Wednesday, December 06, 2006

Microsoft Word security threat.


Microsoft has announced on 5th Dec they are investigating a report of zero day attacks on a Microsoft Word vulnerability.

The affected versions are MS word 2000 & 2002 Microsoft Office Word 2003, Microsoft Word Viewer 2003, Microsoft Word 2004 for Mac, and Microsoft Word 2004 v. X for Mac, as well as Microsoft Works 2004, 2005, and 2006.

The system is effected once the Word document that is send through email is opened or if the user opens the document sent through some other means by the attacker.

Websense the security firm says the exploit connects the system to remote sites which has Trojan downloaders to download additional payloads.

Secunia the security firm has given this a extremely critical rating which means people should excercise extreme caution before opening files from untrusted sources or suspicious files or unexpected files from trusted sources.

Microsoft is still investigating the report and will provide a security update through their monthly release process or provide an out-of-cycle security update. Meanwhile it is suggested to excercise caution while opening documents especially the ones that are received through emails.

Related reading:- Yet another vulnerability in Word.

Tuesday, December 05, 2006

Useful links with tips for the Zune users.


Here are some very useful links for the Zune users. I am putting them here so that it will help enhancing your experience with Zune. Ok so let us have a look.

  • Zune was said to have many drawbacks even before people properly explored it and one among the drawbacks that were attached to Zune was the inability to configure it as an external hard drive. But thanks to Dan who maintains the phaleux.com blog, now we know that confuguring your Zune as an external hard drive is not a dream but a reality.
Take a look at it here along with some minor disadvantages of zune.


  • Another main drawback with Zune was that it's lack of compatibility with Windows Vista. But now this drawback too has been take care of. Thanks to Paul at the Modaco.com website. Take a look at how it can be done at the following link:-
Modaco.com/Zunevista.


  • Something that Apple does not offer but which Microsoft offers through Zune is the subscription service. You can use this for playback on multiple PCs. Follow the link below and check it out as to how you can do it.
Jkontherun blog.


  • Zune can be integrated with a 12MB sized free software called Feedyourzune which is a full featured RSS reader and Podcast Media Player. Get it here.
This software has the following features:-

* Automated download and syncing of Audio and Video Podcasts to your Zune.

* Full featured RSS video playback. Supports all video formats.

* Discover thousands of amazing Video and Audio Podcasts with the built in Channel Guides from Network2, FireAnt, and more to come!

* Open web architecture - supports RSS, BitTorrent, and Blog Permalinks.

* Create playlists, favorites, manage disk space, and more...


  • Ok next up is that Zune can be configured to bypass the Wi-Fi sharing limitations. Go to this page and then check out the Tutorial 3 which is titled "Wi-Fi Transfer of Movies, .Zip files, PDF files etc."
Also, check out this page which has great coverage of all Zune news and tips.


  • And if you want to run Zune on Windows XP 64 bit pro check it out at the following link to find out how it can be done.
Zune on Windows XP 64 bit pro.

Ok guys happy fine zuning..err.. I mean happy fine tuning your Zune.



Reference:- Zdnetblog.


Monday, December 04, 2006

A look at the top 10 security threats for the coming year.


Mcafee's has given a prediction on the security threats. Let us have a look at it one by one.

1.
The number of password-stealing Web sites will increase using fake sign-in pages for popular online services such as eBay.

eBay, myspace, Bank of America, Paypal are all being used for phishing attacks. This is one of the most common way an attacker uses to steal passwords. One of the most common method used is to send the fake links in emails. And as you might be aware the recent security flaw that was spotted with Firefox 2's password manager even allows attackers to steal passwords even if the fake page is not situated on the main site.

Read about the FF2 password manager's security flaw here.

Myspace has been in the news a lot lately with the password stealing issues and phishing attacks. Who can forget the fake YouTube videos which was found at over 1500 myspace pages that lead to another site that downloaded a spyware and the over 4000 fake login pages that has been used to steal passwords.

Check out this article to see some screen shots and information about how fake login pages are used to trick users into giving away their passwords.

Also you can see some myspace security related article here, filed under "Security".

2. The volume of spam, particularly bandwidth-eating image spam, will continue to increase.

More and more Image spams are being used since they can pass through the spam scanners easily. The spam scanners read the text messages and screens it. But they can't scan an image and filter it. So more and more images are being used to send spams to emails. This also leads to increased size in the inbox.

3. The popularity of video sharing on the Web makes it inevitable that hackers will target MPEG files as a means to distribute malicious code.

If you remember it was only recently that a threat was detected in this area with the detection of the Realor worm that targets the Real Player. Attackers are concentrating more on Movie Trojans with the popularity of video sharing. Apart from targetting online videos the attackers can also upload video files which when a user after downloading it opens it in their media player, the software will automatically start downloading and installing malware or adware.

4. Mobile phone attacks will become more prevalent as mobile devices become 'smarter' and more connected.

Mobile phone attacks have already started but it is not wide spread as in the PC world. But it is just waiting to erupt. With smart phone users increasing day by day attackers will be motivated since the victims are larger in number. Already mobile phone trojans that uses JAVA has been spotted world wide. This is mostly used for monetary purposes and also can be used for blackmailing since mobile phones can carry sensitive information. BlueTooth hacking and putting spywares on the phones have all started rolling.

Read more about mobile phone trojans and protection here.

5. Adware will go mainstream following the increase in commercial Potentially Unwanted Programs (PUPs)

It is said that already 91% of the PC's in the world is infected some kind of spyware. And now a days people are downloading any softwares that looks enticing without realising the consequences. Spywares unlike viruses and trojans are not totally illegal. I mean softwares that has spywares that have been installed with the "informed consent" of an user can always escape any legal issues simply by saying that the user has accepted the terms and conditions before installing it. This happens because many of the users don't even read the terms and conditions before installing a software. Adwares, the cousin of spyware is equally a nuisance with ads popping up left right and center on your screen which not only invades the screen but also slows down the PC or may be even bring it to a stand still.

This article takes a deep look at spywares and how to stay protected.

6. Identity theft and data loss will continue to be a public issue - at the root of these crimes is often computer theft, loss of back-ups and compromised information systems.

Phishing attacks have become very rampant. Using popular websites like myspace etc:- , getting the users to download trojans that collects every information,Viruses that can wipe out a hard disk are all methods used to collect information about the user. Not just in the PC world but in the mobile phone world too.

Read this articles and stay protected:-
27 steps to prevent computer viruses.
Best Free AntiViruses.

7. The use of bots, computer programs that perform automated tasks, will increase as a tool favored by hackers.

Botnets is already widespread in the world of Trojan attacks. And most of the Trojans themselves once installed in your PC acts like bots that perform tasks. SOme of them just lay buried just to be active at a particular time to send info to the attacker and stuff. So according to Mcafee this is going to be more wide spread. One of the threats which would be be hard to detect is the combination of a Rootkit and Trojan. Hearse belongs to this class of Trojans.

Everything about Trojans and Anti-Trojans.

8. Parasitic malware, or viruses that modify existing files on a disk, will make a comeback.

This is interesting. Let us wait and watch whether this is going to happen. But even if it makes a comeback I don't think it it will be a menace since all the Antiviruses now a days are very capable of negating this problem.

9. The number of rootkits on 32-bit platforms will increase, but protection and remediation capabilities will increase as well.

Root kits are hard to detect but fortunately all the top Antivirus makes have come up with solutions to deal with this problem. RootKits as you might know are viruses that has the priveleges of the user at the root level.It simply means that that user has the administrative powers. So if a programme has the same priveleges it means that it can bury itself into the operating system's Application Program Interface (API). It will this have the power to be the middle man between the operating system and the programs that rely on it, deciding what those programs can see and do.

Rootkits are typically not malicious by themselves but are used for malicious purposes by viruses, worms, backdoors and spyware. A virus combined with a rootkit produces what was known as full stealth viruses in the MS-DOS environment.

Read more about RootKits and staying protected here.

10. Vulnerabilities will continue to cause concern fueled by the underground market for vulnerabilities.

Underground market for vulnerabilities means the way hacking tools, exploits, botnets etc:- are sold for huge amounts. There are even some IRC "ghettos" where such things are advertised and marketed. Botnets are sold at a high price to people who want to bring down a website for Dos attacks using the zombie computers and for any other malicious purposes. In Feb 06 a WMF (windows Meta File) exploit was sold for $4000 in the under ground market by some Russian hacker groups.

In Dec 2005 bugtraq mailing list reported that using the WMF exploit the site "unionseek.com/d/t1/wmf_exp.htm" exploited a fully patched Windows XP system that had an updated Norton Antivirus.

According to the mailing list the site was successful in installing a .wmf virus on the system and at that time Norton did not detect it. It is a widely reported fact that there are a lot of buyers in the underground market for previously undisclosed flaws which they can use to exploit a system.

Tuesday, November 28, 2006

Mobile phones and Malwares(Viruses,Trojans,Worms etc: -)







MOBILE PHONE MALWARES.

Even though the first mobile phone malware was discovered in june 2004 which was the Cabir worm it was just a proof of concept written by the virus writing gang 29A and it was not dangerous as it was not set out in the wild. The came the variant of the Cabir, Mabir.A. Mabir was one step ahead in the social engineering technique. It acted more smartly by sending itself and MMS reply to the SMS or MMS received so that people and hence the recipient was more inclinded towards opening it.

The Commwarrior worm was the first malware to create a major havoc in the word of mobile phones. It operates on Symbian series 60 devices and being worm it is capable of spreading itself both over Bluetooth and MMS. In addition to spreadingitself over the network and also searches the users local address book for phone numbers and sends itself as an MMS to thecontacts. Unsuspecting mobile phone users open the MMS thinking it is from their contacts. This is the social engineering technique used here just like in case of most of the viruses, worms and Trojans in the PC world.

Some of the messages sent by Commwarrior to trick the user were "Nokia ringtonerNokia RingtoneManager for all models" "Audio drive Live3D driver with polyphonic virtual speakers!".

Read more info here.

Another Mobile phone Trojan that was first found in 2005 was the Fontal.A. It installs corrupted Font file into infected device, thus causing the device to fail at next reboot. However, there is only a small risk of infection and ones who arevulnerable to this are the people in the habit of installing warez mobile games files or some similar files onto their mobile phones.

Read more info here.

And for a while Java seemed to be the one that was safe from these kind of attacks. But just like I had noted in my article "Everything about Trojans and Anti-trojans", Trojans are finding a new home in the mobile phones through Java.

The first Trojan for J2ME (Java) was detected back in Feb 2006 and was called the Red Browser Trojan and it can run on a vast amount of mobile phones that supports Java.

The next one that has been making it's rounds is a Trojan associated with the Russian site games.gsmland.ru which sends SMS to a particular number (1717) and it sends 5 SMS at one time which costs $3 each.This one has been named the Trojan-SMS.J2ME.Wesber.a by Kaspersky labs.



SMS AND TROJANS

And another thing to be noted is that SMS is used by phone operators to make changes to the Mobile phones without user intervention. So what happens is that the phones do not check the source of the SMS to verify whether it is legitimate or not. So this loophole can be used by a malicious person. The possibility of this was demonstrated very recently by Wilfried Hafner of SecurStar. He demonstrated that by sending a bogus SMS he can not only change the settings of the phones but also eavesdrop on conversations and read the user's SMS. Hafner demonstrated this on Nokia E90 and a Qtek Windows Mobile 2005 phone by using an example Trojan called "Rexspy"

Flexispy is another software available in the market which is used for the same purpose and has the characterestics of "Rexspy" But this software has to be manually installed. So that means that even though it can't be remotely installed Flexispy can be easily installed into your mobile phones by anyone who has physical access to your mobile phone. Once installed it can be used to even remotely activate a mobile's camera or microphone.

Major mobile phone operators like Orange and Vodafone are viewing this threat seriously and are taken preventive measures.



PROTECTION


One of the best ways to protect or disinfect your mobile phone is to use the F-Secure's anti-virus tools for mobile phones. If your phone is WAP enabled and you can access the net directly from your phone you can directly go to the F-secure site and download it. If not the other option is to use your PC to download the software and then download it from your PC to your mobile phone. F-Secure offers a free 30 day trial version for each of the product. They offer this for a lot of mobile phones. You can download the trial version here.

Recently F-secure also added a firewall for smart phones. The firewall with ANtivirus is priced at $35 The product F-Secure Mobile Security can also be downloaded as a trial here. It supports symbian s60 and s80



The anti-Virus makers Trend Micro has recently released a new version of it's mobile phone security software which has a firewall. The software costs $35 which includes a years update and service. The ver 3.0 apart from the built in firewall has Anti-Spam for SMS Text Messages and Flexible Virus Scanning. Trend Micro offers a 30 day trial version. Currently the ver. 3.0 is available only for Windows Mobile 5.0 (PocketPC) and Windows Mobile 5.0 (Smartphone). Support for Symbian will be available soon. The ver.2.0 which does not have a firewall supports both Windows mobile and Symbian. You can download both here.




CONCLUSION.

The major reason for worry is that just like in the PC world the trend is to use if for espionage with the intention to blackmail or for financial gains. The trend has already started with the above mentioned commwarrior to Mabir.A that affects Symbian to the RedBrowser Trojan that affects using J2mE (Java) and the Flexispy software.

The mobile phone is a gadget that is always with you and it can carry the contact details and sensitive SMS and apart from the datas it carries if eavesdropped your conversation could give out a lot of sensitive information.

In the world of mobile phones smart phones are gonna be a major target. Symantec's stats show that while 80 per cent of companies allow corporate data on handheld devices, only 25 per cent have so far addressed smartphone security.

There haven't yet been a major outbreak of a mobile phone malware like that in the PC world except for the isolated outbreaks. But experts say that it is not too far. F-secure is already developing products that prevent the spreading of these malwares not only through the browsers etc but also through a wireless technology like Bluetooth. These kind of softwares could even help corporates to scan all the Bluetooth enabled phone in the premises for infection and thus alert them about someone having an infected phone in the premises.




SPECIAL MENTION : Bluetooth and Wi-Fi Hacking.


Apart from the world of the mobile phone malwares (Viruses, Trojans, worms etc:-) the world of Bluetooth hacking. This is an area we will cover later.One of the major problem with Bluetooth is that it is not easy to monitor like the normal Internet's network. The most common blue tooth exploits are Bluesnarfing, Bluebugging, Bluejacking and Denial of service. To have a better understanding of these terminologies take a look here.

But to completely exploit and eavesdrop using the Bluetooth the devices needs to be paired. And in 2005 it has been demonstrated by two Israeli students Yaniv Shaked and Avishai Wool that it is highly possible to pair blue tooth devices without even alerting the user. And they demonstrated that once a connection is set up the attacker could eavesdrop on data transmitted between the target devices and a PC or take control of someone's Bluetooth device. And once the two devices were paired the attacker could work out the link key in 0.06 seconds on a Pentium IV computer.

Also check out this page and on the left hand side you will see the 10 steps to protect your Bluetooth device.

Wireless hacking is another area and any mobile or laptops connected to a network through a wireless connection is very vulnerable to these attacks. If you check out this page you will be amazed to see the
number of tools available. However, these tools are made available by them only for educational and security purposes. They should not be used for any illegal activities.

And to get an idea about the wirless hacking techniques used and how to stay protected this computer world article even though published in 2004 is still worth having a look.

It is not surprising that apart from the Antivirus tools for mobile devices the Antivirus vendors are coming up with firewall and Intrusion detection softwares. Just like in the PC world it is advised to use a combination of firewall and Antivirus.

Other references:-

Techworld.
TheRegister.co.uk
Vnunet.

Related Reading:-
Everything about Trojans and AntiTrojans.




Monday, November 27, 2006

Mac (OS X) as a target for malicious attacks.


Well, it seems now adware creators are targetting Mac. One of the features of Mac is to allow the installation of a system library without prompting the user. And this is exactly the loophole the adware creators needed. The information related to the proof-of-concept adware program was released by F-Secure in their blog. What this adware does is to launch the Safari browser each time an application is opened. F-secure has not not given more info on this. But it seems there is more than meets the eye. For now the adware is called the
iAdware.

Symantec conducted a recent study on the Mac OS X and one of the important things they have mentioned is that since OS X has historically been untargeted by malicious people many of it's users would be unsuspecting of nefarious and malicious activities. The Mac users are relatively unafraid and unsuspicious when it comes to downloading files because of the basic comfort level arising out of the less number of attacks in the past. But this could be a thing of the past since Mac is slowly but steadily become the target of attacks.

One of the basic things to be noticed is that there are currently at least three publicly available RootKits viz:- WeaponX,OSXRK and Togroot targetted at Mac. The chkrookit available at Chkrootkit.org is the ANti-RootKit which is freely available for Mac users to combat the RootKit attacks.

I suggest that Mac users download this PDF file released by Symantec and have a look at least at the "Defenses" part that starts from page 21. to ensure you are protected.

Related Reading:-
What are RootKits.

Sunday, November 26, 2006

Test your PC for DCOM vulnerability.


This is a tool that has been around for a while but am not sure how many of you have heard about it or tested your machine for the DCOM vulnerability.

DCOM or Distributed Component Object Model is a technology used to allow system and application components to inter-operate over the network. Applications like paint brush , wordpad etc:- are all DCOm ready which means they are ready to be operated across the network or the public internet. This means if the DCOM is up and running on your system there are applications that are vulnerable in your system which can be taken over by malicious people or this is an open door to worms.

This was an oversight from Microsoft. This was actually introduced with the idea of have COM distributed across the network so that people can work on the component remotely. But this turned out to be the back door for attacks. This was patched later by Microsoft but the problem is that there are still reports that sometimes the patches do not work. Apart from the patches not working for everyone, some of the people using the older versions of Windows could be prone to the DCOM vulnerability.

GRC'sDCOMbobulator is the ideal tool for checking your machine for the DCOM vulnerability and to shut DCOM down since it's use is only for a misuse. Let us have a look at the various aspects in simple terms:-

On the DCombulator you will find three tabs on top. Viz:- "DCOMbobulator?" , " Am I Vulnerable " and "DCOMbobulate Me". The "DCOMbobulator?" tab can be used if you want information on the DCOM and what the DCOMbobulator tool does.

The " Am I Vulnerable " tab is the one that has to be used to find out whether your machine is still vulnerable to DCOM .

Click on the "Local DCOM Test" button and if your machine is then it will show that "DCOM is available and vulnerable" and if this shows even after the machine has been patched it means the patch hasn't been effective. The "Local DCOM Test" button available under this tab will be disabled if your machine have the right service pack or the version that has already taken care of the vulnerability.

Under this tab you will also see the "Remote Port 135 Test" button. This is to test whether your port 135 is open or not. Even if the tool says that DCOM is safely disabled on this system or "not vulnerable" you should use this button to find out whether port 135 is open or not. This will launch your browser and take you to the Grc.com site to test the port's status.

If it is open it is not good. It is not advised to leave this port open. If you have a firewall and still it says your port is open then you need to close this port. If it is a good firewall the port will be stealthed and the test will show a stealth status.

Also even after DCOM is shutdown still the port is open it simply means that there are other programs like Task Manager using this port. So as long as an application like Task Manager is running this port will be used by it. So if you want to leave applications like that running, use a good firewall to close the port from intrusion. A good firewall will always have the ports stealthed than just displaying a "closed" status.

Ok now let us look at the "DCOMbobulate Me" tab. Under this tab you will find two buttons "DISABLE DCOM" and "ENABLE DCOM".

This means that even if DCOM is patched the component might still be running. And DCOM does not need to be running unless you are a person using it with the purpose of doing something with the COM components across the network. Otherwise this does not have any purpose running and this has to be shut down. So use the "Disable DCOM" button and shut it down.

You can Download DCOMbobulator here.

Also, the UDP port 135 is used by Windows Messenger Service which allows for spam and is a security risk. To close it down you can try the Shoot The Messenger tool.

Google