Showing posts with label Alerts. Show all posts
Showing posts with label Alerts. Show all posts

Exploit published for buffer overflow in BEA WebLogic

A hacker known as KingCope has discovered a potential buffer overflow in BEA WebLogic which can at least trigger system crashes, but may also be exploited to remotely inject and execute arbitrary code. The flaw is caused by Apache Connector which appears not to check certain POST requests sufficiently.

According to comments the published exploit is "broken" and doesn't function properly. Nevertheless, security providers FrSIRT and Secunia have rated the vulnerability as critical and highly critical respectively. According to Secunia, versions 5 to 10 are affected. No patch has so far become available. The only protection currently available is to filter the server's network traffic in order to minimise the risk of an attack.

See also:

[Source: heise-online]

MySpace XSS QuickTime Worm -

Threat Type: Malicious Website / Malicious Code

Websense® Security Labs™ has confirmed the existence of a worm spreading on the MySpace network. This worm is exploiting the Javascript support within Apple's embedded QuickTime player (1). This is used in conjunction with a MySpace vulnerability that was announced two weeks ago on the Full-Disclosure mailing list (2). The vulnerabilities are being used to replace the legitimate links on the user's MySpace profile with links to a phishing site.

Once a user's MySpace profile is infected (by viewing a malicious embedded QuickTime video), that profile is modified in two ways. The links in the user's page are replaced with links to a phishing site, and a copy of the malicious QuickTime video is embedded into the user's site. Any other users who visit this newly-infected profile may have their own profile infected as well.

An infected profile can be identified by the presence of an empty QuickTime video or modified links in the MySpace header section, or both.

  1. http://www.gnucitizen.org/blog/backdooring-quicktime-movies/
  2. http://seclists.org/fulldisclosure/2006/Nov/0275.html
  3. http://www.apple.com/quicktime/tutorials/hreftracks.html

Site screenshot:

[Source: Securitylabs.websense.]

DNS Fast Fluxing - Are you protected? CA Experts issue warning of new hacker attack

on November 20th, 2007

Cybercriminals are increasingly using an advanced method of hiding and sustaining their malicious Websites and botnet infrastructures — dubbed “fast-flux” — that could make them more difficult to detect, researchers say.

DNS Fast Fluxing is also referred to simply as Fast Fluxing, although some advanced security researchers claim Fast Fluxing of services other than Domain Name Services (DNS) may be possible with future developments in attack-and-command botware and crimeware frameworks; in any case, the International Security Convention Consortium (ISCC) will have to convene to consider an appropriate protocol convention for these issues. In the interest of brevity and throughout this article I will generally only make references to “Fast Fluxing” rather than use the long-hand title of DNS Fast Fluxing, and I humbly deign to apologize in advance for any misunderstandings of confusion.

DNS Fast Fluxers, also known as DFFers (or in some circles, FFers) are classed amongst some of the most dangerous of threats to your online assets. DFFers are notorious for defeating anti-phencing systems using flaws within Domain technology such as DNS Services, and for utilizing these flaws to avoid being detected. This makes the DFFer harder to track down completely, as his peer network command is decentralized through the tunnels provided by the popular Internet naming services.

WHAT IS DNS FAST FLUXING?

Fast flux is an advanced method being used by determined botnet operators to hide and preserve their malicious Websites and botnet infrastructures. The bad guys behind Warezov/Stration and Storm, for instance, have separately moved their infrastructures to fast-flux service networks, according to members of the Honeynet Project & Research Alliance, who monitor fast-flux behavior via their honeypots.

What the Fast Flux

With Fast Flux, infected bot machines serve as proxies or hosts for malicious Websites and get rotated regularly, changing DNS records to evade discovery. IP blacklists are basically useless in finding fast flux-based botnets. The bad guys behind these networks can easily hide their fake online pharmacies, pornography, phishing sites, and other malicious content servers using this “round-robin” process.

  • Mark Wade

Mark Wade, 10 year veteran in information security and current manager of Research Content with Computer Associates’ Threat Research Team, and contributer to the Computer Associates Security Advisor Research Blog (CARBS) writes:

“I decided to take a deeper look and see what I could find out about a botnet operation that I stumbled across. This investigation begins from a spammed email message I received, that was selling jewelry.

Since it is common practice we can assume the email was sent or relayed from a compromised computer that may have been part of a botnet. There were two websites in the email message: http://ryih.mhhimto.com and rmfx.mhhimto.com.

Using nslookup, I entered rmfx.mhhimto.com to resolve its IP address. I was not surprised to see eight completely different returned IP addresses returned, all ranging from various IP netblocks. Since I have seen similar types of activity in the past, I ran nslookup again to see if the IP addresses changed. Sure enough, in just under 10 minutes the previously listed IP addresses changed to a completely new set of IP addresses. This seemed to happen about every ten minutes. I quickly identified the ever changing IP addresses as DNS fast fluxing.

Fast fluxing is a method of deception utilized by botnets to conceal the identity of the bot herder or parts of the criminal activity. Fast fluxing works by constantly rotating compromised IP addresses, which are usually acting as a proxy to the end system. This is extremely beneficial to criminals who are involved in phishing scams or using compromised web sites used to deliver malware. “

  • The Honeynet Project

The Honeynet Project & Research Alliance defines a fast-flux network as :
Fast-flux service networks are a network of compromised computer systems with public DNS records that are constantly changing, in some cases every few minutes. These constantly changing architectures make it much more difficult to track down criminal activities and shut down their operations.

  • Adam O’Donnell of Cloudmark

“The purpose of this technique is to render the IP-based block list — a popular tool for identifying malicious systems — useless for preventing attacks,” says Adam O’Donnell, director of emerging technologies at security vendor Cloudmark.

“Fast flux is just the latest method of survival for the bad guys: There are more to come. Any technique that allows a malicious actor to keep his network online longer — and reduce the probability of his messages and attacks being blocked — will be used,” he says. “This is just the latest of those techniques.”

  • Ralph Logan, The Logan Group

All of this research on fast-flux is new. No one had any definitive research on it. [..] We saw a rising trend in illegal, malicious criminal activity here.. [..] Fast-flux helps cybercriminals hide their content servers, including everything from fake online pharmacies, phishing sites, money mules, and adult content sites,” Logan says. “This is to keep security professionals and ISPs from discovering and mitigating their illegal content.”

The bad guys like fast-flux — not only because it keeps them up and running, but also because it’s more efficient than traditional methods of infecting multiple machines, which were easily discovered.

“The ISP would shut down my 100 machines, and then I’d have to infect 100 more to serve my content and relay my spam,” Logan says. Fast-flux, however, lets hackers set up proxy servers that contact the “mother ship,” which serves as command and control. It uses an extra layer of obfuscation between the victim (client) and the content machine, he says.

“Our honeypot can capture actual traffic between the mother ship and the end node,” Logan says. The Alliance is still studying the malicious code and behavior of the fast-flux network it has baited.

A domain has hundreds or thousands of IP addresses, all of which are rotated frequently — so the proxy machines get rotated regularly, too – some as often as every three minutes — to avoid detection. “It’s not a bunch of traffic to one node serving illegal code,” Logan says.

“I send you a phishing email, you click on www.homepharmacy.com — but it’s really taking you to Grandma’s PC on PacBell! .. Which wakes up and says ‘it’s my turn now!‘ threatens Logan. “You’d have 100 different users coming to Grandma’s PC for the next few minutes, and then Auntie Flo’s PC gets command-and-controlled next!” he says, with a menacing tone.

Sources:

http://community.ca.com/blogs/securityadvisor/archive/2007/11/07/web-of-deception.aspx

http://www.darkreading.com/document.asp?doc_id=132720

[Source: xssworm]

Websense Discovers Microsoft Excel High-risk Zero-day Vulnerability - Patch Released -

Websense® Security Labs™ has discovered a high-risk zero-day vulnerability (MS08-014) within the widely-used Microsoft Office Excel.

This vulnerability, discovered by Websense in November 2007, requires minimal user interaction. Exploit code can be embedded within Microsoft Excel files and launched upon opening an excel document. This could be launched over email, through a website or another less common method. Upon discovery Websense responsibly disclosed this important vulnerability to Microsoft and has since been patched. (http://www.microsoft.com/technet/security/bulletin/ms08-mar.mspx)

 


Due to the fact that several targeted attacks have used Microsoft Office vulnerabilities in the past we recommend that users patch machines.

Websense ThreatSeeker™ technology is actively searching for in-the-wild exploits and Websense will automatically protect customers upon discovery.

Note: Microsoft Excel 2002 and earlier versions are affected.

To show how this vulnerability could potentially be used in the wild we’ve created a video, with a proof of concept exploit on a Windows XP machine running an unpatched version of excel. In this demo, the user receives an exploited Excel file via email. The user manually opens it, and is automatically exploited.

For the purpose of visualization, our exploit executes Solitaire, but obviously a malicious exploit could execute arbitrary code.

Proof of concept video: Link

References:
March 2008 bulletin summary

[Source: Securitylabs]

Eltiempo.com Fake Video Trojan

Eltiempo.com Fake Video Trojan - Date: 03.10.2008

Threat Type: Malicious Code

Websense® Security LabsTM has received reports of a phishing attack that claims to be from the popular Columbian news site, Eltiempo.com.

The report claims that the presidents of Colombia, Ecuador, and Venezuela, countries that have recently been in political conflict, have shaken hands. The email tries to lure recipients into clicking links that promise exclusive videos and photos, including footage of the presidents shaking hands.

The link leads to a Trojan Downloader executable hosted in Norway (MD5: 25039a99d27562a1707ac7320b77744d).

At the time of this alert, antivirus software was not providing adequate coverage for this attack.

Translation of the email body to English:

El Tiempo.

Handshake between the presidents of Colombia, Ecuador and Venezuela.
Taken from Internet.


At the Rio summit, after a long day of dialogue between Colombia, Ecuador, and Venezuela, the presidents were able to shake hands and agree to speak in a friendly way about political solutions to this conflict.

Download the complete video about the Rio summit.

Look for more photos and videos.

Astronauts in Colombia.
Four crew members from the recent Discovery mission to the International Space Station are visiting Colombia. On Monday, they spoke with children in Maloka.

These are the documents that tie Chávez and Ecuador with FARC, and that will be shown in OEA (PDF).


Screenshot of email:


[Source: Securitylabs]


China.com game site hosting malicious code

Threat Type: Malicious Web Site / Malicious Code

Websense® Security Labs™ ThreatSeeker technology has detected malicious code hosted on China.com's game site. The malware is a variant of VBS/Redlof and is known to commonly infect files with the extension of "html", "htm", "php", "jsp", "htt", "vbs", and "asp".

This malicious download (MD5: e6df57ea75a77112e94036e5138bd063) is placed in a directory that appears to be reserved for game patch downloads. This virus attempts to spread itself by infecting all outbound emails sent by the victim with MS Outlook or Outlook Express.

Screenshot of site:



Screenshot of the malicious code:



More details on the Microsoft VM ActiveX component vulnerability (MS00-075)

Mass Attack JavaScript injection - UN and UK

Mass Attack JavaScript injection - UN and UK Government websites compromised - Date: 04.22.2008

Threat Type: Malicious Web Site / Malicious Code

This mass injection is remarkably similar to the attack we saw earlier this month. When a user browses to a compromised site, the injected JavaScript loads a file named 1.js which is hosted on http://www.nihao[removed].com The JavaScript code then redirects the user to 1.htm (also hosted on the same server). Once loaded, the file attempts 8 different exploits (the attack last April utilised 12). The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications. Ominously files named McAfee.htm and Yahoo.php are also called by 1.htm but are no longer active at the time of writing.

There are further similarities too between the two mass attacks. Resident on the latest malicious domain is a tool used in the execution of the attack. An analysis of that tool can be found in the ISC diary entry here. Mentioned in that diary entry is http://www.2117[removed].net. Our blog on that attack can be found here. It appears that same tool was used to orchestrate this attack too.

When we first started tracking the use of this domain, the malicious JavaScript was still making use of http://www.nmida[removed].com/:

Now the attackers are referring to a file hosted on the new domain of http://www.nihao[removed].com:

Sites of varying content have been infected including UK government sites, and a United Nations website as can be seen by the Google search results below.

The number of sites affected is in the hundreds of thousands:

Evidence of a compromise on a United Nations website:

Evidence of a compromise on a UK government website:

Evidence of a compromise on a Chinese tourism website:

Casualties of the previous attack included various US news web sites, a major Israeli shopping portal, and numerous travel sites.

Websense security customers are protected against this attack