MSN Norway serving Flash exploits through malvertising

Morten Krakvik from the Norwegian Honeynet Project is reporting that MSN Norway is among the latest victims ofMSN Norway malvertising, a practice where a bogus advertising provider tricks leading portals into accepting advertisements from its network, which often end up redirecting to live exploit URLs. The recent wave of malvertising that also targeted Digg, MSNBC and Newsweek, is very similar to the malvertising campaigns that took place in February which were targeting popular sites as Expedia, Excite, Rhapsody and MySpace. The only thing the malvertisers keep changing are the fake security software domains that they push through their campaigns.

Flash player versions susceptible to exploitation are :

Adobe Flash 9.0.16
Adobe Flash 9.0.28
Adobe Flash 9.0.45
Adobe Flash 9.0.47
Adobe Flash 9.0.115

According to Krakvik’s analysis, the malicious ad came from bannersrotator DOT com which is still active, and servingbannersrotator the malicious ad (tunnel28.swf) currently detected by 9 out of 36 antivirus scanners as SWF:CVE-2007-0071, or SWF.Exploit.

Who’s to blame anyway? The end users for not bothering to patch their browsers and third-party applications at the first place, the portals for doing business with such obviously rogue advertising providers like bannersrotator DOT com, or the advertising networks sacrificing security for efficiency and not screening the ads and newly joining advertisers like bannersrotator DOT com?

It’s the lack of decent situational awareness demonstrated by all parties. For instance, the end user thinking that patching their browser is where it all ends, the portals for not taking advantage of publicly obtainable tools aimed at analyzing malicious flash files, and the advertising networks themselves, for choosing efficiency next to security and helping rogue security software providers have their ads syndicated across legitimate sites.

[Source: zdnet]

iPhone passcode lock rendered useless

iPhone passcode lock rendered uselessDo not trust that passcode lock on Apple’s iPhone.

The feature, which lets users set a four-digit pincode to limit access to the device, can be easily bypassed with a few finger taps on the iPhone to give an intruder access to sensitive information.

Here are a few steps to reproduce this vulnerability (requires physical access to a passcode-protected device) to access the phone, e-mail and SMS messages, Google Maps and the full Safari browser:

  • Set up a passcode lock (Settings > General > Passcode Lock and enter a 4-digit passcode. iPhone then requires you to enter the passcode to unlock it).
  • Set up contacts in address book with e-mail address, phone numbers and Web sites.
  • Turn off/on iPhone and move slider to get to “Enter Passcode” screen.
  • Tap “Emergency Call” button (buttom left).
  • Double tap home button.
  • This pulls up all contacts in the Favorites list.
  • Tap on the blue arrow next to contact’s name to get full access to e-mail, SMS, Safari, etc.

Here’s the most troubling thing about this vulnerability: It was fixed by Apple (see advisory) for iPhone v1.1.3 and iPod touch v1.1.3 back in January this year.

  • Passcode Lock
    CVE-ID: CVE-2008-0034
    Available for: iPhone v1.0 through v1.1.2
    Impact: An unauthorized user may bypass the Passcode Lock and launch iPhone applications
    Description: The Passcode Lock feature is designed to prevent applications from being launched unless the correct passcode is entered. An implementation issue in the handling of emergency calls allows users with physical access to an iPhone to launch an application without the passcode. This update addresses the issue through an improved check on the state of the Passcode Lock.

I have confirmed this issue affects iPhone and iPod Touch 2.0, which means the January fix never made it into the newer versions of the software.

The obvious workaround: Remove all Favorites until Apple ships a proper fix.

UPDATE: In the TalkBack section, reader zrds comes up with a better workaround:

  • I’d like to point out that a good workaround is setting your home button “Settings->General->Home Button” to “Home” will effectively negate the issue.

This does work much better as a mitigation.

[Source: zdnet]

Feel like taunting an identity thief? Don’t.

Phishers bite backThe next time you get the urge to enter angry messages to phishers on fake (malicious) Web sites, stop and consider this discovery by researcher Joe Stewart.

The identity thieves behind the Asprox botnet have built extra logic into phishing sites to detect taunts and subject those computer users to drive-by malware exploits.

“If you are running Windows and haven’t recently installed your security updates and patched all your browser plugins/ActiveX controls, you might find yourself infected with your very own copy of Asprox,” Stewart warns.

Not only do you then get the opportunity to unknowingly send phishing emails on behalf of the botnet, you will likely get some extra goodies, since Asprox is also a downloader trojan. You won’t notice it running, but you might notice some of the things it downloads and installs.

For instance, you might find your desktop wallpaper changed to a “spyware alert” type of message, and now all your screen saver shows is scary blue-screens-of-death.

[ SEE: Adobe Flash ads launching clipboard hijack attack ]

Stewart posts screen shots with evidence that the Asprox botnet operators are linked to the attackers behind the rogue security software (scareware) attacks.

And at any time, Asprox might deliver another malicious payload and install it for you - and it could be much worse: we’ve seen the Zbot banking trojan installed by Asprox in the past. So instead of a dealing with a nuisance program, you might be silently sending your banking and credit card information to the botnet owners. Something to think about before venting your frustrations on the bad guys. Sometimes phish bite back.

* Image source: David Locke’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Malware detected at the International Space Station

Malware is reaching new heights, and going into Space through a removable media carrying the W32.Gammima.AGISS Malware password stealing malware to the International Space Station. According to SpaceRef.com :

“W32.Gammima.AG worm is a level 0 gaming virus intended to gather personal information. Virus was never a threat to any of the computers used for cmd and cntl and no adverse effect on ISS Ops. Theory is virus either in initial software load or possibly transferred from personal compact flash card. Working with Russians (and other partners) regarding ground procedures to protect flown equipment in the future. It was noted that most of the IP laptops and some of the payload laptops do NOT provide virus protection/detection software .”

Going through some of the daily reports from the ISS, it appears that the folks above us may in fact be doing more antivirus signature updates and scanning of arriving removable media then the average Internet users here on Earth. Trouble is, this approach only mitigates the risk of infection from known threats. How long before the ISS’s laptops start phoning back to a botnet command and control here on Earth upon having their laptops infected with an undetectable by their AV scanner malware?

Wired’s Ryan Singel quotes NASA spokesman Kelly Humphries that “This is not the first time we have had a worm or a virus, it’s not a frequent occurrence, but this isn’t the first time :

“NASA downplayed the news, calling the virus mainly a “nuisance” that was on non-critical space station laptops used for things like e-mail and nutritional experiments. NASA and its partners in the space station are now trying to figure out how the virus made it onboard and how to prevent that in the future, according to Humphries.”

Moreover, according to the 2007’s Final Report of the International Space Station Independent Safety Report, someone needs to tip NASA on why quarterly scanning for vulnerabilities leaves a wide open window of opportunity for exploitation through client-side exploits executed against the crew’s laptops :

“The software and workstations that perform communications and commanding functions also have several security measures. Security for the MCC workstations is governed by and consistent with the National Information Assurance Policy for U.S. Space Systems. All work-stations for command and telemetry are continuously monitored by standard anti-virus and spy-ware protection software and are scanned quarterly for vulnerabilities using the latest industry standard security software. Password protection is in place on all workstations and only certain users/accounts can access ISS commanding servers, which require an additional password. Access to ISS commanding is further limited by partitioning available commands by user groups, and users only have access to the commands necessary to perform that discipline’s function. To provide a quality check of commands, two people are required to perform a command. Finally, all commands to the vehicle are encrypted and must pass through a series of validity and authentications checks.”

Wonder which antivirus software they’re running at the ISS? The daily reports detailing the activities of the crew members provide some interesting details :

  • ISS On-Orbit Status 08/14/08 - Working on the Russian RSS-2 laptop, Sergey Volkov ran digital photo flash cards from stowage through a virus check with the Norton AntiVirus application
  • ISS On-Orbit Status 11/14/07 - Yuri also had about an hour set aside for inspecting RS onboard computer & OpsLAN/Ethernet systems, including verifying laptop equipment, familiarizing himself with cabling functions and laptop assignments, checking anti-virus signature updates on the RSS2 laptop, and checking computer spares & accessories kits
  • ISS On-Orbit Status 08/21/08 - Sergey checked another Russian laptop, today RSK-1, for software virus by scanning its hard drives and a photo disk with the Norton AntiVirus application
  • ISS On-Orbit Status 08/22/08 - CDR Volkov began his day by downlinking yesterday’s Norton AntiVirus (NAV) data from the RSK-1 laptop scan

Since it’s fairly logical to assume that the ISS is heavily networked using protocols that malware can easily spread through despite not being originally written and intended to reach the ISS, NASA should definitely take this repeating situation more seriously next to calling a “nuisance”.

Image courtesy of NASA.

[Source: zdnet]

Microsoft confirms ‘InPrivate’ IE 8

Microsoft confirms IE 8 private browsing modeWhen Microsoft’s Internet Explorer 8 browser makeover ships later this year, it will feature several nifty privacy features aimed at giving surfers control over their Web footprints.

One week after bloggers discovered clues that IE 8 will include a private browsing (ahem, porn mode), Microsoft used the official IE blog to discuss four new granular controls in the browser.

They include:

  • InPrivate Browsing: This lets you control whether or not IE saves your browsing history, cookies, and other data.
  • Delete Browsing History: This helps you control your browsing history after you’ve visited Web sites.
  • InPrivate Blocking: This informs you about content that is in a position to observe your browsing history, and allows you to block it.
  • InPrivate Subscriptions: This feature allow you to augment the capability of InPrivate Blocking by subscribing to lists of Web sites to block or allow.

[ SEE: Anti-malware blocker, cross-site scripting protections coming in IE 8 ]

Microsoft program manager Andy Zeigler provides all the details on the new features and my colleague Mary Jo Foley has some additional commentary.

The new beta refresh will also include support for safer Web 2.0-type mashups, DEP (data execution protection) turned on by default in Windows Vista SP 1, domain highlighting to help flag phishing attacks and changes to the way ActiveX controls are handled.

[Source: zdnet]

Linux under attack: Compromised SSH keys lead to rootkit

Compromised SSH keys leads to rootkitThe U.S. Computer Emergency Readiness Team (CERT) has issued a warning for what it calls “active attacks” against Linux-based computing infrastructures using compromised SSH keys.

The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as “phalanx2″ is installed, US-CERT said in a note on its current activity site.

From the advisory:

  • Phalanx2 appears to be a derivative of an older rootkit named “phalanx”. Phalanx2 and the support scripts within the rootkit, are configured to systematically steal SSH keys from the compromised system. These SSH keys are sent to the attackers, who then use them to try to compromise other sites and other systems of interest at the attacked site.

Phalanx, which dates back to 2005, is a self-injecting kernel rootkit designed for the Linux 2.6 branch. It allows an attacker to hide files, processes and sockets and includes a tty sniffer, a tty connectback-backdoor, and auto injection on boot.

Details on the attacks — and targets — remain scarce but it’s a safe bet this is linked to the Debian random number generator flaw that surfaced earlier this year. A working exploit for that vulnerability is publicly available.

To mitigate the risk from this attack, US-CERT recommends:

  • Proactively identify and examine systems where SSH keys are used as part of automated processes. These keys will typically not have passphrases or passwords.
  • Encourage users to use the keys with passphrase or passwords to reduce the risk if a key is compromised.
  • Review access paths to internet facing systems and ensure that systems are fully patched.

If a compromise is confirmed, US-CERT recommends:

  • Disable key-based SSH authentication on the affected systems, where possible.
  • Perform an audit of all SSH keys on the affected systems.
  • Notify all key owners of the potential compromise of their keys.

* Image source: wili_hybrid’s Flickr photostream (Creative Commons 2.0)

[Source: zdnet]

Twitter’s “me too” anti-spam strategy

With Twitter’s continuing growth, its popularity is logically starting to attract the attention of malicious parties, likeTwitter Blacklisting spammers, phishers, and malware authors who wouldn’t mind the fact that nobody is following them when they’re actively updating several hundred users with their latest propositions.

Last’ week’s Twitter announcement that it’s “Turning Up The Heat On Spam” clearly indicates that they are not just aware of the problem, but also, admitting their current inability to deal with it the way they want to. So what is the Twitter team up to? Suspending accounts, community powered feedback on spammers accounts, and hiring dedicated personnel to look for, and shut down spammer’s accounts. Will these measures work? It’s all a matter of implementation, breaking out of the “me too” anti-spam strategies mentality, and listening to what the community has been saying for months.

Twitter is at least being realistic to the situation, and is not offering the Moon with these approaches :

“Suspending a spam account only works after it’s already caused some damage. We have enhanced our admin tools to more accurately factor your feedback for a more timely diagnosis. When you block a spam account, we take note—when more people start blocking a spam account, we go to red alert. Blocking also puts that account out of sight and out of mind so you don’t have to see it anymore.

It’s unfortunate that this has to be done but we’re going to hire people whose full time job will be the systematic identification and removal of spam on Twitter. These folks will work together with our support team, and our automatic spam tools. Our first “spam marshal” is starting at Twitter next week.

As always, fighting spam is a sustained activity. There is no magic wand we can wave or switch we can flip to make it all go away. Spammers will keep finding inventive new ways to advance their motives and harm user experience and we’ll keep shutting them down and slowing their progress. We just wanted to make sure everyone knows that we are taking spam seriously.”

Spammers, phishers and malware authors are becoming harder to differentiate, with each and everyone of these getting involved in areas that used to be exclusively the other party’s territory a while ago. Consequently, what looks like a typical phishing link, may in fact be redirecting to a live exploits page, where the typical exploits set taking advantage of the most common client-side vulnerabilities is waiting for the gullible Twitter-er. Despite it’s recent limiting of followers of a particular account to 2000 in order to prevent malicious users from causing more damage than they could, if Twitter really want some creative thinking applied in the process, it should consider researching what the community has already come up with in the form of tools, strategies and recommendations for Twitter to implement.

For instance, the success of the now down Twitter Blacklist was based on the simple categorization of Twitter users inTwitter Spam order to increase the probability of detecting a spammers account using a simple logic based on the followers and following ratio - 1:5 = twittercaster, 1:2 = notable, 1:1 socially healthy, 2:1 newbie or social climber, 5:1 twitter spammer.

Another highly successful self-auditing service, again courtesy of the community is called Twitter Twerp Scan which “checks the number of followers of everyone on your contact list, the number of people they are following, and the ratio between those. If the person is following more than (n) people (can be customised), and has a Following-to-Followers ratio higher than 1:(m) (can be customised), you’ll be notified by a link.”

There’s also never been a shortage of pragmatic solutions to at least make it harder to spammers to efficiently spam the network, with tips and recommendations made by Twitter users a couple of months ago :

Twitter’s successful anti-spam strategy lies within whether or not they will consider the know-how and experience offered by the community, which as always finds its ways to adapt to a specific situation long before a service has come to introduce its own solution.

Add spam button courtesy of chadspacey’s photostream.

[Source: zdnet]