http://www.sophos.com/en-us/why-sophos/our-people/technical-papers.aspx
Malware authors are still looking for new ways to distribute an old RTF vulnerability (CVE-2010-3333). This SophosLabs technical paper 'A time-based analysis of Rich Text Format manipulations' will explore, over a long period of time, the way that the malware authors attempt to evade detection.
Download 'A time-based analysis of Rich Text Format manipulations'
By Paul Baccas, Senior Threat Researcher, SophosLabs UK, 2011
Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Showing posts with label Exploit Kit Intelligence. Show all posts
Showing posts with label Exploit Kit Intelligence. Show all posts
Thursday, February 9, 2012
Monday, December 12, 2011
Exploit Kit Intelligence: Blackhole 1.2.1 & Java
Building on top of the reports by Brain Kerbs over at Krebs on Security....
Steven over at the XyliBox blog outlines the recent update to the Blackhole Exploit Kit.
PDF exploits followed Java with just 11% of the successful hits. Very likely due to Adobe works to harden Adobe X against PDF exploitation.
------------------------------------------------------------------------
CVE-2011-3544: Oracle Java Applet Rhino Script Engine Remote Code Execution
http://schierlm.users.sourceforge.net/CVE-2011-3544.html
------------------------------------------------------------------------
Oracle Java SE Critical Patch Update Advisory - October 2011
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html
Steven over at the XyliBox blog outlines the recent update to the Blackhole Exploit Kit.
BlackHole 1.2.1:According to just the single instance of Blackhole outlined by Steven, the CVE-2011-3544 exploit was responsible for over 83% of the successful infections made by this specific kit. That is huge!
1. Added Java Rhino exploit [CVE-2011-3544], working silently on all browsers and OS, this increased success rate.
2. Java SMB, Java Skyline, Java Trust removed for no need (Java Rhino covers the whole range of vulnerable JRE from these exploits)
PDF exploits followed Java with just 11% of the successful hits. Very likely due to Adobe works to harden Adobe X against PDF exploitation.
------------------------------------------------------------------------
CVE-2011-3544: Oracle Java Applet Rhino Script Engine Remote Code Execution
http://schierlm.users.sourceforge.net/CVE-2011-3544.html
------------------------------------------------------------------------
Oracle Java SE Critical Patch Update Advisory - October 2011
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html
This Critical Patch Update contains 20 new security fixes for Oracle Java SE - including CVE-2011-3544.Users are recommended to update to Java 6 Update 29 or Java 1 Update 1 to close the CVE-2011-3544 vulnerability.
Wednesday, September 28, 2011
Exploit Kit Intelligence: Five Software Packages = 90%+ Of The Problem
Via CSIS -
When a Microsoft Windows machine gets infected by viruses/malware it does so mainly because users forget to update the Java JRE, Adobe Reader/Acrobat and Adobe Flash. This is revealed by a survey conducted by CSIS Security Group A/S.
Basis of the Study
CSIS has over a period of almost three months actively collected real time data from various so-called exploit kits. An exploit kit is a commercial hacker toolbox that is actively exploited by computer criminals who take advantage of vulnerabilities in popular software. Up to 85 % of all virus infections occur as a result of drive-by attacks automated via commercial exploit kits.
[...]
Most Vulnerable Programs
On the basis of the total statistical data of this study it is documented that following products frequently are abused by malware in order to infect Windows machines: Java JRE, Adobe Reader / Acrobat, Adobe Flash and Microsoft Internet Explorer.
[...]
Vulnerabilities Abused
Among the vulnerabilities we have observed abused by the monitored exploit kits, we find:
The Reason Why Patching is Essential!
The conclusion of this study is that as much as 99.8 % of all virus/malware infections caused by commercial exploit kits are a direct result of the lack of updating five specific software packages.
-------------------------------------------------------------------------
Great research by CSIS.
This builds on the body of knowledge presented by various researchers (e.g. Dan Guido & Mila Parkour), which suggest corporations should focus on the top 5 or 6 products at the desktop level as an effective method of combating exploit kits - at least in their current state.
The exploit kit authors will adapt their attacking method (i.e. technique, vulnerabilities used), as needed, to maintain levels of high infection rates. Therefore, we must adapt as well. This is only the beginning.
When a Microsoft Windows machine gets infected by viruses/malware it does so mainly because users forget to update the Java JRE, Adobe Reader/Acrobat and Adobe Flash. This is revealed by a survey conducted by CSIS Security Group A/S.
Basis of the Study
CSIS has over a period of almost three months actively collected real time data from various so-called exploit kits. An exploit kit is a commercial hacker toolbox that is actively exploited by computer criminals who take advantage of vulnerabilities in popular software. Up to 85 % of all virus infections occur as a result of drive-by attacks automated via commercial exploit kits.
[...]
Most Vulnerable Programs
On the basis of the total statistical data of this study it is documented that following products frequently are abused by malware in order to infect Windows machines: Java JRE, Adobe Reader / Acrobat, Adobe Flash and Microsoft Internet Explorer.
[...]
Vulnerabilities Abused
Among the vulnerabilities we have observed abused by the monitored exploit kits, we find:
- CVE-2010-1885 - Microsoft Help & Support HCP
- CVE-2010-1423 - Java Deployment Toolkit insufficient argument validation
- CVE-2010-0886 - Java Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE
- CVE-2010-0842 - Java JRE MixerSequencer Invalid Array Index Remote Code Execution Vulnerability
- CVE-2010-0840 - Java trusted Methods Chaining Remote Code Execution Vulnerability
- CVE-2009-1671 - Java buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll
- CVE-2009-0927 - Adobe Reader Collab GetIcon
- CVE-2008-2992 - Adobe Reader util.printf
- CVE-2008-0655 - Adobe Reader CollectEmailInfo
- CVE-2006-0003 - IE MDAC
- CVE-2006-4704 - Microsoft Visual Studio 2005 WMI Object Broker Remote Code Execution Vulnerability
- CVE-2004-0549 ShowModalDialog method and modifying the location to execute code
The Reason Why Patching is Essential!
The conclusion of this study is that as much as 99.8 % of all virus/malware infections caused by commercial exploit kits are a direct result of the lack of updating five specific software packages.
-------------------------------------------------------------------------
Great research by CSIS.
This builds on the body of knowledge presented by various researchers (e.g. Dan Guido & Mila Parkour), which suggest corporations should focus on the top 5 or 6 products at the desktop level as an effective method of combating exploit kits - at least in their current state.
The exploit kit authors will adapt their attacking method (i.e. technique, vulnerabilities used), as needed, to maintain levels of high infection rates. Therefore, we must adapt as well. This is only the beginning.
Saturday, August 20, 2011
Exploit Pack Intelligence: An Overview of Exploit Packs (Update 13)
Mila Parkour (@snowfl0w) has released her latest update to the Exploit Pack spreadsheet.
It includes the latest exploit intelligence on 53 different packs (in alphabetical order):
It includes the latest exploit intelligence on 53 different packs (in alphabetical order):
- Best Pack
- Blackhole Exploit 1.0
- Blackhole Exploit 1.1
- Bleeding Life 2.0
- Bleeding Life 3.0
- Bomba
- CRIMEPACK 2.2.1
- CRIMEPACK 2.2.8
- CRIMEPACK 3.0
- CRIMEPACK 3.1.3
- Dloader
- EL Fiiesta
- Eleonore 1.3.2
- Eleonore 1.4.1
- Eleonore 1.4.4 Moded
- Eleonore 1.6.3a
- Eleonore 1.6.4
- Eleonore 1.6.5
- Fragus 1
- Icepack
- Impassioned Framework 1.0
- Incognito
- iPack
- JustExploit
- Katrin
- Merry Christmas Pack
- Liberty 1.0.7
- Liberty 2.1.0*
- LinuQ pack
- Lupit
- Mpack
- Mushroom/unknown
- Open Source Exploit (Metapack)
- Papka
- Phoenix 2.0
- Phoenix 2.1
- Phoenix 2.2
- Phoenix 2.3
- Phoenix 2.4
- Phoenix 2.5
- Phoenix 2.7
- Robopak
- Salo pack
- Sava Pack
- SEO Sploit pack
- Siberia
- T-Iframer
- Unique Pack Sploit 2.1
- Webattack
- Yes Exploit 3.0RC
- Zero Pack
- Zombie Infection kit
- Zopack
Monday, October 18, 2010
Exploit Kit Intelligence
Mila Parkour over at the Contagio Blog has released update 7 of her "Overview of Exploit Packs" spreadsheet. This spreadsheet pulls together information from various locations and outlines which exploits are being used by various exploit kits (including slang / abbreviated names of exploits with CVEs).
An Overview of Exploit Packs (Update 7) XLS
http://www.mediafire.com/?7lfae018l5fcuwa
An Overview of Exploit Packs (Update 7) XLS
http://www.mediafire.com/?7lfae018l5fcuwa
Subscribe to:
Posts (Atom)