Hackers "Pwned" at DefCon

Two speakers proved that they hacked into the attendees' computers


Participants at the DefCon hacking conference, focusing on the latest methods of taking over end users' computers and corporate machines, found out that they had been subjects to a hijack themselves. According to an AFP report, the attendees at the conference were startled by the statements of Tony Kapela and Alex Pilosov, two "lecturers" at the conference, who said that they had silently intercepted data belonging to their colleagues.
Hackers at DefCon learned that their computers had also been hijacked
Enlarge picture

The method used by the two consisted in the exploitation of the paths on which data traveled along the network. Routing can be manipulated in such ways that owners of the affected computers can't tell that their online traffic is being tracked or that they receive other information than what they were waiting for. Instead of trying to break passwords or other security systems, hijackers who choose to use this type of approach only have to "convince" websites that the numbers corresponding to their computer defines the best path for these sites to deliver their data through.

The data traffic across the network is automatic, so websites choose, without verifying, the best path according to the numerical Internet address of the routes. The longer the address is, the higher the chances to be chosen. The hackers' job consists of adding some characters to the array to ensure that their computers are chosen as intermediaries between websites and other users. "Someone can passively intercept traffic," Kapela said. "We can store, drop, filter, mutilate, grope, or modify data heading to you."

And, in fact, this happened during DefCon, when some of the colleagues of the two hackers learned that their computers were not as safe as they thought. The two disclosed some email and search information intercepted while using the aforementioned method. In hackers' slang, some of the attendees, although also well-established hijackers, had been "pwned" by the two, meaning they were completely subdued to the actions of Kapela and Pilosov.

[Source: softpedia]

Russian Hacking Web Affects Hundreds of Thousands of Computers

Joe Stewart, Director of Malware Research at SecureWorks, discovered that a group of Russian hackers used a type of trojan that affected over 378,000 computers. The computers, all part of the same network, were infected via a genuine Microsoft application. Coreflood is the name of the trojan used to steal data from the affected machines, in ways that have never been employed before.

Russian hijackers spread their trojan to hundreds of thousands computers

The targeted companies reported a precise interval during which they felt the effects of the attack. SecureWorks observed some "infection events," with hundred of thousands of computers becoming infected on the same day. As trojans cannot spread all by themselves through a network, specialists took into account all the possibilities for that to happen. The team noticed that a Windows administration tool, PsExec, was used to infect all the computers in a network whose owners had domain administrator privileges. ie1823en.exe was then launched on every affected system.

The hackers, who were identified as being Russians, mostly used Coreflood to get information on bank accounts. They also had access to computers from major institutions, which means they could have gotten their hands on even more important data than previously estimated. Also, the hijackers had another advantage over the people and the institutions they attacked: Coreflood allowed them to get account details without having to log in, because the malicious software has the ability to read screen information. This is one of the reasons that make Coreflood so dangerous. Because of the free access to all data stored on a computer, investigators don't know yet the exact extent of incurred damages.

One of the most affected people was Joe Lopez, a businessman who lost $20,000 when this amount was withdrawn by an unauthorized person. After discovering that the money was missing, he also learned that his computer was infected with the trojan. Joe Stewart stated for the New York Times that the situation was under investigation and that, for this very reason, he could not give explicit details about the case.

Stewart also revealed that, while translating some blog posts that allegedly belonged to one of the members of the group of hackers, he found out that another one of them was dead. However, he also emphasized that, no matter the difficulties these hackers might come across, their illicit activity is still being carried on.

[Source: softpedia]

New StopBadware guidelines take aim at software update bundling

StopBadware draft guidelines take aim at software update bundling

If the StopBadware coalition has its way, software updaters from Sun Microsystems (see screenshot above) and Apple will carry the embarrassing “badware” label.

According to a draft of revamped guidelines (.pdf) from the Google-backed computer security consortium, the badware label will expand to include products that:

  • Install a new application through unattended automatic updates.
  • Introduce new potentially unwanted behaviors to an application through unattended automatic updates.

Under these new guidelines, Apple’s WASU (Windows Automatic Sofware Update) utility will be considered badware because it bundles new products like Safari, iTunes and QuickTime alongside security patches without the end user’s explicit consent.

[ SEE: How does Apple get away with this badware behavior ]

The StopBadware alliance is currently seeking feedback on the new guidelines.

The non-profit group said it would not use the badware label for installation of new applications alongside updates if there is separate disclosure and consent.

[Source: zdnet]

Facebook refuses to fix obvious security flaw

Facebook refuses to fix obvious security flaw

[ UPDATE: Facebook has reversed itself and fixed this vulnerability ]

The Register’s Dan Goodin has the scoop on an obvious security vulnerability that’s being ignored by the powers at Facebook.

The issue, as demonstrated by this proof-of-concept, shows how a social network application can be rigged to hijack a Facebook user’s session identification cookies, deliver pop-up messages or change the color of Facebook pages.

“With a little extra work, an attacker could probably do much more, including send and read messages from a user’s account, change privacy settings and add or delete Facebook friends,” according to the report.

When I tested the code while logged in to Facebook, it worked as advertised and proves conclusively that Facebook fails to sanitize the content of third-party applications. This exposes Facebook’s massive user base to a variety of hacker attacks.

[ SEE: Web worms squirm through Facebook, MySpace ]

Worse, the developer who reported the flaw to Facebook says the company has refused to acknowledge the risk.

  • Wachelka said he filed a bug report with Facebook on Friday and promptly received a message saying the matter had been closed. “Our FBML tags are written not to run Javascript,” Facebook asserted.

A weakness in Facebook’s filtering recently exposed users to a malicious worm attack via the site’s commenting system.

* Image source: We Blog Cartoons.

[Source: zdnet]

Hundreds of Dutch web sites hacked by Islamic hackers

In what appears to be a mass defacement, where several hundred domains take advantage of a shared hosting provider,Net Devilz Netherlands starting as of this Friday, an Islamic hacker known as nEt^DeViL — this is not the NetDevilz team that hijacked the DNS records of the ICANN and Photobucket in June — managed to successfully hack a couple of hundred Dutch web sites as a hacktivist response to the release of the Fitna film, a controversial film released by Geert Wilders, a member of the Dutch parliament in March, 2008.

How did they do it? Since all of the sites are parked on a single IP (81.4.97.190) owned by the Geenpunt.nl hosting company, compromising it means having the ability to compromise the content on all the domains hosted there, which is exactly what happened in this case.

The message they left is still active at most of the sites :

“Anti-Fitna ( Response to the Fitna Movie by ‘Geert Wilders’ Cow ! ) This hax0ring is to defend ISLAM - The Religion of [ Abraham, Moses, Jesus & Muhammad ( Peace Be Upon Them All ) ] that Insulted by a Cow ! from Netherlands ! Show Some Respect ! so , I can Leave you in Peace ! [ You’ve Started it ! ] , I don’t have problems with your site but, that what Geert Wilders Cow! chose for you ;) If you think that ” Insulting GOD Religion is a Freedom of Speech as your country did , then allow me to show you my Freedom knowledge of Hacking ;) ”

[ by the way, nothing was deleted relax ^_^ only your index renamed ] [ NOAnti Fitna Defacements WAR ] … [ NO HATING ] … [ NO Lammers ! ] … [ NO Subdirs ;) ] Can Break Your Lame Security ! [ Love Coding than Hacking ;) ‘ Perl , Python , PHP, JavaScript , HTML, VB , Borland Delphi, a Little of C/C++ & Assembly ‘ ]

aB0 m0h4mMed .. for the Old Times Greets & Peace to my Brothers. Abu_Zahra[My Best friend ] ○ Saudia_Hacker ○ Abu Lafy ○ DeadLine , DosMan & b0hAjEr [ Q8Crackers Crew ] ○ Yanis ○ Broken-Proxy ○ Eddy_BAck0o ○ Mianwalian & ZeRo from [#WHACKERZ ] ○ SaveChanges[ PHA ] ○ FBH Crew ○ Apocalypse ○ PaKBrain ○ DaVenjah! ○ BrEakerS ○ Red Devils Crew[ Saudi|x ] ○ by_emR3 , Kerem125 , Gsy & Alemin Krali [ Gr347 7urk15h |3ro7h3r5 ] ○ sys-worm(turkish) ○ F10 ○ ZombiE_KsA ○ xOOmxOOm net_devil@hackermail.com”

Naturally, this isn’t the first time Islamic hacking groups attacked web sites belonging to a particular country that somehow offended their beliefs. For instance, in 2006, the same mass defacements took place on over 600 Danish web sites in response to the Mohammed’s cartoons released in local newspapers. This hacktivist approach of spreading propaganda isn’t necessarily a full-scale cyber war, it’s an example of information warfare aiming to reach as many Dutch Internet users as possible due to the apparently insecure web hosting provider that they are all using.

Pure hacktivism isn’t dead, as compared to previous web site defacement analysis where the people behind them were hacktivismmultitasking by also hosting malware, phishing and blackhat SEO junk pages on the compromised servers, in this case they only defaced the main pages. However, what pure hacktivism turned into today, consciously of subconsciously, is the propaganda division of an information warfare unit, where given the hundreds of thousands of easily detectable insecure sites within a particular country’s Web, this political propaganda can easily turn into a large scale malware attack.

As in real life through, the real cyber conflicts usually start due to such provocations where a single group or a script kiddie’s actions can cause a lot of damage if that’s what they want to achieve at the first place.

[Source: zdnet]

DEFCON 16: List of tools and stuff released

Defcon 16 tools and utilities

DEFCON, the 9000+ attendee hacker conference in Vegas has become a sort of hydra conference. It has become more like a global fair than what most people think of conferences; even the badge is highly unique.

I say this because there are so many things to do at DEFCON, other than going to talks, that you could spend your whole weekend looking at the “World’s Largest Boar!”, so to speak. One of the CTF (Capture the Flag) contest winners this year actually exclaimed that he only made it to 2 talks in 12 years! I am also one of those individuals who barely get a chance to go to talks and now that the speaker pool is so diverse, it’s hard to find all of the “stuff” they release.

Before anyone has a chance to post “it’s all on the DEFCON CD dummy,” I want to challenge them to try. After a weekend of googling (which came back with few results) and making contact with some of the speakers, I provide you with a mostly accurate list of “stuff” that was released at DEFCON this year. If any of the information is inaccurate, or a tool is missing, please contact me and I will update this post.

Beholder – by Nelson Murilo and Luis Eduardo

  • Description: An open source wireless IDS program
  • Homepage Link: http://www.beholderwireless.org/
  • Email Address: bh@beholderwireless.org
  • The Middler – by Jay Beale

  • Description: The end-all be-all of MITM tools
  • Homepage Link: http://www.themiddler.com/ (Online?)
  • Preface Link: http://www.intelguardians.com/themiddler.html
  • ClientIPS – by Jay Beale

  • Description: An open source inline “transparent” client-side IPS
  • Homepage Link: http://www.ClientIPS.org/ (Online?)
  • Marathon Tool – by Daniel Kachakill

  • Description: A Blind SQL Injection tool based on heavy queries
  • Download Link: DEFCON 16 CD. No online link found.
  • Email Address: dani@kachakil.com
  • The Phantom Protocol – by Magnus Brading

  • Description: A Tor-like protocol that fixes some of Tor’s major attack vectors
  • Homepage Link: http://code.google.com/p/phantom
  • Email Address: brading@fortego.se
  • ModScan – by Mark Bristow

  • Description: A SCADA Modbus Network Scanner
  • Homepage Link: http://modscan.googlecode.com/
  • Email Address: mark.bristow@gmail.com
  • Grendel Scan – by David Byrne

  • Description: Web Application scanner that searches for logic and design flaws as well as the standard flaw seen in the wild today (SQL Injection, XSS, CSRF)
  • Homepage Link: http://grendel-scan.com/
  • iKat – interactive Kiosk Attack Tool (This site has an image as a banner that is definitely not safe for work! – You have been warned) by Paul Craig

  • Description: A web site that is dedicated to helping you break out of Kiosk jails
  • Homepage Link: http://ikat.ha.cked.net
  • Email Address: paul.craig@security-assessment.com
  • DAVIX – by Jan P. Monsch and Raffael Marty

  • Description: A SLAX based Linux Distro that is geared toward data/log visualization
  • Homepage Link: http://code.google.com/p/davix/
  • Download Link: http://www.geekceo.com/davix/davix-0.5.0.iso.gz
  • Email Addresses: jan.monsch@iplosion.com and raffy@secviz.org
  • CollabREate – by Chris Eagle and Tim Vidas

  • Description: An IDA Pro plugin with a server backend that allows multiple people to collaborate on a single RE (reverse engineering) project.
  • Homepage Link: http://www.idabook.com/defcon
  • Email Addresses: cseagle@gmail.com and tvidas@gmail.com
  • Dradis – by John Fitzpatrick

  • Description: A tool for organizing and sharing information during a penetration test
  • Homepage: http://dradis.sourceforge.net
  • Email Address: john.fitzpatrick@mwrinfosecurity.com
  • Squirtle – by Kurt Grutzmacher

  • Description: A Rouge Server with Controlling Desires that steals NTLM hashes.
  • Homepage: http://code.google.com/p/squirtle (Live?)
  • Email Address: grutz@jingojango.net
  • WhiteSpace – by Kolisar

  • Description: A script that can hide other scripts such as CSRF and iframes in spaces and tabs
  • Download Link: DEFCON 16 CD
  • VoIPer – by nnp

  • Description: VoIP automated fuzzing tool with support for a large number of VoIP applications and protocols
  • Homepage Link: http://voiper.sourceforge.net/
  • Barrier – by Errata Security

  • Description: A browser plugin that pen-tests every site that you visit.
  • Homepage Link: http://www.erratasec.com
  • Email Address: sales@erratasec.com
  • Psyche – by Ponte Technologies

  • Description: An advanced network flow visualization tool that is not soley based on time.
  • Homepage Link: http://psyche.pontetec.com/
  • * Rob Fuller is a security researcher and pen-tester. He can be found on Twitter and in Room 362.

    [Source: zdnet]

    OpenVAS emerges as free alternative to Nessus

    OpenVAS emerges as Nessus alternativeA new open-source project called OpenVAS has emerged to take the place of Nessus, the popular vulnerability assessment system that closed its source a few years ago.

    The first stable version of OpenVAS, which is a fork of Nessus 2.2, was released this week featuring a server, a client and an NVT (network vulnerability tests) feed.

    Installation packages are available for OpenSUSE, Fedora, Mandrake, FreeBSD and Gentoo. Packages for Debian and Ubuntu are in the works, the group said. An OpenVAS-Client is available for Microsoft Windows.

    The nitty gritty of the new project:

    [ SEE: Questions swirl as Sourcefire buys ClamAV ]

    • OpenVAS Server — This is a scanner that runs many network vulnerability tests against many target hosts and delivers the results. It uses a communication protocol to have client tools (graphical end-user or batched) connect to it, configure and execute a scan and finally receive the results for reporting. Tests are implemented in the form of plugins which need to be updated to cover recently identified security issues. The server consists of 4 modules: openvas-libraries, openvas-libnasl, openvas-server and openvas-plugins. All need to be installed for a fully functional server.
    • OpenVAS-Client — This is a terminal and GUI client application for both OpenVAS and Nessus. It implements the Nessus Transfer Protocol (NTP). The GUI is implemented using GTK+ 2.4 and allows for managing network vulnerability scan sessions. OpenVAS-Client is a successor of NessusClient 1.X.
    • OpenVAS NVT Feed – This is a public feed of Network Vulnerability Tests (NVTS). It contains only signed files and only the supported NVT families and their dependencies. This feed is configured as default for OpenVAS Server.

    The OpenVAS development team plans to extend the range of the vulnerability tests for present and upcoming security issues, especially for those reported as CVEs, BIDs etc.

    [Source: zdnet]