Search This Blog

Monday, December 6, 2010

Polymorphic injection attack targets WordPress blogs.

Polymorphic injection attack targets WordPress blogs. Security researchers have identified a sophisticated mass injection attack that uses polymorphic obfuscation and so far has targeted WordPress blogs at a U.S.-based hosting provider. According to a principal virus researcher at Sophos, the attacks began in the middle of November, and they all seem to affect Web sites running the popular blogging platform. Successful infection will result in one or several .php files being dropped on the Web server in multiple WordPress directories. However, despite the .php extension, these rogue files actually contain malicious JavaScript code obfuscated with a technique that makes every one unique. In the security world this is known as polymorphic code and is used to evade antivirus software and intrusion detection systems. The second step of the attack is to inject code in legit .js files used by WordPress, like the jQuery library, with the purpose of loading the .php files along with them. Finally, when the obfuscated JavaScript makes it onto the pages parsed by the visitors' browsers, it generates a hidden element. This element is meant to load malicious content from remote servers in an attempt to infect computers with malware.

Source: http://news.softpedia.com/news/Polymorphic-Injection-Attack-Targets-%20WordPress-Blogs-169953.shtml

Beware! New Facebook Scam

Murder video scam circulating on Facebook. Facebook scammers are luring users into signing up for premium rate services with promises of a video showing a guy killing his roommate after playing Black Ops. The new spam messages, which, according to security researchers from GFI Software are rapidly spreading on the social networking site, read: "TODAY ONE GUY KILLED HER ROOM MATE WHILE PLAYING A BLACK OPS GAME IN NETWORK. LIVE DEATH VIDEO CAUGHT ON CAMERA" Black Ops refers to "Call of Duty: Black Ops," the seventh installment in the Call of Duty game series, which was just released. This, of course, is just a lure and there is no video of any killing. Clicking on the picture as instructed prompts a permissions request dialog from a rogue Facebook app called "Shock news." The application wants access to post on people's walls. Allowing it to do this will cause users to unknowingly send spam from their accounts. The app prompt is followed by a so called "human authentication" test, which requires people to take an IQ quiz that tries to sign them up for a $9.99 per month SMS service.


Source: http://news.softpedia.com/news/Murder-Video-Scam-Circulating-on- Facebook-169699.shtml

Friday, November 12, 2010

Beware of how you use search engines

Google SERP’s show malicious URL links. Cybercrooks continue to abuse the Web, boosting their ability to produce search engine optimization (SEO) poisoning so individuals using search engines such as Google increasingly are ending up with choices that are dangerous malware-laden URL links on the Search Engine Results Page (SERP). Some 22.4 percent of Google searches done since June 2010 produced malicious URLs, typically leading to fake antivirus sites or malware-laden downloads as part of the top 100 search results, according to the Websense 2010 Threat Report published November 9. That is in comparison to 13.7 percent of Google searches having that outcome in the latter half of 2009, said the Websense senior manager of security research.

The rising level of SEO poisoning, also known as “Black Hat SEO,” shows that cybercriminals “are fine-tuning their activities and getting better at this,” he said, adding that although search engines such as Google work hard to try and stymie the Black Hat SEO effect, the trend is evident. The irony is that when it comes to getting infected by malware, the chances of that are now less risky at porn and adult content sites, historically viewed as a high source of malware (now at 21.8 percent) than just searching for less scandalous topics, such as news, IT, and entertainment.

Source: http://news.techworld.com/security/3248172/

Phishing Attacks Up

Researchers see real-time phishing jump. Real-time phishing attacks that cheat two-factor authentication are on the rise around the globe as phishers adapt to the latest barriers put in their way, according to a team of researchers. Researchers at Trusteer November 9 said 30 percent of all attacks during the past two-and-a-half months against Web sites using two-factor authentication have been real-time, man-in-the-middle (MITM) methods that allow attackers to bypass this stronger authentication.

The data comes from a sampling of thousands of phishing attacks. Phishing attacks typically are static, so they are mostly rendered powerless when a bank uses two-factor authentication, such as one-time passwords. That is because the attacker may be able to capture the first level of credentials, but they are not able to easily capture and use OTPs, which quickly expire. So phishers are adapting their attacks to find ways around stronger authentication, and security experts said it was only a matter of time until they routinely started cheating banks and other transactional sites’ two-factor authentication.

This type of real-time MITM attack has been isolated and rare thus far, experts saod. Trusteer researchers have spotted these attacks in South Africa, Europe, and now in the United States, the firm’s CEO said. And while these attacks are not a new concept, this is the first time his team has seen them in such high numbers, he said.

Source: http://www.darkreading.com/authentication/security/attacks/showArticle.jhtml?articleI D=228200550

Mac Bug Found

Researchers sound alarm over critical Mac OS X bug. Security researchers November 9 warned that Apple’s OS X contains a critical vulnerability that attackers could use to hijack Macs running the older Leopard version of the operating system. Although Leopard was supplanted by the new Snow Leopard operating system more than 1 year ago, the older version still accounts for about a third of all installations of Mac OS X.

The bug is a variation of one Apple patched last August in iOS. The flaw was used to “jailbreak” iOS 4 devices, and it could also be exploited to plant malware or commandeer an iPhone, iPad, or iPod Touch. According to Core Security Technologies, which issued an advisory November 8, Apple has wrapped up work on a patch.

Source: http://www.computerworld.com/s/article/9195680/Researchers_sound_alarm_over_crit%20ical_Mac_OS_X_bug

Microsoft Patches.. but skips Mac versions of software

Microsoft patches critical Outlook drive-by bug. Microsoft November 9 patched 11 vulnerabilities, including one in Office that hackers will quickly exploit to launch drive-by attacks, security experts said. As expected, Microsoft did not ship a fix for the flaw in Internet Explorer (IE) that criminals are using to hijack Windows PCs. Of the 11 flaws addressed in three separate updates, only one was pegged as “critical,” Microsoft’s top ranking in its four-step scoring system.

The remaining 10 were all marked “important,” the second-highest rating. “The one that gives me the heebie-jeebies this month is the Office update,” said the director of security operations at nCircle Security. “The RTF vulnerability can be triggered simply by viewing a message in Outlook, so all you have to do is receive a [malicious] message. Then the game is over.” He was referring to MS10-087, a fivepatch update for Office XP, 2003, 2007 and 2010 on Windows, and Office for Mac 2004, 2008 and 2011.

The only critical bug this month is in the RTF (rich text format) parser within Outlook, the e-mail client packaged with Office. “The vulnerability could be exploited when the specially crafted RTF e-mail message is previewed or opened in Outlook,” Microsoft’s advisory stated. Both Office 2007 and Office 2010, Microsoft’s two newest suites, can be exploited using drive-by attacks launched against Outlook. Today’s patch was the first critical update for Office 2010, which launched only in June 2010.

Microsoft forgets to patch Mac Office 2004, 2008. Microsoft November 9 revealed four vulnerabilities in the Mac version of its Office suite, but then failed to produce patches for the 2004 and 2008 editions. Office for Mac 2011, which launched October 26, was the only version updated as part of Microsoft’s monthly Patch November 9. Microsoft did not explain the omission of Office for Mac 2004 and Office for Mac 2008 patches, or say when it would ship updates for those editions.

According to that bulletin, Office for Mac contains four vulnerabilities, all rated “important,” the second-highest threat ranking in Microsoft’s four-step scoring system. Microsoft confirmed that each bug could be used by attackers to infect a Mac with malware by labeling them with the phrase “remote code execution.” Along with a fifth bug, the same four flaws were patched November 9 in all still-supported versions of Office for Windows.

Source: http://www.computerworld.com/s/article/9195719/Microsoft_patches_critical_Outlook%20_drive_by_bug

Source: http://www.computerworld.com/s/article/9195819/Microsoft_forgets_to_patch_Mac_O%20ffice_2004_2008

Wednesday, November 10, 2010

New Adobe Reader Flaw

Adobe investigating new Reader flaw. Adobe is warning users about another new vulnerability in its Reader application that causes the software to crash and could possibly lead to remote code execution as well. The new Reader bug was disclosed November 4 on the Full Disclosure mailing list and Adobe security officials said that they are investigating the problem and looking into a potential fix. The bug can be used to cause a denial-of-service condition on vulnerable machines, Adobe said. However, one of the new security measures that the company introduced earlier this year can be used to help protect against attacks on the flaw. Adobe’s JavaScript Blacklist Framework is designed to prevent malicious APIs from running, and Adobe said that the tool can be used to stop attacks on the new Reader vulnerability. IT staffs must enable and populate the blacklist manually, and Adobe has explicit instructions in its advisory on how to do that. Adobe patches Reader on a regular quarterly schedule, and the last release was October 5, which was 1 week earlier than scheduled. It is not clear whether Adobe would release a patch for this latest Reader bug before the next scheduled update. 

Source: http://threatpost.com/en_us/blogs/adobe-investigating-new-reader-flaw-110510