Warning: The magic method Vc_Manager::__wakeup() must have public visibility in /home/b6gnet/public_html/wp-content/plugins/js_composer/include/classes/core/class-vc-manager.php on line 203

Warning: Cannot modify header information - headers already sent by (output started at /home/b6gnet/public_html/wp-content/plugins/js_composer/include/classes/core/class-vc-manager.php:203) in /home/b6gnet/public_html/wp-includes/feed-rss2.php on line 8
2012 Archives - B6G.NET| for all information technology https://b6g.net/pages/tag/2012/ Information Technology News and businesses, Programmers, Software, and free more related articles Wed, 25 May 2022 18:41:12 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.8 https://b6g.net/wp-content/uploads/2021/06/cropped-black-small-logo-32x32.png 2012 Archives - B6G.NET| for all information technology https://b6g.net/pages/tag/2012/ 32 32 Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys https://b6g.net/pages/6638/popular-pypi-package-ctx-and-php-library-phpass-hijacked-to-steal-aws-keys/ https://b6g.net/pages/6638/popular-pypi-package-ctx-and-php-library-phpass-hijacked-to-steal-aws-keys/#respond Tue, 24 May 2022 15:32:03 +0000 http://tag:blogger.com,1999:blog-4802841478634147276.post-3595930521423670942 Two trojanized Python and PHP packages have been uncovered in what's yet another instance of a software supply chain attack targeting the open source ecosystem.
One of the packages in question is "ctx," a Python module available in the PyPi repository. The other involves "phpass," a PHP package that's been forked on GitHub to hand sth. out a rogue update. "In both cases the attacker appears to have

The post Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys appeared first on B6G.NET| for all information technology.

]]>
 

PyPI Package and PHP Library

Two trojanized Python and PHP packages have been uncovered in what’s yet another instance of a software supply chain attack targeting the open source ecosystem.

One of the packages in question is “ctx,” a Python module available in the PyPi repository. The other involves “phpass,” a PHP package that’s been forked on GitHub to distribute a rogue update.

“In both cases the attacker appears to have taken over packages that have not been updated in a while,” the SANS Internet Storm Center (ISC) said, one of whose volunteer incident handlers, Yee Ching, analyzed the ctx package.

It’s worth noting that ctx was final published to PyPi on December 19, 2014. On the other hand, phpass hasn’t received an update since it was uploaded to Packagist on August 31, 2012.

The malicious Python package, which was pushed to PyPi on May 21, 2022, has been removed from the repository, but the PHP library still continues to be available on GitHub.

CyberSecurity

In both instances, the modifications are designed to exfiltrate AWS credentials to a Heroku URL named ‘anti-theft-web.herokuapp[.]com.’ “It appears that the perpetrator is trying to obtain all the environment variables, encode them in Base64, and forward the data to a web app under the perpetrator’s control,” Ching said.

It’s suspected that the attacker managed to gain unauthorized access to the maintainer’s account to publish the new ctx version. Further investigation has revealed that the threat actor registered the expired domain used by the original maintainer on May 14, 2022.

PyPI Package and PHP Library
Linux diff command executed on original ctx 0.1.2 Package and the “new” ctx 0.1.2 Package

“With control over the original domain name, creating a corresponding email to receive a password reset email would be trivial,” Ching added. “After gaining access to the account, the perpetrator could remove the old package and upload the new backdoored versions.”

Coincidentally, on May 10, 2022, security consultant Lance Vick disclosed how it’s possible to purchase lapsed NPM maintainer email domains and subsequently use them to re-create maintainer emails and seize control of the packages.

PyPI Package and PHP Library

What’s more, a metadata analysis of 1.63 million JavaScript NPM packages conducted by academics from Microsoft and North Carolina State University ultimate year uncovered 2,818 maintainer email addresses associated with expired domains, effectively allowing an attacker to hijack 8,494 packages by taking over the NPM accounts.

“In general, any domain name can be purchased from a domain registrar allowing the purchaser to associate to an email hosting service to get a personal email address,” the researchers said. “An attacker can hijack a user’s domain to take over an account associated with that email address.”

CyberSecurity

Should the domain of a maintainer turn out to be expired, the threat actor can acquire the domain and alter the DNS mail exchange (MX) records to appropriate the maintainer’s email address.

“Looks like the phpass compromise happened because the owner of the package source – ‘hautelook’ deleted his account and then the attacker claimed the username,” researcher Somdev Sangwan said in a series of tweets, detailing what’s called a repository hijacking attack.

Public repositories of open source code such as Maven, NPM, Packages, PyPi, and RubyGems are a critical part of the software supply chain that numerous organizations rely on to develop applications.

On the flip side, this has also made them an attractive target for a variety of adversaries seeking to deliver malware.

This includes typosquatting, dependency confusion, and account takeover attacks, the latter of which could be leveraged to ship fraudulent versions of valid packages, main to widespread supply chain compromises.

“Developers are blindly trusting repositories and installing packages from these sources, assuming they are secure,” DevSecOps firm JFrog said last year, adding how threat actors are using the repositories as a malware distribution vector and launch successful attacks on both developer and CI/CD machines in the pipeline.

 

The post Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys appeared first on B6G.NET| for all information technology.

]]>
https://b6g.net/pages/6638/popular-pypi-package-ctx-and-php-library-phpass-hijacked-to-steal-aws-keys/feed/ 0
Name.com Coupons Code For 27 July 2012 https://b6g.net/pages/382/name-com-coupons-code-for-27-july-2012/ https://b6g.net/pages/382/name-com-coupons-code-for-27-july-2012/#respond Sat, 28 Jul 2012 02:19:26 +0000 http://www.b6g.net/?p=382 Save $1.74 off on COM/NET domain registrations and renewals PELOTON $7.49 .US registrations and 15% off any of our shared hosting plans at Name.com USA $10.25 on COM/NET domain registrations and renewals MAKEITRAIN Get Private Whois protection for Free PRIVACYPLEASE $5.99 on .EU domains eu $8.99 on .BIZ domain registrations + 15% off on shared […]

The post Name.com Coupons Code For 27 July 2012 appeared first on B6G.NET| for all information technology.

]]>
Save $1.74 off on COM/NET domain registrations and renewals
PELOTON

$7.49 .US registrations and 15% off any of our shared hosting plans at Name.com
USA

$10.25 on COM/NET domain registrations and renewals
MAKEITRAIN

Get Private Whois protection for Free
PRIVACYPLEASE

$5.99 on .EU domains

eu

$8.99 on .BIZ domain registrations + 15% off on shared hosting plans
MONEY

The post Name.com Coupons Code For 27 July 2012 appeared first on B6G.NET| for all information technology.

]]>
https://b6g.net/pages/382/name-com-coupons-code-for-27-july-2012/feed/ 0
AVG Anti-Virus Free Edition 2012 https://b6g.net/pages/361/avg-anti-virus-free-edition-2012/ https://b6g.net/pages/361/avg-anti-virus-free-edition-2012/#respond Mon, 25 Jun 2012 21:24:56 +0000 http://www.b6g.net/?p=361 Is AVG Anti-Virus FREE right for you? AVG Internet Security 2012 comes with firewall to block attempts to sabotage your system and identity protection to keep your passwords and credit card numbers safe. Recommended if you bank and/or shop online. You just have this ” Features & Benefits ” Protection against viruses and spyware Download […]

The post AVG Anti-Virus Free Edition 2012 appeared first on B6G.NET| for all information technology.

]]>

Is AVG Anti-Virus FREE right for you?

AVG Internet Security 2012 comes with firewall to block attempts to sabotage your system and identity protection to keep your passwords and credit card numbers safe. Recommended if you bank and/or shop online.

http://files.b6g.net/uploads/13406591401.jpgYou just have this ” Features & Benefits ”

Protection against viruses and spyware

Download

http://files.b6g.net/do.php?id=175

 

The post AVG Anti-Virus Free Edition 2012 appeared first on B6G.NET| for all information technology.

]]>
https://b6g.net/pages/361/avg-anti-virus-free-edition-2012/feed/ 0
Name.com Promo Codes Jun 2012 https://b6g.net/pages/302/name-com-promo-codes-jun-2012/ https://b6g.net/pages/302/name-com-promo-codes-jun-2012/#respond Wed, 13 Jun 2012 01:17:45 +0000 http://www.b6g.net/?p=302 Save $2 off each new domain register WILDTHING 1 domain register 2$ discount , 2 domain register , get 4$ discount exct..Expires june 30 2012 —-0—-0—-0—-0—-0—-0 $7.49 .US registrations and 15% off any of our shared hosting plans at Name.com USA —-0—-0—-0—-0—-0—-0 $9.99 on com/net domain registrations/renewals CYBERSPACE —-0—-0—-0—-0—-0—-0 Get Private Whois protection for Free […]

The post Name.com Promo Codes Jun 2012 appeared first on B6G.NET| for all information technology.

]]>
Save $2 off each new domain register
WILDTHING
1 domain register 2$ discount , 2 domain register , get 4$ discount exct..Expires june 30 2012
—-0—-0—-0—-0—-0—-0
$7.49 .US registrations and 15% off any of our shared hosting plans at Name.com
USA
—-0—-0—-0—-0—-0—-0
$9.99 on com/net domain registrations/renewals
CYBERSPACE
—-0—-0—-0—-0—-0—-0
Get Private Whois protection for Free

PRIVACYPLEASE

The post Name.com Promo Codes Jun 2012 appeared first on B6G.NET| for all information technology.

]]>
https://b6g.net/pages/302/name-com-promo-codes-jun-2012/feed/ 0