Some news, views and musing about things going on in the Information Security World.
Showing posts with label trojan. Show all posts
Showing posts with label trojan. Show all posts
Monday, May 14, 2012
Microsoft Causes OSX Vulnerability, Then Gloats
Microsoft discovered a vulnerability in Word that could allow an attacker to execute code on any system using Microsoft Word to read a specially malformed document, then spins it to say it is proof that Macs are just as vulnerable as Windows to document-based attacks.
Key Words:
0-day,
computer viruses,
hacking,
microsoft,
security controls,
trojan
Friday, March 16, 2012
Anyone can say they are part of Anonymous... unless it makes them look bad
Anonymous likes to say that anyone can be a member just by saying they are. But apparently anyone creating malware while claiming to be part of Anonymous are officially *not* part of Anonymous. Unless of course it is malware written by other members of Anonymous. This is bizarre circular thinking for folks who have been known to be far more clever in the past. What gives?
Key Words:
0-day,
Anonymous,
computer viruses,
hacking,
security controls,
social engineering,
trojan
Thursday, September 8, 2011
Award BIOS Flashing Trojan
I used to talk about the possibility of a virus or worm writing boot code on hard drives, or flashing devices with new configurations, or even entirely new code. It seems there is now a trojan out there that does just that. Yes the site is in Chinese. But it describes a trojan that flashes Award BIOS code to add a few new functions on bootup.
Symantec has more details on how it infects the hard drive Master Boot Record (MBR) and specifically targets and alters the Award BIOS. Other BIOS brands are not affected.
Symantec has more details on how it infects the hard drive Master Boot Record (MBR) and specifically targets and alters the Award BIOS. Other BIOS brands are not affected.
Key Words:
0-day,
computer viruses,
security controls,
trojan
Thursday, August 25, 2011
Ten years later, still the same malware?
At Blackhat2011 during an interview about ESET'S recent Global Threat Report, a reporter asked me why we still see very old strains of common, long-detected malware. After all, haven't we detected these threats in the wild for years by now?
Key Words:
0-day,
computer viruses,
hacking,
security controls,
trojan
Wednesday, June 29, 2011
The Navy Bought Fake Trojanized Chinese Microchips
The Navy Bought Fake Trojanized Chinese Microchips. They weren't only low-quality fakes, they had been made with a "back-door" and could have been remotely shut down at any time. If left undiscovered the result could have rendered useless U.S. missiles and killed the signal from aircraft that tells everyone whether it's friend or foe.
The problem remains with these "trojan-horse" circuits that can be built into the chip and are almost impossible to detect -- especially without the original plans to compare them to.
The Intelligence Advanced Research Projects Agency (IARPA) is now looking for ways to check the chips to make sure they haven't been hacked in the production process.
The problem remains with these "trojan-horse" circuits that can be built into the chip and are almost impossible to detect -- especially without the original plans to compare them to.
The Intelligence Advanced Research Projects Agency (IARPA) is now looking for ways to check the chips to make sure they haven't been hacked in the production process.
Key Words:
0-day,
data destruction,
hacking,
physical security,
security controls,
spying,
terrorism,
trojan
Tuesday, June 28, 2011
Old Style MBR Viruses are Back
Microsoft is telling Windows users that they'll have to reinstall the operating system if they get infected with a new rootkit that hides in the machine's boot sector.
A new variant of a Trojan Microsoft calls "Popureb" digs so deeply into the system that the only way to eradicate it is to return Windows to its out-of-the-box configuration, Chun Feng, an engineer with the Microsoft Malware Protection Center (MMPC), said last week on the group's blog.
If this reminds you of the 80's, it should. At least back then you could boot to your DOS rescue disk and type FDISK /MBR to get rid of boot sector viruses. Now that there is too much money to be made off of viruses, I'm sure this command no longer works.
A new variant of a Trojan Microsoft calls "Popureb" digs so deeply into the system that the only way to eradicate it is to return Windows to its out-of-the-box configuration, Chun Feng, an engineer with the Microsoft Malware Protection Center (MMPC), said last week on the group's blog.
If this reminds you of the 80's, it should. At least back then you could boot to your DOS rescue disk and type FDISK /MBR to get rid of boot sector viruses. Now that there is too much money to be made off of viruses, I'm sure this command no longer works.
Key Words:
0-day,
computer viruses,
security controls,
trojan
Monday, June 20, 2011
Japan Criminalizes Creation, Acquisition or Storage of Computer Viruses
A new law in Japan makes creation or distribution of a computer virus without reasonable cause punishable by up to three years in prison, and acquisition or storage of a virus punishable by up to two years.
I am not sure how stringent their definition of "reasonable cause" is in this case, but it sounds like a good start.
I am not sure how stringent their definition of "reasonable cause" is in this case, but it sounds like a good start.
Key Words:
0-day,
computer viruses,
hacking,
security controls,
trojan
Thursday, June 2, 2011
Hackers stole secret Canadian government data
Hackers who attacked two of Canada's federal departments stole classified information before being discovered last January.
Hackers sent malicious emails to staff that appeared to be coming from senior managers. When staff opened the attachments, hackers found a path into the federal network, providing access to classified information.
The linked article contains a chronology of the attack.
Hackers sent malicious emails to staff that appeared to be coming from senior managers. When staff opened the attachments, hackers found a path into the federal network, providing access to classified information.
The linked article contains a chronology of the attack.
Tuesday, February 22, 2011
Why Penetration Testers Need To Remember The Good Old Days
As a penetration test trainer to fortune 500 companies, I often see a few students in the class phase out and stare off with glossy-eyed disinterest when I cover legacy systems and protocols. Examples of these "boring" topics include Windows NT, WEP, and ancient attacks like the 'Ping of Death'. They ask me "Why do we need to learn this stuff when it was fixed years ago?"
The answer is simple: History repeats itself. Just like these students aren't interested in learning from the past, there is a world of developers out there that exhibit the same disinterest. They're churning out vulnerable code with all kinds of old-school vulnerabilities, and the testers, having also slept through that part of the class, barely know how to detect them.
A subject I almost never see covered in Penetration Test / Hacking type courses in general, is the lowly modem. The rationale seems to be that modems are rarely used within the corporate environment, and when they are, a VPN is deployed. VPN security is well understood, and most (definitely not all) companies that use VPN do utilize them reasonably well. But the VPN does not cover all the layers. The modem is still just as vulnerable to attack as always.
To demonstrate why ignoring technical pieces of our computing legacy is tragic, one just has to look at a recent case in New Hampshire. Asu Pala resurrected an ancient idea: use malware to reconfigure modems to dial through a premium rate service.
The damage? In the nearly 5 years his attack ran, Pala made himself a neat $8 million.
The fact is, old equipment and operating systems abound on the Internet, and they nearly always can be found even within organizations who push policies on eradicating them. On top of that, younger developers who do not know their security history tend to repeat the mistakes that were made before their time.
0-day attacks nearly always have some relationship to the old attacks that we like to think don't occur anymore. Penetration testers who are not acquainted with the legacy security issues are likely to be blind to them when they occur.
The answer is simple: History repeats itself. Just like these students aren't interested in learning from the past, there is a world of developers out there that exhibit the same disinterest. They're churning out vulnerable code with all kinds of old-school vulnerabilities, and the testers, having also slept through that part of the class, barely know how to detect them.
A subject I almost never see covered in Penetration Test / Hacking type courses in general, is the lowly modem. The rationale seems to be that modems are rarely used within the corporate environment, and when they are, a VPN is deployed. VPN security is well understood, and most (definitely not all) companies that use VPN do utilize them reasonably well. But the VPN does not cover all the layers. The modem is still just as vulnerable to attack as always.
To demonstrate why ignoring technical pieces of our computing legacy is tragic, one just has to look at a recent case in New Hampshire. Asu Pala resurrected an ancient idea: use malware to reconfigure modems to dial through a premium rate service.
The damage? In the nearly 5 years his attack ran, Pala made himself a neat $8 million.
The fact is, old equipment and operating systems abound on the Internet, and they nearly always can be found even within organizations who push policies on eradicating them. On top of that, younger developers who do not know their security history tend to repeat the mistakes that were made before their time.
0-day attacks nearly always have some relationship to the old attacks that we like to think don't occur anymore. Penetration testers who are not acquainted with the legacy security issues are likely to be blind to them when they occur.
Key Words:
0-day,
computer viruses,
hacking,
physical security,
policy,
security controls,
social engineering,
trojan
Friday, October 22, 2010
Man In The Browser (MITB) Attacks
A new botnet named Feodo has been discovered. It doesn't seem to have much new about its internal workings, but the linked article gives a good description of how Man In The Browser attacks work.
Feodo rewrites specific banking app web pages in order to add input fields, such as PIN numbers and other personal information, that the bank wouldn't normally request on the unmodified version of the page.
Feodo rewrites specific banking app web pages in order to add input fields, such as PIN numbers and other personal information, that the bank wouldn't normally request on the unmodified version of the page.
Key Words:
0-day,
credit card fraud,
hacking,
security controls,
trojan
Tuesday, October 5, 2010
Antivirus Companies Finally Do Something About Their Own Website Security
In an industry where security companies have gotten rich enough to practice what they preach, you'd expect them to be setting the example when it comes to secure coding practices. It's the age old story about the cobbler's kids wearing crappy shoes.
You would expect security companies to hire coders that have at least a basic knowledge to do their jobs securely. How is it that so many such company websites would be afflicted with something as blatant as Cross-Site Scripting flaws? What makes this worse is that some of these companies offer secure web hosting, and post bulletins about other company's security issues! Someone isn't doing their homework.
Some of the companies that should know better: Symantec, Eset, and Panda.
You would expect security companies to hire coders that have at least a basic knowledge to do their jobs securely. How is it that so many such company websites would be afflicted with something as blatant as Cross-Site Scripting flaws? What makes this worse is that some of these companies offer secure web hosting, and post bulletins about other company's security issues! Someone isn't doing their homework.
Some of the companies that should know better: Symantec, Eset, and Panda.
Key Words:
0-day,
computer viruses,
hacking,
microsoft,
security controls,
trojan
Friday, October 1, 2010
Tired of the crap "news" websites are posting about Stuxnet?
F-Secure has posted a bit of a FAQ to help people interested in understanding the Stuxnet worm issue to get more realistic information, versus the omg-CNN-style garbage that has been going around so far.
Is it targeting Iranian nuclear plants? We don't know.
All this conjecture reminds me of the days when hundreds of STONED virus variants were running rampant, and McAfee started pretending they were totally different, and gave them fancy names just to make them sound like different beasts. (for example, Michelangelo). The same virus, with 2 or 3 lines changed suddenly became a totally amazing technological advance hell bent on the worse possible destruction. Just sayin...
Is it targeting Iranian nuclear plants? We don't know.
All this conjecture reminds me of the days when hundreds of STONED virus variants were running rampant, and McAfee started pretending they were totally different, and gave them fancy names just to make them sound like different beasts. (for example, Michelangelo). The same virus, with 2 or 3 lines changed suddenly became a totally amazing technological advance hell bent on the worse possible destruction. Just sayin...
Key Words:
0-day,
computer viruses,
physical security,
security controls,
spying,
terrorism,
trojan
Friday, September 24, 2010
First Worm To Deliberately Attack SCADA Systems Found
In June, Belarus antivirus company VirusBlokAda reported a new bug with some interesting features. The Stuxnet worm they discovered was programmed to specifically attack industrial control systems, and reprogram the controllers to hide the changes from view using a methods almost identical to those used in 1980's - 90's stealth viruses.
The last time someone hacked up a SCADA system like this, it caused a 3 kiloton explosion that was reported as having been the most monumental non-nuclear explosion and fire ever seen from space.
The last time someone hacked up a SCADA system like this, it caused a 3 kiloton explosion that was reported as having been the most monumental non-nuclear explosion and fire ever seen from space.
Key Words:
0-day,
computer viruses,
data destruction,
hacking,
microsoft,
physical security,
security controls,
spying,
terrorism,
trojan
Thursday, September 9, 2010
Twittering Too Much?
The Register posted an article about a bug that could cause Internet Explorer to post tweets just by visiting a website like this one. Of course, since the exploit works by stealing the credentials of other active sessions in your browser, Chris' concept can be tweaked to access just about any site where people tend to stay logged in, such as facebook or gmail.
Of course, just about every other browser in existence has already fixed this bug.
Of course, just about every other browser in existence has already fixed this bug.
Key Words:
0-day,
hacking,
microsoft,
security controls,
trojan
Friday, July 30, 2010
Trojan Cell Phone Apps
First the iphone and now android phones have been center focus for trojan applications that collect personal data and send it off to some nefarious foreign server. One of the trojan apps is a simple desktop wallpaper manager.
Ever wondered why some companies have such strict policies about what you may or may not install on your company-issued cellphone?
Ever wondered why some companies have such strict policies about what you may or may not install on your company-issued cellphone?
Subscribe to:
Posts (Atom)