Saturday, October 10, 2009

Level of (im)maturity in prevention

A few days ago I received an email (not arrived as spam) that I am attracted wide attention, so I wanted to know its origin. Here you can see a screenshot of the email.

This is a false message intentionally sent to my email. The first thing that crossed my mind to see it was, first, the memory of the old "xploits" he thought, mistakenly, missing the fact only because it's easy to underestimate them and their condition very crude attempt to deceive users, on the other, questions will be effective ... today?, what's the level of preventing users from this sort of cheating?

The point is that I also wanted to know their origins. And so I came up a website that offers the "service", specifically, to send this sort of cheating with several alternatives regarding the strategies employed. And of course ... actually, not that the "xploits" ceased to exist but they changed their nomenclature, as this is nothing to Phishing.

However, before dealing in more detail some features of this site, I'd like to share some of the arguments expressed by the author directly through the "terms of use." The first thing we read is welcome ...

"Interested to discover passwords of friends, boyfriends/as, heads, enemies/as of who you want? You know that getting the password of your victim could get many things as personal data, data access and personal sites plenty of information."

This type of activity is punishable in most countries since the mail has the character of private ... condoning the crime? Besides ... someone wants to access my email account :)

It continues with some things funny curious that I share... "All the information provided here is for educational use and/or science."

"Scientific use?... without words...

"Our software is not designed to be used for malevolent purposes, the product was intended for responsible adults, not every person under age 18 may use our programs."

However, to access the site doesn't display a warning stating that they can only access the site over 18 years...

"Spyware programs were created as a solution for remote monitoring and surveillance of the computer."

From the perspective in which information security discusses these aspects, is nothing but an act framed in the guise of privacy violation. There are alternative, less intrusive and aggressive for the purposes of parents who want to "monitor" certain activities of their children without coming to an abusive state. In this regard I consider the best solution is useless if not accompanied by education regarding the dangers that exist online. The question isn't spying on our children...

Aside from the superficial to the mechanism of deception, the domain is hosted at Hosting Solutions International Inc, located in the U.S. under the IP address 69.64.58.50. At least three domains are in this direction and all redirected to the same page.

When you access this "service", we find a menu which is managed by the maneuvers of deception, allowing sending emails with fake messages to the main services (real) webmail and two of the most popular social networks. Even you can customize the messages.

The procedure, after selecting the service option to be used to provide a consistent level of confidence is a matter of selecting one option among several. As an example, consider a snapshot of a Gmail account bombarded with an example of each.

All contain in the body of the message, that address links to a fake page, in this case of Gmail, which requests an authentication process that is part of the deception. The page is a clone of the real and you are looking to steal user's authentication data to the webmail service. But according to this, the question is ... how do realize that is false?

Mainly, checking where to redirect the links found in the message. With the mere fact of passing the mouse over the link in the taskbar is the actual address.

Likewise, we must check the URL. In this case, the address begins with http://login.live.1d8gfh35f9h6438d2g6.tumsg.com/accounts/ServiceLogin.php?service false...

While the real beginning with
https://www.google.com/accounts/ServiceLogin?service...

Besides being completely different, false doesn't have the secure protocol (https) characteristic of all sites that require authentication via the web. While this particular aspect doesn't guarantee full security is a good habit to check your existence.

However, suppose that the attack is directed to a Hotmail user. The real address for this is:

http://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1255052408&rver=6.0.5285.0&wp=MBI&wreply=http:%2F%2Fmail.live.com%2fdefault.aspx&lc=3082&id=64855&mkt=en-

In this case we aren't with "https" and the false address is very similar to the real, which, it's likely that a user who doesn't understand much about it, fall into the trap without too much effort, but wonder... How many users verify the address?

Now, try to find some answers to the questions discussed above lines (are they effective now?, What is the level of preventing users from this sort of cheating?)

To obtain a test that was done was basically sending emails with fake messages using the "services" offered by this website, obviously under strict ethical sense as the intention is only investigative. Moreover, unless they pay a minimum cost of USD 15, there is no access to passwords.

What the business makes it evident that behind this system of deception. Also at the same time, its creators are made from a large database which until now has over 95.000 records, where each of those records is a victim.

For our purposes, obtain a statistic of the level of maturity in terms of sense of prevention on users, but passwords don't need to know how many users rely on the false message.

The sample consisted of 100 addresses to which it sent the same message that had come to my email. From one day to another, ie within 24 hours, emails sent Hundred, these were the results:

Sent: 100
User who fell into the trap: 12

As we see, a little over 10% of users who received this email with the message you have opened, and not only that, but have also offering trusted him unknowingly credentials data access to your accounts e-mail.

Accordingly, trivial attacks of this kind are more common than people think and have a worrisome level of effectiveness, but more worrying still is, in a way, that the level of maturity in terms of prevention is still low and that if these values are enhanced depending on the amount of emails of this kind that any spammer could send per day, the final death toll is very high.

Related information
Estado de la seguridad según Microsoft
Phishing y "cuentos" en navidad
Phishing para American Express y consejos

Jorge Mieres

Friday, October 9, 2009

Automation in creating exploits

In most cases, one of the most common parts used in any attacks are exploits, and the world of malicious code as well. All attacks using malware and are carried out using the infrastructure of the Internet, as an essential component involving the exploitation of vulnerabilities.

Regardless of public vulnerabilities appear every day (and not including the type 0-Day) the most relevant, being the most exploited are those that exploit weaknesses in applications designed to view the files .pdf, .swf, and course, Windows.

In this sense, the fact that they are "fashion" is an attribute that I believe, is based primarily on the early awareness of security risks that still seem to have. That even today are exploiting vulnerabilities are resolved over three years is the clearest evidence, and that also constitute one of the key strategies used by botmasters to recruit zombies a large scale.

Even today, nobody is surprised that web applications designed to control and manage botnets through http protocol, modules are sold with pre-configured exploits, as in the case of YES Exploit System or Liberty Exploit System among many others.

Moreover, the business of design is constantly looking crimeware "resources" automated to optimize their "services" and begin to appear on the black market, resources designed not only to automate the development of threats but also to make those threats as more complex possible.

Encryption malware, anti-debugger techniques, anti-analysis techniques such as detection of controlled environments (VirtualBox, VMWare, Virtual PC, Sandbox, etc.), and automation in the creation of exploits are faithful bulk tests on the market clandestine crimeware.

This last point in particular exploits the automated production, has created significant problems in recent years. But go too far, remember the serious security problem which represented conficker late last year to spread through a vulnerability in the family of Microsoft operating systems. However, its origin was marked before his appearance.

The operating process is generated based on a critical vulnerability on the RPC service published on 23 October 2008 (MS08-067), which forced Microsoft released the patch breaking its usual cycle (the second Tuesday of each month). Immediately after it began to be exploited by the trojan Gimmiv and vulnerability exploited by an exploit created by "ph4nt0m".

From there, the vulnerability was exploited by several malicious codes. In November, is an application that helps automate the process of creating exploits for this security weakness, and also incorporates a port scanner which aims to find vulnerable computers. The application has its origin in China.

A curious fact is that the original version of this program contains no "surprises". However, later manipulated officiate malicious intent as a "booby trap" incorporating a backdoor that installs silently in the team who wants to use the application. That is, biter bit ...

Also during November 2008 is the first version of conficker, a worm that exploits this vulnerability effectively causing great unrest in many companies that suffered the consequences on their networks, and undoubtedly, one of the media of malicious code history.

During the year 2009, another known vulnerability (MS09-002), but this time in Internet Explorer 7, which allows code execution when accessing a website and begin to be incorporated into web applications for control and administration of botnets, the teams exploded through .pdf and .doc files, Drive-by-Download attacks and Multi-Stage attacks.

Among them, Phoenix Exploit's Kit, Fragus, Liberty Exploit System, Eleonore Exploits Pack, Unique Sploits Pack, among others.

But it's a tool to exploit the vulnerability through a process of creating specific exploits for it, it starts to circulate through forums Israeli origin.

The program generates a script obfuscated in JS that hides the exploit.

Thus, the exploit is spreading through websites exploiting Windows systems through vulnerable IE7 browser.

These exploits are actively used by cybercriminals to initiate dissemination and infection processes, and applications that automatically generate it's In-the-Wild, with agravente that its development isn't restricted to deep programming skills .

As we can see, management and deployment of security updates, both operating systems and applications, has no foundation trivial, but is a very important aspect in maintaining the health of equipment.

Related information
Conficker IV. Dominios relacionados... y controversiales
Conficker III. Campaña de propagación (...) de limpieza
Conficker II. Infección distribuida del gusano mediático
Conficker. Cuando lo mediático se hace eco (...) problema de fondo
Anatomía del exploit MS08-078 by FireEye

Jorge Mieres

Monday, October 5, 2009

Sucuri Information security

Sucuri Information security

WOW, we just reached 3,000 sites being monitored on http://sucuri.net . I am so happy with the results so far!


-- Source: http://twitter.com/sucuri_security

Sucuri Information Security is doing an awesome job in all its networking services and tools. Do check it out at Sucuri.net.

- EF

Breaking the conventional scheme of infection

After years of being in the field of information security, and security antivirus particularly, you have the opportunity to hear comments trying to justify the unjustifiable are more like myths than truths.

A journalist recently asked us what our feeling against moderately advanced users who claim not to need antivirus software because they know what they actually have on your computer.

While this may be true, I think we should not sin of arrogance. What I mean by this? Many times we are confident in knowing what we do and then we find that what seemed trivial turned out to be very dangerous. Obviously, the case would be a utopian user aware of the dangers that exist in the cloud (this word so fashionable to refer to the Internet) and act accordingly through prevention mechanisms.

However, many times, these trivial issues lead us to create in our minds a false sense of security, we believe that when they don't. Moved this issue to the world of malware, it's more common than believed.

Let's review the structure in the first instance of malicious code conventional. We could say that it's basically composed of three modules: of harm, self-defense and communication.

The damage module is designed to execute instructions such as removing harmful information, encryption of files, send spam messages to MSN contacts, to execute DDoS attacks, keylogging, among many other things.

The self-defense module will control those aspects that violate their malicious instructions, for example, disabling security programs (firewall, antivirus), blocking access to native operating system functionality (registry, CMD, Task Manager ), including also blocking access to antivirus websites to keep updated. This module also includes more advanced techniques such as rootkits, virtual machine detection, anti-debugging, among others.

As for the communication module, which need not be present but that is characteristic of current malware will be responsible for establishing communication against a malicious server (which may be a zombie) to download other malicious code, update their own code, continue their cycle of propagation, manipulate the network connection (DNS, SMTP, HTTP proxies), encrypt the stolen information, and more depending on the type of malware.

All these activities can reveal the presence of malware on your computer, and they cling antivirus solutions during the discovery process. However ... what if this scheme is broken? This happens in the following example:

We have a file that spreads via email pretending to be a video, his name is videotestimonio.mpeg.exe (Social Engineering applied to the file). The user runs the file and immediately run an instance of the browser that displays a video found on YouTube that refers to what referred to the file name.

That is, not memory resident processes aren't handled any registry key, the PC isn't unusual symptoms and the user envisioned what was promised. However, something happened in the background.

The malicious code added information in the host file running a local pharming attack, intended to perform phishing attacks against the victim. In this case, the malware does not own communication modules, or self-defense, only one form of attack that all he does is add information on the host file, breaking the conventional scheme of infection. On this basis ... the machine is infected? Yes... antivirus will detect it? Most likely not because the host file isn't malware.

Regarding the development of malicious code is also trivial. It simply consists of a file .bat (video.bat) possessing the necessary instructions to add information in the host, generating a compressed file with WinRAR SFX (videotestimonio.mpeg.exe) with two lines of code that run the .bat.

Regardless of how trivial the malware. The effects can be achieved through this technique are very dangerous. Furthermore, the detection rate is very low. Only 12/41 (29.27%).

Obviously, confidence isn't as healthy, especially in an environment as ambiguous as the Internet.

Related information
Propagación automática de códigos maliciosos vía http
Simbiosis del malware actual. Koobface
Análisis esquemático de un ataque de malware basado en web

Jorge Mieres

Saturday, October 3, 2009

Security Jobs

Hello guys,

We have started a link on EvilFingers website, though we did not have enough time to collect all the job openings in infoSec. Hence, we are now going to start posting job openings in a new blog:
http://isjobs.blogspot.com/.

Follow us at the ISJobs blog at your convenience.

- EF

Job Opening: Senior Threat/Research Analyst

Amazing job opening in Atlanta, GA!!
Job Position: Senior Threat/Research Analyst
Job Area: Research
Location: Atlanta, Georgia
Relocation: Required. Relocation assistance is being offered.
Company: Growing company in the Southeast!!!! 8 total positions being added into their Research team. Amazing career potential!!!

Collaborating with the marketing and engineering teams, the Senior Research Analyst will typically need to design and construct analysis tools that automate the extraction of botnet intelligence and make it available to the company’s other technologies and its knowledgebase as well as responding to ad-hoc requests for malware analysis driven by business and client needs to determine characteristics, functionality, and/or recommend countermeasures.

The position may entail interaction with the media following the successful outcome of directed research or response activities.

Responsibilities:
· Independent threat analysis and data mining of new botnet instances
· Research in to new methods for detecting and reporting botnet activities
· Dissection of new botnet samples and the automation of sample processing
· Investigation of new botnet command and control tactics and subsequent enumeration of botnet operators
· Focused analysis of botnet outbreaks within enterprise and ISP networks
· Contribution to research and commercial papers describing the evolving botnet threat

Skills & Experience:
· Experience as a security engineer, threat intelligence analyst, or similar senior technical role
· Extensive knowledge of tracing and debugging Windows processes in the context of malware reverse engineering
· Proficiency with C/C++ programming and x86 assembly /disassembly
· Deep understanding of network flow data analysis, deep packet inspection and network behaviors of malicious software
· Comprehensive knowledge of anti-debugging and anti-instrumentation techniques
· Familiarity with packing and anti-reverse engineering techniques, including data obfuscations that employ primitive or basic cryptography
· Ability to troll underground Internet forums and criminal sites/portals for new botnet intelligence



Rian Freedman



Xpect SVC, LLC

404-522-8889 | LOCAL
888-973-2887 | TOLL
404-520-8081 | CELL
404-393-0862 | FAX
rfreedman@xpectsvc.com
www.xpectsvc.com

Friday, October 2, 2009

remote kernel debugging (on VM), speed it up!

Everyone can get tired of staring at windbg waiting for a remote command to be completed, here are a few tips to get your (virtual) debugging environment a little more pleasant to work with.

for VMware users here's a nice tip:
http://www.vmware.com/support/ws5/doc/ws_devices_serial_advanced.html

set this option in virtual machine configuration: serialN.pipe.charTimePercent = X
where N is the serial port number and X is a positive integer that expresses a percentage of the default speed (30 seems a value that work good)
then select from port advanced configuration on guest the maximum speed available for the com port (128000), and select the same speed when connecting with windbg.

two similar methods that seem to be more reliable, consist in a driver to be loaded on the guest and a patch to be applied to the virtual machine software on the host
VMKD (http://www.nynaeve.net/?page_id=168) which works only on VMware
and
VirtualKD (http://virtualkd.sysprogs.org) which should works also on VirtualBox.

regards
ocean