Home|Contact us|RSS | Search
 
   

 
   
   
 
Home Security Center MCRC Blog 2008
          
Security Center
Overview
Latest Web Vulnerabilities
“In the Wild” Audit Results
URL Analysis
Info Center
Malicious Page of the Month
Test Your Vital Security Policy
Code Obfuscation
Glossary
MCRC Blog

MCRC Blog - 2008

Attacker toolkits for free

During our ongoing research we came up against one curious site. The site is hacking/security oriented, and is written in Russian (hmm... last time i've cheked it was in Netherlands), and not significantly different from many other similar sites.

Crimeware server catering to “grab and run” criminals

During our research for the latest Malicious Page of the Month that has just released, we came across a domain that was being used as a command and control for the Crimeware that was executed on attacked machines. This domain was also used as the “drop site” for private information being harvested by that Crimeware.

New neosploit - without MDAC :)

There are some things in common to most of the attack toolkit, one of which is exploit against the MDAC vulnerability (patched in 2006), MDAC is also in many cases the first exploit the attacker is trying to use.

On the (dis)merits of privacy

Following up on my last post, after filing a complaint with the abuse department of privacyprotect.org (and blogging about the problem), I have just received an update noting that:

Taking down a malicious site - the good, the bad, and the ugly...

As part of the “closure” on the February Malicious Page of the Month, which involved meoryprof.info (taken down), and spywaresafe.net we have contacted the appropriate parties in order to notify them that these websites contain malicious code.

About window of vulnerability (and MS08-017)

We here at the MCRC conduct independent vulnerabilities research once in a while, in order to provide our customers the best protection we can offer. The last MS security update included fixes for 2 vulnerabilities in the MS Office Web Component that we have discovered, one of which (CVE-2007-1201) was reported to Microsoft two years ago (!!). This means a 2 year long window of vulnerability. Needless to say, Finjan customers have been protected for the last 2 years against exploitation of this vulnerability, even at times when this vulnerability has been used in the wild with no patch available.

Optimizing Cross Site Scripting - and general security practices

We have been working recently on a XSS attack that impacted a huge number of potential victims, as the attack itself has been “optimized” by SEO (Seacrh Engine Optimization) practices that pushed it to Google’s indexes.

From 0day PoC to attack

I’m not about to discuss the pros/cons regarding full disclosure, just to show an amusing example of it: A 0day vulnerability was discovered in “Rising” – a Chinese AV product (insecure method vulnerability) and a PoC was published at milw0rm.com. Today we found a site trying to exploit the vulnerability, but the funny thing is, it used the PoC as is (changing only the payload URL, and using obfuscation to hide it) leaving the original function name (test ) and “GO !” button to trigger it (e.g. the exploit will only run once the user clicks the “GO !” button ). Needless to say, the exploit is served as a hidden IFrame so the user won’t even see the button.

Crimeware server and the international man of mystery

While conducting research for the latest Malicious Page of the Month we have just released, we tried to track down the origins of the crimeware.

NeoSploit V.2.0.15 - and behind the scenes

As part of our on-going research we had the chance to “meet in person“ some parts of the server side operations behind the new version of the NeoSpolit toolkit.

The impact of just 5 random letters...

We have been watching in amazement what kind of impact our latest Malicious Page of the Month have had on the industry and media.

And the winner for "top virus" of 2007 is...

Not a virus. Not even a malware. Neither is the runner up... It's the method of how malware is populated.

Archive

2008
2007

 
 
 
  © Copyright 1996 - 2008. Finjan Inc. and its affiliates and subsidiaries. All rights reserved.       Privacy Policy