Showing posts with label network security. Show all posts
Showing posts with label network security. Show all posts

2009-02-13

Conficker; A Bounty Hunter’s Guide

You know things are serious when Microsoft Corp. ponies up a $250,000 bounty. The software vendor is offering the cash in exchange for information leading to the arrest and conviction of the Conficker worm creator(s).


It's part of an unprecedented and coordinated response with ICANN and security researchers from Afilias, AOL LLC , Arbor Networks Inc. , CNNIC, F-Secure Corp. , Georgia Tech, Global Domains International Inc., Internet Storm Center (ISC) , M1D Global, NeuStar Inc. (NYSE: NSR), Public Internet Registry, Shadowserver Foundation, Support Intelligence, Symantec Corp. (Nasdaq: SYMC), and VeriSign Inc. (Nasdaq: VRSN) to disable the hosting and distribution of the worm.


Obviously no one's out to justify or encourage the "Wild West" ethics where this reward's concerned, and it's not the first time Microsoft has gone this route. In 2005, the vendor offered $250,000 for the identity of the creator of Netsky, a.k.a. the Sasser worm, leading to the unmasking of German student Sven Jaschan. But for the interested, the curious, and the bounty-minded, what follows is a starter guide and roadmap to help this latest industry-wide effort along.


What is Conficker?

First, do not get blindsided by the linguistics, and its plethora of names. Conficker.A is what CA Inc. (Nasdaq: CA) calls it, but it also goes by Conficker.worm (McAfee Inc. (NYSE: MFE)); Downadup (Symantec); and Kido and Net-Worm.win32.kido.bt (Kaspersky Lab ). They are all the same thing. It spreads through the use of network shares and weak passwords. Additionally, it uses Windows AutoRun functionality, wherein autorun.inf files are copied to USB drives and other removable media.


When Conficker takes control of the user’s PC


• Injects its code into the address space of one of the “svchost.exe” system processes.


• Disables system restore


• Blocks any addresses which contain the following strings:


indowsupdate / wilderssecurity / threatexpert / castlecops / Spamhaus / cpsecure / arcabit / emsisoft / sunbelt / securecomputing / rising / prevx / pctools / norman / k7computing / ikarus /hauri / hacksoft / gdata / fortinet / ewido / clamav / comodo / quickheal / avira / avast / esafe / ahnlab / centralcommand / drweb / grisoft / eset nod32 / f-prot / jotti / Kaspersky / f-secure / computerassociates / networkassociates / etrust /panda / Sophos / trendmicro / mcafee / Norton Symantec / Microsoft defender / rootkit / malware / spyware / virus



Each day, the worm generates a fresh list of about 250 random domain names such as abfhhibxci.cn. It then checks those domains for new instructions, verifying their cryptographic signature to ensure that they were created by Conficker's author. It should be stressed that this malware is infecting PCs but has not yet been switched on via command and control functions to act as a botnet.


From whence did Conficker spring?

Conficker was first reported to Microsoft as a remote code execution vulnerability in Windows 2000, 2003, 2008, XP, and Vista server service in October 2008; a security update was released on Oct. 23. Estimates vary as to the extent of infection: F-Secure reported on Jan. 16 that Conficker had infected 9 million PCs worldwide with 353,495 unique IP addresses; 10 days later, this was revised to 15 million infected PCs.

Where are the major infection centers?

Panda Security reported on Jan. 21 Conficker in 83 countries, and an estimated 6 percent of the entire world’s PCs were infected, say, 18 million. It further estimated the countries with the highest rates of virulence were the U.S., China, Spain, Taiwan, and Brazil. Press reports have circulated that American military systems were infected by USB drives, and that U.K. Royal Navy warship and submarine systems were infected and rendered unusable; French fighter planes were also reportedly being grounded. Symantec is monitoring 450,000 IP addresses (PCs) with the original infection, with another 1.7 million PCs infected per day.

Who created Conficker?

In this case, the $250,000 question could take a dozen pages of explanation. One simple form of analysis for the potential bounty hunter is to follow the rabbit. But you'll need some Russian language skills. If we examine Kaspersky’s Virus List of Jan. 2, the Conficker worm was originally downloading from trafficconverter.biz, so that's a good starting place. A little examination shows this domain was originally registered via the now defunct EstDomains in December 2008. Even better, some additional Googling gives us a clue to the origin: In Russian hacker forums, we can see earlier offerings from trafficconverter.biz providing excellent reseller margins of $30 a pop to hackers for ensuring downloads of infectious, rogue, anti-virus software.

Not resolving - trafficconverter. biz

Resolving – trafficconverter2.biz



Sister site – RX-Partners.biz


Given the limited space and time, see what conclusions you can draw. You should end up with a combination of hosts, each with a questionable, cybercriminal reputation: AS43816 Centralux (a.k.a. WebAlta, Russia); AS28753 NetDirect (Germany); and AS41867 Geonic (Ukraine). Whether this gets you any closer to Microsoft's reward will depend on which rabbit hole you go down. But safe to say that this sort of incentive will flush out Conficker's writer(s)... The only remaining question is just how long that will take.

Happy hunting!

2009-02-11

Cloning Security

Coming to a PC near you very soon is an innovative and possibly deadly combination of well known exploitation techniques, emerging from the dark side of the Internet. What makes this new attack so innovative are the targets: Internet security information and research Web sites. Hackers in the last week have been creating exact clones of Internet security Websites using proxies, DNS (domain name server) spoofing or redirection, and dedicated denial-of-service (DDoS) attacks.

It should not surprise anyone to realize Internet security research, forums, and information Websites are attacked on a regular or even daily basis. Mostly it is nuisance spam, bogus log-in attempts, or hack attempts to gain entry to the administrator side, and in more intense cases, DDoS.


But this cloning approach emerged from investigation only in the last week. To begin with, there was the discovery purely by accident, of an exact clone of the HostExploit Website. After further investigation, it was discovered this was not an isolated case, with one server hosting clones of security sites like avertlabs.com (McAfee), isc.sans.org, milw0rm.com, nmap.org, packetstormsecurity.org, secunia.com, securiteam.com, securityfocus.com, securityreason.com, thedarkvisitor.com, www-935.ibm.com (IBM), and xforce.iss.net (IBM).

In itself this was a worrying discovery, if simply viewed from content theft, hijacked traffic, click through, SSL forgery, PayPal information, and RSS links etc., of relatively high-traffic security sites. However, in parallel to the emergence of these clones commencing on Friday and over the weekend, several of the real sites listed as clones and a few others -- Metasploit, Zone-H, and Kaspersky -- were under hacker or DDoS attack, and in some cases a mixture of the two. For a while a couple sites were completely unavailable for a day or so, and one or two are still under a continuous DDoS attack.

Working off limited data from server logs and network traffic, at least a couple of the attacks originated from Poland (AS5617 TPNET); Romania (AS 9050 Romtelecom, AS39650 VIANET); Russia (JSC servers funneled via RTcomm, and Rostelecom via AS9002 RETN); and Turkey (AS9121 TTNet, AS8386 KOCNET). Many of these servers appear regularly on lists of the worst European offenders for hosting spam and exploits, according to the German-based anti-spam service UCEprotect.

I must emphasize here that there's no proven link between the appearances of the clones and this weekend's attacks. This could be a simple coincidence, but as Edmund Burke said. "Better be despised for too anxious apprehensions, than ruined by too confident security." It does leave the open question, if by hacking and DDoS, the real security Websites were offline the only source available could be the clones. It is by a simple step to include by DNS redirection, cookie plants, and other exploits, to ensure visitors went to and continued to visit the false, cloned sites.

Consider the mayhem that could be caused by providing bad file downloads and misinformation using these sorts of exploits, botnets, and spam, or even distorting the core news and advisories this sector, its enterprise customers and the press depend upon. Worst of all, even without any changes from the real sites, the data gathered from all those misdirected, security-minded visitors would be hugely valuable.

Obviously the intended outcome of the attacks and the clones is to damage reputations, create distrust, and ultimately make it easier for cyber-criminals to operate. The good news is thanks to swift action, these discovered clones and the hacker site serving them are offline. This is certainly not the last we will see of this approach.

2009-01-23

Majority of Top 100 Websites Host Malicious Content

A majority of the top 100 websites hosted either malicious content or masked redirects according to a Websense report.

Summarizing its significant findings during the six-month period ending in December 2008.


The highlights are:





Web Security

  • 77 percent of Web sites with malicious code are legitimate sites that have been compromised.The number of malicious Web sites identified by Websense Security Labs from January first, 2008 through January first, 2009 has increased by 46 percent.
  • 70 percent of the top 100 sites either hosted malicious content or contained a masked redirect to lure unsuspecting victims from legitimate sites to malicious sites.
  • This represents a 16 percent increase over the last six-month period.

Messaging Security

  • 84.5 percent of email messages were spam. This represents a 3 percent decrease over the last six months.
  • 90.4 percent of all unwanted emails in circulation during this period contained links to spam sites or malicious Web sites. This represents almost a 6 percent increase in emails containing malicious links to compromised sites.
  • Shopping remained the leading topic of spam (22 percent), followed closely by cosmetics (15 percent) and medical (14.5 percent). This remained consistent over the last six months.
  • Pornography-related spam increased sharply by 94 percent, but still only represented 9 percent of all email spam. 6 percent of spam messages were phishing attacks, representing a 33 percent decrease over the last six months.
  • This represents a change in tactics as spammers concentrated on data-stealing Trojan horses and DNS poisoning tactics to lure victims to malicious sites.

Data Security

  • 39 percent of malicious Web attacks included data-stealing code.
  • 57 percent of data-stealing attacks are conducted over the Web.
  • This represents a 24 percent increase over the six-month period.

The full report is here
(PDF)

2008-12-18

Enemy Within

When considering our preparedness (or lack of it) for cyber warfare or fighting cyber criminals, an old African quotation comes to mind: "When there is no enemy within, the enemies outside cannot hurt you."

At first thought, the concept of an enemy within might call to mind the Federal Trade Commission halting the scareware schemes, in which e-marketeers falsely claimed their scans had detected viruses, spyware, and illegal pornography on consumers’ computers. The FTC estimated more than 1 million consumers were duped into buying needless products such as WinFixer, WinAntivirus, DriveCleaner, ErrorSafe, and XP Antivirus, at $40 per install. Yes, a cool $40 million from such a scam based on ineffective products.

The enemy within, though, is actually more insidious than that. According to an alarming annual security report from Cisco Systems Inc. (Nasdaq: CSCO), there was a 90 percent growth rate in threats originating from legitimate domains, nearly double what the company saw in 2007.

In addition, vulnerabilities in virtualization products nearly tripled to 103 in 2008 from 35 in 2007, as more organizations embraced virtualization to save money and increase productivity. The technology basically lets one computer do the job of many, by sharing the resources of a single computer across multiple environments. More importantly, you can further establish virtual environments for Web serving and data transit.

HostExploit was able to determine the problem with McColo by penetrating its virtual environment and exposing it for the business it actually was. This evil network was run from Moscow by cyber criminals; however, it was fully maintained within a data center in Southern California. In similar fashion, recent attacks on Georgia were launched from Plano, Texas, controlled by a Russian group apparently based in London.

The enemy within we should all be most concerned with are these collocation centers. Most would be surprised to learn one particular Russian network operator has three virtual hubs in the U.S.: Ashburn, Va.; New York; and Los Angeles. This may sound worse than it is -- U.S. operators have hubs and nodes in Moscow; this is just the way of the Web Wide World, and allows us to speed the flow or maintain virtualized Web-serving across the globe.

What is disturbing is this particular Russian network operator is RETN, also formerly known as Eltel, a very dirty Russian network infamous for hosting spammers and malware. RETN/Eltel will be reactivating the McColo IPs anytime now, allowing the botnets to contact their masters and the spam to flow again, according to Spamhaus.

In this virtual network operator jigsaw puzzle, consider the potential enemy within. In this unregulated and open market, anyone with a credit card (like RETN) can rent rack space or even simply dispatch a server, right next to equipment from Global Crossing, Level 3, Hurricane Electric, and many others, foreign and domestic. And that's all that's needed to launch a botnet-controlled attack for cyber warfare or cyber criminal purposes from St. Petersburg, Beijing, or Islamabad. Except that it's happening within U.S. cyber space.

Within a very short period, these virtual thugs can send billions of spam messages, distribute malware, or, as the hackers did earlier this year, access White House emails. Add to this the ability to use anonymous proxy networks via botnet C&C (command and controls), and they can make themselves look las if they're from the U.S., China, or whatever virtual destination they choose.

If there was ever a serious case for necessary government regulation and watchfulness, this is it, before anyone jumps up to call this infringing on Internet freedom or net neutrality. These are commercial, criminal concerns operating strategically important communication data and collocation centers; tighter controls would have no effect on individual Net surfing or Web hosting. What more oversight and control would do is create a less welcoming place to harbor the enemy within.

Internet Evolution


2008-04-17

The Top 25 World's Exploit Hosts and Servers - Issue 1: The Base

The Top 25 World's Exploit Hosts and Servers, deals with a holistic problem, requiring a holistic solution, "HostExploit.com" will attempt to be part of the solution.



With the increasing subversion of the DNS (Domain Name System) by the now widespread automated domain generation in the 100’s to 1,000’s per week by the exploiters. This combined with the usage of armies of virtually untraceable P2P (Peer to Peer) directed botnets and undetectable polymorphic viruses and malware. It may appear increasingly difficult for the community to even block such threats let alone reduce them. This involves the whole area of internet security and network security.


Table 1. - The Top25 World's Exploit Hosts and Servers




However, this route is controversial and hitherto a taboo subject; i.e. the hosts, registrars, and servers. Whether it is; spam, exploits, malware, spyware or even botnet control, the domains are registered, the web sites are hosted or served by an organization, i.e. the 'web host' and are assigned an AS # (Autonomous System) by ICANN. To commence we begin exposing the 'Top 25 World's Exploit Hosts and Servers' these alone serve and provide an estimated 80%+ of all the bad stuff on the Internet, infect; good servers, good websites, and overall are a scourge to the average internet user .



Why controversial or taboo?


- It is complex - Yes it is, however through already man years worth of detailed research and even more community references we will partition into manageable chunks. So will add downloadable lists, rules, block information, and educational explanation where possible . Commencing as we do here with a top down 'peeling the onion' approach.


- It involves big money, in most cases many $millions - As we unfold this subject we will provide focused details on a particular 'Exploiting Host' with the economics involved, where possible. It is our view that because an organization makes a great deal of money and exploits or spams the average user, whether 'intentional exploiters' e.g. Atrivo or 'allowed themselves to be highly infected' e.g. The Planet, does not exclude it from exposure.


- Many innocent or grey web sites may suffer due to the few - this will undoubtedly be the case . A major technique for the exploiters is to hide the needle in the haystack , however we and most Internet users would argue, this is not our problem. It is the problem for the host or server, if they are legitimate they will or should move heaven and earth to clean up their act for the benefit of the legitimate webmasters, and more importantly the . For the innocent webmasters, why are you still hosting your web site with these hosts and servers anyway?



In the final analysis this is about choice. Choice for the average PC user to reduce the threat of being exploited, the ISP (Internet Service Provider) to assist in 'prevention' for their users, the hosts, servers, and DNS registrars, to not just take an anonymous client and probably stolen credit card. Authorities such as ICANN are well aware of this increasing problem, perhaps this helps create the groundswell for them to act on behalf of the 99% of Internet users.



Useful Article Links:



Article Downloads - Top 25 csv, IP block lists


SecureWorks - Top Spam Botnets


ICANN - Advisory on Fast Flux Hosting and DNS


DNS Education - How Domain Servers Work




2008-03-24

HostExploit - What? Why? Who?

HostExploit – ‘A call to arms’- Why another Internet security blog and more ‘black hole’ lists? - It's the HOSTS!

It has become increasingly apparent the malware, spam, phishing and other BadWare distributors are now engaged in automated domain generation, 100’s to 1,000’s per week, which is proving a serious difficulty for major domain / IP ‘blocklist’ and ‘blacklist’ providers to simply keep up .

Added to this we now have; iFrame attacks via web portals, several major international web hosts with 1,000’s of their innocent and money paying clients having hacked and infectious (to web surfers) web sites, DDos (distributed denial of service), polymorphic malware that many anti-virus / spyware / malware solutions are unable to detect, and millions of PC users being directed to rogue and fake web sites.

Finally we have the rise of the Botnets, anonymously managed fast and double-flux (ever changing IP addresses) control of 1,000’s of infected zombie PCs.


We now believe the general situation on the Internet calls for an alternative and added open source approach to deal with this head on, i.e. the web hosts and Internet carriers. Every one of the IP’s, web sites or domains are hosted or carried by someone, we feel it is time to break the taboo and name, list and expose the ones that host the malware that infects us all. This approach is not to replace existing methods, but we hope it will add to the security community’s and PC user’s array of possible tools to reduce the threat.


HostExploit – Who? This blog and associated list(s) is edited by Jart Armin and James McQuaid, however the research is provided by a wider volunteer group, some of whom would rather remain anonymous, due to their other professional Internet activities. All those involved are web professionals within; web hosting, server management, DNS (Domain Name System), Internet security, and IDS (Intrusion Detection Systems).


HostExploit – Who is this for?
You, i.e. any PC user, webmaster, ISP (Internet Service Provider) or web host, who wants to reduce the threat of infection or exploitation. Where necessary or possible all topics and articles will contain added information to illuminate and educate.


HostExploit – What to expect?

• Bad Host Lists – these will be in several formats for users to apply for themselves or distribute freely. These lists will initially focus on the (b) and (c) categories (see below) can be used to black hole, block or just for general awareness - click here.


• Specific bad host exposures – On a regular basis there will be articles exposing a specific host and providing detailed and where possible quantification with a historical background.

• Bad Host categorization – host or AS (autonomous server) issue comes down to a certain level of semantics and initially crude differentiation – so we will commence with an ‘a b c’ method:

(a) Hosts / Servers / AS of 'infected sites' = - i.e. infected or hacked sites / domains which have bad exploit code, infected iFrame, SQL injections, XSS exploits, etc. to exploit visitors.

(b) Hosts / Servers / AS of 'user infector sites' = i.e. where the malware and rogues are located and more often than not, users are directed to from infections on sites within (a)

(c) Hosts / Servers / AS of 'user receptor sites' = The ultimately very bad = including the so called "the bullet proof servers" masked by the botnets to; receive, trade, pay affiliates, warez, etc. etc. - from (b); stolen IDs, credit cards, bank phishing info, for (a) to pay partners and affiliates to infect the web sites. Also for DDos Botnet C&C (command and control) actions.


HostExploit - To Inform and educate – Articles that attempt to help explain the processes and terminology involved.


HostExploit – Want to help or have your say?
This is an open source ‘non-profit’ volunteer group and we welcome help, input or feedback. However for security reasons there is no allowance for onsite comments so email HostExploit (at) gmail.com.

It is likely input would be within the following:


• To keep informed or pass on the information? – sign up for a ‘Feedburner’ feed and then you will be informed about new articles. Feel free to pass on articles and the list(s), publish in your blog or magazine or newspaper, under a ‘Creative Commons License’, obviously it is courteous to show hostexploit.com as a reference.


• Have information we may have missed or a new exposure? – email us.

• Web Host / Server / AS, and feel any information or inclusion within the list(s) is in error? – Please email us and say where we are wrong, our objective is to reduce such a list and we will be delighted to explain the error or demonstrate you have cleaned up your act.