13.11.08

Firefox 3.0.4, Firefox 2.0.0.18 And Seamonkey 1.1.13 Released, 11 Security Vulnerabilities Patched, 4 Of Them Critical


Mozilla has released a new version of its flagship Firefox browser to fix a total of 11 vulnerabilities that expose users to code execution, information stealing or denial-of-service attacks. Four of the 11 flaws covered with the new Firefox 3.0.4 are rated “critical” because of the risk of code execution attacks via specially rigged Web pages.
The four critical vulnerabilities are:
MFSA 2008-55 Crash and remote code execution in nsFrameManager. A vulnerability in part of Mozilla’s DOM constructing code can be exploited by modifying certain properties of a file input element before it has finished initializing. When the blur method of the modified input element is called, uninitialized memory is accessed by the browser, resulting in a crash. This crash may be used by an attacker to run arbitrary code on a victim’s computer.
MFSA 2008-54 Buffer overflow in http-index-format parser. This is a flaw in the way Mozilla parses the http-index-format MIME type. By sending a specially crafted 200 header line in the HTTP index response, an attacker can cause the browser to crash and run arbitrary code on the victim’s computer.
MFSA 2008-53 XSS and JavaScript privilege escalation via session restore. The browser’s session restore feature can be used to violate the same-origin policy and run JavaScript in the context of another site. Any otherwise unexploitable crash can be used to force the user into the session restore state. This vulnerability could also be used by an attacker to run arbitrary JavaScript with chrome privileges.
MFSA 2008-52 Crashes with evidence of memory corruption. Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.
The Firefox update also fixes the following issues:
MFSA 2008-58 Parsing error in E4X default namespace.
MFSA 2008-57 -moz-binding property bypasses security checks on codebase principals.
MFSA 2008-56 nsXMLHttpRequest::NotifyEventListeners() same-origin violation.
MFSA 2008-51 file: URIs inherit chrome privileges when opened from chrome.
MFSA 2008-47 Information stealing via local shortcut files.
Mozilla recommends that users who still run FF2 upgrade to FF3 as soon as possible.

11.11.08

Introducing new vulnerability scanner

GFI LANguard N.S.S. makes use of state of the art vulnerability check databases based on OVAL and SANS Top 20, providing over 15,000 vulnerability assessments when your network is scanned. GFI LANguard N.S.S. gives you the information and tools you need to perform multi-platform scans across all environments, to analyze your network’s security health and effectively install and manage patches on all machines across different operating systems and in different languages. This results in a consistently configured environment that is secure against all vulnerabilities.
QualysGuard® Vulnerability Management (VM) automates the lifecycle of network auditing and vulnerability management across the enterprise, including network discovery and mapping, asset prioritization, vulnerability assessment reporting and remediation tracking according to business risk. Driven by the most comprehensive vulnerability KnowledgeBase in the industry, QualysGuard delivers continuous protection against the latest worms and security threats without the substantial cost, resource and deployment issues associated with traditional software. As an on demand Software-as-a-Service (SaaS) solution, there is no infrastructure to deploy or manage.
QualysGuard VM enables small to large organizations to effectively manage their vulnerabilities and maintain control over their network security with centralized reports, verified remedies, and full remediation workflow capabilities with trouble tickets. QualysGuard provides comprehensive reports on vulnerabilities including severity levels, time to fix estimates and impact on business, plus trend analysis on security issues.
By continuously and proactively .
Nessus 3.0 ( for windows , linux and others )
Passive vulnerability scanning is the process of monitoring network traffic at the packet layer to determine topology, services, and vulnerabilities. This document will discuss the technology of passive vulnerability scanning, its deployment issues, and its many applications. It will also compare passive vulnerability scanning technology to network intrusion detection technology. Example "plugins" used to detect network vulnerabilities is also included. This paper assumes the reader has a basic knowledge of TCP/IP networking, network intrusion detection, and vulnerability scanning.
Tenable offers the Passive Vulnerability Scanner (formerly NeVO). This paper not only serves as an introduction to passive vulnerability scanning, it also includes many examples specific to the Passive Vulnerability Scanner.

Barack Obama used for a malware spam attack

Archive:

Malware authors haven’t been slow reacting to the latest US elections news and President Elect Barrack Obama is already being used as a lure for infecting unsuspecting internet users.Here is a typical piece of spam that is being seen in Sophos spam traps around the world:



Were you to click on the link you would find yourself on a website pretending to be a news site offering information and a video of Barack Obama’s historic win. However, the site tries to fool you into installing what it claims is an update to Adobe Flash to view the video.

The file referenced is detected by Sophos as a piece of malware called Mal/Behav-027. It’s likely that the cybercriminals behind this attack will rotate the malware being served up by this dangerous website - so we will continue to monitor its activity as well as block access to the infected webpage with our web protection solutions.

9.11.08

Latest Virus Description !!

Trojan-Downloader.JS.Small.fi 29 Oct 2008 20:03:00 +030This Trojan downloads other files via the Internet and launches them for execution on the victim machine. The program is an HTML page which contains Java Script scenarios. It is 1432 bytes in size.
Trojan-PSW.Win32.OnLineGames.sxa 29 Oct 2008 20:01:00 +030This malicious program is a Trojan. It is a Windows PE EXE file. It is 118103 bytes in size. Installation The Trojan copies its executable file to the Windows system directory: %System%\kavo.exe In order to ensure that the Trojan is launched automatically each time the system is restarted, the…
Trojan-PSW.Win32.OnLineGames.lfi 29 Oct 2008 20:00:00 +030This malicious program is a Trojan. It is a Windows PE EXE file. It is 123873 bytes in size. Installation The Trojan copies its executable file to the Windows system directory: %System%\amvo.exe In order to ensure that the Trojan is launched automatically each time the system is restarted, the…
Trojan-Downloader_Win32_Agent.nmi 29 Oct 2008 19:59:00 +030This Trojan downloads another program via the Internet and launches it on the victim machine without the user’s knowledge or consent. It is a Windows PE EXE file. The size of infected files can range from 18KB to 47KB.
Trojan-Downloader.Win32.Braidupdate.c 28 Oct 2008 15:54:00 +030This Trojan downloads another program via the Internet and launches it on the victim machine without the user’s knowledge or consent. It is a Windows PE EXE file. It is 79360 bytes in size. It is written in C++. Installation In order to ensure that the Trojan is launched automatically each…
Trojan-Downloader.JS.Agent.sg 28 Oct 2008 15:52:00 +030This Trojan downloads other files via the Internet and launches them for execution on the victim machine. It is an HTML page which contains Visual Basic Script and Java Script. It is 677 bytes in size.
Trojan-GameThief.Win32.OnLineGames.tnys 28 Oct 2008 15:48:00 +030This Trojan is designed to steal account data from the online game LineAge2. It is a Windows PE EXE file. It is 654848 bytes in size.

8.11.08

White House Network Hacked By Chinese On Multiple Occasions


According to Demetri Sevastopulo from Financial Times, Chinese hackers have penetrated the White House computer network on multiple occasions, and obtained e-mails between government officials. US officials say Chinese hackers have raided White House email archives multiple times. The Financial Times reports some people it describes as “US government cyber experts” suspect the raids were sponsored by the Chinese regime.
Each attack cracked the unclassified network’s defenses for a short time. The classified network remained secure, according to Financial Times. The official said the Chinese cyber attacks had the hallmarks of the “grain of sands” approach taken by Chinese intelligence, which involves obtaining and pouring through lots of - often low-level - information to find a few nuggets.
“For a short period of time, they successfully breach a wall, and then you rebuild the wall  …  it is not as if they have continued access. It is constant cat and mouse on this stuff,” the source reportedly said.
The FT’s revelations came just days after Newsweek reported that both the Obama and McCain campaigns had been hacked from overseas, with large amounts of data downloaded, apparently in an attempt to track the candidates’ evolving policy positions. This could of course potentially help the unnamed foreign entities in future negotiations.
The campaign attacks were picked up by the authorities, with the FBI and the Secret Service notifying the Obama campaign back in August that what staffers thought was a virus was something more sinister.
“You have a problem way bigger than what you understand,” an FBI agent reportedly told Obama staff members. “You have been compromised, and a serious amount of files have been loaded off your system.”
The US has increased efforts to tackle cyber security, particularly since Chinese hackers believed to be associated with the Peoples’ Liberation Army last year perpetrated a major attack on the Pentagon.
US military computer experts battled for weeks against a sustained attack that eventually overcame the Pentagon’s defenses. The cyber attackers managed to obtain information and emails traffic from the unclassified computer system that supports Robert Gates, the defense secretary. Pentagon IT technicians were forced to take the network down for days to conduct repairs.
Concerns about Chinese hacking last year prompted President George W. Bush to tell reporters ahead of a meeting with President Hu Jintao of China that he might raise the issue with countries of concern.
Over the past year, the US government has tightened restrictions on officials using BlackBerrys and computers overseas, particularly in Russia and China, and sometimes bars them from removing the equipment from US government aircraft in the country.
In another incident, US government cyber investigators have determined that an attack this summer on the Obama and McCain campaign computer networks also originated in China. Details of the intrusion were first reported by Newsweek.
”There is no doubt that foreign governments are actively targeting cyber space not only for sensitive information but to influence our most sensitive processes such as the US presidential election,” said Sami Saydjari, head of the Cyber Defence Agency, a private company that advises government on hacking.
While the US has raised concerns about cyber attacks, many governments believe the US is also engaged in electronic spying. Bob Woodward, the veteran Washington Post reporter, this year revealed that the US had been spying on the Iraqi government.

Highly Critical Vulnerabilities In VLC Media Player

The issues, reported in versions 0.5.0 through 0.9.5, could let hackers take complete control of compromised machines through rigged media files. VideoLAN, the open-source group that manages the VLC project, has released patches and strongly recommends that users upgrade to VLC media player 0.9.6.
Exploitation of this issue requires the user to explicitly open a specially crafted file. As with any media player, the standard advice is to avoid from opening files from untrusted third parties or accessing untrusted remote sites.

Details:

Summary : Buffer overflows in VLC RealText and CUE demuxers
Date : November 2008
Affected versions : VLC media player 0.9.5 down to 0.5.0
ID : VideoLAN-SA-0810
CVE reference : CVE-2008-xxxx, CVE-2008-xxxx

Solution

VLC media player 0.9.6 addresses this issue. Patches for older versions are available from the official VLC source code repository 0.9-bugfix branch.

Daily Report

7.11.08

Break news

Facebook “added friend confirmation” Malicious Spam


Websense Security Labs has discovered another round of malicious Facebook messages. This campaign is another visual social-engineering spam campaign which tries to visually trick users into believing that the message is a legitimate added friend confirmation. The “From” address in the message is spoofed to make it look as if it was sent from Facebook, and the links look like they lead to Facebook.


In previous Facebook “add friend” Malicious Spam campaign, spammers included a malicious zip attachment that claimed to contain a picture, to entice the recipient to double-click on it. From a spammer’s perspective, the likelihood of attack success decreases when antivirus software picks up the attachment. If not picked up by antivirus software, then content learning technologies filter such messages and their attachments after receiving a certain volume of similar messages.


In order to maintain their attack over a longer time period with increased success rates, spammers have switched their tactics by including links to an external Web site. The use of external links in emails makes antivirus detection tougher, as not all antivirus software has the ability to scan or detect links included in email messages. Also, from a spammer’s perspective, using links consisting of compromised ‘legitimate’ domains hosting malware as a lure increases the success rate, as this is more likely to bypass security filters that rely heavily on reputation services.


Websense Security Labs sees these tactics adopted by spammers and malware authors as an ongoing trend, increasingly targeting Web 2.0 sites to carry out a wide range of attacks.


The links in the message actually lead to a malicious executable named “update.exe” (SHA1: a4dc17d1bcb191af75afedddf60aecbc2af2a37f).


This malicious executable has a very low AV detection. When run, the malicious executable steals data from its victim, establishing a connection with an IRC botnet.

Break News

After Election: Files Stolen In Obama And McCain Campaigns Cyberattack, Obama-themed Malware Makes Rounds

According to an article published Wednesday by Newsweek, hackers broke into computer systems of both the Barack Obama and John McCain campaigns and stole a large amount of data
Officials with the FBI and the Secret Service notified Obama staffers in August of the breach after tech consultants for the campaign detected what they thought at the time was a computer virus. “You have a problem way bigger than what you understand,” an FBI agent told Obama staff members. “You have been compromised, and a serious amount of files have been loaded off your system.”
White House chief of staff Josh Bolten also weighed in, telling an Obama campaign chief: “You have a real problem…and you have to deal with it.”
Investigators told Obama aides that the McCain computer systems had been similarly compromised. A senior McCain official confirmed to Newsweek that the campaign’s network had been hacked and the FBI was investigating.
According to investigators at the FBI and the White House, a “foreign entity or organization” is believed to be behind the attacks in an attempt to “gather information on the evolution of both camps’ policy positions.” The information could prove useful in negotiations with a future administration. The investigators told the Obama team the hack wasn’t carried out by political opponents.
Representatives of both campaigns weren’t available to comment on the Newsweek report.
Cyber criminals are actively capitalizing on Barack Obama’s victory in the US presidential race. Within 12 hours of his acceptance speech Tuesday night, net users were being treated to scams involving Google AdWords and prodigious volumes of spam.
The spam comes masked as dispatches from legitimate news sources, including the BBC and CNN, and invite readers to click a link to view a video of Obama accepting his country’s vote. Those who take the bait are sent to a spoof page of the news site that claims they need to update their Adobe Flash Player before viewing the speech.
In fact, Adobe_flash9.exe installs the notorious Trojan-PSW:W32/Papras.CL, according to anti-virus provider F-Secure. Earlier Wednesday, just 14 of the 36 major anti-virus programs detected the trojan, according to an analysis from VirusTotal. Once installed, the malware, which cloaks itself in a rootkit, logs passwords for bank sites and other sensitive information and sends them to a server located in Ukraine.
The fraudulent news sites are being hosted on a fast-flux network of infected machines, according to CyberCrime & Doing Time blog. Cloudmark, a company that provides spam filtering service, has already seen more than 10 million of the spam messages, according to the Zero Day blog.
Scammers were also exploiting the now-completed presidential race using Google’s Sponsored Links. Early Wednesday, searches related to the President Elect returned paid results that included links to websites that tried to install malware on end users’ machines, The Times Online reported. The malicious ads were no longer appearing on Google at time of writing.
The barrage of Obama-themed attacks are part of a broader trend of using current events to trick people into following links that lead to attacks. The US presidential election has been a favorite source of such attacks over the past year, with the names of candidates such as John McCain, Hillary Clinton, Ron Paul and Mike Huckabee all invoked.
source : cyberinsecure.com

Old Facebook Worm Using New Ways To Spread By Abusing Google Reader And Picasa Websites


Notice :

Researchers at unified threat management vendor Fortinet noticed that a program similar to the Koobface worm had started using the Google Reader and Picasa websites to spread. In the attack, criminals host images that look like YouTube videos on the Google sites in hopes of tricking victims into downloading malicious Trojan software.
Hackers initially unleashed Koobface in late July, but Facebook’s security team soon slowed its spread by blocking the webites that were hosting the malicious Trojan software. That has prompted the criminals to change tactics. In this latest attack they have hosted files that appear to be YouTube videos on Picasa and Google Reader and used Facebook to send them to victims.
The links appear safe because they go to Google sites, but once the victim arrives on the Google Reader or Picasa page, he is invited to click on a video or a web link. The victim is then told he needs to download special codec decompression software to view the video. That software is actually a malicious Trojan Horse program, which is blocked by most anti-virus programs, according to Facebook.
It could be the cyber-criminals behind Koobface have deliberately misspelled their Facebook messages to further help them evade detection by filters. This latest attack do not use the self-copying worm code that Koobface used last August, but it could easily be added.
Koobface has been a top security concern at Facebook since July. The worm’s creators have used Facebook’s instant messaging feature and also hosted their malicious links on sites such as Tinyurl.com and Bloglines.
Security experts have long warned that the Web 2.0 mash-up model of allowing users to put together their own content from many different sources naturally creates many security problems. In part, this is because it allows anyone to post material on trustworthy domains such as Google.
Facebook is working with Google to shut down the problem, said Facebook spokesman Barry Schnitt.


Founded: 30 oct 2008