Showing posts with label Exploit Kit Intelligence. Show all posts
Showing posts with label Exploit Kit Intelligence. Show all posts

Thursday, February 9, 2012

A Time-based Analysis of Rich Text Format Manipulations: A Deeper Analysis of the RTF Exploit CVE-2010-3333

http://www.sophos.com/en-us/why-sophos/our-people/technical-papers.aspx

Malware authors are still looking for new ways to distribute an old RTF vulnerability (CVE-2010-3333). This SophosLabs technical paper 'A time-based analysis of Rich Text Format manipulations' will explore, over a long period of time, the way that the malware authors attempt to evade detection.

Download 'A time-based analysis of Rich Text Format manipulations'

By Paul Baccas, Senior Threat Researcher, SophosLabs UK, 2011

Monday, December 12, 2011

Exploit Kit Intelligence: Blackhole 1.2.1 & Java

Building on top of the reports by Brain Kerbs over at Krebs on Security....

Steven over at the XyliBox blog outlines the recent update to the Blackhole Exploit Kit.
BlackHole 1.2.1:
1. Added Java Rhino exploit [CVE-2011-3544], working silently on all browsers and OS, this increased success rate.
2. Java SMB, Java Skyline, Java Trust removed for no need (Java Rhino covers the whole range of vulnerable JRE from these exploits)
According to just the single instance of Blackhole outlined by Steven, the CVE-2011-3544 exploit was responsible for over 83% of the successful infections made by this specific kit. That is huge!

PDF exploits followed Java with just 11% of the successful hits. Very likely due to Adobe works to harden Adobe X against PDF exploitation.

------------------------------------------------------------------------

CVE-2011-3544: Oracle Java Applet Rhino Script Engine Remote Code Execution
http://schierlm.users.sourceforge.net/CVE-2011-3544.html

------------------------------------------------------------------------

Oracle Java SE Critical Patch Update Advisory - October 2011
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html
This Critical Patch Update contains 20 new security fixes for Oracle Java SE - including CVE-2011-3544.
Users are recommended to update to Java 6 Update 29 or Java 1 Update 1 to close the CVE-2011-3544 vulnerability.

Wednesday, September 28, 2011

Exploit Kit Intelligence: Five Software Packages = 90%+ Of The Problem

Via CSIS -

When a Microsoft Windows machine gets infected by viruses/malware it does so mainly because users forget to update the Java JRE, Adobe Reader/Acrobat and Adobe Flash. This is revealed by a survey conducted by CSIS Security Group A/S.

Basis of the Study
CSIS has over a period of almost three months actively collected real time data from various so-called exploit kits. An exploit kit is a commercial hacker toolbox that is actively exploited by computer criminals who take advantage of vulnerabilities in popular software. Up to 85 % of all virus infections occur as a result of drive-by attacks automated via commercial exploit kits.

[...]

Most Vulnerable Programs
On the basis of the total statistical data of this study it is documented that following products frequently are abused by malware in order to infect Windows machines: Java JRE, Adobe Reader / Acrobat, Adobe Flash and Microsoft Internet Explorer.

[...]

Vulnerabilities Abused
Among the vulnerabilities we have observed abused by the monitored exploit kits, we find:
  • CVE-2010-1885 - Microsoft Help & Support HCP
  • CVE-2010-1423 - Java Deployment Toolkit insufficient argument validation
  • CVE-2010-0886 - Java Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE
  • CVE-2010-0842 - Java JRE MixerSequencer Invalid Array Index Remote Code Execution Vulnerability
  • CVE-2010-0840 - Java trusted Methods Chaining Remote Code Execution Vulnerability
  • CVE-2009-1671 - Java buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll
  • CVE-2009-0927 - Adobe Reader Collab GetIcon
  • CVE-2008-2992 - Adobe Reader util.printf
  • CVE-2008-0655 - Adobe Reader CollectEmailInfo
  • CVE-2006-0003 - IE MDAC
  • CVE-2006-4704 - Microsoft Visual Studio 2005 WMI Object Broker Remote Code Execution Vulnerability
  • CVE-2004-0549 ShowModalDialog method and modifying the location to execute code

The Reason Why Patching is Essential!
The conclusion of this study is that as much as 99.8 % of all virus/malware infections caused by commercial exploit kits are a direct result of the lack of updating five specific software packages.


-------------------------------------------------------------------------

Great research by CSIS.

This builds on the body of knowledge presented by various researchers (e.g. Dan Guido & Mila Parkour), which suggest corporations should focus on the top 5 or 6 products at the desktop level as an effective method of combating exploit kits - at least in their current state.

The exploit kit authors will adapt their attacking method (i.e. technique, vulnerabilities used), as needed, to maintain levels of high infection rates. Therefore, we must adapt as well. This is only the beginning.

Saturday, August 20, 2011

Exploit Pack Intelligence: An Overview of Exploit Packs (Update 13)

Mila Parkour (@snowfl0w) has released her latest update to the Exploit Pack spreadsheet.

It includes the latest exploit intelligence on 53 different packs (in alphabetical order):
  1. Best Pack
  2. Blackhole Exploit 1.0
  3. Blackhole Exploit 1.1
  4. Bleeding Life 2.0
  5. Bleeding Life 3.0
  6. Bomba
  7. CRIMEPACK 2.2.1
  8. CRIMEPACK 2.2.8
  9. CRIMEPACK 3.0
  10. CRIMEPACK 3.1.3
  11. Dloader
  12. EL Fiiesta
  13. Eleonore 1.3.2
  14. Eleonore 1.4.1
  15. Eleonore 1.4.4 Moded
  16. Eleonore 1.6.3a
  17. Eleonore 1.6.4
  18. Eleonore 1.6.5
  19. Fragus 1
  20. Icepack
  21. Impassioned Framework 1.0
  22. Incognito
  23. iPack
  24. JustExploit
  25. Katrin
  26. Merry Christmas Pack
  27. Liberty 1.0.7
  28. Liberty 2.1.0*
  29. LinuQ pack
  30. Lupit
  31. Mpack
  32. Mushroom/unknown
  33. Open Source Exploit (Metapack)
  34. Papka
  35. Phoenix 2.0
  36. Phoenix 2.1
  37. Phoenix 2.2
  38. Phoenix 2.3
  39. Phoenix 2.4
  40. Phoenix 2.5
  41. Phoenix 2.7
  42. Robopak
  43. Salo pack
  44. Sava Pack
  45. SEO Sploit pack
  46. Siberia
  47. T-Iframer
  48. Unique Pack Sploit 2.1
  49. Webattack
  50. Yes Exploit 3.0RC
  51. Zero Pack
  52. Zombie Infection kit
  53. Zopack

Monday, October 18, 2010

Exploit Kit Intelligence

Mila Parkour over at the Contagio Blog has released update 7 of her "Overview of Exploit Packs" spreadsheet. This spreadsheet pulls together information from various locations and outlines which exploits are being used by various exploit kits (including slang / abbreviated names of exploits with CVEs).

An Overview of Exploit Packs (Update 7) XLS
http://www.mediafire.com/?7lfae018l5fcuwa