Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Oracle Issues Workaround for Publicly Disclosed Vulnerability -

The vulnerability in question is rated as highly critical, ranking in at 10.0 on the CVSS (Common Vulnerability Scoring System), and it is the first time since 2005 that Oracle breaks the quarterly update release cycle to address a security issue. The Apache plugin for Oracle WebLogic (you might know it under its former name, BEA WebLogic) suffers from a buffer overflow vulnerability that may allow a hacker to plant malicious software onto a particular machine.

"Unfortunately, the person(s) who published this vulnerability and associated exploit codes did not contact Oracle before publicly disclosing this issue. This means that the vulnerability was made public before providing Oracle an opportunity to develop an appropriate fix for this issue and notify its customers. In addition, the vulnerability was made public shortly after the publication of the July 15th Critical Patch Update, therefore prompting Oracle to issue an out of cycle security update," says Eric Maurice from Oracle.

Once the Oracle team found out about the vulnerability, which has been named CVE-2008-3257, it got right to work on trying to find a fix. The first counter measure that the development team came up with was a "recommended workaround", and all Oracle users were advised to read it and implement the measures presented within. As of yesterday, the 28th of July, Oracle has announced that a patch will also be made available.

"We expect this fix to be ready very soon, and we will issue an updated Security Alert to let customers know about its availability. In the meanwhile, we recommend that all customers implement the recommended workaround," said Eric Maurice.

The recently discovered vulnerability in the Oracle software further adds to the debate that disclosing security vulnerabilities aids attackers. On the one hand, an attacker does not have to spend huge amounts of time looking for vulnerabilities because technical details are already available on the web. On the other hand, by making such information available to the general public, the software manufacturer is forced to take action and address the situation.

The best course of action would be to inform the software provider about the situation and allow its research team to come up with a fix. After the vulnerability has been fixed, one can release technical details about the vulnerability.

[Source: softpedia]

Public Vulnerability Disclosure Aids Attackers

It would seem that people who are up to no good and want to get your machine infected, take less time to do so than in the past. By using information available to the general public, they are able to prepare an attack in a shorter time limit. Generally speaking, it takes about 24 hours from the moment a vulnerability is disclosed until an attack is already prepared and ready to launch. The thing is that most users find out about that particular vulnerability a lot later and consequently leave themselves exposed to infection.

In the past hackers and attackers of all sorts would spend quite a considerable amount of time looking for security vulnerabilities that they could exploit. In recent trends, this research work has been replaced by programs that generate automated attacks based on what information has been released about a security issue.

"The bad guys are not the ones actively finding vulnerabilities — they've shifted their business to standing on the shoulders of the security research community. They don't have to do the hard work anymore. Their job is packaging what's been provided to them," says Kris Lamb, operations manager for IBM's X-Force as cited by MSNBC.

Since the security experts do all the research and then by disclosing the findings basically make the attacker's work that much easier, a debate has been launched on how much information should be shared with the general public and how much should be kept private. If a researcher releases technical details as well as "proof-of-concept" exploit code, then a wrongdoer has all the necessary information to launch an attack, especially if said researcher has done so before a security fix could be issued by the software manufacturer.

Just to put things into perspective, in 94% of the cases a hacking exploit was ready in less than 24 hours after disclosing a vulnerability within various web browsers. Compared to 2007, one can notice a 24% increase.
[Source: softpedia]

Gary McKinnon – ‘world’s most dangerous hacker’ – to be extradited

Gary McKinnonThe Guardian, out of the United Kingdom, is reporting that Gary McKinnon, the “world’s most dangerous hacker”, will be extradited to the United States to face criminal hacking charges. McKinnon, a 42 year old unemployed systems administrator from north London, allegedly hacked into systems belonging to the US army, navy, air force, and Nasa in 2001. From the article:

He said he was merely searching for evidence of extraterrestrial life, but American officials labeled him the world’s most dangerous hacker and accused him of deleting important files and causing hundreds of thousands of dollars’ worth of damage.

According to prosecutors, McKinnon scanned more than 73,000 US government computers and hacked into 97 machines belonging to the US army, navy, air force and Nasa.

Not to stick up for this guy, but I am not sure that scanning 73,000 machines and hacking into 97 of them qualifies someone as the “world’s most dangerous hacker”. Certainly he is not harmless, but I have to believe there’s a lot of hackers out their with a bigger trophy case than McKinnon’s. This is not to trivialize what he has done, I just worry that the US may be over-sensationalizing this to play into their case.

The Guardian article claimed:

His lawyers have fought vigorously against the extradition, arguing that McKinnon could face up to 60 years in prison as a result of his actions, and could even be classed as an “enemy combatant” and interned at Guantánamo Bay. Instead they argued that he should face prosecution under Britain’s more lenient computer crime laws because he carried out the hacking from his bedroom in London.

McKinnon is certain to get harsh treatment here, but has he caused enough damage to warrant 60 years in prison and a trip to Gitmo? The article talked about what comes next for McKinnon and his legal team:

In a statement, McKinnon’s legal team said it would be taking the appeal to the European Court of Human Rights.

“Gary McKinnon is neither a terrorist nor a terrorist sympathizer,” the statement said. “His case could have been properly dealt with by our own prosecuting authorities. Instead, we believe that the British government declined to prosecute him to enable the US government to make an example of him.

“American officials involved in this case have stated that they want to see him ‘fry’. The consequences he faces if extradited are both disproportionate and intolerable and we will be making an immediate application to the European Court to prevent his removal.”

[Source: zdnet]

Sabre Security CEO Figures Out DNS Vulnerability

Recently, the DNS flaw discovered by Dan Kaminsky made all the headlines, first of all because of its gravity, and secondly because the Director of Penetration Testing for IOActive would not release specific, technical details about the flaw. Kaminsky stated on numerous occasions that he would disclose all the information on the 6th of August, at the BlackHat Security Conference in Las Vegas. But it seems that Thomas Dullien, CEO and head of research with Sabre Security has figured it all out, even though he admits he is not an expert in DNS.
Halvar Flake may have discovered how the DNS flaw works
This is the message posted on the Matasano Security blog in regard to Dullien's discovery: "The cat is out of the bag. Yes, Halvar Flake figured out the flaw Dan Kaminsky will announce at Black Hat". Halvar Flake is the hacker alias used by Thomas Dullien. It must be noted that the blog post presented above was posted for about five minutes and then it was taken down.

Thomas Ptacek from Matasano Security has posted another statement on the site, saying that they "dropped the ball" and it was all a regrettable error. "Earlier today, a security researcher posted their hypothesis regarding Dan Kaminsky’s DNS finding. Shortly afterwards, when the story began getting traction, a post appeared on our blog about that hypothesis. It was posted in error. We regret that it ran. We removed it from the blog as soon as we saw it. Unfortunately, it takes only seconds for Internet publications to spread," says Ptacek.

According to Halvar Flake, there is no good reason behind Kaminsky's request not to publicly speculate on the DNS vulnerability. He agrees that Kaminsky did the right thing by not disclosing the vulnerability and getting the industry heavyweights to come up with a fix, but by not speculating you are not buying the user any time. "In a strange way, if nobody speculates publicly, we are pulling wool over the eyes of the general public, and ourselves," says Halvar Flake.

Dan Kaminsky did not confirm or deny the fact that Hlavar Flake had indeed discovered the DNS vulnerability that he came upon earlier this year, and he is urging all users to update, if they haven't done so already. On the 24th Kaminsky will do a webcast for BlackHat, but he says this opportunity will not be used to disclose details on the DNS vulnerability. All those interested in the issue will have to wait until the 6th of August.

[Source: softpedia]

David Litchfield on details of one of the critical vulnerabilities from the latest Oracle patch

More details coming out on the Oracle patches that were released last week, see Ryan Naraine’s write up here. David Litchfield, noted security researcher from NGSSoftware, released details of one of the vulnerabilities on the Full-Disclosure email list today, and the details are staggering. The flaw allows potential unauthenticated remote exploitation resulting in full control of the database server. One thing that I think is key to note here is that this vulnerability was reported in October of 2007 and is just now getting patched in July of 2008. End result is, if you are using Oracle, get patched ASAP.
Read the details below…

Litchfield’s details are provided below:

Name: PLSQL Injection in Oracle Application Server
Systems Affected: Oracle Application Server 9.0.4.3, 10.1.2.2, 10.1.4.1
Severity: Critical
Vendor URL: http://www.oracle.com/
Author: David Litchfield [ davidl@ngssoftware.com ]
Reported: 9th October 2007
Date of Public Advisory: 15th July 2008
Advisory number: #NISR15072008
CVE: CVE-2008-2589

Overview
********
Oracle has just released a fix for a flaw that, when exploited, allows an unauthenticated attacker on the Internet to gain full control of a backend Oracle database server via the front end web server.

Details
*******
Oracle Application Server installs a number of PLSQL packages in the backend
database server. One of these is the WWV_RENDER_REPORT package and it is vulnerable to PLSQL injection. This package uses definer rights execution and therefore executes with the privileges of the owner, in this case the highly privileged PORTAL user.

Specifically, the SHOW procedure takes as its 2nd argument the name of a function to execute and this is embedded with a dynamically executed anonymous block of PLSQL without first being sanitized. Because it is a block of anonymous PLSQL, an attacker can exploit this flaw to run any SQL statement, for example, create new users, grant dba privileges, delete or
modify data. This is achieved by wrapping the statement(s) within an “execute immediate” statement and specifying the autonomous_transaction pragma.


[Source: zdnet]

Google Wages War against Phishing Attacks

People who fall victim to phishing attacks can end up penniless because the attacker will most likely use the information obtained through a phishing site to drain the victim's account dry. Search engine giant Google has been at the forefront of the battle against such scam attempts, warning users that the message may have malicious intent. The latest messages to come under close scrutiny are those that come, or claiming to come from eBay and PayPal.

Brad Taylor, Software Engineer with Google's Gmail comments: "Gmail does its best to put a red warning label on phishing messages, but it can be hard for us to know sometimes and we can't be 100% perfect. So, for the fraction of a time when Gmail misses it, you may end up squinting three times and turning the message sideways before suspecting that it's phishing. Wouldn't it be better if you never saw phishing messages at all, not even in your spam folder?"

This is how the whole thing goes: you will receive a message that seems to originate from PayPal in your inbox. The spammer makes up some reason to get you to visit what seems to be the PayPal web page, but it is in fact a close replica meant to steal your security credentials. Once he has all your private info he can then access your account and transfer all the funds out of it.

Google puts a stop to eBay and PayPal phishing
Comments: Google puts a stop to eBay and PayPal phishing
Credits: Low Impact Living

In order to prevent such things from happening to Gmail users, Google has resorted to high grade authentication that does not even allow a suspicious message into your inbox. Usually some messages that are identified as spam, and phishing is a form of spam, are allowed into your inbox; but a message that is suspected of phishing will not. This is available not just for eBay and PayPal, but for all international organizations that offer similar services.

Gmail can accurately tell if a message does not come from the previously mentioned companies because the two employ DomainKeys and DKIM to sign their e-mails. The phishing protection is already up and running with Gmail. Another great security feature about Gmail is the introduction of remote sign out.

[Source: softpedia]

Microsoft addresses 9 security vulnerabilities with 4 “Important” bulletins

Microsoft LogoMicrosoft announced 4 “Important” security bulletins today that cover 9 separate vulnerabilities. Of note were vulnerabilities reported in Windows DNS server and client, and within SQL Server. Briefly, the vulnerabilities involve:

  • Cache poisoning and insufficient socket entropy flaws in Microsoft DNS Server
  • A remote code execution vulnerability when saving a specially crafted search file within Windows Explorer
  • Outlook Web Access data validation and parsing Cross-Site Scripting vulnerabilities
  • Information disclosure and potential remote code execution flaws due to memory corruption in SQL Server

More details below:

  • MS08-037 (Maximum severity of Important): This update resolves two newly discovered and privately reported vulnerabilities in the Windows Domain Name System (DNS), which could allow a remote attacker to redirect network traffic intended for systems on the Internet to the attacker’s own systems.
    • Dan Kaminsky of IOActive reported a DNS Insufficient Socket Entropy Vulnerability (CVE-2008-1447)
      • A spoofing vulnerability exists in Windows DNS client and Windows DNS server. This vulnerability could allow a remote unauthenticated attacker to quickly and reliably spoof responses and insert records into the DNS server or client cache, thereby redirecting Internet traffic.To view this vulnerability as a standard entry in the Common Vulnerabilities and Exposures list, see CVE-2008-1447.
    • A cache poisoning vulnerability was reported in the Windows DNS Server
      • A cache poisoning vulnerability exists in Windows DNS Server. The vulnerability could allow an unauthenticated remote attacker to send specially crafted responses to DNS requests made by vulnerable systems, thereby poisoning the DNS cache and redirecting Internet traffic from legitimate locations.To view this vulnerability as a standard entry in the Common Vulnerabilities and Exposures list, see CVE-2008-1454.
  • MS08-038 (Maximum severity of Important): This security update resolves a publicly reported vulnerability in Windows Explorer that could allow remote code execution when a specially crafted saved-search file is opened and saved. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
    • A vulnerability was reported in the way Windows handles saved searches
      • A remote code execution vulnerability exists when saving a specially crafted search file within Windows Explorer. This operation causes Windows Explorer to exit and restart in an exploitable manner. To view this vulnerability as a standard entry in the Common Vulnerabilities and Exposures list, see CVE-2008-1435.
  • MS08-039 (Maximum severity of Important): This update resolves two newly discovered and privately reported vulnerabilities in Outlook Web Access (OWA) for Microsoft Exchange Server, which could allow an attacker to gain access to an individual OWA client’s session data, allowing elevation of privilege.
    • Michael Jordan of Context Information Security reported the OWA Data Validation Cross-Site Scripting Vulnerability (CVE-2008-2247) and the OWA Parsing Cross-Site Scripting Vulnerability (CVE-2008-2248)
      • This is a cross-site scripting vulnerability in the affected versions of Outlook Web Access (OWA) for Exchange Server. Exploitation of the vulnerability could lead to elevation of privilege on individual OWA clients connecting to Outlook Web Access for Exchange Server. To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted e-mail that would run malicious script from within an individual OWA client. If the malicious script is executed, the script would run in the security context of the user’s OWA session and could perform any action the user could perform such as reading, sending, and deleting e-mail as the logged-on user.To view this vulnerability as a standard entry in the Common Vulnerabilities and Exposures list, see CVE-2008-2247.
      • This is a cross-site scripting vulnerability in the affected versions of Outlook Web Access (OWA) for Exchange Server. Exploitation of the vulnerability could lead to elevation of privilege on individual OWA clients connecting to Outlook Web Access for Exchange Server. To exploit the vulnerability an attacker would have to convince a user to open a specially crafted e-mail that would run malicious script from within an individual OWA client. The script would run in the security context of the user’s OWA session and could perform any action the user could perform, such as reading, sending, and deleting e-mail as the logged-on user.To view this vulnerability as a standard entry in the Common Vulnerabilities and Exposures list, see CVE-2008-2248.
  • MS08-040 (Maximum severity of Important):This security update resolves four privately disclosed vulnerabilities. The more serious of the vulnerabilities could allow an attacker to run code and to take complete control of an affected system. An authenticated attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.This security update is rated Important for supported releases of SQL Server 7.0, SQL Server 2000, SQL Server 2005, Microsoft Data Engine (MSDE) 1.0, Microsoft SQL Server 2000 Desktop Engine (MSDE 2000), Microsoft SQL Server 2005 Express Edition, Microsoft SQL Server 2000 Desktop Engine (WMSDE), and Windows Internal Database (WYukon).
    • An anonymous finder reported a Memory Page Reuse Vulnerability (CVE-2008-0085)
      • An information disclosure vulnerability exists in the way that SQL Server manages memory page reuse. An attacker with database operator access who successfully exploited this vulnerability could access customer data. To view this vulnerability as a standard entry in the Common Vulnerabilities and Exposures list, see CVE-2008-0085.
    • An anonymous finder reported a Convert Buffer Overrun Vulnerability (CVE-2008-0086)
      • A vulnerability exists in the convert function in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system. To view this vulnerability as a standard entry in the Common Vulnerabilities and Exposures list, see CVE-2008-0086.
    • Brett Moore of Insomnia Security working with the iDefense VCP reported a SQL Server Memory Corruption Vulnerability (CVE-2008-0107)
      • A vulnerability exists in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system. To view this vulnerability as a standard entry in the Common Vulnerabilities and Exposures list, see CVE-2008-0107.
    • An anonymous finder reported the SQL Server Buffer Overrun Vulnerability (CVE-2008-0106)
      • A vulnerability exists in SQL Server that could allow an authenticated attacker to gain elevation of privilege. An attacker who successfully exploited this vulnerability could run code and take complete control of the system. To view this vulnerability as a standard entry in the Common Vulnerabilities and Exposures list, see CVE-2008-0106.

SQL Server and DNS vulnerabilities are always concerning. We’ll see if more details on these flaws become available.

[Source: zdnet]

Say it ain’t so AVG, say it ain’t so: AVG LinkScanner = Badware?

The Register covered a very interesting story about AVG. Apparently AVG is spamming the Internet with traffic that looks to be coming from Internet Explorer. AVG software pre-crawls search results to try to protect users, but uses a user agent that makes the software appear to be Internet Explorer. This pre-crawling is flooding websites with meaningless traffic (Slashdot claims it is up to 6% of their traffic, which given Slashdot’s load is CONSIDERABLE). More importantly, they’re apparently aware of this bad behavior and are changing their user agent to avoid filters. From the Register’s article:

Early last month, webmasters here at The Reg noticed an unexpected spike in our site traffic. Suddenly, we had far more readers than ever before, and they were reading at a record clip. Visits actually doubled on certain landing pages, and more than a few ho-hum stories attracted an audience worthy of a Pulitzer Prize winner. Or so it seemed.

DAMN! Why couldn’t it have happened here? I’m about to get married, the extra traffic would translate to extra dollars and help me out quite a bit! :) The Register article continues:

Read more it gets MUCH BETTER…

As it turns out, much of this traffic was driven by the new malware scanner from AVG Technologies.

Six months ago, AVG acquired Exploit Prevention Labs and its LinkScanner, a tool that automatically scans search engine results beforeyou click on them. If you search Google, for instance, and ten results turn up, it visits all ten links to ensure they’re malware free.

Then, in February, AVG paired LinkScanner with its anti-virus engine, which has about 70 million active users worldwide. The company estimates that 20 million machines have upgraded to its new security suite, AVG version 8, and this has already cooked up enough ghost clicks to skew traffic not only on The Reg but any number of other sites as well.

Adam Beale, who runs a UK-based internet consultancy, says that across his small stable of clients, traffic has spiked as much as 80 per cent on some sites. And this is more than just an inconvenience. After all, sites live and die by their traffic numbers. And net resources aren’t free.

This is ridiculous! On a site like ours, that feeds off of traffic, this is great (for me, not necessarily for ZDNet), but for most sites out there, this increase in traffic could lead to server downtime, network congestion, and might even force companies to by expensive load balancer devices and additional servers when the traffic really is NOT generating any more business for them. The Register continues:

“Although [the AVG LinkScanner] might be good for the security of users, it’s a real pain for website owners and webmasters,” Beale tells us, having blogged about this growing problem. “It’s causing people to think their traffic is increasing, costing those who pay for bandwidth, and wasting disk space with large amounts of unnecessary lines in log files.”

One of his clients, Beale says, normally pulls in 140GB of bandwidth a month, and for June, he predicts a 5 per cent jump.

When we spoke to AVG chief of research Roger Thompson earlier this week, he was unaware of these issues. But he defended the role of LinkScanner, which he designed while serving as CTO of Exploit Prevention Labs.

“There’s so much hacking activity going on the web. The only way to really tell what’s there is to go and have a look,” he told us. “I don’t want to sound flip about this, but if you want to make omelettes, you have to break some eggs.”

Holy crap, that is the single most irresponsible thing I have EVER heard a CTO of any company say. Unbelievable! On top of this, how much security is it really providing? It’s not like Anti-Virus or these fancy link scanners or anything like that have really lessened the impact of malware that much. We’ll see at DEFCON this year just how easy it is for attackers to morph malware into something that AVs do NOT pick up on. Funny… I just saw AVG’s corporate images:

AVG Logo

Maybe it should be the other way around?

Back to the Register article:

But what about webmasters?

Webmasters deal with robot traffic and other rogue visits all the time. But this is a little different. In an effort to fool even the sneakiest malware exploits, LinkScanner does its best to imitate real user clicks - which means most webmasters are completely unaware of the problem.

At the moment, there is a way of filtering AVG traffic from log files. But it’s unclear whether this method would bag legitimate traffic as well. And Thompson suggests that - in the name of high security - AVG may make changes that prevent such filtering.

Can you believe the cojones on this guy? He’s basically flooding our servers with illegitimate traffic and then telling you that in the high name of security, you should bend over, present, enjoy it, and then PAY HIM FOR IT!

[Source: zdnet]

Google Calendar now the target of phishers

A few months ago, spam came to Google Calendar. Now phishing has arrived.

Intrepid Google watcher Philipp Lenssen wrote late last week about being the target of a phishing attempt via Google Calendar.

He received an e-mail to his Gmail account with a reference to a legitimate event from his calendar. The sender was listed as "customer care," and it asked him to verify his account by supplying his username and password.

"We are having congestions (sic) due to the anonymous registration of Gmail accounts, so we are shutting down some Gmail accounts, and your account was among those to be deleted. We are sending you this email to so that you can verify and let us know if you still want to use this account," the e-mail said, complete with grammatical and spelling mistakes that can tip people off to phishing attempts.

On May 28, a Google Talk Guide addressed the issue in a Google Groups thread, urging users to click the "Report Phishing" link if they receive suspicious e-mails and not to click on links within the e-mails or open attachments.

Late on Monday, a Google representative e-mailed this statement: "Spam is an issue for all Internet users, and we work very hard to fight it. Using Google Calendar, or any Google product, to send spam is a violation of our product policies. We are actively identifying Calendar accounts that send spam and disabling them."

Google has more information on how to protect against e-mail fraud on its Official Google Blog Web site.

Philipp Lenssen of Google Blogoscope writes about how phishers targeted him via Google Calendar. This is a screenshot of the e-mail he received.

(Credit: Blogoscoped)

[Source: Cnet]