[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label DOS/DDOS. Tampilkan semua postingan
Tampilkan postingan dengan label DOS/DDOS. Tampilkan semua postingan

28/10/11

More Mac malware - new Tsunami backdoor variants discovered

WavesAs our friends at ESET have mentioned on their blog, new variants of the latest Mac malware - the Tsunami backdoor Trojan - have been discovered.

SophosLabs has received a few new samples of the malware - which can be used both to launch denial-of-service attacks and by remote hackers to gain access to your computer.

The new versions, which Sophos is adding detection for as OSX/Tsunami-Gen, are builds for 32-bit Intel x86 and PowerPC Mac computers, whereas the original version was 64-bit only. In addition, the new samples use a different IRC domain for their command & control server.

Some folks have questioned why the computer security industry has dubbed this threat "Tsunami", and I must admit that I find myself feeling somewhat uncomfortable with the name because of the devastating natural disasters that have struck in some parts of the world.

The truth is, however, that the name derives from one of the commands that can be sent to computers running the malicious code, to flood a target with internet traffic.

Tsunami command

It's actually the same command that was built into the Linux version of the attack tool (which Sophos calls Troj/Kaiten) first seen some years ago.

Because we see considerably less malware for Mac OS X than we do for Windows, new Mac threats tend to make the news headlines. It's important to note that the sky is not falling, and we believe the threat posed by OSX/Tsunami is currently quite low. Indeed, we have not received any reports from customers yet of infections by this Mac malware.

Nevertheless, it's clear that someone is working on developing new versions of this code for the Mac platform and you have to presume they are not doing it purely for the intellectual challenge. (If they are, Lord help them.. it's not much of a challenge)

Mac users would be wise to take preventative steps against this, and the other malware which we see for the Mac OS X platform. Free anti-virus software is available for Mac home users - so there's really no excuse.
Read More...

26/10/11

Tsunami backdoor for Mac OS X discovered

TsunamiOSX/Tsunami-A, a new backdoor Trojan horse for Mac OS X, has been discovered.

What makes Tsunami particularly interesting is that it appears to be a port of Troj/Kaiten, a Linux backdoor Trojan horse that once it has embedded itself on a computer system listens to an IRC channel for further instructions.

Typically code like this is used to rally compromised computers into a DDoS (distributed denial-of-service) attack, flooding a website with traffic.

If you were wondering where the name "Tsunami" comes from, that should probably help explain things.

It's not just a DDoS tool though. As you can see by the portion of OSX/Tsunami's source code that I have reproduced below, the bash script can be given a variety of different instructions and can be used to remotely access an affected computer.

Tsunami source code

Sophos's Mac anti-virus products (including our free anti-virus for Mac home users) are being updated to detect OSX/Tsunami-A.

The big question, of course, is how would this code find itself on your Mac in the first place? It could be that a malicious hacker plants it there, to access your computer remotely and launch DDoS attacks, or it may even be that you have volunteered your Mac to participate in an organised attack on a website.

But remember this - not only is participating in a DDoS attack illegal, it also means that you have effectively put control of your Mac into someone else's hands. If that doesn't instantly raise the hairs on the back of your neck, it certainly should.

Tsunami snapshot
Mac users are reminded that even though there is far less malware in existence for Mac OS X than for Windows, that doesn't mean the problem is non-existent. You only need to read our short history of Mac malware to realise that.

We fully expect to see cybercriminals continuing to target poorly protected Mac computers in the future. If the bad guys think they can make money out of infecting and compromising Macs, they will keep trying.

My advice to Mac users is simple: don't be a soft target, protect yourself.
Read More...

New DOS tool overloads SSL servers with ease

The DOS attack tool takes advantage of a feature in SSL that can be maliciously exploited to overload servers using a single laptop

A newly released denial-of-service (DOS) tool can be used to bring down SSL servers using an average laptop computer and a standard DSL connection.

Called THC-SSL-DOS, the tool was created by German hacking outfit The Hackers Choice (THC) and exploits a rarely used, but widely available, feature in the SSL protocol called SSL renegotiation.

[ Learn how to greatly reduce the threat of malicious attacks with InfoWorld's Insider Threat Deep Dive PDF special report. ]

This type of attack is not new. In fact, vendors have known about the issue since 2003 and, according to the THC, the method was used in last year's DOS attacks against MasterCard.

The hacking outfit decided to release the tool now because it has already been leaked online a couple of months ago. "We are hoping that the fishy security in SSL does not go unnoticed. The industry should step in to fix the problem so that citizens are safe and secure again," a THC member said.

It's worth pointing out that even without SSL renegotiation enabled, attackers can still use THC-SSL-DOS successfully against servers. However, such attacks would require more than a single laptop.

"It still works if SSL renegotiation is not supported but requires some modifications and more bots before an effect can be seen," the group noted. "Taking on larger server farms who make use of SSL load balancers required 20 average size laptops and about 120kbit/sec of traffic," it added.

This is not the first time when SSL renegotiation exposed servers to security risks. Back in November 2009, a Turkish grad student devised a proof-of-concept man-in-the-middle attack that exploited a vulnerability in this SSL feature to steal Twitter login credentials passed over secure connections.
Read More...

25/10/11

THC SSL DoS/DDoS Tool Released For Download

THC-SSL-DOS is a tool to verify the performance of SSL. Establishing a secure SSL connection requires 15x more processing power on the server than on the client. THC-SSL-DOS exploits this asymmetric property by overloading the server and knocking it off the Internet. This problem affects all SSL implementations today. The vendors are aware of this problem since 2003 and the topic has been widely discussed.

This attack further exploits the SSL secure Renegotiation feature to trigger thousands of renegotiations via single TCP connection.

Usage

./thc-ssl-dos 127.3.133.7 443
Handshakes 0 [0.00 h/s], 0 Conn, 0 Err
Secure Renegotiation support: yes
Handshakes 0 [0.00 h/s], 97 Conn, 0 Err
Handshakes 68 [67.39 h/s], 97 Conn, 0 Err
Handshakes 148 [79.91 h/s], 97 Conn, 0 Err
Handshakes 228 [80.32 h/s], 100 Conn, 0 Err
Handshakes 308 [80.62 h/s], 100 Conn, 0 Err
Handshakes 390 [81.10 h/s], 100 Conn, 0 Err
Handshakes 470 [80.24 h/s], 100 Conn, 0 Err
 
Comparing flood DDoS vs. SSL-Exhaustion attack

A traditional flood DDoS attack cannot be mounted from a single DSL connection. This is because the bandwidth of a server is far superior to the bandwidth of a DSL connection: A DSL connection is not an equal opponent to challenge the bandwidth of a server.

This is turned upside down for THC-SSL-DOS: The processing capacity for SSL handshakes is far superior at the client side: A laptop on a DSL connection can challenge a server on a 30Gbit link. Traditional DDoS attacks based on flooding are sub optimal: Servers are prepared to handle large amount of traffic and clients are constantly sending requests to the server even when not under attack.

The SSL-handshake is only done at the beginning of a secure session and only if security is required. Servers are _not_ prepared to handle large amount of SSL Handshakes. The worst attack scenario is an SSL-Exhaustion attack mounted from thousands of clients (SSL-DDoS).

Tips & Tricks for Whitehats
  1. The average server can do 300 handshakes per second. This would require 10-25% of your laptops CPU.
  2. Use multiple hosts (SSL-DOS) if an SSL Accelerator is used.
  3. Be smart in target acquisition: The HTTPS Port (443) is not always the best choice. Other SSL enabled ports are more unlikely to use an SSL Accelerator (like the POP3S, SMTPS, … or the secure database port).
Counter measurements
No real solutions exists. The following steps can mitigate (but not solve) the problem:
  1. Disable SSL-Renegotiation
  2. Invest into SSL Accelerator
Either of these countermeasures can be circumventing by modifying THC-SSL-DOS. A better solution is desireable. Somebody should fix this.

You can download THC-SSL-DOS here:

Windows: thc-ssl-dos-1.4-win-bin.zip

Linux: thc-ssl-dos-1.4.tar.gz

Or read more here.
Read More...

19/10/11

DDoS and SQL injection are hot topics on hacking forums

Forums are the cornerstone of hacking, providing a venue for hackers to sell and exchange information

Distributed denial of service and SQL injection are the main types of attack discussed on hacking forums, according to new research from security vendor Imperva.

Underground discussion forums are an important piece in the cybercriminal ecosystem. They offer a place for hackers to sell and exchange information, software tools, exploits, services and other illegal goods.

[ Learn how to greatly reduce the threat of malicious attacks with InfoWorld's Insider Threat Deep Dive PDF special report. ]

"Forums are the cornerstone of hacking -- they are used by hackers for training, communications, collaboration, recruitment, commerce and even social interaction," Imperva stressed.

The company's researchers have recently analyzed discussions going back several years from HackForums.net, one of the largest hacker forums with over 220,000 registered members. Their effort was aimed at determining the most common attack targets, what business trends can be observed, and what directions hackers are leaning toward.

As far as attack popularity goes, the analysts determined that DDoS was mentioned in 22 percent of discussions. SQL injection, a technique commonly used to compromise websites, is the second most frequently discussed attack method, being at the center of 19 percent of conversations.

Unsurprisingly, with a 16 percent discussion occurrence rate, spam is the third most favorite attack type according to Imperva's content analysis. That's probably because it is one of the primary methods of generating illegal income.

Zero-day exploits make up 10 percent of attack discussions on the forum, however, Microsoft's latest Security Intelligence Report (SIR) claims that this type of exploit is used in less than 1 percent of real-world compromises.

Forums are also an important learning tool for new hackers -- Imperva determined that up to a quarter of discussions fall into the beginner hacking category. Another 25 percent of conversations involved hacking tools and programs, while a fifth mentioned Web and forum hacking.

One trend observed by Imperva's researchers was that mobile hacking is increasingly popular. This is also reflected in real-world attack statistics and reports from other vendors. iPhone hacking in particular accounted for half of conversations on this topic.

Overall, discussions about hacking have increased more than 150 percent over the last four years. "We think the growth in hacker forum activity helps explain that, along with automated hacking, there are simply more hackers causing more breaches," Imperva concluded.
Read More...

18/10/11

Inside a Hacker Forum

Hacker forumHacker forums function as a kind of combination training academy, social network and central bazaar for attackers looking for new tools, methods and techniques. They're also often patrolled by law enforcement agents and security researchers, but it's rare that any of the information that those people gather ever makes it into the hands of the public. One security company is now laying out some of the details of a year-long observation of a large hacker forum.

As it turns out, hackers in many ways are just like most people, with the small distinction that they steal things for a living. Researchers at Imperva began looking at one specific forum in June 2010, and focused in large part on what kinds of discussions the members were having. They found that many of the would-be attackers are not only interested in finding new tools and techniques, but also sometimes enjoy discussing religion, books and philosophy.

But when it comes to specific attacks, much of the discussion focuses on the techniques that have been among the more popular methods in recent years, especially DDoS and SQL injection. They found that 22 percent of the discussions on attack techniques by members of this unnamed forum were about DDoS attacks, while another 19 percent were about SQL injection. Both of those methods have been in widespread use for a long time now, and they also can be executed by people without a lot of technical skills.

DDoS attacks in particular often are the first forays by new attackers as they get into the scene, and there are a lot of simple point-and-shoot tools available for these people to experiment with. Even with these tools readily available, a lot of the discussions on hacking methods also center on learning how to get started, the researchers found. The Imperva study is by no means a a comprehensive survey of hacker forums, but just a snapshot of one specific forum at a point in time.

"Hackers devote most of their time, 25%, towards discussing beginning hacking. The strongest category with nearly 25% of discussions was on hacking tutorials. This means there’s a strong, steady interest in content to learn hacking, ensuring a steady supply of new talent. Other hacks, such as botnets and zombies, were prominent but website hacking more than tripled the next highest topic," the study found.

In addition to discussions about specific techniques and tools, the forum that the researchers studied also includes quite a bit of educational content for members looking to learn. There are sections on learning skills such as social engineering, SQL injection and how to cover your tracks once you've compromised a machine.

As nice as all of the education and sharing on the forum is, the main reason for being for many of these sites is to help attackers who are looking to buy or sell pilfered goods find one another. The Imperva researchers found that in the forum they observed, credit card numbers, many of which include dates of birth and other information, were selling for short money. For U.S. numbers, the prices ranged from $2 for Visa up to $6 for Discover. The prices were slightly higher for numbers from countries in the European Union, going as high as $8 for American Express and Discover.
Read More...

13/10/11

VeriSign Demands The Power To Take Down Websites/Domains

I was scanning the news today, and nothing much was going on. There were some half-arsed stories about Anonymous and LulzSec – but nothing really worth writing about. And then, and then I spotted this, which quite frankly scares the shit out of me.

As much as it may well have a use in law enforcement, I’m sorry but I don’t want any single organization, corporation or entity to have the power to take out domains.

It’s just plain wrong, and well the UK has already started tabling something like this back in September.

VeriSign, which manages the database of all .com internet addresses, wants powers to shut down “non-legitimate” domain names when asked to by law enforcement.

The company said today it wants to be able to enforce the “denial, cancellation or transfer of any registration” in any of a laundry list of scenarios where a domain is deemed to be “abusive”. VeriSign should be able to shut down a .com or .net domain, and therefore its associated website and email, “to comply with any applicable court orders, laws, government rules or requirements, requests of law enforcement or other governmental or quasi-governmental agency, or any dispute resolution process”, according to a document it filed today with domain name industry overseer ICANN.

The company has already helped law enforcement agencies in the US, such as the Immigration and Customs Enforcement agency, seize domains that were allegedly being used to sell counterfeit goods or facilitate online piracy, when the agency first obtained a court order.

That seizure process has come under fire because, in at least one fringe case, a seized .com domain’s website had already been ruled legal by a court in its native Spain.

Senior ICE agents are on record saying that they believe all .com addresses fall under US jurisdiction.

But the new powers would be international and, according to VeriSign’s filing, could enable it to shut down a domain also when it receives “requests from law enforcement”, without a court order.

Yes VeriSign do manage all the .com and .net domains, but they aren’t technically ruled under the US jurisdiction – there are plenty of .com domains that are hosted outside of the US, including the DNS infrastructure.

What I’m especially interested in, is how they plan to handle the fact that lots of things are illegal in some countries and perfectly legal in others. The part that scares me is they will be able to take down a domain without a court order, just on ‘request’ from a law enforcement agency.

To me, that opens it up to abuse – if you are going to do something like this, at least institute a due process to manage it properly.


“Various law enforcement personnel, around the globe, have asked us to mitigate domain name abuse, and have validated our approach to rapid suspension of malicious domain names,” VeriSign told ICANN, describing its system as “an integrated response to criminal activities that utilize Verisign-managed [top-level domains] and DNS infrastructure”.

The company said it has already cooperated with US law enforcement, including the FBI, to craft the suspension policies, and that it intends to also work with police in Europe and elsewhere.

It’s not yet clear how VeriSign would handle a request to suspend a .com domain that was hosting content legal in the US and Europe but illegal in, for example, Saudi Arabia or Uganda.

VeriSign made the request in a Registry Services Evaluation Process (RSEP) document filed today with ICANN. The RSEP is currently the primary mechanism that registries employ when they want to make significant changes to their contracts with ICANN.

The request also separately asks for permission to launch a “malware scanning service”, not dissimilar to the one recently introduced by ICM Registry, manager of the new .xxx extension.

That service would enable VeriSign to scan all .com websites once per quarter for malware and then provide a free “informational only” security report to the registrar responsible for the domain, which would then be able to take re-mediation action. It would be a voluntary service.

Scary thoughts really. However the malware scanning service sounds like something that would help the Internet clean up all the nasty stuff, but then again – do the registrars really care, and would they respond?

Either way, I don’t like the fact that these draconian control laws may be placed on the Internet as we know – that basically allow US law enforcement agencies to take down domains as they please.

What I’m guessing, if this is implemented, it may well become a major target for Social Engineering efforts. What’s more effective than a traditional DDoS attack? Having the domain completely killed by VeriSign – that’s what.
Read More...

12/10/11

Report: Smartphones will become a way to attack otherwise protected devices

Compromised smartphones will infect computers when they dock in much the same way malware gets onto laptops via thumb drives

Smartphones will become an increasing menace to network security that could drop malware onto protected devices when they dock to sync or plug into USB ports to charge, security experts say in a Georgia Tech report.

Compromised smartphones will infect computers they may plug into for otherwise legitimate reasons, much the same way malware such as Stuxnet found its way onto laptops via thumb drives, according to the "Emerging Cyber Threats Report 2012" (PDF) released at the Georgia Tech Cyber Security Summit 2011" today. It was presented by the Georgia Tech Information Security Center and Georgia Tech Research Institute. [ Stay ahead of advances in mobile technology with InfoWorld's Mobile Edge blog and Mobilize newsletter. ]

ONLINE SECURITY: Father of SSL says despite attacks it has lots of life left

The report warns that "mobile phones will be a new on-ramp to planting malware on more secure devices." The document cites an anonymous industry source saying that "... someone who just needs to charge his phone can introduce malware as soon as it's plugged into a computer within that location."

Other problems include the differences between laptop browsers and those used on smartphones. The latter display address bars fleetingly, leaving little time to observe the safety status of sites being visited, the report says. "If a user does click on a malicious link on a mobile browser," the report says, "it becomes easier to obfuscate the attack since the Web address bar is not visible."

Finding information about SSL certificates a site may be using may be difficult if the information is available through the browser at all, the researchers say.

Touch screens on smartphones may make users more susceptible to clicking on links that seem legitimate but mask malicious sites beneath them, which could lead to drive-by downloads of malware.

Patches and updates for smartphones are woefully infrequent, the report says. "While computers can be manually configured not to trust compromised certificates or can receive a software patch in a matter of days, it can take months to remediate the same threat on mobile devices -- leaving mobile users vulnerable in the meantime."

Meanwhile, the authors say that bot masters will find more ways to make money off their zombie machines beyond using them as spam or DDoS engines. For example, a downloader controlled by a bot master could infect machines with reconnaissance malware that profiles the user of the machine for marketing purposes. The information can be sold and resold until a legitimate business buys the information as part of a lead-generation effort, the report says.

Or alternatively, the zombies could be queried for personal technical details as a way to design a long-term stealthy attack to compromise data. Botnet operators will work more to create bot armies that they lease to others for whatever purpose they have in mind. "Infrastructure and information sharing will also occur more regularly between botnet operators and other malicious actors," the report says.
Read More...

06/10/11

Fed Seeks Industry Standard for Botnet Mitigation

The Departments of Commerce and Homeland Security met with various other government agencies and private-sector leaders yesterday to discuss the need for a code of conduct for detecting, mitigating, and otherwise dealing with botnets.

The invitational meeting was hosted by the Center for Strategic and International Studies (CSIS) and among the topics covered by the group of IT policy experts was the problematic and at time controversial issue of notifying individuals whose computers have been infected with malware and are part of a botnet. There was also a panel discussion with members from the U.S. Internet Service Providers Association, DHS, National Institute of Standards and Technology (NIST), and StopBadware. The panel discussed how ISPs and other organizations can play their part in the fight against botnets by developing ways to better detect their activities and notify infected consumers.

According to a NIST press release, there are an estimated 4 million new botnets infections each month. These infected machines can be used for any number of reasons. Individuals can have their personal information and communications monitored, their computing power and internet access exploited, or more commonly, their computer can be used to disseminate spam, store or transfer illegal content and launch DDoS attacks.

“Improving cybersecurity requires a combination of efforts in which everyone has a role to play,” said White House Cybersecurity Coordinator Howard Schmidt in his keynote address. “By working together to achieve better security, we can make the improvements needed that will ensure the security and resilience we need to prosper as a nation.”

As examined in a recent Securelist piece and asked in our latest Threatpost poll, the question of how to deal with the network of infected computers left in the wake of a botnet takedown is an increasingly relevant one, as corporate and law enforcement partnerships experience more success against botnets. Read More...

Home Topics Blogs Multimedia Resources About Home › Malware Attacks › October 5, 2011, 9:23AM Chinese DDoS Bots Lack Sophistication, Stealth

China botsBARCELONA--China may have caught and passed many western nations in terms of economic power and military might, but, despite its reputation as a major player in the malware economy, many of the bots and DDoS tools that come out of the country are shoddy, cobbled-together malware full of bugs and with no real effort made to hide themselves.

"A lot of it has the feel that it was chopped up and hacked together," Jeff Edwards, a security analyst at Arbor Networks, said in a talk on Chinese bot families at the Virus Bulletin conference here Wednesday. "There's a lot of sloppiness everywhere with blatant flaws."

Arbor researchers follow the botnet scene closely and the company took a specific look at a variety of bot families that are commonly used in DDoS attacks originating in China and against Chinese targets. What they found was a collection of roughly 40 bot families, many of which showed evidence of some serious inbreeding. Code re-use is rampant among the major Chinese DDoS bots, and Edwards said that it's not uncommon to see whole sections lifted from one bot and used in another, bugs and errors included.

Like bots found elsewhere on the Web, Chinese-produced DDoS tools often will have the ability to employ a wide variety of attack methods. The classic SYN flood and TCP flood methods are prevalent, as are HTTP floods. But what's not typically found at all in Chinese bots is the ability to execute the slow HTTP DDoS attacks that have been cropping up in the United States, Russia and elsewhere in recent years.

This tactic is far less noisy than a typical denial-of-service attack. Instead of sending huge numbers of packets to a target server, these attacks involve breaking up TCP requests into tiny pieces and taking as long as an hour or more to complete one request.

"This just hasn't show up in the Chinese DDoS space for some reason," Edwards said.

It may just be a matter of time before this behavior appears in China. But for now, what Edwards and other Arbor researchers found in their study of the landscape is that many DDoS attacks in China tend to focus on smaller, lower profile sites, and some bot families even seem to specialize in attacking one particular industry. The Darkshell bot, for example, tends to target the sites of manufacturers of food processing equipment in China for whatever reason.

In general, the DDoS bots being written and deployed in China right now just aren't very sophisticated. Few of them employ any meaningful obfuscation and Edwards said he has yet to see any real encryption deployed to complicate analysis.

"There's virtually no rootkit behavior and no real attempts at hiding," he said. "There are a ton of these families cropping up all the time, at least one a week. There's a ton of code sharing across families and there's little or no stealthiness." Read More...

26/09/11

Homeless hacker 'Commander X' pleads not guilty [VIDEO]

Commander XThe FBI believes that the homeless man they arrested on Thursday was "Commander X", a member of the People's Liberation Front (PLF) associated with Anonymous hacktivism.

47-year-old Christopher Doyon has entered a not guilty plea to charges of "conspiracy to cause intentional damage to a protected computer, causing intentional damage to a protected computer, and aiding and abetting".

According to an indictment filed against Christopher Doyon and another man, Joshua John Covelli, the charges specifically relate to a denial-of-service attack against the servers of Santa Cruz County in December 2010, after the city put in place a law prohibiting camping inside the city.

Indictment against Christopher Doyon and Joshua John Covelli
The indictment gives Doyon the aliases "PLF", "Commander Adama" (clearly a Battlestar Galactica fan) and "Commander X". Covelli meanwhile is alleged to use the pseudonyms "Absolem" and "Toxic". 26-year-old Covelli was previously named in connection with internet attacks on PayPal.

Someone calling themselves "Commander X" gave an interview to CBS News earlier this year, claiming responsibility for denial-of-service attacks by Anonymous.


According to a CBS News report, "Commander X" told their reporter that he had no fear about being caught:
"We're not going to turn ourselves in. They can come and get us is what I say. Bring it on. Until then, we run... We will remain free and at liberty and at large for as long as we can, and when the time comes that each and every one of us eventually will be brought to justice, we will hold our head high in any court of law and we will defend our actions."
Doyon is scheduled to appear on September 29th for a bail hearing.

nb : nakedsecurity.sophos
Read More...

22/09/11

SSCC 73 - Patch Tuesday, UBS, SpyEye, Twit.tv and Windows 8

Sophos Security Chet Chat logoI was very happy to have Paul Ducklin, Sophos's Head of Technology, Asia Pacific, as my guest again this week.

Paul joined me amidst what he referred to as a Denial of Service (DoS) attack at the security checkpoint of Sydney airport.

Paul shared his thoughts on the September 2011 Patch Tuesday release from Microsoft and Adobe (Hint: if you have to prioritize, start with Adobe.)

We chatted a bit about the guy who lost more than £2.3 billion as a trader for UBS bank. If they can't keep track of £2.3 billion, are they taking proper care of our personally identifiable information?

It appears SpyEye is following in the Zeus bot's footsteps and is beginning to target mobile banking users on Android who use their phone as a second factor for authentication. Paul explains the social engineering aspects of this malware.
One of the most popular tech podcast/vodcast sites, Twit.tv, run by Leo LaPorte was hacked this week. The malware targeted unpatched versions of Adobe Reader and Java. Remember, there is no such thing as safe surfing.

I asked Paul what he thought about the news that Microsoft will be including a free unmanaged anti-virus program in Windows 8.

He talked a bit about patching in general, and was upbeat that users who care to keep themselves up to date could definitely benefit.


nb : nakedsecurity.sophos
Read More...

18/09/11

Oracle issues rare out-of-band update for Apache DDoS vulnerability

Oracle, the giant enterprise database company - and, of course, owner of the erstwhile Sun Microsystems - has just published an out-of-band security update.

This is only the fifth time Oracle has issued an alert outside its routine quarterly patch cycle since introducing its own version of Patch Tuesday at the start of 2005.

The update introduces an updated version of the Apache web server, httpd, to Oracle's Fusion Middleware and Application Server products. The former product includes Apache httpd 2.2; the latter includes Apache httpd 2.0.
 
Apache httpd was recently discovered to be vulnerable to an easily-exploited denial of service attack. The vulnerability, CVE-2011-3192, allowed even a single web client to trigger a huge number of simultaneous requests for large amounts of data. The flaw was exploited by sending a request for multiple parts of the same file at the same time.

(The Range feature of the HTTP protocol was intended to make it easy for web clients to restart interrupted downloads where they left off, or to permit large files to be fetched piecemeal and stitched together later. Apache httpd made it easy to misuse this feature by tolerating redundant Range requests which asked for many large and overlapping parts of a single file.)

Oracle doesn't say on its public-facing web pages exactly how it patched the flawed Apache versions in its products.

The Apache Software Foundation has actually issued two official patches for httpd 2.2 relevant to the so-called byte-range flaw. Version 2.2.20 came out at the end of August, but that patch was recently superseded by 2.2.21, which is effect a patch for the 2.2.20 patch. Apache describes 2.2.21 as "[including] fixes to the patch introduced in release 2.2.20 for protocol compliance, as well as the MaxRanges directive."

It's not clear whether Oracle's out-of-band fix includes the patch-to-the-patch, which appeared only three days ago.

And the previous official Apache httpd version, 2.0, hasn't been patched since May, when 2.0.64 came out. Oracle, one assumes, has done its own back-port of the fix it applied to 2.2.

The fact that a patch-to-the-patch was necessary will no doubt cause more conservative IT administrators to say, "See. I told you that patches should never be rushed."

In this case, however, I consider the glass half-full, not half-empty. I'd argue that the first patch greatly improved the situation, despite being imperfect. The second patch simply improved the improvement further.

However conservative you might be, if you're an Oracle user, this patch is definitely recommended in a hurry. The general unwillingness of Oracle to deviate from its once-every-three-months patch cycle spells one word, "Importance."
As Oracle itself points out, in bold characters:
Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Security Alert fixes as soon as possible.
Sysadmins, there you have it. A little something for the weekend!

nb : nakedsecurity.sophos
Read More...

16/09/11

Oracle: Security flaw could bring down app servers

Oracle has issued an emergency patch to fix a vulnerability it says could bring down HTTP application servers it sells that are based on Apache 2.0 or 2.2.
Attackers can exploit the weakness remotely without a username or password, Oracle said in a security alert issued Thursday.

[ Discover what's new in business applications with InfoWorld's Technology: Applications newsletter. | Get the latest insight on the tech news that matters from InfoWorld's Tech Watch blog. ]

Products impacted by the bug include Oracle Fusion Middleware 11g Release 1, versions 11.1.1.3.0, 11.1.1.4.0 and 11.1.1.5.0; Oracle Application Server 10g Release 3, version 10.1.3.5.0; and Oracle Application Server 10g Release 2, version 10.1.2.3.0.

The U.S. Government's National Vulnerability Database has assigned a CVSS (Common Vulnerability Scoring System) rating of 7.8, "indicating a complete Operating System denial of service," Oracle said.
But Oracle took issue with that assessment in its security alert.

"A complete Operating System denial of service is not possible on any platform supported by Oracle, and as a result, Oracle has given the vulnerability a CVSS Base Score of 5.0 indicating a complete denial of service of the Oracle HTTP Server but not the Operating System," it stated.

In any event, the bug is serious enough for Oracle to issue the patch outside of its usual large quarterly updates, the next of which is scheduled for Oct. 18.

nb : infoworld Read More...

FBI: Psychological Profile of Anonymous Leadership is a Fake

It looks as if Anonymous's latest prank is a damning psychological profile of its own members, allegedly assembled by the FBI.

A spokesperson for the federal law enforcement agency said the document that was published online is a forgery, confirming speculation that it was a fake. The denial points a finger at Anonymous, itself, as the source of the document, in what appears to be an elaborate prank or an effort to sow disinformation.

The fake profile includes assessments of known Anonymous leaders, as identified by their Web-pseudonyms. It includes psychological sketches of Sabu, his described second-in-command, Kayla, the already-arrested and former spokesperson, Topiary, and the so-called autonomous members, JoePie91 and Tflow.

Many of the document's allegations are damning. It characterizes Sabu as a self-perceived martyr and narcissistic American male in his early thirties with a nihilistic world-view, likely an information security professional operating within the business community without alerting his peers to his other online activities. Kayla, characterized as the second-in-command, is profiled as a middle-American male in his early to mid-twenties whose stunted emotional age and inferiority complex may be the result of childhood trauma, perhaps an abusive parent, and who seeks attention as a result of a childhood desire for parental approval. Hmmm.... Very, very interesting.

Links to the document appeared on a Tumblr site and Twitter account affiliated with the group, media outlets ran with the story, even as they cast doubts about its authenticity.  Indeed, from the very first, casual readers and Anonymous sympathizers suspected it was a fake. The tone of the document is sensational and its content is rife with broad and thinly-sourced generalizations about the group and its members. (Wikipedia is cited for its description of the group.) It contains numerous spelling  and grammar errors and, perhaps the biggest red flag, casts aspersions on the FBI's own enforcement actions. In just one example, Topiary, a core member was arrested in the UK, is described as an ego-driven and idealistic youth with "Aspergers syndrome" (sp) who was used as cannon fodder for law enforcement.

It is unclear what the purpose of the document is. Despite its outsize reputation, Anonymous's core leadership is believed to be quite young. Many of those arrested so far in connection with distributed denial of service (DDoS) attacks and other actions are in their teens to early 20s. The profiles document may be a ham-fisted effort to throw investigators off the group's scent, or merely a practical joke from one Anonymous member to another.

nb : threatpost Read More...

13/09/11

QR Tags Can Hide Malicious Links, Experts Warn


QR CodeQR tags have become the next big thing in interactive marketing. But as smart phone users flock to the trendy, postage-stamp sized bar codes, researchers are warning that they could be used to hijack mobile phones by directing them to malicious Web pages.

In a post on the mobile security blog Kaotic Neutral on Saturday, researcher Augusto Pereyra demonstrated a practical attack that would link a malicious QR tag to an Internet based attack server running an instance of the Metasploit penetration testing. Similar attacks could be used to push malicious programs to vulnerable mobile devices that scan the QR tag, he said.

As mobile devices become a sought after conduit for advertisers, there's increasing concern about physical world attacks using interactive displays and advertising that could push malicious programs to smart phones. QR - or "Quick Response" - barcodes were first developed by a Toyota subsidiary to streamline supply chain activities, but have since been adopted outside the auto industry because they can easily store and convey large amounts of data and be deployed anywhere that bar codes can be, including product packaging and display advertising.

Researchers have already pointed out vulnerabilities in the implementation of NFC (Near Field Communications) on many smart phones, including mobile devices running Google's Android operating system. In June, researcher Collin Mulliner of Technische Universitaet in Berlin, Germany, demonstrated a denial of service vulnerability on Nexus S version Android phones that could be used to launch denial of service attacks.

As with the NFC attacks, QR attacks work mainly because users can't easily vet the content stored in the tags before they are scanned. The data in QR tags - rendered in machine-readable bar codes - must be scanned to reveal the purpose of the tag. That, effectively, creates a 'run first, ask questions later' implementation that greatly benefits attackers, says Kaspersky Lab researcher Timothy Armstrong.
"This type of attack is only legit(imate) because in essence it's a way of fooling people to visit a URL where they can't necessarily see where they're going," he said.

Kaspersky Lab researchers have seen Web based proof of concept attacks that use QR tags successfully against both iPhones and Android phones, Armstrong said.

In his proof of concept attack, Pereyra embedded the URL for an attack server, evilsite.dyndns(dot)org, in a QR tag he created using a free online tag creator. Mobile phones that scanned the tag would be redirected to that domain, from which attacks could be hosted, he said.

The only other task would be putting the attack QR tags out in public in places where users might be tempted to scan them. Pereyra hypothesized that attackers could plaster neighborhoods with phony contest posters asking passersby to scan the QR code for a chance to win, or even manufacture QR stickers that could be applied on top of legitimate tags on already posted advertisements. Researchers in Austria have also developed methods for physically altering existing tags to alter the data transmitted by them. (PDF)

Security for contactless technology like QR tags and NFC transactions is a major area of concern, especially as mobile device makers, carriers and third party firms push ahead with a wide range of services that leverage smart phones as transaction terminals. The U.S., already a laggard in mobile transaction and smart card adoption, is stuck playing catch up in areas related to conctactless devices, according to a recent conference to discuss RFID and other contactless transaction technologies.

nb : threatpost
Read More...

07/09/11

Solutions Now Available for Apache Killer

If you are a frequent reader of this blog, more or less you are already familiar with denial-of-service (DoS) attack. This attack typically targets a specific systems or servers and “floods” it with information in order to prevent legitimate users to access the information or service.

This time around, we have observed a DoS attack exploiting a specific vulnerability. This is different from the usual known methods for DoS. Denial-of-Service attacks are typically done by flooding the target site with traffic (SYN flood, UDP flood, ICMP flood). However, what makes this attack noteworthy is that it does not require a great amount of traffic. All the attacker has to do is send the especially-crafted HTTP request and the site will be rendered inaccessible.

We recently did a deeper analysis on the said vulnerability (CVE-2011-3192) found on certain versions of Apache HTTP Server that allows a remote attacker to conduct a denial-of-service attack by sending a small HTTP request.

The vulnerability exists in the byterange filter in Apache HTTP Server 1.3.x, 2.0.x through 2.0.64 and 2.2.x through 2.2.19. It can be exploited by a range header that expresses multiple overlapping ranges. The proof-of-concept for the exploit abusing this vulnerability was published in August. A tool that conducts DoS attacks by exploiting this vulnerability was later created, and dubbed as “Apache Killer”. Apache already patched this security hole last week.

A typical attack scenario exploiting this vulnerability involves the attacker sending an HTTP request with multiple range:bytes header to the Apache server.


Once the server receives the said request, it will create each bucket as a number of crafted range:bytes HTTP header items and insert bucket to bucket brigade. This will cause heightened memory consumption, and eventually, denial-of-service.


Web administrators using Apache HTTP Server are advised to apply the patch as soon as possible. And while patch management for vulnerability remediation can be a painful exercise for IT departments, Trend Micro Deep Security shields systems from threats that may leverage vulnerabilities in systems until a patch is available and deployed. Trend Micro provides protection against threats leveraging on this vulnerability through Deep Security, specifically rule VSU11-026 (1004782 – Apache httpd Range Header Remote Denial Of Service).

nb : trendmicro Read More...

03/09/11

Anonymous claims hack of Texas police website

The group has released controversial email said to have been sent by Texas police officers

Anonymous has attacked the website of the Texas Police Chiefs Association, in retaliation for the arrests of alleged members of the hacker group.

It said Thursday it had defaced the website, and leaked information that was classified as "law enforcement sensitive" and "for official use only". Among the leaked documents were also said to be some private emails from police officers, that had racist and sexist content.

[ Anonymous hackers also breached San Francisco's public transport site. | Master your security with InfoWorld's interactive Security iGuide. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

Anonymous also claimed in a message on Twitter that it had brought down the police website for over three hours. The site which was subsequently restored, and the defacement removed, was however defaced again late Thursday. "It seems they restored the website somehow without removing the backdoors," Anonymous said in a Twitter message.

The Texas Police Chiefs Association did not respond to a request by email for comment.

Separately, Anonymous claimed it had taken down the website of the United States Courts for the Ninth Circuit on Thursday, as justice argues that "civil disobedience is cyber-terrorism".

The Antisec operation by the hacker group and affiliates is protesting the arrest of people suspected to be its members, including Topiary, the person regarded as the spokesman of Anonymous and another group called LulzSec. Jake Davis, the person suspected to be Topiary, was arrested in July in the U.K. and charged with conspiring with others to conduct DDOS (distributed denial-of-service) attacks against the website of the Serious Organised Crime Agency (SOCA), a British law enforcement institution.

Police in the U.K. said Thursday they had charged two more persons in connection with investigations into online attacks, according to reports. Two others were also charged earlier this week, according to the Metropolitan Police.

Anonymous has been involved in a number of attacks on the websites of U.S. law enforcement agencies and defense contractors, and also government websites in Malaysia, Turkey, and Brazil. Its Antisec program targets governments, law enforcement, and corporations.

 

Read More...

30/08/11

HTTP DDoS Attacks Still Reign Supreme

Despite the media’s love-affair with Anonymous style cyber-anarchy and vigilante-hacktivism, the vast majority of DDoS attacks are carried out by criminals seeking financial gain, not activists, according to a new research report.

The top four targets of DDoS attacks in the second quarter were online shopping, gaming, stock exchange and banking sites, in that order, accounting for 69 percent of all DDoS attacks, according to the report on botnet activity from Kaspersky Lab. As for the “hacktivism” that’s gotten a lot of coverage lately, the bottom four spots on the list (excluding the one percent designated ‘other’) are transport, other business related and government sites respectively, accounting for a mere seven percent of attacks.

That said, the new report only accounts for botnet-driven attacks. Those popularized by Anonymous, which use the Low Orbit Ion Cannon (LOIC) DDoS tool, are not accounted for in this report.

Alarmingly, attacks on ‘blogs and forums’ and the ‘mass media’ accounted for eight percent and seven percent respectively, perhaps evidence of individuals and groups launching DDoS attacks in order to silence media channels, or more broadly, opinions with which they disagree.

On an interesting note, the analysis found that Tuesday is the most popular day of the week to launch a DDoS attack (closely followed by Wednesday, Monday and Thursday, in that order). Sunday is the least popular day to launch such attacks, Friday the second least and Saturday the third least popular. Also interesting is the author’s belief that as the summer holiday season comes to an end, more zombie machines will come back into use, making DDoS attacks all the more potent.

Seventy-two percent of attacks were aimed at IP addresses rather than specific domains.

HTTP flood attacks where massive amounts of HTTP requests are sent to targeted site in a short period of time, crippling the site, remain, by far, the most popular method of DDoSing. Read More...