Aug 19 2008

Adobe Flash Ad Hack and Gmail Supposed Hack

Category: Linux, Windows, Workzerolove @ 11:57 pm

Idiots er people are using Flash apps to hijack the clipboard putting a url in the clipboard that won’t go away till the browser is closed. This effects Firefox, Opera, IE, and Safari even on Linux and Mac. By seizing control of the clipboard they are able to place a URL to a fake anti virus program.

These have been showing up on sites such as Newsweek, Digg, and MSNBC.com. They are showing up in forums and in comments on blogs. So if you go to a page and all the sudden every time you right click and paste or cntrl + v something and you see a URL, unless you put it there do NOT go it.

If you want to test this out go here Aviv Raff a Security Researcher has created a proof of concept. This will insert http://www.evil.com into your clipboard and will NOT go away till you close out the browser. So click THIS LINK HERE to test.

If you are interested in knowing how this works, I’ll tell ya. It uses a continuous loop within flash that calls the command setClipboard. Closing the Tab or Browser will break the loop and allow you to copy and paste again.

So once again they are betting on the fact that some /luser will actually go to the site, download and install the software. Guess what… People have done it! I guess you could also exploit this if the person had something like I don’t know… maybe a Clipboard monitor that ran or did something like download automatic.  Either way be careful.

Now Gmail, the exploit is not out yet. It will be soon but seems Google has paid enough attention to add to your Gmail settings. The setting you are looking for is under Settings -> General scroll to the bottom and select Always use https. Do this because just going to https://www.gmail.com does NOT work. This only secures the authentication and not the rest of the data.  This one I take from Nike and tell ya, Just Do It!

Share:
  • Digg
  • del.icio.us
  • Facebook
  • Google
  • E-mail this story to a friend!
  • Fark
  • Furl
  • LinkedIn
  • Live
  • Pownce
  • Print this article!
  • Propeller
  • Reddit
  • Slashdot
  • SphereIt
  • StumbleUpon
  • Technorati
  • TwitThis
  • MySpace

Tags: , , ,


Aug 18 2008

msnbc.com – BREAKING NEWS: VIRUS Alert

Category: Spamassassin, Windows, Workzerolove @ 11:56 pm

Well we have another one following on the heals of the CNN Alert and CNN.com Daily Top 10. These are the same and have links to download an updated flash player. The flash player is NOT flash player at all but a trojan.

Some examples of the Subject:

msnbc.com - BREAKING NEWS: All Baseball Players May Be Indicted For Steroid Abuse

msnbc.com - BREAKING NEWS: SJC Loosens Handgun Control To Stimulate Economy

msnbc.com - BREAKING NEWS: Elizabeth Taylor found murdered at home

msnbc.com - BREAKING NEWS: Nature Did Not Connect the Funny Bone to the Satire Bone

They are also starting a BBC NEWS and just a breaking news. None of the From: fields are msnbc, cnn, or BBC. So lets just start calling this the news alert virus. These viruses are based on the assumption that someone they are sending to is signed up to receive the alert. Without looking just clicking links, I know for one I am signed up to receive some of these type of alerts. I guess one of the things that have saved me is I only receive email in plain text and I do not click on the links if they are not from the sending domain. For instance in one of the breaking news from msnbc.com the link goes to www.4×4.co.rs and well this is NOT msnbc.com. So some tips:

If you receive breaking news alerts instead of clicking the link move your mouse over the link and copy the shortcut. Open your web browser and paste it into the web browsers URL field. If the URL is NOT to the site the email came from DO NOT GO TO IT. Delete it from the URL and delete the email.

Remember folks this is a simple one. If you are NOT expecting the email do not open it, especially if it has an attachment. If it is from someone you know and it has an attachment call them and ask “Hey what is this your sending me” if they do not know then do NOT open it. It is just common sense.

If you go to a web site and it wants you to update any software go to the original site to update it. For instance all these trojans want you to update FLASH Player. Go to the Adobe download site at http://www.adobe.com/products/flashplayer/ and update your flash player. Do NOT update it from a web site you do not know. You should never install and or update software from a web site that you do not know.

Others:
http://www.securitywatch.co.uk/2008/08/13/msnbccom-breaking-news-spam/
http://blog.mxlab.be/2008/08/13/msnbccom-breaking-news/
http://www.securitywatch.co.uk/2008/08/13/msnbccom-breaking-news-spam/
http://www.securitymanagement.com/news/beware-msnbc-com-breaking-news-spam-e-mails-004502
http://securitylabs.websense.com/content/Alerts/3159.aspx

Share:
  • Digg
  • del.icio.us
  • Facebook
  • Google
  • E-mail this story to a friend!
  • Fark
  • Furl
  • LinkedIn
  • Live
  • Pownce
  • Print this article!
  • Propeller
  • Reddit
  • Slashdot
  • SphereIt
  • StumbleUpon
  • Technorati
  • TwitThis
  • MySpace

Tags: , , , , , , , ,


Aug 08 2008

CNN Alerts: My Custom Alert - Virus Alert!

Category: Spamassassin, Windows, Workzerolove @ 10:32 am

Follow up to yesterdays post about CNN.Com Daily Top 10, today we have a new one. This one has the subject of CNN Alerts: My Custom Alert. The email “From” address is random, and the content looks legit except for the Full Story link. This is the one that takes you to the site that immediately ask for you to install an updated version of flash. This is the virus, the payload…. This virus is part of the Rustock Rootkit and Spam Bot.

Share:
  • Digg
  • del.icio.us
  • Facebook
  • Google
  • E-mail this story to a friend!
  • Fark
  • Furl
  • LinkedIn
  • Live
  • Pownce
  • Print this article!
  • Propeller
  • Reddit
  • Slashdot
  • SphereIt
  • StumbleUpon
  • Technorati
  • TwitThis
  • MySpace

Tags: , , ,


Aug 03 2008

Follow Up - DNS Vulnerability

Category: Linux, Windowszerolove @ 12:57 am

Follow up to “Oops DNS Attack Disclosed! And once again DJB…” there is now a working exploit out. It is an exploit using MetaSploit, a tool used to conduct security vulnerability research. You can also test your network using Nessus by Tenable Network Security.

The released exploit is available at the MetaSploit trac here.

This is now being exploited in the wild. Now here is an issue I ran into. I updated our Bind servers and then tested and noticed we were still vulnerable. How could this be.. I was getting pissed then I noticed.

query-source port 53;

So check your /etc/named.conf and check for both

query-source port 53;
query-source-v6 port 53;

Share:

Tags: ,


Jul 30 2008

UPS, FedEx, and US Customs Email Virus Alert!

Category: Spamassassin, Windows, Workzerolove @ 12:27 am

In the last week I’ve seen this hit in the wild several time and at several locations. At one location this virus infecting over 200 computers. The email arrives as follows

From: United Parcel Service [user@not_ups.com]

Subject: UPS Paket N473133142

Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office

Your UPS

Attachment: UPS_Invoice.zip

There is a variant of this from FedEx and from United States Customs. They have even posted this response to the email at http://www.customs.gov/xp/cgov/newsroom/alerts/email_virus.xml

Good afternoon,

We have received a parcel for you, sent from France on July 9. Please fill out the customs declaration attached to this message and send it to us by mail or fax. The address and the fax number are at the bottom of the declaration form.

Kind regards,

Rolland Hanna

Your Customs Service

The ones I have seen install a Trojan that then begins sending out Spam. They have all been part of the Cutwail Botnet. This botnet includes around 150,000 computers, sending over 16 Billion Spam emails a day.

None of the Virus scanners I had could clean this, and all the information is about older version of the cutwail virus. I always recommend if you get infected with any type of trojan/virus like this to just do a reinstall, never ever trust an infected machine again. I had this cleaned or so I thought on one computer until I rebooted and it was found again by Trend. Trend could not clean or quarantine this virus.

This version created a file in c:\windows\system32\drivers\tcpsr.sys and c:\windows\system32\drivers\Win32x.sys, there was also several registry keys created I did not copy these down before the reinstall.

Side note:

Let me just point this out also. None of the systems that where infected are protected by the Spam and Virus protection provided by my employer. I have checked the logs on all of our spam/virus gateway systems and this virus has been stopped all along. If you own your own domain, and want Spam and Virus protection, you can contact me for pricing.

Share:
  • Digg
  • del.icio.us
  • Facebook
  • Google
  • E-mail this story to a friend!
  • Fark
  • Furl
  • LinkedIn
  • Live
  • Pownce
  • Print this article!
  • Propeller
  • Reddit
  • Slashdot
  • SphereIt
  • StumbleUpon
  • Technorati
  • TwitThis
  • MySpace

Tags:


Next Page »