Spam rates massively down on shutdown of rogue ISP

Several major news outlets are reporting that the shutdown of a rogue ISP in the Bay Area has lead to a massive drop in the global amount of spam. While this is “good thing”, this event is not an end of spam, nor is it even the beginning of the end of spam; it is merely a temporary lull.

Thanks in no small part to evidence gathered by Brian Krebs, The San Jose based McColo was dropped from the Internet yesterday resulting in a massive decline in spam rates around the globe. The common consensus right now is that the takedown resulted in a 35% to 50% drop in inbound spam sending attempts.

The shutdown has removed pieces of infrastructure critical for the operation of several spammers, but this does not mean they cannot adapt. We have seen that command and control servers can be eliminated by using distributed control algorithms, and storefronts can be hidden across compromised websites. The spammers may even regroup by recreating the services provided by McColo somewhere in Eastern Europe.

While many people would like to declare this event as the first step in the end to spam, I can pretty much guarantee you that it isn’t. Over the next few weeks, spammers will further decentralize their operation, turn the botnets back on, and restart their barrage.

[Source: zdnet]

$10k hacking contest announced

Hacking ContestIsraeli software developer Gizmox is challenging hackers to try hacking into the company’s Visual WebGui Platform, by offering a $10,000 incentive to those who manage to achieve the objectives of their contest launched at the beginning of the month. What’s particularly interesting about the contest is the fact that the company is running the contest as an investigation into the identity of their secret agent, the data for whom resides on their unhackable platform.

Nothing’s unhackable, the unhackable just takes a little longer.

“Gizmox, the developer of Visual WebGui open source platform, today announced a contest, sponsored by the Company, which will pay $10,000 to anyone who can hack into its Visual WebGui Platform. The Contest will take the shape of an investigation into the identity of a secret agent. The goal of the contest is to uncover the true identity of their secret agent, code named OWL. The Contest will feature a flash movie presented within the Visual WebGui application that will contain the data necessary to uncovering the identity of the OWL. Participants will be required to provide a reproducible pathway into the Visual WebGui Pipeline (without having to penetrate any non Visual WebGui Peripherals) in order to claim the prize. The contest will begin on November 3rd and end January 30th, Participants must register to receive login information and contest details.”

Registration is open to everyone, here are some of the highlights of what is considered acceptable hacking of the company’s framework :

“- The game assumes that the database is safe and cannot be penetrated to; hacking the database in any level will not qualify. In addition gaining a more powerful username and password is only valid if done through Visual WebGui path and will not be a valid winner in any other case.
- Assume in general, that any peripheral system and software is safe and cannot be penetrated through; in general a non-Visual WebGui layer hack-through will not be considered a win.
- Hacking through the Visual WebGui pipeline only is acceptable, meaning that using the VWG AJAX messages will qualify for winning the award.
- Manipulating any client code (JS, XSLT, XML, HTML and any client resource) is permitted, in order to try and shift the system from its original security behavior.
- Using any side effects or consequences of Visual WebGui code in runtime in order to hack the system is allowed, as long as the actual hack will use those side effects and consequences in order to manipulate the original server security behavior and not to penetrate any other software or infrastructure.”

Gizmox Hacking ContestOffering financial incentives in the form of hacking contests or bug bounties are nothing new. For instance, in 2000 PacketStormSecurity offered $10k reward for the winner in their “Protecting Against the Unknown” whitepaper contest, with another $10k offered by iDefense for a critical Microsoft vulnerability in 2006, followed by the most recent PWN 2 OWN $10k reward this year.

Gizmox’s contest is different in that it’s indirectly advertising the “unhackability” of its products compared to enticing research into the products of other companies. Whatever their motivation, the contest is worth the try, especially when their AJAX/Silverlight Web Applications Framework can be “examined” for free.

[Source: zdnet]

Google fixes critical XSS vulnerability

Google SSL Login XSSAll your accounting data are not belong to us. Hours after a proof of concept example detailing a XSS vulnetability at Google’s account login page was posted at the XSS Project’s clearing house, the company quickly took notice and fixed it.

“Security researcher “Xylitol” is credited with the discovery of this critical bug. In this case, the fact that SSL is being used on the login page, does not necessarily mean that the users’ login information is secured. Malicious people can exploit this Google XSS to propagate malware, spyware, adware and steal authentication credentials.”

Google SSL Login XSSIn October, Google was criticized for not paying attention to an already reported cross domain frame injection vulnerability, prompting the release of a proof of concept example demonstrating how third-party content can be injected within Google pages. Ignoring the endless debate of the pros and cons of full disclosure, responsible disclosure and partial disclosure for a moment, the fact that a large number of already reported vulnerabilities remain unfixed despite the potential for abuse, clearly indicates a company’s commitment — or the lack of.

XSSed is a great open source resource, whose early warning feature and RSS feeds are an invaluable resource that could help the affected sites into prioritizing the fixing of particular flaw that’s now in the public domain, if only were the affected companies to embrace it as such.

[Source: zdnet]

MS Patch Tuesday: Critical Windows, Office flaws fixed

Microsoft patches 4 critical flaws on Patch TuesdayMicrosoft’s scheduled batch of patches for November crossed the wires today with fixes for at least four documented vulnerabilities affecting millions of Windows and Office users.

As previously reported, the company released two security bulletins — one rated critical, one rated important — with fixes for flaws that could lead to remote code execution attacks. The updates apply to users running all supported versions of Windows (including Vista and Windows Server 2008) and most versions of Microsoft Office.

The critical MS08-069 bulletin should be treated with the utmost priority because of the risk of remote code execution attacks if a Windows user is simply tricked into browsing to a rigged Web page with Internet Explorer.

Details from the bulletin:

  • CVE-2007-0099: A remote code execution vulnerability exists in the way that Microsoft XML Core Services parses XML content. The vulnerability could allow remote code execution if a user browses a Web site that contains specially crafted content or opens specially crafted HTML e-mail. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
  • CVE-2008-4029: An information disclosure vulnerability exists in the way that Microsoft XML Core Services handles error checks for external document type definitions (DTDs). The vulnerability could allow information disclosure if a user browses a Web site that contains specially crafted content or opens specially crafted HTML e-mail. An attacker who successfully exploited this vulnerability could read data from a Web page in another domain in Internet Explorer. In all cases, however, an attacker would have no way to force users to visit these Web sites.
  • CVE-2008-4033: An information disclosure vulnerability exists in the way that Microsoft XML Core Services handles transfer-encoding headers. The vulnerability could allow information disclosure if a user browses a Web site that contains specially crafted content or opens specially crafted HTML e-mail. An attacker who successfully exploited this vulnerability could read data from a Web page in another domain in Internet Explorer.

The second update — MS08-068 — provides cover for a publicly disclosed vulnerability in Microsoft Server Message Block (SMB) Protocol. Exploit code for this flaw is currently available on the Internet.

  • CVE-2008-4037: A remote code execution vulnerability exists in the way that Microsoft Server Message Block (SMB) Protocol handles NTLM credentials when a user connects to an attacker’s SMB server. This vulnerability allows an attacker to replay the user’s credentials back to them and execute code in the context of the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
[Source: zdnet]

Why did Microsoft wait 7 years to fix SMBRelay attack flaw?

Micosoft takes 7 years to fix SMB Relay vulnerabilityOne of the code execution vulnerabilities fixed in this month’s Microsoft Patch Tuesday release dates back to 2001 when it was first disclosed by Cult of the Dead Cow hacker Sir Dystic (pictured left).

If that wasn’t cause for worry, get this: An exploit for the bug — in the way that Microsoft Server Message Block (SMB) Protocol handles NTLM credentials — has been part of the Metasploit hacking tool since July 2007.

So, why did it take Microsoft seven years to fix something that could lead to full system takeover?

Microsoft’s Christopher Budd explains:

When this issue was first raised back in 2001, we said that we could not make changes to address this issue without negatively impacting network-based applications. And to be clear, the impact would have been to render many (or nearly all) customers’ network-based applications then inoperable. For instance, an Outlook 2000 client wouldn’t have been able to communicate with an Exchange 2000 server. We did say that customers who were concerned about this issue could use SMB signing as an effective mitigation, but, the reality was that there were similar constraints that made it infeasible for customers to implement SMB signing.

[ SEE: Responsible disclosure, the Microsoft way ]

Sisk said the case was never closed and investigations continued over the years to determine if there was a way to fix the bug without requiring developers to completely rewrite applications.

Over the course of the past year, however, that ongoing work showed us a way to build on those incremental changes that we believed would enable us to make changes that address the issues outlined in the SMBRelay attack and also minimize the impact on network applications. If we were able to do that, we would be able to look at addressing this issue not in a new version of Windows but instead in a security update, provided it met the appropriate quality bar.

Our engineering teams spent a great deal of time testing this approach and found it was feasible. We then took that work and developed it into a security update, putting it through our standard testing to ensure it met an appropriate level of quality for broad release. What we released today with MS08-068 is that security update. It addresses the SMBRelay issue but does so in a way that doesn’t have the negative impact on applications that we originally believed addressing this issue would have.

[ SEE: Where on earth are these Microsoft patches? ]

Microsoft wasn’t alone discussing attack paths to this old vulnerability. In 2003, on the Full Disclosure mailing list, there’s evidence of public discussion of the issue and a note by Dave Aitel that it was already part of a previous DefCon presentation.

Microsoft has done an amazing job of improving its security response process but these time-to-patch hiccups continue to be a major source of worry. I’ve documented several times in the past when Microsoft failed to fix issues in a timely — and responsible — manner and these examples only highlight one of the company’s biggest security weakness.

Oh, by the way, there’s another outstanding issue collecting cobweb. This ‘token kidnapping’ issue was first discussed in March 2008 and, after a bit of hemming and hawing, confirmed in this Microsoft security advisory. Exploit code for this privilege escalation vulnerability was publicly released last month.

Microsoft knows all this.

We are still waiting on a patch.

[Source: zdnet]

BBC hit by a DDoS attack

BBC DDoS AttackThe British Broadcasting Corporation (bbc.co.uk) was hit by a DDoS attack on Thursday, according to a statement sent to the Inquirer :

“In a statement to the INQ, the BBC said the attack originated in a number of different countries but didn’t specify which. When the Beeb’s techies blocked international access to a limited subset of servers, it resulted in a marked improvement of the serving of bbc.co.uk. Service supplier Siemens was forced to block addresses and prevent the attack using other methods like changing the DNS settings.”

The attack appears to have lasted for 1 hour and 15 minutes, which is the longest time the site has been offline during the entire 2008, was also confirmed by the distributed uptime monitoring company Pingdom earlier today :

“During the attack, the BBC website responded very slowly, and our monitoring shows that for a total of 1 hour and 15 minutes it did not respond at all. The downtime was spread over multiple short intervals, lasting just a few minutes each time. The attack lasted the entire evening. It started to have an effect after 5 p.m. CET and the performance was not back to normal until after 10 p.m. CET. Analyzing the response times of the website clearly shows the effect the DDoS attack had on the performance of the BBC website. The diagram below shows the hourly average load time of the HTML page (just the HTML page, without any images, external scripts, etc).”

Was the attack an act of hacktivism based on a particular article that somehow contradicted with the attackers’ perspective of the world? With the lack of specific details regarding the DDoS attack provided by the BBC, we may never know. One thing’s for sure - political DDoS attacks (Georgia President’s web site under DDoS attack from Russian hackers; Coordinated Russia vs Georgia cyber attack in progress) are going to get even more mainstream in 2009.

What are some of the driving factors contributing to this trend? The overall availability of malware infected hosts, which when once monetized ends up in DDoS for hire services whose prices for a large scale hourly attack are getting disturbingly affordable to anyone. The recently released “Worldwide Infrastructure Security Report” report by Arbor Networks also indicates that the DDoS attack rates exceed the ISP network’s growth, and have already reached the 40GB barrier. Ironically, the report also states that managed DDoS mitigation services are increasing, which is exactly what is happening on the DDoS for hire services front - they’re becoming ubiquitous as outsourcing DDoS attacks to experienced attackers directly messes up the entry barriers into a space that used to require experience, and an operational botnet a couple of years ago.

[Source: zdnet]

Profitability of spam finally measured

Researchers at UCSD have determined the return on investment for spam generated by the Storm botnet. While the per-message response rate is astonishingly low, it is sufficient for a spammer to generate a profit.

At this year’s ACM Conference on Computer and Communication Security, Stefan Savage, Vern Paxson and crew presented a paper that measures the conversion rate, or the rate at which an advertising impression results in a product sale, for spam. The team used somewhat aggressive tactics to collect their data; namely, they hijacked a portion of the Storm botnet to inject spam that contained links to domains and storefronts they controlled.

The team’s data and analysis has shown that that generating 28 sales, averaging around $100 each, of various “male-enhancement” products required 350 million separate spams. This provides a yearly revenue rate of the Storm botnet for the sale of pharmaceuticals of around $3.5 million dollars.

What I feel to be the most interesting result from the paper is the direct measurement of the quality of anti-spam technology broken down by geographic location. The countries with the spam lowest response rate include the UNited States and Japan. Both nations have some of the highest capital investment in anti-spam technologies. As of early 2008, the countries with the worst anti-spam technology appear to be India, Pakistan, and Bulgaria.

The researchers do state that the profit margins of the spammers appear to be sensitive to anti-spam techniques. I am left to wonder what would be the profitability of spam if everyone in the world used effective anti-spam software.

[Source: zdnet]