Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Critical Adobe Shockwave flaw affects millions

Adobe’s Shockwave Player contains a critical vulnerability that could be exploited by remote hackers to take complete control of Windows computers, according to a warning from the software maker.

The flaw affects Adobe Shockwave Player 11.5.0.596 and earlier versions. Details from Adobe’s advisory:

This vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected system. Adobe has provided a solution for the reported vulnerability (CVE-2009-1860). This issue was previously resolved in Shockwave Player 11.0.0.465; the Shockwave Player 11.5.0.600 update resolves a backwards compatibility mode variation of the issue with Shockwave Player 10 content. To resolve this issue, Shockwave Player users on Windows should uninstall Shockwave version 11.5.0.596 and earlier on their systems, restart, and install Shockwave version 11.5.0.600, available here: http://get.adobe.com/shockwave/. This issue is remotely exploitable.

Adobe boasts that 450 million Internet-enabled desktops have installed Adobe Shockwave Player.

[Source: zdnet]

Adobe PDF patch released, but only for some

After weeks of swinging and missing on proper response to a gaping security hole in its ever-present PDF Reader software, Adobe has finally shipped a patch but only for some affected users.

On the same day Microsoft issued its scheduled batch of patches, Adobe dropped a security bulletin warning of a “critical” vulnerability in Adobe Reader 9 and Acrobat 9 and earlier versions. However, if you are a user of one of those “earlier versions,” you’ll have to wait at least for another week.

[ SEE: Adobe swings and misses as PDF abuse worsens ]

The Adobe bulletin explains the severity:

  • This vulnerability would cause the application to crash and could potentially allow an attacker to take control of the affected system. There are reports that this issue is being exploited.

Only Adobe Reader 9 and Acrobat 9 is patched.

  • Adobe is planning to make available updates for Adobe Reader 7 and 8, and Acrobat 7 and 8, by March 18. In addition, Adobe plans to make available Adobe Reader 9.1 for Unix by March 25.

ALSO SEE:

Unofficial ‘patch’ for Adobe Reader, Acrobat zero-day

[Source: zdnet]

New study details the dynamics of successful phishing

Can you teach an old employee new phishing protection tricks?

In a recently presented study by the Intrepidus Group, the company behind the PhishMe.com spear phishing awareness service allowing companies to ethically attempt to phish their employees on their way to build security awareness, presents some interesting key findings based on 32 phishing scenarios tested against a total of 69,000 employees around the world. Here they are:

  • 23% of people worldwide are vulnerable to targeted/spear phishing attacks
  • Phishing attacks that use an authoritative tone are 40% more successful than those that attempt to lure people through reward-giving
  • Men and women are both equally susceptible to phishing
  • On an average 60% of corporate employees that were found susceptible to targeted spear phishing responded to the phishing emails within three hours of receiving them
  • People are less cautious when clicking on active links in emails than when they are requested for sensitive data

Metrics are invaluable, but in this case the obsession with metrics can result in more insecurities since it excludes the possibility of blended threats. For instance, last year I was closely monitoring a similar blended Skype phishing campaign, where the cybercriminals (IkbMan) were attempting to optimize the click-through rate of their campaign by serving client-side exploits to the visitors, “just in case” if they find the site suspicious and do not enter any accounting data. For the time being the exploit is served instantly upon visiting the phishing site, however, the possibility for serving it only if the user hasn’t entered anything and is leaving the site is always there.

Considering one of the key points from Intrepidus Group’s study, namely that “People are less cautious when clicking on active links in emails than when they are requested for sensitive data“, a phishing email should be treated as spam, namely (in a perfect world) it shouldn’t be even allowed to reach the employee’s mailbox. Otherwise, it appears that the trade-off for coming up with quality metrics on the current degree of security awareness in regard to phishing, is the potential exposure of the tested population against potential blended threats.

With managed localization services in the sense of dedicated translators of messages to be used in spam, phishing, and malware campaigns already a fact, the cybercrime ecosystem will soon be talking in a native language, and with the increasingly automated phishing tools whose features were once available to a more sophisticated crowd of cybecriminals, now available for free - the future of phishing looks promising.

The only threat that can outpace its growth is the threat posed by the much more efficient and sophisticated financial data targeting tactic of using crimeware targeting each and every E-banking site simultaneously upon successful infection.

[Source: zdnet]

International Kaspersky sites susceptible to SQL injection attacks

According to a security group going under the name of TeamElite, the international sites of Kaspersky Iran (kasperskylabs.ir), Taiwan (web.kaspersky.com.tw) and South Korea (kasperskymall.co.kr) are susceptible to SQL injection attacks, allowing the injection of malicious iFrames and potentially assisting malicious attackers into obtaining sensitive data from the web sites in question.

The group’s analysis comes shortly after the series of posts by a Romanian group of serial pen-testers of security vendors, which discovered similar flaws in the web sites of F-Secure, Symantec, BitDiffender, and Kaspersky USA.

Let’s start from the basics. PR contingency planning in the spirit of total denial is perhaps the worst thing a vendor can do in this case. Despite the fact that these are reseller web sites and are managed by local companies, they still have the license to harness the power of the brand of an information security company, and therefore not demonstrating basic security awareness by taking care of trivial web application vulnerabilities on these sites, can undermine the brand’s integrity and what it stands for at the first place.

From a pragmatic perspective, the licensing company can either exercise pen-testing authority over the locally managed web sites, keep an eye on them through community service warning systems, or introduce obligatory pen-testing before a license is obtained.

Both groups have been notifying the affected vendors according to their posts.

[Source: zdnet]

USAID.gov compromised, malware and exploits served

0The Azerbaijan section at the United States Agency for International Development (azerbaijan.usaid.gov) has been compromised and is embedded with malware and exploits serving scripts approximately around the 1st of March. The malicious script is taking advantage of a series of redirects which are dynamically loading live exploits, or rogue security software and are all currently active. Roger Thompson at AVG Technologies featured a video demonstrating what happens when an unprotected user visits the site.

Let’s dissect the attack, take into consideration the big picture, and bring a skeleton out of the closet — one of the malware’s phone back locations is a domain exclusively used by the Russian Business Network back in January, 2008.

This particular campaign relies on an embedded malicious script that appears to be dynamically creating subdomains within the cybercriminal’s controlled domain. For instance, cs.ucsb.edu.4afad2ceace1e653.should-be .cn/jan10 .cn is where the first redirection in USAID.gov’s attack takes place. From there, the surfer is taken to orderasia .cn/index.php and then to orderasia .cn/iepdf.php?f=old where the exploitation of multiple (patched) Adobe Reader and Acrobat buffer overflows takes place. Upon successful exploitation, a downloader with an improving signatures-based detection rate during the past several hours is served.

It gets even more interesting when the phone back location of the malware fileuploader .cn/check/check.php is revealed. The domain in question was exclusively used by Russian Business Network/customers of the RBN in January, 2008 part of the cybercrime powerhouse’s attempt to throw sand in the eyes of the community by issuing fake account suspended notices whereas the malware campaigns remained active.

USAID.gov’s insecurities appear to be a juicy target for cybercriminals. In 2007, the site’s Tanzanian section was hacked with links redirecting to Zlob malware, followed by another research released the same year putting USAID.gov among some of the key spam doorways which WebmasterWorld analyzed back then.

Moreover, in 2007 cybercriminals indicated their ability and desire to target international governments’ web sites in an attempt to use them as infection vectors in the face of such incidents as the malware embedded French Embassy in Libya; the Syrian Embassy in London; the U.S Consulate in St. Petersburg; the The Dutch Embassy in Moscow; and most recently the Embassy of Brazil in India followed by the Embassy of India in Spain - and the list is prone to expand, that’s for sure.

[Source: zdnet]

Security holes in Apple Time Capsule, AirPort Base Station

Apple has released a firmware update with fixes for three documented security vulnerabilities affecting its Time Capsule and AirPort Base Station products.

The vulnerabilities could lead to denial-of-service or information disclosure attacks via specially crafted packets. Details on the vulnerabilities:

  • CVE-2008-2476 - The IPv6 Neighbor Discovery Protocol implementation does not validate the origin of Neighbor Discovery messages. By sending a maliciously crafted message, a remote user may cause a denial of service, observe private network traffic, or inject forged packets. This update addresses the issue by performing additional validation of Neighbor Discovery messages.
  • CVE-2008-0473 - An out-of-bounds memory access issue exists in the handling of PPPoE discovery packets. By sending a maliciously crafted PPPoE discovery packet, a remote user may be able to cause an
    unexpected device shutdown. This update addresses the issue through improved bounds checking.
  • CVE-2008-3530 - When IPv6 support is enabled, IPv6 nodes use ICMPv6 to report errors encountered while processing packets. An implementation issue in the handling of incoming ICMPv6 “Packet Too Big” messages
    may cause an unexpected device shutdown. This update addresses the issue through improved handling of ICMPv6 messages.

Apple says the update (firmware version 7.4.1) is installed into Time Capsule or AirPort Base Station with 802.11n* via AirPort Utility provided with the device.

[Source: zdnet]

Study: Firefox wins browser time-to-patch race

A new report from Secunia is pouring more gas on the Internet Explorer vs. Mozilla Firefox security debate.

The security alerts aggregator collected and crunched the numbers on security flaws publicly reported — and fixed — by the two vendors and found that Mozilla easily won the time-to-patch race, despite having to respond to almost four times the number of vulnerabilities.

(Table shows window of exploitation for vulnerabilities publicly disclosed in IE and Firefox in 2008. The number of days unpatched are in red for those vulnerabilities that are still unpatched as of Dec. 1, 2008)

On average, according to the Secunia 2008 report (.pdf), Mozilla averaged 43 days to respond to 115 reported Firefox vulnerabilities while Microsoft took 110 days to release patches for 31 Internet Explorer holes.

* Image source: Channy Yun’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Conficker worm to DDoS legitimate sites in March

ets, Browsers, Hackers, Malware......

Tags: Security, Internet Worm, Remote Code Execution, MS08-067, Conficker......

Among the key innovations of the Conficker worm (W32.Downadup) was the pseudo-random domain generation algorithm used for the generation of dynamic command and control locations in order to make it nearly impossible for researchers and the industry to take them down. However, once the domain registration algorithm was successfully reverse engineering, it became possible to measure the estimated number of affected hosts by registering several of the upcoming phone back locations.

What if the Conficker worm suddenly decided that the phone-back locations for March were those of legitimate sites?

According to Sophos, during March, the millions of Conficker infected hosts will attempt to phone back to several legitimate domains, among which is a Southwest Airlines owned wnsux.com, potentially causing a distributed denial of service attack on all of them. Here’s a list of the legitimate domains and dates on which Conficker will attempt to contact/potentially DDoS them:

Music Search Engine - jogli.com on 8th of March
Southwest Airlines - wnsux.com on 13th of March
Women’s Net in Qinghai Province - qhflh.com on 18th of March
Phonetics by Computer - praat.org on 31th of March

In an attempt to mitigate this attack, Southwest Airlines owned wnsux.com domains was modified yesterday and is no longer resolving to a particular IP. However, praat.org is a redirect to the University of Amsterdam’s Institute of Phonetic Sciences and just like qhflh.com and jogli.com is still active.

The reverse engineering of the domain registration algorithm not only made it possible to anticipate the upcoming command and control locations, but also, allowed security companies to pre-register them and lock them under the Conficker Cabal alliance with members such as Microsoft and the ICANN. Moreover, perhaps the most pragmatic mitigation solution implemented on a large scale so far, has been OpenDNS updated Stats System which automatically stops resolving Conficker’s latest domains, a feature which they introduced last month.

For the time being, the Conficker botnet remains in a “stay tuned” mode with the real malicious payload to be delivered at any particular moment. A patch has been available since October, 2008.

Conficker graph courtesy of Microsoft’s Malware Protection Center.

[Source: zdnet]

Opera plugs security holes; adds ASLR, DEP support

Opera plugs security holes, adds anti-exploit mechanisms Opera Software has shipped a high-priority security patch for its flagship Web browser to plug at least three vulnerabilities that expose Windows users to code execution and cross-domain scripting attacks.

The Opera 9.64 upgrade also adds support for DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization), two anti-exploitation mechanisms that helps to limit the damage from malware attacks on the Windows platform.

Opera has only released details on one of the three security vulnerabilities, which was discovered and reported by Google’s Tavis Ormandy.

  • Specially crafted JPEG images can cause Opera to corrupt memory and crash. Successful exploitation can lead to execution of arbitrary code.

Opera said the update also fixes an issue where plug-ins could be used to allow cross domain scripting and a third “moderately severe” issue that remains a mystery.

“Details will be disclosed at a later date,” the company said.

* Image source: andyket’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

PHP plugs security holes

The open-source PHP Group has issued a patch for at least four security flaws in the widely-used general-purpose scripting language.

With PHP 5.2.9 (see changeLog), the PHP development team corrects a total of 50 bugs, including a publicly-known flaw that allows attackers to read the contents of arbitrary memory locations in certain situations.

Here’s the skinny on that issue, which is rated medium-severity:

  • Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.

The other security fixes in PHP 5.2.9 are:

  • Fixed a crash on extract in zip when files or directories entry names contain a relative path. (Pierre)
  • Fixed explode() behavior with empty string to respect negative limit. (Shire)
  • Fixed a segfault when malformed string is passed to json_decode(). (Scott)

ALSO SEE:

Flaw trifecta kicks off Month of PHP Bugs

Controversial ‘month of bugs’ getting security results

[Source: zdnet]

Malware campaign at YouTube uses social engineering tricks

Remember last month’s Google Video search results poisoning attack which was hijacking legitimate YouTube titles in order to acquire potential traffic coming from Google Video? Or the massive comment-spam attack on Digg.com?

It appears that the cybercriminals behind both of these campaigns aren’t giving up just yet, and are currently experimenting with a catchy social engineering attack at YouTube which is once again attempting to serve rogue security software under the disguise of a required media codec.

Here’s how the new campaign looks like.

This time their experiment relies on a new “visual social engineering vector”, a message “Click Here to Join the Club” or “Click Here for Free Porn” is embedded within the legitimate video, with a pointer enticing the user into clicking on the PornTube link right next to it. This novel approach slightly differs from previous campaigns involving fake YouTube sites, or the use of the very same malware links this time basically posted within the comments of a video.

The campaign does suffer from a major weakness, and that’s its adult content which YouTube has already — perhaps automatically — started removing. The fake codecs used in the campaign act as downloaders for rogue security software, with the cybercriminals earning revenue in the process. Moreover, not only are the Google Video, Digg.com’s and this latest campaign launched by the same attackers, but the malware campaigners behind them continue using highly toxic net blocks residing within the Latvian DATORU EXPRESS SERVISS Ltd (zlkon.lv), and the Dutch WORLDSTREAM DBM which makes them fairly easy to keep track of - at least for now.

[Source: zdnet]

Apple catches up on Safari (browser) security

After years of lagging behind on important security features, Apple has finally added a malware-blocker, a phishing filter and support for EV (extended validation) certificates into the latest refresh of its Safari Web browser.

The malware roadblock headlines a list of Safari 4 security features that also includes cookie blocking, private browsing, secure encryption, safe downloads and parental controls.


[ SEE: PayPal: If a browser doesn't have anti-phishing technology (like Safari) ditch it ]

Apple has been heavily criticized in the past for neglecting basic security features in Safari. PayPal CIO Michael Barrett went so far as to suggest that end users should avoid the browser because of the missing protections.

Now, it looks like Apple has finally caught up. According to a source, the crucial malware block is powered by Google’s blacklist of malicious sites and will trigger a warning when a user lands at known malware sites.

Microsoft’s Internet Explorer, Mozilla’s Firefox and Opera all provide the ability to issue similar warnings.

The support for EV-Certs (see right) is also important. This allows Web surfers to easily identify legitimate Web sites and businesses. For sites that have an EV Certificate, Safari 4 will display the site’s name in green on the right side of the address field.

[Source: zdnet]

Heads-up: Critical Adobe Flash Player patch coming

[ UPDATE: Here's the official alert from Adobe with information on the patch. It covers a total of five vulnerabilities and affects Flash Player 10.0.12.36 and earlier ]

Sometime later today, Adobe will issue a patch for at least one critical vulnerability affecting its ubiquitous Flash Player. If you live on the Windows ecosystem, this is a heads-up to pay attention to Adobe’s security updates page and treat this as a high-priority issue.

According to an advisory from iDefense, the company that brokered the disclosure process, the patch will fix a Flash Player vulnerability that could allow an attacker to use rigged Shockwave Flash files to execute arbitrary code with the privileges of the current user.

From the iDefense alert:

  • During the processing of a Shockwave Flash file, a particular object can be created, along with multiple references that point to the object. The object can be destroyed and its associated references removed. However a reference can incorrectly remain pointing to the object. The invalid object resides in uninitialized memory, which the attacker may control to gain arbitrary execution control.

To exploit this vulnerability, iDefense said a targeted user must load a malicious Shockwave Flash file created by an attacker. This can be trivially done via social engineering techniques or injecting content into a compromised, trusted site or advertising network.

  • Utilizing various techniques, an attacker is able to re-allocate and control the memory used by the destroyed object. This allows the attacker to subvert execution when a virtual function is called via the invalid reference.

The flaw was confirmed latest version of Flash Player (9.0.124.0). Previous versions may also be affected. iDefense said it tested exploitation on Windows XP SP3 and Windows Vista SP1.

  • iDefense believe that all platforms supported by Flash Player are affected by this vulnerability, including Linux and MacOS.

Adobe was first notified of this issue last August. The company is currently in the midst of responding to zero-day attacks against bugs in its Adobe Reader and Acrobat products.

[Source: zdnet]

Adobe Reader 9 and Acrobat 9 zero day exploited in the wild

Yesterday, Adobe confirmed the existence of a critical vulnerability affecting Adobe Reader and Acrobat versions 9.0 and earlier, originally detected by the Shadowserver Foundation last week.

The onging targeted attacks have since been confirmed by both, Symantec and McAfee urging users to disable JavaScript in Adobe Reader and Acrobat until Adobe issues a patch on the 11th of March in the following way - Click: Edit -> Preferences -> JavaScript and uncheck Enable Acrobat JavaScript.

Symantec’s comments on the potential for massive attacks using the exploit:

So far, these attacks appear to be targeted and not widespread. Symantec is continuing to monitor the vulnerability’s use in the wild.

While examining the JavaScript code used for “heap-spraying” in these PDFs, we can see the same comments that show that these separate exploit attempts come from the same source! It seems likely that the people behind this threat are using targeted attacks against high-ranking people within different organizations—for example, locating the CEO’s email address on the company website and sending a malicious PDF in the hope that their malicious payload will run. Once the machine is compromised, the attackers may gain access to sensitive corporate documents that could be costly for companies breached by this threat.

For the time being, cybercriminals chose to generate less noise by launching targeted attacks just like they did earlier this week using IE7’s MS09-002 vulnerability. However, as we’ve previously seen it’s only a matter of time until copycat attackers start using it on a large scale.

With several targeted campaigns currently active, what are the chances that a sample malware campaign would be once again monetizing infected hosts by infecting them with rogue security software similar to Conficker’s first release? Huge.

Upon analyzing the binary served once an infected host gets successfully exploited from a sample campaign, it’s attempting to trick the user into install the very latest rogue security software Spyware Protect 2009. The cute part is that the cybercriminals didn’t manage to successfully configure their campaign resulting in a 404 error.

What’s important to point out is that the original targeted attacks detected by the Shadowserver Foundation are once again using a well known and previously abused Chinese DNS provider (js001.3322.org) with more details about its owner available in a related BusinessWeek article.

[Source: zdnet]

New Symbian-based mobile worm circulating in the wild

F-Secure and Fortinet are investigating a newly discovered mobile malware identified as SymbOS/Yxes.A!worm or “Sexy View”. The malware is affecting S60 3rd Edition series devices, and has a valid certificate signed by Symbian tricking the mobile device user into thinking it’s a legitimate application. In terms of propagation, “Sexy View” propagates by collecting all the phone numbers from the infected device, and then SMS-es itself to all of them including a link to a web site hosting a copy of it.

SymbOS/Yxes.A!worm is the second mobile malware detected in the wild for 2009, followed by last month’s discovery of Trojan-SMS.Python.Flocker by Kaspersky Labs. A trend, a fad, or opportunists experimenting for mobile malware’s prime time in 2009?

Using spam and phishing as analogies, both, spammers and phishers require huge databases of harvested email address in order to hit them directly. What used to be old-fashioned directory attacks where they were attempting to guess user names and associate them with email boxes, is today’s greatly matured underground market segment offering millions of segmented (on per country, city, industry, email provided basis) emails which cybecriminals easily integrate within their campaign management kits.

What’s particularly interesting about SymbOS/Yxes.A!worm is that it appears that the worm’s main objective is to harvest information from the infected devices such as phone numbers, IMEI, IMSI as well as the phone type. This data harvesting approach is pretty similar to that of email harvesting tools, and in the long term the harvested data will be monetized and resold to phone scammers whose activities are already driving the success of such site as WhoCallsme? and 800notes.

Moreover, Guillaume Lovet, a senior manager of Fortinet’s Threat Research Team is also speculating on the potential for a mobile botnet due to the ways in which Yxes.A!worm spreads: “As far as our analysis goes, the worm currently does not take commands from the remote servers it contacts. However, since the copies hosted on the malicious servers are controlled by the cyber criminals, they may update them whenever they want, thereby effectively mutating the worm, adding or removing functionality. We’re really at the edge of a mobile botnet here.”

With carriers, manufacturers, and service providers clearly aware of the emerging mobile malware threat, thankfully, they seem to be thinking in the right direction - according to McAfee’s 2009’s Mobile Security Report, when asked “Who Should Bear the Cost of Securing Mobile Devices?” 44% of the mobile device manufacturers forwarded the responsibility to themselves instead of their clients.

In times when your mobile number and physical location for a successful scam targeting is prone to become a valuable good in the underground economy, your vigilance remains a cost-effective solution.

[Source: zdnet]

Microsoft: ‘Consistent exploit code likely’ for IE vulnerabilities

Microsoft today shipped four bulletins with patches for at least 8 documented security vulnerabilities affecting Windows users and warned that “consistent exploit code could be easily crafted” to launch attacks via the Internet Explorer browser.

The Patch Tuesday batch includes fixes for a pair of code execution holes in IE, two bugs in the Microsoft Exchange Server, a remote code execution issue in the Microsoft SQL Server, and three separate flaws haunting users of Microsoft Office Visio.

The Internet Explorer bulletin (MS09-002) should be treated with urgency because the flaws can be exploited to launch drive-by download attacks.

  • This security update is rated Critical for Internet Explorer 7 running on supported editions of Windows XP and Windows Vista. For Internet Explorer 7 running on supported editions of Windows Server 2003 and Windows Server 2008, this security update is rated Moderate.

The Microsoft warning that consistent exploit code was likely suggests that it’s very easy for an attacker to host a specially crafted Web site and attack unpatched users who surfed to the rigged Web site.

  • The attacker could also take advantage of compromised Web sites and Web sites that accept or host user-provided content or advertisements. These Web sites could contain specially crafted content that could exploit this vulnerability.

Enterprise administrators will also want to pay special attention to the Microsoft Exchange update (MS09-003) which covers two different vulnerabilities that expose users to code execution or denial-of-service attacks.

Microsoft explains:

  • The first vulnerability could allow remote code execution if a specially crafted TNEF message is sent to a Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could take complete control of the affected system with Exchange Server service account privileges. The second vulnerability could allow denial of service if a specially crafted MAPI command is sent to a Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could cause the Microsoft Exchange System Attendant service and other services that use the EMSMDB32 provider to stop responding.

The company says it expects to see “inconsistent exploit code” published for this bulletin. However, nCircle director of security operations Andrew Storms says this is a very serious problem.

“This vulnerability means that any cybercriminal sending a well crafted email attachment to an enterprise could gain complete control over the server and gaining one of the keys to the kingdom,” Storms said.

“All kinds of highly confidential and proprietary information pass through an Exchange server every day. Gaining control over it and its content would be a gold mine to any cyber criminal,” he added.

[Source: zdnet]

Targeted malware attacks exploiting IE7 flaw detected

Researchers at TrendMicro have detected a targeted malware attack exploiting last week’s patched critical MS09-002 vulnerability affecting Internet Explorer 7. Upon opening the spammed Microsoft office document, vulnerable users are automatically forwarded to a Chinese live exploit site which still remains active.

The attack has also been confirmed by McAfee and by the ISC, who point out that the cybercriminals appear to have reverse engineered Microsoft’s patch in order to come up with the exploit.

From TrendMicro’s post:

The threat starts with a spammed malicious .DOC file detected as XML_DLOADR.A. This file has a very limited distribution script, suggesting it may be a targeted attack. It contains an ActiveX object that automatically accesses a site rigged with a malicious HTML detected by the Trend Micro Smart Protection Network as HTML_DLOADER.AS.

HTML_DLOADER.AS exploits the CVE-2009-0075 vulnerability, which is already addressed by the MS09-002 security patch released last week. On an unpatched system though, successful exploitation by HTML_DLOADER.AS downloads a backdoor detected as BKDR_AGENT.XZMS.

This backdoor further installs a .DLL file that has information stealing capabilities. It sends its stolen information to another URL via port 443.

The attackers trade-off in this case is to either launch a less noisy targeted attack, or attempt to target as many users as possible by using legitimate web sites as infection vectors, a choice that depends on what they’re trying to achieve, and who are they targeting in particular.

Who’s behind the attack anyway? The web service (9966.org) used as a “phone back” location with the stolen data, is a well known one used primarily by Chinese hackers in previous massive SQL injections attacks, which doesn’t necessarily mean the campaign is launched by Chinese hackers, since it could be international hackers from anywhere using a well known malicious infrastructure in order to forward the responsibility to local hackers.

Moreover, in this particular campaign I can easily argue that the window of opportunity for abusing this vulnerability in a targeted fashion, is just as wide open as attempting to exploit the same hosts by diversifying the use of different exploits. For instance, despite the timely exploitation of MS09-002, based on the number of Conficker affected hosts globally, a situation where once again a patch is present, there’s a great chance that some of the hosts they’re attempting to exploit through the use of MS09-002 are already part of Conficker’s botnet, or remain susceptible to outdated vulnerabilities.

So far, no massive malware campaigns are taking advantage of the exploit, but users are advised to self-audit themselves against known client-side vulnerabilities and MS09-002 in particular.

[Source: zdnet]

Crimeware tracking service hit by a DDoS attack

A week after a newly launched crimeware tracking service went public, cybercriminals didn’t hesitate to prove its usefulness by launching a distributed denial of service attack (DDoS) against it. According to the Swiss security blog, the Zeus tracker came under attack from a previously known source that also attacked abuse.ch over an year ago taking advantage of a well known do-it-yourself DDoS malware.

Just like November 2008’s DDoS attack against the anti-fraud site Bobbear.co.uk — with evidence that the attack was commissioned provided by Zero Day back then — the single most evident proof of the usefulness of your cybercrime tracking service always comes in the form of a direct attack against its availability.

What is the Zeus Tracker anyway, and why is it so special at the first place?

The Zeus Tracker is a full-disclosure project keeping track of known Zeus hosting locations, one of the most ubiquitous crimeware applications cybercriminals take advantage of for years. Moreover, by maintaining a real-time blocklist that allows the community to easily take action against known Zeus domains/IPs it shouldn’t come as a surprise that the service is getting attacked - simply because it exposes active crimeware campaigns.

Once available as a proprietary crimeware tool costing several thousands dollars, today, pirated copies of Zeus are so prevalent, that most of the innovations attempting to to improve its usefulness and abilities to sniff E-banking transaction data come from third parties in a true open source crimeware fashion. In fact, the Zeus crimeware is so popular that cybercriminals themselves are looking for and successfully finding remotely exploitable vulnerabilities within the kit in an attempt to hijack someone else’s botnet.

Moreover, with or without the Zeus Tracker’s real-time data, the Zeus malware is prone to continue dominating the crimeware landscape due to its maturity into a cybercrime-as-a-service proposition. For instance, the increasing number of services offering managed Zeus botnets not only allow less sophisticated cybercriminals easy access to hundreds of thousands of banker malware infected hosts, but also, the relatively low prices the services charge due to the fact that they’re running pirated copies of Zeus ultimately results in the scalability of cybercrime in general.

Attempting to undermine this scalability would mean coming up with ways to shorten the average time a Zeus command and control domain/IP remains online, next to communicating the already known locations as a public service just like the Zeus Tracker does.

[Source: zdnet]

Should Microsoft decouple IE from Patch Tuesday?

A security researcher wants Microsoft to follow the lead of other browser makers and start fixing Internet Explorer security problems outside of the Patch Tuesday cycle to help contain the Windows malware epidemic.

[ Microsoft: ‘Consistent exploit code likely’ for IE vulnerabilities ]

According to Wolfgang Kandek, chief technology officer at vulnerability management firm Qualys, IE’s dominant userbase and high risk profile exposes Windows users to a wide range of malicious hacker attacks but, despite years of warnings, business users are not rushing to install IE patches ahead of other critical updates (see chart below).


[ SEE: Hackers exploiting (unpatched) IE 7 flaw to launch drive-by attacks ]

The chart, powered by data collected by Qualys over the last six months, shows that critical IE patches are applied in very much the same speed as other high-priority updates.

I had a chat with Kandek about his findings and he was adamant that the risk presented by a critical IE vulnerability is higher than another critical flaw in another piece of software that doesn’t interact directly with the Internet.

  • “Every month when Microsoft issues it security advisories we get asked what patch to apply first. Typically we are reluctant to elevate one vulnerability over the other, however looking at the 2008 data we agree that Internet Explorer vulnerabilities should be given the highest priority and patched first. The browser is the heaviest used software application that interacts with the Internet, the most likely source of malicious content. It is not only used for professional purposes but also in private interactions – e-commerce, social networking, private e-mail, etc. Browser patches are heavily tested by Microsoft and unlikely to break any existing functionality on the desktop.

Unfortunately, Kandek says the vulnerability data shows that companies treat browser patches just like all other patches — their deployment cycle correlates very closely with other critical patches.

The answer? Kandek argues that Microsoft should borrow from the Mozilla Firefox playbook and fit an automatic-update utility directly into IE to handle patching on the fly.

“Think about it. There’s a very big exposure area. Hackers are increasingly targeting the browser. Enterprises are on a tight patch schedule. If IE got moved out of Patch Tuesday, won’t it be better?” he added.

[ GALLERY: How to configure Internet Explorer to run securely ]

“Patches would be deployed faster and we would have a healthier IE population,” Kandek added, nothing that IE add-ons like Flash and other media players would benefit from an automatic update tool embedded in the browser.

The Qualys data was culled from 9.5 million IP scans per month.

* Hat tip to Gregg Keizer at ComputerWorld.

[Source: zdnet]

Massive comment spam attack on Digg.com leads to malware

According to PandaSecurity, the social news site Digg.com is among the very latest Web 2.0 services to be targeted by cybecriminals on their way to acquire legitimate traffic to their malware serving domains. The ongoing attack is far more widespread the originally stated, with +500,000 bogus comments

leading to 15 currently active malware domains, where the end user is enticed to install a fake video codec in order to view the video. Once executed, the codec attempts to trick the user that they’re infected with malware, and in order to get rid of it, a rogue security software has to be purchased.

Despite the obvious similarities with last month’s Google Video keywords poisoning attack, the comment-spam campaign at Digg.com is unique in the sense that it appears to have been active for over an year now. Let’s dissect the campaign, and explain how it works.

The cybercriminals are taking advantage of on purposely registrated bogus accounts, in a combination with compromised legitimate accounts to not only post Digg stories directly leading to malware, but also, to heavily comment on legitimate and bogus stories by posting even more malware-serving links.

So basically, you have a catchy title submitted through a bogus account, with a miltitude of bogus accounts commenting on it, and linking to more malware serving domains. Or exactly the opposite - bogus accounts commenting on legitimate stories since January, 2008. This practice of self-recommendation greatly reminds me a similar Ebay bot talk scheme back in 2006, where bogus accounts were automatically giving positive recommendation to fraudulent accounts, all operated by the same person/gang.

Interestingly, just like in Google’s keywords poisoning campaign, no client-side vulnerabilities are used. Instead, the cybecriminals are entirely relying on the end user to download and execute the codec on their way to view the video.

Digg.com’s abuse department has already been notified of all the related malware domains used across the site.

UPDATE: The following is a complete list of the malware domains used within the comments posted at Digg.

[Source: zdnet]