Apache Tomcat Patches Important Security Vulnerabilities

The Apache Software Foundation (ASF) has released security updates to address several vulnerabilities in its Tomcat application server, one of which could allow a remote attacker to obtain sensitive information.

Apache Tomcat is an open source web server and servlet system, which uses several Java EE specifications like Java Servlet, JavaServer Pages (JSP), Expression Language, and WebSocket, and provides a "pure Java" HTTP web server environment for Java concept to run in.

Unlike Apache Struts2 vulnerabilities exploited to breach the systems of America credit reporting  agency Equifax late last year, new Apache Tomcat vulnerabilities are less likely to be exploited in the wild.

Apache Tomcat — Information Disclosure Vulnerability

The more critical flaw (CVE-2018-8037) of all in Apache Tomcat is an information disclosure vulnerability caused due to a bug in the tracking of connection closures which can lead to reuse of user sessions in a new connection.

The vulnerability, marked as important, was reported to the Apache Tomcat Security Team by Dmitry Treskunov on 16 June 2018 and made public on 22 July 2018.

The flaw affects Tomcat versions 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31, and it has been fixed in Tomcat 9.0.10 and 8.5.32.

Apache Tomcat — Denial of Service (DoS) Vulnerability

Another important vulnerability, tracked as CVE-2018-1336, in Apache Tomcat resides in the UTF-8 decoder that can lead to a denial-of-service (DoS) condition.

"An improper handling of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service," the Apache Software Foundation says in its advisory.

Apache Tomcat Server Software Updates (Patches)

The vulnerability affects Tomcat versions 7.0.x, 8.0.x, 8.5.x and 9.0.x, and has been addressed in Tomcat versions 9.0.7, 8.5.32, 8.0.52 and 7.0.90.

The Apache Software Foundation also included a security patch in the latest Tomcat versions to address a low severity security constraints bypass bug (CVE-2018-8034), which occurs due to missing of the hostname verification when using TLS with the WebSocket client.

Administrators are strongly recommended to apply the software updates as soon as possible and are advised to allow only trusted users to have network access as well as monitor affected systems.

The Apache Software Foundation says it has not detected any incident of the exploitation of one of these Apache Tomcat vulnerabilities in the wild.

A remote attacker could exploit one of these vulnerabilities to obtain sensitive information.

Source: TheHackerNews

Google launches 'Data Transfer Project' to make it easier to switch services

A lot of new online services are cropping up every day, making our life a lot easier.

But it is always harder for users to switch to another product or service, which they think is better because the process usually involves downloading everything from one service and then re-uploading it all again to another.

Thanks to GDPR—stands for General Data Protection Regulation, a legal regulation by European Union that sets guidelines for the collection and processing of users' personal information by companies—many online services have started providing tools that allow their users to download their data in just one click.

But that doesn't completely simplify and streamline the process of securely transferring your data around services.

To make this easier for users, four big tech companies—Google, Facebook, Microsoft, and Twitter—have teamed up to launch a new open-source, service-to-service data portability platform, called the Data Transfer Project.

For more information head over to the source link TheHackerNews

New Bluetooth Hack Affects Millions of Devices from Major Vendors

Yet another bluetooth hacking technique has been uncovered.

A highly critical cryptographic vulnerability has been found affecting some Bluetooth implementations that could allow an unauthenticated, remote attacker in physical proximity of targeted devices to intercept, monitor or manipulate the traffic they exchange.

The Bluetooth hacking vulnerability, tracked as CVE-2018-5383, affects firmware or operating system software drivers from some major vendors including Apple, Broadcom, Intel, and Qualcomm, while the implication of the bug on Google, Android and Linux are still unknown.

The security vulnerability is related to two Bluetooth features—Bluetooth low energy (LE) implementations of Secure Connections Pairing in operating system software, and BR/EDR implementations of Secure Simple Pairing in device firmware.

How the Bluetooth Hack Works?

Researchers from the Israel Institute of Technology discovered that the Bluetooth specification recommends, but does not mandate devices supporting the two features to validate the public encryption key received over-the-air during secure pairing.

Since this specification is optional, some vendors' Bluetooth products supporting the two features do not sufficiently validate elliptic curve parameters used to generate public keys during the Diffie-Hellman key exchange.

In this case, an unauthenticated, remote attacker within the range of targeted devices during the pairing process can launch a man-in-the-middle attack to obtain the cryptographic key used by the device, allowing them to potentially snoop on supposedly encrypted device communication to steal data going over-the-air, and inject malware.

Here's what the Bluetooth Special Interest Group (SIG), the maintainers of the technology, says  about the flaw:

"For an attack to be successful, an attacking device would need to be within wireless range of two vulnerable Bluetooth devices that were going through a pairing procedure."
"The attacking device would need to intercept the public key exchange by blocking each transmission, sending an acknowledgment to the sending device, and then injecting the malicious packet to the receiving device within a narrow time window. If only one device had the vulnerability, the attack would not be successful."

On Monday, CERT/CC also released a security advisory, which includes additional technical details about the Bluetooth vulnerability and attack method.

According to the CERT/CC, Bluetooth makes use of a device pairing mechanism based on elliptic-curve Diffie-Hellman (ECDH) key exchange to allow encrypted communication between devices.

The ECDH key exchange involves a private and a public key, and the public keys are exchanged to produce a shared pairing key.

The devices must also agree on the elliptic curve parameters being used, but in some implementations, these parameters are not sufficiently validated, allowing remote attackers within wireless range "to inject an invalid public key to determine the session key with high probability."

Stop Bluetooth Hacking—Install Patches from Vendors

To fix the issue, the Bluetooth SIG has now updated the Bluetooth specification to require products to validate public keys received as part of public key-based security procedures.

Moreover, the organization has also added testing for this vulnerability within its Bluetooth Qualification Process.

The CERT/CC says patches are needed both in firmware or operating system software drivers, which should be obtained from vendors and developers of the affected products, and installed—if at all possible.

Apple, Broadcom, Intel, and Qualcomm Found Affected

So far, Apple, Broadcom, Intel, and Qualcomm have been found including affected Bluetooth chipsets in their devices, while Google, Android, and Linux have yet to confirm the existence of the vulnerability in their respective products. Microsoft products are not vulnerable.

Apple and Intel have already released patches for this security vulnerability. Apple fixed the bug with the release of macOS High Sierra 10.13.5, iOS 11.4, watchOS 4.3.1, and tvOS 11.4.

Intel released both software and firmware updates to patch the Bluetooth bug on Monday, informing users that the high severity flaw impacts the company's Dual Band Wireless-AC, Tri-Band Wireless-AC, and Wireless-AC product families.

According to Broadcom, some of its products supporting Bluetooth 2.1 or newer technology may be affected by the reported issue, but the chip maker claims to have already made fixes available to its OEM customers, who are now responsible for providing them to the end-users.

Qualcomm has not released any statement regarding the vulnerability.

The Bluetooth SIG says that there is no evidence of the bug being exploited maliciously and that it is not aware of "any devices implementing the attack having been developed, including by the researchers who identified the vulnerability."

Have something to say about this article? Comment below!

Source: TheHackerNews

Ecuador to Withdraw Asylum for Wikileaks Founder Julian Assange

After protecting WikiLeaks founder Julian Assange for almost six years, Ecuador is now planning to withdraw its political asylum, probably next week, and eject him from its London embassy—eventually would turn him over to the British authorities.

LenĂ­n Moreno, the newly-elected President of Ecuador, has arrived in London this Friday to give a speech at Global Disability Summit on 24 July 2018.

However, media reports suggest the actual purpose of the President's visit is to finalize a deal with UK government to withdraw its asylum protection of Assange.

According to RT editor-in-chief Margarita Simonyan and the Intercept's Glenn Greenwald, multiple sources close to the Ecuadorian Foreign Ministry and the President’s office have confirmed that Julian Assange will be handed over to Britain in the coming weeks or even days.

Julian Assange, 47, has been living in Ecuador's London embassy since June 2012, when he was granted asylum by the Ecuador government after a British court ordered his extradition to Sweden to face questioning sexual assault and rape.

Although Sweden dropped its preliminary investigation into the rape accusation against Julian Assange just last year, Assange chose not to leave the embassy due to fears that he would eventually be extradited to the US, where he is facing federal charges for his role in publishing classified information leaked by Chelsea Manning in 2010.

Founder of the whistleblowing website WikiLeaks, Julian Assange, has not been online since last three months after Ecuador cut his communications with the outside world from its London embassy.

The Ecuadorian government took this decision in order to save its good relation with Spain after Assange tweeted in support of Catalan independence movement and blasted the Spanish government over alleged human rights violations.

According to Ecuador, Assange had breached an agreement to refrain from interfering in other states' affairs.

"Sources close to Assange said he himself was not aware of the talks but believed that America was putting 'significant pressure' on Ecuador, including threatening to block a loan from the International Monetary Fund (IMF) if he continues to stay at the embassy," RT said.

Assange is currently facing an arrest warrant from the British government for a minor charge of "failure to surrender," which carries a prison term of three months and a fine.

Now, what will be the future of Assange?

Source: TheHackerNews

Qualcomm unveils 5G antennas for the X50 modem: up to four in a phone with MIMO

The Qualcomm X50 modem promises stunning speeds of 5Gbps, but it will need the right antennas to get there. The company just unveiled its first antennas for millimeter wave and for sub-6GHz communication.

What’s the difference? Millimeter wave operates at very high frequencies – the QTM052 antenna works above 26GHz and even in the 37-40GHz range and it can receive up to 800MHz of bandwidth. That’s how you get to 5Gbps transfer speeds.

The antenna itself is tiny and it needs to be. Qualcomm envisions up to 4 of them inside smartphones. Together with the X50 modem, they support beam forming, beam steering and beam tracking technologies that are necessary to get a stable connection at a decent range.

But these high-gigahertz connections are high-bandwidth, low-range – good for densely populated cities (or even indoor use), but not outside them. This is where the sub-6GHz tech comes in.

The QPM56xx family is also designed to work with the XZ50. They will work in several bands from 3.3GHz to 5.0GHz and support MIMO for improved reception.

Qualcomm is offering these antennas to phone makers for testing, so 5G handsets are getting closer to reality (but we still won't see them this year).


Source: GSMarena

5G Technology- How 5G makes use of millimeter waves

It took a while, but the first ever 5G spec was finally approved late last year. 5G NR, as it's called, will bring about super fast mobile internet by tapping into new spectrum. We're expecting to see the first 5G-ready phones in the first half of 2019, although most people likely won't experience the full benefits of the new technology until about a year later. Still, 5G NR promises to dramatically improve cellular internet speeds and enable experiences like always connected laptops or livestreaming from VR headsets. The entire mobile industry is excited as hell for it, so here's a little guide to help you make sense of the hype.

5G refers to the fifth generation of mobile networking standards determined by the 3GPP, the organization that sets the guidelines for every company operating in cellular communications. The official name, 5G NR, stands for New Radio, and doesn't really mean anything. It'll be used the way "LTE" is today, to differentiate it from previous versions.

Where 3G brought the internet everywhere and 4G LTE made it faster, 5G NR is meant to vastly boost both the capacity and speed of networks, bringing you your high-res cat videos and 4K VR livestreams without delay.

One of the ways 5G will enable this is by tapping into new, unused bands at the top of the radio spectrum. These high bands are known as millimeter waves (mmwaves), and have been recently been opened up by regulators for licensing. They've largely been untouched by the public, since the equipment required to use them effectively has typically been expensive and inaccessible.

But technology has improved to the point where the industry collectively believes we can start tapping them for consumer electronics. And since they haven't been used for much, compared to lower bands, they're far less congested and can therefore enable super fast transfers. Qualcomm said you can expect "typical speeds" of 1.4 Gbps -- that's twenty times faster than the average US home broadband connection. At peak rates, think 5 Gbps, it's enough to stream more than 50 4K movies from Netflix at the same time.

Millimeter waves tend to be susceptible to interference and generally need to maintain line-of-sight for transmission to work. At the most basic level, mmwave transmissions usually go in a straight line between point A and point B. But something as simple as a person walking in between the receiver and transmitter can block the signal altogether.

So companies have to figure out how to make sure the signal gets from base stations to mobile devices, and with 5G NR, part of the solution are two processes called beamforming and beamtracking.

In the most simple scenario for beamforming, where the biggest challenge is that the receiver isn't facing the transmitter, the solution is as simple as bouncing the beam off a surface at a precise angle. The receiving device uses beam tracking to determine which signal is the strongest and picks it up.

That sounds straightforward, until you consider the challenges when implementing this in the real world -- like in an office building. Even when you have base stations set up on your floor, there are many variables to consider. For instance, metals bounce beams, while concrete absorbs them. So if you're inside a conference room, a base station from outside could potentially shoot a beam in through a hollow wall, hit a metal lamp and bounce off to your phone. To get this to work reliably enough for public use, there have to be a ton of beams for your phone to track.

Not only that, your phone's antenna array has to be built in a way that your hand doesn't completely cover up the receiver at any time. Qualcomm's solution is to stash tiny antenna arrays in various corners of your phone, and is working with many major smartphone brands on where to place them.

If you're not convinced that mmwaves will be stable enough when 5G first rolls out, don't fret. Just as your phone falls back to 3G when LTE isn't available, 4G will stick around to make sure you remain connected to the internet even if you're not using mmwaves. Most people won't have access to 5G immediately anyway -- the rollout is likely to begin in cities and spread out to rural areas, and you may need an expensive, high-end device to tap the new technology at first. Later versions of 5G will also allow things like IoT devices to connect to mmwaves, as well as allow for use of unlicensed spectrum to increase speeds some more. But eventually, it should become as prevalent as 4G is today. When that happens, what a world it will be.


Source: Engadget

Why buying an iPhone X knockoff can be a security nightmare

A couple of years ago, a friend of mine travelling through China sent me an email and asked if I’d be interested in a knockoff iPhone 5. “How much is it?” I asked. “About $50,” my friend answered. I decided to pass. Though I was intrigued about what it was like to use a mythical iPhone knockoff, $50 seemed a little steep to satiate what was nothing more than mild curiosity.

My friend ended up picking up an iPhone knockoff for himself, and when I used it briefly, it was entertaining though clearly not a bonafide Apple product from both a hardware and software perspective. Years later, iPhone knockoffs have gotten markedly better at mimicking iOS. More worrisome, though, is that some iPhone knockoffs can be downright dangerous. While a cheap iPhone knockoff can be fun to play around with for a few mins, Jason Koebler of Motherboard recently discovered that such knockoffs can be brimming with malware.

After a colleague of Koebler’s picked up an alleged iPhone X for $100, Koebler was immediately struck by how sophisticated the software looked. While a deeper dive revealed some glaring holes and obvious references to Android, the device at first glance was rather remarkable. It even boasts a working Lightning port! As far as impostor devices are concerned, this one certainly seems top-notch.

So what’s the problem here? Why not have a little bit of fun with an Android posing an iPhone? Well, Koebler eventually sent the device to security researcher Chris Evans who quickly discovered that the device was nothing short of a security nightmare, complete with backdoors and apps designed to spy on user behavior and run code remotely.

“If it isn’t outright malicious its overall security is pretty much non-existent,” Evans told us.

…

Several of the stock fake Apple apps such as Compass, Stocks, Clock ask for “invasive permissions,” such as reading text messages. It’s unclear if this is a sign that the developers were mediocre or malicious, Evans wrote.

“The mismash of default apps preinstalled on the phone I was given are horribly insecure (if not outright malware),” Evans said.

Put simply, if you’re ever inclined to pick up a knockoff iPhone just for kicks, you’d be well advised to err on the side of caution. And if you simply can’t help yourself, the last thing you want to do is actually enter in any of your credentials for services like email and iCloud.

Intel Tiger Lake CPUs to come with Anti-Malware Protection

Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...