Showing posts with label popular. Show all posts
Showing posts with label popular. Show all posts

Saturday, April 22, 2017

Popular hacking distro BlackArch Linux update released 2017

Popular hacking distro BlackArch Linux update released 2017


Popular Hacking Distro BlackArch Linux 2017-03-01 Released With Nearly 1700 Ethical Hacking Tools And Kernel 4.9.11

Being into cyber security, the one Linux distro developments that we follow regularly is BlackArch Linux. After Kali Linux, BlackArch Linux is undoubtedly one of the best and the most popular distros for ethical hackers, security researchers and penetration testers. The BlackArch Linux devs have now released the new version ISO image of the Arch Linux-based operating system designed especially for hackers and security professionals.
The newly released BlackArch Linux 2017-03-01 update comes with over 1700 ethical hacking and pentesting tools pre-installed. It is based on the Arch Linux 2017-03-01 install medium released earlier, which has dropped support for 32-bit installations.
The BlackArch devs have released the new BlackArch Linux 2017-03-01 version as separate Live ISOs for both 32-bit and 64-bit computers, as well as a 64-bit OVA image that you can use in either the VirtualBox, QEMU, or VMware virtualization software
Among the 1700 hacking tools, the newly released update comes with 50 new penetration testing and hacking tools. In the new release, all system packages have been updated, along with some of the in-house built BlackArch tools and the menu entries for the Openbox, Fluxbox, and Awesome window managers.

Update option for existing BlackArch Linux users

Existing users need only to make sure that they have all the latest updates installed by running the “sudo pacman -Syu” command in a terminal emulator or the virtual console. Once the new kernel version is updated, you’ll need to reboot your PC/laptops.
First time BlackArch Linux users can visit their official website to download the latest version of the distro..

Go to link download

Read more »

Thursday, April 6, 2017

9 Popular Password Manager Apps Found Leaking Your Secrets

9 Popular Password Manager Apps Found Leaking Your Secrets


Is anything safe? Its 2017, and the likely answer is NO.

Making sure your passwords are secure is one of the first line of defense – for your computer, email, and information – against hacking attempts, and Password Managers are the one recommended by many security experts to keep all your passwords secure in one place.

Password Managers are software that creates complex passwords, stores them and organizes all your passwords for your computers, websites, applications and networks, as well as remember them on your behalf.

But what if your Password Managers itself are vulnerable?

Well, its not just an imagination, as a new report has revealed that some of the most popular password managers are affected by critical vulnerabilities that can expose user credentials.


The report, published on Tuesday by a group of security experts from TeamSIK of the Fraunhofer Institute for Secure Information Technology in Germany, revealed that nine of the most popular Android password managers available on Google Play are vulnerable to one or more security vulnerabilities.

Popular Android Password Manager Apps Affected By One Or More Flaws


The team examined LastPass, Keeper, 1Password, My Passwords, Dashlane Password Manager, Informaticores Password Manager, F-Secure KEY, Keepsafe, and Avast Passwords – each of which has between 100,000 and 50 Million installs.
"The overall results were extremely worrying and revealed that password manager applications, despite their claims, do not provide enough protection mechanisms for the stored passwords and credentials," TeamSIK said.
In each application, the researchers discovered one or more security vulnerabilities – a total of 26 issues – all of which were reported to the application makers and were fixed before the groups report went public.

Encryption Keys for Master Key Hard-Coded in the Apps Code 


According to the team, some password manager applications were vulnerable to data residue attacks and clipboard sniffing. Some of the apps stored the master password in plain text or even exposed encryption keys in the code.

For example, one high severity flaw affected Informaticores Password Manager app, which was due to the app storing the master password in an encrypted form with the encryption key hard coded in the apps code itself. A similar bug was also discovered in LastPass.



In fact, in some cases, the users stored passwords could have easily been accessed and exfiltrated by any malicious application installed on the users device.

Besides these issues, the researchers also found that auto-fill functions in most password manager applications could be abused to steal stored secrets through "hidden phishing" attacks.

And whats more worrisome? Any attacker could have easily exploited many of the flaws discovered by the researchers without needing root permissions.

List of Vulnerable Password Managers and Flaws Affecting Them


Heres the list of vulnerabilities disclosed in some of the most popular Android password managers by TeamSIK:

MyPasswords


  • Read Private Data of My Passwords App
  • Master Password Decryption of My Passwords App
  • Free Premium Features Unlock for My Passwords


1Password – Password Manager


  • Subdomain Password Leakage in 1Password Internal Browser
  • HTTPS downgrade to HTTP URL by default in 1Password Internal Browser
  • Titles and URLs Not Encrypted in 1Password Database
  • Read Private Data From App Folder in 1Password Manager
  • Privacy Issue, Information Leaked to Vendor 1Password Manager


LastPass Password Manager


  • Hardcoded Master Key in LastPass Password Manager
  • Privacy, Data leakage in LastPass Browser Search
  • Read Private Data (Stored Master password) from LastPass Password Manager


Informaticore Password Manager


  • Insecure Credential Storage in Microsoft Password Manager


Keeper Password Manager


  • Keeper Password Manager Security Question Bypass
  • Keeper Password Manager Data Injection without Master Password


Dashlane Password Manager


  • Read Private Data From App Folder in Dashlane Password Manager
  • Google Search Information Leakage in Dashlane Password Manager Browser
  • Residue Attack Extracting Master Password From Dashlane Password Manager
  • Subdomain Password Leakage in Internal Dashlane Password Manager Browser


F-Secure KEY Password Manager


  • F-Secure KEY Password Manager Insecure Credential Storage


Hide Pictures Keepsafe Vault


  • Keepsafe Plaintext Password Storage


Avast Passwords


  • App Password Stealing from Avast Password Manager
  • Insecure Default URLs for Popular Sites in Avast Password Manager
  • Broken Secure Communication Implementation in Avast Password Manager
Researcher also going to present their findings at HITB conference next month. For more technical details about each vulnerability, users can head on

Go to link download

Read more »