• 0

Security Discussion on Silent Drive-by Malicious Payloads from Hacked servers


Question

First of all, there appears to be a segment of the technology community that does not believe in the existance of Silent Drive-by Malicious Payloads from Hacked servers or else they believe this is not possible with a major server. If you fall into that category, please try to keep this thread read-only.

 

The intended discussion is on how to deal with it, not on whether it exists or not.

 

I am hoping this thread will be a useful repository of information for server operators and for users wishing to protect themselves from this particular attack vector.

 

 

  • I generated a giant load of links while trying to find a particular Google disclosure website - taking a while to organize the info

5 answers to this question

Recommended Posts

  • 0

Public Non-Silent Hacks

 

The thread is on Silent Hacks. The stuff that makes all the news sites that people read is the flashy defacements with political agendas etc. This makes silent attacks fall into the boring category from a news point of view. Here are some examples of public attacks:

 

  • 0

There was a time when sites  like Google and Microsoft provided what the security industry calls Full Disclosure - https://en.wikipedia.org/wiki/Full_disclosure_(computer_security)

 

These days, major sites are a bit more prideful of their reputation and have come up with the non-transparent concept they call Transparency which mainly pokes a stick at the government but to the credit of Google and Microsoft also includes some Malware issues.

 

Google:

 

https://www.google.com/transparencyreport/?hl=en

 

Microsoft:

 

https://www.microsoft.com/about/csr/transparencyhub/

 

Twitter:

 

https://transparency.twitter.com/

 

 

  • 0

MIsc Hacked Website Info:

 

  • 0

Misc Malware Notes:

 

  • GozNym combines Nymaim and Gozi Trojans to hit 24 U.S. and Canadian banks "The new computer Trojan targets 22 websites that belong to banks, credit unions and e-commerce platforms based in the U.S., and two that belong to financial institutions from Canada. Business banking services appear to be a top target for GozNym's creators, according to the IBM researchers. Nymaim is what researchers call a dropper. Its purpose is to download and run other malware programs on infected computers. It is usually distributed through Web-based exploits launched from compromised websites. Nymaim uses detection evasion techniques such as encryption, anti-VM and anti-debugging routines, and control flow obfuscation. In the past, it has primarily been used to install ransomware on computers. This malware is as stealthy and persistent as the Nymaim loader while possessing the Gozi ISFB Trojan’s ability to manipulate Web sessions, resulting in advanced online banking fraud attacks, the IBM X-Force researchers said"
  • 0
This topic is now closed to further replies.
  • Posts

    • But building your own.. what? You can't build anything like the Steam Machine yourself. Even trying to get close costs a good deal more. Even just the CPU cooler in their price comparison is as big as the entire Steam Machine. If you want a regular gaming PC, then by all means, build that. If you want a a small console-like PC for the living room that is good for gaming, I'm not sure what else is a better deal. In the GN review, they only mentioned a small form factor Dell, which is like twice the size and hundreds of dollars more expensive.
    • Those are some popular multiplayer games. But hardly "all". Just those that don't work on Linux currently due to specific anti-cheat implementations. I think it's also fair to point out the literally thousands of games that don't work on the PS5. And it's not locked at 1080p. That's the default, which you can change.
    • Ubuntu Livepatch arrives on Arm64 to eliminate system reboots for kernel updates by Paul Hill Canonical has just announced that its Livepatch service now supports computers with Arm64 processors. For those who are not familiar, Livepatch allows users to apply important kernel updates without any service interruption or rebooting. While home users will benefit from this, it’s even more important for critical machines that absolutely should not be going offline at all. The feature is available as part of Ubuntu Core 26 for Arm64 and Ubuntu Core 20 and onwards for AMD64. According to Canonical, this will improve the security of systems that aren’t security-maintained daily or weekly, and it helps organizations work towards Cyber Resilience Act (CRA) compliance. If you are familiar with Ubuntu, you probably know that most packages can be updated without having to restart the system. There is one big exception to this, and that’s the kernel; it typically requires you to reload the system to boot into the new kernel. With Livepatch, Canonical has done something so that you don’t need to restart to begin using the new kernel. Aside from Ubuntu Core 26, users with Arm64 chips running Ubuntu 26.04 LTS can also use Livepatch. If you want to learn more about Livepatch, check out its product page. There, you can also find a button to join Ubuntu Pro (it’s free for several home devices) so that you can enable Livepatch. By linking your computer to Ubuntu Pro, you will also extend the life of your Ubuntu install from five years to ten years. If you are running Ubuntu, let us know in the comments if you have been looking forward to this feature on your ARM-based computer. If you’ve had a compatible AMD64 machine for a while and never used this feature, let us know why in the comments!
  • Recent Achievements

    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
    • Dedicated
      tuben earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      500
    2. 2
      +Edouard
      207
    3. 3
      PsYcHoKiLLa
      97
    4. 4
      Michael Scrip
      89
    5. 5
      neufuse
      71
  • Tell a friend

    Love Neowin? Tell a friend!