Exploit Prevention Labs BlogAs Chief Researcher for Exploit Prevention Labs, I come across some really interesting bad-guy behavior patterns that on the whole don't bode well for the future of a trusted Internet. I'll be posting my thoughts on some of the most interesting stuff I find to this blog.This might be the ultimate irony- March 30, 2008 Today we found what might be the ultimate irony... a spyware product where the home page has been hacked, and is installing someone else's rootkit! The product is one of those spy-on-your-spousekidsemployees things that says it's stealthy (in other words, _it's_ supposed to be a rootkit itself), and the home page has a chunk of escaped javascript a href="http:bp2.blogger.com_loJ1Rw68BvQR_BEmqYiikIAAAAAAAAADMBUGQ9Kp3TKgs16http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... GPack- March 28, 2008 Correction: Sorry folks... there's so much happening at the moment, I've merged a couple of kits in my mind. It's not a mix of vbscript and javascript. It's just javascript, and thus far, we've only seen one exploit come out of it ... a mouldy, old MS06-014, although we expect there are more than that. The rest of the write-up is reasonably accurate, and we'll continue to correct things as we find more. Hi folks, A new exploit framework, called Gpack, has been popping up on our radar for ahttp://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... New Exploit Targets Corporate Users of CA Apps- March 28, 2008 Update: We should note that CA has offered a patch for the vulnerability. What is not known is how widely applied the patch is. On about March 17, 2008, some folks, such as frsirt started talking about a vulnerability in dll ocx used in various CA products. See here, for example. Today we found it in the wild, in none other than a new NeoSploit framework. This means several things... Firstly, the Neo developers are _very_ achttp://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... Arthur C Clark dies, and Space.com gets hacked!- March 23, 2008 Can't you see the pattern emerging Seriously though, uplink.space.com (careful) has had an iframe injected into it, and it's reaching out to another seemingly hacked site (www.forvideo.at - careful), img style="cursor:pointer; cursor:hand;" src="http:bp3.blogger.com_loJ1Rw68BvQR-cNPKYiihIAAAAAAAAAChttp://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... Something new tonight- March 20, 2008 Tonight we found something new in an exploit pack coming from a site in China. Well, the exploit is actually from May 2007, but this is the first time we've seen it in use. This indicates two things... the first is that the Bad Guys are apparently combing older exploit announcements looking for appropriate samples. When you think about it, any exploit that allows remote code execution, and for which there is no forced or automatic upgrade of the vulnerable program is useful to them. Remember, thhttp://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... Unfortunate hack at tax time- March 13, 2008 We noticed a couple of Alabama county websites have been hacked, with a Neosploit call out to a website in Germany. The two websites are... hxxp:www.co.blount.al.us and hxxp:www.blountrevenue.com (The actual exploit server in Germany seems to be 404 at the moment, but you should still be careful) The second one is more interesting, particularly given the time of year. The front page looks like this ... a href="http:bp2.blogger.com_loJ1Rw68BvQR9mahttp://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... Something interesting- March 2, 2008 Hat-tip to Stle Fagerland of Norman for noticing this article ... To save you _having_ to read it, the story is about a CEO of a Korean software company being arrested for foisting fake anti-spy software on unsuspecting victims. (entering sarcasm mode) Gosh, who"d have thought it (leaving sarcasm mode) Apparently, not only would the software lie about detecting problems on the system, and try really hard to get victihttp://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... |