‏إظهار الرسائل ذات التسميات acer. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات acer. إظهار كافة الرسائل

الثلاثاء، 21 يونيو 2016

Evilgrade: Updating a backdoor never gets old


In case you haven’t seen past month advisories, there was a release of multiple vulnerabilities on Original Equipment Manufacturers (OEM) regarding the safety of updates mechanisms.


Most of the vulnerabilities described on those advisories were ported as a module to evilgrade, and additional modules for non OEM were also included as well.


This vulnerabilities were made public by coresecurity and duo, affecting the following vendors:
Samsung, Lenovo, Intel, Acer, Dell, Hewlett Packard, Asus.


  • Dell: One high-risk vulnerability involving lack of certificate best practices, known as eDellroot.
  • Hewlett Packard: Two high-risk vulnerabilities that could have resulted in arbitrary code execution on affected systems. In addition, five medium-to-low risk vulnerabilities were also identified.
  • Asus: One high-risk vulnerability that allow for arbitrary code execution as well as one medium severity local privilege escalation.
  • Acer: Two high-risk vulnerabilities that allow for arbitrary code execution.
  • Lenovo: One high-risk vulnerability that allows for arbitrary code execution.


From coresecurity’s advisories:
  • Samsung: Samsung SW Update Tool is prone to a Man in The Middle attack which could result in integrity corruption of the transferred data, information leak and consequently code execution.
  • Lenovo: Lenovo SHAREit for Windows and Android are prone to multiple vulnerabilities which could result in integrity corruption, information leak and security bypasses.
  • Intel: Intel Driver Update Utility is prone to a Man in The Middle attack which could result in integrity corruption of the transferred data, information leak and consequently code execution.


Non-OEM Additional modules:
  • Keepass: Keepass uses in all versions up to the current 2.33, unencrypted HTTP requests to check for new software versions. An attacker can abuse this automatic update check – if enabled – to “release” a new version and redirect the user to a malicious download page.
  • Openbazaar: A man in the middle could intercept the update request and reply with a fake JSON response, forcing the electron updater to download a custom payload and, on platforms where code signing is not enforced by settings, this could lead to a remote code execution.
  • Sparkle: All applications that use the Sparkle Updater framework and are connecting over HTTP instead of a secure HTTPS connection are vulnerable. On a side note, a few years ago we reported a prior vulnerability of Sparkle, for an example application like Adium. Despite the way the updates were handled was modified, AppCast, the RSS feed that hosts information about software updates and more, is prone to MITM attacks, resulting in insertion of modified HTML and JavaScript code into a WebView component, finally displaying it to the user. From there, there are interesting things you can do, and one of them was applied to the new Sparkle module.
  • Timedoctor: The autoupdate implementation in TimeDoctor Pro 1.4.72.3 on Windows relies on unsigned installer files that are retrieved without use of SSL, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.


Evilgrade’s latest release (2.0.8 at this moment) includes all the necessary modules to fulfill the exploitation of the mentioned updaters, including one that according to what we know so far hasn’t been published explicitly yet, neither has a CVE, but was mentioned on a blogpost last year, which exploits a firmware update on Lenovo’s mobile devices.


Moreover, there has been fixes and upgrades to the usage of evilgrade and they will be described briefly below:


  • A bug on the current version of ReadLine::Gnu that was affecting mostly Kali users was fixed on our side.
  • Extended filtering of requests via user agent was added. An example module can be found here. By setting useragent to true, this allows us to trigger an action when the regular expression fields inside of request: req and useragent match the current request. This also grants us the opportunity to filter a request only by the User-Agent header, as seen in sparkle2 module, where req  field accepts all incoming requests “.*” if and only if the useragent matches “Sparkle”.
  • 2 new configuration variables <%URL_FILE%> and <%URL_FILE_EXT%> were added to provide a more realistic approach. An example module can be found here. This variables may be used to handle the victim a file with the same name that was requested, for an example. In the asus module scenario, the updater requests an .ide file, for example MODEL_A123.ide that is not legible, but it also has the possibility to request .idx files which are in plaintext. The variables are used to make the updater believe it is asking for the same file but with a different extension.
  • Optimization on matching requests: When a module answers a request, the lookup on the following modules stops. This enables evilgrade to serve responses much faster, and encourages users to develop modules that match accordingly.

We hope you enjoy it, and let us know if you have any questions or comments.
https://github.com/infobyte/evilgrade

الخميس، 9 يونيو 2016

Acer Receives Seven Red Dot Product Design Awards in 2016

Seven Acer products have received the Red Dot Award:  Product Design 2016, including the ultra-slim Aspire S13 notebook, convertible Aspire R15 notebook with 360-degree versatility, flagship TravelMate P6 series commercial notebooks, modular Revo Build mini PC, compact Veriton N series commercial desktops, curved Acer XR342CK gaming monitor, and full-functioned abTouchPhone touchscreen IP desk phone.


Acer Receives Seven Red Dot Product Design Awards in 2016
Acer wins 7 RedDot Product Design Awards

The winning Acer products were selected among 5,200 entries from 57 countries by an independent panel of 41 experts.  The products were assessed according to criteria such as degree of innovation, formal quality, functionality and ecological compatibility.

Aspire S13 Ultra-Slim Notebook

Acer Aspire S13

The Aspire S13 is a perfectly engineered thin and powerful Windows 10 notebook for design-conscious users.  The angular, sleek chassis houses the best-value-priced laptops on the market today, packed with features for work and play.  There is a sleek chamfer diamond-cut on the edges and the touchpad, with Acer nano-imprint patterning on the top cover and a blend of premium finishes.  The Aspire S13 is powered by 6th Generation Intel Core processors and up to 8 GB of LPDDR3 system memory, not only enabling fast performance and enhanced graphics, but also low power consumption.

Aspire R15 Convertible Notebook

The Aspire R15 features a metal top cover with a hairline-brushed finish, and the bottom cover is made of 40% glass fiber and silver particles, which improves rigidity while maintaining a thin profile. Diamond-cut edges complement the 360-degrees versatility of the Aspire R15, which can lay perfectly flat at 180-degrees, and with Acer’s patented soft-closing hinge design, converting between laptop, tablet, display and tent modes has never been so elegant.

TravelMate P6 Series Commercial Notebooks

Winning the Red Dot Award for the third year in a row, the TravelMate P6 series are Acer’s flagship commercial notebooks designed for professional road warriors.  Built to withstand the rigors of travel, the updated series features an ultra-slim and robust design with carbon and glass fiber-protected lids, spill-resistant keyboards and commercial grade reliability.  Available with 14- and 15-inch screen options, the TravelMate P6 series feature 6th Generation Intel Core processors for speed and performance, the latest 802.11ad gigabit Wi-Fi technology from Qualcomm Atheros, and wired and wireless docking options for ultimate productivity.

Revo Build Mini PC

The Revo Build is a mini PC that is easily customized with blocks that provide different functions such as extra storage, speakers and microphones, or even wireless charging.  The block connects precisely via magnetic pogo pins that make assembling a computer as easy as playing with toy blocks.  The blocks can also work independently or with other PCs.  The Revo Build Mini PC is packaged in a tiny one liter chassis with a 125 x 125mm footprint that takes up minimal space and can be placed almost anywhere.


Veriton N Series Commercial Desktops

The Verizon N Series commercial desktops combine flexibility, security, and manageability in a compact 1-liter form factor.  It is expandable with a modular design with graphics card, optical drive, and I/O expansion options available.  With a rectangular profile and black finish, the Veriton N series conveys a solid and classic image.


Acer XR342CK Gaming Monitor


The Acer XR342CK gaming monitor features a curved 34-inch 21:9 panel with a 1900R curvature and delivers immersive, picture-perfect visuals.  Special features like 6-axis color adjustment and DTS Sound deepen the audio/visual impact, while a customizable ambient light at the lower edge of the monitor provides lighting effects that match the desired mood.  The base can swivel from -30 to +30 degrees, allowing users to easily adjust the monitor to their desired viewing angle.

abTouchPhone Touchscreen IP Desk Phone

The abTouchPhone is a full-functioned, multimedia IP desk phone, supporting Acer’s abPBX communications system.  It features a minimalist sleek metal design with an anti-fingerprint glass touchscreen, and supports both voice and video calls.


The Red Dot Design Award

The Red Dot Award is organized by the Design Zentrum Nordrhein Westfalen in Essen, Germany.  With more than 17,000 entries in 2015 alone, it is one of the largest competitions in the world.  It was in 1955 that a jury convened for the first time to assess the best designs of the day.  The name and brand of the award were developed in the 1990s by Red Dot CEO, Professor Dr. Peter Zec.  Since then, the sought-after “Red Dot” is the revered international seal of outstanding design quality.

For further information, please visit www.red-dot.org.

Like this story? Share it and don't forget to follow us on our social channels: FacebookTwitter InstagramGoogle+YoutubeFlickr

Taiwan Excellence 2016 strengthens brand awareness in the Philippines

The Taiwan government project also known as “Taiwan Excellence” recently held its 3rd year campaign in the Philippines. It was heralded at the Ballroom 2 of Fairmont Hotel in Makati and attended by reputable CEOs, Directors and Board Members both from Taiwan and Philippines. Taiwan continuously reinforces its importance as the Philippines’ trading partner. According to 2015 Philippine Statistics Authority data, Taiwan is the 4th top import country (with 5.2 billion USD imports) and the 9th top export country (with 2.2 billion USD exports) in the world. With this, Taiwan Excellence campaign, which is organized by Bureau of Foreign Trade (BOFT) of Taiwan government and implemented by Taiwan External Trade Development Council (TAITRA), is again rolling out for the third time in the Philippines to further strengthen trading ties between the two countries.

Taiwan Excellence, the symbol of superiority of products from Taiwan, will have more exciting and more comprehensive activities in 2016. Through experiential activities to be staged throughout the year, TAITRA aims to let Filipino consumers experience how they can enhance their lives and create a truly “Excellent Lifestyle.”

Over the years, Taiwan Excellence activities have brought Filipinos closer to Taiwanese products. These innovative and high quality products have seen greater acceptance in the market and have become an integral part of the Filipino lifestyle – from appliances that provide convenience in managing households, gadgets that complement hectic schedules, and equipment that makes committing to a healthy goal easier.

For this year, Taiwan Excellence will introduce its latest product line-up, all of which capture Taiwan brands’ features that have gained global recognition for their distinct quality and sheer excellence. Some brands include ACER, ASUS, MSI and PX for Information and Communications Technology products; Tatung, Sakura, and Caesar for Household Goods; and Johnson, Pacific and KYMCO for Sports and Leisure products.

“In the past two years, we have witnessed the very strong demand among Filipinos for high quality Taiwan-made products to meet their lifestyle needs. Through the Taiwan Excellence campaign, we hope to bring high quality products that will help Filipinos upgrade their lifestyles. We hope Filipino consumers will be empowered to make educated decisions about their purchases and experience the benefits and superior quality of our products and brands,” said Scott Yang, Deputy Executive Director of TAITRA.

Among the activities slated for 2016 are Taiwan Excellence Experiencing Zones scheduled on June 3 to 5 in SM Megamall, July 8 to 10 in SM Mall of Asia, August 19 to 21 in TriNoma, and October 21 to 23 in Market! Market!. Visit www.taiwanexcellence.ph for more details.

Like this story? Share it and don't forget to follow us on our social channels: FacebookTwitter InstagramGoogle+YoutubeFlickr

الثلاثاء، 7 يونيو 2016

The best gadgets Dad deserves for Father's Day

What better way is there to greet your dad or husband a Happy Father’s Day other than giving him a usual greeting card or preparing his favorite meal for breakfast? Now that it’s just around the corner, don’t panic because Home Credit’s got it covered for you. From the latest smartphones to the hottest laptops and tablets, and even the newest TV and home theater systems, there is an easy, simple and fast way to purchase these great gifts he will surely enjoy.

Home Credit team member and a customer


For the different kinds of loving dads

The man who loves capturing life’s greatest moments deserves that Samsung Galaxy J7 he’s been eyeing at an affordable price. With a 13-megapixel rear camera and a 5-megapixel front camera for selfies, he can shoot excellent photos midday or even in the dark. The OPPO F1 is another great phone the selfie-loving dad will enjoy. Dubbed as the “selfie expert,” OPPO F1 comes with a 13-megapixel rear camera, an 8-megapixel front camera and a Beauty 3.0+ to brighten the skin and remove those unwanted wrinkles.

For the hardworking dad who comes home late at night, the new ASUS ZenBook UX305 comes with a built-in webcam which allows him to talk to his family anytime, anywhere. The Acer Iconia One 8 can also be an alternative for on-the-go dads --- a pocket-friendly 8-inch Android tablet that permits him to edit his presentations on the way to meetings.

And for every household’s remote control king, he definitely deserves an all-new LG 55-inch TV accompanied by a home theater system. Now, he can enjoy watching the NBA finals in the best way possible. What more can the best dad in the world ask for?


Avail of that gift through Home Credit

In partnership with Silicon Valley, Automatic Centre, MemoXpress, and Western Appliances, Home Credit ensures customers will be able to avail of these gadgets for most deserving dads and husbands by applying for a Home Credit loan in an easy, simple and fast way. All the customer needs to do is to present at least two (2) valid IDs and the loan gets approved in as little as five minutes.  The customer only has to cash out an initial down payment and a minimal 3% processing fee and afterwards, leave the store with the perfect Father’s Day gift.

With Home Credit, customers may purchase their smartphones, tablets, and a lot more at Silicon Valley, MemoXpress, and other leading concept stores and retailing partners with an approved monthly installment varying from 6 to 9 months at a cash out with 0% interest.

Customers may also avail of these gadgets or even their LED TV and home theater system from selected Western Appliances stores from June 1 to July 31, 2016. Through the "Hulugang abot kaya, mas pinagaan pa" promo, customers can choose a loan term of 6 or 12 months.

No hassle, it’s that easy, simple and fast! For more information, visit www.homecredit.ph.

Like this story? Share it and don't forget to follow us on our social channels: FacebookTwitter InstagramGoogle+YoutubeFlickr

الجمعة، 6 مارس 2015

(21% Off) Acer C720 Chromebook Rs.16490 + Free 64GB Sandisk Pendrive

M.R.P :- ₹ 21,000
Discount :- 21% Off
Offer Price :- ₹ 16,490
Free :- 64GB Sandisk Pendrive

Features of Acer C720 Chromebook :-
  • Screen Size : 29.46cm (11.6)
  • Processor : Celeron Dual Core (4th Generation)
  • Type : Notebook
  • Operating System : Chrome OS
  • Utility : Everyday Use
  • Hard Disk Capacity : 16 GB SSD
  • Memory (Ram) : 2 GB