6700, CVE-2015-6701, CVE-2015-6702, CVE-2015-6703, CVE-2015-6704, CVE-2015-6697).

These updates resolve security bypass vulnerabilities that could lead to information disclosure (CVE-2015-5583, CVE-2015-6705, CVE-2015-6706, CVE-2015-7624).

These updates resolve various methods to bypass restrictions on Javascript API execution (CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-7614, CVE-2015-7616, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, CVE-2015-7623, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715).
WARNING:

As ever, running software over the Internet can be dangerous. The most dangerous software to use are the Adobe Flash, Adobe Shockwave and Oracle Java browser plug-ins. If you don't need them, either trash them or pull them out of your system and put them intp a 'disabled' folder. You can find all of these plug-ins here:


/Library/Internet Plug-ins/


Adobe Acrobat and Reader can be dangerous if you're using them to read PDF files you've downloaded from the Internet. The safest way to run either of these programs is with 'Enhanced Security' (Security 'Enhanced') turned ON in their preferences. Even then, as noted in the CVE list above, that may not protect you from malicious PDF files.


Also dangerous, for the same reason, are the Adobe PDF Viewer plug-ins for web browsers. As with the other dangerous plug-ins noted above, either trash them or put them into a 'disabled' folder. If you have a specific reason to use the Viewer plug-ins, then you're stuck with them. However, for the vast majority of people there is NO reason to use them. All web browsers have their own built-in PDF viewer functions. You can find the Adobe PDF Viewer plug-ins here:


/Library/Internet Plug-ins/AdobePDFViewer.plugin

/Library/Internet Plug-ins/AdobePDFViewerNPAPI.plugin

~ ~ ~ ~ ~

As usual:

The #1 Rule of Computing and Security is:


MAKE A BACKUP!


Backups allow you to restore your computer back to health if it gets PWNed (zombied/botted) or otherwise compromised on the Internet.


There are many articles on the Internet about computer backup strategies. Here are a three articles and two ebooks specific to Mac backups:


Bulletproof backups: When you absolutely can't lose any data


Apple: Backing up your Mac hard drive


Apple Support Communities: Most commonly used backup methods


Backing Up Your Mac: A Joe On Tech Guide


TAKE CONTROL OF Security for Mac Users


Stay safe out there kids!



--

Wednesday, September 23, 2015

Critical Adobe Flash & AIR Out-Of-Band Updates

--

I watched the update installers appear online...

Adobe Flash v19.0.0.195


Adobe AIR v19.0.0.190


But no Adobe Security Bulletins appeared to determine whether they were security updates or not. Then... POP! Adobe bothered to let us know, a bit LATE. 


23 CVEs have been patched. I've provided CVE links below for those currently listed:

Security updates available for Adobe Flash Player

(and AIR)
September 21, 2015
Vulnerability Details

These updates resolve a type confusion vulnerability that could lead to code execution (CVE-2015-5573).

These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-5570, CVE-2015-5574, CVE-2015-5581, CVE-2015-5584, CVE-2015-6682).

These updates resolve buffer overflow vulnerabilities that could lead to code execution (CVE-2015-6676, CVE-2015-6678).

These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-5575, CVE-2015-5577, CVE-2015-5578, CVE-2015-5580, CVE-2015-5582, CVE-2015-5588, CVE-2015-6677).

These updates include additional validation checks to ensure that Flash Player rejects malicious content from vulnerable JSONP callback APIs  (CVE-2015-5571).

These updates resolve a memory leak vulnerability (CVE-2015-5576). 
These updates include further hardening to a mitigation to defend against vector length corruptions  (CVE-2015-5568).

These updates resolve stack corruption vulnerabilities that could lead to code execution (CVE-2015-5567, CVE-2015-5579).

These updates resolve a stack overflow vulnerability that could lead to code execution (CVE-2015-5587).

These updates resolve a security bypass vulnerability that could lead to information disclosure (CVE-2015-5572).

These updates resolve a vulnerability that could be exploited to bypass the same-origin-policy and lead to information disclosure (CVE-2015-6679).
There aren't any zero-day exploits currently listed. However, when Adobe pushes out a security update that isn't on the second Tuesday of the month, you can count on there being an imminent exploit.

So UPDATE NOW!


As usual, if you don't use Adobe Flash (which is increasingly being replaced with HTML5) then remove the Internet Plugin from your OS X system! Apple has built in a couple methods of protecting users from awful Adobe Flash in Safari. But when surfing the Internet using ANY web browser, be sure to install a Flash blocker add-on/extension into your web browser! There is no WORSE software you can run on the Internet than Flash. It has surpassed awful Oracle Java in danger. You never want Flash automatically running in any web page.


And also as usual: The #1 Rule of both computing and computer security is:



With backups, we can restore our systems back to pre-infection status.





--

Saturday, August 22, 2015

So You Want To Be
An Advanced Mac Security User...

--

As I often point out, we're still in The Dark Age of Computing.

Today's recommended reading

Want security? Next-gen startups show how old practices don't cut it
Stop hackers from walking on the eggshells protecting your datacenter
22 Aug 2015 at 13:30, Trevor Pott @The Register ®
In case you hadn't noticed, IT security sucks. There is a chronic lack of people trained in IT security, people who will listen to IT security, and even a lack of agreement on how best to go about IT security. Fortunately, a new generation of startups are helping to tackle the issues....
[Note: This is a two page article]

As the imperative to create REAL security, with actual surprises versus entirely expected security flaws and hacks (which is actually what we have right now!). It's going to be an actual coding REVOLUTION! But there's an incredible amount of work required.

My attitude is: If you've got the interest, don't pay attention to how foreboding the subject may appear to be. Dive in and learn to swim through it, exercise your brain and climb the learning curve. You have the basic skills for learning and analyzing the information. Get to it! Make yourself an expert. Then share your expertise and help others with their swimming lessons.

No one ever told me I had innate tech skills. I entirely figured it out on my own by deciding I liked it and wanted to learn it. *Ding* I realized I'm great at it! (Except that CLI stuff, which I grudgingly tolerate).

There is nothing male, female or color selective about working with tech, including tech security. It's a human talent and developed skill. If you've got a hint that the talent is yours, jump into it and add your flavor to the mix. For me, its play time! If you're not enjoying it, you're not doing it right. That's why I write and work with tech, offering up what I know for free.

:-Derek

--

Monday, August 17, 2015

The OS X _PAGEZERO Memory Exploit,
A vulnerability in 10.10.5 and 10.9.5

--

Oh surprise. A new bad memory management exploit. Who'd have guessed. /s

In an effort to offer more advanced user Mac security information, I'm posting this article about an article about an article about a discovery for those interested:

My most excellent colleague Topher Kessler published an article today at his most excellent MacIssues website today about a newly discovered exploit of OS X, of both 10.10.5 and 10.9.5 with the latest security update already applied.

New Zero-Day memory injection vulnerability discovered in OS X
August 17, 2015 by Topher Kessler
PCWorld is reporting that a new zero-day vulnerability has been found for OS X, which affects versions of OS X from 10.9.5 through to the recently-released 10.10.5. The problem comes from how NULL pointers in programs are handled, where malicious programs may use a special condition to bypass the default location where NULL code is directed to, and allow the program to bypass OS X’s security. . . .
Italian teen finds two zero-day vulnerabilities in Apple's OS X
Jeremy Kirk, IDG News Service, Aug 17, 2015 6:26 AM ET
An Italian teenager has found two zero-day vulnerabilities in Apple’s OS X operating system that could be used to gain remote access to a computer. 
The finding comes after Apple patched last week a local privilege escalation vulnerability that was used by some miscreants to load questionable programs onto computers. 
Luca Todesco, 18, posted details of the exploit he developed on GitHub. The exploit uses two bugs to cause a memory corruption in OS X’s kernel, he wrote via email. . . .
xnu local privilege escalation via cve-2015-???? & cve-2015-???? for 10.10.5, 0day at the time | poc||gtfo
cve-2015-???? poc ~ os x 10.10.5 kernel local privilege escalation 
vulnerability got burned in 10.11. . . .
If you're interested in this current exploit, be certain to read through all of Topher's article, listed at the top above. He has some extremely relevant advice to follow before playing with Luca Todesco's "Null Guard" patch tool.

NOTE: I've decided to make an effort to bring attention to these advanced-level-user issues because Apple has been sitting on these things for months on end, causing the company to acquire a lazy security reputation. I figure it can't hurt to bring more pressure to bear on Apple to get their, apparently, lazy security fingers busy writing patches. Security is, after all, everyone's most basic need.

ALSO NOTE: As Graham Cluley has recently pointed out, Apple has still not fully patched the Thunderstrike 2 EFI rootkit attack. We know Apple is working on it.

Coming Up: I'll post a spreadsheet of recent Apple CVE patches. It's long. *sigh*

--

Thursday, August 13, 2015

When Apple's AirDrop Lets In The Loonies

--
An Apple AirDrop setting issue has begun causing concern. In this case, a very nice woman received some very obscene pictures of a sexual nature from an abusive FlasherRat within Bluetooth or Wi-Fi range of her iPhone. It's preventable with a setting change.

Read and watch this BBC article for details in order to avoid these offending events on your own iOS devices. I suspect this issue is just breaking the surface. One of the BBC's accompanying videos demonstrates how to change iOS AirDrop settings.

Police investigate 'first cyber-flashing' case
By Sarah Bell
Victoria Derbyshire programme, BBC
Police are investigating a "new" crime of cyber-flashing after a commuter received an indecent image on her phone as she travelled to work. . . .

Supt Gill Murray said this particular crime was new to her force and urged people to report any other incidents. . . .

'Report it'

Ms. Crighton-Smith called the British Transport Police as she said she was worried about the motives of the perpetrator.

"What's the next stage from sending a naked photograph to a stranger, what happens next, was he getting any sort of gratification from it?" . . .

Airdrop is specific to iOS device and Apple Macs. It uses wi-fi and Bluetooth to talk over a short range to other devices, like other iPhones.

Its default setting is for "contacts only", which means only people you know can see you.

But if you want to share your information or your contacts with other people, you may make a change to the settings and change it to "everyone".

"This means that typically in a train carriage, or tube carriage, you can see other devices," commented Ken Munro, a cybersecurity consultant at Pentest Partners.

"That's what's happened in this particular case, someone has enabled everyone and then hasn't then set it back. As a result anyone within wi-fi or Bluetooth range can send something to you that's quite horrible...."
--

Tuesday, August 11, 2015

Happy Second Tuesday!
Adobe Flash v18.0.0.232 &
Adobe AIR 18.0.0.199
Patch 35 CVEs

--

[CVE = Common Vulnerabilities and Exposures]

Another Second Tuesday of the month... Another Adobe Flash and Adobe AIR patch marathon!


This time we're up to Adobe Flash v18.0.0.232 and Adobe AIR v18.0.0.199, patching 35 (thirty-five) CVE security flaws.


Where to download the updates

https://get.adobe.com/flashplayer/

https://get.adobe.com/air/


The new Adobe Flash (and AIR) Security Bulletin

https://helpx.adobe.com/security/products/flash-player/apsb15-19.html

Details from the new Adobe Flash (and AIR) Security Bulletin, with added links to available CVE data!

Vulnerability Details

These updates resolve type confusion vulnerabilities that could lead to code execution (CVE-2015-5128, CVE-2015-5554, CVE-2015-5555, CVE-2015-5558, CVE-2015-5562).

These updates include further hardening to a mitigation introduced in version 18.0.0.209 to defend against vector length corruptions (CVE-2015-5125).

These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-5550, CVE-2015-5551, CVE-2015-3107, CVE-2015-5556, CVE-2015-5130, CVE-2015-5134, CVE-2015-5539, CVE-2015-5540, CVE-2015-5557, CVE-2015-5559, CVE-2015-5127, CVE-2015-5563, CVE-2015-5561, CVE-2015-5124, CVE-2015-5564).

These updates resolve heap buffer overflow vulnerabilities that could lead to code execution (CVE-2015-5129, CVE-2015-5541).

These updates resolve buffer overflow vulnerabilities that could lead to code execution (CVE-2015-5131, CVE-2015-5132, CVE-2015-5133).

These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-5544, CVE-2015-5545, CVE-2015-5546, CVE-2015-5547, CVE-2015-5548, CVE-2015-5549, CVE-2015-5552, CVE-2015-5553).

These updates resolve an integer overflow vulnerability that could lead to code execution (CVE-2015-5560).
(Note: CVEs not linked above did not have available data at Mitre.org at the time of this posting).

No new zero-day Flash/AIR exploits have been reported at this time. However, Adobe considers these updates to be CRITICAL. Therefore, it is advised to update ASAP.




--

Friday, August 7, 2015

CRITICAL Firefox Exploit In The Wild!
Update to v39.0.3, ESR v38.1.1 or
Firefox OS v2.2 NOW
PLUS a list of ongoing Apple security flaws

--

[UPDATE: 2015-08-11. Today Mozilla released Firefox v40.0, available HERE.]

[Firefox ESR is the Extended Support Release version, typically used by large organizations who need its special update features and reliability.]

Uh Oh! Firefox is being exploited in the wild, allowing a malicious/hacked website to abuse JavaScript along side Firefox's PDF viewer to search for and steal files from the user's computer. At the moment, Macs are not yet known to be targets, but are just as vulnerable. You can read about the exploit at Mozilla's website HERE.

Further details about the exploit are available from the Mozilla Security Blog.
The vulnerability comes from the interaction of the mechanism that enforces JavaScript context separation (the “same origin policy”) and Firefox’s PDF Viewer. Mozilla products that don’t contain the PDF Viewer, such as Firefox for Android, are not vulnerable. The vulnerability does not enable the execution of arbitrary code but the exploit was able to inject a JavaScript payload into the local file context. This allowed it to search for and upload potentially sensitive local files.
THEREFORE:

Update to Firefox v39.0.3 (or higher) for regular users. Enterprise Firefox users can update to ESR v38.1.1 (or higher). Firefox OS users can update to v2.2.

~ ~ ~ ~ ~

Meanwhile, in the wings, off stage, coming up: We're waiting for Apple to release fixes for a few more security flaws. 

One of them is also being exploited in the wild as a method of infecting Macs with adware and crapware. It is generically called the DYLD_PRINT_TO_FILE exploit. 

Another pair of security flaws are called 'Thunderstrike' and 'Thunderstrike 2' rootkits. They involve infecting Mac EFI firmware with malware. Apple has been progressively patching these two problems since 10.10.2, but has not yet entirely blocked them.

The last of the currently prominent security flaws allows hacking the Keychain on both OS X and iOS to steal user passwords. This flaw further implicates problems in Apple's app sandbox system and their security vetting of iOS apps for the iOS App Store. Apple has known about this set of flaws since October 2014 and has so far neglected to patch them. 

It is assumed at this time that Apple will patch this group of security flaws in OS X 10.10.5 Yosemite. So keep an eye out for it in the very near future. If you find it annoying and dangerous that Apple has been sitting on these OS X and iOS security flaws for a considerable amount of time, you're not alone!
--