Showing posts with label Kernel-level Exploits. Show all posts
Showing posts with label Kernel-level Exploits. Show all posts

Pwn2Own hacker contest targets browsers, smart phones

After two straight years of taking dead aim at Macbooks and Windows-powered machines, hackers at this year’s CanSecWest conference will have shiny new targets: Web browsers and mobile phones.

According to CanSecWest organisers, there will be two separate Pwn2Own competitions this year — one pitting hackers against IE8, Firefox 3 and Safari and another targeting Google Android, Apple iPhone, Nokia Symbian and Windows Mobile.

[ SEE: 10 questions for MacBook hacker Dino Dai Zovi ]

On the browser side, the IE vs Firefox battle is sure to grab headlines although I’m not quite sure why Opera or Google’s Chrome was not included in the target list.

The rules of engagement are not yet available but it’s a safe bet that a successful attacker would have to exploit a zero-day vulnerability to gain full access to the target computer.

CanSecWest organizers plan to Sony VAIO P running Windows 7 as the platform for the contest. The successful hacker gets to keep the machine.

[ SEE: Google Android vulnerable to drive-by browser exploit ]

The second contest — against mobile phone platforms — will be another closely watched affair. Hackers have already successfully infiltrated the iPhone and Android platforms and there are known security problems in Symbian and Windows Mobile so we’re likely to see a lot of attention paid to this contest.

In 2007, New York-based security researcher Dino Dai Zovi teamed up with Shane Macaulay to hijack a MacBook Pro via a flaw in Apple’s QuickTime software. A year later, hacker Charlie Miller needed just two minutes to exploit a Safari bug to win that contest.

Alex Sotirov also partnered with Macaulay in 2008 to exploit an Adobe Flash vulnerability on a Windows Vista box. (Thanks to NonZealot for the correction).

* Image source: Channy Yun’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Remote buffer overflow bug bites Linux Kernel


Remote buffer overflow flaw in Linux KernelA remote buffer overflow vulnerability in the Linux Kernel could be exploited by attackers to execute code or cripple affected systems, according to a Gentoo bug report that just became public.

The flaw could allow malicious hackers to launch arbitrary code with kernel-level privileges. This could lead to complete system compromise or, in some cases if an exploit fails, result in denial-of-service attacks.

This from the Gentoo bug report:

  • Anders Kaseorg discovered that ndiswrapper did not correctly handle long ESSIDs. If ndiswrapper is in use, a physically near-by attacker could generate specially crafted wireless network traffic and crash the system, leading to a denial of service.

Secunia rates this a “moderately critical” vulnerability:

  • The vulnerability is caused due to a boundary error in the ndiswrapper kernel driver when processing wireless network packets. This can be exploited to cause a buffer overflow via an overly long ESSID (Extended Service Set Identifier). Successful exploitation may allow execution of arbitrary code.

The vulnerability (CVE-2008-4395) affects Linux Kernel 2.6.27. As a temporary mitigation, Linux users should disable wireless network card that are not in use.

[Source: zdnet]


MS ships emergency patch for Windows worm hole

windows_bullet_holes.jpgMicrosoft has released an out-of-band patch to fix an extremely critical worm hole that exposes Windows users to remote code execution attacks.

The emergency update comes just one week after the regularly scheduled Patch Tuesday and follows the discovery of a targeted zero-day attack, Microsoft said in an advisory. The vulnerability is rated “critical” on Windows 2000, Windows XP and Windows Server 2003.

On Windows Vista and Windows Server 2008, the flaw carries an “important” rating.

From Microsoft’s critical MS08-067 bulletin:

  • A remote code execution vulnerability exists in the Server service on Windows systems. The vulnerability is due to the service not properly handling specially crafted RPC requests. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Microsoft said it was aware of “limited, targeted attacks attempting to exploit the vulnerability” but the company did not provide any clues about the origin of the attacks or the target that was hit. There are no signs yet of public proof-of-concept code.

According to the bulletin, there is a chance that the vulnerability could lead to a “wormable exploit.”

  • The vulnerability could allow remote code execution if an affected system received a specially crafted RPC request. On Microsoft Windows 2000, Windows XP, and Windows Server 2003 systems, an attacker could exploit this vulnerability without authentication to run arbitrary code. It is possible that this vulnerability could be used in the crafting of a wormable exploit.
  • Firewall best practices and standard default firewall configurations can help protect network resources from attacks that originate outside the enterprise perimeter.

The vulnerable Windows Server service provides RPC support, file and print support, and named pipe sharing over the network. It is also used to allow the sharing of your local resources (such as disks and printers) so that other users on the network can access them.

This is the first out-of-cycle patch from Microsoft since the fix for the animated cursor vulnerability in April 2007. It is the 67th bulletin from Redmond this year.

[Source: zdnet]

On Opera patch day, a new zero-day flaw

On Opera patch day, a new zero-day flawOn the same day Opera shipped a browser update with patches for three separate security vulnerabilities, hackers are openly discussion a new zero-day flaw that exposes Windows users to remote code execution attacks.

With Opera 9.61, the Norwegian browser maker corrects an issue where History Search could be used to reveal browser history (rated extremely severe); a Fast Forward bug that allows cross-site scripting (highly severe); and an information disclosure flaw in news feeds (also highly severe).

But even as Opera users were scrambling to apply the latest patches, a public discussion on the Full Disclosure mailing list exposed a zero-day vulnerability that could lead to cross-site scripting and even remote code execution attacks.

The discussion began with this Roberto Suggi advisory on the History Search bug fixed in Opera 9.61 but quickly expanded to raise the possibility of code execution attacks.

Within hours, researcher Aviv Raff discovered a way to execute code from remote and released a harmless proof-of-concept exploit that launches the Windows calculator.

I can confirm that a separate exploit exists that launches harmful code remotely against fully patched versions of the Opera browser.

Until Opera can fix this new issue, users are strongly urged to consider a different browser or avoid clicking on links on untrusted Web pages.

[Source: zdnet]

Secunia: popular security suites failing to block exploits

Secunia Comparative Review Internet Security SuitesIn a recently conducted comparative review, Danish security company Secunia, tested the detection rate of 12 different Internet Security Suites against 300 exploits (144 malicious files and 156 malicious web pages) affecting popular end user applications, to find that even the top performer in the test is in fact performing poorly in general. Their conclusion :

“These results clearly show that the major security vendors do not focus on vulnerabilities. Instead, they have a much more traditional approach, which leaves their customers exposed to new malware exploiting vulnerabilities.

While we did expect a fairly poor performance in this field, we were quite surprised to learn that this area is more or less completely ignored by most security vendors. Some of the vendors have taken other measures to try to combat this problem. One is Kaspersky who has implemented a feature very similar to the Secunia PSI, which can scan a computer for installed programs and notify the user about missing security updates. BitDefender also offers a similar system, albeit this is more limited in scope than the one offered by Kaspersky and Secunia. We do, however, still consider it to be the responsibility of the security vendors to be able to identify threats exploiting vulnerabilities, since this is the only way the end user can learn about where, when, and how they are attacked when surfing the Internet.”

And while it’s boring to scroll through the empty tables of the study, is Secunia’s report a frontal attack against the security software vendors’ inability to block exploits, or are they trying to emphasize on the fact that the end user should make better informed purchasing decisions when relying on All-in-One Security products?

In 2007, Secunia released data indicating that 28% of all installed apps are insecure, and despite that the vulnerabilities has been already addressed, the end users were still living in the reactive response world. Cybercriminals on the other hand, took notice, and following either common sense or publicly obtainable data indicating that end users remain susceptible to already patched vulnerabilities, started integrating outdated exploits into what’s to become one of the main growth factors for web malware in the face of today’s ubiqutous web malware exploitation kits.

Live Exploit Kit SampleA year later, another study confirmed this fact and pointed out that one of most effective vehicle for the success of web malware — the insecure web browser — remains largely ignored by millions of Google users. So, theoretically, the more traffic the malicious attackers acquire and redirect to their exploit serving domains, the higher the probability for a successful infection with an undetected by standard signatures based scanning piece of malware - which is exactly what they’ve been doing the entire 2007 and 2008.

What is more important, to detect the latest malware binary behind the exploit serving file, or prevent the latest malware binary from reaching the end user/company by blocking the relatively static exploit serving file? It’s all a matter of perspective.

Naturally, the reactions to the comparative review, and the methodology used are already receiving criticism from the vendors. Sunbelt Software’s Alex Eckelberry comments on the report, and also includes AV-Test.org’s Andreas Marx opinion emphasizing on why it’s important to prioritize :

“In most cases, it is simply not practical to scan all data files for possible exploits, as it would slow-down the scan speed dramatically. Instead of this, most companies focus on some widely used file-based exploits (like the ANI exploits) and some companies also remove the detection of such exploits after some time has passed by (as most users should have patched their systems in the meantime and in order to avoid more slow-downs). There are a lot more practical solutions built-in to security suites, like the URL filter (which checks and blocks known URLs which are hosting malware or phishing websites) and the exploit filter in the browser (which would also block access to many “bad” websites). Some tools also have virtualization and buffer/stack/heap overflow protection mechanisms included, too.

Then we have the traditional “scanner” — and even if some exploit code gets executed, a HIPS, IDS or personal firewall system might be able to block the attack. For example, some security suites are knowing that Word, Excel or WinAmp won’t write EXE files to disk — so potentially dropped malware cannot get executed and the system is left in a “good” state.”

Emphasizing on defense-in-depth, and prioritizing in the case of blocking the most popular exploits used is a very good point since it has the potential to protect as many customers as possible from the default set of exploits used in the majority of malware attacks. For instance, the massive SQL injections attacks that took place during the last couple of months, were all relying on relatively static javascript file, whose generic detection is a good example of prioritizing. Moreover, due to the evident template-ization of malware serving sites, and the commoditization of web malware exploitation kits, the impact of ensuring that your customers are protected from the default sets of exploits included within these kits, means that your customers will be protected from a huge percentage of web based malware attacks.

No Internet Security Suite can protect you from yourself, so do yourself and the Internet a favor - patch all your insecure applications - it’s free.

[Source: zdnet]

VMWare issues ‘critical’ ESXi security advisory

VMWare issues ‘critical’ security advisoryVMware has released new ESXi and ESX 3.5 packages to fix a “critical” security issue that allows a remote, unauthenticated attacker to launch harmful code on the host running the hypervisor.

According to this VMWare advisory, the patches fix two remote buffer overflows in the handling of HTTP basic authentication headers.

  • This vulnerability could potentially be exploited by users without valid login credentials.

The vulnerability exists in the “Openwsman” system management platform which is enabled by default in ESX to implement the Web Services Management protocol (WS-Management).

[Source: zdnet]

Apple mega-patch covers 34 Mac OS X security issues


Mac OS X mega-patch swats 34 security holesApple has shipped another mega-update to address security vulnerabilities affecting Mac OS X users, warning that the most serious issues could lead to arbitrary code execution attacks.

The update, available for Tiger and Leopard, addresses a total of 34 documented vulnerabilities, some in third-party components like ClamAV, BIND, OpenSSH and Ruby.

It also provides fixes for the following Mac OS X flaws:

  • CVE-2008-2305 — A heap buffer overflow exists in Apple Type Services’ handling of PostScript font names. Viewing a document containing a maliciously crafted font may lead to arbitrary code execution.
  • CVE-2008-2329 — An information disclosure issue exists in Login Window when it is configured to authenticate users with Active Directory. By supplying wildcard characters in the user name field, a list of user names from Active Directory may be displayed.
  • CVE-2008-2330 — An insecure file operation issue exists in the slapconfig tool used for configuring OpenLDAP. A local user can cause
    the password entered by a system administrator running slapconfig to be written to a file controlled by the user.
  • CVE-2008-2331 – Finder does not update the displayed permissions under some circumstances in a Get Info window. After clicking the lock button, changes to the filesystem Sharing & Permissions will take effect, but will not be displayed.
  • CVE-2008-3613 — A null pointer dereference issue exists in the Finder when it searches for a remote disc. An attacker with access to the local network can cause Finder to exit immediately after it starts, making the system unusable.
  • CVE-2008-2327 – Multiple uninitialized memory access issues exist in libTIFF’s handling of LZW-encoded TIFF images. Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-2332 — A memory corruption issue exits in ImageIO’s handling of TIFF images. Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-3608 — A memory corruption issue exists in ImageIO’s handling of embedded ICC profiles in JPEG images. Viewing a large maliciously crafted JPEG image may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-1382 — libpng in ImageIO is updated to version 1.2.29. CVE-2008-1382 is not known to affect the use of libpng in ImageIO, and this update is applied as a precautionary measure.
  • CVE-2008-3609 — Cached credentials are not always flushed when a vnode is recycled. This may allow a local user to read or write to a file
    where the permissions would not allow it. This update addresses the issue through improved handling of purged vnodes.
  • CVE-2008-1447 — libresolv provides translation between host names and IP addresses for applications that use its unicast DNS resolution API. A weakness in the DNS protocol may allow remote attackers to perform DNS cache poisoning attacks. As a result, applications that rely on libresolv for DNS may receive forged information.
  • CVE-2008-3610 — A race condition exists in Login Window. To trigger this issue, the system must have the Guest account enabled or another account with no password. In a small proportion of attempts, an attempt to log in to such an account will not complete. The user list would then be presented again, and the person would be able to log in as any user without providing a password. If the original account were the Guest account, the contents of the new account will be deleted on logout.
  • CVE-2008-3611 – When a system has been configured to enforce policies on login passwords, users may be required to change their password in the login screen. If a password change fails, an error message is displayed, but the current password is not cleared. This may not be obvious to the user. If the user leaves the system unattended with this error message displayed, a person with access to the login
    screen may be able to reset that user’s password.
  • CVE-2008-1447 – mDNSResponder provides translation between host names and IP addresses for applications that use its unicast DNS resolution API. A weakness in the DNS protocol may allow a remote attacker to perform DNS cache poisoning attacks. As a result, applications that rely on mDNSResponder for DNS may receive forged information.
  • CVE-2008-3614 – An integer overflow exists in QuickDraw’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-3616 -- Integer overflow issues exist in functions within the SearchKit framework. Passing untrusted input to SearchKit via an application may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-2312 – Network Preferences stores PPP passwords unencrypted in a world readable file, accessible to any local user. This update addresses the issue by storing PPP passwords in the system keychain when the password is changed.
  • CVE-2008-3617 — Remote Management and Screen Sharing can be configured to require a password for VNC viewers. The maximum length for VNC viewer passwords is eight characters. The password field can display more than eight characters, implying that the additional characters are used in the password.

Other documented vulnerabilities affect System Preferences, Time Machine, VideoConference and Wiki Server.

* Image source: DeclanTM’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Secunia launches pay-as-you-go exploit shop

Secunia launches pay-as-you-go exploit shopDanish security research firm Secunia has launched a pay-as-you-go vulnerability analysis service aimed at providing technical details, exploits and proof-of-concept code to security software vendors.

The new Binary Analysis Service is billed as a one-stop-shop for indepth analysis of the “worst and most interesting vulnerabilities” affecting widely deployed software products. It will include exploits and proof-of-concepts for verification purposes and is available only for “certain types of vendors and governments.”

Secunia CTO Thomas Kristensen said the service is strictly “defensive in nature” with a goal to provide reliable intelligence for security vendors — especially anti-virus and IDS/IPS companies that rely on flaw data to create rules and signatures. It is also being marketed to corporate and national entities that have the technical capacity to create custom rules in-house for their IDS/IPS products.

[ SEE: Microsoft makes daring vulnerability sharing move ]

The company says it will strictly monitor access to the new service.

All the security vendors and other companies, who are approved, will get access to buy the Binary Analyses on a “pay as you go” basis or as an annual subscription, which gives unlimited access to the historical analyses and approximately 200 new analyses per year.

The company has already released free sample analyses with information on serious security vulnerabilities in Microsoft GDI+, Microsoft Word, Microsoft Windows OLE automation, Samba and Adobe Flash.

Secunia rolls out one-stop exploit shop

During the past 2 years we have serviced a few selected AV and IDS/IPS vendors with this intelligence, however, we have also realized that far too many of the other AV and IDS / IPS vendors — including the major ones — fail to detect many attacks utilising critical vulnerabilities simply because they too often create payload based signatures rather than vulnerability based signatures, Kristensen said.[ SEE: Secunia: 28% of all installed apps are insecure ]

The Secunia move follows news from Microsoft that it will start sharing details on software vulnerabilities with security vendors ahead of Patch Tuesday. The new Microsoft Active Protections Program (MAPP), which launches in October, will give anti-virus, intrusion prevention/detection and corporate network security vendors a headstart to add signatures and filters to protect against Microsoft software vulnerabilities.

The idea is to provide detection guidance ahead of time to help security vendors reproduce the vulnerabilities being patched and ship signatures and detection capabilities without false positives.

Some criteria for participants in MAPP include:

  • Members must offer commercial protection features to Microsoft customers against network- or host-based attacks.
  • Members must provide protection features to a large number of customers.
  • Members may not sell attack-oriented tools.
  • Protection features provided by members must detect, deter or defer attacks.

* Image sources: Secunia and HorseHats.com.

[Source: zdnet]

Intel ships BIOS fix for Rutkowska’s Black Hat flaw

Intel ships BIOS fix for Rutkowska’s Black Hat flawIntel has shipped a BIOS update with a fix for a privilege escalation vulnerability that was used by rootkit researcher Joanna Rutkowska to bluepill the Xen hypervisor.

The vulnerability was discussed by Rutkowska at the Black Hat briefings earlier this month but details on the exploit were withheld until Intel could release its patch.

That patch is now available (you can download a new firmware for your motherboard here) with a severity rating of “important.”

According to Intel’s advisory, software running administrative (ring 0) privilege can under certain circumstances change code running in System Management Mode.

  • A new BIOS update is available for select Intel desktop motherboards to ensure proper configuration settings. This change would prevent a malicious user from modifying software that is run in System Management Mode (SMM). SMM is a privileged operating environment running outside of OS control. Malicious software running in this environment could therefore perform any number of operations. Administrative level privileges are required to exploit this issue. BIOS updates to correct this issue are available for all affected Intel branded motherboards.

In a blog entry following Intel’s patch release, Rutkowska warns that an attacker could also use this bug to “directly modify the hypervisor memory, without jumping into the SMM first, just as we did it with our exploit.”

  • Also, in case of e.g. Linux systems, the Ring 0 access is not strictly required to perform the attack, as it’s just enough for the attacker to get access to the PCI config space of the device 0:0:0, which e.g. on Linux can be granted to usermode applications via the iopl() system call.

Affected Intel motherboards: DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, DX38BT and MGM965TW (Mobile).

In its advisory, Intel provides a step-by-step walk-through to help identify systems at risk and detailed instructions on updating your BIOS.

[Source: zdnet]

Linux under attack: Compromised SSH keys lead to rootkit

Compromised SSH keys leads to rootkitThe U.S. Computer Emergency Readiness Team (CERT) has issued a warning for what it calls “active attacks” against Linux-based computing infrastructures using compromised SSH keys.

The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as “phalanx2″ is installed, US-CERT said in a note on its current activity site.

From the advisory:

  • Phalanx2 appears to be a derivative of an older rootkit named “phalanx”. Phalanx2 and the support scripts within the rootkit, are configured to systematically steal SSH keys from the compromised system. These SSH keys are sent to the attackers, who then use them to try to compromise other sites and other systems of interest at the attacked site.

Phalanx, which dates back to 2005, is a self-injecting kernel rootkit designed for the Linux 2.6 branch. It allows an attacker to hide files, processes and sockets and includes a tty sniffer, a tty connectback-backdoor, and auto injection on boot.

Details on the attacks — and targets — remain scarce but it’s a safe bet this is linked to the Debian random number generator flaw that surfaced earlier this year. A working exploit for that vulnerability is publicly available.

To mitigate the risk from this attack, US-CERT recommends:

  • Proactively identify and examine systems where SSH keys are used as part of automated processes. These keys will typically not have passphrases or passwords.
  • Encourage users to use the keys with passphrase or passwords to reduce the risk if a key is compromised.
  • Review access paths to internet facing systems and ensure that systems are fully patched.

If a compromise is confirmed, US-CERT recommends:

  • Disable key-based SSH authentication on the affected systems, where possible.
  • Perform an audit of all SSH keys on the affected systems.
  • Notify all key owners of the potential compromise of their keys.

* Image source: wili_hybrid’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Microsoft investigating NSlookup.exe flaw, reported attacks

Microsoft investigating new Windows zero-day attackMicrosoft is investigating new public reports of a zero-day Windows vulnerability that’s being exploited in the wild.

According to a this SecurityFocus alert, the attacks are exploiting a remote code-execution vulnerability due to an unspecified error in NSlookup.exe, the command-line administrative tool used for testing and troubleshooting DNS servers.

  • Successfully exploiting this issue would allow the attacker to execute arbitrary code on an affected computer. Failed attacks will cause denial-of-service conditions. Microsoft Windows XP Professional SP2 is vulnerable; other versions and products may also be affected.

According to the alert, the issue is reportedly “being actively exploited” in the wild but details on the attacks are scarce.

A video of a proof-of-concept exploit in action was released by Argentinian researcher Ivan Sanchez.

On its monthly Patch Tuesday Webcast (see transcript), Microsoft’s security response team said it was aware of the flaw report and had started an investigation. The company has not yet issued a security advisory with workarounds or mitigations.

Some other highlights from the Webcast:

  • The Microsoft Access Snapshot Viewer ActiveX control vulnerability was only partially fixed with MS08-041. The standalone Access Snapshot Viewer is still vulnerable and unpatched. There are confirmed in-the-wild exploits for this vulnerability.
  • The reason the massive IE killbit update was done as an advisory instead of a bulletin was because it only included killbits for third-party (Aurigma and HP) ActiveX controls. Microsoft does not provide a security rating for these controls and the company never releases bulletins without severity ratings. “Since there is no severity associated with this release, we decided to release this update via an advisory.”
[Source: zdnet]

From Metasploit to Microsoft: Skape goes to Redmond

Skape goes to RedmondMetasploit developer Matt Miller, who for years frustrated Microsoft officials with the public release of Windows exploits, is heading to Redmond to join Microsoft’s Security Science team.

Miller, who uses the hacker moniker Skape,will work on improved ways to find security vulnerabilities and better software defenses through mitigations, according to an announcement by SDL guru Michael Howard.

“Matt brings a massive amount of real-world exploit and defense experience to our team,” Howard said, nothing that Miller has been focused on design review for Windows 7, the next major revision of the operating system.

[ SEE: Hacking with Metasploit on a Nokia N800 ]

Miller’s work around exploiting — and attempting to secure — the Windows ecosystem is legendary. In tandem with HD Moore, he has been one of the core developers on Metasploit, a free point-and-click pentest/attack tool, specializing in exploitation techniques/mitigations, reverse engineering, program analysis and modeling, rootkits and virtualization.

Over IM this morning, HD Moore said Miller designed a large chunk of the Metasploit 3 architecture, built the meterpreter payload system, and generally led the entire win32 shellcode improvement efforts.

“He has done some exploit work as well, but his focus was mostly on encoders, shellcode, and payloads,” Moore said. Miller was the third ‘full-time’ developer at Metasploit, having joined the volunteer group in mid-2004.

He is the author of several groundbreaking research papers, including techniques to bypass Windows Hardware-enforced DEP, improving software security analysis using exploitation properties and exploring the history of exploitation techniques (.pdf) and mitigations on Windows.

Miller is also an editor for the Uninformed Journal, a free online journal that focuses on encouraging the sharing of technical knowledge.

UPDATE: Over on Twitter, Dan Guido points out that Miller just open-sourced his WehnTrust HIPS project, which adds anti-exploit mechanisms/mitigations to Windows 2000, Windows XP and Windows Server 2003 systems.

[Source: zdnet]

uTorrent silently patches critical vulnerability

Code execution hole in uTorrentIf uTorrent is the client you use to download files, now might be a good time to hit that “check for updates” button.

According to security alerts aggregator Secunia, there’s a “highly critical” uTorrent vulnerability that could allow remote code execution attacks with rigged .torrent files.

From the advisory:

  • The vulnerability is caused due to a boundary error in the processing of “.torrent” files. This can be exploited to cause a stack-based buffer overflow by tricking the user into opening a “.torrent” file containing an overly long “created by” field.
  • Successful exploitation may allow execution of arbitrary code.
  • The vulnerability is confirmed in version 1.7.7 (build 8179). Prior versions may also be affected.

The issue was silently patched by the vendor in version 1.8 RC7. Rhys Kidd says the flaw is at least two years old.

[Source: zdnet]

Google releases open-source crypto toolkit


Google releases open-source crypto toolkit Google’s security team has released an open-source cryptographic toolkit aimed at making it easier and safer for developers to use cryptography in their applications.

The toolkit, called KeyCzar, was originally developed by Steve Weis (Google) and Arkajit Dey (MIT) and is available under an Apache 2.0 license.

From Google’s announcement:

Keyczar is a cryptographic toolkit that supports encryption and authentication for both symmetric and public-key algorithms. It addresses some of the aforementioned issues by choosing safe defaults, tagging outputs with key version information, and providing a simple application programming interface. Keyczar’s key versioning system makes it easy to rotate and revoke keys, without worrying about backward compatibility or making any changes to source code.

[ SEE: Google’s anti-malware team comes out of the shadows ]

Some features of KeyCzar include:

  • A simple API
  • Key rotation and versioning
  • Safe default algorithms, modes, and key lengths
  • Automated generation initialization vectors and ciphertext signatures
  • Java and Python implementations (C++ coming soon)
  • International support in Java (Python coming soon)

Google’s security team previously released two other open-source utilities — a fuzzer called Flayer and Ratproxy, a passive Web application security audit tool.

[Source: zdnet]

Black Hat Las Vegas Day 1

Well, this is well late, but here’s my recap of Black Hat Day 1. Sorry for the delay, but I’ve been terribly busy finishing up preparations for my Day 2 talk.

The first talk I went to see, “Pointers and Handles, A Story of Unchecked Assumptions in the Windows Kernel”, by Apple’s Alex Ionescu, discussed a number of vulnerabilities in the Windows kernel-mode library responsible for the Windows GUI subsystem. Most of this talk centered around attacking code where bad assumptions were made regarding the validity of pointers before they are dereferenced, and abusing the kernel mechanism of “protect from close” handles.

As Alex mentioned, these attacks have largely been overlooked in the past, due to the fact that most simply result in Denial of Service conditions. Alex mentioned how these flaws can no longer be overlooked as we have so many users working in Terminal Services emulated environments. I don’t know if Alex mentioned it, but a Denial of Service condition of this fashion could obviously also have lasting effects if used against a “cloud computing” or virtual server environment, where numerous systems could depend upon the up time of a singular machine.

About 3/4 of the way through Alex’s talk, I made my way over to Nitesh Dhanjani and Billy Rios’s talk on identity theft, “Bad Sushi”. I’ve seen and blogged about this presentation numerous times now, but there was some new tricks the pair pulled together. Dhanjani and Rios have talked at a few Black Hat conferences on this, and covered the ecosystem that is identity theft and how phishing, ATM skimming, etc. fill the demand for this market. So, I mentioned they had some new stuff, and it pretty much went like this:

  1. Rios shows a picture of a terrorist with an AK-47 spraying bullets into a crowd, comparing this to the current state of mass phishing attacks.
  2. He says, “Most people will turn and run, or get mowed down, but I will not go quietly into the night… I’m fighting back!”.
  3. Rios now shows a slide of Rambo with a automatic weapon that seems unlikely to be wielded by a single individual, which is to represent Rios and his attack back on the phishers.
  4. Rios sends out numerous word document files with embedded Rick-rolls to the phishers, claiming it is his account information and he’s looking to buy some of their phishing kits.
  5. Said phisher gets Rick-rolled. Awesome!

I next made my way to the “DNS Goodness” talk by Dan Kaminsky. What a circus! By the time I got their, the largest room for Black Hat was full, people were standing room only, spilling out into the hallway for several feet. The heavily air-conditioned room couldn’t keep the temperature down with this many people in the room. Dan’s talk did not let down, despite all of the hype and leakage of information from the attack. The highlight for me was the visualization of vulnerable DNS servers turning into patched DNS servers on a global scale. All said and done, kudos to Dan, he found a serious bug and handled it as best he could to try to protect as many people as possible in my opinion.

The next talk I watched was “Return-Oriented Programming: Exploits Without Code Injection”, by Hovav Shacham. The idea with this talk is that you didn’t need to inject your own shellcode and jump to it, and you don’t need to do a return-to-libc into system, etc. The technique takes what already exists in the program to create shellcode. The method for doing this involves linking code snippets together that achieve the intended purpose, which end in ret instructions which will allow the attacker to control the stack to chain together instructions resulting in shellcode, etc.

Because the executed code is stored in memory marked executable, common protections like DEP and W^X are bypassed. Unfortunately, we’re still left to potentially deal with ASLR, but a very interesting talk and possibly useful technique.

After the “Return Oriented Programming” talk I went to watch my good friend Kevin Stadmeyer talk with co-worker Jacob Carlson on FLEX, AMF 3, and BlazeDS. The talk was interesting, and a bit different then a lot of the talks you see at Black Hat. The talk didn’t focus on any one specific vulnerability, it talked more about how you tackle the challenge of assessing FLEX, AMF 3, and BlazeDS. It also provided perspective for developers on what to keep in mind as potential security issues during design and development. Very interesting perspective, something I think the audience in attendance saw as very useful, especially considering the decent amount of questions that came up.

Finally, and most entertaining for the day, was the Pwnie Awards. The ZDNet blog had two Pwnie Award winners this year, myself (along with Rob Carter and Billy Rios) for best client-side bug, and Ryan Naraine, accepting the award on behalf of Kaspersky for best song. This was my first time attending the show, and it was a ton of fun. Judges Mark Dowd, Alex Sotirov, Dave Aitel, Dino Dai Zovi, and Halvar Flake gave Rob Carter, Billy Rios, and I the nod for best client-side bug, although I will say this for the record, it’s likely we got it as a default since Mark was one of the judges. He certainly deserved it for the amazing amount of hoops he jumped through to pull of his exploit.

Look for Day 2 later today, followed by coverage of DEFCON!

[Source: zdnet]

Apple finally ships DNS flaw fix, patches 16 other Mac OS X holes

Apple finally ships DNS flaw fix, patches 16 other Mac OS X holes [ UPDATE: nCircle Andrew Storms reports that the DNS client on the OSX 10.4.11 distribution still has not been patched. ]

Apple has shipped a Mac OS X security update with patches for at least 17 documented vulnerabilities, including a fix for the serious DNS cache poisoning vulnerability reported by hacker Dan Kaminsky.

With Security Update 2008-005, Apple plugs holes that could lead to privilege escalation, denial-of-service, information disclosure and arbitrary code execution attacks.

The update affects Mac OS X Server 10.4, Mac OS X 10.4.11, Mac OS X Server 10.5, and Mac OS X 10.5.4.

[ Microsoft joins ‘patch DNS now’ chant; Apple patch missing ]

Vulnerability details below the fold:

CVE-2008-1447 - BIND: A weakness in the DNS protocol may allow remote attackers to perform DNS cache poisoning attacks. As a result, systems that rely on the BIND server for DNS may receive forged information. This update addresses the issue by implementing source port randomization to improve resilience against cache poisoning attacks. For Mac OS X v10.4.11 systems, BIND is updated to version 9.3.5-P1. For Mac OS X v10.5.4 systems, BIND is updated to version 9.4.2-P1.

CVE-2008-2320 - CarbonCore: A stack buffer overflow exists in the handling of long filenames. Processing long filenames may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.

CVE-2008-2830 - Open Scripting Architecture: A design issue exists in the Open Scripting Architecture libraries when determining whether to load scripting addition plugins into applications running with elevated privileges. Sending scripting addition commands to a privileged application may allow the execution of arbitrary code with those privileges. This update addresses the issue by not loading scripting addition plugins into applications running with system privileges.

CVE-2008-2321 - CoreGraphics: CoreGraphics contains memory corruption issues in the processing of arguments. Passing untrusted input to CoreGraphics via an application, such as a web browser, may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.

CVE-2008-2322 - CoreGraphics: An integer overflow in the handling of PDF files may result in a heap buffer overflow. Viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution.

CVE-2008-2323 - Data Detectors Engine: Viewing maliciously crafted content in an application that uses Data Detectors may lead to a denial of service, but not arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.5.

CVE-2008-2324 - Disk Utility: The “Repair Permissions” tool in Disk Utility makes /usr/bin/emacs setuid. After the Repair Permissions tool has been run, a local user may use emacs to run commands with system privileges. This update addresses the issue by correcting the permissions applied to emacs in the Repair Permissions tool.

CVE-2008-2952 - OpenLDAP: An issue exists in OpenLDAP’s ASN.1 BER decoding. Processing a maliciously crafted LDAP message may trigger an assertion and lead to an unexpected application termination of the OpenLDAP daemon, slapd. This update addresses the issue by performing additional validation of LDAP messages.

CVE-2007-5135 - OpenSSL: A range checking issue exists in the SSL_get_shared_ciphers() utility function within OpenSSL. In an application using this function, processing maliciously crafted packets may lead to an unexpected application termination or arbitrary code execution.

CVE-2008-2051, CVE-2008-2050, CVE-2007-4850, CVE-2008-0599, CVE-2008-0674: PHP is updated to version 5.2.6 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution. Further information is available via the PHP website at http://www.php.net/ PHP version 5.2.x is only provided with Mac OS X v10.5 systems.

CVE-2008-2325 - QuickLook: Multiple memory corruption issues exist in QuickLook’s handling of Microsoft Office files. Downloading a maliciously crafted Microsoft Office file may lead to an unexpected application termination or arbitrary code execution.

CVE-2007-6199, CVE-2007-6200 - rsync: Path validation issues exist in rsync’s handling of symbolic links when running in daemon mode. Placing symbolic links in an rsync module may allow files outside of the module root to be accessed or overwritten. Further information on the patches applied is available via the rsync web site at http://rsync.samba.org.

[Source: zdnet]

Apple looking to hire iPhone hacker

Apple looking to hire iPhone hacker Apple is in the market for someone capable of hacking into the iPhone.

According to this job listing, the company is looking for an iPhone Security Engineer capable of, among other things, developing “proof of concept” attacks on the device’s current security mechanisms.

The successful candidate will be tasked primarily with validating the security architecture for the iPhone.

Some responsibilities:

  • Review and provide feedback on security mechanisms implemented in OS X
  • Provide risk analysis of potential security threats to our embedded products
  • Develop “proof of concept” attacks on the current security mechanisms
  • Come up with new and innovative ways of increasing security while preserving ease-of-use and increasing the quality of the end-user experience.
  • Work cooperatively with other parts of CoreOS on cross-functional technologies and initiatives to enhance security and security policies

[ SEE: Apple caught neglecting iPhone security ]

This moves comes amidst news that the latest versions of iPhone are vulnerable to vulnerabilities that could aid phishing and spamming attacks.

Apple has also been criticized in the past for inordinate delays in shipping iPhone patches, a problem caused mostly because Apple’s agreement with carriers require every minor release is reviewed and approved, a mind-numbingly slow/exhaustive process.

* Photo credit: quinn.anya’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Remote code execution through Intel CPU bugs

Kris Kaspersky, author of numerous books on reverse engineering and software engineering, will be presenting hisKris Kaspersky research on remote code execution through Intel CPU bugs at the upcoming Hack in the Box Security Conference in Malaysia. If his proof of concept code consisting of JavaScript or TCP/IP packet attacks on Intel based machines succeeds, given Intel’s dominant market share on the market the potential outbreak could be enormous since as he claims, the PoC is OS independent, namely all operating systems running Intel chips are said to be vulnerable. Here’s an abstract from his upcoming presentation :

“Intel CPUs have exploitable bugs which are vulnerable to both local and remote attacks which works against any OS regardless of the patches applied or the applications which are running. In this presentation, I will share with the participants the finding of my CPU malware detection research which was funded by Endeavor Security. I will also present to the participants my improved POC code and will show participants how it’s possible to make an attack via JavaScript code or just TCP/IP packets storms against Intel based machine. Some of the bugs that will be shown are exploitable via common instruction sequences and by knowing the mechanics behind certain JIT Java-compilers, attackers can force the compiler to do what they want (for example: short nested loops lead to system crashes on many CPUs). I will also share with the participants my experience in data recovery and how CPU bugs have actually contributed in damaging our hard drives without our knowledge. “

Intel will be keeping an eye on his upcoming research :

“George Alfs, a spokesman for Intel, said he has not yet seen Kaspersky’s research, nor has he spoken to him about it. “We have evaluation teams always looking at issues. We’ll certainly take a look at this one,” said Alfs. “All chips have errata, and there could be an issue that needs to be checked. Possibly. We’d have to investigate his paper.”

BIOS based rootkits are nothing new with John Heasman’s research into Implementing and Detecting a PCI Rootkit, published in 2006. And with the possibility of malware hiding at the lowest possible level already a fact, what will be very interesting to monitor is a universal remote code execution based on chip’s manufacturer. Everything is possible, the impossible just takes a little longer.

[Source: zdnet]

Apple ships (long overdue) iPhone security patches

Apple ships (long overdue) iPhone security patchesFinally, after months of waiting, iPhone users finally get security fixes for a batch of known software vulnerabilities.

The latest iPhone 2.0 and iPod Touch 2.0 update patches at least 13 documented vulnerabilities, including several code execution holes in the Safari (mobile) Web browser. The Safari bug that won the CanSecWest Pwn2Own contest was also patched.

In all, Apple documents eight flaws affecting Safari and another three bugs in WebKit, the open-source browser engine that powers Safari.

[ SEE: Apple caught neglecting iPhone security ]

The update also patches a CFNetwork bug that could lead to spoofing attacks on iPhone and a kernel vulnerability that could cause denial-of-service conditions.

This Apple advisory spells out the risks:

CVE-2008-0050 - A malicious HTTPS proxy server may return arbitrary data to CFNetwork in a 502 Bad Gateway error, which could allow a secure website to be spoofed.

CVE-2008-0177 - An undetected failure condition exists in the handling of packets with an IPComp header. Sending a maliciously crafted
packet to a system configured to use IPSec or IPv6 may cause an unexpected device reset.

CVE-2008-1588 - When Safari displays the current URL in the address bar, Unicode ideographic spaces are rendered. This allows a maliciously crafted website to direct the user to a spoofed site that visually appears to be a legitimate domain.

CVE-2008-1589 - When Safari accesses a website that uses a self-signed or invalid certificate, it prompts the user to accept or reject the
certificate. If the user presses the menu button while at the prompt, then on the next visit to the site, the certificate is accepted with no prompt. This may lead to the disclosure of sensitive information.

CVE-2008-2303 - A signedness issue in Safari’s handling of JavaScript array indices may result in an out-of-bounds memory access. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.

CVE-2006-2783 - Safari ignores Unicode byte order mark sequences when parsing web pages. Certain websites and web content filters attempt to sanitize input by blocking specific HTML tags. This approach to filtering may be bypassed and lead to cross-site scripting when
encountering maliciously-crafted HTML tags containing byte order mark sequences.

CVE-2008-2307 - A memory corruption issue exists in WebKit’s handling of JavaScript arrays. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.

CVE-2008-2317 - A memory corruption issue exists in WebCore’s handling of style sheet elements. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.

CVE-2007-6284 - A memory consumption issue exists in the handling of XML documents containing invalid UTF-8 sequences, which may lead to a denial of service.

CVE-2008-1767 - A memory corruption issue exists in the libxslt library. Viewing a maliciously crafted HTML page may lead to an unexpected application termination or arbitrary code execution.

CVE-2008-1590 - A memory corruption issue exists in JavaScriptCore’s handling of runtime garbage collection. Visiting a maliciously
crafted website may lead to an unexpected application termination or arbitrary code execution.

CVE-2008-1025 - An issue exists in WebKit’s handling of URLs containing a colon character in the host name. Accessing a maliciously crafted URL may lead to a cross-site scripting attack.

CVE-2008-1026 - A heap buffer overflow exists in WebKit’s handling of JavaScript regular expressions. The issue may be triggered via
JavaScript when processing regular expressions with large, nested repetition counts. This may lead to an unexpected application termination or arbitrary code execution. This is Charlie Miller’s Pwn2Own contest vulnerability.

* Image source: nerichards Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Researcher Behind Linux Kernel Flaw Speaks

From Search Security.com:

When a vulnerability researcher discloses a flaw in a widely-used operating system or application, some IT professionals question the motive. Such has been the case with a Linux Kernel flaw that was disclosed last week. Wojciech Purczynski, a researcher with Singapore-based security firm COSEINC, discovered the flaw, and a researcher using the online name “Qaaz” followed it up with attack code. Qaaz declined an interview request, but Purczynski did answer some questions in an email exchange. In this Q&A, he explains how he reported the security hole and why Linux users should take his findings seriously.

For the email interview read on.


Article Link

[Source: Liquidmatrix]