Showing posts with label internet security. Show all posts
Showing posts with label internet security. Show all posts

2009-02-19

Are you a Conficker Zombie?

With the advent of Conficker and to avoid becoming one of the estimated now 20 million or so zombie recruits of the botnet armies requires ongoing awareness. At least we need to be personally alert, to make it difficult for the cyber criminals. If you are reading this article on a MS widows based PC and you have not upgraded your XP or Vista operating system since October 2008, there is a reasonable chance you are a zombie, or rather your PC is.

Before we see the regular smirks and responses from Mac and Linux users, stressing how safe they are and it is all the fault of Microsoft. The now common place blended attacks, whose singular purpose is to add your PC to the zombie botnet armies, are designed to gain control regardless of operating system. MS Windows, Mac, Linux, iPhone, iPod, all have “Hosts files” which allow; you, webmasters, or network administrators to configure a direct link to a remote IP address. So if you can do this, guess who else could configure your host file, more about this below.

As a couple of examples of the sophistication of the latest blended attacks, and also acts as the latest clue for Conficker bounty hunters.

Fig 1 - Fig 1 - Conficker - (ref; Internetpol.fr)

Gone are the days when the simple diagnostic of an infected PC or Zombie was essentially the machine was overheating and a markedly drop in speed. The Conficker agents essentially check for the presence of the firewall and ask the firewall to open a backdoor to the Internet, once done it downloads the payload. Interestingly the early version checks if the target has a Ukrainian IP address also checked for a Ukraine keyboard and if either present stopped any infection. Once a PC is infected it will sleep solely to wake up every 3-4 hours to (quietly) call home for its latest instructions and IP addresses.

Another recent example which is called “Virux” (see PE_VIRUX variants - TrendMicro)

Fig 2 - Virux (TrendMicro)

Here Virux infects the PC via the browser and phones home via IRC (Internet Relay Chat) servers for botnet control instructions. Just to emphasize there is some dispute as to where Virux is another variant or from the same stable as Conficker, due to its similarity of attack vectors, or just an update of the older “Virut” exploit which gained fame back in November 2008 for utilizing a vulnerability in Adobe Reader . Either of these examples, both Conficker and Virux, block access to security websites and anti-virus downloads. Also using sophisticated Geo Location IP systems to gain further exploits for the appropriate location of the victim and more importantly this is for enhanced cyber criminal affiliate sales, for example resale and botnet rental of say just PCs on the US West Coast or Australia, etc.

Now for the good news, all the above should alarm the average reader, however most of this can and should be avoided. Either of these examples spreads through the use of; network sharing, weak passwords, and the bad guys making use of the autorun.inf files which are copied to USB drives and other removable media. Further if you have made use of the latest operating system updates, anti-virus, and upgraded to use Adobe Reader 9.0. Also why anyone whether and individual or company, would not use the free “OpenDNS” service which you can set to avoid phishing, adware, or many of these nuisances, is still surprising.

For a really simple check, how is your “Hosts file”? For more the wider details visit Tom Olzak’s excellent article here . For MS windows users it is really simple; using windows explorer go to c:\windows\system32\drivers\etc open the hosts file in Notepad, if you see anything else beyond the standard “127.0.0.1 localhost” then ask yourself why, or more worryingly you are already a botnet zombie.

2009-02-11

Cloning Security

Coming to a PC near you very soon is an innovative and possibly deadly combination of well known exploitation techniques, emerging from the dark side of the Internet. What makes this new attack so innovative are the targets: Internet security information and research Web sites. Hackers in the last week have been creating exact clones of Internet security Websites using proxies, DNS (domain name server) spoofing or redirection, and dedicated denial-of-service (DDoS) attacks.

It should not surprise anyone to realize Internet security research, forums, and information Websites are attacked on a regular or even daily basis. Mostly it is nuisance spam, bogus log-in attempts, or hack attempts to gain entry to the administrator side, and in more intense cases, DDoS.


But this cloning approach emerged from investigation only in the last week. To begin with, there was the discovery purely by accident, of an exact clone of the HostExploit Website. After further investigation, it was discovered this was not an isolated case, with one server hosting clones of security sites like avertlabs.com (McAfee), isc.sans.org, milw0rm.com, nmap.org, packetstormsecurity.org, secunia.com, securiteam.com, securityfocus.com, securityreason.com, thedarkvisitor.com, www-935.ibm.com (IBM), and xforce.iss.net (IBM).

In itself this was a worrying discovery, if simply viewed from content theft, hijacked traffic, click through, SSL forgery, PayPal information, and RSS links etc., of relatively high-traffic security sites. However, in parallel to the emergence of these clones commencing on Friday and over the weekend, several of the real sites listed as clones and a few others -- Metasploit, Zone-H, and Kaspersky -- were under hacker or DDoS attack, and in some cases a mixture of the two. For a while a couple sites were completely unavailable for a day or so, and one or two are still under a continuous DDoS attack.

Working off limited data from server logs and network traffic, at least a couple of the attacks originated from Poland (AS5617 TPNET); Romania (AS 9050 Romtelecom, AS39650 VIANET); Russia (JSC servers funneled via RTcomm, and Rostelecom via AS9002 RETN); and Turkey (AS9121 TTNet, AS8386 KOCNET). Many of these servers appear regularly on lists of the worst European offenders for hosting spam and exploits, according to the German-based anti-spam service UCEprotect.

I must emphasize here that there's no proven link between the appearances of the clones and this weekend's attacks. This could be a simple coincidence, but as Edmund Burke said. "Better be despised for too anxious apprehensions, than ruined by too confident security." It does leave the open question, if by hacking and DDoS, the real security Websites were offline the only source available could be the clones. It is by a simple step to include by DNS redirection, cookie plants, and other exploits, to ensure visitors went to and continued to visit the false, cloned sites.

Consider the mayhem that could be caused by providing bad file downloads and misinformation using these sorts of exploits, botnets, and spam, or even distorting the core news and advisories this sector, its enterprise customers and the press depend upon. Worst of all, even without any changes from the real sites, the data gathered from all those misdirected, security-minded visitors would be hugely valuable.

Obviously the intended outcome of the attacks and the clones is to damage reputations, create distrust, and ultimately make it easier for cyber-criminals to operate. The good news is thanks to swift action, these discovered clones and the hacker site serving them are offline. This is certainly not the last we will see of this approach.

2008-10-11

Actions against registry services abuse – Report Oct 2008 - HostExploit and Directi

Jart Armin of HostExploit.com & Bhavin Turakhia, CEO of Directi are pleased to jointly report on the outcome of community actions against abuse of Directi’s domain registry and PrivacyProtect.








The above in figures review of the actions that Directi, in conjunction with HostExploit, have recently taken to track down and stop abusive domain names and registrants from abusing Directi’s services.
Registrar Abuse

  • Over 50,000 domain names have been suspended that were either involved in abusive activity or registered by customers/registrants exhibiting persistent patterns of abuse.
  • These domain names (and/or their registrants) were involved in various types of abuse, such as spamming, phishing/spoofing, malware perpetration, suspected pedopornography, financial frauds and falsified ‘Whois’ information.
  • All other services utilized by any of these domain names have also been revoked.
  • Over the past three months, certain resellers have been identified who have been the destination of choice for bad actors; among these are Vivids Media GMBH, Klikdomains, MyNick.name, and Webst.ru. Approximately 125,000 domain names registered through these resellers have been suspended so far.

PrivacyProtect

  • A large incentive for bad actors to use Directi’s services has been PrivacyProtect.org. This service has been disabled for over 27,000 abusive domain names.
  • The service had been permanently disabled for all existing and new registrations through resellers/registrars that have seen high volumes of abusive registrations - notable being the ones mentioned above and Estdomains. This has amounted to approximately 500,000 domain names which had privacy protection canceled.

Analysis

When suspending domain names on receiving complaints about their involvement in abuse, HostExploit is pleased to report that, Directi, while reviewing the complaints over the past few months, even before the ‘Atrivo-Cyber Crime USA’ report, found certain trends:

  • Domain names registered with the same/similar contact information (name, address patterns)
  • Bulk registrations of domain names with a slight variation in the domain name e.g. 018xyz.com, 018xyza.com, 018xyzb.com, 018xyzc.com …. by abusive registrants/customers
  • Same blacklisted name servers being repeatedly utilized.
  • Registrations in the same customer account involved in various forms of abuse
  • Based on these, we reviewed all domain names, first in the customer's account, then in the reseller's account and then across the databases. Based on these similarities, 35,000 domain names were identified and have been labeled as co-network.

Discussion

Directi’s strengthened abuse team continues to review complaints and revoke privacy protection for abusive domain names, while also forwarding the complaint to the Registrars for whom Directi provide software and other services for them to take action. Where reports of abuse emerge from security community blogs or forums, Directi are now proactively making searches for such comments and investigating any issue that may involve Directi or a reseller.

One advantage of this exercise has been the development of active communication channels between us and the community. We've been able to refresh contacts with organizations e.g. StopBadware, Knujon, CastleCops, Spamhaus, and Artists Against 419, among others, sharing intelligence on abuse activity.

In scouring for more such cases however, every emphasis is made on avoiding any false positives. With this is mind and with the view on net-neutrality all actions are based upon ACM (Association of Computing Machinery)
http://www.acm.org/about/code-of-ethics e.g.

1.2 Avoid harm to others.

"Harm" means injury or negative consequences, such as undesirable loss of information, loss of property, property damage, or unwanted environmental impacts. This principle prohibits use of computing technology in ways that result in harm to any of the following: Internet users, and the general public.


An active list of directly suspended domains is available for down load from 
HostExploit.com

HostExploit and Directi have agreed to maintain their cooperative collaboration to clamp down spam and other forms of abuse on the Internet as rapidly as possible. HostExploit confirms that they are pleased to work directly with the Directi abuse desk in helping Directi identify any miscreants that maybe using Directi's services. The partnership includes sharing investigative processes and intelligence data on an ongoing basis.

We welcome any concerns or reports related to the abuse of Directi’s registry services forward to abuse(at)directi.com or admin(at)hostexploit.com

Together with the community we hope to continue taking steps to make the Internet a better and safer place.

2008-09-06

ATRIVO – Cyber Crime USA Report - Update 090608 a

We demonstrated a limited number of examples of badware websites with Directi providing some form of Internet connectivity with data confirmation on Sept 04 08, and historical third party sources. Below we show the welcome results of actions taken by Directi as of Saturday 090608. - Click on the graphics to enlarge.


xpantivirussecurity.com – rogue anti-virus – was with connectivity by Atrivo and Directi (OpticalJungle), registrar Directi (PublicDomainRegistry), registrant, obviously false data March 08 courtesy Sunbelt Software





Graphics of internet connectivity 9/4/08









Graphics of Internet connectivity Sat 9/6/08






Loads.cc – botnet and DDos for hire service – was with connectivity by Directi (OpticalJungle), registrar Directi (PublicDomainRegistry) registrant, obviously false data Cited Nov 2007

Graphics of internet connectivity 9/4/08





Graphics of Internet connectivity Sat 9/6/08



No Internet Connectivity!



Comment:


“That's one small step for Directi, one giant leap for a safer Internet”.



On behalf of the online community we thank Bhavin Turakhia, CEO and Directi, for their prompt actions, to our findings. These examples are perhaps only a small in comparison to the overall problem we face, but are still significant victories in the fight against cyber crime and the head on approach of HostExploit's 'Atrivo - Cyber Crime USA' report.


We all hope this leads to even greater actions and security focus by the Hosting and Registrar community?





Jart Armin

HostExploit.com

2008-08-28

Report Slams U.S. Host as Major Source of Badware

In a new study entitled "Atrivo - Cyber Crime USA", the authors have extensively tracked and documented ongoing cyber criminal activity from within the Internet servers controlled by the California-based Atrivo, and other associated entities. Atrivo is one of the Internet's Autonomous Systems and controls a large number of IP addresses, which web sites must use to reach consumers.

Produced by cyber crime researcher Jart Armin, in association with Matt Jonkman and James McQuaid, the first of its kind Open Source Security study set out to quantify and continuously track cyber crime using numerous methods of measurement. It focuses specifically on the notorious Atrivo, which has been seen by many over several years as a main conduit for financial scams, identity theft, spam and malware. This study although fully self contained is the first of a series of reports, on a monthly basis there will be a follow up to report on the community response, the efforts of the cyber criminals to evade exposure, listings to assist in blocking the risks to Internet users, and hopefully efforts to stop them.

In addition to original quantitative research conducted by Armin, Jonkman and McQuaid, the study draws upon the findings of other research efforts, including StopBadware, EmergingThreats, Knujon, Sunbelt, CastleCops, Spamhaus, and many others. What emerges is a picture of a front for ruthless cyber criminals, who have specifically targeted consumers in the United States and elsewhere. The study provides hard data regarding specific current activity within Atrivo, explains how consumers are targeted, describes Atrivo's virtual network structure, organizational modeling, and cites Atrivo's collusive failure to respond to abuse complaints from 2004 to the present. The study includes three dimensional charts, diagrams, and a YouTube video which make it easy to grasp the statistics or processes discussed.

Document available for download from hostexploit.com


Video of the Exploitation of a PC User - YouTube

Press reviews:

2008-04-17

The Top 25 World's Exploit Hosts and Servers - Issue 1: The Base

The Top 25 World's Exploit Hosts and Servers, deals with a holistic problem, requiring a holistic solution, "HostExploit.com" will attempt to be part of the solution.



With the increasing subversion of the DNS (Domain Name System) by the now widespread automated domain generation in the 100’s to 1,000’s per week by the exploiters. This combined with the usage of armies of virtually untraceable P2P (Peer to Peer) directed botnets and undetectable polymorphic viruses and malware. It may appear increasingly difficult for the community to even block such threats let alone reduce them. This involves the whole area of internet security and network security.


Table 1. - The Top25 World's Exploit Hosts and Servers




However, this route is controversial and hitherto a taboo subject; i.e. the hosts, registrars, and servers. Whether it is; spam, exploits, malware, spyware or even botnet control, the domains are registered, the web sites are hosted or served by an organization, i.e. the 'web host' and are assigned an AS # (Autonomous System) by ICANN. To commence we begin exposing the 'Top 25 World's Exploit Hosts and Servers' these alone serve and provide an estimated 80%+ of all the bad stuff on the Internet, infect; good servers, good websites, and overall are a scourge to the average internet user .



Why controversial or taboo?


- It is complex - Yes it is, however through already man years worth of detailed research and even more community references we will partition into manageable chunks. So will add downloadable lists, rules, block information, and educational explanation where possible . Commencing as we do here with a top down 'peeling the onion' approach.


- It involves big money, in most cases many $millions - As we unfold this subject we will provide focused details on a particular 'Exploiting Host' with the economics involved, where possible. It is our view that because an organization makes a great deal of money and exploits or spams the average user, whether 'intentional exploiters' e.g. Atrivo or 'allowed themselves to be highly infected' e.g. The Planet, does not exclude it from exposure.


- Many innocent or grey web sites may suffer due to the few - this will undoubtedly be the case . A major technique for the exploiters is to hide the needle in the haystack , however we and most Internet users would argue, this is not our problem. It is the problem for the host or server, if they are legitimate they will or should move heaven and earth to clean up their act for the benefit of the legitimate webmasters, and more importantly the . For the innocent webmasters, why are you still hosting your web site with these hosts and servers anyway?



In the final analysis this is about choice. Choice for the average PC user to reduce the threat of being exploited, the ISP (Internet Service Provider) to assist in 'prevention' for their users, the hosts, servers, and DNS registrars, to not just take an anonymous client and probably stolen credit card. Authorities such as ICANN are well aware of this increasing problem, perhaps this helps create the groundswell for them to act on behalf of the 99% of Internet users.



Useful Article Links:



Article Downloads - Top 25 csv, IP block lists


SecureWorks - Top Spam Botnets


ICANN - Advisory on Fast Flux Hosting and DNS


DNS Education - How Domain Servers Work




2008-03-24

HostExploit - What? Why? Who?

HostExploit – ‘A call to arms’- Why another Internet security blog and more ‘black hole’ lists? - It's the HOSTS!

It has become increasingly apparent the malware, spam, phishing and other BadWare distributors are now engaged in automated domain generation, 100’s to 1,000’s per week, which is proving a serious difficulty for major domain / IP ‘blocklist’ and ‘blacklist’ providers to simply keep up .

Added to this we now have; iFrame attacks via web portals, several major international web hosts with 1,000’s of their innocent and money paying clients having hacked and infectious (to web surfers) web sites, DDos (distributed denial of service), polymorphic malware that many anti-virus / spyware / malware solutions are unable to detect, and millions of PC users being directed to rogue and fake web sites.

Finally we have the rise of the Botnets, anonymously managed fast and double-flux (ever changing IP addresses) control of 1,000’s of infected zombie PCs.


We now believe the general situation on the Internet calls for an alternative and added open source approach to deal with this head on, i.e. the web hosts and Internet carriers. Every one of the IP’s, web sites or domains are hosted or carried by someone, we feel it is time to break the taboo and name, list and expose the ones that host the malware that infects us all. This approach is not to replace existing methods, but we hope it will add to the security community’s and PC user’s array of possible tools to reduce the threat.


HostExploit – Who? This blog and associated list(s) is edited by Jart Armin and James McQuaid, however the research is provided by a wider volunteer group, some of whom would rather remain anonymous, due to their other professional Internet activities. All those involved are web professionals within; web hosting, server management, DNS (Domain Name System), Internet security, and IDS (Intrusion Detection Systems).


HostExploit – Who is this for?
You, i.e. any PC user, webmaster, ISP (Internet Service Provider) or web host, who wants to reduce the threat of infection or exploitation. Where necessary or possible all topics and articles will contain added information to illuminate and educate.


HostExploit – What to expect?

• Bad Host Lists – these will be in several formats for users to apply for themselves or distribute freely. These lists will initially focus on the (b) and (c) categories (see below) can be used to black hole, block or just for general awareness - click here.


• Specific bad host exposures – On a regular basis there will be articles exposing a specific host and providing detailed and where possible quantification with a historical background.

• Bad Host categorization – host or AS (autonomous server) issue comes down to a certain level of semantics and initially crude differentiation – so we will commence with an ‘a b c’ method:

(a) Hosts / Servers / AS of 'infected sites' = - i.e. infected or hacked sites / domains which have bad exploit code, infected iFrame, SQL injections, XSS exploits, etc. to exploit visitors.

(b) Hosts / Servers / AS of 'user infector sites' = i.e. where the malware and rogues are located and more often than not, users are directed to from infections on sites within (a)

(c) Hosts / Servers / AS of 'user receptor sites' = The ultimately very bad = including the so called "the bullet proof servers" masked by the botnets to; receive, trade, pay affiliates, warez, etc. etc. - from (b); stolen IDs, credit cards, bank phishing info, for (a) to pay partners and affiliates to infect the web sites. Also for DDos Botnet C&C (command and control) actions.


HostExploit - To Inform and educate – Articles that attempt to help explain the processes and terminology involved.


HostExploit – Want to help or have your say?
This is an open source ‘non-profit’ volunteer group and we welcome help, input or feedback. However for security reasons there is no allowance for onsite comments so email HostExploit (at) gmail.com.

It is likely input would be within the following:


• To keep informed or pass on the information? – sign up for a ‘Feedburner’ feed and then you will be informed about new articles. Feel free to pass on articles and the list(s), publish in your blog or magazine or newspaper, under a ‘Creative Commons License’, obviously it is courteous to show hostexploit.com as a reference.


• Have information we may have missed or a new exposure? – email us.

• Web Host / Server / AS, and feel any information or inclusion within the list(s) is in error? – Please email us and say where we are wrong, our objective is to reduce such a list and we will be delighted to explain the error or demonstrate you have cleaned up your act.