Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Saturday, 13 December 2008

IE Zero-Day Follow-Up: Now Featuring Mass SQL Injections

We recently reported about a flaw in IE that could be exploited by hackers and now we have discovered an even further flaw. This needs to be stopped asap.

Read on.....

Malware criminals were quick to pounce on the recently discovered — and still unpatched — zero-day exploit for Internet Explorer and to mount mass SQL injection attacks, Trend Micro researchers have found. Researchers industry-wide have correctly warned that it was only a matter of time before this exploit, which is publicly available, was used for a wider scope of attack. The folks at the SANS Internet Storm Center (ISC) are also reporting this.

Advanced Threats Researcher Ivan Macalintal puts the number of infected sites so far at 6,000 and (quickly) increasing in number. He cites at least two Web sites infected with code that exploits the zero-day vulnerability, one in the .tw domain, and the other under .cn. The first is a Taiwanese search engine [Update: Now clean. -Ed.] which was found injected with the malicious JavaScript code through SQL injection.

The second is a Chinese sporting goods site with a traffic rank of close to 7 million, which was found containing HTML code directing users to a remote site which contains the same malicious script.


Fig. 1. A webpage of the compromised popular Chinese skating/sporting goods site


Fig. 2. An image of an injected redirection to a third-party site hosting the exploit

The final payload is a worm detected by Trend Micro as WORM_AUTORUN.BSE. Other exploits that also lead to the worm are as follows:

  • HTML_IFRAME.ZM
  • JS_DLOADER.QGV
  • HTML_AGENT.CPZZ

Obfuscated JavaScript in the HTML webpages are also detected as JS_DLOAD.MD, the same malicious script found to exploit the zero-day vulnerability in IE7.

Microsoft posted revisions to its Security Advisory with the latest analysis about the underlying flaw in this attack, which the advisory also states, renders Microsoft Internet Explorer 5.01 Service Pack 4, Microsoft Internet Explorer 6 Service Pack 1, Microsoft Internet Explorer 6, and Windows Internet Explorer 8 Beta 2 on all supported versions of Microsoft Windows as potentially vulnerable.

The Trend Micro Smart Protection Network already detects the malicious scripts as well as WORM_AUTORUN.BSE at the desktop level, and provides solutions for the removal of the worm.

Cops reel in greedy hackers

The authorities are now catching these guys and its about time. If they put their talents to good use they would not need to keep looking over their shoulders and they would make decent money doing it. Stupid hackers :)

Read on....

A syndicate of Internet thieves has stolen more than R400-million from government departments, including the Presidency.

Two computer identity-theft hackers, believed to be the masterminds of the cyber gang, were nabbed by the police this week.

These follow the earlier arrests of 13 people involved in stealing millions of rands from government departments and employees across the country.

The syndicate allegedly hacked into computer systems linked to the Presidency using specialised spy software (spyware) programs.

The Internet-based syndicate, which had operatives in banks and government departments, is alleged to be behind the theft of R400-million from bank accounts of the departments of Home Affairs and Public Works, the licensing department, several parastatals and financial institutions, as well as from staff working in the various organisations over the past two years.

The syndicate, the members of which have been arrested over the past month, was bust during an operation conducted by the South African Police Service's Covert Intelligence Collective Directorate and the Commercial Crime Unit.

The operation, dubbed Operation Swift, had detectives and undercover agents raiding houses in Tshwane and North West. The latest arrests were made in Centurion and Ramokokastad, North West.

The arrests bring an end to what has been described as the country's biggest cyber attack on government organisations.

The theft, say police, allegedly took place through fraudulent electronic funds transfers (EFTs) from the various institutes and its staff members' accounts since 2006, and saw the syndicate, which comprises small business owners and IT specialists employed in both the government and the private sector, siphoning off money to fictitious bank accounts.

Police spokesperson Senior Superintendent Tummi Golding said the latest arrests followed information received from undercover operatives.

She said the information showed that since 2006 the suspects had allegedly stolen more than R5-million from the Office of the Presidency's budget.

"One of the suspects was arrested in Centurion in a townhouse he rents and the second was arrested at his home in the North West town of Ramokokastad," she said.

Golding said the men, aged 40 and 36, would appear in the Pretoria Magistrate's Court soon on charges of fraud.

Golding said that during the arrests, police seized a Mercedes-Benz SLK and a Harley-Davidson motorbike, which had allegedly been bought with fraudulent documents.

She said that in other raids conducted as part of the operation, police raided several houses in Soshanguve, where they arrested five people and seized two laptop computers, two printing machines, a laminating machine and documents used to commit the alleged fraud.

Explaining how the syndicate operated, Golding said the group operated by infiltrating targeted departments and institutions and installing spyware on their IT systems.

"The spyware was used to collect the user names and passwords of users of the government salary systems.

"Once this information is compromised, it is used to effect fraudulent EFTs into bank accounts opened by runners using fraudulent documents.

"In some cases, government officials within IT departments used remote access software available on the commercial market to gain unauthorised access and modify the banking details of registered suppliers," she explained.

Golding said the syndicate also targeted bank officials for recruitment and facilitation of fraudulent transactions.

"These bank officials load stop orders from bank accounts of government departments using compromised user names and passwords of other bank employees.

"The funds are transferred into fraudulently opened bank accounts using the details of registered business entities.

"As well as this, the syndicate, in collaboration with government officials, used compromised log-on details of other users to create ghost workers on the Persal system and pay the salaries of these nonexistent employees into fraudulent bank accounts," she said.

Thursday, 11 December 2008

In Midst of Economic Meltdown, Malware Business is Booming


1.9 million job losses, a dollar worth less than the Canadian and Australian dollar, the collapse of the auto industry, the complete meltdown of credit. What a year it’s been for we working stiffs!

If you, as many ‘mericans already have, find yourself on the job hunt in the near future, forget about real estate, investment, Avon sales or tool and die work. Apparently, the boom industry in 2009 will be in the crimeware sector. Hopefully, with corresponding spikes in the antivirus industry (please don’t leave me to the spammers!).

According to industry insiders, 2008 saw a 258% spike in the URLs spreading contagions via phishing tactics. Classic scams like emulating login portals to harvest valuable personal data, passwords and usernames are becoming more common as cyber criminals perfect their craft. Malicious tapeworms, retroviruses, MoBo-VD, circuitry eating zombie nets and Trojan donkey-kits are proliferating rapidly.

If you do a lot online banking, social networking, or even MMORPGing think twice before throwing your social security number, birthday, maiden name and blood type around the internet. Phishing tactics are no longer as transparent as the koobface worm we’re still seeing on Facebook.

These dweeb and nerd criminals manage to make some convincing mimic logon pages and tricky programs. Red flags to look for include any obviously ex-Soviet URLs (.ru, .az, .kz, .by .cz, .tm et al), key misspellings (think Homtail, hotmale, or hottamale instead of hotmail), and anything that has a .exe within a hundred feet of it.

If, on the other hand, you’re looking to get involved in the profitable crimeware industry, there are great opportunities out there. Why not work as the overlord of a zombie botnet? Trading in stolen credit card numbers would be a refreshing career change, no? Just be prepared to feel my wrath, and the wrath of anyone else who has ever lost personal information!

If you’re not feeling ambitious enough for a fast track career in malware development, you’re probably going to want arm yourself with up-to-date antivirus and antispyware software. Check out our software reviews to keep your identity secure.

To curb cyber crimes, expert bats for digital signature

It is believed that due to the rapid growth of the net the only way to avoid hackers is through a digital signature. We found a fresh article on this and bring it to you here.

Read on....

In these times, where information technology is witnessing a rapid growth, the common man could easily fall prey to hackers and cyber crimes. The only way to overcome such attacks is to go for digital signature, feels Rohas Nagpal, an IT expert, while speaking on Cyber crime investigations and Forensics at the ClubHack 2008, the international convention og hackers in Pune.

Citing numerous ways by which hoax emails could be sent from one’s email account or spoof SMS messages from ones mobile number, without the owners notice, Nagpal said, “Email services and SMS services were not built to authenticate users.”

While hackers could use techniques to play havoc, few Telecom providers or ISP providers would be able to trace the culprit, he said.

“A few years ago, we told police officers across the world that we would be sending them spoof messages on their phones and asked them to trace it back through their telecom operators. No telecom operator was able to trace who had sent the message,” Nagpal said, adding that the only way to shield such attacks is to go for a digital signature, he said.

Nagpal spoke about several tools that hackers use to sniff passwords and credit card details. During the course of the workshop it emerged that banking security is not as it should be, with many banks having fallen prey to hackers. One of the prominent one is Bank of India, where the bank server was severely affected for 14 days.

Nagpal said that banks were liable to pay compensation if the customer money was siphoned off because of fraud. “Customers frequently using online transactions can secure themselves by not using wireless networks, using a powerful anit virus, zone alarms and fire walls,” he added.