About Security Update 2011-003
http://support.apple.com/kb/HT4657
---------------------------------------------------------------------
This update adds detection [into File Quarantine] and removes all known variants of Mac Defender FakeAV.
In addition, Apple is enabling daily update checks for File Quarantine definitions, so Apple can quickly respond to future malware variants.
Will be interesting to see how long this can last...
Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Tuesday, May 31, 2011
Two Iraqi Nationals Indicted on Federal Terrorism Charges in Kentucky
http://www.justice.gov/opa/pr/2011/May/11-nsd-701.html
An Iraqi citizen who allegedly carried out numerous Improvised Explosive Device (IED) attacks against U.S. troops in Iraq and another Iraqi national alleged to have participated in the insurgency in Iraq have been arrested and indicted on federal terrorism charges in the Western District of Kentucky.
The arrests in Bowling Green, Ky., and the criminal complaints and indictment unsealed today were announced by Todd Hinnen, Acting Assistant Attorney General for National Security; David J. Hale, U.S. Attorney for the Western District of Kentucky; Elizabeth A. Fries, Special Agent in Charge of the FBI Louisville Division; and the members of the Louisville Joint Terrorism Task Force (JTTF).
Waad Ramadan Alwan, 30, and Mohanad Shareef Hammadi, 23, both former residents of Iraq who currently reside in Bowling Green, were charged in a 23-count indictment returned by a federal grand jury in Bowling Green on May 26, 2011. Alwan is charged with conspiracy to kill U.S. nationals abroad; conspiracy to use a weapon of mass destruction (explosives) against U.S. nationals abroad; distributing information on the manufacture and use of IEDs; attempting to provide material support to terrorists and to al-Qaeda in Iraq [AQI]; as well as conspiracy to transfer, possess and export Stinger missiles. Hammadi is charged with attempting to provide material support to terrorists and to al-Qaeda in Iraq, as well as conspiracy to transfer, possess and export Stinger missiles.
--------------------------------------------------------------------
According to J.M. Berger of Intelwire.com, both men arrested today in Kentucky were actually former insurgents, and both were approved to live in the U.S. under refugee status.
An Iraqi citizen who allegedly carried out numerous Improvised Explosive Device (IED) attacks against U.S. troops in Iraq and another Iraqi national alleged to have participated in the insurgency in Iraq have been arrested and indicted on federal terrorism charges in the Western District of Kentucky.
The arrests in Bowling Green, Ky., and the criminal complaints and indictment unsealed today were announced by Todd Hinnen, Acting Assistant Attorney General for National Security; David J. Hale, U.S. Attorney for the Western District of Kentucky; Elizabeth A. Fries, Special Agent in Charge of the FBI Louisville Division; and the members of the Louisville Joint Terrorism Task Force (JTTF).
Waad Ramadan Alwan, 30, and Mohanad Shareef Hammadi, 23, both former residents of Iraq who currently reside in Bowling Green, were charged in a 23-count indictment returned by a federal grand jury in Bowling Green on May 26, 2011. Alwan is charged with conspiracy to kill U.S. nationals abroad; conspiracy to use a weapon of mass destruction (explosives) against U.S. nationals abroad; distributing information on the manufacture and use of IEDs; attempting to provide material support to terrorists and to al-Qaeda in Iraq [AQI]; as well as conspiracy to transfer, possess and export Stinger missiles. Hammadi is charged with attempting to provide material support to terrorists and to al-Qaeda in Iraq, as well as conspiracy to transfer, possess and export Stinger missiles.
--------------------------------------------------------------------
According to J.M. Berger of Intelwire.com, both men arrested today in Kentucky were actually former insurgents, and both were approved to live in the U.S. under refugee status.
The Emergence of Open and Organized Pro-Government Cyber Attacks in the Middle East: The Case of the Syrian Electronic Army
http://www.infowar-monitor.net/2011/05/7349/
Introduction
Since the beginning of the popular uprisings and protests in the Middle East and North Africa, events in the region have been characterized by increased contestation in cyberspace among regime sympathizers, governments, and opposition movements. One component of this contestation is the tendency among governments and networks of citizens supportive of the state to use offensive computer network attacks. Such tactics are supplements to legal, regulatory, and other controls, and technical forms of Internet censorship.
For example, a group known as the Iranian Cyber Army has defaced Twitter and Iranian opposition websites. Also, Tunisian political activists and Yemeni oppositional websites have both accused their government security organizations of launching attacks on their sites in an attempt to silence their message and deny access to their content.
In this report, we document the activities of the Syrian Electronic Army, which appears to be a case of an open and organized pro-government computer attack group that is actively targeting political opposition and Western websites. Our aim is to assess to what extent we can find evidence of Syrian government assistance for the attack groups, and what the significance of the attacks themselves are for civil society and cyberspace contestation.
Overview
Syria has become the first Arab country to have a public Internet Army hosted on its national networks to openly launch cyber attacks on its enemies. The intensity and scope of the Syrian Electronic Army’s activities signal an interesting development in the Syrian pro-regime Internet arena: In addition to being one of the most repressive Internet censors in the region, the local media, some of which is government-run is apparently supporting the Army’s orchestrated aggressive efforts to attack, by means of website defacements and comment spamming, political opposition and Western websites.
The Syrian Electronic Army claims on its website that it was founded by a team of young Syrian enthusiasts who did not want to stay passive “towards the fabrication of facts on the events in Syria.” Information Warfare Monitor (IWM) research found that the group has a connection with the Syrian Computer Society, which was headed in the 1990s by the current Syrian President Bashar al-Assad before he became president.
The Army has been attacking and defacing Syrian oppositional and “hostile Western news” websites. However, IWM found that some of the targeted Western websites are actually not news websites but rather non-political commercial websites. Although Facebook has been disabling the Army’s Facebook pages, the Army has been creating alternative pages and has been actively spamming popular and political Facebook pages with highly repetitive and orchestrated pro-regime comments.
Introduction
Since the beginning of the popular uprisings and protests in the Middle East and North Africa, events in the region have been characterized by increased contestation in cyberspace among regime sympathizers, governments, and opposition movements. One component of this contestation is the tendency among governments and networks of citizens supportive of the state to use offensive computer network attacks. Such tactics are supplements to legal, regulatory, and other controls, and technical forms of Internet censorship.
For example, a group known as the Iranian Cyber Army has defaced Twitter and Iranian opposition websites. Also, Tunisian political activists and Yemeni oppositional websites have both accused their government security organizations of launching attacks on their sites in an attempt to silence their message and deny access to their content.
In this report, we document the activities of the Syrian Electronic Army, which appears to be a case of an open and organized pro-government computer attack group that is actively targeting political opposition and Western websites. Our aim is to assess to what extent we can find evidence of Syrian government assistance for the attack groups, and what the significance of the attacks themselves are for civil society and cyberspace contestation.
Overview
Syria has become the first Arab country to have a public Internet Army hosted on its national networks to openly launch cyber attacks on its enemies. The intensity and scope of the Syrian Electronic Army’s activities signal an interesting development in the Syrian pro-regime Internet arena: In addition to being one of the most repressive Internet censors in the region, the local media, some of which is government-run is apparently supporting the Army’s orchestrated aggressive efforts to attack, by means of website defacements and comment spamming, political opposition and Western websites.
The Syrian Electronic Army claims on its website that it was founded by a team of young Syrian enthusiasts who did not want to stay passive “towards the fabrication of facts on the events in Syria.” Information Warfare Monitor (IWM) research found that the group has a connection with the Syrian Computer Society, which was headed in the 1990s by the current Syrian President Bashar al-Assad before he became president.
The Army has been attacking and defacing Syrian oppositional and “hostile Western news” websites. However, IWM found that some of the targeted Western websites are actually not news websites but rather non-political commercial websites. Although Facebook has been disabling the Army’s Facebook pages, the Army has been creating alternative pages and has been actively spamming popular and political Facebook pages with highly repetitive and orchestrated pro-regime comments.
MMPC Threat Report: Cracking Open Qakbot
Via MMPC Blog -
Today, we’re releasing a Microsoft Malware Protection Center Threat Report on Qakbot as a follow-up to the recently-released Microsoft SIRv10 and our special report on Battling Botnets in late 2010. This report focuses on one botnet in particular, Qakbot. Qakbot is a backdoor that includes user-mode rootkit functionality to hide itself and also steal sensitive user data from infected machines.
In addition to some of the interesting traits of Qakbot, such as the areas of the world where it’s most prevalent and the types of computers it targets, we found one particular aspect to be quite interesting – where the Qakbot authors may have gotten some of their code.
We have long suspected that the Qakbot authors were taking code samples from the Internet and incorporating them into their malware as the family evolved. Recently, while reviewing some of the earliest samples of Qakbot, we found something interesting: NtIllusion debug strings.
[...]
NtIllusion is a rootkit that was first disclosed in an article within the underground security zine called Phrack in July of 2004. It includes functionality to hide processes, files, registry entries, and evidence of TCP/IP communication. It hooks several network communication APIs in order to steal POP3 and FTP passwords. This code still appears in Qakbot today.
You can read about this and more on Qakbot in our Threat Report:
http://go.microsoft.com/?linkid=9773832
-----------------------------------------------------------------------------------------------------------
Mila has posted details and access to several Qakbot/Pinkslipbot samples on her Contagio Malware Dump Blog.
Today, we’re releasing a Microsoft Malware Protection Center Threat Report on Qakbot as a follow-up to the recently-released Microsoft SIRv10 and our special report on Battling Botnets in late 2010. This report focuses on one botnet in particular, Qakbot. Qakbot is a backdoor that includes user-mode rootkit functionality to hide itself and also steal sensitive user data from infected machines.
In addition to some of the interesting traits of Qakbot, such as the areas of the world where it’s most prevalent and the types of computers it targets, we found one particular aspect to be quite interesting – where the Qakbot authors may have gotten some of their code.
We have long suspected that the Qakbot authors were taking code samples from the Internet and incorporating them into their malware as the family evolved. Recently, while reviewing some of the earliest samples of Qakbot, we found something interesting: NtIllusion debug strings.
[...]
NtIllusion is a rootkit that was first disclosed in an article within the underground security zine called Phrack in July of 2004. It includes functionality to hide processes, files, registry entries, and evidence of TCP/IP communication. It hooks several network communication APIs in order to steal POP3 and FTP passwords. This code still appears in Qakbot today.
You can read about this and more on Qakbot in our Threat Report:
http://go.microsoft.com/?linkid=9773832
-----------------------------------------------------------------------------------------------------------
Mila has posted details and access to several Qakbot/Pinkslipbot samples on her Contagio Malware Dump Blog.
Thursday, May 26, 2011
DNS Filtering Legislation Would Derail DNSSEC, Experts Contend
Via DarkReading.com -
A key provision in an intellectual property protection bill that was approved today by the Senate Judiciary Committee could sabotage Internet security and specifically, DNSSEC, according to a who's who of Internet infrastructure and security experts including Dan Kaminsky.
The PROTECT (Preventing Real Online Threats to Economic Creativity and Theft of Intellectual Property Act) IP Act calls for using recursive DNS servers to blacklist and block domain names of servers offering pirated music or other illegally obtained intellectual property. A group of renowned Internet security experts including Kaminsky released a white paper explaining how forcing these millions of recursive servers on the Internet to filter out DNS requests to those sites would basically cripple the emerging DNSSEC technology. DNSSEC is currently in the process of being adopted on the Internet; it provides verification that the site a user visits is indeed that site and not a spoofed or redirected one.
Along with Kaminsky, who discovered and helped get patched a serious flaw in DNS, the authors of the paper include Steve Crocker, an IETF pioneer and CEO of Shinkuro; David Dagon, a post-doctoral researcher at Georgia Institute of Technology studying DNS security and a co-founder of Damballa; Danny McPherson, chief security officer for Verisign; and Paul Vixie, principal author of the pervasive BIND DNS server software and creator of several DNS standards.
The authors say they support enforcement intellectual property rights, but that the DNS filtering requirement would stymie federal government and private industry efforts for beefing up Internet security -- namely DNSSEC. And the filters could easily be bypassed and therefore would likely be unable to quell online copyright infringement, they say.
"It's like trying to make a telephone that won't carry swear words," Kaminsky says of the DNS-filtering approach.
They maintain that the DNS filtering—which would force the censoring of websites via blacklists published by the Department of Justice--would clash with DNSSEC by encouraging the brand of network manipulation that DNSSEC aims to prevent.
[...]
A full copy of the "Security and Other Technical Concerns Raised by the DNS Filtering Requirements in the PROTECT IP Bill" is available here for download.
A key provision in an intellectual property protection bill that was approved today by the Senate Judiciary Committee could sabotage Internet security and specifically, DNSSEC, according to a who's who of Internet infrastructure and security experts including Dan Kaminsky.
The PROTECT (Preventing Real Online Threats to Economic Creativity and Theft of Intellectual Property Act) IP Act calls for using recursive DNS servers to blacklist and block domain names of servers offering pirated music or other illegally obtained intellectual property. A group of renowned Internet security experts including Kaminsky released a white paper explaining how forcing these millions of recursive servers on the Internet to filter out DNS requests to those sites would basically cripple the emerging DNSSEC technology. DNSSEC is currently in the process of being adopted on the Internet; it provides verification that the site a user visits is indeed that site and not a spoofed or redirected one.
Along with Kaminsky, who discovered and helped get patched a serious flaw in DNS, the authors of the paper include Steve Crocker, an IETF pioneer and CEO of Shinkuro; David Dagon, a post-doctoral researcher at Georgia Institute of Technology studying DNS security and a co-founder of Damballa; Danny McPherson, chief security officer for Verisign; and Paul Vixie, principal author of the pervasive BIND DNS server software and creator of several DNS standards.
The authors say they support enforcement intellectual property rights, but that the DNS filtering requirement would stymie federal government and private industry efforts for beefing up Internet security -- namely DNSSEC. And the filters could easily be bypassed and therefore would likely be unable to quell online copyright infringement, they say.
"It's like trying to make a telephone that won't carry swear words," Kaminsky says of the DNS-filtering approach.
They maintain that the DNS filtering—which would force the censoring of websites via blacklists published by the Department of Justice--would clash with DNSSEC by encouraging the brand of network manipulation that DNSSEC aims to prevent.
[...]
A full copy of the "Security and Other Technical Concerns Raised by the DNS Filtering Requirements in the PROTECT IP Bill" is available here for download.
Wednesday, May 25, 2011
NASA Says Goodbye to Spirit Mars Rover
Via discovermagazine.com (Bad Astronomy Blog) -
After nearly a year of trying to reestablish communications with the Spirit Mars rover, NASA has decided to suspend efforts. For all intent and purpose, Spirit is dead.
The rover sent its last message in March of 2010, and it was hoped that as Martian summer dawned at Spirit’s location, the solar cells might absorb enough energy to reawaken the plucky explorer. However, repeated attempts over several months have yielded no joy. And now, just months away from the launch of the much more ambitious "Curiosity" Mars Science Laboratory (MSL) — a golfcart-sized rover with better range and instrumentation than any previous mission — communications satellites and Mars orbiters NASA uses to work with Spirit need to be transitioned to MSL.
This makes me sad, of course: Spirit was an amazing machine. But I have to admit, that sadness is offset by the incredible accomplishments of the rover. Designed to last for three months, Spirit kept on roving for over six years. Imagine having a car, a computer, that lasted for 25 times the warranty!
Or living to be 1500 years old. How much could you accomplish in that time?
Spirit’s made good use of its lifespan.
-------------------------------------------------------------------------------
Sad to see Spirit go, but its twin, Opportunity, continues active exploration of Mars - http://marsrover.nasa.gov/mission/status.html
R.I.P Spirit, Long Live Opportunity!
After nearly a year of trying to reestablish communications with the Spirit Mars rover, NASA has decided to suspend efforts. For all intent and purpose, Spirit is dead.
The rover sent its last message in March of 2010, and it was hoped that as Martian summer dawned at Spirit’s location, the solar cells might absorb enough energy to reawaken the plucky explorer. However, repeated attempts over several months have yielded no joy. And now, just months away from the launch of the much more ambitious "Curiosity" Mars Science Laboratory (MSL) — a golfcart-sized rover with better range and instrumentation than any previous mission — communications satellites and Mars orbiters NASA uses to work with Spirit need to be transitioned to MSL.
This makes me sad, of course: Spirit was an amazing machine. But I have to admit, that sadness is offset by the incredible accomplishments of the rover. Designed to last for three months, Spirit kept on roving for over six years. Imagine having a car, a computer, that lasted for 25 times the warranty!
Or living to be 1500 years old. How much could you accomplish in that time?
Spirit’s made good use of its lifespan.
-------------------------------------------------------------------------------
Sad to see Spirit go, but its twin, Opportunity, continues active exploration of Mars - http://marsrover.nasa.gov/mission/status.html
R.I.P Spirit, Long Live Opportunity!
Tuesday, May 24, 2011
Apple Support: How to Avoid or Remove Mac Defender Malware
http://support.apple.com/kb/HT4650
Summary
A recent phishing scam has targeted Mac users by redirecting them from legitimate websites to fake websites which tell them that their computer is infected with a virus. The user is then offered Mac Defender "anti-virus" software to solve the issue.
This “anti-virus” software is malware (i.e. malicious software). Its ultimate goal is to get the user's credit card information which may be used for fraudulent purposes.
The most common names for this malware are MacDefender, MacProtector and MacSecurity.
In the coming days, Apple will deliver a Mac OS X software update that will automatically find and remove Mac Defender malware and its known variants. The update will also help protect users by providing an explicit warning if they download this malware.
In the meantime, the Resolution section below provides step-by-step instructions on how to avoid or manually remove this malware.
-----------------------------------------------------------------------------
Sadly, Apple doesn't recommend disabling the "Open Safe Files After Downloading" feature in Safari. But you should as a practical defense-in-depth measure...
How To Disable "Open Safe Files After Downloading" Feature In Safari
http://browsers.about.com/od/safar1/ht/safarisafefiles.htm
Or you can just use Google Chrome on OSX, which is my suggestion.
Summary
A recent phishing scam has targeted Mac users by redirecting them from legitimate websites to fake websites which tell them that their computer is infected with a virus. The user is then offered Mac Defender "anti-virus" software to solve the issue.
This “anti-virus” software is malware (i.e. malicious software). Its ultimate goal is to get the user's credit card information which may be used for fraudulent purposes.
The most common names for this malware are MacDefender, MacProtector and MacSecurity.
In the coming days, Apple will deliver a Mac OS X software update that will automatically find and remove Mac Defender malware and its known variants. The update will also help protect users by providing an explicit warning if they download this malware.
In the meantime, the Resolution section below provides step-by-step instructions on how to avoid or manually remove this malware.
-----------------------------------------------------------------------------
Sadly, Apple doesn't recommend disabling the "Open Safe Files After Downloading" feature in Safari. But you should as a practical defense-in-depth measure...
How To Disable "Open Safe Files After Downloading" Feature In Safari
http://browsers.about.com/od/safar1/ht/safarisafefiles.htm
Or you can just use Google Chrome on OSX, which is my suggestion.
Monday, May 23, 2011
Targeted Attack: Trend Micro Researchers Identify Vulnerability in Hotmail
Via Trend Micro Blog -
A couple of days ago, my colleagues reported an attack that appears to be targeted and that involves email messages sent through a Webmail service. Upon further investigation, we were able to confirm that this attack exploits a previously unpatched vulnerability in Hotmail. Trend Micro detects the malicious email messages as HTML_AGENT.SMJ.
The said attack simply requires the targeted user to open the specially crafted email message, which automatically executes the embedded script. This then leads to the theft of critical information, specifically email messages and information about the affected user’s personal contacts. The stolen email messages may contain sensitive information that cybercriminala can use for various malicious routines.
The script connects to http://www.{BLOCKED}eofpublic.com/Microsoft.MSN.hotmail/mail/rdm/rdm.asp?a={user account name}{number} to download yet another script.
The nature of the said URL strongly suggests that the attack is targeted. The URL contains two variables—{user account name}, which is the target user’s Hotmail ID, and {number}, which is a predefined number set by the attacker. The number seems to determine the malicious payload that will be executed, as we’ve found that the information theft routines are only executed when certain numbers are in the {number} field.
The URL leads to another script detected by Trend Micro as JS_AGENT.SMJ. The script triggers a request that is sent to the Hotmail server. The said request sends all of the affected user’s email messages to a certain email address. The email message forwarding, however, will only work during the session wherein the script was executed and will stop once the user logs off.
The attack takes advantage of a script or a CSS filtering mechanism bug in Hotmail. Microsoft has already taken action and has updated Hotmail to fix the said bug.
We analyzed the embedded crafted code before the actual email message’s content and discovered that once Hotmail’s filtering mechanism works on the code, it ironically helps inject a character into the CSS parameters to convert the script into two separate lines for further rendering in the Web browser’s CSS engine. This allows the cybercriminals to turn the script into something that allows them to run arbitrary commands in the current Hotmail login session.
[...]
Microsoft has already acknowledged the presence of the vulnerability and has released a security update to address the issue.
As Microsoft’s senior response communications manager Bryan Nairn mentioned, this illustrates Microsoft and Trend Micro’s continuous effort and shared commitment to protect customers via coordinated vulnerability disclosure.
A couple of days ago, my colleagues reported an attack that appears to be targeted and that involves email messages sent through a Webmail service. Upon further investigation, we were able to confirm that this attack exploits a previously unpatched vulnerability in Hotmail. Trend Micro detects the malicious email messages as HTML_AGENT.SMJ.
The said attack simply requires the targeted user to open the specially crafted email message, which automatically executes the embedded script. This then leads to the theft of critical information, specifically email messages and information about the affected user’s personal contacts. The stolen email messages may contain sensitive information that cybercriminala can use for various malicious routines.
The script connects to http://www.{BLOCKED}eofpublic.com/Microsoft.MSN.hotmail/mail/rdm/rdm.asp?a={user account name}{number} to download yet another script.
The nature of the said URL strongly suggests that the attack is targeted. The URL contains two variables—{user account name}, which is the target user’s Hotmail ID, and {number}, which is a predefined number set by the attacker. The number seems to determine the malicious payload that will be executed, as we’ve found that the information theft routines are only executed when certain numbers are in the {number} field.
The URL leads to another script detected by Trend Micro as JS_AGENT.SMJ. The script triggers a request that is sent to the Hotmail server. The said request sends all of the affected user’s email messages to a certain email address. The email message forwarding, however, will only work during the session wherein the script was executed and will stop once the user logs off.
The attack takes advantage of a script or a CSS filtering mechanism bug in Hotmail. Microsoft has already taken action and has updated Hotmail to fix the said bug.
We analyzed the embedded crafted code before the actual email message’s content and discovered that once Hotmail’s filtering mechanism works on the code, it ironically helps inject a character into the CSS parameters to convert the script into two separate lines for further rendering in the Web browser’s CSS engine. This allows the cybercriminals to turn the script into something that allows them to run arbitrary commands in the current Hotmail login session.
[...]
Microsoft has already acknowledged the presence of the vulnerability and has released a security update to address the issue.
As Microsoft’s senior response communications manager Bryan Nairn mentioned, this illustrates Microsoft and Trend Micro’s continuous effort and shared commitment to protect customers via coordinated vulnerability disclosure.
Tehrik-e-Taliban Pakistan: Who or what are they?
http://diis.dk/graphics/Publications/Reports2010/RP2010-12-Tehrik-e-Taliban_web.pdf
When regional and Western media report about terrorism in Pakistan, they frequently and indiscriminately use the labels of 'Pakistani Taliban' and 'Tehrik-e-Taliban Pakistan' (TPP). However, it remains unclear what is exactly meant by these catchall terms.
Qandeel Siddique in this DIIS Report unpacks the concept of who/what the Tehrik-e-Taliban is. The author discusses individual components of the TTP and the spread of 'talibanization' across Pakistan, and she makes an effort at understanding the organization's strength in terms of recruitment strategy, ideology and financial support. Special attention is given to the prevailing socio-economic conditions and the political history of Pakistan's north-western region as factors giving impetus to the TTP movement.
When regional and Western media report about terrorism in Pakistan, they frequently and indiscriminately use the labels of 'Pakistani Taliban' and 'Tehrik-e-Taliban Pakistan' (TPP). However, it remains unclear what is exactly meant by these catchall terms.
Qandeel Siddique in this DIIS Report unpacks the concept of who/what the Tehrik-e-Taliban is. The author discusses individual components of the TTP and the spread of 'talibanization' across Pakistan, and she makes an effort at understanding the organization's strength in terms of recruitment strategy, ideology and financial support. Special attention is given to the prevailing socio-economic conditions and the political history of Pakistan's north-western region as factors giving impetus to the TTP movement.
Targeted Attack: Norway Army Says Faced Cyber Attack After Libya Bombing
Via DefenseNews.com / AFP (May 19, 2011) -
The Norwegian military said May 19 that it had been the victim of a serious cyber attack at the end of March, a day after Norwegian F-16 fighter jets for the first time carried out bombings in Libya.
"The army is regularly the target of cyber and virus attacks, but not as extensive as this," Hilde Lindboe, a spokeswoman for Norwegian Defence Information Infrastructure (INI), told AFP.
On March 25, a day after Norwegian F-16s first took part in the NATO-led bombing in Libya, around 100 military employees, some of them high-ranking, received an email in Norwegian with an attachment that, once opened, let loose a virus made to extract information from the host computer.
"From what we have seen, no sensitive information has been obtained," Lindboe said.
According to INI, only one computer containing non-classified information was contaminated.
The Norwegian Police Security Service (PST) has opened an investigation to determine who launched the attack, but authorities say it is too soon to say whether there was a link to the Libya bombings.
--------------------------------------------------------------------------------
Sometimes it can be hard to determine if reports of targeted attacks are really targeted, but in this case...I think the fact that the e-mails were written in Norwegian and took aim at Norwegian army officials adds some serious creditable to calling it a “targeted attack”.
It would be interesting to know if the subject of the malicious e-mails or the malicious attachments directly referenced the new NATO campaign in Libya.
TrendMicro Threat Encyclopedia: Understanding Highly Targeted Attacks
http://about-threats.trendmicro.com/RelatedThreats.aspx?language=us&name=Understanding+Highly+Targeted+Attacks
The Norwegian military said May 19 that it had been the victim of a serious cyber attack at the end of March, a day after Norwegian F-16 fighter jets for the first time carried out bombings in Libya.
"The army is regularly the target of cyber and virus attacks, but not as extensive as this," Hilde Lindboe, a spokeswoman for Norwegian Defence Information Infrastructure (INI), told AFP.
On March 25, a day after Norwegian F-16s first took part in the NATO-led bombing in Libya, around 100 military employees, some of them high-ranking, received an email in Norwegian with an attachment that, once opened, let loose a virus made to extract information from the host computer.
"From what we have seen, no sensitive information has been obtained," Lindboe said.
According to INI, only one computer containing non-classified information was contaminated.
The Norwegian Police Security Service (PST) has opened an investigation to determine who launched the attack, but authorities say it is too soon to say whether there was a link to the Libya bombings.
--------------------------------------------------------------------------------
Sometimes it can be hard to determine if reports of targeted attacks are really targeted, but in this case...I think the fact that the e-mails were written in Norwegian and took aim at Norwegian army officials adds some serious creditable to calling it a “targeted attack”.
It would be interesting to know if the subject of the malicious e-mails or the malicious attachments directly referenced the new NATO campaign in Libya.
TrendMicro Threat Encyclopedia: Understanding Highly Targeted Attacks
http://about-threats.trendmicro.com/RelatedThreats.aspx?language=us&name=Understanding+Highly+Targeted+Attacks
Multiverse = Many Worlds, Say Physicists
Via The Physics arXiv Blog (MIT Technology Review) -
The many worlds interpretation of quantum mechanics is the idea that all possible alternate histories of the universe actually exist. At every point in time, the universe splits into a multitude of existences in which every possible outcome of each quantum process actually happens.
So in this universe you are sitting in front of your computer reading this story, in another you are reading a different story, in yet another you are about to be run over by a truck. In many, you don't exist at all.
This implies that there are an infinite number of universes, or at least a very large number of them.
That's weird but it is a small price to pay, say quantum physicists, for the sanity the many worlds interpretation brings to the otherwise crazy notion of quantum mechanics. The reason many physicists love the many worlds idea is that it explains away all the strange paradoxes of quantum mechanics.
[...]
Let's put the many world interpretation aside for a moment and look at another strange idea in modern physics. This is the idea that our universe was born along with a large, possibly infinite, number of other universes. So our cosmos is just one tiny corner of a much larger multiverse.
Today, Leonard Susskind at Stanford University in Palo Alto and Raphael Bousso at the University of California, Berkeley, put forward the idea that the multiverse and the many worlds interpretation of quantum mechanics are formally equivalent.
But there is a caveat. The equivalence only holds if both quantum mechanics and the multiverse take special forms.
[...]
At one time, such an idea would have been heresy. But in theory, it could be done if an observer could perform an infinite number of experiments and observe the outcome of them all.
But that's impossible, right? Nobody can do an infinite number of experiments. Relativity places an important practical limit on this because some experiments would fall outside the causal horizon of others. And that would mean that they couldn't all be observed.
But Susskind and Bousso say there is a special formulation of the universe in which this is possible. This is known as the supersymmetric multiverse with vanishing cosmological constant.
If the universe takes this form, then it is possible to carry out an infinite number of experiments within the causal horizon of each other.
Now here's the key point: this is exactly what happens in the many worlds interpretation. At each instant in time, an infinite (or very large) number of experiments take place within the causal horizon of each other. As observers, we are capable of seeing the outcome of any of these experiments but we actually follow only one.
Bousso and Susskind argue that since the many worlds interpretation is possible only in their supersymmetric multiverse, they must be equivalent. "We argue that the global multiverse is a representation of the many-worlds in a single geometry," they say.
They call this new idea the multiverse interpretation of quantum mechanics.
[...]
But what this idea lacks is a testable prediction that would help physicists distinguish it experimentally from other theories of the universe. And without this crucial element, the multiverse interpretation of quantum mechanics is little more than philosophy.
That may not worry too many physicists, since few of the other interpretations of quantum mechanics have testable predictions either (that's why they're called interpretations).
Still, what this new approach does have is a satisfying simplicity-- it's neat and elegant that the many worlds and the multiverse are equivalent. William of Ockham would certainly be pleased and no doubt, many modern physicists will be too.
The many worlds interpretation of quantum mechanics is the idea that all possible alternate histories of the universe actually exist. At every point in time, the universe splits into a multitude of existences in which every possible outcome of each quantum process actually happens.
So in this universe you are sitting in front of your computer reading this story, in another you are reading a different story, in yet another you are about to be run over by a truck. In many, you don't exist at all.
This implies that there are an infinite number of universes, or at least a very large number of them.
That's weird but it is a small price to pay, say quantum physicists, for the sanity the many worlds interpretation brings to the otherwise crazy notion of quantum mechanics. The reason many physicists love the many worlds idea is that it explains away all the strange paradoxes of quantum mechanics.
[...]
Let's put the many world interpretation aside for a moment and look at another strange idea in modern physics. This is the idea that our universe was born along with a large, possibly infinite, number of other universes. So our cosmos is just one tiny corner of a much larger multiverse.
Today, Leonard Susskind at Stanford University in Palo Alto and Raphael Bousso at the University of California, Berkeley, put forward the idea that the multiverse and the many worlds interpretation of quantum mechanics are formally equivalent.
But there is a caveat. The equivalence only holds if both quantum mechanics and the multiverse take special forms.
[...]
At one time, such an idea would have been heresy. But in theory, it could be done if an observer could perform an infinite number of experiments and observe the outcome of them all.
But that's impossible, right? Nobody can do an infinite number of experiments. Relativity places an important practical limit on this because some experiments would fall outside the causal horizon of others. And that would mean that they couldn't all be observed.
But Susskind and Bousso say there is a special formulation of the universe in which this is possible. This is known as the supersymmetric multiverse with vanishing cosmological constant.
If the universe takes this form, then it is possible to carry out an infinite number of experiments within the causal horizon of each other.
Now here's the key point: this is exactly what happens in the many worlds interpretation. At each instant in time, an infinite (or very large) number of experiments take place within the causal horizon of each other. As observers, we are capable of seeing the outcome of any of these experiments but we actually follow only one.
Bousso and Susskind argue that since the many worlds interpretation is possible only in their supersymmetric multiverse, they must be equivalent. "We argue that the global multiverse is a representation of the many-worlds in a single geometry," they say.
They call this new idea the multiverse interpretation of quantum mechanics.
[...]
But what this idea lacks is a testable prediction that would help physicists distinguish it experimentally from other theories of the universe. And without this crucial element, the multiverse interpretation of quantum mechanics is little more than philosophy.
That may not worry too many physicists, since few of the other interpretations of quantum mechanics have testable predictions either (that's why they're called interpretations).
Still, what this new approach does have is a satisfying simplicity-- it's neat and elegant that the many worlds and the multiverse are equivalent. William of Ockham would certainly be pleased and no doubt, many modern physicists will be too.
Friday, May 20, 2011
Sophos Whitepaper: What is ZeuS?
http://www.sophos.com/medialibrary/PDFs/technical%20papers/Sophos%20what%20is%20zeus%20tp.pdf
Abstract
Zeus or Zbot is one of the most notorious and widely-spread information stealing Trojans in existence. Zeus is primarily targeted at financial data theft; its effectiveness has lead to the loss of millions worldwide. The spectrum of those impacted by Zbot infections ranges from individuals who have had their banking details compromised, to large public order departments of prominent western governments.
We will explore the various components of the Zeus kit from the Builder through to the configuration file; examine in detail the functionality and behaviour of the Zbot binary; and assess emerging and future trends in the Zeus world.
Abstract
Zeus or Zbot is one of the most notorious and widely-spread information stealing Trojans in existence. Zeus is primarily targeted at financial data theft; its effectiveness has lead to the loss of millions worldwide. The spectrum of those impacted by Zbot infections ranges from individuals who have had their banking details compromised, to large public order departments of prominent western governments.
We will explore the various components of the Zeus kit from the Builder through to the configuration file; examine in detail the functionality and behaviour of the Zbot binary; and assess emerging and future trends in the Zeus world.
Symantec - W32.Qakbot in Detail
http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_qakbot_in_detail.pdf
Background
W32.Qakbot is a worm that has been seen spreading through network shares, removable drives, and infected webpages, and infecting com- puters since mid-2009. Its primary purpose is to steal online bank- ing account information from compromised computers. The malware controllers use the stolen information to access client accounts within various financial service websites with the intent of moving currency to accounts from which they can withdraw funds. It employs a classic key- logger, but is unique in that it also steals active session authentication tokens and then piggy backs on the existing online banking sessions. It then quickly uses that information for malicious purposes.
In-field telemetry shows that the malware authors have gotten more and more aggressive and successful in their ability to infect the com- mon client. Even though we don’t have evidence to show the increase in monetary gain made by malware controllers, we do believe the in-field propagation is directly proportional to the loss incurred by banks and end clients.
There are several information stealing Trojans found in cyberspace to- day. What makes Qakbot stand apart from most of the others is sophis- tication and continuous evolution. The purpose of this white paper is to provide an insight into the worm’s capabilities.
-----------------------------------------------------------------------------------------------------
Qakbot has been gaining some press recently, especially with this recent outbreak in April at Massachusetts Department of Unemployment Assistance and Department of Career Services.
For more information on Qakbot, check out this RSA paper from Oct 2010.
Businesses Beware: Qakbot is No Laughing Matter [PDF]
Background
W32.Qakbot is a worm that has been seen spreading through network shares, removable drives, and infected webpages, and infecting com- puters since mid-2009. Its primary purpose is to steal online bank- ing account information from compromised computers. The malware controllers use the stolen information to access client accounts within various financial service websites with the intent of moving currency to accounts from which they can withdraw funds. It employs a classic key- logger, but is unique in that it also steals active session authentication tokens and then piggy backs on the existing online banking sessions. It then quickly uses that information for malicious purposes.
In-field telemetry shows that the malware authors have gotten more and more aggressive and successful in their ability to infect the com- mon client. Even though we don’t have evidence to show the increase in monetary gain made by malware controllers, we do believe the in-field propagation is directly proportional to the loss incurred by banks and end clients.
There are several information stealing Trojans found in cyberspace to- day. What makes Qakbot stand apart from most of the others is sophis- tication and continuous evolution. The purpose of this white paper is to provide an insight into the worm’s capabilities.
-----------------------------------------------------------------------------------------------------
Qakbot has been gaining some press recently, especially with this recent outbreak in April at Massachusetts Department of Unemployment Assistance and Department of Career Services.
For more information on Qakbot, check out this RSA paper from Oct 2010.
Businesses Beware: Qakbot is No Laughing Matter [PDF]
Panetta Warns CIA Employees Against Bin Laden Leaks
Via Washington Post -
CIA Director Leon E. Panetta warned agency employees not to reveal secrets about the raid on Osama bin Laden’s compound earlier this month, saying in a memo sent to employees Wednesday that disclosures could jeopardize future operations.
"The intense public and media interest in the operation that killed Osama bin Laden has led to an unprecedented amount of very sensitive — in fact, classified — information making its way into the press," Panetta said, according to a copy of the memo obtained Thursday by The Washington Post.
Panetta’s message is part of a broader effort by the Obama administration to clamp down on disclosures surrounding the raid, as well as months of sensitive intelligence-gathering efforts that preceded it.
Senior Defense Department officials had conveyed a similar message in a news briefing Wednesday at the Pentagon. "We have talked far too much about this," said Adm. Mike Mullen, the chairman of the Joint Chiefs of Staff. "We need to move on."
[...]
In his note, Panetta warned that the agency will investigate leaks and that, "when warranted, referrals will be made to the Dept. of Justice." He also said CIA employees "have every reason to be proud of the bin Laden operation." Obama is scheduled to appear at CIA headquarters Friday to congratulate employees on the operation.
CIA Director Leon E. Panetta warned agency employees not to reveal secrets about the raid on Osama bin Laden’s compound earlier this month, saying in a memo sent to employees Wednesday that disclosures could jeopardize future operations.
"The intense public and media interest in the operation that killed Osama bin Laden has led to an unprecedented amount of very sensitive — in fact, classified — information making its way into the press," Panetta said, according to a copy of the memo obtained Thursday by The Washington Post.
Panetta’s message is part of a broader effort by the Obama administration to clamp down on disclosures surrounding the raid, as well as months of sensitive intelligence-gathering efforts that preceded it.
Senior Defense Department officials had conveyed a similar message in a news briefing Wednesday at the Pentagon. "We have talked far too much about this," said Adm. Mike Mullen, the chairman of the Joint Chiefs of Staff. "We need to move on."
[...]
In his note, Panetta warned that the agency will investigate leaks and that, "when warranted, referrals will be made to the Dept. of Justice." He also said CIA employees "have every reason to be proud of the bin Laden operation." Obama is scheduled to appear at CIA headquarters Friday to congratulate employees on the operation.
Russia Expels Israeli Military Attache for 'Industrial Espionage'
Via telegraph.co.uk -
In a scandal that risks souring traditionally good relations between the two countries, Russian security sources claimed that Air Force Colonel Vadim Leiderman, Israel's military attaché in Russia, had been caught "red-handed" receiving classified documents in Moscow last Thursday.
"This deals entirely with industrial espionage or rather his overly active work on behalf of certain Israeli companies on the Russian market," a Russian security source told the RIA Novosti news agency.
Col Leiderman was reportedly detained at a café where he was meeting a source from the Russian defence ministry and questioned for several hours before being told to leave the country within 48 hours.
Israel's Haaretz daily said the Soviet-born diplomat's expulsion was the first incident of its kind in almost two decades. Israeli officials insisted Col Leiderman had been questioned on his return and put through a lie-detector test, and that the allegations against him were "without foundation". According to claims in the Israeli media, Russia had attempted to recruit him as a double agent and grown angry when he refused.
In a scandal that risks souring traditionally good relations between the two countries, Russian security sources claimed that Air Force Colonel Vadim Leiderman, Israel's military attaché in Russia, had been caught "red-handed" receiving classified documents in Moscow last Thursday.
"This deals entirely with industrial espionage or rather his overly active work on behalf of certain Israeli companies on the Russian market," a Russian security source told the RIA Novosti news agency.
Col Leiderman was reportedly detained at a café where he was meeting a source from the Russian defence ministry and questioned for several hours before being told to leave the country within 48 hours.
Israel's Haaretz daily said the Soviet-born diplomat's expulsion was the first incident of its kind in almost two decades. Israeli officials insisted Col Leiderman had been questioned on his return and put through a lie-detector test, and that the allegations against him were "without foundation". According to claims in the Israeli media, Russia had attempted to recruit him as a double agent and grown angry when he refused.
New 64-Bit Rootkit Being Used to Steal Banking Credentials
Via Threatpost.com -
Security researchers have come across a new rootkit that is designed specifically to infect 64-bit Windows systems and steal users' online banking credentials. It's believed to be the first piece of malware of its kind that is capable of compromising x64 systems.
The new rootkit is being used by attackers in Brazil as part of drive-by download attacks and is then used to steal banking credentials after the infection. The malware has the ability to change some of the boot configurations of infected machines and then aims to redirect users to phishing sites. The new rootkit can infect machines running either 32-bit or 64-bit versions of Windows.
The drive-by download is accomplished by using a malicious Java applet that is targeted at older versions of the Java Runtime Environment. The applet includes a number of files that each have different jobs to do once they're on an infected PC, including one that disables the Windows User Account Control mechanism.
[...]
The rootkit mainly is being seen in Brazil right now, a country where the penetration of online banking is extremely high.
------------------------------------------------------------------
Rootkit Banker - now also to 64-bit
http://www.securelist.com/en/blog/11266/Rootkit_Banker_now_also_to_64_bit
Security researchers have come across a new rootkit that is designed specifically to infect 64-bit Windows systems and steal users' online banking credentials. It's believed to be the first piece of malware of its kind that is capable of compromising x64 systems.
The new rootkit is being used by attackers in Brazil as part of drive-by download attacks and is then used to steal banking credentials after the infection. The malware has the ability to change some of the boot configurations of infected machines and then aims to redirect users to phishing sites. The new rootkit can infect machines running either 32-bit or 64-bit versions of Windows.
The drive-by download is accomplished by using a malicious Java applet that is targeted at older versions of the Java Runtime Environment. The applet includes a number of files that each have different jobs to do once they're on an infected PC, including one that disables the Windows User Account Control mechanism.
[...]
The rootkit mainly is being seen in Brazil right now, a country where the penetration of online banking is extremely high.
------------------------------------------------------------------
Rootkit Banker - now also to 64-bit
http://www.securelist.com/en/blog/11266/Rootkit_Banker_now_also_to_64_bit
Thursday, May 19, 2011
Sayf al-’Adl and al-Qa’ida’s Historical Leadership
Via Jihadica.com -
In light of the widely reported news that Sayf al-‘Adl (also spelled Saif al-Adel) has taken the reins of operational leadership within al-Qa’ida in the wake of the death of Osama bin Laden, I thought it would be useful to Jihadica’s readers to provide a bit of context about this man and about the significance, if any, of these reports (see, e.g., Musharbash and Bergen), all of which rely on the testimony of Noman Benotman, a former leader of the Libyan Islamic Fighting Group.
-----------------------------------------------------------------
Good background on Sayf al-‘Adl...
In light of the widely reported news that Sayf al-‘Adl (also spelled Saif al-Adel) has taken the reins of operational leadership within al-Qa’ida in the wake of the death of Osama bin Laden, I thought it would be useful to Jihadica’s readers to provide a bit of context about this man and about the significance, if any, of these reports (see, e.g., Musharbash and Bergen), all of which rely on the testimony of Noman Benotman, a former leader of the Libyan Islamic Fighting Group.
-----------------------------------------------------------------
Good background on Sayf al-‘Adl...
CDC: Preparedness 101: Zombie Apocalypse
http://emergency.cdc.gov/socialmedia/zombies_blog.asp
There are all kinds of emergencies out there that we can prepare for. Take a zombie apocalypse for example. That’s right, I said z-o-m-b-i-e a-p-o-c-a-l-y-p-s-e. You may laugh now, but when it happens you’ll be happy you read this, and hey, maybe you’ll even learn a thing or two about how to prepare for a real emergency.
[...]
The rise of zombies in pop culture has given credence to the idea that a zombie apocalypse could happen. In such a scenario zombies would take over entire countries, roaming city streets eating anything living that got in their way. The proliferation of this idea has led many people to wonder “How do I prepare for a zombie apocalypse?”
Well, we’re here to answer that question for you, and hopefully share a few tips about preparing for real emergencies too!
-----------------------------------------------------------------------
Very smart move by the CDC to add some humor to the serious (and sometimes dry) subject of emergency preparedness.
They have also created various buttons & banners to capitalize on the recent 'Zombie' attention surge...
There are all kinds of emergencies out there that we can prepare for. Take a zombie apocalypse for example. That’s right, I said z-o-m-b-i-e a-p-o-c-a-l-y-p-s-e. You may laugh now, but when it happens you’ll be happy you read this, and hey, maybe you’ll even learn a thing or two about how to prepare for a real emergency.
[...]
The rise of zombies in pop culture has given credence to the idea that a zombie apocalypse could happen. In such a scenario zombies would take over entire countries, roaming city streets eating anything living that got in their way. The proliferation of this idea has led many people to wonder “How do I prepare for a zombie apocalypse?”
Well, we’re here to answer that question for you, and hopefully share a few tips about preparing for real emergencies too!
-----------------------------------------------------------------------
Very smart move by the CDC to add some humor to the serious (and sometimes dry) subject of emergency preparedness.
They have also created various buttons & banners to capitalize on the recent 'Zombie' attention surge...
Wednesday, May 18, 2011
Fearing Destruction, Researcher Cancels Disclosure of New Siemens SCADA Holes
Via Wired.com (Threat Level) -
A security researcher has discovered multiple security vulnerabilities in Siemens industrial control systems that he says would allow hackers with remote access to the systems cause physical destruction.
Dillon Beresford canceled a planned demonstration of the vulnerabilities on Wednesday at the Takedown security conference in Texas after Siemens and the Department of Homeland Security expressed concern over the phone and at the conference about disclosing information before Siemens could patch the vulnerabilities.
Beresford, a researcher who works for NSS Labs in Austin, Texas, says he decided to cancel the talk — “Chain Reactions–Hacking SCADA” — after realizing the full ramifications of the information he planned to reveal.
“Based on my own understanding of the seriousness behind this, I decided to refrain from disclosing any information due to safety concerns for the consumers that are affected by the vulnerabilities,” Beresford told Threat Level, adding that “DHS in no way tried to censor the presentation.”
[...]
The decision to pull the talk at the last minute caused rumors to fly at the conference. Another presenter at Takedown tweeted that DHS had banned Beresford’s talk.
But Beresford disputed this and said he’s been “extremely impressed” with the way ICS-CERT has handled the matter.
“This is different from simply stealing money out of someone’s bank account,” said NSS Labs CEO Rick Moys. “Things could explode. I don’t want to overplay this and sound like it’s a bunch of FUD but physical damage can occur and people can be seriously injured or worse. So we felt … it was best to be prudent and wait a little bit longer until we get more information.”
A security researcher has discovered multiple security vulnerabilities in Siemens industrial control systems that he says would allow hackers with remote access to the systems cause physical destruction.
Dillon Beresford canceled a planned demonstration of the vulnerabilities on Wednesday at the Takedown security conference in Texas after Siemens and the Department of Homeland Security expressed concern over the phone and at the conference about disclosing information before Siemens could patch the vulnerabilities.
Beresford, a researcher who works for NSS Labs in Austin, Texas, says he decided to cancel the talk — “Chain Reactions–Hacking SCADA” — after realizing the full ramifications of the information he planned to reveal.
“Based on my own understanding of the seriousness behind this, I decided to refrain from disclosing any information due to safety concerns for the consumers that are affected by the vulnerabilities,” Beresford told Threat Level, adding that “DHS in no way tried to censor the presentation.”
[...]
The decision to pull the talk at the last minute caused rumors to fly at the conference. Another presenter at Takedown tweeted that DHS had banned Beresford’s talk.
But Beresford disputed this and said he’s been “extremely impressed” with the way ICS-CERT has handled the matter.
“This is different from simply stealing money out of someone’s bank account,” said NSS Labs CEO Rick Moys. “Things could explode. I don’t want to overplay this and sound like it’s a bunch of FUD but physical damage can occur and people can be seriously injured or worse. So we felt … it was best to be prudent and wait a little bit longer until we get more information.”
Microsoft EMET v2.1 Released
http://blogs.technet.com/b/srd/archive/2011/05/18/new-version-of-emet-is-now-available.aspx
Today we are pleased to announce a new version of the Enhanced Mitigation Experience Toolkit (EMET) with brand new features and mitigations. Users can click here to download the tool free of charge.
The Enhanced Mitigation Experience Toolkit enables and implements different techniques to make successful attacks on your system more difficult. EMET is designed to mitigate exploitation attempts (even of 0-days) by making “current” exploitation techniques harder and less reliable. Users interested in finding out more about EMET can read more here.
[...]
This release marks a big milestone for EMET since this is the first version that is available as an officially-supported product. Support will be form based, with the on-line form available here.
Today’s release comes with some new features:
Today we are pleased to announce a new version of the Enhanced Mitigation Experience Toolkit (EMET) with brand new features and mitigations. Users can click here to download the tool free of charge.
The Enhanced Mitigation Experience Toolkit enables and implements different techniques to make successful attacks on your system more difficult. EMET is designed to mitigate exploitation attempts (even of 0-days) by making “current” exploitation techniques harder and less reliable. Users interested in finding out more about EMET can read more here.
[...]
This release marks a big milestone for EMET since this is the first version that is available as an officially-supported product. Support will be form based, with the on-line form available here.
Today’s release comes with some new features:
- EMET is an officially-supported product through online forms
- “Bottom-up Rand” new mitigation randomizes (8 bits of entropy) the base address of bottom-up allocations (including heaps, stacks, and other memory allocations) once EMET has enabled this mitigation.
- Export Address Filtering is now available for 64 bit processes. EAF filters all accesses to the Export Address Table which blocks most of the existing shellcodes
- Improved command line support for enterprise deployment and configuration
- Ability to export/import EMET settings
- Improved SEHOP (structured exception handler overwrite protection) mitigation
- Minor bug fixes
Subscribe to:
Posts (Atom)