Undoubtedly, we are increasingly dependent on technology and computer networks, not only at home but also at much higher levels as are business and government where the need to obtain and preserve information become relevant actions.
Under this scenario, create new challenges and new strategies to address these challenges at the same time, make the rules of a game where technological resources, information and intelligence processes are the key pieces to ensure business continuity (in trade) and the operation of government projects/military at any level.
First, because business environments are pouring money into new and better technologies to ensure the survival of their business and keep your information reaches the hands of competitors, jealously guarded by security schemes that seek to curb the actions of hired computer is often hired to perform espionage.
On the other hand, states also invest in technologies through its intelligence services (government and military) giving rise to new ways of getting information in a timely manner under the use of technical resources and different sources of information and intense competition channeling constantly trying to advance on their enemies to steal information that would betray the plans (geopolitical, military and economic) of other nations.
This inevitably means that, from a particular point of view, who we are devoted to information security we should funnel some of the efforts to add state of the art methodologies in certain activities that formerly were awarded only to the intelligence.
In this regard, government initiatives to protect their technological perimeters receive special attention from various States who are involved in a war that is happening in a scene that many may consider again, but nevertheless it isn't: the virtual and whose strategies the "battle" was conducted behind closed doors by using something as common as today's Internet.
These matches aren't based on mass murder as in a conventional war, but are based on computer and technological aspects. Consequently, those who develop better technologies and better implement it, enjoy the ability to obtain higher and better level of information. This form of struggle and large-scale unconventional called Cyber-Warfare.
What are we talking about? It's the use of computerized systems for carrying out a war over the Internet. From this perspective, it becomes necessary to resort to Computer Intelligence (CYBINT - Cyber Intelligence).
From a broad perspective, the Cyber-Warfare is no different to what specialists make Information Security in trying to devise defensive strategies, and offensive, to the safeguarding and protection of information, whether at government or private .
Can we say then that those who dedicate ourselves to this we are soldiers in a war that develops virtual world? I would say it indirectly. We are part of a virtual war that feeds on other smaller and private.
From the very existence of intelligence, information became the spoils of war and at the same time, the food with which daily feed regardless of the methods and mechanisms used for their production. So it's obviously the reason for designing mechanisms to obtain in a timely manner.
Gestate strategies and tactics to virtual combat and conflict scenarios carefully planned by intelligence analysts and other characters from the secret that is entertaining environment from a desktop designing action plans to enable implant rumors, shares of diversion and propaganda campaigns to cover up questions "good" (in the broad sense of the word) without attracting the attention of others, even through malware.
It's then that one of the most important parts of the Cyber-Warfare is Information Warfare, but through information technology and where the soldiers are people with extensive computer skills that are risking their lives the battlefield, their weapons are computers and their ammunition are the bits.
The intelligence services know this very well and were always involved in computations maneuvers designed to "learn more from others" (individuals, governments, companies ...), resorting to espionage through actions that involve technological resources as COMINT (Communications Intelligence) and other not so much as HUMINT (Human Intelligence) but directly related to Information Security, among other activities of military intelligence.
All these issues we directly applied the relevant conflicts that were generated in recent years with cases such as USA and Israel, Russia and Estonia, among others where hacktivism, computer vandalism, campaigns propagandists and psychological action strategies flood Internet for the sole fact weaken the opponent.
The first question that might be created in the mind is why use technology in this way? Well ... Sun Tzu I make it quite excellent when still no one spoke of it: "The enemy that operates in isolation, lacking a strategy and taking their opponents lightly will inevitably end up being defeated."
Jorge Mieres
Sunday, September 20, 2009
Saturday, September 19, 2009
Phoenix Exploit's Kit. Another alternative for controlling botnets
This is another of the alternatives in the underground market crimeware. In this case, another web application developed in PHP and originally from Eastern Europe. Phoenix Exploit's Kit.
This package consists of nine (9) exploits:
As information processing, Phoenix allows, as is usual in most such programs, to obtain statistical data on the types of browsers (MSIE, Firefox, Opera, etc.), versions of browsers, operating systems such infected countries of origin and some more data that together they become a normal intelligence process conducted by the botmasters.
While Phoenix Exploit's Kit isn't a recent development, the first version emerged in the heyday of this type of crimeware (2007), currently in the "business" underground at a price that raced around USD 400 when purchased with a domain.
Phoenix joins the collection and supply of a criminal world that moves everyday gear dark underground and illegal businesses on the Russian market of crimeware.
Related information
iNF`[LOADER]. Control de botnets, marihuana y (...) malware
Fragus. Nueva botnet framework In-the-Wild
Liberty Exploit System. Otra alternativa crimeware...
Los precios del crimeware ruso. Parte 2
Eleonore Exploits Pack. Nuevo crimeware In-the-Wild
Jorge Mieres
This package consists of nine (9) exploits:- IE6 MDAC
- MS Office Snapshot
- PDF Collab / printf / getIcon in Adobe Reader
- IE7 MEMCOR in Internet Explorer 7, Windows XP and Windows Vista
- FF Embed
- Flash 9 in plugin vulnerable of Shockwave Flash
- IE6/IE7 DSHOW
- JAVA in JRE
- Flash 10 in the versions 10.0.12.36 and 10.0.22.87 of Flash Player
As information processing, Phoenix allows, as is usual in most such programs, to obtain statistical data on the types of browsers (MSIE, Firefox, Opera, etc.), versions of browsers, operating systems such infected countries of origin and some more data that together they become a normal intelligence process conducted by the botmasters.While Phoenix Exploit's Kit isn't a recent development, the first version emerged in the heyday of this type of crimeware (2007), currently in the "business" underground at a price that raced around USD 400 when purchased with a domain.
Phoenix joins the collection and supply of a criminal world that moves everyday gear dark underground and illegal businesses on the Russian market of crimeware.
Related information
iNF`[LOADER]. Control de botnets, marihuana y (...) malware
Fragus. Nueva botnet framework In-the-Wild
Liberty Exploit System. Otra alternativa crimeware...
Los precios del crimeware ruso. Parte 2
Eleonore Exploits Pack. Nuevo crimeware In-the-Wild
Jorge Mieres
Sunday, September 13, 2009
The danger of a new generation of bootkits
While both the rootkits as bootkit part of the same concept and end up being the ultimate goals remain the same, there are certain patterns that differentiate and make bootkit the inevitable evolution of rootkit conventional state of the art by adding more complex actions.
By definition, a rootkit is designed to conceal certain activities that an attacker can take on a vulnerable system, precisely this characteristic being exploited by malware writers to hide the activities of the (handling registry keys, processes, files, etc.) at the time of infecting a system. That is, the primary objective of a rootkit is to prevent an attacker's activities are discovered.
This situation represents a serious potential danger to the security of any computer system and that depending on the type of rootkit can quietly go unnoticed because they generally have the ability to run a low level (kernel level).
Therefore, antivirus companies are characterized as hazardous or extremely hazardous, even, perhaps this is one of the responses on the efforts of securing the core operating system.
In this regard, earlier this year (2009) we witnessed the emergence of a type of rootkit that infects the MBR (Master Boot Record) of equipment, but unlike conventional rootkits of this style, this new variant is much more harmful and aggressive. His name is Stoned bootkit (based on the famous Stoned virus), was developed by Peter Kleissner and presented at BlackHat 2009.
When activated from the MBR, the infection bootkit ensures the equipment before starting the operating system can run from any storage device (USB, CD, DVD, etc.).. This means that no trace will be operating systems (processes in memory for example) because the bootkit no direct change on this.
Despite being considered a tool for handling a system (like the rootkit) as is its name suggests (toolkit boot sector) can, without doubt, be used for malicious purposes, and taking into Stoned Bootkit account that is designed to work well on Windows 7, regardless of their architecture (32-bit or 64-bit), may represent the most exploited malicious code during 2010.
Related information
Bootkit multiplataforma al ataque...
RootkitAnalytics
Jorge Mieres
By definition, a rootkit is designed to conceal certain activities that an attacker can take on a vulnerable system, precisely this characteristic being exploited by malware writers to hide the activities of the (handling registry keys, processes, files, etc.) at the time of infecting a system. That is, the primary objective of a rootkit is to prevent an attacker's activities are discovered.
This situation represents a serious potential danger to the security of any computer system and that depending on the type of rootkit can quietly go unnoticed because they generally have the ability to run a low level (kernel level).
Therefore, antivirus companies are characterized as hazardous or extremely hazardous, even, perhaps this is one of the responses on the efforts of securing the core operating system.
In this regard, earlier this year (2009) we witnessed the emergence of a type of rootkit that infects the MBR (Master Boot Record) of equipment, but unlike conventional rootkits of this style, this new variant is much more harmful and aggressive. His name is Stoned bootkit (based on the famous Stoned virus), was developed by Peter Kleissner and presented at BlackHat 2009.
When activated from the MBR, the infection bootkit ensures the equipment before starting the operating system can run from any storage device (USB, CD, DVD, etc.).. This means that no trace will be operating systems (processes in memory for example) because the bootkit no direct change on this.
Despite being considered a tool for handling a system (like the rootkit) as is its name suggests (toolkit boot sector) can, without doubt, be used for malicious purposes, and taking into Stoned Bootkit account that is designed to work well on Windows 7, regardless of their architecture (32-bit or 64-bit), may represent the most exploited malicious code during 2010.
Related information
Bootkit multiplataforma al ataque...
RootkitAnalytics
Jorge Mieres
Saturday, September 12, 2009
BootkitAnalytics: Under review status
Thanks to BootkitAnalytics team Vipin Kumar, Peter Klessner and Anushree Reddy, we are on editing stage. The final release should be there in about 10-20 days tops.
EF
EF
iNF`[LOADER]. Control of botnets, marihuana, and spreading malware
This is more of the many alternatives that exist for web applications designed to function as boards of directors and control botnets via web (C&C).
In this new example, how could it be otherwise, is of Russian origin and judging by the favicon and the image displayed in the upper left corner, perhaps his creator has admiration for marihuana and, why not, maybe it Bob Marley's fans :-)
Then observe the capture of the administration panel INF `[LOADER], but if we see another active too, can access ... better write me a mail and I pass the URL :-)
While this web application isn't new since its first version is 2007, its author was updated once per year (the current version 3) and the last is that we see in the catch, it was hardly within the crimeware underground environment.
At first he was associated with the spread of a rootkit called Goldun known, however it should be borne in mind that regardless of the malware that bring the kit by default, these applications are designed to exploit any vulnerability and disseminate any type of malware.
Among its modules, has one designed to try to bypass antivirus and firewall programs, self-destruction module with which you can remove the information from part or all of the zombies as part of its network, zombies statistics system discriminated country, among others.
As we see, the functionality offered by this threat aren't competitive in relation to others that exist in the market and are available at low cost even may even get a combo, although their cost doesn't exceed USD 100 now.
Still, this doesn't constitute a serious threat, regardless of the interface having the administration control panel and, if this force is because it has at its command, a good amount of zombies that make botmaster activity, a "work" profitable.
Related information
Fragus. Nueva botnet framework In-the-Wild
Liberty Exploit System. Otra alternativa crimeware...
Los precios del crimeware ruso. Parte 2
Eleonore Exploits Pack. Nuevo crimeware In-the-Wild
Especial!! ZeuS Botnet for Dummies
Jorge Mieres
In this new example, how could it be otherwise, is of Russian origin and judging by the favicon and the image displayed in the upper left corner, perhaps his creator has admiration for marihuana and, why not, maybe it Bob Marley's fans :-)
Then observe the capture of the administration panel INF `[LOADER], but if we see another active too, can access ... better write me a mail and I pass the URL :-)
While this web application isn't new since its first version is 2007, its author was updated once per year (the current version 3) and the last is that we see in the catch, it was hardly within the crimeware underground environment.At first he was associated with the spread of a rootkit called Goldun known, however it should be borne in mind that regardless of the malware that bring the kit by default, these applications are designed to exploit any vulnerability and disseminate any type of malware.
Among its modules, has one designed to try to bypass antivirus and firewall programs, self-destruction module with which you can remove the information from part or all of the zombies as part of its network, zombies statistics system discriminated country, among others.
As we see, the functionality offered by this threat aren't competitive in relation to others that exist in the market and are available at low cost even may even get a combo, although their cost doesn't exceed USD 100 now.Still, this doesn't constitute a serious threat, regardless of the interface having the administration control panel and, if this force is because it has at its command, a good amount of zombies that make botmaster activity, a "work" profitable.
Related information
Fragus. Nueva botnet framework In-the-Wild
Liberty Exploit System. Otra alternativa crimeware...
Los precios del crimeware ruso. Parte 2
Eleonore Exploits Pack. Nuevo crimeware In-the-Wild
Especial!! ZeuS Botnet for Dummies
Jorge Mieres
Sunday, September 6, 2009
ICFE Course
ICFE CG will be organising a 1-Day Masterclass on "Understanding Cyber Crime and introduction to Digital Forensics", on 19 November 2009 in Parkroyal Hotel, Kuala Lumpur, Malaysia.
For more details click here.
Course Introduction:
Forensics is the application of science and technology to civil and criminal legal investigations. While most forensics programs focus on the traditional approaches — fingerprints, DNA, photography — the CSI World Headquarters inauguration program targets cyberforensics — forensic analysis and procedures of the new millennium.
The CSI-CyberForensics program focuses on the basics of computer forensics with an emphasis on the legal aspects and techniques for such investigation.
There is a whole new science to collecting evidence and ensuring it will be admissible in a court of law. In the computer age, systemic risk investigators must learn to catch someone who has committed a crime when the evidence is most likely to be found on that suspect's computer, PDA, cell phone, MP3 player, or other digital device. It's often highly sensitive data that, if mishandled, can be corrupted and lost forever.
Because computer-aided systemic risk and identity theft are on the rise with no end in sight, computer forensics training is essential for the modern systemic risk investigator. In America, the FBI sponsors the Regional Computer Forensics Laboratories (RCFLs) staed by local, state and federal law enforcement personnel to meet this very pressing need. In this rst CSI World Headquarters Malaysian Chapter inauguration meeting, CSI instructors will share their knowledge with the registered participants on this very interesting and exciting tool in cybercrime investigation.
You can expect more computer forensics labs to start appearing around the world, as digital experts continue to emerge and branch out. The career prospect in this specialized eld is just beginning to be realized. This is an opportunity to be a Certied System Investigator and a chance to be ahead of the market place in the world of digital forensics and cybercrime investigation.
-----------
EF
For more details click here.
Course Introduction:
Forensics is the application of science and technology to civil and criminal legal investigations. While most forensics programs focus on the traditional approaches — fingerprints, DNA, photography — the CSI World Headquarters inauguration program targets cyberforensics — forensic analysis and procedures of the new millennium.
The CSI-CyberForensics program focuses on the basics of computer forensics with an emphasis on the legal aspects and techniques for such investigation.
There is a whole new science to collecting evidence and ensuring it will be admissible in a court of law. In the computer age, systemic risk investigators must learn to catch someone who has committed a crime when the evidence is most likely to be found on that suspect's computer, PDA, cell phone, MP3 player, or other digital device. It's often highly sensitive data that, if mishandled, can be corrupted and lost forever.
Because computer-aided systemic risk and identity theft are on the rise with no end in sight, computer forensics training is essential for the modern systemic risk investigator. In America, the FBI sponsors the Regional Computer Forensics Laboratories (RCFLs) staed by local, state and federal law enforcement personnel to meet this very pressing need. In this rst CSI World Headquarters Malaysian Chapter inauguration meeting, CSI instructors will share their knowledge with the registered participants on this very interesting and exciting tool in cybercrime investigation.
You can expect more computer forensics labs to start appearing around the world, as digital experts continue to emerge and branch out. The career prospect in this specialized eld is just beginning to be realized. This is an opportunity to be a Certied System Investigator and a chance to be ahead of the market place in the world of digital forensics and cybercrime investigation.
-----------
EF
Bootkit multi-platform attack. Is the resurrection of the boot viruses?
As many know, in the world of malicious code there is an extensive nomenclature to refer to each of the malicious programs that are walking around the large network, adopted according to the directions and purpose for which it was designed, with the most widely accepted English language. Even some direct translations are ugly ;P
In this connection, they may have read about a new name that has been doing a lot of noise from the last BlackHat: Bootkit. But ... what is it?
A bootkit is basically a type of rootkit designed to infect the boot sector of Windows operating systems, commonly known as the Master Boot Records (MBR).
While the rootkit concept dates back almost to the very existence of UNIX platforms and malicious code that abuse this feature isn't new, we could say that the concept of bootkit refers to a new family of malware to circumvent any system developed threat detection hosting its harmful instructions in the boot sector.
In fact there are several names that have made noise throughout history:
Now ... where is the most important point of all this. I think Mebroot marked the turning point adding to the illicit sphere a new methodology together with a concept that has direct relation to the crime in terms of using malware attacks that seek not only information that can be exploited even do intelligence or espionage, but also to fuel the economy of its developers, and continues with Vbootkit v2 now prepared to exploit Windows 7.
Under this scenario, the thing is heavy, since it is in complete professionalization of the evidence increasingly malware developers.
Stoned bootkit, is also designed to skip the security structures that offer products as TruCrypt by encrypting the entire volume of a unit, causing a direct attack on TrueCrypt. That is, has the ability to infect a computer even when encrypted, gaining access to the entire system regardless of safety precautions around the credentials with administrative permissions.
Ironically, the author uses a legend similar to the one that showed the old Stoned (Your PC is now Stoned!), Display each time you boot your system:
Your PC is now Stoned! ... again
Also unlike other rootkits to infect the boot sector of a specific operating system, the new Stoned has the ability to infect all versions from Windows XP to the highly anticipated Windows 7.
Given this, perhaps to become an essential module for malware writers seeking to break the security barriers of Windows 7.
Despite the absence of a significant amount of malicious code with these characteristics (bootkits) every time you receive one makes noise in the environment. Are we talking about resurrection? I think not. Especially after trying something he did not think possible at present: the Stoned 1897, still operates on Windows Vista.
# Jorge Mieres
In this connection, they may have read about a new name that has been doing a lot of noise from the last BlackHat: Bootkit. But ... what is it?
A bootkit is basically a type of rootkit designed to infect the boot sector of Windows operating systems, commonly known as the Master Boot Records (MBR).
While the rootkit concept dates back almost to the very existence of UNIX platforms and malicious code that abuse this feature isn't new, we could say that the concept of bootkit refers to a new family of malware to circumvent any system developed threat detection hosting its harmful instructions in the boot sector.
In fact there are several names that have made noise throughout history:
- Stoned in 1987 (it was taken as the basis for the development of Michelangelo) showing different messages on the screen.
- BootRoot first presented in 2005 during the BlackHat and designed to run on Windows XP.
- Kon-Bot makes a baypass on Windows authentication scheme, jumping and the authentication process.
- Vbootkit in 2007, which runs on Windows Vista and its second version appeared this year, designed to exploit in Windows 7 (including 64-bit). Both versions presented at the BlackHat.
- MebRoot, whose first version appeared in 2007, is designed to steal bank details and nature of which we see a screenshot presented in the paper "Now Your Computer is Stoned (... Again!). The Rise of MBR Rootkits" jointly developed by Symantec and F-Secure showing its evolution.
Now ... where is the most important point of all this. I think Mebroot marked the turning point adding to the illicit sphere a new methodology together with a concept that has direct relation to the crime in terms of using malware attacks that seek not only information that can be exploited even do intelligence or espionage, but also to fuel the economy of its developers, and continues with Vbootkit v2 now prepared to exploit Windows 7.
Under this scenario, the thing is heavy, since it is in complete professionalization of the evidence increasingly malware developers.
Stoned bootkit, is also designed to skip the security structures that offer products as TruCrypt by encrypting the entire volume of a unit, causing a direct attack on TrueCrypt. That is, has the ability to infect a computer even when encrypted, gaining access to the entire system regardless of safety precautions around the credentials with administrative permissions.
Ironically, the author uses a legend similar to the one that showed the old Stoned (Your PC is now Stoned!), Display each time you boot your system:
Your PC is now Stoned! ... again
Also unlike other rootkits to infect the boot sector of a specific operating system, the new Stoned has the ability to infect all versions from Windows XP to the highly anticipated Windows 7.
Given this, perhaps to become an essential module for malware writers seeking to break the security barriers of Windows 7.
Despite the absence of a significant amount of malicious code with these characteristics (bootkits) every time you receive one makes noise in the environment. Are we talking about resurrection? I think not. Especially after trying something he did not think possible at present: the Stoned 1897, still operates on Windows Vista.
# Jorge Mieres
Subscribe to:
Posts (Atom)
