Author Topic: Technical  (Read 961002 times)

0 Members and 3 Guests are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #1935 on: September 23, 2017, 09:07:21 AM »
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33068
  • malware fighter
Re: Technical
« Reply #1936 on: September 23, 2017, 10:59:49 AM »
Dear Asyn and others that follow this thread,

In the light of the recent attacks against CCleaner with redirection to controlled C2 servers by sophisticated state hackers, known as Group 72, we should also consider the following insights:

The recent actions againgst Asian C2 servers: https://tweakers.net/nieuws/123911/interpol-en-beveiligingsbedrijven-identificeren-8800-c2-servers-in-zuidoost-azie.html  (translate to English using Google translate).

Because of collision issues we can no longer profoundly trust MD5 or SHA1 hashes. NIST recently removed a weakened NSA-algorithm
and NSA has difficulty getting two new weakened  distrusted algoritms approved: http://www.reuters.com/article/us-cyber-standards-insight/distrustful-u-s-allies-force-spy-agency-to-back-down-in-encryption-fight-idUSKCN1BW0GV

But then after the Snowden reports, who can trust a "burglar that sells locks"?

Another issue: Dual EC DRBG is a "cryptographically secure pseudorandom number generator", something that generatess streeams of bits, that are quasi-random, and one cannot tell the difference with real randomness. As such a tool in that is not an encryption algorithm, but it should have a place inside the crytographer's toolchest. Well this one should be quarantained, as it does more wrong than it is worthless as such.

And despite of that RSA Security (the firm by that name*) has Dual EC DRBG installed as per default, while there are much better choices available. Is not that a coincidence? Why anyone should ever now believe NIT  anymore?

Wanna have a go at it: download LCPT_gcc.cc program from directory: wuala.com/FreemoveQuantumExchange/Aspects/Randomness/Theory/Berlekamp-Massey
source code is there as well.

When you start to test files s01.dat and s.02.dat using the LCPT_gcc.cc program, it appears complexity halts at 19937
and does not go further, which is the complexity of a Mersenne-Twister. Whenever using Mersenne
to be found inside mentioned directory generate pseudo-random files and test those you will find the compexity is 4*19937.
This is why per output (of 32bits) 4 bits are being sampled. In the same way one can test the output of the Microsoft PRNG,
see that same dir. One would find similar results.

Now we see why with CCleaner the 32-bit versions were compromised. We know the trick now that the l33t hacker(s) used.

Is it not kind of weird that security organizations and state agents wanna undermine everyone's security with this kind of nonsense/crap?

So you can create backdoors when you alone own the secret key. Sort of similar to a normal public key scheme.

polonus (volunteer website security analyst and website error-hunter).

P.S. It should be a concern that the Microsoft Windows certificate store (you find it inside the registry) identifies certifivcates 'uniquely" on basis of their SHA1 hash - collision can not be avoided under all circumstances. SHA1 is unsafe
« Last Edit: September 23, 2017, 11:43:47 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 45155
  • 61 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Technical
« Reply #1937 on: September 23, 2017, 05:15:27 PM »
Free avast! Security Seminar: http://bit.ly/2N1eaR2  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 10 Pro v20H2 64bit, 24 Gig Ram, 1TB SSD, AvastOmni 20.7.xxx, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #1938 on: September 24, 2017, 11:39:18 AM »
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #1939 on: September 25, 2017, 09:58:23 AM »
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #1940 on: September 25, 2017, 11:41:04 AM »
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33068
  • malware fighter
Re: Technical
« Reply #1941 on: September 25, 2017, 01:00:44 PM »
What a wrong update could have as a result, Dutch posters making posts in Swedish via MS Outlook: https://www.security.nl/posting/531515/Ansikte+id+p%C3%A5+din+smartphone+%C3%A4r+a%3A

Funny if the Microsoft Update Release Management was not that tragically wrong.  :o

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #1942 on: September 26, 2017, 06:55:23 AM »
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #1944 on: September 27, 2017, 08:54:04 AM »
CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management
https://www.usenix.org/system/files/conference/usenixsecurity17/sec17-tang.pdf
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #1945 on: September 28, 2017, 08:30:30 AM »
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #1946 on: September 29, 2017, 09:12:47 AM »
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #1947 on: September 30, 2017, 10:49:48 AM »
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Technical
« Reply #1948 on: October 02, 2017, 09:23:07 AM »
PrivateBin
PrivateBin is a minimalist, open source online pastebin where the server has zero knowledge of pasted data
https://privatebin.info/
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 70067
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Win 8.1 [x64] - Avast PremSec 21.4.2460.B#1 [UI.612] - EEK - Firefox ESR 78.10 [NS/uBO/PB] - TB 78.10
Avast-Tools: Secure Browser 90.0 - Cleanup 21.1 - SecureLine 5.11 - Driver Updater 21.1 - CCleaner 5.78
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0