Monday, February 23, 2009

Hackers have been spreading malicious PDF Files

Adobe zero-day flaw already attracting attention

A newly discovered zero-day vulnerability within Adobe's Acrobat Reader is being actively targeted by attackers, warns researchers at Symantec Corp.

Hackers have been spreading malicious PDF Files containing the Pidef Trojan. If a person opens the malicious PDF file, the Trojan attempts to exploit an unpatched processing error in Adobe Acrobat Reader 8 and 9, which results in a buffer overflow.

"Malicious PDFs using this exploit will be detected as Trojan.Pidief.E," Symantec said in a statement. Symantec said it received reports of attacks targeting the vulnerability at government, large enterprises and financial services organizations. Exploit code is circulating in the wild in the U.S., China, Japan, Taiwan and the U.K.

Please refer here to read full details and click here to update your Adobe Acrobat Reader.

Sunday, February 22, 2009

Why Microsoft OS is more susceptible to attacks than other OS?

How to Write a Linux Virus in 5 Easy Steps

It's easy for people to pick at Windows for being prone to virus and malware attacks. It's almost a given belief that if you're running a PC with a Windows operating system, you're much more susceptible to attacks than users with other operating systems.

But let's quickly look at the reasons for this. First, it isn't really Microsoft's fault. It isn't that Windows is technically inferior, it's that the majority of the world runs on Windows. This fact alone is very attractive for any virus coder or exploiter. As a vrius writer, you'd want to attack the majority, not the minority.

Secondly, because the vast majority of the world's computers runs on Windows, everyone from very tech savvy users to the greenest of novices is included in this pool. There are many who are just not as educated--for various reasons--about software and Internet safety. So here we have a huge pool of people, many of which aren't informed. These are two main reasons why a Windows desktop is the prime target for attacks.

Please refer here to read in detail step-by-step guide about How to Write a Linux Virus in 5 Easy Steps.

Friday, February 20, 2009

Malware crooks were quick to develop MS09-002 exploit

MS09-002 Exploit in the wild uses MSWord Lure

An exploit found to be targeting a recently patched vulnerability for Internet Explorer 7 was discovered in-the-wild. Malware crooks were quick to develop a working exploit for the vulnerability in Internet Explorer 7, which was part of the February Microsoft patch release. Microsoft rated this vulnerability critical with the possibility of a consistent exploit code.

The attack, delivered in the form of a maliciously crafted document, is sent out to unsuspecting users. This word document contains an embedded ActiveX control which upon opening, connects to a website hosting the MS09-002 exploit.

Malware authors are always working to create new and improved ways to evade detection and control compromised machines. This time, malware authors introduced obfuscation (base64 encoding) possibly to evade easy analysis and detection.

The ActiveX control facilitates connection to the malicious website to launch and execute the MS09-002 exploit.

For those who have not patched their machines, I suggest you install the MS09-002 patch immediately. It will just be a matter of time before different variants of this exploit start circulating in the wild and become incorporated into various Do-It-Yourself web attack toolkits.

The malicious word document is detected with the current DATS as Exploit-MSWord.k and the Internet Explorer 7 exploit is detected as Exploit-XMLhttp.d / Exploit-CVE2009-0075 McAfee Anti-Virus.

Tuesday, February 17, 2009

ActiveX kill-bit patch zaps Visual Basic apps

Deactivating kill bits wipes out some programs

One of the updates released by Microsoft this week causes some applications using Visual Basic controls to failThe short-term solution is to remove the update, but be sure to reinstall it once your VB apps have been corrected.

If your organization's line-of-business programs use Visual Basic for Applications (VBA) controls, one of this month's Windows patches may cause your programs to misfire. The patch that's the focus of this
Microsoft Security Advisory includes an ActiveX kill bit that also affects some custom VBA controls. The update is described in KB 960715.

Terry Seiberlich reports that two of his company's applications — the Office Tools Professional business-management program and Sage Software's ACT contact manager/CRM app — were affected by this ActiveX kill bit. I've been unable to determine whether the problem is present in ACT itself or only in applications that use these VBA controls and also plug into ACT.

Any applications relying on msflxgrd.ocx may also be affected. For example, if one of your line-of-business apps uses the Microsoft Access database program, you may wish to contact the program's vendor prior to installing this patch.

You may need to wait for your vendors to give you the thumbs-up before you install this kill bit. If the update has already been installed on your PC, and you need to remove it, click Start (Start, Run in XP), type appwiz.cpl, and press Enter. In Windows XP, make sure Show updates is checked at the top of the Add or Remove Programs window. In Vista, click View installed updates in the top-left pane. Look for Security Update for Windows (KB960715), as shown below:


Friday, February 13, 2009

Recession, Will it increase the security threats in 2009?

Security Threat Predictions/Trends for 2009

I have been reading alot of articles and posts regarding predictions and security threats in 2009. As the recession continues and unemployment rises, we will see the top cybercrime trend for 2009 as the continued exploitation of the financial crisis to scam people with fake financial transactions services, bogus investment firms, and fraudulent legal services.

Main Threat Predictions/Trends for 2009:

• Threats on Social-Networking Sites. Cybercriminals no longer deliver threats only via spam. They are taking advantage of Facebook, MySpace, and other popular social-networking sites. In 2008, we have seen scammers already taking aid from these social networking websites. In 2009, we will see alot of progression in this area.

• Personalized Threats Speak Your Language. We will see alot of malwares originating from different countries in different languages, which will give hard job for malware researchers to perform reverse-engineering and understanding these threats. Cybercriminals have come to realize that by diversifying into a global market they can access even larger pools of valuable identity and confidential information.

• Malware Targets Consumer Devices. We will see increased attacks involving USB sticks and flash-memory devices used in cameras, picture frames, and other consumer electronics. This trend will continue due to the almost unregulated use of flash storage across enterprise environments as well as their popularity among consumers. Apple Iphone will remain in news among the security researchers.

• Security Software Scams. The malware underworld is using mainstream practices in an effort to “sell” security software that is either misleading or outright fraudulent. We will see vendors will use FUD to their maximum level.

• Abusing Free Web-Hosting/Blogging Services. Websites such as Geocities, Blogspot, and Live.com allow anyone to create a public website for free, without the authentication necessary when purchasing a domain-name website. This gives spammers the opportunity to run their underground business with minimal expense. Spam from do-it-yourself social-website-hosting providers arrives at its destination with far greater frequency than links pointing to domain names assigned by legitimate registrars. With little to no threat of punishment for their hosted content, and the new restrictions on short-term domain tasting, the attractiveness of free bandwidth offered by these sites will undoubtedly draw greater focus from malicious parties.

• More Targeted Phishing and Corporate Blackmailing. Botnets, a.k.a. zombie computers, that spread into corporate networks and financial datacenters will increasingly be used to gather sensitive information that can be used for blackmail or sold on the underground market.

• Browser-Based Attacks. Cybercriminals will increasingly attack via web browsers as they are the least-protected and, therefore, easiest way to transfer malware.

• Security Breaches of Confidential Data. Information that is managed by partner and subsidiary companies of bigger companies will be exposed more frequently, forcing an overhaul of data-security practices.

• An Increase in Localized Phishing Campaigns. Online scammers will increasingly target specific communities, especially on college campuses, where professional-looking emails claiming to be associated with the school’s financial or scholarship department will be blasted to all the students at the school. This is a significant danger to people who are just becoming responsible for their own finances.

• More Scams Involving Home Businesses. “Legitimate” home business scams generally involve either a pay-up-front and do-it-yourself kit, or a pay-to-play shell game of training and certification. We’ll see more of it on television, and the same infrastructure that supports diploma spam and confidence fraud will adjust to the new unemployment reality and will offer people some new bait on the old check-cashing scam.

• Increase in Forging and Abuse of Free Email Services. The free email services have started to allow accounts to send mails with arbitrary “from” addresses. This has increased the usability of these services significantly to businesses, but has also increased the “abusability” by spammers.

• McColo: The Effects of a Takedown. Spam traffic took a tremendous dive in volume when ISPs pulled the plug on spam host McColo Corp., the source of up to 60 percent of worldwide spam. In 2009, we expect to see a continued shift in organizations, from passive support of law enforcement to an active role of working collaboratively with ISPs and global Internet entities such as ICANN.

• New Businesses to Replace Lost McColo Hosting. Hosting companies will be set up in countries that are eager to embrace a burgeoning Internet market and will offer services to replace the disrupted command and control centers formerly hosted by McColo. These may be used as pawns by entities that perceive strategic value in sculpting the battlefield of the future.

Wednesday, February 11, 2009

Downadup/Conficker Worm Details and Removal

Seeing this message in your web browser lately? You are not alone!

Millions of other people are also finding that they can't reach microsoft.com or can't load antivirus websites. The reason is they are infected by the Downadup worm.

Downadup (also called Downad, Kido, Conficker or Conflicker) is a Windows worm that spreads by exploiting weak administrator passwords, use of autorun on removable and network drives, and the MS08-067 exploit.

Once installed, the worm does the following things:

  • Copies itself to the system directory as a randomly-named DLL file
  • Adds itself as a randomly-named system service for persistence after reboot
  • Disables certain Windows services that might aid in cleanup or detection of the worm
  • Deletes existing system restore points
  • Disables access to multiple websites related to antivirus and security, most notably Microsoft and Windows Update.
  • Spreads through the local Microsoft network using password brute-forcing or MS08-067 exploit
  • Adds itself to any removable/network drives using an autorun.inf file
  • Adjusts the Windows TCP/IP settings to allow a greater number of simultaneous connections in order to facilitate the spread of the wrom
  • Waits three hours, then attempts to download additional code by generating 250 different domain names and connecting to each via HTTP. Each day a new set of 250 domain names will be generated.

Despite using fairly old and well-known spreading vectors, and a patch being available for MS08-067 for months now, the worm is having fairly good success at spreading to networks worldwide. Estimates are currently around 10M infected machines, although it is possible that machines are being counted multiple times by some entities. Whatever the real number of infected machines, it is certainly possible that it has infected millions of machines around the world based on the sheer number of IP addresses hitting sinkhole servers that have been set up for observation.

Key indicators of an infection are:

  • Network drives/USB drives with hidden autorun.inf files, especially ones that are larger than 512 bytes.
  • Network logins being locked out for too many failed attempts.
  • Workstations no longer able to access microsoft.com or other security/AV related websites.

The problem of Conficker/Downadup cleanup is exacerbated by the fact that the worm blocks the download of potential removal tools, including Microsoft's own Malicious Software Removal Tool (MSRT) which has been updated to remove Conficker/Downadup. It does this by hooking the system DNS and networking APIs and blocking DNS lookups where certain strings are present in the domain name.

The complete list of strings blocked in DNS requests is below:

cert.
sans.
bit9.
vet.
avg.
avp.
nai.
windowsupdate
wilderssecurity
threatexpert
castlecops
spamhaus
cpsecure
arcabit
emsisoft
sunbelt
securecomputing
rising
prevx
pctools
norman
k7computing
ikarus
hauri
hacksoft
gdata
fortinet
ewido
clamav
comodo
quickheal
avira
avast
esafe
ahnlab
centralcommand
drweb
grisoft
eset
nod32
f-prot
jotti
kaspersky
f-secure
computerassociates
networkassociates
etrust
panda
sophos
trendmicro
mcafee
norton
symantec
microsoft
defender
rootkit
malware
spyware
virus

Obviously not being able to reach any of these domains makes it difficult for an infected party to find information on or cleanup tools for the worm. However, the worm does not prevent use of a proxy server to reach the same websites, so in organizations where a proxy server is already in use for web traffic, removal may be easier.

Conficker/Downadup Removal:

In a network setting, one must take care to isolate infected machines from the other computers on the network while cleaning them, as the machine may be reinfected by other systems not yet cleaned. For more information please refer to Roger's post.

Tuesday, February 10, 2009

Online security dented by certificate hack

Is internet banking safe? Yes it is, if we use little bit of our intelligence

A group of academics has succeeded in breaking a key security feature used by banks to protect online banking websites.

The exploit allows hackers to replicate trusted certificates issued by organisations called "certificate authorities". These trusted certificates are used to verify website certificates, which in turn verify the identity of a website or user for security purposes, such as during an e-commerce or online banking transaction.

Hackers can use the replicated trusted certificates to create forged website certificates. So far only certificate authorities using a cryptographic function to sign and verify digital certificates called the "MD5 algorithm" are vulnerable.

It could be used for identity theft. You might think you're going to a secure website, but in fact you could unknowingly be redirected to a site serving up malicious software. This exploit is potentially a huge problem for any organisation dealing with certificate authorities and for certificate authorities themselves.

Microsoft has issued an advisory to business customers asking them to contact their certificate authority for guidance and says it is working with certificate authorities to encourage them to upgrade to a newer algorithm.

Attacks were unlikely because of the expertise required, and only certificates signed using MD5 after the exploit was published were believed to be at risk.

My only advice to all my readers and users out there,

Please check the websites by clicking on the "padlock" to view the certificate's details, which shows the signature algorithm used.

Thursday, February 5, 2009

Are we really secure? Who is responsible?

Half of security vulnerabilities going unpatched!

More than half of the security vulnerabilities disclosed during 2008 had no patches available from the vendor by the end of the year, according to a report released on Monday by IBM's X-Force research group.

Meanwhile, 46 per cent of vulnerabilities from 2006 and 44 per cent from 2007 still had no patch by the end of 2008, the 2008 X-Force Trend and Risk report said. X-Force documented a record number of 7,406 new vulnerabilities last year.

Overall, Microsoft is the vendor that tops the list in percentage of vulnerabilities disclosed, the report said. The Macintosh and base Linux kernel operating systems have dominated the top spots for vulnerabilities by operating system over the past three years, the report said. There were no breakdowns by vendor or operating system for unpatched vulnerabilities.

Most of the spam last year appeared to come from Russia (12 per cent), followed by the US (9.6 per cent), and Turkey (7.8 per cent), although the spam senders could be located in a different location, the report says.

China unseated the US as the country hosting the largest number of malicious websites for the first time last year.

Meanwhile, 46 per cent of all malware attacks last year were Trojans targeting people playing online games and doing online banking, and 90 per cent of phishing attacks targeted financial institutions, according to the report.

Two main trends attackers used last year were SQL injection attacks, in which a small malicious script is inserted into a database that feeds information to the website, and malicious URLs hosting exploits.

Tuesday, February 3, 2009

How secure is to use Social Networking Websites?

Social Networking, Privacy and Password

I have been warning for a long time of the issue of adding our personal information to any social network. I use them by myself (Facebook, LinkedIn, etc.) and I'm surprised at the amount of personal information that my contacts have there, even more surprised when more than the 90% of my contacts work in security related companies -yes, that means that my social life sucks, I know ;-)

Social networks are also a good communication tool, just a few days ago we could see how the Queenstown police arrested a man thanks to Facefook. But things are not black or white, and when the mankind is involved you can also see the dark side. In September 2008 we could see some news reports about terrorist using Facebook to kidnap Israeli soldiers.

But we don't need to go that far. There is another major issue: people are lazy, we don't want to have complex passwords that we can't remember, nor to have a different password for each application; so people just choose an easy to remember password or just create passwords consisting of some of their own personal information, using their birthday, wife/husband name, hometown, etc. Last week 4 people were arrested for blackmailing Spanish singer David Bisbal. Basically they had got into his mail account and used the information stored there. The head of the gang, psychologist, was able to figure out his password after studying all the personal information of the singer that can be obtained from the Internet.

We do not usually have that kind of information about ourselves available for our friends, but we have it on Facebook and similar networks. They are only visible to our friends (we should redefine the word "friend" in a social network enviroment, but I won't talk about it here). I have not tried (and won't) to figure out my friends passwords, but I could do it and I'm sure it would work in many cases. And what happens if one of our friend's accounts gets hacked, is that whoever it is will have access to all his friends info... scary at least.

So please, just follow some basic recommendations:

• Use common sense.
• Restrict viewing of your details to trusted persons.
• Don't publish your full birth date.
• Don't reveal your e-mail, phone number or postal address.
• Ignore unsolicited requests to be friends or group membership from unknown people.
• Use different passwords, and change them periodically.

Finally, you can take a look at this list, containing a list of the Top 500 worst passwords of all times, taken from the book Perfect Password (Mark Burnett, 2005). I miss some passwords in this list, as "guest", "admin" or "backup", but it is useful so that you can know which ones you shouldn't choose.

Wednesday, January 21, 2009

Facebook and Extortion?

Hackers ripping off Aussie Facebook users

Hackers are hijacking the profiles of Australian Facebook users and attempting to extort money from their friends using a bogus story about being mugged in London.

Ninemsn has spoken to four Facebook users whose accounts have been hacked — three in the past week — and evidence suggests more have been targeted.

In each instance, the attack followed the same pattern. First the person's user name, password, alternative email address and other details were changed. The scammers then assumed the user's identity and contacted scores of people, claiming to be stuck in London after being mugged at gunpoint.

It is not clear where the fraudsters are based, if the same people are behind all of the attacks or how the accounts were initially compromised but the London suburb of Kentish Town is mentioned in several exchanges.

At least one person fell for the sophisticated scam and sent cash through to the hackers via a Western Union money transfer.

It is interesting read, please refer here to read full article.

Friday, January 9, 2009

PCWorld - Five Most Dangerous Security Myths

The Five Most Dangerous Security Myths

Still think that today's computer viruses and other malware come from some maladjusted teen out to vandalize your PC to make a name for himself? Think again. The persistent myth is a holdover from days long gone, and it's important to dispel it if you want to know what you're up against - and how to protect yourself.

The splashy worms and malicious viruses that clogged entire networks and indiscriminately wiped hard drives are essentially gone. Today, it's all about cash - and lots of it. If there's a way to use evil software to make money, whether it means taking over a PC to send pharmacy-advertising spam, or stealing financial logins and credit card info, or even hacking game accounts, it's out there in some form.

There's even a thriving online black market that sells everything from software kits to roll-your-own malware to spam services using infected PCs to reams and reams of credit card data stolen by keylogger malware.

Refer here to read full article.

This article is good to read but many readers didn't agree with it.

Wednesday, January 7, 2009

If you have LinkedIn Profile, Be careful!

Fake celeb LinkedIn profiles lead to malware

A security researcher has discovered fake profiles for celebrities on LinkedIn that have links to malicious code, according to a blog posting on Trend Micro's site.

The celebrity profiles that are not to be trusted include ones created using the names: Beyonce Knowles, Victoria Beckham, Christina Ricci, Kirsten Dunst, Salma Hayek, and Kate Hudson. They were uncovered by Trend Micro Advanced Threats Researcher Ivan Macalintal.

In its blog posting late on Monday, Trend Micro said it was continuing its investigation. The links on the professional networking site attempt to lure viewers by purporting to be nude shots of the celebrities. McAfee's Avert Labs Blog has more details and screenshots.

Tuesday, January 6, 2009

De-ICE Pen Test LiveCD

VMware Documentation for De-ICE Pen Test LiveCD's Released

The De-ICE Pen Test LiveCD's are Slax based hacking scenarios that are easy to setup in a lab environment. Great for developing your pen test skills on your own time. This article describes the LiveCD's and also provides documentation on configuring a virtual network in VMware to easily use the LiveCD's.

Sunday, January 4, 2009

Malware Behavior Analysis Tool

Zero Wine

Zero wine is an open source (GPL v2) research project to dynamically analyze the behavior of malware. Zero wine just runs the malware using WINE in a safe virtual sandbox (in an isolated environment) collecting information about the APIs called by the program.

The output generated by wine (using the debug environment variable WINEDEBUG) are the API calls used by the malware (and the values used by it, of course). With this information, analyzing malware's behavior turns out to be very easy.

Zero wine is distributed as one QEMU virtual machine image with a Debian operating system installed. The image contains software to upload and analyze malware and to generate reports based on the information gathered (this software is stored in /home/malware/zerowine).

Running the distributed virtual machine with the correct command line options (use the supplied startup shell script to run the virtual machine) provides a web based (web server is written in python) graphical interface to upload malware to be analyzed (a CGI written, also, in python).

When a new malware is uploaded, it is copied to the directory /tmp/vir/MD5_OF_THE_FILE, then, the previous created WINE environment (WINEPREFIX if you prefer) is removed and a backup system is untared (the backup system is /home/malware/backup/backup.tar.gz). After this operation, the malware is executed using the shell script malware_launcher.sh (the file is stored in the folder /home/malware/bin).

For more details please refer here.

Happy New Year

2008 is gone! Let's Welcome the brand new 2009.

I would like to wish all my readers best for 2009. Thanks for visiting my blog, comments and suggestions throughout the year 2008.

Looking forward to post more interesting stuff in 2009.

Shoaib