Showing posts with label Rootkit. Show all posts
Showing posts with label Rootkit. Show all posts

Critical Adobe Shockwave flaw affects millions

Adobe’s Shockwave Player contains a critical vulnerability that could be exploited by remote hackers to take complete control of Windows computers, according to a warning from the software maker.

The flaw affects Adobe Shockwave Player 11.5.0.596 and earlier versions. Details from Adobe’s advisory:

This vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected system. Adobe has provided a solution for the reported vulnerability (CVE-2009-1860). This issue was previously resolved in Shockwave Player 11.0.0.465; the Shockwave Player 11.5.0.600 update resolves a backwards compatibility mode variation of the issue with Shockwave Player 10 content. To resolve this issue, Shockwave Player users on Windows should uninstall Shockwave version 11.5.0.596 and earlier on their systems, restart, and install Shockwave version 11.5.0.600, available here: http://get.adobe.com/shockwave/. This issue is remotely exploitable.

Adobe boasts that 450 million Internet-enabled desktops have installed Adobe Shockwave Player.

[Source: zdnet]

Google sponsored links spreading (scareware) rogue AV

Malware hunters at Websense Security Labs have discovered legitimate Google sponsored links being used to plant scareware programs (rogue anti-virus applications) on the computers of Windows users.

In a blow-by-blow description of the rogueware attack, Websense researcher Elad Sharf shows how an innocent Google search for the Winrar file archiver and data compression utility can lead to a fake C|Net downloads.com page hosting a legitimate version of Winrar, with a nefarious twist:

Google sponsored links spreading (scareware) rogue AV

According to Sharf, the installer also drops a malicious file named explore.exe in the Windows system32 folder, and then runs the executable. The malicious file is associated with the icon used by Winrar SFX archives, and it binds to the system’s start-up.

The malicious explore.exe file proceeds to change the hosts file to point popular home page sites to a fake Microsoft Security Center site and displays displays a message box at one minute intervals.

This is how the scam works: after installing the infected program, users are interrupted with message boxes at one minute intervals. Thinking that the system has been infected, and irritated at the constant interruption, they might next search for information about the infection using the text that appears in the pop-up message. Finding legitimate forums discussing this infection, they will find confirmation that they are infected. The malware itself offers a fake remedy in the form of a pointer to a fake site. Users with any of the sites in the modified hosts file as their home page, or users who try to access any of those sites, are redirected to a site that pretends to be a Microsoft security center alert.

The end result is the user is tricked into running a security scan using this rogueware and receiving confirmation that the machine is indeed infected. The criminals then attempt to sell a disinfection tool to remove the malware they installed on the victim’s machine.

Ugly stuff.

[Source: zdnet]

Malware found in Lenovo software package

Malware found in Lenovo ThinkCenter driverComputer maker Lenovo is shipping a malware-infected software package to Windows XP users, according to warning from anti-virus researchers at Microsoft.

The malicious file was identified by Microsoft as Win32/Meredrop, a Trojan dropper that is used to install and execute multiple malicious executables on an infected computer. Other anti-virus vendors are detecting the threat as a ‘hooligan’ virus or a porn dialer. It was found the Lenovo Trust Key software for Windows XP, a digitally signed driver package available to Windows XP SP2 users.

The infected software is used to install the Lenovo Security Logon and the Lenovo Private folder applications for use with the Lenovo Trust Key (also known as Lenovo Insider Key).

[ SEE: Malware-infected USB drives distributed at security conference ]
My sources tell me the Lenovo package contains lots of files, including the one with the embedded malware. At first glance, the malicious file contains functional, but buggy code and attemps to infect files, spread across the network and USB drives.

Lenovo has been notified and is investigating the issue.

UPDATE: Lenovo has removed the compromised download from its Web site.

[Source: zdnet]

Under worm attack, US Army bans USB drives

Under worm attack, US Army bans USB drivesUnder sustained attack from what is described as a rapidly spreading network worm, the U.S. army has banned the use of USB sticks, CDs, flash media cards, and all other removable data storage devices, according to internal e-mail messages seen by Wired’s Noah Shachtman.

According to the article, service members have been ordered to “cease usage of all USB storage media until the USB devices are properly scanned and determined to be free of malware.” Eventually, some government-approved drives will be allowed back under certain “mission-critical,” but unclassified, circumstances. “Personally owned or non-authorized devices” are “prohibited” from here on out, according to the e-mails.

The USB device ban was handed down by the commander of U.S. Strategic Command and includes everything from external hard drives to “floppy disks. It takes effect immediately.

To make sure troops and military civilians are observing the suspension, government security teams “will be conducting daily scans and running custom scripts on NIPRNET and SIPRNET to ensure the commercial malware has not been introduced,” an e-mail says. “Any discovery of malware will result in the opening of a security incident report and will be referred to the appropriate security officer for action.”

The threat from malware that spreads via removable media has been on a steady rise with some estimates showing a 10 percent increase in detections this year.

ALSO SEE:

Malware-infected USB drives distributed at security conference

Malware found in Lenovo software package

[Source: zdnet]

Microsoft kills OneCare, replaces it with freebie ‘Morro’

Microsoft kills OneCare, pushes ‘free’ anti-malware toolMicrosoft today announced plans to kill its Windows Live OneCare PC care and security suite and replace it with a free anti-malware utility.

The new product, code-named “Morro,” will be designed for a smaller footprint that will use fewer computing resources, making it ideal for low-bandwidth scenarios or less powerful PCs, Microsoft said its surprise announcement.

Retail sales of Windows Live OneCare, which offered non-security PC care features such as printer sharing, data backup and automated PC tune-up, ends on June 30, 2009.

The company said “Morro” will be available in the second half of 2009 and will feature standard anti-malware capabilities to detect viruses, spyware, rootkits and trojans.

Morro will use the same home-built malware protection engine that powered Windows Live OneCare.

The new solution will deliver the same core protection against malware as that offered through Microsoft’s enterprise solutions, but will not include many of the additional non-security features found in many consumer security suites.

The freebie will be available as a stand-alone download and offer malware protection for the Windows XP, Windows Vista and Windows 7 operating systems.

UPDATE: Mary-Jo Foley has more, including this nugget:

Microsoft’s Equipt — which Microsoft launched in July of this year — is dead and Microsoft is having to go back and pull copies of Equipt from the channel (Circuit City in the U.S. and DSGI in the U.K.). Microsoft is offering customers a pro-rated refund for the service and allowing purchasers to keep Office Home & Student edition for free forever, Microsoft officials said.

* Disclosure: I work for a company that competes directly with Microsoft’s anti-malware offerings.

[Source: zdnet]

MS08-067 worms squirming in the wild

MS08-067 worms squirming in the wildFirst came Microsoft’s emergency patch. Then the public release of reliable exploit code. Now, virus hunters are reporting two new in-the-wild worms exploiting the critical MS08-067 vulnerability.

The worms, intercepted on Chinese-language versions of Windows, are being used to install a Trojan downloader, a denial-of-service bot and a rootkit to maintain stealthy presence on infected machines.


[ SEE: MS ships emergency patch for Windows worm hole ]

The in-the-wild attacks are using portions of the proof-of-concept code that’s publicly available, according to a source tracking this new threat.

One of the two worms spotted is capable of conducting DDoS (distributed denial-of-service) attacks against several Chinese sites, including the two big search engines Google and Baidu. It also downloads the eMule peer-to-peer program and drops an erotic movie on the hijacked system.

Windows users that have applied the MS08-067 update are not vulnerable to these attacks. Patch now.

[Source: zdnet]

Lead, melamine, and backdoored routers

It seems that not a day goes by without a new media alert regarding bad things in the chinese supply chain. First it was lead in our toys, then it was melamine in our milk, and now it also may be backdoors in our counterfeit Cisco hardware.

A recent BusinessWeek article discusses a criminal prosecution from late 2007 that raised the possibility that counterfeit Cisco routers have made their way into the western supply chain. Purchasers apparently include several government agencies and contractors, including branches of the military.

While counterfeit products may be a major economic concern, they also present a vector for foreign concerns to inject backdoors into critical infrastructure. This scenario is rather unlikely, as it would be far more cost effective for an attacker to compromise desktop systems using social engineering and trojans than it would be to create a trojaned router. Nevertheless, the possibility pushed the FBI to launch Operation Cisco (Cylon?) Raider in an effort to clamp down on the sale of counterfeit routers.

Unlike toys and food, performing a in-depth analysis of what goes into these routers would be expensive and possibly imperfect. Much like the apocryphal story of the CIA-initiated Soviet oil pipeline sabotage, we may never know if these mongrel devices were either pure clones or something more sinister.

[Source: zdnet]

DarkMarket ID theft message board shuts down


DarkMarket ID theft message board shuts downDarkMarket, an infamous underground message board that provides a haven for identity thieves to buy, trade and sell stolen data, plans to shut down operations.

According to Threat Level’s Kevin Poulsen, the three-year-old forum will go dark on October 4. The shutdown plan follows the recent arrest of Cagatay Evyapan, a Turkish hacker who was one of DarkMarket’s administrators. Evyapan, who used the hacker moniker “Cha0,” was a notorious underground figure who sold ATM-skimming devices.

Here’s a portion of the shutdown notice:

“[R]ecent events have proven that even in our best efforts to expel and deactivate the accounts of suspected LE [law enforcement], reporters, and security agents, it is obvious that we haven’t been entirely successful,” Splyntr wrote in a message on the site.

“It is apparent that this forum … is attracting too much attention from a lot of the world services (agents of FBI, SS, and Interpol),” wrote Splyntr. “I guess it was only time before this would happen. It is very unfortunate that we have come to this situation, because … we have established DM as the premier English speaking forum for conducting business. Such is life. When you are on top, people try to bring you down.”

Poulsen reports that DarkMarket was the last known survivor from a handful of underground forums used by online scammers to do business. Back in 2005, as part of “Operation Firewall,” law enforcement officials successfully infiltrated and shut down the ShadowCrew marketplace.

[Source: zdnet]

Apple mega-patch covers 34 Mac OS X security issues


Mac OS X mega-patch swats 34 security holesApple has shipped another mega-update to address security vulnerabilities affecting Mac OS X users, warning that the most serious issues could lead to arbitrary code execution attacks.

The update, available for Tiger and Leopard, addresses a total of 34 documented vulnerabilities, some in third-party components like ClamAV, BIND, OpenSSH and Ruby.

It also provides fixes for the following Mac OS X flaws:

  • CVE-2008-2305 — A heap buffer overflow exists in Apple Type Services’ handling of PostScript font names. Viewing a document containing a maliciously crafted font may lead to arbitrary code execution.
  • CVE-2008-2329 — An information disclosure issue exists in Login Window when it is configured to authenticate users with Active Directory. By supplying wildcard characters in the user name field, a list of user names from Active Directory may be displayed.
  • CVE-2008-2330 — An insecure file operation issue exists in the slapconfig tool used for configuring OpenLDAP. A local user can cause
    the password entered by a system administrator running slapconfig to be written to a file controlled by the user.
  • CVE-2008-2331 – Finder does not update the displayed permissions under some circumstances in a Get Info window. After clicking the lock button, changes to the filesystem Sharing & Permissions will take effect, but will not be displayed.
  • CVE-2008-3613 — A null pointer dereference issue exists in the Finder when it searches for a remote disc. An attacker with access to the local network can cause Finder to exit immediately after it starts, making the system unusable.
  • CVE-2008-2327 – Multiple uninitialized memory access issues exist in libTIFF’s handling of LZW-encoded TIFF images. Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-2332 — A memory corruption issue exits in ImageIO’s handling of TIFF images. Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-3608 — A memory corruption issue exists in ImageIO’s handling of embedded ICC profiles in JPEG images. Viewing a large maliciously crafted JPEG image may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-1382 — libpng in ImageIO is updated to version 1.2.29. CVE-2008-1382 is not known to affect the use of libpng in ImageIO, and this update is applied as a precautionary measure.
  • CVE-2008-3609 — Cached credentials are not always flushed when a vnode is recycled. This may allow a local user to read or write to a file
    where the permissions would not allow it. This update addresses the issue through improved handling of purged vnodes.
  • CVE-2008-1447 — libresolv provides translation between host names and IP addresses for applications that use its unicast DNS resolution API. A weakness in the DNS protocol may allow remote attackers to perform DNS cache poisoning attacks. As a result, applications that rely on libresolv for DNS may receive forged information.
  • CVE-2008-3610 — A race condition exists in Login Window. To trigger this issue, the system must have the Guest account enabled or another account with no password. In a small proportion of attempts, an attempt to log in to such an account will not complete. The user list would then be presented again, and the person would be able to log in as any user without providing a password. If the original account were the Guest account, the contents of the new account will be deleted on logout.
  • CVE-2008-3611 – When a system has been configured to enforce policies on login passwords, users may be required to change their password in the login screen. If a password change fails, an error message is displayed, but the current password is not cleared. This may not be obvious to the user. If the user leaves the system unattended with this error message displayed, a person with access to the login
    screen may be able to reset that user’s password.
  • CVE-2008-1447 – mDNSResponder provides translation between host names and IP addresses for applications that use its unicast DNS resolution API. A weakness in the DNS protocol may allow a remote attacker to perform DNS cache poisoning attacks. As a result, applications that rely on mDNSResponder for DNS may receive forged information.
  • CVE-2008-3614 – An integer overflow exists in QuickDraw’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-3616 -- Integer overflow issues exist in functions within the SearchKit framework. Passing untrusted input to SearchKit via an application may lead to an unexpected application termination or arbitrary code execution.
  • CVE-2008-2312 – Network Preferences stores PPP passwords unencrypted in a world readable file, accessible to any local user. This update addresses the issue by storing PPP passwords in the system keychain when the password is changed.
  • CVE-2008-3617 — Remote Management and Screen Sharing can be configured to require a password for VNC viewers. The maximum length for VNC viewer passwords is eight characters. The password field can display more than eight characters, implying that the additional characters are used in the password.

Other documented vulnerabilities affect System Preferences, Time Machine, VideoConference and Wiki Server.

* Image source: DeclanTM’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Intel ships BIOS fix for Rutkowska’s Black Hat flaw

Intel ships BIOS fix for Rutkowska’s Black Hat flawIntel has shipped a BIOS update with a fix for a privilege escalation vulnerability that was used by rootkit researcher Joanna Rutkowska to bluepill the Xen hypervisor.

The vulnerability was discussed by Rutkowska at the Black Hat briefings earlier this month but details on the exploit were withheld until Intel could release its patch.

That patch is now available (you can download a new firmware for your motherboard here) with a severity rating of “important.”

According to Intel’s advisory, software running administrative (ring 0) privilege can under certain circumstances change code running in System Management Mode.

  • A new BIOS update is available for select Intel desktop motherboards to ensure proper configuration settings. This change would prevent a malicious user from modifying software that is run in System Management Mode (SMM). SMM is a privileged operating environment running outside of OS control. Malicious software running in this environment could therefore perform any number of operations. Administrative level privileges are required to exploit this issue. BIOS updates to correct this issue are available for all affected Intel branded motherboards.

In a blog entry following Intel’s patch release, Rutkowska warns that an attacker could also use this bug to “directly modify the hypervisor memory, without jumping into the SMM first, just as we did it with our exploit.”

  • Also, in case of e.g. Linux systems, the Ring 0 access is not strictly required to perform the attack, as it’s just enough for the attacker to get access to the PCI config space of the device 0:0:0, which e.g. on Linux can be granted to usermode applications via the iopl() system call.

Affected Intel motherboards: DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, DX38BT and MGM965TW (Mobile).

In its advisory, Intel provides a step-by-step walk-through to help identify systems at risk and detailed instructions on updating your BIOS.

[Source: zdnet]

Feel like taunting an identity thief? Don’t.

Phishers bite backThe next time you get the urge to enter angry messages to phishers on fake (malicious) Web sites, stop and consider this discovery by researcher Joe Stewart.

The identity thieves behind the Asprox botnet have built extra logic into phishing sites to detect taunts and subject those computer users to drive-by malware exploits.

“If you are running Windows and haven’t recently installed your security updates and patched all your browser plugins/ActiveX controls, you might find yourself infected with your very own copy of Asprox,” Stewart warns.

Not only do you then get the opportunity to unknowingly send phishing emails on behalf of the botnet, you will likely get some extra goodies, since Asprox is also a downloader trojan. You won’t notice it running, but you might notice some of the things it downloads and installs.

For instance, you might find your desktop wallpaper changed to a “spyware alert” type of message, and now all your screen saver shows is scary blue-screens-of-death.

[ SEE: Adobe Flash ads launching clipboard hijack attack ]

Stewart posts screen shots with evidence that the Asprox botnet operators are linked to the attackers behind the rogue security software (scareware) attacks.

And at any time, Asprox might deliver another malicious payload and install it for you - and it could be much worse: we’ve seen the Zbot banking trojan installed by Asprox in the past. So instead of a dealing with a nuisance program, you might be silently sending your banking and credit card information to the botnet owners. Something to think about before venting your frustrations on the bad guys. Sometimes phish bite back.

* Image source: David Locke’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Intel proactively fixes security flaws in its chips

Despite the skepticism surrounding Kris Kaspersky’s upcoming “Remote code execution through Intel CPU bugs“Intel chip presentation to be held at this year’s Hack in the Box con, it appears that he’s been on the right track, as Intel has proactively taken care of the problem by fixing two of the critical flaws according to Kaspersky :

“On Friday, Kaspersky told Computerworld that he has been communicating with Intel about the flaws for nearly a month and the company has told him that it fixed the two critical flaws he brought to Intel’s attention. Both of the flaws — one in the cache controller and one in the Arithmetic logic unit — could be used by a remote attacker to execute arbitrary code, according to Kaspersky.”

And whereas he’s been asked not to release proof of concept code at at the conference due to the potential implications given Intel’s leading market share, and the fact that the flaw is OS independent, he’ll be releasing technical details on the vulnerability. Was Intel caught off guard at the first place?

Depends on the perspective. Intel has been actively investing in R&D of security technologies to make their chips moreTrusted Execution Technology secure. An example of such a successful effort is Intel’s Trusted Execution Technology already introduced in several of their chip families :

“Intel® Trusted Execution Technology for safer computing, formerly code named LaGrande Technology, is a versatile set of hardware extensions to Intel® processors and chipsets that enhance the digital office platform with security capabilities such as measured launch and protected execution. Intel Trusted Execution Technology provides hardware-based mechanisms that help protect against software-based attacks and protects the confidentiality and integrity of data stored or created on the client PC. It does this by enabling an environment where applications can run within their own space, protected from all other software on the system. These capabilities provide the protection mechanisms, rooted in hardware, that are necessary to provide trust in the application’s execution environment. In turn, this can help to protect vital data and processes from being compromised by malicious software running on the platform”

The question based on Kaspersky’s modest details ahead of the presentation is, whether or not he’ll be demonstrating direct Java bytecode execution, and which chip families is he going to target. One thing’s for sure, when a vendor is proactively fixing vulnerabilities you were speculating about based on off the record discussions with you, you knew what you were looking for.

[Source: zdnet]

Today’s assignment : Coding an undetectable malware

Today’s dynamic Internet threatscape is changing so rapidly, that the innovations and creativity applied by malwareMalware authors can easily render an information security course’s curricular on malware outdated pretty fast, or worse, provide the students with a false feeling of situational awareness about today’s malware that’s driving the entire cybercrime ecosystem at the end of the day. In fact, one can easily spot an outdated academic curricular on the basis of the malware it’s discussing, and whether or not the lecturer is even bothering to imply that antivirus software the way it is, and the way it’s been for the past couple of years, is only mitigating a certain percentage of the threat, next to eliminating it entirely and urging everyone to “keep their antivirus software up to date.”

George Ledin, a professor at Sonoma State University thinks that coding malware helps students better understand the enemy. What is Ledin trying to achieve anyway?

“Ledin insists that his students mean no harm, and can’t cause any because they work in the computer equivalent of biohazard suits: closed networks from which viruses can’t escape. Rather, he’s trying to teach students to think like hackers so they can devise antidotes. “Unlike biological viruses, computer viruses are written by a programmer. We want to get into the mindset: how do people learn how to do this?” says Ledin, who was born to Russian parents in Venezuela and trained as a biologist before coming to the United States and getting into computer science. “You can’t really have a defense plan if you don’t know what the other guy’s offense is,” says Lincoln Peters, a former Ledin student who now consults for a government defense agency.”

To code an undetectable malware in an academic environment in order to scientifically prove that signatures based malware scanning wouldn’t detect the just coded malware, or to keeping providing a false feeling of security by the wrongly positioned antivirus software? That’s the question Sonoma State University’s George Ledin seems to asking, and he’s naturally receiving a lot of criticism from companies “making their living fighting viruses” reaching such heights as companies speculating on not hiring his students, now capable of coding malware. The companies however, forget one thing - how easy is in fact to “generate” an undetectable piece of malware using the hundreds of malware builders that they are aware of, ones that come very handy for internal benchmarking purposes for instance.

For the past couple of years, antivirus software has been a pure reactive security solution, namely compared to pro-activeThe Race to Zero approaches embraced by the vendors who are in catch-up mode with the malware authors, it was reacting to known threats. Two months ago, Eva Chen, Trend Micro’s CEO made some very bold, but pretty realistic statements on signatures based malware scanning, and how the entire industry was wrongly positioned for the past 20 years :

“In the antivirus business, we have been lying to customers for 20 years. People thought that virus protection protected them, but we can never block all viruses. Antivirus refresh used to be every 24 hours. People would usually get infected in that time and the industry would clean them up with a new pattern file. In the last 20 years, we have been misrepresenting ourselves. No-one is able to detect five and a half million viruses. Nowadays there are no mass virus outbreaks; [malware] is targeted. But, if there are no virus samples submitted, there’s no way to detect them.”

Precisely, so what Ledin is blamed for is in fact an outdated fact by itself starting from the basic nature of how antivirus software works. The very same outdated approach of proving a known fact will be taken by the upcoming “The Race to Zero” undetectable malware coding contest to be held at this year’s Defcon security conference. Moreover, in between vendors counting how much malware they are detecting, taking a peek at publicly obtainable statistics on detection rates for malware in the wild, you will see how dynamic “the best antivirus software” position is, since it literally changes every day. And theoretically, even “the best antivirus software” wouldn’t be able to detect the malware coded by Ledin’s students, or the one that someone requested to be coded for hire, a service that’s been getting increasingly popular these days due to its customerization approach.

Ironically, the IT underground is a step ahead of George Ledin, using distance learning approaches by including videoPinch tutorials on how to use malware kit, including practical examples of successful attacks and providing tips from personal experience while using it. Coding an undetectable malware in 2008 isn’t rocket-science, with do-it-yourself malware builders providing point’n'click features integration that used to be only available to a sophisticated malware author a couple of years ago. Then again, having an undetected malware, doesn’t mean that they’ll be able to successfully spread it and infect millions of users, so from a strategic perspective it’s all about the tactics and combination of tactics that would use in their campaign.

Before you judge Ledin’s vision, ask yourself the following - does coding malware ultimately improve the career competitiveness of his students in the long-term, or isn’t what he’s trying to prove a known fact already?

[Source: zdnet]

Neosploit exploit kit shutters operations?

Neosploit exploit kit shutters operation?The distributors of Neosploit, one of the more dangerous drive-by download exploit kits on the Internet, have shut down operations because of financial problems, according to malware researchers at RSA FraudAction Research Labs.

In a blog entry, the company said it found evidence that Neosploit will no longer be supported (yes, the do-it-yourself malware installation kit comes with terms of service and customer support!) and will not feature any new exploits.

Here’s a rough translation of the shutdown announcement, which was posted on a Russian Web site:

“Unfortunately, supporting our product is no longer possible. We apologize for any inconvenience, but business is business since the amount of time spent on this project does not justify itself.

We tried hard to satisfy our clients’ needs during the last few months, but the support had to end at some point. We were 1.5 years with you and hope that this was a good time for your business.

Now we will not be with you, but nevertheless we wish that your businesses will prosper for a long time! Good luck all, The Neosploit Team!”

Neosploit was notorious for being very aggressive about adding new exploits for vulnerabilities and was considered the the most advanced infection kit used by online criminals. From a bad guy’s perspective, it was considered reliability, scalable and efficient, even offering GUI-based features for tracking malware infections by OS, browser version or country.

According to the RSA research team, the Neosploit creators ran a successful business selling the kit to malware purveyors but things have apparently gone downhill:

In mid-July, however, evidence showed that Neosploit’s successful business was running into problems. It is likely that Neosploit was finding it difficult to sustain its new customer acquisition rate, and that its existing customers were not generating enough revenue to sustain the prior rate of development. These problems appear to have been too much of a burden, and we now believe that the Neosploit development team has been forced to abandon its product.

If this shutdown is for real, it is good news for computer security but it’s certainly not only malware installation kits available for sale online. Neosploit competed with others like IcePack, Black Sun, Cyber Bot, Mpack and Zunker.

[Source: zdnet]

Remote code execution through Intel CPU bugs

Kris Kaspersky, author of numerous books on reverse engineering and software engineering, will be presenting hisKris Kaspersky research on remote code execution through Intel CPU bugs at the upcoming Hack in the Box Security Conference in Malaysia. If his proof of concept code consisting of JavaScript or TCP/IP packet attacks on Intel based machines succeeds, given Intel’s dominant market share on the market the potential outbreak could be enormous since as he claims, the PoC is OS independent, namely all operating systems running Intel chips are said to be vulnerable. Here’s an abstract from his upcoming presentation :

“Intel CPUs have exploitable bugs which are vulnerable to both local and remote attacks which works against any OS regardless of the patches applied or the applications which are running. In this presentation, I will share with the participants the finding of my CPU malware detection research which was funded by Endeavor Security. I will also present to the participants my improved POC code and will show participants how it’s possible to make an attack via JavaScript code or just TCP/IP packets storms against Intel based machine. Some of the bugs that will be shown are exploitable via common instruction sequences and by knowing the mechanics behind certain JIT Java-compilers, attackers can force the compiler to do what they want (for example: short nested loops lead to system crashes on many CPUs). I will also share with the participants my experience in data recovery and how CPU bugs have actually contributed in damaging our hard drives without our knowledge. “

Intel will be keeping an eye on his upcoming research :

“George Alfs, a spokesman for Intel, said he has not yet seen Kaspersky’s research, nor has he spoken to him about it. “We have evaluation teams always looking at issues. We’ll certainly take a look at this one,” said Alfs. “All chips have errata, and there could be an issue that needs to be checked. Possibly. We’d have to investigate his paper.”

BIOS based rootkits are nothing new with John Heasman’s research into Implementing and Detecting a PCI Rootkit, published in 2006. And with the possibility of malware hiding at the lowest possible level already a fact, what will be very interesting to monitor is a universal remote code execution based on chip’s manufacturer. Everything is possible, the impossible just takes a little longer.

[Source: zdnet]

Warning: MBR Rootkit Hunting Windows XP Computers!

I must mention from the beginning that every unpatched system connected to the web is vulnerable to this rootkit, so in case you're running an outdated version of Windows XP, you may be in danger pal! Now, let's see some juicy (if you're one of those loving computer infections)
details about the rootkit. First of all, you should know that this new threat infects the MBR (Master Boot Record) of the hard disk, so only a few antivirus technologies would be able to detect and stop it. Symantec's antivirus is one of these exceptions, the application labeling the infection as Trojan.Mebroot, Elia Florio wrote on the Symantec blog.

Infecting the MBR means that the Trojan.Mebroot harms you computer even before the operating system is loaded, so antiviruses are somehow useless. "The main problem is that some versions of Microsoft Windows allow programs to overwrite disk sectors directly (including the MBR) from user mode, without restrictions. As such, writing a new MBR into Sector 0 as a standard user is a relatively easy task", the Symantec official explained.

Elia Florio wrote that Trojan.Mebroot affects Windows XP users, no matter what Service Pack has been deployed. Windows Vista users seem to be protected of the rootkit, according to the Symantec report. The Windows XP vulnerability is caused by "some hard-coded values inside the attack code", as the Symantec official wrote.

It seems like the virus writers found a way to avoid Windows antiviruses
Comments: It seems like the virus writers found a way to avoid Windows antiviruses
Credits: ciasolutions.com.au

What's worse is that the infection cannot be removed while the operating system is running, Elia Florio explained. "It must be removed while the rootkit code itself is not running", Florio stated. "During our tests, running the 'fixmbr' command from within the Windows Recovery Console successfully removed the malicious MBR entry. To help prevent similar attacks in the future, and if your system BIOS includes the Master Boot Record write-protection feature, now is a good time to enable it!"

[Source: softpedia]

Cisco confirms possibility of IOS rootkits

Cisco confirms possibility of IOS rootkitsOn the heels of an EUSecWest conference presentation on malicious rootkits for Cisco IOS (see background), Cisco’s security response team has published a must-read document confirming that stealthy malware can be loaded on the software used on the vast majority of its routers and network switches.

Cisco warns:

It is possible that an attacker could insert malicious code into a Cisco IOS software image and load it onto a Cisco device that supports that image. This attack scenario could occur on any device that uses a form of software, given a proper set of circumstances.

The company’s confirmation follows a technical discussion by Core Security researcher Sebastian Muniz of “Da IOS Rootkit,” which is basically a binary modification to the IOS image downloaded from the device.

In this Q&A, Muniz explains his creation:

The main feature of Da IOS Rootkit is the universal password. Every call to the different password validation routines grant access to the user if the unique rootkit password is specified. This is what will be in the public release. Other features such as hiding files, processes and connections will not be included. The core of the rootkit code is written in plain C instead of assembly. It doesn’t persist through upgrades yet but future versions probably will.

I haven’t tested on Catalyst switches because they run CatOS which a different than IOS. The rootkit code is rather generic so it should work with some modifications. As a matter of fact, some parts of the code are so generic that they will work on any other class of devices (not even CISCO devices).

Cisco, in response, published a list of security best practices  to improve the security posture of a routing and switching network.  “These practices are particularly relevant to ensure that Cisco IOS devices only use authorized and unaltered Cisco IOS software images,” the company said.

[Source: Zdnet]

Rootkits - The new age of viruses



Ah I remember some of the nastiest viruses back in the day attaching themselves in the MBR (Master Boot Record) rendering most anti-virus software useless (as it sits on top of the OS).

Now it seems MBR infection is back in fashion for a new age of rootkits.

Security mavens have uncovered a new class of attacks that attach malware to the bowels of a hard drive, making it extremely hard to detect and even harder to remove.

The rootkit modifies a PC’s master boot record (MBR), which is the first sector of a storage device and is used to help a PC locate an operating system to boot after it is turned on. The result: the rootkit is running even before Windows loads. There have been more than 5,000 infections in less than a month, researchers say.

“Master boot record rootkits are able to subvert the Windows kernel before it loads, which gives it a distinct stealth advantage over rootkits that load while Windows is running,” said Matthew Richard, director of the rapid response team for iDefense, a security provider owned by VeriSign. “It gives it a great stealth mechanism that allows it to persist even after removal.” Such rootkits can even survive reinstallation of the operating system, he said.

Pretty stealthy and extremely sticky, time to be a little more wary. MBR infectors are extremely nasty and the majority of people won’t even know they are. Plus as they can subvert the Windows kernel before it even loads…it has a huge stealth advantage.

The new rootkit is part of the arms race between security vendors and malware writers, he said. “We’re definitely making it harder and harder for the bad guys to do stuff to the operating system,” he said. They respond by attacking new parts of a PC.

Every version of Windows, including Vista, is vulnerable to the rootkit.

About 30,000 websites, mostly located in Europe, are actively trying to install the rootkit by exploiting users who have failed to install Windows updates, Richard says. There were 5,000 infections from December 12 to January 7. The rootkit is being spread by the same group responsible for distributing the Torpig banking Trojans, which are used to steal online banking credentials.

* McAfee detects the Trojan as StealthMBR (DAT 5204 or above) or StealthMBR!rootkit
* Symantec as Trojan.Mebroot or Boot.Mebroot
* Sophos uses name Troj/Mbroot-A
* Trend Micro uses the name TROJ_SINOWAL.AD

(Info from Securiteam)

A timeline is available from SANS here.