|
|
|
Elderwood Project Behind Latest Internet Explorer Zero-Day Vulnerability |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : In our recent blogs about the latest Internet Explorer zero-day vulnerability, we explained what watering hole attacks are and referenced our research paper about the Elderwood Project. The paper highlights a string of watering hole attacks by the Elderwood group. After revisiting those previous attacks, we have been able to confirm that this latest Internet Explorer zero-day is a continuation of the Elderwood Project. Related Elderwood zero-day vulnerabilities The following are the vulnerabilities produced by the Elderwood group that are directly related to the most recent Internet Explorer zero-day. CVE BID Description Discovered 2012-1875 53847 Microsoft Internet Explorer CVE-2012-1875 Same ID Property Remote Code Execution Vulnerability May 2012 2012-1889 53934 Microsoft XML Core Services CVE-2012-1889 Remote Code Execution Vulnerability Jun 2012 2012-4969 55562 Microsoft Internet Explorer Image Arrays Use-After-Free Remote Code Execution Vulnerability Sep 2012 2012-4792 57070 Microsoft Internet Explorer 'CDwnBindInfo' Use-After-Free Remote Code Execution Vulnerability Dec 2012 Table 1. Vulnerabilities produced by the Elderwood group In May 2012, Amnesty International s Hong Kong website was compromised and used to serve up a malicious SWF file that exploited CVE-2012-1875. In September 2012, the same group was responsible for CVE-2012-4969. In addition, late last month the website for a US based think tank was compromised to serve up CVE-2012-4792. But that wasn t the only site serving this vulnerability. Security Researcher Eric Romang wrote about another website that was found to be hosting the latest Internet Explorer zero-day. In his post, he also ties the same website to another zero-day vulnerability, CVE-2012-4969, back in September. Our own research has come to the same conclusion and we can add that this website was compromised to serve CVE-2012-1889 back in June with a file called movie.swf. The file, movie.swf, is associated with the Elderwood Project. Figure 1. Three zero-day vulnerabilities hosted on a single site Shockwave files We have analyzed a sampling of the SWF files that were used in the Elderwood watering hole attacks and found that the Flash exploit author included symbols in some of the attacks. Filename CVE Common symbols HeapSpary hexToBin OS_Version URL_Addr Flahs_Version Geoffrey.swf 2012-1875 Yes Yes Yes Yes Yes Moh2010.swf 2012-4969 Yes Yes Yes Yes Yes Today.swf 2012-4792 Yes Yes Yes No No Table 2. Symbols included in attacks Figure 2. Comparison of Symbols used in the decompiled ActionScript As noted in Figure 2, all the samples we identified include a function named HeapSpary. HeapSpary is a clear mistyping of Heap Spray, a common attack step used in vulnerability exploitation. In addition to this commonality, there are many other symbols in common between the files. Examples include Geoffrey.swf and Moh2010.swf both using variables named URL_Addr and Flahs_Version mistyping of Flash_Version , as well as all three exploit files using the variable name OS_Version. We were unable to recover the symbols of movie.swf for comparison, but movie.swf is tied directly to Moh2010.swf by the packer registrant information for the SWF files. Additionally, movie.swf and Moh2010.swf share similar structure and shellcode. AlienVault Labs has previously published some great research investigating the authors behind the Moh2010.swf attacks the attackers believed to be behind the latest attack. It has become clear that the group behind the Elderwood Project continues to produce new zero-day vulnerabilities for use in watering hole attacks and we expect them to continue to do so in the New Year.
Les mots clés de la revue de presse pour cet article : internet zero-day vulnerability Les videos sur SecuObs pour les mots clés : internet vulnerability Les mots clés pour les articles publiés sur SecuObs : internet Les éléments de la revue Twitter pour les mots clé : internet zero-day vulnerability
Les derniers articles du site "Symantec Connect Security Response Billets" :
- What you need to know about election apps and your personal data - Microsoft Patch Tuesday April 2016 - New Adobe Flash Player exploit used by Magnitude and Nuclear exploit kits - Latest Intelligence for March 2016 - New Flash zero-day exploited by attackers in the wild - Samsam may signal a new trend of targeted ransomware - Four tax scams to watch out for this tax season - Most prevalent Android ransomware in the West arrives in Japan - Taiwan targeted with new cyberespionage back door Trojan - Seven Iranians charged in relation to cyberattacks against US
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.190.17.190 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.190.17.190 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|