More on Microsoft security front.
As you might know, MS12-AUG is out on 14 Aug 2012.
Among the patches, there is one which addresses a vulnerability on CGM images corruption that I have reported to MS.
Details follow:
Related (older) reports, CVEs, patches:
Stay secure!
Securely yours,
Andrei
UPDATE: You can subscribe to postscript-sec@andreicostin.com for notifications and tools & PoC releases.
Small updates on the Xerox security front.
Few days back Xerox issued its Security Bulletin XRX12-005 and the P49 security patch.
Updates on the Oracle Java security front.
Few days back Oracle issued it’s June patch/CPU for Java marked as highly critical and containing a vulnerability (CVSS 2.1) numbered:
Code:
phdays.com, phdays.ru | |
Moscow, 2012 | |
Day1, Track2, 11:00 | |
Aleksandr Matrosov, Eugene Rodionov, | |
Smartcard vulnerabilities in modern banking malware | |
| |
Impact since 2010 | |
| |
Blackhole | |
| |
Nuclear pack Apr 2012 | |
carders moved from blackhole to nuclear pack | |
| |
New in nuclear pack | |
added check for legitimate user | |
Java is one of the main vectors in attacking users | |
| |
Example: google search for "евровидение 2012" | |
contains an injected iframe with yandeXXX.<trololo>.ru - valid looking domain | |
this helps to void the AV/IDS detection of randomly generated domains | |
then the iframe redirects to an exploit | |
| |
Russia | |
provides detection of 70% of worldwide carders activity | |
3x increase in detection rate from Nov 2011 till Jun 2012 | |
| |
Biggest botnets | |
Origami, Gizmo, Dudorov | |
| |
BK-LOADER (BootKit) | |
Ringo bundle (ZeroKit or 0kit) | |
First bootkit to modify volume boot record | |
version 1.0, 11/02/2011 | |
| |
Carberp sample | |
Around 3000 bots receiving volume boot record BK debug messages | |
Looks like GSVSoft supplied some parts of the BK code | |
After screenshot publication, their start (because of high traffic incentive) -> started redirecting users to blackhole | |
| |
Rovnix, Carberp with BK, Rovnix.B | |
VBR | |
Polimorphic VBR | |
Malware driver storage | |
| |
Anti-debugging | |
Removes hooks of HIP systems | |
WinAPI functions called by hash, not by name | |
| |
Cards | |
Attacks on APDU level | |
| |
crackme.esetnod32.ru | |
win ipad | |
win amazon kindle | |
| |
Feisty | |
if there is any delay in protocol or program execution, the malware changes it's behaviour | |
malicious plugins not saved on disk, directly loaded into kernel memory |
First, I would like to thank HP SSRT security team for great communication and cooperation on the report.
Other advisory numbers: HPSBPI02779 SSRT100855, CVE-2012-2011
HP WJA
- uses non-secure transport protocol (read MITM)
- does not implement or at least verify secure-hashing i.e. authenticated&authorized origins of the DOWNLOADED files
- has several XSS vulnerabilities (perhaps many more to be discovered)
:: Next Page >>
A deep dive into brain's curiosities
| Next >
| Sun | Mon | Tue | Wed | Thu | Fri | Sat |
|---|---|---|---|---|---|---|
| << < | > >> | |||||
| 1 | 2 | 3 | 4 | |||
| 5 | 6 | 7 | 8 | 9 | 10 | 11 |
| 12 | 13 | 14 | 15 | 16 | 17 | 18 |
| 19 | 20 | 21 | 22 | 23 | 24 | 25 |
| 26 | 27 | 28 | 29 | 30 | 31 | |