Showing posts with label vulnerabilities. Show all posts
Showing posts with label vulnerabilities. Show all posts

Friday, October 9, 2009

Automation in creating exploits

In most cases, one of the most common parts used in any attacks are exploits, and the world of malicious code as well. All attacks using malware and are carried out using the infrastructure of the Internet, as an essential component involving the exploitation of vulnerabilities.

Regardless of public vulnerabilities appear every day (and not including the type 0-Day) the most relevant, being the most exploited are those that exploit weaknesses in applications designed to view the files .pdf, .swf, and course, Windows.

In this sense, the fact that they are "fashion" is an attribute that I believe, is based primarily on the early awareness of security risks that still seem to have. That even today are exploiting vulnerabilities are resolved over three years is the clearest evidence, and that also constitute one of the key strategies used by botmasters to recruit zombies a large scale.

Even today, nobody is surprised that web applications designed to control and manage botnets through http protocol, modules are sold with pre-configured exploits, as in the case of YES Exploit System or Liberty Exploit System among many others.

Moreover, the business of design is constantly looking crimeware "resources" automated to optimize their "services" and begin to appear on the black market, resources designed not only to automate the development of threats but also to make those threats as more complex possible.

Encryption malware, anti-debugger techniques, anti-analysis techniques such as detection of controlled environments (VirtualBox, VMWare, Virtual PC, Sandbox, etc.), and automation in the creation of exploits are faithful bulk tests on the market clandestine crimeware.

This last point in particular exploits the automated production, has created significant problems in recent years. But go too far, remember the serious security problem which represented conficker late last year to spread through a vulnerability in the family of Microsoft operating systems. However, its origin was marked before his appearance.

The operating process is generated based on a critical vulnerability on the RPC service published on 23 October 2008 (MS08-067), which forced Microsoft released the patch breaking its usual cycle (the second Tuesday of each month). Immediately after it began to be exploited by the trojan Gimmiv and vulnerability exploited by an exploit created by "ph4nt0m".

From there, the vulnerability was exploited by several malicious codes. In November, is an application that helps automate the process of creating exploits for this security weakness, and also incorporates a port scanner which aims to find vulnerable computers. The application has its origin in China.

A curious fact is that the original version of this program contains no "surprises". However, later manipulated officiate malicious intent as a "booby trap" incorporating a backdoor that installs silently in the team who wants to use the application. That is, biter bit ...

Also during November 2008 is the first version of conficker, a worm that exploits this vulnerability effectively causing great unrest in many companies that suffered the consequences on their networks, and undoubtedly, one of the media of malicious code history.

During the year 2009, another known vulnerability (MS09-002), but this time in Internet Explorer 7, which allows code execution when accessing a website and begin to be incorporated into web applications for control and administration of botnets, the teams exploded through .pdf and .doc files, Drive-by-Download attacks and Multi-Stage attacks.

Among them, Phoenix Exploit's Kit, Fragus, Liberty Exploit System, Eleonore Exploits Pack, Unique Sploits Pack, among others.

But it's a tool to exploit the vulnerability through a process of creating specific exploits for it, it starts to circulate through forums Israeli origin.

The program generates a script obfuscated in JS that hides the exploit.

Thus, the exploit is spreading through websites exploiting Windows systems through vulnerable IE7 browser.

These exploits are actively used by cybercriminals to initiate dissemination and infection processes, and applications that automatically generate it's In-the-Wild, with agravente that its development isn't restricted to deep programming skills .

As we can see, management and deployment of security updates, both operating systems and applications, has no foundation trivial, but is a very important aspect in maintaining the health of equipment.

Related information
Conficker IV. Dominios relacionados... y controversiales
Conficker III. Campaña de propagación (...) de limpieza
Conficker II. Infección distribuida del gusano mediático
Conficker. Cuando lo mediático se hace eco (...) problema de fondo
Anatomía del exploit MS08-078 by FireEye

Jorge Mieres

Tuesday, February 10, 2009

Exploiting vulnerabilities through SWF

One of the formats used to massively exploit the weaknesses of the teams are the Small Web Format files .swf. Usually, they're often subjected to the injection of the exploit code to undermine a particular bug.

The same wave file attacks using malicious JavaScript that had been mentioned in the post of vulnerabilities through files .js, was combined with other alternatives such as this.

In this case, it exploits a vulnerability in Adobe Flash Player described in CVE-2007-0071 by which through a file .swf manipulated maliciously causes a Buffer Overflow allows code execution by a remote attacker.

This means that if the user accesses, for example, the URL http://www.710sese .cn/a1 / (59.34.197.115) the file is executed f16.swf (MD5: 95EC9202FBE74D508205442C49825C08) that according to the report VirusTotal , is detected by antivirus 18 of 39 for which the sample scanning. The insert in the exploit .swf exploit the vulnerability if you have installed the application and be vulnerable.

Some of the URLs used to spread the exploit are:

http://www.710sese .cn/a1/f16 .swf
http://www.710sese .cn/a1/f28 .swf

http://www.710sese .cn/a1/f45 .swf

http://www.710sese .cn/a1/f47 .swf

http://www.710sese .cn/a1/f64 .swf

http://www.710sese .cn/a1/f115 .swf

http://www.710sese .cn/a1/i28 .swf

http://www.710sese .cn/a1/i16 .swf

http://www.710sese .cn/a1/i45 .swf

http://www.baomaaa .cn/a279/f16 .swf

http://www.baomaaa .cn/a279/f28 .swf

http://www.baomaaa .cn/a279/f45 .swf

http://www.baomaaa .cn/a279/f47 .swf

http://www.baomaaa .cn/a279/f64 .swf

http://www.baomaaa .cn/a279/f115 .swf

http://www.baomaaa .cn/a279/i28 .swf

http://www.baomaaa .cn/a279/i16 .swf

http://www.baomaaa .cn/a279/i45 .swf

http://000.2011wyt .com/versionff .swf

http://000.2011wyt .com/versionie .swf

http://sss.2010wyt .net/versionie .swf


http://sss.2010wyt .net/versionff .swf
http://www.misss360 .cn/versionff .swf

http://www.misss360 .cn/versionie .swf

http://daoye.sh .cn/a08_1272/m16 .swf

http://daoye.sh .cn/a08_1272/m28 .swf

http://daoye.sh .cn/a08_1272/m45 .swf

http://ccsskkk .cn/new7/fl/f16 .swf

http://ccsskkk .cn/new7/fl/f28 .swf

http://ccsskkk .cn/new7/fl/f45 .swf

http://ccsskkk .cn/new7/fl/f47 .swf

http://ccsskkk .cn/new7/fl/f64 .swf

http://1.ganbobo .com/template/kankan/js/4.0/curtain .swf

http://1.ganbobo .com/template/kankan/js/4.0/playerctrl .swf


Once it explodes in your computer, download the binary a1.css from http://d.aidws .com new, a malicious code which we have already mentioned in other post.

Related information:
Exploitation of vulnerabilities through JS

# Jorge Mieres

Wednesday, February 4, 2009

Most common safety violations

A while ago I came across an interesting recent report developed by the company by Verizon Business, which describes the most common safety problems that occurred during the past four years, causing considerable loss of information in enterprises.

The report shows that:
  • In 87% of cases, problems could have avoided problems through without basic safety measures.
  • In 66% of cases, companies did not know they were publishing sensitive information through their systems and websites
  • At 39% of security breaches, business partners actively participating in the company (Partners), which was multiplied since 2004.
As you will see, so far only mentioned three of the most important document which sets but beyond that, they are often considered trivial bypass forgetting, however, are the keys to an attacker. On the other hand,
  • 73% of the weaknesses were due to external sources,
  • 18% was caused by internal staff, which is known as an insider.
Given this information, we can demystify the belief that states that the greatest damage is caused by external attacks (73%) is perhaps carried out by a guy who is across the world from your PC and drinking beer. Contrary to what may seem surprising that this percentage, damage from these attacks have a minimal impact.

This doesn't apply where the attack is led from within the organization because, although the percentage is lower (18%), this type of attack is what causes more damage in the company because, in most of the cases committed by personnel who have known and privileged and sensitive information of the company.

However, after reading these points, the question that generates the turning point on this issue is could have been avoided? As the answer a resounding YES.

The same report states that 87% of the problems could have been prevented through basic security, namely through the implementation of reasonable security controls designed precisely to prevent this important 87% of problems.

Another important document that sets out is that 22% of the attacks occurred through the exploitation of vulnerabilities, of which more than 80% were known, ie it was not 0-Day exploit, besides having its for a security patch that fixes the weakness.

This point in particular, brings to mind the great noise that has been causing, for example, the worm Conficker high infection rate in just a few days, taking advantage of a vulnerability in Windows platforms settled in security bulletin MS08-067, or the recent vulnerability in Internet Explorer settled in the bulletin MS08-078 trojan and many are actively exploiting.

It sa very important to know that some of the basic safety measures that must be taken into account through implementing and/or update the Security Policy of the information in the enterprise, and monitor the implementation of the measures outlined in this focuses almost all solution to security problems mentioned above.

We know what data, where they are stored and what's the value that each one of them according to the plan made hazards, is also an issue to consider because it's not possible to ensure that it's not known or not knows where you are.

We must try to take the sense of a strategy to secure the environment, or at least find a proper balance of security in it.

An interesting document which calls for an examination of the security problems that commonly presents without leaving an organization's most valuable asset protection to which account information, often without knowing who is available to the public".

Related Information:
Massive exploitation of vulnerabilities through servers ghosts
Malware attack via Internet
Commonly exploited security weaknesses
Whitepaper Ataques informáticos - Debilidades de seguridad comúnmente explotadas (in Spanish)


# Jorge Mieres

Monday, January 19, 2009

Vulnerabilities & proofs-of-concept

During this week, securityfocus, have reported a number of vulnerabilities in several applications where, as usual, one can not miss for Microsoft environments. Given that these "unsafe gaps" in planning the program allows to conduct attacks of various kinds, it's interesting to know the potential that can exploit a vulnerability through proofs-of-concept.

Office Viewer AcitveX Controls (OCX)
Office Viewer presents a series of vulnerabilities in ActiveX controls that allow you to edit and view Microsoft Office files from your web browser. This implies the possibility of an attacker to execute arbitrary code with the privileges of the current user.

There are a number of PoC on these vulnerabilities:
http://downloads.securityfocus.com/vulnerabilities/exploits/33245.html
http://downloads.securityfocus.com/vulnerabilities/exploits/33238_powerpoint.html
http://downloads.securityfocus.com/vulnerabilities/exploits/33238_office.html
http://downloads.securityfocus.com/vulnerabilities/exploits/33238_word.html
http://downloads.securityfocus.com/vulnerabilities/exploits/33222.html
http://downloads.securityfocus.com/vulnerabilities/exploits/33243-office.html
http://downloads.securityfocus.com/vulnerabilities/exploits/33243-powerpoint.html
http://downloads.securityfocus.com/vulnerabilities/exploits/33243-word.html
http://downloads.securityfocus.com/vulnerabilities/exploits/33243-excel.html


Microsoft Knowledge Base
How to prevent the execution of an ActiveX control in IE

NullSoft Winamp v5.3.2 & sup
Since this version of Winamp, there defects in the processing of mp3 files and AIIF (Audio Interchange File Format) by which, through mp3 file or AIFF intentionally manipulated could cause a buffer overflow to allow an attacker to execute arbitrary code with the privileges of the current user. There is a PoC for this weakness:

http://downloads.securityfocus.com/vulnerabilities/exploits/33226.pl

Microsoft Windows Compiled HTML Help Handling Buffer Overflow
The Compiled HTML Help (CHM) is a document format, commonly used in help files for Microsoft Windows. Through an intentional manipulation of this style can exploit a vulnerability in Windows XP SP3 causing a buffer overflow.

http://downloads.securityfocus.com/vulnerabilities/exploits/33204.pl

# Jorge Mieres

Friday, January 9, 2009

Commonly exploited security weaknesses

Many attacks that an environment can suffer for the sole reason of being part of the World Web Wide, so it is necessary to centralize all efforts to improve strategic and proactive manner all aspects representing a potential point attack without neglecting those most trivial.

Therefore, we have written a new paper that explains the importance of attending to every aspect of security with the same level of acuity, for this seems more common.

In the Publications section of EvilFingers.com, will find this new source of information in Spanish, or if you wish, you can download it from here.

Thinking about those who do not entirely dominate the Spanish language, will soon be available in English.

# Jorge Mieres