Friday, March 5, 2010

Why DRM Doesn’t Work

THE GEEK CODE

The Geek Code is basicly a (small) part of Internet history. When the author incarnation of the code back in '93, it was as a lark. Eventually, it evolved into the form you see online now and has remained virtually unchanged since that time.

The Code Looks Something As Below....

GED/J d-- s:++>: a-- C++(++++) ULU++ P+ L++ E---- W+(-) N+++ o+ K+++ w--- O- M+ V-- PS++>$ PE++>$ Y++ PGP++ t- 5+++ X++ R+++>$ tv+ b+ DI+++ D+++ G+++++ e++ h r-- y++**


This parody of the output created by the PGP program will attempt to universalize how you will see the Geek Code around the net. Your GEEK CODE BLOCK will look like the following:

-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GED/J d-- s:++>: a-- C++(++++) ULU++ P+ L++ E---- W+(-) N+++ o+ K+++ w---
O- M+ V-- PS++>$ PE++>$ Y++ PGP++ t- 5+++ X++ R+++>$ tv+ b+ DI+++ D+++
G+++++ e++ h r-- y++**
------END GEEK CODE BLOCK------

To Cerate A Code...
http://www.geekcode.com/geek.html






Thursday, March 4, 2010

Tutorial: Real Life HTTP Client-side Exploitation Example


Tutorial: Real Life HTTP Client-side Exploitation Example

This section illustrates an example of a real life attack conducted against an organization that resulted in loss of critical data for the organization.

In this attack, Acme Widgets Corporation suffered a major breach from attackers who were able to compromise their entire internal network infrastructure using two of the most powerful and common attack vectors today: Exploitation of client-side software and pass-the-hash attacks against Windows machines.

Step 0: Attacker Places Content on Trusted Site
In Step 0, the attacker begins by placing content on a trusted third-party website, such as a social networking, blogging, photo sharing, or video sharing website, or any other web server that hosts content posted by public users. The attacker's content includes exploitation code for unpatched client-side software.


Step 1: Client-Side Exploitation
In Step 1, a user on the internal Acme Widgets enterprise network surfs the Internet from a Windows machine that is running an unpatched client-side program, such as a media player (e.g., Real Player, Windows Media Player, iTunes, etc.), document display program (e.g., Acrobat Reader), or a component of an office suite (e.g., Microsoft Word, Excel, Powerpoint, etc.). Upon receiving the attacker's content from the site, the victim user's browser invokes the vulnerable client-side program passing it the attacker's exploit code. This exploit code allows the attacker to install or execute programs of the attacker's choosing on the victim machine, using the privileges of the user who ran the browser. The attack is partially mitigated because this victim user does not have administrator credentials on this system. Still, the attacker can run programs with those limited user privileges.


Step 2: Establish Reverse Shell Backdoor Using HTTPS
In Step 2, the attacker's exploit code installs a reverse shell backdoor program on the victim machine. This program gives the attacker command shell access of the victim machine, communicating between this system and the attacker using outbound HTTPS access from victim to attacker. The backdoor traffic therefore appears to be regular encrypted outbound web traffic as far as the enterprise firewall and network is concerned.


Steps 3 & 4: Dump Hashes and Use Pass-the-Hash Attack to Pivot
In Step 3, the attacker uses shell access of the initial victim system to load a local privilege escalation exploit program onto the victim machine. This program allows the attacker to jump from the limited privilege user account to full system privileges on this machine. Although vendors frequently release patches to stop local privilege escalation attacks, many organizations do not deploy such patches quickly, because such enterprises tend to focus exclusively on patching remotely exploitable flaws. The attacker now dumps the password hashes for all accounts on this local machine, including a local administrator account on the system.


In Step 4, instead of cracking the local administrator password, the attacker uses a Windows pass-the-hash program to authenticate to another Windows machine on the enterprise internal network, a fully patched client system on which this same victim user has full administrative privileges. Using NTLMv1 or NTLMv2, Windows machines authenticate network access for the Server Message Block (SMB) protocol based on user hashes and not the passwords themselves, allowing the attacker to get access to the file system or run programs on the fully patched system with local administrator privileges. Using these privileges, the attacker now dumps the password hashes for all local accounts on this fully patched Windows machine.

Step 5: Pass the Hash to Compromise Domain Controller
In Step 5, the attacker uses a password hash from a local account on the fully patched Windows client to access the domain controller system, again using a pass-the-hash attack to gain shell access on the domain controller. Because the password for the local administrator account is identical to the password for a domain administrator account, the password hashes for the two accounts are identical. Therefore, the attacker can access the domain controller with full domain administrator privileges, giving the attacker complete control over all other accounts and machines in that domain.


Steps 6 and 7: Exfiltration
In Step 6, with full domain administrator privileges, the attacker now compromises a server machine that stores secrets for the organization. In Step 7, the attacker exfiltrates this sensitive information, consisting of over 200 Megabytes of data. The attacker pushes this data out to the Internet from the server, again using HTTPS to encrypt the information, minimizing the chance of it being detected.

Ncrack – High Speed Network Authentication Cracking Tool

Ncrack is a high-speed network authentication cracking tool. It was built to help companies secure their networks by proactively testing all their hosts and networking devices for poor passwords. Security professionals also rely on Ncrack when auditing their clients.

Ncrack was designed using a modular approach, a command-line syntax similar to Nmap and a dynamic engine that can adapt its behaviour based on network feedback. It allows for rapid, yet reliable large-scale auditing of multiple hosts.

Ncrack’s features include a very flexible interface granting the user full control of network operations, allowing for very sophisticated bruteforcing attacks, timing templates for ease of use, runtime interaction similar to Nmap’s and many more.

Ncrack was started as a “Google Summer of Code” Project in 2009. While it is already useful for some purposes, it is still unfinished, alpha quality software. It is released as a standalone tool, be sure to read the Ncrack man page to fully understand Ncrack usage.

Rootkit.TDSS - A malware

Rootkit.TDSS, TDL3 or Alureon [Microsoft] is a malware designed to hide the existence of any process on the infected machine in order to perform malicious and dangerous actions. TDSS may also replace essential system executable files, which may then be used to hide processes and files installed by the attackers.

Rootkit.TDSS is installed without user's permission through the use of trojan viruses, whereas trojan virus can download and install additional malware, adware or even rogue anti-spyware applications. Rootkit.TDSS removal can be complicated, but it is essential.

SEO Poisoning Sites Use Flash for Redirection


Description:
Another day, another news, and well... another SEO Poisoning stint.

Using PDF files in SEO poisoning is a bit recent, but not exactly fresh news. So we were thinking of just adding the malicious URLs to our Browsing Protection and creating detections for the corresponding files... Then, we saw something...

Ok, could be one time thing, so we checked the other sites:

And in the usual geeky fashion in the lab... we got excited.

When decompressed, the SWF contains this:

Since a lot of websites use SWF, most users have already installed Flash support in their browsers, thereby also enabling support for the malware behavior.

The SWF is of course the key to getting to:

It seems that the bad guys want the malicious URLs to be hidden inside the SWF. Perhaps it makes them sleep better at night thinking that their sites won't be discovered very soon.

Malicious URLs are now blocked via the Browsing Protection and malicious files are detected.

http://www.f-secure.com/weblog/archives/00001899.html

Google Gears for Attackers


Google Gears is a free and open source project from Google that provides some powerful features to both web applications and site users. Browsers like Google Chrome and SRWare Iron come with Gears pre‐installed. Users of other browsers can install Google Gears on their systems to experience these features.
This paper describes multiple stealthy and remote attacks against users of Google Gears which could have impacts ranging from stealing the entire Gmail Inbox of the victim to setting permanent backdoors in popular sites like Gmail, MySpace, WordPress, Google Docs etc.
For a website to make use of Google Gears, the user should explicitly permit the site to make use of Gears. Once this is done the site can store data on the user’s hard disk, in the form of SQLite databases. The site can read, write and alter this database. Gears also lets the site to save and serve pages locally from the user’s system, in effect, creating a web server on the user’s system. All of Google Gears’ features are accessible using the Gears API from JavaScript.
If an attacker controls the DNS server or is able to inject his data in to the user’s HTTP traffic then an attacker can serve content for a site that has been permitted by the user to use Gears. When this happens the attacker can exploit the features provided by Google Gears to cause serious and long‐lasting damage to the victim.
In traditional attacks in this scenario, the attacker would get the credentials of the user directly if the login is on HTTP. If it is on HTTPS then the attacker could perform a SSL MITM which is noisy or could strip off the SSL layer which is stealthier. A smart user might detect these attacks so alternatively the attacker could let the authentication happen securely on HTTPS and capture the post authenticated cookie, since most sites switch back to HTTP after authentication. All of these attacks depend entirely on the user entering his credentials which takes the control away from the attacker.
The attacks described in this paper could result in long‐term compromise and do not require user interaction, the attack duration is typically a second or two and is virtually undetectable by the user. Gears is a new technology which creates possibilities for new types of attacks to be carried out against the user. This paper discusses in details the various attacks that can be performed using the Database and LocalServer modules of Google Gears.
Interestingly the local database and content caching features are also part of HTML5. Attacks of similar nature to the ones described in this paper does work on HTML5 as well. However, no popular site has been found to use these features of HTML5 yet, hence this paper only focuses on Google Gears.

http://andlabs.org/whitepapers/GoogleGears_for_Attackers.pdf