Fedora infrastructure breach?

Fedora server compromised?Has there been a security breach in Red Hat Fedora’s infrastucture systems?

According to a cryptic announcement posted to the Fedora-Announce mailing list, the open-source group is investigating an unspecified “issue in the infrastructure systems” that has resulted in widespread service outages.

In the note, Fedora maintainers recommend that end users avoid downloading packages on Fedora systems, which strongly hints at a security-related problem:

  • The Fedora Infrastructure team is currently investigating an issue in the infrastructure systems. That process may result in service outages, for which we apologize in advance. We’re still assessing the end-user impact of the situation, but as a precaution, we recommend you not download or update any additional packages on your Fedora systems.

A follow-up message posted over the weekend said the investigations were continuing but there are no details available on the cause of the problem.

Efforts to contact Red Hat Fedora maintainers have so far been unsuccessful. I will update this post as necessary.

* Image credit: jgbrl’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Microsoft investigating NSlookup.exe flaw, reported attacks

Microsoft investigating new Windows zero-day attackMicrosoft is investigating new public reports of a zero-day Windows vulnerability that’s being exploited in the wild.

According to a this SecurityFocus alert, the attacks are exploiting a remote code-execution vulnerability due to an unspecified error in NSlookup.exe, the command-line administrative tool used for testing and troubleshooting DNS servers.

  • Successfully exploiting this issue would allow the attacker to execute arbitrary code on an affected computer. Failed attacks will cause denial-of-service conditions. Microsoft Windows XP Professional SP2 is vulnerable; other versions and products may also be affected.

According to the alert, the issue is reportedly “being actively exploited” in the wild but details on the attacks are scarce.

A video of a proof-of-concept exploit in action was released by Argentinian researcher Ivan Sanchez.

On its monthly Patch Tuesday Webcast (see transcript), Microsoft’s security response team said it was aware of the flaw report and had started an investigation. The company has not yet issued a security advisory with workarounds or mitigations.

Some other highlights from the Webcast:

  • The Microsoft Access Snapshot Viewer ActiveX control vulnerability was only partially fixed with MS08-041. The standalone Access Snapshot Viewer is still vulnerable and unpatched. There are confirmed in-the-wild exploits for this vulnerability.
  • The reason the massive IE killbit update was done as an advisory instead of a bulletin was because it only included killbits for third-party (Aurigma and HP) ActiveX controls. Microsoft does not provide a security rating for these controls and the company never releases bulletins without severity ratings. “Since there is no severity associated with this release, we decided to release this update via an advisory.”
[Source: zdnet]

Intel proactively fixes security flaws in its chips

Despite the skepticism surrounding Kris Kaspersky’s upcoming “Remote code execution through Intel CPU bugs“Intel chip presentation to be held at this year’s Hack in the Box con, it appears that he’s been on the right track, as Intel has proactively taken care of the problem by fixing two of the critical flaws according to Kaspersky :

“On Friday, Kaspersky told Computerworld that he has been communicating with Intel about the flaws for nearly a month and the company has told him that it fixed the two critical flaws he brought to Intel’s attention. Both of the flaws — one in the cache controller and one in the Arithmetic logic unit — could be used by a remote attacker to execute arbitrary code, according to Kaspersky.”

And whereas he’s been asked not to release proof of concept code at at the conference due to the potential implications given Intel’s leading market share, and the fact that the flaw is OS independent, he’ll be releasing technical details on the vulnerability. Was Intel caught off guard at the first place?

Depends on the perspective. Intel has been actively investing in R&D of security technologies to make their chips moreTrusted Execution Technology secure. An example of such a successful effort is Intel’s Trusted Execution Technology already introduced in several of their chip families :

“Intel® Trusted Execution Technology for safer computing, formerly code named LaGrande Technology, is a versatile set of hardware extensions to Intel® processors and chipsets that enhance the digital office platform with security capabilities such as measured launch and protected execution. Intel Trusted Execution Technology provides hardware-based mechanisms that help protect against software-based attacks and protects the confidentiality and integrity of data stored or created on the client PC. It does this by enabling an environment where applications can run within their own space, protected from all other software on the system. These capabilities provide the protection mechanisms, rooted in hardware, that are necessary to provide trust in the application’s execution environment. In turn, this can help to protect vital data and processes from being compromised by malicious software running on the platform”

The question based on Kaspersky’s modest details ahead of the presentation is, whether or not he’ll be demonstrating direct Java bytecode execution, and which chip families is he going to target. One thing’s for sure, when a vendor is proactively fixing vulnerabilities you were speculating about based on off the record discussions with you, you knew what you were looking for.

[Source: zdnet]

Adobe Flash ads launching clipboard hijack attack

Clipboard hijackMalicious hackers are using booby-trapped Flash banner ads to hijack clipboards for use in rogue security software attacks.

In the Web attacks, which target Mac, Windows and Linux users running Firefox, IE and Safari, hackers are seizing control of the machine’s clipboard and using a hard-to-delete URL that points to a fake anti-virus program.

According to victims on several Web forums, the attack is coming from Adobe Flash-based advertising on legitimate sites — including Newsweek, Digg and MSNBC.com.

Here is a Mac OS X user explaining the attack:

This has happened to me twice now, on two separate computers at work. My clipboard has been hijacked with this:

[ malicious URL deleted ]

And once it’s in the clipboard, I can’t copy anything else over it until I’ve restarted the machine.

I’m only going to websites that are directly linked off the main page of digg.com, so they’re not obscure, and I’m surfing in firefox, though the system wide clipboard is getting taken over, so I can’t even copy something over that from a program like TextEdit.

The 5th post on this MSNBC.com forum shows what happens when a victim is tricked into pasting — and spamming — the malicious link to help spread the rogue security software.

Security researcher Aviv Raff has created a proof-of-concept demo to show how easy it is to use Flash with ActionScript code to load (persistently) a malicious URL into a target clipboard. (BEWARE: If you click on the demo link, your clipboard is automatically hijacked and will only be released if the browser window is closed).

[Source: zdnet]

China busts hacking ring, managed to penetrate 10 gov’t databases

If you needed a university certificate in China during the last couple of months, there’s a big chance that a group of tenChinese Net Police people could have supplied with you such, going a step further and adding your details in more than ten government databases across different provinces in the country, making $300k in the process.

Shanghai Daily is reporting on this sophisticated group of local hackers who were selling “valid” educational certificates by modifying government databases. How they got caught? Apparently, by cross-checking the validity of the certificate, and since they couldn’t hack each and every database in order to add a reference to it, their business model was quickly detected and shut down.

“The suspects sold fake certificates to make money. Since authentic certificates can be checked on government Websites, they allegedly attacked databases and added false information, the report said. The scheme was discovered after someone purchased a fake doctor’s certificate to apply for a business license in Zhejiang Province in June. Zhejiang authorities found the certificate was faked even though the information on the Jiangxi Public Health Department’s Website matched it, the report said. The Jiangxi Public Health Department checked the database and found it was attacked several months and that many statistics were distorted. It reported the case to police.”

Whereas China has a very strong reputation on dealing with local cybercrime attacks in a very short time frame, it has perhaps one of the worst reputations across the globe when in comes to the big picture, with Chinese networks topping each and every chart on malicious Internet activity. Is there a double standard on fighting cybercrime in China? Depends. There’s no shortage or organizational bodies fighting cybercrime in the country, however, as in many other countries there seems to be a lack of political awareness on how severe the situation has gotten while they were trying to assess its severity, a situation which when combined with the lack of right priorities set, speaks for itself.

As far as this hacking ring is concerned, once the people behind it could add authentic entries into the database, they could have also taken a peek at others, which in the context of China’s overall bureaucratic mentality for anything related to cybercrime, could easily turn into a major espionage case — or they can easily make it look like one. Moreover, when there’s demand for a particular good or a service, there’s also supply :

“Li said demand for fake certificates was strong, according to the report. He contacted his friend surnamed Wang to attack the government databases and validate his false certificates, the report said. The investigation showed Wang attacked more than 10 government databases in Jiangxi, Hubei, Guizhou, Sichuan, Jiangsu and Liaoning provinces from March this year. Wang sold the user rights of every database to Li for 5,000 yuan to 8,000 yuan, the report said.”

From a security perspective, detecting the fake certificate seems to have worked since these provinces are either not syndicating their databases and trusting a single database as a central point which when once hacked and modified could distribute false data across the rest of the provinces, or the data was cross-checked via offline sources or historical copies of the database. If bureaucracy can help fighting cybercrime by ensuring that a clerk doesn’t trust everything he sees on his monitor, and prompts him to cross-check with different databases “just for the record”, then that’s one of those rare cases.

[Source: zdnet]

Can Adobe mitigate ‘clipboard hijack’ issue?

Adobe investigating clipboard hijack attackAdobe’s product security incident response team (PSIRT) says it is investigating possible solutions to the clipboard hijack attacks spotted on Flash-based advertisements on high-profile Web sites.

A barebones note on the PSIRT blog simply acknowledges the issue and promised more information after the investigation but, by mentioning “possible solutions,” it is clear that that Adobe is looking for ways to mitigate the threat.

Here’s an interesting bit from the Flash documentation:

  • The System.setClipboard() method allows a SWF file to replace the contents of the clipboard with a plain-text string of characters. This poses no security risk. To protect against the risk posed by passwords and other sensitive data being cut or copied to clipboards, there is no corresponding “getClipboard” (read) method.

[ SEE: Adobe Flash ads launching clipboard hijack attack ]

I’m not entirely sure why a SWF file would need the ability to write to the clipboard but, now that we know it does present a security risk (see harmless clipboard-takeover demo), Adobe might want to nuke that functionality altogether or at least rewrite the documentation to discuss this threat.

Or, the company can put up a roadblock/warning mechanism whenever a Flash file tries to use the System.setClipboard() method.

[ SEE: Adobe: Beware of fake Flash downloads ]

Adobe already does this when a SWF file attempts to access a user’s camera or microphone using the Camera.get() or Microphone.get() methods — via a Privacy dialog box, in which the user can allow or deny access to their camera and microphone:

Can Adobe mitigate ‘clipboard hijack’ issue?

While Adobe works on a fix (they should, at the very least, provide a warning screen!), end users should start looking for mitigations elsewhere. I’d start with Firefox and NoScript, a combination that blocks this attack by default.

* Image source: annia316’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

From Metasploit to Microsoft: Skape goes to Redmond

Skape goes to RedmondMetasploit developer Matt Miller, who for years frustrated Microsoft officials with the public release of Windows exploits, is heading to Redmond to join Microsoft’s Security Science team.

Miller, who uses the hacker moniker Skape,will work on improved ways to find security vulnerabilities and better software defenses through mitigations, according to an announcement by SDL guru Michael Howard.

“Matt brings a massive amount of real-world exploit and defense experience to our team,” Howard said, nothing that Miller has been focused on design review for Windows 7, the next major revision of the operating system.

[ SEE: Hacking with Metasploit on a Nokia N800 ]

Miller’s work around exploiting — and attempting to secure — the Windows ecosystem is legendary. In tandem with HD Moore, he has been one of the core developers on Metasploit, a free point-and-click pentest/attack tool, specializing in exploitation techniques/mitigations, reverse engineering, program analysis and modeling, rootkits and virtualization.

Over IM this morning, HD Moore said Miller designed a large chunk of the Metasploit 3 architecture, built the meterpreter payload system, and generally led the entire win32 shellcode improvement efforts.

“He has done some exploit work as well, but his focus was mostly on encoders, shellcode, and payloads,” Moore said. Miller was the third ‘full-time’ developer at Metasploit, having joined the volunteer group in mid-2004.

He is the author of several groundbreaking research papers, including techniques to bypass Windows Hardware-enforced DEP, improving software security analysis using exploitation properties and exploring the history of exploitation techniques (.pdf) and mitigations on Windows.

Miller is also an editor for the Uninformed Journal, a free online journal that focuses on encouraging the sharing of technical knowledge.

UPDATE: Over on Twitter, Dan Guido points out that Miller just open-sourced his WehnTrust HIPS project, which adds anti-exploit mechanisms/mitigations to Windows 2000, Windows XP and Windows Server 2003 systems.

[Source: zdnet]