Microsoft Windows Vista Community Forums - Vistaheads
Recommended Download - Clean, repair and optimize your system



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Driver Scanner 2009 - Free Scan Now

Branching targeted attack execution paths outside of the code, (Mon, Mar 10th)

Security News




Recommended Fix - Fix Vista Errors and Optimize Performance

Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Driver Scanner 2009 - Free Scan Now
Reply
  #1 (permalink)  
Old 03-10-2008
Steve's Avatar
Moderator
 
Join Date: Sep 2006
Location: Emerald Isle
Posts: 57,969
Steve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to behold
Thanks: 11
Thanked 92 Times in 21 Posts
Branching targeted attack execution paths outside of the code, (Mon, Mar 10th)
Tom and Jeb were at it again. They were in the big leagues now, with a new contract. All that remained to be done for their current mission was to raid confidential data from an electronics giant. They had failed so far to Hack the Gibson compromising the companys web servers had proven to be challenging, to say the least.
They pulled up an old C compiler, grabbed the sources of a common Trojan family from a torrent, and crafted a malicious binary. It would do nothing out of the ordinary, just download a second binary from a web server. That second stage payload would then grab e-mails matching certain text patterns, and submit those through an HTTPS channel to a server under their control.
They had done their homework: after setting up a fake social networking account, they identified the people representatives their target company talked to. They studied the writing style of one of those contacts. Now, they would ship off their exploit to some people within the overall community in an otherwise innocuous e-mail, posing to be one of them.
To ensure the message reached its target, they clearly mentioned in the e-mail that recent privacy breaches that had been discussed on a public list frequented by the target, were an outrage, and everyone should be made aware of them. Only a few hours later, Tom and Jebs message was forwarded to the target company by one of their legitimate contacts. This made the message look all the more trustworthy.
Some other recipients though, found out the code was malicious. They forwarded it on to their anti virus vendor. The vendor investigated the issue, but found the host name for the secondary payload to resolve to 127.0.0.1. They built coverage, patterns were distributed, and machines were cleaned. Tom and Jebs attack was brought to an abrupt halt. The security community had been victorious!
In the background, however, Tom and Jeb were sitting behind their machine, looking at the targets confidential data flow in. Bit by bit, valuable data trickled through, allowing them to plan the next steps in their deep compromise.
What had gone wrong, you ask? The fact that most of the time we prepare for attacks that are global in nature, while in fact incident handlers need to deal with uncertainties, multiple execution paths, if you will, at every step of the way.
Tom and Jeb had set their sights on a very specific target. They accessed their target through people they trust, making it more likely for them to click on the message. Next, they had set up two views on a hacked DNS server, authorative for the domain in which their control server resided. In BIND tongue:
View world {
match-clients }
zone controlserver.com {

file /resolve.localhost
view target {

zone controlserver.com
file /resolve.controlserverip
Only the resolver DNS servers of the real target had seen a real IP address when looking up the IP address for the control server. All others saw 127.0.0.1. The code that was forwarded to the various anti virus vendors did not give them sufficient data to protect the target. To them, the secondary payload server was no longer live.
The above situation took place in a recent targeted attack on an NGO. When handling incidents for others at a different location, be careful. The execution path you see may not be the same as the clients. A lot of attention in industrial espionage investigations is being spent on ensuring we covered all the execution paths within a malware specimen, but in some cases, these paths branch outside the actual code.
Seen this as well, or any comments or ideas? Write to us.
--

Maarten Van Horenbeeck

More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Resolutions 2008, (Mon, Dec 10th) Steve Security News 0 12-10-2007 16:40
Skype worm, (Mon, Sep 10th) Steve Security News 0 09-10-2007 22:20
Firekeeper, (Sat, Mar 10th) Steve Security News 0 03-10-2007 22:00
DST hype, (Sat, Mar 10th) Steve Security News 0 03-10-2007 22:00
New malware spreading through compromised sites, (Sat, Mar 10th) Steve Security News 0 03-10-2007 16:42




All times are GMT +1. The time now is 08:07.




Driver Scanner - Free Scan Now

Vistaheads.com is part of the Heads Network. See also XPHeads.com and Win7Heads.com.


Funny Commercials to make you laugh :-)

Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119