Showing posts with label Internet security. Show all posts
Showing posts with label Internet security. Show all posts

Saturday, 13 December 2008

IE Zero-Day Follow-Up: Now Featuring Mass SQL Injections

We recently reported about a flaw in IE that could be exploited by hackers and now we have discovered an even further flaw. This needs to be stopped asap.

Read on.....

Malware criminals were quick to pounce on the recently discovered — and still unpatched — zero-day exploit for Internet Explorer and to mount mass SQL injection attacks, Trend Micro researchers have found. Researchers industry-wide have correctly warned that it was only a matter of time before this exploit, which is publicly available, was used for a wider scope of attack. The folks at the SANS Internet Storm Center (ISC) are also reporting this.

Advanced Threats Researcher Ivan Macalintal puts the number of infected sites so far at 6,000 and (quickly) increasing in number. He cites at least two Web sites infected with code that exploits the zero-day vulnerability, one in the .tw domain, and the other under .cn. The first is a Taiwanese search engine [Update: Now clean. -Ed.] which was found injected with the malicious JavaScript code through SQL injection.

The second is a Chinese sporting goods site with a traffic rank of close to 7 million, which was found containing HTML code directing users to a remote site which contains the same malicious script.


Fig. 1. A webpage of the compromised popular Chinese skating/sporting goods site


Fig. 2. An image of an injected redirection to a third-party site hosting the exploit

The final payload is a worm detected by Trend Micro as WORM_AUTORUN.BSE. Other exploits that also lead to the worm are as follows:

  • HTML_IFRAME.ZM
  • JS_DLOADER.QGV
  • HTML_AGENT.CPZZ

Obfuscated JavaScript in the HTML webpages are also detected as JS_DLOAD.MD, the same malicious script found to exploit the zero-day vulnerability in IE7.

Microsoft posted revisions to its Security Advisory with the latest analysis about the underlying flaw in this attack, which the advisory also states, renders Microsoft Internet Explorer 5.01 Service Pack 4, Microsoft Internet Explorer 6 Service Pack 1, Microsoft Internet Explorer 6, and Windows Internet Explorer 8 Beta 2 on all supported versions of Microsoft Windows as potentially vulnerable.

The Trend Micro Smart Protection Network already detects the malicious scripts as well as WORM_AUTORUN.BSE at the desktop level, and provides solutions for the removal of the worm.

Cops reel in greedy hackers

The authorities are now catching these guys and its about time. If they put their talents to good use they would not need to keep looking over their shoulders and they would make decent money doing it. Stupid hackers :)

Read on....

A syndicate of Internet thieves has stolen more than R400-million from government departments, including the Presidency.

Two computer identity-theft hackers, believed to be the masterminds of the cyber gang, were nabbed by the police this week.

These follow the earlier arrests of 13 people involved in stealing millions of rands from government departments and employees across the country.

The syndicate allegedly hacked into computer systems linked to the Presidency using specialised spy software (spyware) programs.

The Internet-based syndicate, which had operatives in banks and government departments, is alleged to be behind the theft of R400-million from bank accounts of the departments of Home Affairs and Public Works, the licensing department, several parastatals and financial institutions, as well as from staff working in the various organisations over the past two years.

The syndicate, the members of which have been arrested over the past month, was bust during an operation conducted by the South African Police Service's Covert Intelligence Collective Directorate and the Commercial Crime Unit.

The operation, dubbed Operation Swift, had detectives and undercover agents raiding houses in Tshwane and North West. The latest arrests were made in Centurion and Ramokokastad, North West.

The arrests bring an end to what has been described as the country's biggest cyber attack on government organisations.

The theft, say police, allegedly took place through fraudulent electronic funds transfers (EFTs) from the various institutes and its staff members' accounts since 2006, and saw the syndicate, which comprises small business owners and IT specialists employed in both the government and the private sector, siphoning off money to fictitious bank accounts.

Police spokesperson Senior Superintendent Tummi Golding said the latest arrests followed information received from undercover operatives.

She said the information showed that since 2006 the suspects had allegedly stolen more than R5-million from the Office of the Presidency's budget.

"One of the suspects was arrested in Centurion in a townhouse he rents and the second was arrested at his home in the North West town of Ramokokastad," she said.

Golding said the men, aged 40 and 36, would appear in the Pretoria Magistrate's Court soon on charges of fraud.

Golding said that during the arrests, police seized a Mercedes-Benz SLK and a Harley-Davidson motorbike, which had allegedly been bought with fraudulent documents.

She said that in other raids conducted as part of the operation, police raided several houses in Soshanguve, where they arrested five people and seized two laptop computers, two printing machines, a laminating machine and documents used to commit the alleged fraud.

Explaining how the syndicate operated, Golding said the group operated by infiltrating targeted departments and institutions and installing spyware on their IT systems.

"The spyware was used to collect the user names and passwords of users of the government salary systems.

"Once this information is compromised, it is used to effect fraudulent EFTs into bank accounts opened by runners using fraudulent documents.

"In some cases, government officials within IT departments used remote access software available on the commercial market to gain unauthorised access and modify the banking details of registered suppliers," she explained.

Golding said the syndicate also targeted bank officials for recruitment and facilitation of fraudulent transactions.

"These bank officials load stop orders from bank accounts of government departments using compromised user names and passwords of other bank employees.

"The funds are transferred into fraudulently opened bank accounts using the details of registered business entities.

"As well as this, the syndicate, in collaboration with government officials, used compromised log-on details of other users to create ghost workers on the Persal system and pay the salaries of these nonexistent employees into fraudulent bank accounts," she said.

An Anti-virus can Also be Vulnerable to Hackers

iViZ, an information security company that offers "Green Cloud Security", has discovered new classes of vulnerabilities in many popular commercial and open source anti-virus software. The company states that these vulnerabilities can potentially allow attackers to gain access to systems using such antivirus software.

According to iViZ, an attacker can craft an e-mail with malicious code that can crash the vulnerable anti-virus and bypass the computer's local security solution.

The iViZ "Green Cloud Security" Vulnerability Research team , using a variety of "file fuzzing" techniques discovered abnormal behavior in several security tools -- especially when handling complex or unusual executable header data. Multiple bugs were found in antivirus software while processing malformed packed executables as well.
Some of these bugs proved to be security vulnerabilities, which could make the antivirus itself a back door for hackers.

The affected software included popular commercial and open source anti-virus software such as AVG, F-Secure (F-Prot), Sophos, ClamAV, BitDefender and Avast. It stated that the list could include other security-based software as well.

iViZ experts advised businesses to perform regular and periodic penetration testing as it can help them combat constantly evolving vulnerabilities and threats.

12 Types Of Anti-Spyware Programs

You can try out each program and get the best choice to protect your computer from the possible threats.

In the market there are many anti spyware and ad ware programs like Ad-Aware SE Pro, Counterspy, Trend Micro, Spy Sweeper, AntiSpy, Spy ware Doctor, PestPatrol, etc. available in the market. Each program has its own identity and method to access the internet. The anti-spyware company’s offers free download or it offers for free trial for certain period of time. There are many free antispyware are also available online for free trial with self-update.

You can try out each program and get the best choice to protect your computer from the possible threats. There are many anti-spy ware programs available for free. There are many free games and video or peer to peer sites also contents various spy wares. It is not advisable not to access the system. Many freeware have give virus or malicious things as gift with the installation.

1. Lavasoft’s Ad-aware SE pro 6. It can give you many good features where we can’t find it in other products.

2. Spy Sweeper launched upgraded version 5.2 with many updates for the customers. The Spy Sweeper 5.2 runs quickly, custom or full sweeps in record time.

3. Spyware Doctor promise real-time blocking and protection features.

4. The Norton Internet Security 2007 offers triple security against antivirus, firewall, and antispyware and. It also gives anti Spam, privacy, and parental control.

5. AVG Anti-Spyware offers the free services as well as the paid one. It gives 30 day trial version.

6. CounterSpy runs in the background and protect from spyware and ad ware.

7. McAfee is an effective anti-virus product. It is user-friendly and provides many different forms of support.

8. Trend Micro Anti-Spyware has unique features. Trend Micro Anti-Spyware covers all types of spyware or ad ware components.

9. The Anti-spy provides customize solution. It can automatically start scanning as defined time.

10. CA Anti-Spyware 2007's active shields recognized and blocked spyware.

11. CyberDefender AntiSpywareis identify and defense invasive spyware on your computer.

12. The Spy Sweeper is user-friendly. Spy Sweeper one of the favorite amongst the anti-spyware tools.

Apart from this there are many anti-spyware available in the market. All have different features and compatibilities.

Firefox: Most Risky App to Businesses in New Study

The good old FF browser gets little love when it comes to security

Firefox has its plate full when it comes to security. It has grown a substantial enough market share to place it in a strong second after Microsoft. This gives it a high profile and leaves it a desirable target to be exploited by hackers and malware writers. Worse yet, it has less money to fund security efforts that Microsoft, and according to some experts, less focus as well.

While small market share browsers like Opera and Chrome have built a reputation on their security (with Safari, being a noticeable exception, have a reputation for insecurity), Firefox continues to plod along in a day to day fight, trying to remain a secure platform while dealing with the challenges of browser celebrity.

Perhaps for this reason, Bit9, an application whitelisting firm that helps employers block employee access to certain apps, placed Firefox on the top its list of most vulnerable apps. The remaining spots on the list were filled out with more familiar names, with two through twelve respectively being: Adobe Flash & Acrobat; EMC VMware Player, Workstation, and other products; Sun Java Runtime Environment; Apple QuickTime, Safari, and iTunes; Symantec Norton products; Trend Micro OfficeScan; Citrix products; Aurigma and Lycos image uploaders; Skype; Yahoo Assistant; and Microsoft Windows Live Messenger.

The Bit9 study looked at several factors in ranking vulnerability. One factor was how popular the applications were. Another factor was how many known vulnerabilities existed, and how severe they were. Lastly, it looked at how hard patching was for the particular application.

In order to make the list, programs hand to run in Windows and not be centrally updatable via services such as Microsoft SMS and WSUS. Many say that the survey was unfair to Apple products because it kept easier patched Microsoft applications off the list.

In some ways, though Bit9's list is a useful benchmark. It aptly points out that many networks have Firefox installations running on machines, without the system administrator being fully aware of the instance of these installs. Thus, despite the fact that most of the vulnerabilities looked at have been patched, the installs may not receive these patches immediately, until the employee upgrades to the next edition of the browser.

The study's conclusions only marginally apply to the consumer market. However, when it comes to the business market, the study argues that picking or allowing employees to run Firefox, even with its security plug-ins, is a ticket to the IT danger zone as malware increasingly targets application layer targets such as Firefox.

Friday, 12 December 2008

We need to monitor information security grifters, too

A new report from the Anti-Phishing Working Group is yet another reminder of the information security threats we all face. This latest publication states that the number of compromised URLs used to distribute malicious code nearly tripled in the 12-month period from July 2007 through July 2008.

This data, along with similar research from McAfee, RSA Security, Symantec, and Trend Micro, demonstrate that the bad guys are taking advantage of the global recession with an increase in attack volume and sophistication. Certainly, security professionals recognize this unsettling trend, and according to ESG Research data, security remains a top IT priority for 2009. Based upon recent activities, it appears the federal government also sees the need for countermeasures.

While insiders seem to see the storm approaching, however, I'm worried about the Internet everyman--"Joe the Online User," if you will. Information security tends to be an esoteric topic sure to bore the pants off friends and neighbors at upcoming holiday parties, but there's more in play than ignorance alone.

I am starting to see a whole bunch of no-name security grifters pitching second-tier products and services with Chicken Little, "the sky is falling" scare tactics. You tend to find these guys are on drive-time radio and entertainment Web sites. I'm not alone in this observation. This week the U.S. District Court in Maryland ordered two fly-by-night companies to stop promoting "scareware" through online advertisements. These pop-up ads would warn Web surfers that their systems had been compromised by viruses, spyware, and even "illegal pornographic content." They were even so brazen as to suggest that users could be investigated or outed as some type of degenerate porn addict. Of course, they were happy to sell you software and services to alleviate the problem.

Unfortunately, there will always be a population of low-down dirtbags willing to take advantage of people's fears and hardships. After September 11 they pitched gas masks; they sold bottled water for $10 a piece following Hurricane Katrina. Given the cybersecurity activity out there, we are bound to see more and more of these security scams. The difference here is that security con artists are preying on fears that users really don't understand. Consumers may get scammed or become cynical--neither of which is good.

We need a focused effort to pull together as a security community, educate consumers, and push for strict punishment of these flimflammers. If not, things can only get worse.