Anzeige
Mehr »
Mittwoch, 22.10.2025 - Börsentäglich über 12.000 News
Das Comeback des Goldrauschs - diesmal ausgelöst durch eine Währungskrise
Anzeige

Indizes

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Aktien

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Xetra-Orderbuch

Fonds

Kurs

%

Devisen

Kurs

%

Rohstoffe

Kurs

%

Themen

Kurs

%

Erweiterte Suche
PR Newswire
283 Leser
Artikel bewerten:
(1)

F-Secure Finds Major Vulnerabilities in Popular Wireless Presentation System

Security consultants warn that the devices we trust without a second thought are attackers' favorite targets

HELSINKI, Dec. 16, 2019 /PRNewswire/ -- Consultants with cyber security provider F-Secure have discovered several exploitable vulnerabilities in a popular wireless presentation system. Attackers can use the flaws to intercept and manipulate information during presentations, steal passwords and other confidential information, and install backdoors and other malware.

Barco's ClickShare wireless presentation system is a collaboration tool that helps groups of people present content from different devices. ClickShare is a market-leading wireless presentation system with a market share of 29% according to FutureSource Consulting's 'Global wireless presentation solutions 2019' report.*

F-Secure Consulting's Dmitry Janushkevich, a senior consultant that specializes in hardware security, says the popularity of these user-friendly tools make them logical targets for attack, which is what compelled his team to investigate.

"The system is so practical and easy to use, people can't see any reason to mistrust it. But its deceptive simplicity hides extremely complex inner workings, and this complexity makes security challenging," explains Janushkevich. "The everyday objects that people trust without a second thought make the best targets for attackers, and because these systems are so popular with companies, we decided to poke at it and see what we could learn."

Janushkevich and his F-Secure Consulting colleagues researched the ClickShare system on an on-and-off basis for several months after noticing its popularity during red team assessments. They discovered multiple exploitable flaws, 10 of which have CVE (Common Vulnerabilities and Exposures) identifiers. The different issues facilitate a variety of attacks, including intercepting information shared through the system, using the system to install backdoors or other malware on users' computers, and stealing information and passwords.

While exploiting some of the vulnerabilities requires physical access, others can be done remotely if the system uses its default settings. Furthermore, Janushkevich says the execution of the exploits can be done quickly by a skilled attacker with physical access (possibly while posing as a cleaner or office worker), allowing them to inconspicuously compromise the device.

"Our tests' primary objectives were to backdoor the system so we could compromise presenters, and steal information as it's presented. Although cracking the perimeter was tough, we were able to find multiple issues after we gained access, and exploiting them was easy once we knew more about the system," explains Janushkevich. "For an attacker, this is a fast, practical way to compromise a company, and organizations need to inform themselves about the associated risks."

F-Secure Consulting shared their research with Barco on October 9, 2019, and the two companies worked together in a coordinated disclosure effort. Today, Barco published a firmware release on their website to mitigate the most critical vulnerabilities. However, several of the issues involve hardware components that require physical maintenance to address, and are unlikely to get fixed.

"This case highlights how hard it is to secure 'smart devices'. Bugs in silicon, in the design, and in the embedded software can have long-lasting negative effects on both the vendor and users, undermining the trust we put in these devices," says Janushkevich.

F-Secure Consulting operates on four continents from 11 different countries. It provides cyber security services tailored to fit the needs of banking, financial services, aviation, shipping, retail, insurance, and other organizations working in highly targeted sectors. Details of the research are available in a blog post on F-Secure Labs. More information on F-Secure Consulting is available here.

*Source: https://futuresource-consulting.com/reports/posts/2019/may/futuresource-wireless-presentation-solutions-market-report-worldwide-may-19/?locale=en

About F-Secure

Nobody has better visibility into real-life cyber attacks than F-Secure. We're closing the gap between detection and response, utilizing the unmatched threat intelligence of hundreds of our industry's best technical consultants, millions of devices running our award-winning software, and ceaseless innovations in artificial intelligence. Top banks, airlines, and enterprises trust our commitment to beating the world's most potent threats. Together with our network of the top channel partners and over 200 service providers, we're on a mission to make sure everyone has the enterprise-grade cyber security we all need.

Founded in 1988, F-Secure is listed on the NASDAQ OMX Helsinki Ltd.

f-secure.com | twitter.com/fsecure | linkedin.com/f-secure

CONTACT:

F-Secure media relations
Sandra Proske
+49-176-7003-6664

This information was brought to you by Cision http://news.cision.com

© 2019 PR Newswire
Epische Goldpreisrallye
Der Goldpreis hat ein neues Rekordhoch überschritten. Die Marke von 3.500 US-Dollar ist gefallen, und selbst 4.000 US-Dollar erscheinen nur noch als Zwischenziel.

Die Rallye wird von mehreren Faktoren gleichzeitig getrieben:
  • · massive Käufe durch Noten- und Zentralbanken
  • · Kapitalflucht in sichere Häfen
  • · hohe Nachfrage nach physisch besicherten Gold-ETFs
  • · geopolitische Unsicherheit und Inflationssorgen

Die Aktienkurse vieler Goldproduzenten und Explorer sind in den vergangenen Wochen regelrecht explodiert.

Doch es gibt noch Titel, die Nachholpotenzial besitzen. In unserem kostenlosen Spezialreport erfahren Sie, welche 3 Goldaktien jetzt besonders aussichtsreich sind und warum der Aufwärtstrend noch lange nicht vorbei sein dürfte.

Laden Sie jetzt den Spezialreport kostenlos herunter und profitieren Sie von der historischen Gold-Hausse.

Dieses Angebot gilt nur für kurze Zeit – also nicht zögern, jetzt sichern!
Werbehinweise: Die Billigung des Basisprospekts durch die BaFin ist nicht als ihre Befürwortung der angebotenen Wertpapiere zu verstehen. Wir empfehlen Interessenten und potenziellen Anlegern den Basisprospekt und die Endgültigen Bedingungen zu lesen, bevor sie eine Anlageentscheidung treffen, um sich möglichst umfassend zu informieren, insbesondere über die potenziellen Risiken und Chancen des Wertpapiers. Sie sind im Begriff, ein Produkt zu erwerben, das nicht einfach ist und schwer zu verstehen sein kann.