Showing posts with label Metasploit. Show all posts
Showing posts with label Metasploit. Show all posts

Emergency Adobe Flash Player patch coming today


Less than a week after warning that hackers were embedding malicious Flash Player files (.swf) into Microsoft Word documents to launch targeted malware attacks, Adobe plans to release an emergency Flash Player patch today to fix the underlying problem.

The patch will fix a “critical” vulnerability in Flash Player 10.2.153.1 and earlier versions for Windows, Mac OS X Linux and Solaris.

According to this Secunia advisory, the flaw allows a hacker to completely hijack a vulnerable Windows computer:

A vulnerability has been reported in Adobe Flash Player, which can be exploited by malicious people to compromise a user’s system.

The vulnerability is caused due to an error when parsing ActionScript that adds a custom function to the prototype of a predefined class. This results in incorrect interpretation of an object (i.e. object type confusion) when calling the custom function, which causes an invalid pointer to be dereferenced.

Secunia has posted a technical analysis of the flaw as well.

Adobe has confirmed that the vulnerability (CVE-2011-0611) could cause a crash and potentially allow an attacker to take control of the affected system.

There are reports that this vulnerability is being exploited in the wild in targeted attacks via a malicious Web page or a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an email attachment, targeting the Windows platform. At this time, Adobe is not aware of any attacks via PDF targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.

A patch for Google Chrome users is already available in Chrome version 10.0.648.205.

Adobe plans to fix the vulnerability in Adobe Acrobat and Adobe Reader at a later date.

[Source: zdnet]

Metasploit's HD Moore releases 'war dialing' tools

HD Moore wants to simplify pen-testing and simulated hacking attacks against telephone systems.

The Metasploit founder has released WarVOX as a free suite of tools to explore, classify and audit a range of telephone systems, including modems, faxes, voicemail boxes, PBXs, loops, dial tones, IVRs and forwarders.

Moore explains:

  • WarVOX requires no telephony hardware and is massively scalable by leveraging Internet-based VoIP providers. A single instance of WarVOX on a residential broadband connection, with a typical VoIP account, can scan over 1,000 numbers per hour. The speed of WarVOX is limited only by downstream bandwidth and the limitations of the VoIP service. Using two providers with over 40 concurrent lines we have been able to scan entire 10,000 number prefixes within 3 hours.
  • The resulting call audio can be used to extract a list of modems that can be fed into a standard modem-based wardialing application for fingerprinting and banner collection. One of the great things about the WarVOX model is that once the data has been gathered, it is archived and available for re-analysis as new signatures, plugins, and tools are developed. The current release of WarVOX (1.0.0) is able to automatically detect modems, faxes, silence, voice mail boxes, dial tones, and voices.

Moore hopes WarVOX can replace the “slow and inefficient” systems currently in place to identify security holes in phone systems.

This presentation (.pdf) covers the motivation behind the tools and the implementation details.

[Source: zdnet]

Exploit published for Windows worm hole

Exploit published for Windows worm holeReliable exploit code for the remote code execution vulnerability patched with Microsoft’s MS08-067 update has been posted to the Internet, prompting a new “patch immediately” advisory from the Redmond software maker.

The exploit, which has been added to the freely available Metasploit point-and-click attack tool, provides a roadmap for code execution on Windows 2000, Windows XP, and Windows Server 2003. A second exploit has been posted to Milw0rm.com, increasing the likelihood of in-the-wild malware attacks.

[ SEE: MS ships emergency patch for Windows worm hole ]

From the Microsoft advisory:

  • Our investigation of this exploit code has verified that it does not affect customers who have installed the updates detailed in MS08-067 on their computers. Microsoft continues to recommend that customers apply the updates to the affected products by enabling the Automatic Updates feature in Windows.

Several proof-of-concepts have also been publicly released.

Microsoft shipped an out-of-band update last week to plug the hole after discovering “limited, targeted attacks” against Windows users. The attacks included the use of reconnaissance Trojans hijacking sensitive system information.

The vulnerability is due to the Windows Server service not properly handling specially crafted RPC requests. The vulnerable Windows Server service provides RPC support, file and print support, and named pipe sharing over the network. It is also used to allow the sharing of your local resources (such as disks and printers) so that other users on the network can access them.

[Source: zdnet]

MS Patch Tuesday heads-up: 11 bulletins, 4 critical

11 bulletins, 4 criticalIt will be a very busy Patch Tuesday for administrators managing Microsoft Windows computer systems.

According to Microsoft’s advance notice mechanism, 11 security bulletins will drop next Tuesday (October 14, 2008), covering a wide range of serious vulnerabilities.

Four of the 11 bulletins are rated “critical,” meaning that those vulnerabilities can be exploited to launch remote, code execution attacks.


[ SEE: Microsoft makes daring vulnerability sharing move ]

The four “critical” bulletins apply to the widely deployed Internet Explorer browser, Active Directory, Microsoft Excel and Host Integration Server.

Six of the bulletins will be rated “important” and will provide fixes for a range of Microsoft Windows operating system vulnerabilities.

The final bulletin, rated “moderate,” will provide patches for an information disclosure bug in Microsoft Office.

This month will see the first appearance of the previously announced Exploitability Index, a new Microsoft initiative aimed at attempting predictions on whether exploit code will be released.

This index will attempt to predict if a vulnerability is likely to have functioning exploit code released, or have inconsistent exploit code released that wouldn’t work every time an attacker attempted to used it. We’ll even highlight vulnerabilities where we think it’s unlikely that functioning exploit code will ever be released.

Starting this month, Microsoft will also start sharing details on software vulnerabilities with security vendors ahead of Patch Tuesday under a new program aimed at reducing the window of exposure to hacker attacks.

The new Microsoft Active Protections Program (MAPP) will give anti-virus, intrusion prevention/detection and corporate network security vendors a headstart to add signatures and filters to protect against Microsoft software vulnerabilities.

* Image source: jeffwilcox’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Critical WMP, MS Office bugs on Patch Tuesday swat list

WMP, Office, Windows bugs on Patch Tuesday swat listMicrosoft today announced plans to ship four security bulletins next Tuesday (September 9, 2008) to cover worm holes affecting Windows users.

All four bulletins in September’s Patch Tuesday will be rated “critical,” Microsoft’s highest severity rating. A “critical” rating is used to rate a vulnerability that can be exploited to allow the propagation of an Internet worm without any user action.

Here’s the skinny on what’s coming:
According to the company’s advance notice, the four bulletins will include patches for software flaws in Windows Media Player 11, the Windows Media Encoder, Microsoft Office and several components on the Windows operating system.

All the bulletins address “remote code execution” vulnerabilities:

Windows Media Player Bulletin (Impact: Remote Code Execution)

  • Windows Media Player 11 on Windows XP Service Pack 2 and Windows XP Service Pack 3
  • Windows Media Player 11 on Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
  • Windows Media Player 11 on Windows Vista and Windows Vista Service Pack 1
  • Windows Media Player 11 on Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1
  • Windows Media Player 11 on Windows Server 2008 for 32-bit Systems (Windows Server 2008 Server Core installation not affected)
  • Windows Media Player 11 on Windows Server 2008 for x64-based Systems (Windows Server 2008 Server Core installation not affected)

Windows Bulletin (Impact: Remote Code Execution)

  • Microsoft Internet Explorer 6 on Microsoft Windows 2000 Service Pack 4
  • Microsoft .NET Framework 1.0 Service Pack 3 on Microsoft Windows 2000 Service Pack 4
  • Microsoft .NET Framework 1.1 Service Pack 1 on Microsoft Windows 2000 Service Pack 4
  • Microsoft .NET Framework 2.0 on Microsoft Windows 2000 Service Pack 4
  • Microsoft .NET Framework 2.0 Service Pack 1 on Microsoft Windows 2000 Service Pack 4
  • Windows XP Service Pack 2 and Windows XP Service Pack 3
  • Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
  • Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
  • Windows Server 2003 x64 Edition and Windows 2003 Server x64 Edition Service Pack 2
  • Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium based Systems
  • Windows Vista and Windows Vista Service Pack 1
  • Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1
  • Windows Server 2008 for 32-bit Systems (Windows Server 2008 Server Core installation not affected)
  • Windows Server 2008 for x64-based Systems (Windows Server 2008 Server Core installation not affected)
  • Windows Server 2008 for Itanium-based Systems
  • Microsoft Office XP Service Pack 3
  • Microsoft Office 2003 Service Pack 2
  • 2007 Microsoft Office System
  • Microsoft Visio 2002 Service Pack 2
  • Microsoft Office PowerPoint Viewer 2003
  • Microsoft Works 8
  • Microsoft Digital image Suite 2006
  • QFE update for SQL 2000 Reporting Services Service Pack 2 when installed on Microsoft Windows 2000 Service Pack 4
  • GDR update for SQL Server 2005 Service Pack 2
  • QFE update for SQL Server 2005 Service Pack 2
  • GDR update for SQL Server 2005 x64 Edition Service Pack 2
  • QFE update for SQL Server 2005 x64 Edition Service Pack 2
  • GDR update for SQL Server 2005 for Itanium-based Systems Service Pack 2
  • QFE update for SQL Server 2005 for Itanium-based Systems Service Pack 2
  • Microsoft Visual Studio .NET 2002 Service Pack 1
  • Microsoft Visual Studio .NET 2003 Service Pack 1
  • Microsoft Visual Studio 2005 Service Pack 1
  • Microsoft Visual Studio 2008
  • Microsoft Report Viewer 2005 Service Pack 1 Redistributable Package when installed on Microsoft Windows 2000 Service Pack 4
  • Microsoft Report Viewer 2008 Redistributable Package when installed on Microsoft Windows 2000 Service Pack 4
  • Microsoft Visual FoxPro 8.0 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4
  • Microsoft Visual FoxPro 9.0 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4
  • Microsoft Visual FoxPro 9.0 Service Pack 2 when installed on Microsoft Windows 2000 Service Pack 4
  • Microsoft Platform SDK Redistributable: GDI+
  • Microsoft Forefront Client Security 1.0 when installed on Microsoft Windows 2000 Service Pack 4

Windows Media Encoder Bulletin (Impact: Remote Code Execution)

  • Windows Media Encoder 9 Series on Microsoft Windows 2000 Service Pack 4
  • Windows Media Encoder 9 Series on Windows XP Service Pack 2 and Windows XP Service Pack 3
  • Windows Media Encoder 9 Series on Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
  • Windows Media Encoder 9 Series x64 Edition on Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
  • Windows Media Encoder 9 Series on Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
  • Windows Media Encoder 9 Series on Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2
  • Windows Media Encoder 9 Series x64 Edition on Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2
  • Windows Media Encoder 9 Series on Windows Vista and Windows Vista Service Pack 1
  • Windows Media Encoder 9 Series on Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1
  • Windows Media Encoder 9 Series x64 Edition on Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1
  • Windows Media Encoder 9 Series on Windows Server 2008 for 32-bit Systems (Windows Server 2008 Server Core installation not affected)
  • Windows Media Encoder 9 Series on Windows Server 2008 for x64-based Systems (Windows Server 2008 Server Core installation not affected)
  • Windows Media Encoder 9 Series x64 Edition on Windows Server 2008 for x64-based Systems (Windows Server 2008 Server Core installation not affected)

Office Bulletin (Impact: Remote Code Execution)

  • Microsoft Office XP Service Pack 3
  • Microsoft Office 2003 Service Pack 2
  • Microsoft Office 2003 Service Pack 3
  • 2007 Microsoft Office System
  • 2007 Microsoft Office System Service Pack 1
  • Microsoft Office OneNote 2007
  • Microsoft Office OneNote 2007 Service Pack 1
[Source: zdnet]

Linux under attack: Compromised SSH keys lead to rootkit

Compromised SSH keys leads to rootkitThe U.S. Computer Emergency Readiness Team (CERT) has issued a warning for what it calls “active attacks” against Linux-based computing infrastructures using compromised SSH keys.

The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as “phalanx2″ is installed, US-CERT said in a note on its current activity site.

From the advisory:

  • Phalanx2 appears to be a derivative of an older rootkit named “phalanx”. Phalanx2 and the support scripts within the rootkit, are configured to systematically steal SSH keys from the compromised system. These SSH keys are sent to the attackers, who then use them to try to compromise other sites and other systems of interest at the attacked site.

Phalanx, which dates back to 2005, is a self-injecting kernel rootkit designed for the Linux 2.6 branch. It allows an attacker to hide files, processes and sockets and includes a tty sniffer, a tty connectback-backdoor, and auto injection on boot.

Details on the attacks — and targets — remain scarce but it’s a safe bet this is linked to the Debian random number generator flaw that surfaced earlier this year. A working exploit for that vulnerability is publicly available.

To mitigate the risk from this attack, US-CERT recommends:

  • Proactively identify and examine systems where SSH keys are used as part of automated processes. These keys will typically not have passphrases or passwords.
  • Encourage users to use the keys with passphrase or passwords to reduce the risk if a key is compromised.
  • Review access paths to internet facing systems and ensure that systems are fully patched.

If a compromise is confirmed, US-CERT recommends:

  • Disable key-based SSH authentication on the affected systems, where possible.
  • Perform an audit of all SSH keys on the affected systems.
  • Notify all key owners of the potential compromise of their keys.

* Image source: wili_hybrid’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

DEFCON 16: List of tools and stuff released

Defcon 16 tools and utilities

DEFCON, the 9000+ attendee hacker conference in Vegas has become a sort of hydra conference. It has become more like a global fair than what most people think of conferences; even the badge is highly unique.

I say this because there are so many things to do at DEFCON, other than going to talks, that you could spend your whole weekend looking at the “World’s Largest Boar!”, so to speak. One of the CTF (Capture the Flag) contest winners this year actually exclaimed that he only made it to 2 talks in 12 years! I am also one of those individuals who barely get a chance to go to talks and now that the speaker pool is so diverse, it’s hard to find all of the “stuff” they release.

Before anyone has a chance to post “it’s all on the DEFCON CD dummy,” I want to challenge them to try. After a weekend of googling (which came back with few results) and making contact with some of the speakers, I provide you with a mostly accurate list of “stuff” that was released at DEFCON this year. If any of the information is inaccurate, or a tool is missing, please contact me and I will update this post.

Beholder – by Nelson Murilo and Luis Eduardo

  • Description: An open source wireless IDS program
  • Homepage Link: http://www.beholderwireless.org/
  • Email Address: bh@beholderwireless.org
  • The Middler – by Jay Beale

  • Description: The end-all be-all of MITM tools
  • Homepage Link: http://www.themiddler.com/ (Online?)
  • Preface Link: http://www.intelguardians.com/themiddler.html
  • ClientIPS – by Jay Beale

  • Description: An open source inline “transparent” client-side IPS
  • Homepage Link: http://www.ClientIPS.org/ (Online?)
  • Marathon Tool – by Daniel Kachakill

  • Description: A Blind SQL Injection tool based on heavy queries
  • Download Link: DEFCON 16 CD. No online link found.
  • Email Address: dani@kachakil.com
  • The Phantom Protocol – by Magnus Brading

  • Description: A Tor-like protocol that fixes some of Tor’s major attack vectors
  • Homepage Link: http://code.google.com/p/phantom
  • Email Address: brading@fortego.se
  • ModScan – by Mark Bristow

  • Description: A SCADA Modbus Network Scanner
  • Homepage Link: http://modscan.googlecode.com/
  • Email Address: mark.bristow@gmail.com
  • Grendel Scan – by David Byrne

  • Description: Web Application scanner that searches for logic and design flaws as well as the standard flaw seen in the wild today (SQL Injection, XSS, CSRF)
  • Homepage Link: http://grendel-scan.com/
  • iKat – interactive Kiosk Attack Tool (This site has an image as a banner that is definitely not safe for work! – You have been warned) by Paul Craig

  • Description: A web site that is dedicated to helping you break out of Kiosk jails
  • Homepage Link: http://ikat.ha.cked.net
  • Email Address: paul.craig@security-assessment.com
  • DAVIX – by Jan P. Monsch and Raffael Marty

  • Description: A SLAX based Linux Distro that is geared toward data/log visualization
  • Homepage Link: http://code.google.com/p/davix/
  • Download Link: http://www.geekceo.com/davix/davix-0.5.0.iso.gz
  • Email Addresses: jan.monsch@iplosion.com and raffy@secviz.org
  • CollabREate – by Chris Eagle and Tim Vidas

  • Description: An IDA Pro plugin with a server backend that allows multiple people to collaborate on a single RE (reverse engineering) project.
  • Homepage Link: http://www.idabook.com/defcon
  • Email Addresses: cseagle@gmail.com and tvidas@gmail.com
  • Dradis – by John Fitzpatrick

  • Description: A tool for organizing and sharing information during a penetration test
  • Homepage: http://dradis.sourceforge.net
  • Email Address: john.fitzpatrick@mwrinfosecurity.com
  • Squirtle – by Kurt Grutzmacher

  • Description: A Rouge Server with Controlling Desires that steals NTLM hashes.
  • Homepage: http://code.google.com/p/squirtle (Live?)
  • Email Address: grutz@jingojango.net
  • WhiteSpace – by Kolisar

  • Description: A script that can hide other scripts such as CSRF and iframes in spaces and tabs
  • Download Link: DEFCON 16 CD
  • VoIPer – by nnp

  • Description: VoIP automated fuzzing tool with support for a large number of VoIP applications and protocols
  • Homepage Link: http://voiper.sourceforge.net/
  • Barrier – by Errata Security

  • Description: A browser plugin that pen-tests every site that you visit.
  • Homepage Link: http://www.erratasec.com
  • Email Address: sales@erratasec.com
  • Psyche – by Ponte Technologies

  • Description: An advanced network flow visualization tool that is not soley based on time.
  • Homepage Link: http://psyche.pontetec.com/
  • * Rob Fuller is a security researcher and pen-tester. He can be found on Twitter and in Room 362.

    [Source: zdnet]

    Adobe Flash ads launching clipboard hijack attack

    Clipboard hijackMalicious hackers are using booby-trapped Flash banner ads to hijack clipboards for use in rogue security software attacks.

    In the Web attacks, which target Mac, Windows and Linux users running Firefox, IE and Safari, hackers are seizing control of the machine’s clipboard and using a hard-to-delete URL that points to a fake anti-virus program.

    According to victims on several Web forums, the attack is coming from Adobe Flash-based advertising on legitimate sites — including Newsweek, Digg and MSNBC.com.

    Here is a Mac OS X user explaining the attack:

    This has happened to me twice now, on two separate computers at work. My clipboard has been hijacked with this:

    [ malicious URL deleted ]

    And once it’s in the clipboard, I can’t copy anything else over it until I’ve restarted the machine.

    I’m only going to websites that are directly linked off the main page of digg.com, so they’re not obscure, and I’m surfing in firefox, though the system wide clipboard is getting taken over, so I can’t even copy something over that from a program like TextEdit.

    The 5th post on this MSNBC.com forum shows what happens when a victim is tricked into pasting — and spamming — the malicious link to help spread the rogue security software.

    Security researcher Aviv Raff has created a proof-of-concept demo to show how easy it is to use Flash with ActionScript code to load (persistently) a malicious URL into a target clipboard. (BEWARE: If you click on the demo link, your clipboard is automatically hijacked and will only be released if the browser window is closed).

    [Source: zdnet]

    From Metasploit to Microsoft: Skape goes to Redmond

    Skape goes to RedmondMetasploit developer Matt Miller, who for years frustrated Microsoft officials with the public release of Windows exploits, is heading to Redmond to join Microsoft’s Security Science team.

    Miller, who uses the hacker moniker Skape,will work on improved ways to find security vulnerabilities and better software defenses through mitigations, according to an announcement by SDL guru Michael Howard.

    “Matt brings a massive amount of real-world exploit and defense experience to our team,” Howard said, nothing that Miller has been focused on design review for Windows 7, the next major revision of the operating system.

    [ SEE: Hacking with Metasploit on a Nokia N800 ]

    Miller’s work around exploiting — and attempting to secure — the Windows ecosystem is legendary. In tandem with HD Moore, he has been one of the core developers on Metasploit, a free point-and-click pentest/attack tool, specializing in exploitation techniques/mitigations, reverse engineering, program analysis and modeling, rootkits and virtualization.

    Over IM this morning, HD Moore said Miller designed a large chunk of the Metasploit 3 architecture, built the meterpreter payload system, and generally led the entire win32 shellcode improvement efforts.

    “He has done some exploit work as well, but his focus was mostly on encoders, shellcode, and payloads,” Moore said. Miller was the third ‘full-time’ developer at Metasploit, having joined the volunteer group in mid-2004.

    He is the author of several groundbreaking research papers, including techniques to bypass Windows Hardware-enforced DEP, improving software security analysis using exploitation properties and exploring the history of exploitation techniques (.pdf) and mitigations on Windows.

    Miller is also an editor for the Uninformed Journal, a free online journal that focuses on encouraging the sharing of technical knowledge.

    UPDATE: Over on Twitter, Dan Guido points out that Miller just open-sourced his WehnTrust HIPS project, which adds anti-exploit mechanisms/mitigations to Windows 2000, Windows XP and Windows Server 2003 systems.

    [Source: zdnet]

    uTorrent silently patches critical vulnerability

    Code execution hole in uTorrentIf uTorrent is the client you use to download files, now might be a good time to hit that “check for updates” button.

    According to security alerts aggregator Secunia, there’s a “highly critical” uTorrent vulnerability that could allow remote code execution attacks with rigged .torrent files.

    From the advisory:

    • The vulnerability is caused due to a boundary error in the processing of “.torrent” files. This can be exploited to cause a stack-based buffer overflow by tricking the user into opening a “.torrent” file containing an overly long “created by” field.
    • Successful exploitation may allow execution of arbitrary code.
    • The vulnerability is confirmed in version 1.7.7 (build 8179). Prior versions may also be affected.

    The issue was silently patched by the vendor in version 1.8 RC7. Rhys Kidd says the flaw is at least two years old.

    [Source: zdnet]

    Android security team appeals to hackers

    Android security team appeals to hackersAlready burned by the discovery of serious security vulnerabilities in its SDK, the Android Security Team emerged from the shadows this week with an appeal to the security community for help fixing flaws in the Linux-based mobile platform.

    In a note posted to several public mailing lists, the open-source group published a detailed FAQ covering its security philosophy and process and made a direct request for hackers to use responsible disclosure (.pdf) ethics when vulnerabilities are discovered.

    [ SEE: Google Android SDK has multiple vulnerabilities ]

    • As you may expect, building and maintaining a secure mobile platform is a difficult task. The Android platform team has put a great deal of work into trying to design a platform that balances our goal of open development and user choice with the unique challenges of securing a consumer-focused mobile system.
    • While we have found and fixed many of our own bugs as well as flaws in other open source projects, we realize that the discovery of additional security issues in a system this large and complex is inevitable. That is why we would like to introduce ourselves today and let the security research community know how they can reach out and work with us.

    The group provided an e-mail address for reporting bugs in Android (security-at-android.com) and a promise to respond to bug reports and keep reporters informed of the progress of an investigation.

    • We do appreciate and encourage responsible disclosure, especially since Android will be deployed on many different devices that will require a large amount of coordination to patch. Help from security researchers in the form of usable bug reports and responsible time lines will greatly assist us in securing the ecosystem of Android devices as quickly as possible. Our vulnerability bulletins will credit responsible reporters of any flaws.

    The Android security team, which is part of the Open Handset Alliance, plans to release more details of the security features of the Android platform over the next several months.

    [Source: zdnet]

    Measuring (not so) recent BIND nameserver patching

    Guest editorial by Derek Callaway

    Approximate Measurement of (Not So) Recent BIND Nameserver UpdatingThis post is meant to provide an approximation of BIND nameserver updates that occurred during the past month, most likely in response to Dan Kaminsky’s DNS cache poisoning vulnerability. I conducted this research because I was curious as to how widely BIND nameserver updates have been deployed given that a month has passed since US-CERT first alerted the public about the nature of the vulnerability and availability of patches.

    In an interview with Dark Reading at BlackHat Las Vegas 2008, Kaminsky estimated that between 60 and 70 percent of Fortune 500 companies have patched — but what about the rest of the Internet? Originally, I considered executing nameserver version query sweeps against only U.S. government networks, but I decided not to as I figured I would already be turning enough heads as it is.

    [ SEE: Vulnerability disclosure gone awry: Understanding the DNS debacle ]

    A number of assumptions have been made throughout this research:

    1. That the version number and patch level advertised by the nameserver is correct.
    2. That properly patched nameservers are not still vulnerable as a result of gateway device Port Address Translation.
    3. That the domain names retrieved from the Open Directory Project are served by a representative sample of BIND nameservers as a whole.

    Therefore, the measurements provided should only be treated as what they are — rough estimates. To that end, I wrote a bash shell script that: downloads the content file from the Open Directory Project, parses out random domain names that have three character top-level domains, sends a version query to the nameserver(s) authoritative for each domain, compares the result of the query to BIND version numbers with and without the fix, continues this process until 1,000 unique domain names have been tested, and calculates statistics based on the results. Note that invalid version query responses such as timeouts and strings that do not adhere to BIND version numbering cause a domain to be discarded.

    [ SEE: Attack code published for DNS flaw ]

    Here’s what I found:

    Approximate Measurement of (Not So) Recent BIND Nameserver Updating

    First, let me define a few terms to describe my findings. Un-Patched means that the domain had at least one nameserver that was not patched to address the DNS cache poisoning vulnerability; therefore, in all likelyhood it is vulnerable to CVE-2008-1447. In this research, Out-Dated means that the domain had at least one nameserver that hasn’t been updated for over a year so, in addition to CVE-2008-1447, it’s vulnerable to issues from previous CERT advisories. Dinosaur describes a domain with a nameserver that was last updated during or before the year 2002. Up-To-Date means that the domain is not vulnerable to any publicly known vulnerabilities, including Kaminsky’s bug from CVE-2008-1447 because all of the nameservers responsible for it have been recently updated.

    As matters stand, according to the aforementioned definitions:

    • 950 domains were vulnerable
      • Un-Patched: 319
      • Out-Dated: 593
      • Dinosaurs: 38
    • 336 domains had a nameserver that performed recursive queries
      • Of these, 327 were vulnerable to cache poisoning
    • 69 domains had a nameserver performed zone transfers
    • 50 domains were Up-To-Date

    A previous test run yielded similar results so I feel that these numbers are a decent estimation. Again, the domains that were a part of this experiment only have nameservers that respond with the default VERSION.BIND string. Still, this is quite a patching deficiency when taking into account that this is a major security hole in the Internet infrastructure that received significant media attention and well over a month has passed since patches were released.

    Here’s how I did it. Here’s the output from the shell script. Here is the output from all the executions of the tool by the shell script.

    * Derek Callaway is a computer programmer and security analyst. When he’s not analyzing applications, system architecture, or penetration testing, his preferred areas of study are vulnerability research and security tool development. He is currently part of the development team for a dynamic binary analysis tool at Security Objectives.

    [Source: zdnet]

    Did Apple forget to patch something?

    Apple DNS patch misses markLess than 24 hours after Apple (belatedly) released a patch for the DNS cache poisoning vulnerability, there are reports circulating that the DNS client on the OSX 10.4.11 distribution still has not been patched.

    According to nCircle’s Andrew Storms, the client libraries on a fully patched OSX 10.4.11 system still does not implement source port randomization, which is the recommended to help improve resilience against DNS cache poisoning attacks.

    Storms provided a comparison between a patched FreeBSD 6.3 system and a patched OSX 10.4.11 system:

    FreeBSD 6.3

    • 08:49:58.405934 IP [BSD].64328 > [SERVER].domain: 39741+ A? www.yahoo.com. (34)
    • 08:50:02.708123 [BSD].51023 > [SERVER].domain: 45758+ A? www.yahooooo.com. (35)
    • 08:50:07.625034 IP [BSD].50648 > [SERVER].domain: 23806+ A? www.www.net. (29)

    OSX 10.4.11

    • 08:05:47.741385 IP [OSX].49193 >[SERVER].domain: 55613+ A? www.cnn.com. (29)
    • 08:05:48.207547 IP [OSX].49194 >[SERVER].domain: 1106+ PTR? 21.91.236.64.in-addr.arpa. (43)
    • 08:05:51.717245 IP [OSX].49195 >[SERVER].domain: 27650+ A? www.cnn.com. (29)

    This clearly shows no source port randomization happening on OS X 10.4.11.

    For Apple, it matters most that they patch the client libraries since there are so few OSX recursive servers in use. The bottom line is that despite this update, it appears that the client libraries still aren’t patched.

    Apple does not respond to media queries about security issues.

    ALSO SEE:

    * Microsoft joins ‘patch DNS now’ chant; Apple patch missing

    * Vulnerability disclosure gone awry: Understanding the DNS debacle

    [Source: zdnet]

    Neosploit exploit kit shutters operations?

    Neosploit exploit kit shutters operation?The distributors of Neosploit, one of the more dangerous drive-by download exploit kits on the Internet, have shut down operations because of financial problems, according to malware researchers at RSA FraudAction Research Labs.

    In a blog entry, the company said it found evidence that Neosploit will no longer be supported (yes, the do-it-yourself malware installation kit comes with terms of service and customer support!) and will not feature any new exploits.

    Here’s a rough translation of the shutdown announcement, which was posted on a Russian Web site:

    “Unfortunately, supporting our product is no longer possible. We apologize for any inconvenience, but business is business since the amount of time spent on this project does not justify itself.

    We tried hard to satisfy our clients’ needs during the last few months, but the support had to end at some point. We were 1.5 years with you and hope that this was a good time for your business.

    Now we will not be with you, but nevertheless we wish that your businesses will prosper for a long time! Good luck all, The Neosploit Team!”

    Neosploit was notorious for being very aggressive about adding new exploits for vulnerabilities and was considered the the most advanced infection kit used by online criminals. From a bad guy’s perspective, it was considered reliability, scalable and efficient, even offering GUI-based features for tracking malware infections by OS, browser version or country.

    According to the RSA research team, the Neosploit creators ran a successful business selling the kit to malware purveyors but things have apparently gone downhill:

    In mid-July, however, evidence showed that Neosploit’s successful business was running into problems. It is likely that Neosploit was finding it difficult to sustain its new customer acquisition rate, and that its existing customers were not generating enough revenue to sustain the prior rate of development. These problems appear to have been too much of a burden, and we now believe that the Neosploit development team has been forced to abandon its product.

    If this shutdown is for real, it is good news for computer security but it’s certainly not only malware installation kits available for sale online. Neosploit competed with others like IcePack, Black Sun, Cyber Bot, Mpack and Zunker.

    [Source: zdnet]

    DNS cache poisoning attacks exploited in the wild

    UPDATE: Arbor Networks have provided more details in their “30 Days of DNS Attack Activity” analysis, SANS confirmed HD Moore’s statement on DNS cache poisoned AT&T DNS servers. Numerous independent sources are starting to see evidence of DNS cache poisoning attempts on their local networks, inDNS Cache Poisoning Test what appears to be an attempt to take advantage of the “recent” DNS cache poisoning vulnerability :

    ” client 143.215.143.11 query (cache) ‘www.ebay.com/ANY/IN’ denied: 31
    Time(s)
    client 143.215.143.11 query (cache) ‘www.facebook.com/ANY/IN’
    denied: 30 Time(s)
    client 143.215.143.11 query (cache) ‘www.gmail.com/ANY/IN’ denied:
    30 Time(s)
    client 143.215.143.11 query (cache) ‘www.google.com/ANY/IN’ denied:
    30 Time(s)
    client 143.215.143.11 query (cache) ‘www.live.com/ANY/IN’ denied: 30
    Time(s)
    client 143.215.143.11 query (cache) ‘www.microsoft.com/ANY/IN’
    denied: 30 Time(s)
    client 143.215.143.11 query (cache) ‘www.msn.com/ANY/IN’ denied: 30
    Time(s)
    client 143.215.143.11 query (cache) ‘www.myspace.com/ANY/IN’ denied:
    30 Time(s)”

    Surprised? I’m not, since this was pretty logical given that the three publicly available exploits have been downloaded over 15,000 times in the last couple of days. What I’m actually surprised of is that it took so long to produce a working exploit, and the despite the media outbreak raising awareness on the potential for abuse, major international and local ISPs remain vulnerable. Ironically, remain vulnerable just like they’ve always been even though patches for a particular vulnerability were available. Insecure and misconfigured DNS servers were, and continue to be a realistic threat even in a Web 2.0 world.

    Take for instance a survey of DNS security conducted back in 2004, showing that :

    “We next examine which names depend on nameservers with known security flaws. Of the 166771 nameservers, 27141 have known vulnerabilities. These vulnerabilities affect 185802 names. A naive expectation might be that, with ~17% vulnerable nameservers, only 17% of the names would be affected. This is patently not the case; transitive trust relationships “poison” every path that passes through an insecure nameserver. Hence 34% of DNS names can be compromised by launching well-known, scripted attacks. “

    Another DNS measurement study conducted back in 2005, showed that 84% of Internet name servers could be vulnerable to pharming attacks. Even if you’re more conservative than you should be, you can easily consider that at least 50% of Internet name servers remain vulnerable three years later. Well, that seems to be the case according to last year’s survey of DNS security, again conducted by Infoblox :

    “Still more than 50% of Internet name servers allow recursive queries, which is consistent with 2006 results. Accepting recursive queries from arbitrary addresses allows servers to be used in DNS amplification attacks that can bring down major networks, and also leaves them vulnerable to cache poisoning attacks. The percentage of name servers that allowed us to transfer zones actually increased slightly, from 29% to 31%. While this change is probably within the survey’s margin of error, it does show that this aspect of security isn’t improving. A change in the default behavior of the BIND 9 name server (like the change to the default recursion setting introduced in BIND 9.4) might help here.”

    State of IP SpoofingMoreover, the MIT’s IP Spoofer project originally running since 2005, continues to automatically generate graphs representing the state of DNS servers security across the globe, particularly their susceptibility to IP spoofing, the ABC of DNS security. Despite the hype over the recent vulnerability, DNS cache poisoning has been around for years, and it’s not going away anytime soon.

    Most importantly, malicious attackers don’t need to take advantage of this flaw to successfully commit cybercrime like they do on a daily basis. What hasn’t been taken care of for years, wouldn’t be solved in a matter of days, that’s for sure. Until then, take control of the situation, check whether or not your ISP is running DNS servers susceptible to cache poisoning, approach them in between sharing your evidence online, and consider going through the possible abuse scenarios malicious attackers can take advantage of using DNS cache poisoning.

    [Source: zdnet]

    How OpenDNS, PowerDNS and MaraDNS remained unaffected by the DNS cache poisoning vulnerability

    The short answer is being paranoid about tackling a known vulnerability. It’s 2001, and Daniel J. Bernstein (DJB),Daniel J. Bernstein (DJB) author of the then popular djbdns security-aware DNS implementation, is applying basic math principles to raise awareness on what’s to turn into the “sky is falling” critical Internet vulnerability in 2008, in an email on the unix.bind-users newsgroup :

    “I said “cryptographic randomization.” The output of random() is not cryptographically secure. In fact, it is quite easily predictable. This is a standard exercise in first-semester cryptography courses. Randomizing the port number makes a huge difference in the cost of a forgery for blind attackers—i.e., most attackers on the Internet. It’s funny that the BIND company has gone to so much effort to move from the first line to the second, but now pooh-poohs the third line. Do you think that “RSA” is a magic word that makes security problems disappear? Without a central key distribution system—a system that doesn’t exist now and won’t exist for the foreseeable future—DNSSEC doesn’t stop forgeries.”

    The skeleton from the closet makes another appearance in January 2005, according to Marcus H. Sachs, Director, SANS Internet Storm Center, in the face of Ian Green’s GIAC Security Essentials Certification (GSEC) submitted paper detailing the same vulnerability :

    “Three years ago Ian Green, then studying for his GIAC Security Essentials Certification (GSEC), submitted a paper that details the same DNS spoofing vulnerability, the SANS Institute’s Internet Storm Centre notes.In order to spoof a DNS request it’s necessary to “guess” both the Query ID and the source port. The query ID is 16 bits long, and the UDP source port also has over 60,000 potential option. But as Green noted back in January 2005, DNS transactions are incremented by one for each subsequent query while the UDP source port remains the same during a session.”

    Apparently, OpenDNS, PowerDNS and MaraDNS were all aware of the possibility for abuse here, and took action long before the recent vulnerability disclosure and coordinated multi-vendor patching initiated by Dan Kaminsky took place. How did they do it, and what’s the current state of the coordinated patching campaign across the Internet?

    On July 8th, David Ulevitch at OpenDNS posted a statement that OpenDNS isn’t vulnerable :

    “I’m very proud to announce that we are one of the only DNS vendor / service providers that was not vulnerable when this issue was first discovered by Dan. During Dan’s testing he confirmed (and we later confirmed) that our DNS implementation is not susceptible to the attack that was discovered. In other words, if you used OpenDNS then you were already protected long before this attack was even discovered.

    In fact, for those of you who were listening in on the Microsoft press call this morning, you’ll note that OpenDNS was suggested as the easy and simple solution for anyone who can’t upgrade their DNS infrastructure today. Pointing your DNS servers to forward requests to OpenDNS and firewalling all other DNS traffic off at your server will help mitigate this risk.” Bert Hubert, author of PowerDNS, alerted me to the fact that PowerDNS was also not vulnerable when this issue was discovered. That’s not surprising considering Bert is one of the authors of the wonderful DNS forgery resilience Internet Draft that has recently been published. :-) I updated the statement in bold appropriately.”

    On July 9th, Sam Trenholme at MaraDNS pointed out that the service is too, immune to the new cache poisoning attack :

    “MaraDNS is immune to the new cache poisoning attack. MaraDNS has always been immune to this attack. Ditto with Deadwood (indeed, people can use MaraDNS or Deadwood on the loopback interface to protect their machines from this attack). OK, basically, this is an old problem DJB wrote about well over seven years ago. The solution is to randomize both the query ID and the source port; MaraDNS/Deadwood do this (and have been doing this since around the time of their first public releases that could resolve DNS queries) using a cryptographically strong random number generator (MaraDNS uses an AES variant; Deadwood uses the 32-bit version of Radio Gatun).”

    And while these DNS services and secure DNS implementations like MaraDNS in this case, weren’t susceptible to the DNSDNS Fix Causes Huge Surge in DNS traffic in the Internet cache poisoning, during that time, across the Internet a synchronized patching was causing a lot of DNS anomalies, the direct effect of the ongoing patching in progress. According to Narus’s Supranamaya Ranjan, they saw a 1000x increase in aggregate volume of anomalous DNS traffic between Julu 7th and 11th :

    “Look at the figure below, which shows the aggregate volume (in Mbits/hour) over time for the DNS anomalies seen between July 7th and 11th. Clearly, before the CERT announcement and release of the patches, there were no anomalies. But after the announcement on July 8th, NSS saw a 1000x increase in aggregate volume of anomalous DNS traffic. NSS defines a traffic event as an anomaly if the amount or behavior of traffic heading to an ip-address exhibits sudden changes. A further analysis of the sources of these queries shows that they were being originated from open DNS proxies on the Internet and from DNS clients from well-reputed institutions from around the world. The reputation of the anomaly sources leads to the conclusion that these anomalies were not really attacks, but a side-effect of the synchronized patching.”

    The most recent study on the state of patching vulnerable DNS servers, was released today courtesy of Austria’s CERT, stating that :

    “The conclusions are rather grim so far – more than two thirds of the Austrian Internet’s recursive DNS servers are unpatched while at the same time the upgrade adoption rate seems rather slow. Our findings are matched by the observations of Alexander Klink of Cynops GmbH who analyzed the results of the online vulnerability test on Dan Kaminsky’s doxpara site.”

    The big picture? It seems that it’s not just At&T’s DNS servers which are susceptible to DNS cache poisoning, but many other like the following according to a request for self-auditing initiated by the Register :

    “Skybroadband, Carphone Warehouse Broadband, Opal Telecom, T-Mobile, Videotron Telecom, Roadrunner, Orange, Enventis Telecom, Earthlink, Griffin Internet and Jazztel.”

    Publicly available exploits for remote DNS cache poisoning

    With three publicly available exploits for remote DNS cache poisoning released during the last three days “in the wild”, it remains yet to be seen whether or not malicious attackers would take advantage of the window of opportunity, or continue using the “cybercrime as usual” attack tactics.

    [Source: zdnet]

    Microsoft joins ‘patch DNS now’ chant; Apple patch missing

    On the heels of the release of weaponized exploit code for the DNS cache poisoning vulnerability, Microsoft has joined the chorus of security pros pleading with DNS server providers to immediately apply patches to protect users from malicious attacks.

    Microsoft joins ‘patch DNS now’ chant; Apple patch missing

    The Redmond, Wash. security giant issued a formal security advisory advisory today with a terse warning that “attacks are likely imminent” because of the availability of exploit code:

    Since the coordinated release of these updates, the threat to DNS systems has increased due to a greater public understanding of the attacks, as well as detailed exploit code being published on the Internet.

    Microsoft is not currently aware of active attacks utilizing this exploit code or of customer impact at this time. However, attacks are likely imminent due to the publicly posted proof of concept and Microsoft is actively monitoring this situation to keep customers informed and to provide customer guidance as necessary.

    [ SEE: Attack code published for DNS flaw ]

    The company said its investigation of the exploit code, which was included in Metasploit, has verified that it does not affect Microsoft customers who have installed the updates detailed in Microsoft Security Bulletin MS08-037.

    However, as Dan Goodin reports, some of the world’s biggest ISPs are still very slow to ship fixes to protect customers. Goodin found that the tardy ISPs included AT&T, Time Warner and Bell Canada.

    My own testing of AT&T’s network on the iPhone returned conflicting results. Dan Kaminsky’s Doxpara DNS checker said AT&T was vulnerable but the same test at the DNS-OARC’s DNS checker and got this: 209.183.33.23 (schinetdns.mycingular.net) appears to have GREAT source port randomness and GREAT transcation ID randomness.

    [ Vulnerability disclosure gone awry: Lessons from the DNS debacle ]

    According to Rich Mogull, Apple is also among the tardy vendors:

    Apple has yet to patch the vulnerability which affects both Mac OS X and Mac OS X Server. While individual computers that look up DNS are vulnerable, servers are far more at risk due to the nature and scope of the attack.

    Apple uses the popular Internet Systems Consortium BIND DNS server which was one of the first tools patched, but Apple has yet to include the fixed version in Mac OS X Server, despite being notified of vulnerability details early in the process and being informed of the coordinated patch release date.

    All users of Mac OS X Server who use it for recursive DNS must immediately switch to an alternative or risk being compromised and traffic being redirected. Installing the above-mentioned BIND should be relatively trivial for anyone who can compile software at the command line. The Mac community could take this up if someone created a compiled version of BIND 9.0.5-P1 and distributed it for simpler installation.

    With active exploit code available in a common attack tool, it is imperative that Apple fix this vulnerability. Due to their involvement in the process and the ability of other vendors to fix their products in a timely fashion, it’s hard to imagine any possible justification for Apple’s tardy behavior.

    I have confirmed at least three publicly available exploits for this vulnerability and there are reliable behind-the-scenes mumbling that others are on the way.

    Dan Kaminsky gets the last word: “Less drama, more patching.”

    [Source: zdnet]

    Gaping holes in RealPlayer patched

    RealPlayer patches 4 serious flawsDigital media delivery firm RealNetworks has shipped a high-prority patch to cover four gaping holes in its flagship RealPlayer software, warning that the vulnerabilities could put users at risk of code execution attacks.

    The patch comes a few hours after Secunia released an advisory warning for one of the vulnerabilities, a heap-based buffer overflow caused by a design error within RealPlayer’s handling of frames in Shockwave Flash (SWF) files.

    According to RealNetworks, at least one of the four bugs affects all platforms — Windows, Mac OS X and Linux.

    [ SEE: IE users beware: RealPlayer zero-day flaw under attack ]

    Details are only available for these two vulnerabilities:

    • CVE-2008-1309: The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll 6.0.10.45 in RealNetworks RealPlayer 11.0.1 build 6.0.14.794 does not properly manage memory for the Console property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory. CVSS Base Score 9.3.
    • CVE-2007-5400: The vulnerability is caused due to a design error within the handling of frames in Shockwave Flash (SWF) files and can be exploited to cause a heap-based buffer overflow. Successful exploitation may allow execution of arbitrary code.

    In its advisory, RealNetworks also lists CVE-2008-1309, a RealPlayer ActiveX controls property heap memory corruption; and CVE-2008-3064, a local resource reference vulnerability.

    [Source: zdnet]

    Apple caught neglecting iPhone security

    Apple neglecting iPhone security?If you’re waiting on iPhone 2 to standardize your business on the awesome new device (yeah, I’ll be on line to buy one), you might want to pay attention to the conspicuous absence of iPhone security patches over the last four months.

    As WaPo’s Brian Krebs reports, the iPhone runs a stripped down version of Mac OS X but, even though OS X security updates are coming fast and furious, the iPhone has been neglected.

    This means that there are multiple serious iPhone code execution flaws — including the CanSecWest Safari contest bug — that remains unpatched.

    Krebs writes:

    In seeking confirmation of this, I spoke recently with Charlie Miller, one of the foremost OS X and iPhone security researchers. Miller confirmed that the iPhone updater tells users that if they have version 1.1.4 installed then they are running the most current version. The problem is that this update does not include fixes for a slew of security holes in the Safari Web browser and other OS X components upon which the iPhone relies heavily.

    “Apple should either update their software like they do with the core operating system, or otherwise don’t advertise the fact that the iPhone checks for updates every week,” Miller said. “Right now, an iPhone user is going to think they’re up-to-date because there’s no patch available, but the reality is that users are only as secure as they were back in February.”

    Even more worrisome, Miller has created a tool to exploit the Safari vulnerability on an iPhone.

    Using the exploit, an attacker who convinces an iPhone user to click on a malicious link could steal the victim’s call records or contacts, send text messages or read the user’s sent and received messages, and make outgoing calls, among other things.

    There’s also an iPhone zero-day floating around out there.

    So, if you love your iPhone like I do, consider sending Apple a note () and let them know that this neglect is unacceptable.

    * Image source: oskay’s Flickr photostream (Creative Commons 2.0).

    [Source: zdnet]