Wednesday, June 29, 2011

Hacker Attack Allegedly Cripples Al-Qaida Web Communications

Via MSNBC.com -

Computer hackers shut down al-Qaida's ability to communicate its messages to the world through the Internet, interrupting the group's flow of videos and communiqués, according to a terrorism expert.

Al-Qaida's online communications have been temporarily crippled, and it does not have a single trusted distribution channel available on the Internet," said Evan Kohlmann, of Flashpoint Global Partners, which monitors the group's communications.

The attack was carried out within the past few days by unknown hackers targeting al-Qaida's Internet communications systems. It was "well coordinated and involved the use of an unusual cocktail of relatively sophisticated techniques," Kohlmann said.

"My guess is that it will take them at least several days more to repair the damage and get their network up and functioning again," he said.

A year ago, al-Qaida's Internet communications suffered a similar hacker attack.

[...]

Kohlmann said the latest incident "once again appears to bear the telltale fingerprints of government-sponsored hackers."


--------------------------------------------------------------------------------------------------------

Here are several of Evan's previous tweets outlining the allegedly attacks...

http://twitter.com/#!/IntelTweet/status/85468524537057280
Hackers have hijacked the primary web domain used by the top-tier "Shamukh" chat forum, which disseminates propaganda on behalf of Al-Qaida.
27 Jun
http://twitter.com/#!/IntelTweet/status/85488197286637568
The ongoing hacking attack on the top-tier "Shamukh" jihadi web forum has dramatically escalated, with the entire website now unavailable.
27 Jun
http://twitter.com/#!/IntelTweet/status/86132506423853056
Even with the return of Atahadi and Ansar al-Muj, the ongoing jihadi web blackout is by now the most significant such event since June '10.
29 Jun
http://twitter.com/#!/IntelTweet/status/86133041696751616
At the present time, Al-Qaida has been left without a trusted operational channel on the Internet for distributing its media and propaganda.
29 Jun

Pwnie Awards 2011 - Nominations Open

http://pwnies.com/

It is time to open the nominations for the Pwnie Awards 2011. We invite all members of the security community to look back at the past year and nominate all great bugs, lame vendors, amazing research and of course, songs. The full list of award categories and the submission form can be found at the nominations page.

We will accept nominations until July 20th, after which the top five nominees in each category will be announced on this website. The winners will be determined by a vote of the Pwnie Award judges shortly before the award ceremony.

The Pwnie Awards ceremony will take place during the BlackHat USA reception on August 3, 2011, starting at 6:15pm. The Pwnie Award organizers thank BlackHat for their generous sponsorship.

Symantec: A Window Into Mobile Device Security

http://www.symantec.com/content/en/us/about/media/pdfs/symc_mobile_device_security_june2011.pdf

Executive Summary

The mass-adoption of both consumer and managed mobile devices in the enterprise has increased employee productivity but has also exposed the enterprise to new security risks. The latest mobile platforms were designed with security in mind—both teams of engineers attempted to build security features directly into the operating system to limit attacks from the outset. However, as the paper discusses, while these security provisions raise the bar, they may be insufficient to protect the enterprise assets that regularly find their way onto devices. Finally, complicating the security picture is the fact that virtually all of today’s mobile devices operate in an ecosystem, much of it not controlled by the enterprise—they connect and synchronize out-of-the-box with third-party cloud services and computers whose security posture is potentially unknown and outside of the enterprise’s control.

[...]

Summary of iOS Security


Overall, Symantec considers iOS’s security model to be well designed and thus far it has proven largely resistant to attack. To summarize:

  • iOS’s encryption system provides strong protection of emails and email attachments, and enables device wipe, but thus far has provided less protection against a physical device compromise by a determined attacker.
  • iOS’s provenance approach ensures that Apple vets every single publicly available app. While this vetting approach is not foolproof, and almost certainly can be circumvented by a determined attacker, it has thus far proved a deterrent against malware attacks, data loss attacks, data integrity attacks, and denial of service attacks.
  • iOS’s isolation model totally prevents traditional types of computer viruses and worms, and limits the data that spyware can access. It also limits most network-based attacks, such as buffer overflows, from taking control of the device. However, it does not necessarily prevent all classes of data loss attacks, resource abuse attacks, or data integrity attacks.
  • iOS’s permission model ensures that apps can’t obtain the device’s location, send SMS messages, or initiate phone calls without the owner’s permission.
  • None of iOS’s protection technologies address social engineering attacks such as phishing or spam.
[...]

Summary of Android’s Security

Overall, while we believe the Android security model is a major improvement over the models used by traditional desktop and server-based operating systems, it has two major drawbacks. First, its provenance system enables attackers to anonymously create and distribute malware. Second, its permission system, while extremely powerful, ultimately relies upon the user to make important security decisions. Unfortunately, most users are not technically capable of making such decisions and this has already led to social engineering attacks. To summarize:
  • Android’s provenance approach ensures that only digitally signed applications may be installed on Android devices. However, attackers can use anonymous digital certificates to sign their threats and distribute them across the Internet without any certification by Google. Attackers can also easily “trojanize” or inject malicious code into legitimate applications and then easily redistribute them across the Internet, signing them with a new, anonymous certificate. On the plus side, Google does require application authors wishing to distribute their apps via the official Android App Marketplace to pay a fee and register with Google (sharing the developer’s digital signature with Google). As with Apple’s registration approach, this should act as a deterrent to less organized attackers.
  • Android’s default isolation policy effectively isolates apps from each other and from most of the device’s systems including the Android operating system kernel, with several notable exceptions (apps can read all data on the SD card unfettered).
  • Android’s permission model ensures that apps are isolated from virtually every major device system unless they explicitly request access to those systems. Unfortunately, Android ultimately relies upon the user to decide whether or not to grant permissions to an app, leaving Android open to social engineering attacks. Most users are unequipped to make such security decisions, leaving them open to malware and all of the secondary attacks (for example DDoS attacks, Data Loss attacks) that malware can launch.
  • Android recently began offering built-in encryption in Android 3.0. However, earlier versions of Android (running on virtually all mobile phones in the field), contain no encryption capability, instead relying upon isolation and permissions to safeguard data. Thus, a simple jailbreak of an Android phone or theft of the device’s SD card can lead to a significant amount of data loss.
  • As with iOS, Android has no mechanism to prevent social engineering attacks such as phishing attacks or other (off-device) Web-based trickery.

Hackers Steal Info on Military, Defense Personnel

Via ComputerWorld -

Email addresses and names of subscribers to DefenseNews, a highly-regarded website that covers national and international military and defense news, were accessed by hackers and presumed stolen, Gannett announced yesterday. DefenseNews' subscribers include active and retired military personnel, defense contractors and others in both the U.S. and other countries' defense establishments.

"We discovered that the attacker gained unauthorized access to files containing information of some of our users," said Gannett Government Media, an arm of the media chain that publishes not only DefenseNews, but also the Military Times and Federal Times sites, as well as a number of military-specific magazines and journals, ranging from the Army Times to the Intelligence, Surveillance and Reconnaissance Journal.

In a message posted to its site Monday, Gannett acknowledged that the accessed information included first and last names, email addresses, account passwords, and duty status branch of service for military personnel.

One security expert said it was possible the attack against DefenseNews and the other sites Gannett operates was targeted, perhaps by state-backed hackers. "It's hard to know if this was just part of the general ransacking of sites, or an attempt to obtain valuable information for spear-phishing," said Anup Ghosh, the founder and CEO of Web security firm Invincea. Ghosh said it's likely the attack was deliberately after the names and email addresses of people in the defense industry and military.

"This is a pretty selective group," Ghosh said of the DefenseNews account holders, and would be restricted in scope to the military-industrial [establishment]. It would be very attractive from a nation-state point of view."

Monday, June 27, 2011

2011 CWE/SANS Top 25 Most Dangerous Software Errors

http://cwe.mitre.org/top25/index.html

Introduction

The 2011 CWE/SANS Top 25 Most Dangerous Software Errors is a list of the most widespread and critical errors that can lead to serious vulnerabilities in software. They are often easy to find, and easy to exploit. They are dangerous because they will frequently allow attackers to completely take over the software, steal data, or prevent the software from working at all.

The Top 25 list is a tool for education and awareness to help programmers to prevent the kinds of vulnerabilities that plague the software industry, by identifying and avoiding all-too-common mistakes that occur before software is even shipped. Software customers can use the same list to help them to ask for more secure software. Researchers in software security can use the Top 25 to focus on a narrow but important subset of all known security weaknesses. Finally, software managers and CIOs can use the Top 25 list as a measuring stick of progress in their efforts to secure their software.

The list is the result of collaboration between the SANS Institute, MITRE, and many top software security experts in the US and Europe. It leverages experiences in the development of the SANS Top 20 attack vectors and MITRE's Common Weakness Enumeration (CWE). MITRE maintains the CWE web site, with the support of the US Department of Homeland Security's National Cyber Security Division, presenting detailed descriptions of the top 25 programming errors along with authoritative guidance for mitigating and avoiding them. The CWE site contains data on more than 800 programming errors, design errors, and architecture errors that can lead to exploitable vulnerabilities.

The 2011 Top 25 makes improvements to the 2010 list, but the spirit and goals remain the same. This year's Top 25 entries are prioritized using inputs from over 20 different organizations, who evaluated each weakness based on prevalence, importance, and likelihood of exploit. It uses the Common Weakness Scoring System (CWSS) to score and rank the final results. The Top 25 list covers a small set of the most effective "Monster Mitigations," which help developers to reduce or eliminate entire groups of the Top 25 weaknesses, as well as many of the hundreds of weaknesses that are documented by CWE.

Sunday, June 26, 2011

Chinese Minister Was Caught in a 'Honeytrap'

Via Telegraph UK -

When Jin Renqing stepped down in August 2007, it was for 'personal reasons' according to the Chinese government. Now, it appears that Mr Jin was caught in a 'honeytrap' operation by a woman employed by Taiwan's intelligence agency to discover sensitive secrets.

At the time, there was speculation in the Hong Kong media that Mr Jin had resigned after he was found to have been unknowingly sharing a mistress with other senior Chinese officials. But the confidential cable from the US government claims that the then 63-year-old and the other officials were victims of a 'honeytrap', in which a seductive young woman is used to compromise a man with access to secret information of interest to a rival state.

"The woman was introduced to these men as 'someone working with a Chinese military intelligence department'. However investigators now believe that she is a Taiwan intelligence operative," said the cable, which was released by WikiLeaks earlier this month. 'Honeytraps', which are also known as 'Honeypots', are as old as espionage itself, and have long been a staple of both intelligence agencies and Hollywood spy films.

While the KGB and former East German security services were especially adept at using 'honeytraps', ironically it is now China's spies who have enthusiastically adopted the technique.

In 2008, an aide to then Prime Minister Gordon Brown had his Blackberry stolen by a Chinese woman he met in a Shanghai nightclub.

A year later, a leaked MI5 report distributed to hundreds of UK companies warned of the dangers posed by charming young Chinese women in search of commercial secrets who approach British businessmen travelling in China.


------------------------------------------------------------------------------------------

Reminds me of one of the stickers on my refrigerator ....
http://www.flickr.com/photos/9teen87/5227974324/
"Beware of inquisitive women as well as prying men".

Saturday, June 25, 2011

The Triple Agent

Via Newsweek -

On Dec. 30, 2009, seven CIA operatives were killed at a U.S. base in Khost, Afghanistan, when a Jordanian double agent who claimed to have cracked Al Qaeda’s inner circle proved instead to be a suicide bomber—in other words, a triple agent.

The attack, the deadliest for the CIA in 25 years, was unlike any in the agency’s history. Over the decades, a multitude of CIA informants had lied, defrauded, betrayed, stolen money, or skipped town. But none had sought to lure his handlers into a trap with the aim of killing them, along with himself.

A 2010 internal CIA review identified a chain of failures that allowed 32-year-old physician Humam al-Balawi to gain access to the highly secure CIA base, breezing through checkpoints without a search until he came face to face with a large gathering of CIA officers anxious to meet him. Balawi had promised to deliver Ayman al-Zawahiri, deputy to Al Qaeda’s leader, Osama bin Laden. (Last week, in the wake of bin Laden’s death, Zawahiri emerged as the terrorist group’s new leader, though he was already in essence its operational commander.)

Balawi had backed his intelligence claims with evidence so electrifying that even President Obama had been briefed in advance. But the Jordanian was not what he seemed.

The warning signs, painfully obvious in hindsight, would be obscured by two singular forces that collided at Khost on that late-December day. One was the mind of Balawi, a man who flitted pre-cariously between opposing camps. The other was the eagerness of war-weary intelligence operatives who saw a mirage and desperately wanted it to be real.


------------------------------------------------------------------------

Excerpted from the forthcoming The Triple Agent by Joby Warrick.

China Opens String of Spy Schools

Via Telegraph UK -

Last week, China opened its eighth National Intelligence College on the campus of Hunan University in the central city of Changsha. Since January, similar training schools have opened inside universities in Beijing, Shanghai, Xian, Qingdao and Harbin.

The move comes amid growing worries in the West at the scale and breadth of Chinese intelligence-gathering, with MI5 saying that the Chinese government "represents one of the most significant espionage threats to the UK".

In February, China allegedly managed to penetrate the Foreign Office's internal communications network.

Until now, however, the bulk of Chinese foreign espionage is thought to have been conducted primarily by academics and students who are sent to the host countries only for a short period of time.

The new schools aim to transform and modernise the Chinese intelligence services, producing spies who are trained in the latest methods of data collection and analysis. Each school will recruit around 30 to 50 carefully-selected existing undergraduates each year.

The move echoes similar efforts by Western intelligence agencies, including MI5, to improve their analytical capabilities and use of technology.

The United States has a similar project, named the National Security Education Program, that was set up in the wake of the first Gulf war in order to boost language and culture training for US spies.

The Chinese programme began in 2008 with the founding of the first Intelligence College at Nanjing university. A second school was set up in the southern province of Guangdong at the end of last year, and the programme has now been dramatically accelerated.

"The establishment of an Intelligence college at Fudan is in response to the urgent need for special skills to conduct intelligence work in the modern era," said a spokesman for Shanghai's Fudan university.

"The college will use Fudan's existing computer science, law, management, journalism and sociology resources and then carry out special intelligence training," he added.

Syria's President Gives OK to Pro-Gov Cyber Attackers?

Via Committee to Protect Journalists (CPJ.org) -

On Monday [June 20, 2011], Syrian President Bashar al-Assad gave his third public address on the vast unrest that has roiled his nation. Reporters described him as nervous. He, the reporters, or perhaps both, may have been thinking about the significance of speech No. 3. Both Tunisia's Zine El Abidine Ben Ali and Egypt's Hosni Mubarak were overthrown shortly after they delivered their third addresses on tumult in their countries. My interest, however, was on a sentence buried near the end of his address. Here's the official translation:
The army consists of the brothers of every Syrian citizen, and the army always stands for honour and dignity. Young people have an important role to play at this stage, because they have proven themselves to be an active power. There is the electronic army which has been a real army in virtual reality. There were those who took part in the blood donation campaign, and other initiatives. I met a number of youth delegations from different sections of society and found that Syrian youth enjoy a high sense of patriotism, and this is self-evident because they belong to this country.
Those bolded italics include a direct reference to the Syrian Electronic Army, a pro-government hacking group. On Twitter, the group thanked al-Assad for the mention, and went on to say on its Facebook page:
Our message to the news agencies and reporters: If you have a shortage of professionals to report the correct news ... the hordes of the Syrian Electronic Army will not be forgiving with you.
The statement sits next to a screenshot of the army's most frequent and mildest tactic: encouraging followers to saturate online forums with pro-Assad commentary. The group has taken such actions on American and French politicians' sites, as well as news sites such as that of the BBC.

But the army also claims responsibility for more invasive attacks, including defacing websites by exploiting security holes. Their attacks appear aimed more at the lower-hanging fruit of unsecured sites rather those who write critically about Syrian affairs: Past targets have included local town councils in England, Israeli pizza shops, and Australian window sellers.

Nonetheless, to my knowledge this is the first time a head of state has explicitly approved of such actions. Governments are usually careful to distance themselves from nationalistic hacking groups, even if they tacitly permit it through lack of law enforcement. By mentioning the Electronic Army, al-Assad is signaling his support of computer sabotage and vigilante censorship in the name of his country. At least, that is how his online supporters are likely to interpret his words.


------------------------------------------------------------

Check out this great article by Information Warfare Monitor for background....

The Emergence of Open and Organized Pro-Government Cyber Attacks in the Middle East: The Case of the Syrian Electronic Army

Wednesday, June 22, 2011

Apple’s “Censoring” Patent Just a Sign of Things to Come

Via EFF Deeplinks -

Apple has been much maligned in the press recently for filing a patent application covering a camera system with infrared technology that could, among other things, allow the recording functionality to be shut off by a third party. For example, in its application, Apple shows how the technology could be used to "prevent illegal image capturing" at a rock concert.

[...]

To be clear, we should not fear this one patent application, but rather the larger technology that may be captured by governments and implemented in widespread standards that could have serious consequences, for example, by shutting down citizens’ ability to capture and disseminate video. The technology in this patent just may be a harbinger of that, and—for that reason—we will continue to watch it closely.

Friday, June 17, 2011

Analysis: Who Might Be Behind Attempted IMF Data Hacking?

Via Reuters (June 13, 2011) -

A national government is the most likely culprit in an apparent cyber attack on the International Monetary Fund, say experts, given the complexity of the assault and its targeting of the organization's secrets.

With the IMF leadership up for grabs as it mulls Eurozone bailouts and global financial reform, there are no shortage of states who might like to read its mail.

Any confirmation of a country's involvement would become a major diplomatic incident.

"For what we can tell, the aim ... appears to be to gather intelligence rather than cause disruption," said John Bassett, a former senior official at Britain's signals intelligence agency GCHQ and now a senior fellow at the Royal United Services Institute.

"The intrusion appears to be sophisticated and well executed at an operational level (suggesting) that it originates from or is sponsored by a state."

For many, China topped the list of suspects. Chinese hackers have been suspected of being behind several recent data theft attempts including one aimed at breaching the security of Google's Gmail on accounts belonging to activists, US officials and others. Beijing angrily denies any government link.

But experts say almost every sophisticated state indulges in electronic snooping, whilst independent hackers potentially working for militant groups or even banks or investment funds could also be in the frame.

Philip Blank, an expert on security, risk and fraud at San Francisco-based Javelin Strategy and Research said the IMF "would be an extraordinarily attractive target." Other financial industry insiders agreed.

"Given how central the IMF is at the moment, there are plenty of people who would like to know what it is thinking," said one London-based currency markets veteran, asking not to be named because of the sensitivity of the issue.

"They range from the world's largest reserve holders -- which are the key emerging economies like China -- to brokerages and funds to the Eurozone governments themselves."

Access to IMF files might give a hacker access to not only details of its own policy of thoughts and internal debates but also those of other major powers, he said.

[...]


Larry Wortzel, a commissioner on the congressionally created U.S.-China Economic and Security Review Commission, said he suspected Chinese authorities had sought to pierce IMF networks to get inside information before meetings in Beijing last week with French Finance Minister Christine Lagarde, the frontrunner to replace Strauss-Kahn.

The bipartisan commission has accused Chinese hackers of infiltrating both the US and other international computer systems to gain information for commercial and strategic gain.

"You don't have to be Inspector Clouseau to figure this out," Wortzel, a retired U.S. Army colonel who served two tours as a military attache in China, said in a telephone interview, referring to the fictional French police detective. Wortzel said he did not have any forensic information to back his speculation. "To me, this is just practical common sense."

[...]

But Alexander Klimburg, a cyber security expert at the Austrian Institute for International affairs, said the source of the attacks could just as likely be from Russia.

Some security experts say both Moscow and Beijing in particular deliberately turn a blind eye to the activities of hackers in their territory providing they only attack foreign targets outside their borders.

Such hackers are believed to occasionally carry out work on behalf of governments as well as trading information for cash.

During the brief 2008 war between Georgia and Russia over breakaway South Ossetia, attacks disabled and took offline websites in all the countries involved.

Global coordination was key to countering the attacks, Klimburg said.

"This is potentially a great opportunity to launch a "communal" investigation into an attack on a "communal" institution," he said. "If the fingers can be pointed, they should be pointed. The only way to stop such attacks is "naming and shaming" and in this case... there is a clear global interest at stake."

Exploit for MS11-50 Vulnerability in the Wild

Via Symantec Über Security Response Blog -

Symantec Security Response has confirmed that the Microsoft Internet Explorer Time Element Uninitialized Memory Remote Code Execution Vulnerability (CVE-2011-1255) is being exploited in the wild. The vulnerability affects Internet Explorer versions 6, 7, and 8; however, the exploit we have acquired seems to only affect version 8. Microsoft has already released patches as part of the MS Tuesday release on June 14, so Symantec advises all users to install the patch. So far, we have only seen limited attacks taking advantage of this vulnerability and believe that the exploit is only being carried out in targeted attacks at present.

We have been able to confirm the existence of one such attack that involves a compromised website hosting content for a neighborhood restaurant. It appears that a duplicate of the top page of the website was either hacked to include a hidden iframe tag linking to an exploit page or was prepared from scratch, which, if run successfully, the included shell code downloads an encrypted malicious file from the same site. Interestingly, a link to cnzz.com, which is a site that offers statistical analysis, is included in the page to perhaps to provide the attackers with an idea of how the attack is progressing. The downloaded malware then contacts 323332.3322.org using the HTTP protocol and awaits further commands. 3322.org provides a type of dynamic DNS service and is known to be used for various malicious purposes, so it may not be a bad idea to block access to this domain and, if needed, whitelist the subdomains that you may need access to. It's likely that the attacker sends emails to targets with a link to the website with the intent to steal confidential information, which is a common method used in targeted attacks.

To protect themselves from attack, users should apply the latest patch for this vulnerability. They should also keep all other software on their computer up to date as well, including security software. Users should also be cautious when receiving emails with attachments and links they receive from both known and unknown sources.


------------------------------------------------------------------------

Threat Mitigation - Apply MS11-050
The vulnerability outlined above was patched in Microsoft's Security Bulletin MS11-050 - Cumulative Security Update for Internet Explorer (2530548)
http://www.microsoft.com/technet/security/Bulletin/MS11-050.mspx

Thursday, June 16, 2011

Jihadi Forum Watchers Beat Wires to Zawahri Story

Via The Atlantic Wire -

In the wee hours of Thursday morning, the news broke that al-Qaeda had officially tapped Ayman al-Zawahri, Osama bin Laden's former second-in-command, as its next leader. But how did the news break? It turns out that terrorism experts who monitor jihadi forums managed to beat the super-fast wire services to the story.

Here's how it all went down. At around 2 am EST, Aaron Zelin, who runs the website Jihadology, tweeted that al-Qaeda's General Command had announced its new leader, linking to a statement on the Islamist website Ansar al-Mujahideen (Followers of the Holy Warriors, pictured above). He told The Atlantic Wire that he was randomly checking Ansar's Arabic forum when he came across the statement, which had just been posted. Zelin, who is currently in an Arabic immersion program at Middlebury College, isn't allowed to speak English, so he tweeted the news in Arabic and sent the link via instant message to Daveed Gartenstein-Ross, the director of the Center for the Study of Terrorist Radicalization, for distribution to the wider world. Gartenstein-Ross swiftly did just that in between observations about his dissertation and rioting Vancouver Canucks fans. After seeing Gartenstein-Ross's tweet, Leah Farrall, who runs the blog All Things Counter Terrorism, quickly observed, "Reason number one thousand why you should always read AQ primary materials. Succession of al-Zawahiri as amir."

Minutes later, the analysts transitioned to fact-checking mode. J.M. Berger, who runs the site IntelWire, asked about the document's authenticity and Farrall noticed that the properties data on the file announcing the promotion was created on May 21 and modified on June 14, with six revisions, though she decided to "leave it to those with funkier toys to have a look around the data." Berger concluded that since Ansar was running the statement as a banner headline, it's "either authentic or a whole new class of forgery," adding that since many people expected al-Zawahri to succeed bin Laden, the probability that people would spend time and effort on a forgery was low. Within the hour, Al Arabiya television was reporting the news, which was picked up in a Reuters "FLASH" and soon covered by hundreds of other sources. Al Arabiya and Reuters, of course, may have also spotted the statement on jihadi forums this morning and simply been delayed in publishing the news by internal verification requirements. But the genesis of the story gives us another example, in the wake of the 'Gay Girl in Damascus' hoax, of how collaborative fact-checking and news breaking can work on Twitter.


--------------------------------------------------

Awesomeness. Nice work gentleman and lady ;)

Wednesday, June 15, 2011

TrustDefender Labs - Torpig: Back to The Future

http://www2.trustdefender.com/labs/2011/06/Torpig%20-%20Back%20to%20the%20Future%20-%20TrustDefender%20indepth%20report%20-%20June%202011%20-%20final.pdf

Executive Summary

We have seen many different examples how improvements in the security landscape have forced the bad guys to change tactics and achieve their results via different, potentially less useful, methods.

A prime example is the introduction of UAC in Windows 7 together with the default user not running as administrator. This poses a tricky question for malware developers: Do I ask for elevation (UAC) and risk that users get suspicious, or do I do whatever I can without administration privileges?

Well the answer has been given. We’ve analysed Zeus before and Zeus will not bring up the UAC and will only infect the currently logged in user.

In this TrustDefender Labs report we look at a new strain of the notorious Torpig Trojan that gained massive publicity in 2008 when it was distributed together with the Mebroot / MBR virus. In this report we look at a new variant that will do an impressive amount of things completely without administrator privileges.

On a positive note, the lack of privileges restricts the trojan’s ability to hide itself deep in the system and is much easier to detect and remove.


--------------------------------------------------------------------

As Windows 7 and the practice of running non-admin becomes more standard, malware will most likely adapt in the three following ways:

  • Some malware will run without admin privileges. Although per-user malware is not as dangerous as privileged malware (e.g., it can't infest the kernel to install a rootkit or keylogger), it can easily acquire and exfiltrate any data on the system that the user has access to. This is already happening, as noted in SecureWork’s March 2010 report on Zeus & and the Torpig report above.
  • Other malware will utilize exploit local privileges escalation vulnerabilities in Windows 7 to bypass UAC and acquire administrative privilege itself. This can only happen after the malware is already on the system, so it will require the malware to exploit two or three different vulnerabilities, which is pretty rare at this point. This type of attack would work, even if the user is only a standard user. This is already been seen in a couple of cases. In 2008, F-Secure noticed a worm that was using a public escalation of privileges (EoP) vulnerability to gain admin rights on system and install a rootkit. In 2010, Stuxnet used a local privilege escalation zeroday vulnerability to get admin privileges on both Windows 7 / 2008.
  • Protected Admin Users of Windows 7 (i.e. those running as Admin under UAC) might even see some malware attempting to trick the user into self-elevating, thru the use of social engineering techniques. Once the user self-elevates using UAC, the malware will have full run of the kernel. Foreseeing this, Microsoft has implemented a "Secure Desktop" in UAC.

Adobe Patches Flash Player 0-Day Used in Targeted Attacks

http://www.adobe.com/support/security/bulletins/apsb11-18.html

A critical vulnerability has been identified in Adobe Flash Player 10.3.181.23 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.185.23 and earlier versions for Android. This memory corruption vulnerability (CVE-2011-2110) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in targeted attacks via malicious Web pages.

Adobe recommends users of Adobe Flash Player 10.3.181.23 and earlier versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 10.3.181.26, available now. Adobe expects to make available an update for Adobe Flash Player 10.3.185.23 and earlier versions for Android before the end of the week of June 13, 2011.

Note: This issue does not affect the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.3) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems.


------------------------------------------------------------------------------------------

Extremely Poor AV Detection on New Adobe Flash 0-Day - 2/41 (4.9%)
http://www.virustotal.com/file-scan/report.html?id=8d592113d251be2f3d2a96c53373df1b5c1d23e00397d295b60d809208ad3ab5-1308109907

Threat Mitigation - Verify Your Flash Player Version
To verify the version of Adobe Flash Player installed on your system, access the About Flash Player page. Verify the number in the "Version Information" box matches your current browser and operations system in the table below. If it doesn't, you should apply the latest version. If you use multiple browsers, perform the check for each browser you have installed on your system.

Pakistan Arrests C.I.A. Informants in Bin Laden Raid

Via NY Times -

Pakistan’s detention of five C.I.A. informants, including a Pakistani Army major who officials said copied the license plates of cars visiting Bin Laden’s compound in Abbottabad, Pakistan, in the weeks before the raid, is the latest evidence of the fractured relationship between the United States and Pakistan. It comes at a time when the Obama administration is seeking Pakistan’s support in brokering an endgame in the war in neighboring Afghanistan.

At a closed briefing last week, members of the Senate Intelligence Committee asked Michael J. Morell, the deputy C.I.A. director, to rate Pakistan’s cooperation with the United States on counterterrorism operations, on a scale of 1 to 10.

“Three,” Mr. Morell replied, according to officials familiar with the exchange.

The fate of the C.I.A. informants arrested in Pakistan is unclear, but American officials said that the C.I.A. director, Leon E. Panetta, raised the issue when he travelled to Islamabad last week to meet with Pakistani military and intelligence officers.

Some in Washington see the arrests as illustrative of the disconnect between Pakistani and American priorities at a time when they are supposed to be allies in the fight against Al Qaeda — instead of hunting down the support network that allowed Bin Laden to live comfortably for years, the Pakistani authorities are arresting those who assisted in the raid that killed the world’s most wanted man.

The Bin Laden raid and more recent attacks by militants in Pakistan have been blows to the country’s military, a revered institution in the country. Some officials and outside experts said the military is mired in its worst crisis of confidence in decades.

American officials cautioned that Mr. Morell’s comments about Pakistani support was a snapshot of the current relationship, and did not represent the administration’s overall assessment.

“We have a strong relationship with our Pakistani counterparts and work through issues when they arise,” said Marie E. Harf, a C.I.A. spokeswoman. “Director Panetta had productive meetings last week in Islamabad. It’s a crucial partnership, and we will continue to work together in the fight against Al Qaeda and other terrorist groups who threaten our country and theirs.”


----------------------------------------------------------------------------------

Why Has Pakistan Targeted Informants Who Helped Track Bin Laden?
http://www.time.com/time/world/article/0,8599,2077838,00.html
The move against the informants appears to be an attempt to stand up to what the ISI sees as American unilateralism and, in particular, an unauthorized expansion of the CIA's footprint in Pakistan.

Tuesday, June 14, 2011

Better 'Protected Mode' Support in Adobe Reader X (10.1)

According to the release notes for the just released Adobe Reader X (10.1), this version adds support for "Protected Mode" in cases where Reader is hosted on Citrix / Terminal Services and in cases where PDFs are embedded in Office Documents (OLE). Good news indeed!

This should enable users of those configurations to enable "Protected Mode" - which is a great defense-in-depth security strategy for mitigating and preventing security vulnerabilities.

See Page 5....
http://kb2.adobe.com/cps/837/cpsid_83708/attachments/Acrobat_Reader_ReleaseNote_10.1.pdf

Assessing the Risk of the Microsoft's June Security Updates

Terminology - Microsoft releases "bulletins" which contain fixes or patches for individual vulnerabilities. It isn't uncommon to see people call a single bulletin (MS11-050) a "patch", but it is important to remember that, most of the time, a single bulletin addresses many vulnerabilities.

----------------------------------------------------------------------------

This month, the number of bulletins rated critical was nine, which is the exact number outlined in the advanced notification.

However, the exploitability index number was divided into two separate numbers recently - 
  • Exploitability Index for Latest Software Release (Windows 7 & 2008 R2)
  • Exploitability Index for Older Software Releases (Windows XP)

According to today’s bulletin summary, CVE-2011-1262 (part of MS11-050) has an exploitability index of “2” for new operating systems and an exploitability index of “1” for older operation systems. New operating systems have more mitigation layers (Default DEP, ASLR, UAC, etc) and therefore are less vulnerable than older operating systems. The summary table list details for each vulnerability in each bulletin.

While the SRD table is just combining all the individual vulnerability data and listing the “max” severity rating and "max" exploitability rating (in this case, the lowest – since lower is more exploitable) for each bulletin as a whole.

Given all of this, I would say the numbers in the SRD table seems to be the safest route when assessing the risk.

Monday, June 13, 2011

US Blocks Ship Suspected of Carrying North Korean Arms

Via VOA News -

A senior U.S. official says the Navy intercepted a ship suspected of carrying banned weapons technology from North Korea to Burma and forced it to return home. U.S. officials say they received support from the Association of Southeast Asian Nations, including Burma, in putting pressure on Pyongyang to halt the ship.

The USS McCampbell, a Navy destroyer, intercepted the M/V Light in international waters on May 26, as it made its way from North Korea to Burma. The ship carries the Belize flag, and authorities in Belize had given permission for it to be boarded.

But the North Korean crew refused to be boarded, and after a few days of military confrontation and diplomatic pressure, turned toward home.

Gary Samore is the White House special assistant on arms control and weapons of mass destruction. He said in Seoul Monday that the ship came under suspicion because it has been involved in weapons exports to Burma and the Middle East in the past.

[...]

He says the United States met with its partners in the Association of Southeast Asia Nations, and "made the case" that the ship might be violating U.N. sanctions against North Korea and there were grounds for it to be inspected if it visited ASEAN ports. He said the ASEAN nations indicated their willingness to comply with the U.N. resolutions.

"The Burmese said in the meeting I was in that they would respect and honor their obligations under [U.N. Security Council Resolution] 1874. They never committed to doing inspections, but they said they would honor 1874," said Samore.

Security Council Resolution 1874 and an earlier one, 1718, bar North Korea from engaging in the arms trade. 1874 was imposed in 2009 after North Korea conducted its second nuclear-weapons test.

[...]

Washington also has been concerned with Burma's growing military contacts with North Korea. The two countries in recent years have resumed ties, which were severed after North Korean agents planted a bomb in Rangoon in 1983 that killed several visiting South Korean Cabinet members.

There have been numerous reports in the past two years that Burma's military aims to obtain sophisticated weaponry, including nuclear bombs. There has been no official confirmation of those reports.

The United States, like many developed nations, has imposed sanctions on Burma's leadership for human rights abuses.

APT: International Monetary Fund Reportedly Hacked

Via H-Online -

Although no statement has been released on the web site of the International Monetary Fund (IMF), it has been reported by the New York Times and Bloomberg that the IMF has been the victim of a "large and serious" cyber attack. The full extent of the attack has not been revealed, but it has been said that the attackers were able to plant software on a computer within the IMF which enabled them to have some level of external access to its network. The software may well have been planted as a result of a targeted spear phishing attack; the IMF’s chief information officer, Jonathan Palmer, sent out an email warning employees of “increased phishing activity”. The World Bank took the problem seriously and, as a precaution, severed the network connection that allows the two organisations to share data.

According to the Bloomberg report, the attack appears to have been mounted by a foreign government, although no specific country was named. The same report quoted an unnamed source as stating that the IMF lost a "large quantity" of data which included emails and other documents. Some of the information held by the IMF is highly sensitive, much of it dealing with countries suffering financial difficulties and the negotiations in which they are involved. Very large sums of money are involved in these negotiations, around £56 billion last year in emergency loans.


------------------------------------------------------------------------

What Defines an APT?
McAfee Labs summarized it well in their 2011 Threat Predictions whitepaper (PDF). The generally accepted definition of an APT is one that describes a targeted cyber espionage or cyber sabotage attack that is carried out under the sponsorship or direction of a nation-state for something other than a pure financial/criminal reason or political protest. Not all APT attacks are highly advanced and sophisticated, just as not every highly complex and well-executed targeted attack is an APT. The motive of the adversary, not the level of sophistication or impact, is the primary differentiator of an APT attack from a cybercriminal or hacktivist one.

Suspected APT Attacks Against Other Financial Institutions
Other financial institutions such as the French Ministry of Finances and Canadian Finance Department and Treasury Board have also been the victim of hacks this year.

French Ministry of Finances
In December 2010, The French Ministry of Finance detected an attack, which appeared to target documents related to the G20 summit and the French G20 presidency. According to McAfee, over 150 computers in the ministry were infiltrated through targeted spear phishing emails containing a malicious attachments.

Canadian Finance Department and Treasury Board
A federal cabinet minister reported that, hackers, perhaps from China, compromised computers in two Canadian government departments in early January 2011. According to the CBC and other Canadian news organizations, a technique that is sometimes known as “executive spear phishing” was utilized. At the same time, other employees in the departments received e-mails that falsely appeared to come from the senior officials that included malicious Adobe PDF attachments. Reports indicate the attackers were targeting financial records.