<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: workaround]]></title>
    <link>http://securityratty.com/tag/workaround</link>
    <description></description>
    <pubDate>Thu, 24 Apr 2008 00:37:46 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Web Based Botnet Command and Control Kit 2.0]]></title>
      <link>http://securityratty.com/article/4f945955ba8a424fe6b9352583602062</link>
      <guid>http://securityratty.com/article/4f945955ba8a424fe6b9352583602062</guid>
      <description><![CDATA[The average web based command and control kit for a botnet consisting of single user, single campaign functions only, has just lost its charm, with a recent discovery of a proprietary botnet kit whose...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK7vNKA_3xI/AAAAAAAACFk/bFba_0dWvI4/s1600-h/web_botnet_cc_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK7vNKA_3xI/AAAAAAAACFk/TqKIw6bxpjw/s200-R/web_botnet_cc_1.JPG" /></a>The average web based command and control kit for a botnet consisting of single user, single campaign functions only, has just lost its charm, with a recent discovery of a proprietary botnet kit whose features clearly indicate that the kit's coder know exactly which niches to fill - presumably based on his personal experience or market research into competing products.<br />
<br />
What are some its key differentiation factors? <b>Multitasking</b> at its best, for instance, the kits provides the botnet master with the opportunity to manage numerous different task such as several malware campaigns and DDoS attacks simultaneously, where each of these gets a separate metrics page.  <b>&nbsp;</b><br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8Bf1BEKoI/AAAAAAAACFs/Yicbw9alvSs/s1600-h/web_botnet_cc_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8Bf1BEKoI/AAAAAAAACFs/rzG7g1DxhQs/s200-R/web_botnet_cc_2.JPG" /></a><b>Automation</b> of malicious tasks, by setting up tasks, and issuing notices on the status of the task, when it was run and when it was ended. Just consider the possibilities for a scheduling malware and DDoS attacks for different quarters. <b>&nbsp;</b><br />
<br />
<b>Segmentation</b> in every aspect of the tasks, for instance, a DDoS attacks against a particular site can be scheduled to launched on a specific date from infected hosts based in chosen countries only. <b>&nbsp;</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8BqO4a_VI/AAAAAAAACF0/UMGxAh9uGF0/s1600-h/web_botnet_cc_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8BqO4a_VI/AAAAAAAACF0/ZlxV-mc44fM/s200-R/web_botnet_cc_3.JPG" /></a><b>Customized DDoS</b> in the sense of empowering the botnet master with point'n'click ability to dedicate a precise number of the bots to participate, which countries they should be based in, and for how long the attack should remain active. <b>Quality and assurance in DDoS attacks</b> based on the measurement of the bot's bandwidth against a particular country, in this case the object of the attack, so theoretically bots from neighboring countries would DDoS the country in question far more efficiently. <b>&nbsp;</b><br />
<br />
<a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8B0rE_rgI/AAAAAAAACF8/NKwLnKmmH44/s1600-h/web_botnet_cc_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8B0rE_rgI/AAAAAAAACF8/pVosEgAltxk/s200-R/web_botnet_cc_4.JPG" /></a><b>Historical malware campaign performance</b>, is perhaps the most quality assurance feature in the entire kit, presumably created in order to allow the person behind it to measure which were the most effective malware and DDoS campaigns that he executed in the past. From an OSINT perspective, sacrificing his operational security by maintaing detailed logs from previous attacks is a gold mine directly establishing his relationships with previous malware campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8B8T36-3I/AAAAAAAACGE/BhFmeDoa8Lk/s1600-h/web_botnet_cc_5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8B8T36-3I/AAAAAAAACGE/vij9THb60ow/s200-R/web_botnet_cc_5.JPG" /></a><b>Bot Description</b>:  &nbsp; <br />
<div dir="ltr" id="result_box">1. Completely invisible Bot work in the system.  <br />
2. Not loads system.  <br />
3. Invisible in the process.  <br />
4. Workaround all firewall.  <br />
5. Bot implemented as a driver.  </div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CIQJHsKI/AAAAAAAACGM/SzpE6NqryP8/s1600-h/web_botnet_cc_6.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CIQJHsKI/AAAAAAAACGM/CptzW9_ji-k/s200-R/web_botnet_cc_6.JPG" /></a><b>Functions Bot</b> (constantly updated):&nbsp;</div><div dir="ltr" id="result_box">1. Downloading a file (many options). <br />
2. HTTP DDoS (many options, including http authentication).  </div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CQZXzF1I/AAAAAAAACGU/LI52hSDJhpA/s1600-h/web_botnet_cc_7.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CQZXzF1I/AAAAAAAACGU/AIaGhGUL0Fk/s200-R/web_botnet_cc_7.JPG" /></a><b>The web interface</b>&nbsp;</div><div dir="ltr" id="result_box">-- Convenient manager tasks. <br />
-- Every task can be stopped, put on pause, etc. ... <br />
-- Interest and visual scale of the task.&nbsp;&nbsp;</div><div dir="ltr" id="result_box">-- A task manager for DDoS and Loader <br />
&nbsp;&nbsp;&nbsp;&nbsp;</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8Cvw3fTbI/AAAAAAAACGc/Zqcrn6XWYEw/s1600-h/web_botnet_cc_8.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8Cvw3fTbI/AAAAAAAACGc/0PQgE_timh4/s200-R/web_botnet_cc_8.JPG" /></a>-- <b>For DDoS tasks</b> </div><div dir="ltr" id="result_box">Bots involved in DDoS 'f. <br />
Condition of the victim (works, fell).  <br />
</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8C5JVrIeI/AAAAAAAACGk/HNHO_ar0MgA/s1600-h/web_botnet_cc_9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8C5JVrIeI/AAAAAAAACGk/Y1z0VIR3B9k/s200-R/web_botnet_cc_9.JPG" /></a>2. <b>Bots manager  </b><br />
-- Displays a list of bots (postranichno). <br />
-- Obratseniya date of the first and last. <br />
-- ID Bot. <br />
-- Country Bot. <br />
-- Type Bot. <br />
-- The status Bot (online / offline). <br />
-- Bot bandwidth to different parts of the world (europe, asia). <br />
-- The possibility of removing bots</div><div dir="ltr" id="result_box">-- When you click on ID Bot loadable still a wealth of information about it</div><div dir="ltr" id="result_box"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8D0Vm4XxI/AAAAAAAACGs/BM5pm1_Rtag/s1600-h/web_botnet_cc_11.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8D0Vm4XxI/AAAAAAAACGs/mQEa7wVxDNc/s200-R/web_botnet_cc_11.JPG" /></a>3. <b>Statistics botneta  </b><br />
-- Statistics both common and build Bot. <br />
-- Information on the growth and decline botneta dates (and build). <br />
-- Bots online <br />
-- All bots</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8D6Gv_qnI/AAAAAAAACG0/JTOJS-ZHQek/s1600-h/web_botnet_cc_12.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8D6Gv_qnI/AAAAAAAACG0/ujbOfFEX9TA/s200-R/web_botnet_cc_12.JPG" /></a>-- Dead bots. <br />
<br />
4. <b>Statistics botneta country</b></div><div dir="ltr" id="result_box">-- All countries to work on&nbsp;</div><div dir="ltr" id="result_box">-- New work by country&nbsp;</div><div dir="ltr" id="result_box">-- Online work from country to country</div><div dir="ltr" id="result_box">-- Dead bots by country</div><div dir="ltr" id="result_box"></div><div dir="ltr" id="result_box">5. <b>Detailed history botneta</b>&nbsp;</div><div dir="ltr" id="result_box">6. <b>Convenient user-friendly interface adding teams</b> <br />
8. <b>Admin minimal server loads</b>  <br />
-- Use php5/mysql  <br />
</div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8EKSfrczI/AAAAAAAACG8/3oulo2cgTtM/s1600-h/web_botnet_cc_13.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8EKSfrczI/AAAAAAAACG8/xEI9xAwNGNM/s200-R/web_botnet_cc_13.JPG" /></a><b>Upcoming features : </b><br />
1. Form grabber (price increase substantially), for old customers will be charged as an upgrade <br />
2. Public key cryptography<br />
3. Clustering campaigns and DDoS attacks<br />
<br />
Despite it's proprietary nature, it's quality and innovative features will sooner or later leak out for everyone to take advantage of, a rather common lifecycle for the majority of proprietary malware kits in general.</div><div dir="ltr" id="result_box"><br />
<b>Related posts:</b></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/02/blackenergy-ddos-bot-web-based-c.html">BlackEnergy DDoS Bot Web Based<br />
</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A New DDoS Malware Kit in the Wild</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The Cyber Bot - Web Based Malware</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The Black Sun Bot - Web Based Malware</a> </div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/09/custom-ddos-capabilities-within-malware.html">Custom DDoS Capabilities Within a Malware</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">Botnet on Demand Service</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/03/loadsccs-ddos-for-hire-service.html">Loads.cc - DDoS for Hire Service</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a>&nbsp;</div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/03/botnet-communication-platforms.html">Botnet Communication Platforms</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/04/botnet-masters-to-do-list.html">A Botnet Master's To-Do List</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/05/ddos-on-demand-vs-ddos-extortion.html">DDoS on Demand VS DDoS Extortion</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/how-does-botnet-with-100k-infected-pcs.html">How Does a Botnet with 100k Infected PCs Look Like?</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Y5dBtK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Y5dBtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WsNccK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WsNccK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ToV4Pk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ToV4Pk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=I6a7ak"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=I6a7ak" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2S7WNK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2S7WNK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Qk66sK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Qk66sK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8S5ask"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8S5ask" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/372102101" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 10:02:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ddos attacks based">ddos attacks based</category>
      <category domain="http://securityratty.com/tag/ddos attacks">ddos attacks</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/previous malware campaigns">previous malware campaigns</category>
      <category domain="http://securityratty.com/tag/ddos attacks simultaneously">ddos attacks simultaneously</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/country bot">country bot</category>
      <category domain="http://securityratty.com/tag/ddos">ddos</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/372102101/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</source>
    </item>
    <item>
      <title><![CDATA[VMware Big-Time Boo-Boo]]></title>
      <link>http://securityratty.com/article/f9466fc19dd83d3ab8c94a3fa2655f2a</link>
      <guid>http://securityratty.com/article/f9466fc19dd83d3ab8c94a3fa2655f2a</guid>
      <description><![CDATA[VMware needs some good press these days. What it certainly does not need is this VI 3.5 update snafu which can shutdown thousands of virtual infrastructures and breaks VMotion
Alert do not upgrade to...]]></description>
      <content:encoded><![CDATA[<p>VMware needs some good press these days. What it certainly does not need is this VI 3.5 update snafu which can <a href="http://www.virtualization.info/2008/08/vmware-mistake-shuts-down-thousands-of.html" target="_blank">shutdown “thousands of virtual infrastructures”</a> and breaks VMotion.
<p><b>Alert – do not upgrade to Virtual Infrastructure 3.5 Update 2.</b>
<p>Apparently there’s some problem with the license expiration time and the workaround suggested by a Virtualization.Info reader is to set the date back to August 10 – which of course messes up your logs and any monitoring that you may be doing. No immediate solution forthcoming from VMware and in fact, good luck getting in touch with the company.
<p>“At the moment it seems that <strong>the entire VMware Knowledge Base collapsed</strong>. Calling the support line customers can just receive a brief message saying that <strong>the problem will be solved within 36 hours</strong>. <br />Additionally, <strong>VMware removed the capability to download any affected product</strong>.”</p>
]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 14:49:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/support line customers">support line customers</category>
      <category domain="http://securityratty.com/tag/license expiration time">license expiration time</category>
      <category domain="http://securityratty.com/tag/virtual infrastructures">virtual infrastructures</category>
      <category domain="http://securityratty.com/tag/breaks vmotion">breaks vmotion</category>
      <category domain="http://securityratty.com/tag/info reader">info reader</category>
      <category domain="http://securityratty.com/tag/shutdown thousands">shutdown thousands</category>
      <category domain="http://securityratty.com/tag/virtual infrastructure">virtual infrastructure</category>
      <category domain="http://securityratty.com/tag/luck">luck</category>
      <source url="http://blog.sciencelogic.com/vmware-big-time-boo-boo/08/2008">VMware Big-Time Boo-Boo</source>
    </item>
    <item>
      <title><![CDATA[Cisco IPS Jumbo Frame DoS]]></title>
      <link>http://securityratty.com/article/30454d5fc63a7266c8e9e99fd78bec4d</link>
      <guid>http://securityratty.com/article/30454d5fc63a7266c8e9e99fd78bec4d</guid>
      <description><![CDATA[For a networking company, thats gotta hurt
From Cisco
Cisco Intrusion Prevention System (IPS) platforms that have gigabit network interfaces installed and are deployed in inline mode contain a denial...]]></description>
      <content:encoded><![CDATA[<p>For a networking company, that&#8217;s gotta hurt.</p>
<p>From Cisco:</p>
<blockquote><p>Cisco Intrusion Prevention System (IPS) platforms that have gigabit network interfaces installed and are deployed in inline mode contain a denial of service vulnerability in the handling of jumbo Ethernet frames. This vulnerability may lead to a kernel panic that requires a power cycle to recover platform operation. Platforms deployed in promiscuous mode only or that do not contain gigabit network interfaces are not vulnerable.</p>
<p>Cisco has released free software updates that address this vulnerability. There is a workaround for this vulnerability.</p></blockquote>
<p>Update or workaround? Which is it then? At the very least get your patch on.</p>
<p><a href="http://www.cisco.com/warp/public/707/cisco-sa-20080618-ips.shtml">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=Vm2zt9"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=Vm2zt9" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=bkPt2I"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=bkPt2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=yttCii"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=yttCii" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=YD8Jki"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=YD8Jki" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=9543ri"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=9543ri" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=NbWq0i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=NbWq0i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/314909884" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 18 Jun 2008 17:22:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gigabit network interfaces">gigabit network interfaces</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/service vulnerability">service vulnerability</category>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <category domain="http://securityratty.com/tag/jumbo ethernet frames">jumbo ethernet frames</category>
      <category domain="http://securityratty.com/tag/recover platform operation">recover platform operation</category>
      <category domain="http://securityratty.com/tag/kernel panic">kernel panic</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/power cycle">power cycle</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/314909884/">Cisco IPS Jumbo Frame DoS</source>
    </item>
    <item>
      <title><![CDATA[Crimeware in the Middle - Zeus]]></title>
      <link>http://securityratty.com/article/7031903e13ac81d8b420bb698c242d03</link>
      <guid>http://securityratty.com/article/7031903e13ac81d8b420bb698c242d03</guid>
      <description><![CDATA[Virtual greed, or response rate optimization? The idea of converging phishing emails with embedded exploits and banking malware is nothing new, in fact phishers realizing that combining attack...]]></description>
      <content:encoded><![CDATA[<div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SBBF9tDpi_I/AAAAAAAABn4/wmeAn27YZ30/s1600-h/zeus_in_the_middle.JPG"><img id="BLOGGER_PHOTO_ID_5192727296727419890" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SBBF9tDpi_I/AAAAAAAABn4/wmeAn27YZ30/s200/zeus_in_the_middle.JPG" border="0" /></a>Virtual greed, or response rate optimization? The idea of converging phishing emails with embedded exploits and banking malware is nothing new, in fact phishers realizing that combining attack approaches can increase the chance of achieving their objective which in this case is either logging the authentication process or hijacking it, often forget that the phishing email could have succeeded without the embedded malware or exploit, which in many cases would have triggered an alarm.<br /><br />Yesterday, <a href="http://rsa.com/blog/blog_entry.aspx?id=1274">Uriel Maimon posted an overview of the convergence of Rock Phish emails with Zeus</a>, a crimeware kit used to deliver banking trojans :<br /><br />"<span style="font-style: italic;">The Trojan that was used in this attack belonged to the "Zeus" family of malware. Zeus is a nefarious type of Trojan for multiple reasons:</span> <span style="font-style: italic;"><br /><br />1. The Zeus Trojan is a kit for sale: Anyone in the criminal community can purchase it for roughly $700. This means that the Rock group did not need to develop new skill-sets to write Trojan horses; they just purchased it on the open market. In the past 6 months RSA's Anti-Fraud Command Center has detected more than 150 different uses of the Zeus kit, each one infecting on average roughly 4,000 different computers a day.</span> <span style="font-style: italic;"><br /><br />2. Resistance to detection: The kit purchased is a binary generator. Each use creates a new binary file, and these files are radically different from each other -- making them notoriously difficult for anti-virus or security software to detect. To date very few variants have had effective anti-virus signatures against them and each use of the kit usually makes existing signatures ineffective. Just like in most cases, this particular use of the Zeus kit did not have any a</span><span style="font-style: italic;">nti-virus detection (with the popular engines we tested) at the time of this writing.</span> <span style="font-style: italic;"><br /><br />3. Rich feature set: the Zeus Trojan has many startling capabilities. In addition to listening in on the submission of forms in the browser, the Trojan also has advanced capabilities, for instance the ability to take screenshots of a victim's machine, or control it remotely, or add additional pages to a website and monitor it, or steal passwords that have been stored by popular programs (remember when you clicked on the "Remember this password?" checkbox?)... And the features-list goes on.</span> <span style="font-style: italic;">As I look upon this blissful union of fraud and crime technologies, I can only envy the criminals who can find such coupling. Looking forward to my next birthday, I can only hope that I will have the opportunity to find such partnership in my own life (and maybe give my mother one less reason for disappointment).</span>"<br /><br />We cannot talk about Zeus unless we compare it to another such crimeware kit serving banking trojans, in this <a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">the Metaphisher kit</a>. Metaphisher is particularly interested because of its much more customized GUI, it's modular nature, allowing its sellers to lower or increase the price depending on which modules you'd like included, and which ones you'd like excluded, where a module means a preconfigured fakes, TANs, and phishing pages for all the banks in a country of choice. Moreover, despite that both, Zeus and Metaphisher are open source, and therefore malicious parties visionary enough to build communities around their kits in order to enjoy the innovation brought by multiple parties, Metaphisher has a bigger community next to Zeus, considered as the MPack in the web malware exploitations kits, namely a bit of an outdated commodity that is of course still capable of doing what does best - hijacking E-banking sessions and logging them to the level of impersonation.<br /><br />How are the authors of Zeus describing the kit themselves? Here's a description :<br /><br />"<span style="font-style: italic;">ZeuS has the following main features and properties (full list is given here, in your part of assembling this list may not):</span>  <span style="font-style: italic;"><br /><br />Bot:</span> <span style="font-style: italic;">- Written in VC + + 8.0, without the use of RTL, etc., on pure WinAPI, this is achieved at the expense of small size (10-25 Kb, depends on the assembly).</span> <span style="font-style: italic;"><br /><br />- There has its own process, through this can not be detected in the process list.</span> <span style="font-style: italic;"><br />- Workaround most firewall (including the popular Outpost Firewall versions 3, 4, but suschetvuet temporary small problem with antishpionom). Not a guarantee unimpeded reception incoming connections.</span> <span style="font-style: italic;"><br />- Difficult to d</span><span style="font-style: italic;">etect finder / analysis, bot sets the victim and creates a file, the system files and arbitrary size.</span><br /><span style="font-style: italic;">- Works in limited accounts Windows (work in the guest account is not currently supported).</span> <span style="font-style: italic;"><br />- Nevid ekvaristiki for antivirus, Bot body is encrypted.</span> <span style="font-style: italic;"><br />- Some way creates a suspected its presence, if you do not want it. Here is the view of the fact that many authors do love spyware: unloading firewall, antivirus, the ban on their renewal, blocking Ctrl + Alt + Del, etc.</span><br /><span style="font-style: italic;">- Locking Windows Firewall (the feature is required only for the smooth reception incoming connections).</span> <span style="font-style: italic;"><br />- All your settings / logs / team keeps bot / Takes / sends encrypted on HTTP (S) protocol. (ie, in text form data will see only you, everything else bot <-> server will look like garbage).</span> <span style="font-style: italic;"><br />- Detecting NAT through verification of their IP through your preferred site.</span> <span style="font-style: italic;"><br />- A separate configuration file that allows itself to protect against loss in cases of inaccessibility botneta main server. Plus additional (reserve) configuration files, to which the bot will ap</span><span style="font-style: italic;">ply, will not be available when the main configuration file. This system ensures the survival of your botneta in 90% of cases.</span> <span style="font-style: italic;"><br />- Ability to work with any browsers / programs work through wininet.dll (Internet Explorer, AOL, Maxton, etc.):</span> <span style="font-style: italic;"><br />- Intercepting POST-data + interception hitting (including inserted data from the clipboard).</span> <span style="font-style: italic;"><br />- Transparent URL-redirection (at feyk sites, etc.) c task redirect the simplest terms (for example: only when GET or POST request, in the presence or absence of certain data in POST-request).</span> <span style="font-style: italic;"><br />- Transparent HTTP (S) substitution content (Web inzhekt, which allows a substitute for not only HTML pages, but also any other type of data). Substitution of sets with the help of guidance masks substitute.</span><br /><span style="font-style: italic;">- Obtaining the required contents page, with the exception HTML-tags. Based on Web inzhekte.</span> <span style="font-style: italic;"><br />- Custo</span><span style="font-style: italic;">mizable TAN-grabber for any country.</span> <span style="font-style: italic;"><br />- Obtaining a list of questions and answers in the bank "Bank Of America" after successful authentication.</span> <span style="font-style: italic;"><br />- Removing POST-needed data on the right URL.</span> <span style="font-style: italic;"><br />- Ideal Virtual Keylogger solution: After a call to the requested URL, a screenshot happening in the area, where was clicking.</span> <span style="font-style: italic;"><br />- Receiving certificates from the repository "MY" (certificates marked "No exports" are not exported correctly) and its clearance. Following is any imported certificate will be saved on the server.</span> <span style="font-style: italic;"><br />- Intercepting ID / password protocols POP3 and FTP in the independence of the port and its record in the log only with a successful authorise.</span> <span style="font-style: italic;"><br />- Changing the local DNS, removal / appendix records in the file% system32% \ drivers \ etc \ hosts, ie comparison specified domain with the IP for WinSocket.</span> <span style="font-style: italic;"><br />- Keeps c</span><span style="font-style: italic;">ontents Protected Storage at first start the computer.</span> <span style="font-style: italic;"><br />- Removes S ookies from the cache when Internet Explorer first run on a computer.</span> <span style="font-style: italic;"><br />- Search on the logical disk files by mask or download a specific file.</span><br /><span style="font-style: italic;">- Recorded just visited the page at first start the computer. Useful when installing through sployty, if you buy a download service from the suspect, you can see that even loaded in parallel.</span><br /><span style="font-style: italic;">- Getting screenshot with the victim's computer in real time, the computer must be located outside the NAT.</span> <span style="font-style: italic;"><br />- Admission commands from the server and sending reports back on the successful implementation. (There are currently launching a local / remote file an immediate update the configuration file, the destruction OS).</span> <span style="font-style: italic;"><br />- Socks4-server.</span><br /><span style="font-style: italic;">- HTTP (S) PROXY-server.</span> <span style="font-style: italic;"><br />- Bot Upgrading to the latest version (URL new version set in the configuration file).</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SBBPQdDpjAI/AAAAAAAABoA/2LMvwvtY3uQ/s1600-h/zeus_in_the_middle_fake_injects.JPG"><img id="BLOGGER_PHOTO_ID_5192737514454617090" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SBBPQdDpjAI/AAAAAAAABoA/2LMvwvtY3uQ/s200/zeus_in_the_middle_fake_injects.JPG" border="0" /></a>What's most important to keep in mind in regarding to these crimeware kits, is that the sellers are shifting from product-centered to service-centered propositions, and while an year ago they would have been selling the kit only, today they've realized that it's the output of the kit in terms of logged stolen accounting data that they're selling. <a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">Committing identity theft and abusing stolen E-banking accounting data is already a service</a>, compared to the product it used to be.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2007/11/targeted-spamming-of-bankers-malware.html">Targeted Spamming of Bankers Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/03/localized-bankers-malware-campaign.html">Localized Bankers Malware Campaign</a><br /><a href="http://ddanchev.blogspot.com/2007/05/client-application-for-secure-e-banking.html">Client Application for Secure E-banking?</a><br /><a href="http://ddanchev.blogspot.com/2007/05/defeating-virtual-keyboards.html">Defeating Virtual Keyboards</a><br /><a href="http://ddanchev.blogspot.com/2007/08/paypals-security-key.html">PayPal's Security Key</a><br /><a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">Nuclear Grabber Kit</a><br /><a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">Apophis Kit</a> </div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aTzMwJG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aTzMwJG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2VBaffG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2VBaffG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TWtWGFg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TWtWGFg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yhZiA5g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yhZiA5g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QlyIkhG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QlyIkhG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GeVECiG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GeVECiG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8XfDHog"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8XfDHog" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/276786652" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 24 Apr 2008 00:37:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/remote file">remote file</category>
      <category domain="http://securityratty.com/tag/zeus trojan">zeus trojan</category>
      <category domain="http://securityratty.com/tag/binary file">binary file</category>
      <category domain="http://securityratty.com/tag/file system32 drivers">file system32 drivers</category>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/metaphisher kit">metaphisher kit</category>
      <category domain="http://securityratty.com/tag/configuration file">configuration file</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/276786652/crimeware-in-middle-zeus.html">Crimeware in the Middle - Zeus</source>
    </item>
  </channel>
</rss>
