Showing posts with label Exploits. Show all posts
Showing posts with label Exploits. Show all posts

Wednesday, July 28, 2010

Open source Razorback - Attacks Malware & Zero-day exploits

Sourcefire, best known for its Snort intrusion-prevention technology, Tuesday is unveiling a new open source project called Razorback that's designed to spot malware and especially zero-day exploits.

Sourcefire says Razorback is designed with a "defense routing system" that monitors for certain traffic types, such as HTTP, Web or SMTP-based e-mail, in order to forward mirrored data to any means of security analysis system that can be plugged into it.

Security tools supporting Razorback could be either open-source or proprietary.

Razorback monitoring could be integrated directly into security gateways as well as deployed on standalone servers. A typical place to put the main Razorback monitoring component would be directly behind an antivirus filtering point, according to Sourcefire, which also shepherds the open source Clam A/V toolkit. Razorback could also work with security information and event management products.

Razorback "knows the resources in the organization that might have a specific interest in files, such as PDFs, for example," which could have malicious code embedded in them, Watchinski says. Razorback-monitored PDF files could be sent to a forensics tool that could analyze them for zero-day vulnerabilities or possible exploit code.

Razorback's "defense-routing system" is not necessarily real-time and it's not yet designed to directly block suspicious data.The underlying idea of the open source project is to set up multiple paths to simultaneously transmit any mirrored data of specific security concern onward to designated security points for analysis, output and feedback to Razorback.

On a more advanced level, these third-party Razorback-supported tools, after security analysis, could in theory assist Razorback in recommendations to take protective blocking measures or update threat determinations.

Today, Razorback has been developed to work with open source Snort and Clam A/V as well as other open source code, such as Postfix.

Sourcefire has no publicly stated intention as of yet to launch a commercial product based on Razorback. The company does say the defense sector is interested in development of the kind of defense-routing system that Razorback seeks to foster through open source.

Razorback will be licensed by Sourcefire under open source GPLv2 license. In general, Sourcefire expects the code to be available for free to users and vendors -- but if Razorback is modified with the intent to sell it as a commercial product, discussion about licensing fees can be expected.

Wednesday, December 2, 2009

YouTube Better Watch out: Koobface Botnet Exploits Social Engineering Sites

The Koobface botnet, one of the most efficient social engineering driven botnets, is entering the Xmas season with a newly introduced template spoofing a YouTube video page, in between enticing the visitor into installing a bogus Adobe Flash Player Update (New Koobface campaign spoofs Adobe’s Flash updater), which remains one of the most popular social engineering tactics used by the botnet masters.

What is the Koobface gang up to? Would they continue sticking to their true nature and rely on social engineering tactics, or would they start using active exploitation tactics such as client-side exploits?

Let’s discuss some of the new developments introduced on the Koobface front over the past week, and try to answer these questions.

Experimenting with client-side exploits - last week, for the first time ever, the Koobface botnet started serving client-side exploits by embedding two iFrames on the hundreds of thousands of Koobface-infected hosts, for a period of several hours.

Despite its reliance on outdated exploits used by the web malware exploitation kit in question, this does not automatically mean that their “infection optimization” strategy would go in vain taking into consideration the fact that a huge percentage of users/enterprises continue failing to properly manage their “software inventory”.

Whether the gang would re-introduce the use of client-side exploits (drive-by download) remains yet to be seen, however, this move directly contradicts with the infection model of the botnet, which so far has been exclusively using social engineering tactics. Read More.......