Home|Contact us|RSS | Search
 
   

 
   
   
 
Home Security Center MCRC Blog 2008
          
Security Center
Overview
Latest Web Vulnerabilities
“In the Wild” Audit Results
URL Analysis
Info Center
Malicious Page of the Month
Test Your Vital Security Policy
Code Obfuscation
Glossary
MCRC Blog

MCRC Blog - 2008

Yahoo Cache Magic!?

Recently, the popular social media service site, imeem.com, was compromised by permanent XSS attack – this attack is very similar to the one we discussed few month ago - XSS attack optimized by SEO techniques . Fortunately, for most cases, the XSS attack on imeem.com did not work, as the malicious IFrame was injected to the page HTML Title tag (which is being rendered as text by popular web browsers). The search term along with the malicious IFrame were also appended to the bottom of the page, this time in HTML escape form, which neutralize the attack.

Governmental, Healthcare, and Top Business Websites have fallen victims to the new round of Asprox mass attack

As covered in my previous post a new round of mass Web attacks has started during May 2008. Hackers successfully compromised a large number of government and top businesses websites worldwide to infect visitors with malware. The attack toolkit being used (which is aliased as “Asprox”) has been around for few years; however, during the last year we have noticed a rise in the number of attacks using it. The attack toolkits is designed to first search Google for webpages with the file extension [.asp] and then launch SQL injection attacks to append a reference to the malware file using the SCRIPT tag.

Short research of “in-the-cloud-service” and “unknown malware samples”

It looks like the new AV buzzword of “in-the-cloud-service” has gathered momentum among Anti- Virus vendors. On June 30, 2008 an interview with Trend Micro’s CEO was published on Zdent.co.uk titled “Antivirus industry lied for 20 years “– it makes me wonder what is going to be changed in the 21st year? In the interview Trend Micro’s CEO unveiled the new vision of her company - moving to “In the Could Service” e.g. “throws all the unknown samples up into the cloud for deeper and faster pattern recognition”. What will happen if I’m offline...?.

2008 Cybercrime economy

A couple of years ago, credit card numbers and bank account PINs were traded for $100 or more on sites selling that kind of stolen information. But nowadays prices have dropped to $10-$40 per item.

Guess who’s got your passwords and emails stored on their servers…?

In our recent MPOM report, we reported on a Crimeserver hosting 1.4G of unprotected stolen data, including passwords, medical data, emails etc. Many people asked us how we found the data. Was the data secure or not?

Attacker toolkits for free

During our ongoing research we came up against one curious site. The site is hacking/security oriented, and is located in Russia (hmm... the previous time i've cheked it was in Netherlands), and not significantly different from many other similar sites.

Crimeware server catering to “grab and run” criminals

During our research for the latest Malicious Page of the Month that has just released, we came across a domain that was being used as a command and control for the Crimeware that was executed on attacked machines. This domain was also used as the “drop site” for private information being harvested by that Crimeware.

New neosploit - without MDAC :)

There are some things in common to most of the attack toolkit, one of which is exploit against the MDAC vulnerability (patched in 2006), MDAC is also in many cases the first exploit the attacker is trying to use.

On the (dis)merits of privacy

Following up on my last post, after filing a complaint with the abuse department of privacyprotect.org (and blogging about the problem), I have just received an update noting that:

Taking down a malicious site - the good, the bad, and the ugly...

As part of the “closure” on the February Malicious Page of the Month, which involved meoryprof.info (taken down), and spywaresafe.net we have contacted the appropriate parties in order to notify them that these websites contain malicious code.

About window of vulnerability (and MS08-017)

We here at the MCRC conduct independent vulnerabilities research once in a while, in order to provide our customers the best protection we can offer. The last MS security update included fixes for 2 vulnerabilities in the MS Office Web Component that we have discovered, one of which (CVE-2007-1201) was reported to Microsoft two years ago (!!). This means a 2 year long window of vulnerability. Needless to say, Finjan customers have been protected for the last 2 years against exploitation of this vulnerability, even at times when this vulnerability has been used in the wild with no patch available.

Optimizing Cross Site Scripting - and general security practices

We have been working recently on a XSS attack that impacted a huge number of potential victims, as the attack itself has been “optimized” by SEO (Seacrh Engine Optimization) practices that pushed it to Google’s indexes.

From 0day PoC to attack

I’m not about to discuss the pros/cons regarding full disclosure, just to show an amusing example of it: A 0day vulnerability was discovered in “Rising” – a Chinese AV product (insecure method vulnerability) and a PoC was published at milw0rm.com. Today we found a site trying to exploit the vulnerability, but the funny thing is, it used the PoC as is (changing only the payload URL, and using obfuscation to hide it) leaving the original function name (test ) and “GO !” button to trigger it (e.g. the exploit will only run once the user clicks the “GO !” button ). Needless to say, the exploit is served as a hidden IFrame so the user won’t even see the button.

Crimeware server and the international man of mystery

While conducting research for the latest Malicious Page of the Month we have just released, we tried to track down the origins of the crimeware.

NeoSploit V.2.0.15 - and behind the scenes

As part of our on-going research we had the chance to “meet in person“ some parts of the server side operations behind the new version of the NeoSpolit toolkit.

The impact of just 5 random letters...

We have been watching in amazement what kind of impact our latest Malicious Page of the Month have had on the industry and media.

And the winner for "top virus" of 2007 is...

Not a virus. Not even a malware. Neither is the runner up... It's the method of how malware is populated.

Archive

2008
2007

 
 
 
  © Copyright 1996 - 2008. Finjan Inc. and its affiliates and subsidiaries. All rights reserved.       Privacy Policy