Thursday, March 22, 2012

New variant of Duqu


As a facinated by the history of Duqu and Stuxnet I found this very intereting. See the text below by Kelly Jackson Higgins from Dark Reading.

The creators of Duqu may not have used traditional malware writers to craft their code, but they have done something that malware writers do: They released a new variant of their code with just enough tweaks to evade detection.

A day after researchers from Kaspersky Lab revealed that with the help of the security community, they had cracked the mystery of the programming language used in Duqu, researchers from Symantec yesterday announced they had discovered a new variant of Duqu -- the first one spotted since October. The first two were found in the wild in November 2010.

Vikram Thakur, principal manager at Symantec Security Response, says the creators of Duqu -- which Symantec and Kaspersky agree are the same ones who are behind Stuxnet -- basically changed a few bytes here and there to allow the malware to sneak past detection tools, including an open-source one built by the Laboratory of Cryptography and System Security (CrySyS Labs). "This is round two of the same thing: the old code, tweaked a bit," Thakur says.

The attackers changed the encryption algorithm and, rather than employing a stolen digital certificate as they had done before, used a phony Microsoft cert to make the driver appear to be legitimate. The sample discovered by Symantec came out of Iran, Thakur says, and it's just one piece of the malware package: specifically, the "loader," which installs the rest of the malware when the victim's machine restarts. The compile date on the malware is Feb. 23, 2012.

"We just found one component. We don't have the main file that landed on the computer or the config file where the command-and-control server is," he says.

Even so, it was enough evidence to show that the Duqu gang has not given up, despite all of the publicity and research focused on it. "These guys have a mission, whatever that might be, and don't care about what the security community or media might know about the threat," Thakur says. "They are extremely confident that it won't get back to them or be attributable to the person behind it. So they are continuing business as it is."

Roel Schouwenberg, senior antivirus researcher for Kaspersky Lab, says the latest move by the Duqu creators is that they are watching and will change their code as necessary. "It shows that their operations are still ongoing," Schouwenberg says. "It also means that up until that time, they didn't see a need to actually release new variants to evade detection."

And they obviously plan to use their existing framework despite the research community's scrutiny. They continue to leverage their investment in that code, security experts say.

Meanwhile, both Symantec and Kaspersky maintain that Duqu is more of an intelligence-gathering, cyberespionage malware, while Stuxnet was built to sabotage its target. Symantec's Thakur says the tricky part is that it's difficult to gain visibility into Duqu because it's so targeted. "We think Duqu does reconnaissance and [the attackers] take action based on the data they get back. Whether it's one mission ... is still up for debate," he says. "It's definitely by the same people."

Kaspersky's Schouwenberg says it's no surprise that Duqu showed up again in Iran. "Stuxnet's mission was sabotage. Duqu's mission was espionage and intelligence-gathering. Everything we have seen so far indicates that this operation is basically to gauge the status of the [Iranian] nuclear progress," he says.

And this won't be the last variant of Duqu. "I have no doubt we are going to see additional versions of Duqu. Maybe they are already out there," Thakur says. It's less likely there will be a new Stuxnet variant attacking the same Iranian nuclear facility, however, he says.

While enterprises, in general, don't have to worry much about Duqu, the sophisticated malware has added a new dimension to cyberespionage. "Duqu's espionage is clearly much better written than the average 'APT' espionage thing we see on a daily basis," Kaspersky's Schouwenberg says. "People should be paying attention to Duqu. There's a lot of interest in IP [intellectual property] out there."

To read the entire post from Dark Reading click here.

Thursday, March 15, 2012

51% of website traffic on the Internet is "non human"


A study released today shows that an alarming 51% of website traffic on the Internet are not actually humans but come from automated programs, most of which are malicious.

The study done by Incapsula, a provider of cloud security for websites, claims that most of this "non human" traffic is invisible because it does not show up on analytics software. The data was apparently collected from a sample of 1000 websites that are enrolled in to the Incapsula service. The breakdown of the 51% of "non-human" traffic is as follows:

- 5% is hacking tools searching for an unpatched or new vulnerability in a web site.

- 5% is scrapers.

- 2% is automated comment spammers.

- 19% is from “spies” collecting competitive intelligence.

The remaining 20% while automated, comes from benign search engines.

Source: HITB

Friday, February 17, 2012

New cybersecurity bill would define 'critical' infrastructure


Source: HITB
Submitted by: l33tdaw

A group of senators introduced a bill earlier this week that calls for the U.S. government to determine which infrastructure firms are, in fact, "critical," and could force these companies to develop and meet security standards.

The Cybersecurity Act of 2012 calls for the Department of Homeland Security to assess the risks major cyberattacks pose to power plants, electrical and water companies, waste-treatment facilities and other infrastructure systems.

As worded in the legislation, companies "whose disruption from a cyber attack would cause mass death, evacuation, or major damage to the economy, national security, or daily life," would fall under the definition of critical infrastructure. These companies would then have to work with the DHS to develop and comply with security standards and "cybersecurity performance requirements." Firms would retain the right to appeal the "critical infrastructure" designation.

Saturday, November 26, 2011

How to Crack WPA2 [BackTrack 5]

BackTrack 5 Overview - Video

Great overview video of the new version of BackTrack.
The author gives some explanation on what some of the tools do. Great source for someone that is just getting into Linux and wants to know what Backtrack is and what it can do.

Tuesday, November 22, 2011

Great CompTIA training resource

Hey everyone,

during my Computer Repair class we were discussing about good resource of information to get prepared for the CompTIA A+ certification exam. The lab manager at HCC recommended the web site ProfessorMesser.com.
At the top of his page, you can see some tabs for the different training programs. Under each tab, you find links to videos and quizzes.
Each video takes from 5 to 30 min long, and have an excellent coverage of the material for the exams.
This is a great resource to get an extra help in order to prepare for the CompTIA exams.
Visit the web site and find more information.

Sunday, November 13, 2011

Facebook infected by Anonymous 'Fawkes Virus'

     According to the web site The Enquirer, the group Anonymous has infected Facebook with a new virus. See the article below.

By Dave Neal.

     HACKTIVIST GROUP Anonymous has posted a video about a virus on Facebook that appears to be spinning out of control.
"Anonymous #Operation 'Fawkes Virus' Released on Facebook," said a short tweet made by the @Anon_Central account, which links to a Youtube video.
     The video says that the virus attaches itself to a Facebook page, starts sending out malicious links and gains access to your account. Once there it seizes control, then starts making friend requests and hopping between pages.
     According to the video the worm is sophisticated and a hacked account could open users up to hacks on their hard drives and loss of control over their entire systems. Although it seems firmly rooted in Facebook, the video said that it could be applied to any social network and added, "We did not expect the intensity in which it would spread."
     "Anonymous would like to welcome you to the Fawkes virus which was fully written by Anonymous programmers," says the robotic voice-over as it explains just how far and wide and vigorously it seems to be spreading. "After the worm is under control Anonymous will use this to its advantage against corruption and as an alternative attack against its opponents".
     We have asked Facebook for a comment on the virus, and will update when we have its response.

Friday, November 11, 2011

Do you have a Facebook account?

Here are some "not fun" facts about Facebook's security that the web site The Register post on 10/30/11.

     Every 24 hours 600,000 Facebook accounts are subject to attempted hacking or violation, Facebook has revealed.
     The Social Network™ disclosed details of hacking activity as it unveiled new measures to protect user’s privacy. “We are adapting and responding to new threats everyday and will continue to roll out new ways to protect your account,” Facebook said.
     In a blog post, Facebook revealed new tools to help users access their accounts if they are locked out and help prove your identity through your friends. “It's sort of similar to giving a house key to your friends when you go on vacation - pick the friends you most trust in case you need their help,” it explains.
     ‘Trusted friends’ allows users to nominate a few friends as a default measure that will be given access codes to your account if you cannot access it.
     It is also testing a feature that allows users to use app passwords for logging into third party applications.
     Initial feedback from users has been mixed with many pointing out that “friends” are also subject to hacking and security maybe further compromised by exposing access information to other parties.
     Meanwhile according to researchers at Barracuda Labs, one in 100 tweets are malicious while one in 60 Facebook posts are malicious.
     The new Barracuda survey data of social media users found that LinkedIn is the least-blocked social network by enterprises, with only 20 percent of organizations preventing their employees from using LinkedIn from work.
     Over 90 percent of users have received spam over a social network, and more than half have experienced phishing attacks. More than 20 percent have received malware, 16.6 percent have had their account used for spamming, and about 13 percent have had their account hijacked or their password stolen. Significantly more than half are unhappy with Facebook's privacy controls. ®

Source The Register 10/30/11.

Lastest on Duqu

Hungarian research centre CrySyS releases Duqu detection toolkit
Patch Tuesday leaves Duqu 0-day for another day
Microsoft Issues Workaround for Kernel Flaw Exploited by Duqu
Duqu spawned by 'well-funded team of competent coders'

Wednesday, November 9, 2011

Duqu - the backdoor for a catastrophe

     A new era of computer system attacks have come from the movies to our reality. As new time comes, the computer and technology era evolves faster than anything else, I guess, if not compared to the excitement and ambition of virtual-terrorists. User’s computers, servers, entire networks, or even large institutions do not seem to be desirable enough targets to attack. During summer 2011, Stuxnet amazed everyone with its impressive well-written code and alerted us all about the intention of this new era of attacks. Around October 14th 2011, not too long after Stuxnet hit the security world news, another similar-coded threat was discovered in computer system located in Europe, Duqu. Because the similarities in their codes, researchers still don’t know which malware came first since Duqu seems to be a first stage, reconnaissance phase, of a Stuxnet attack. Named after the filename prefix it creates “~DQ”, Duqu is still being researched and decoded by the major research labs around the world, and is directly linked to Stuxnet because of its similarities and differences.
     Even though researchers seem to agree that it is the same person or organization that wrote both malwares, Duqu differentiates from Stuxnet. Duqu has about 50% of its code exactly the same as the code used in Stuxnet; however both malware have different purpose. According to Symantec, Duqu's purpose is to gather intelligence data and assets from entities, in order to more easily conduct a future attack against another third party. The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility, a SCADA-type of attack as the intention of the code found in Stuxnet. Also, instead of a payload designed to sabotage an industrial control system, the Duqu payload has been replaced with general remote access capabilities.
     Duqu have an unusual purpose when compare to other information gathering malware, but have clever characteristics. Duqu is a remote access Trojan (RAT) that does not self-replicate. The main purpose is to open a backdoor to retrieve information from an infostealer program that can record keystrokes, enumerating the network and gain other system information. Using HTTP and HTTPS to communicate with the command-and-control server, the malware uses a C&C protocol to primarily downloading or uploading what appear to be a JPG files. Once the communication is established, it retrieves an encrypted and compressed local log file. Finally, because it is configured to run for 36 days it will automatically remove itself from the system.
     According to the latest updated on Duqu, an installer has been recent recovered. CrySys, the same research lab that initially discovered Duqu, was able to recover one of the many possible installers of the malware. The installer was integrated in a Microsoft Word document (.doc) and exploits a previously unknown kernel vulnerability that allows code execution. Once the file is opened, the malware installs the main Duqu binaries. Below is a schematic of how the Word document installs Duqu.
     Although investigation and research from all major AV companies and even Microsoft continue, nobody could extract all desired details from the code found in the variants of Duqu. What they know is that if it was the same person or organization that wrote both Duqu and Stuxnet, the programmers did not repeated the same mistake of using a stolen certificate from a Taiwan company as they did with Stuxnet. With Duqu, they managed to use an untraceable digital certificate, making it more mysterious. A greater and more serious suspicion is that because of the complexity of both codes, researches believe that nation-states could be behind these attacks. For far, Duqu infections have been confirmed in six possible organizations in eight countries. The author of Duqu nobody knows yet, but in game is the ability and power of a nation being aware of and prepared to deal with the major results of a successful attack.

Reference:

Tuesday, November 8, 2011

Stuxnet: Anatomy of a computer virus

A new era of computer system virus. Are we prepared?

Stuxnet: Anatomy of a Computer Virus from Patrick Clair on Vimeo.

Windows Evolution

I thought it was cool to see all the different version of Window.
Which one have you used?

1985  Windows 1.0
 

1987  Windows 2.0

1988  Windows 2.1

1990   Windows 3.0

1992  Windows 3.1

1995  Windows 95

1998  Windows 98

2000   Windows Me

2001   Windows XP

2006   Windows Vista

2009   Windows 7

2012  Windows 8