<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
		<title>Security Response Weblog</title>
		<link>http://www.symantec.com/enterprise/security_response/weblog/</link> 
		<description>Security Response</description>    
		<language>en-us</language>
        <lastBuildDate>pet, 9 sij 2009 15:11:30 &#43;0000</lastBuildDate>
		
		<item>
				<title>New Variants of W32.Downadup.B Find New Ways to Propagate</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;thread.id=225</link>
				<description>Symantec has observed an increase in infections relating to W32.Downadup over the holiday period and is urging organizations to apply the patch for Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability as soon as possible. A new variant of this threat, called W32.Downadup.B, appeared on December 30th</description>
				<content:encoded>&lt;p&gt;Symantec has observed an increase in infections relating to W32.Downadup over the holiday period and is urging organizations to apply the patch for &lt;a href=&#034;http://www.securityfocus.com/bid/31874&#034; target=&#034;_blank&#034;&gt;Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability&lt;/a&gt; as soon as possible.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;A new variant of this threat, called &lt;a href=&#034;http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-123015-3826-99&#034; target=&#034;_blank&#034;&gt;W32.Downadup.B&lt;/a&gt;, appeared on December 30th and can not only propagate by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability, but can also spread through corporate networks by infecting USB sticks and accessing weak passwords. These propagation methods are nothing new; W32.Spybot, W32.Randex, and W32.Mytob variants all use almost identical methods to spread, but this variant requires more effort to protect corporate networks. &amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;W32.Downadup.B creates an autorun.inf file on all mapped drives so that the threat automatically executes when the drive is accessed. The threat then monitors for drives that are connected to the compromised computer in order to create an autorun.inf file as soon as the drive becomes accessible. The worm also monitors DNS requests to domains containing certain strings and blocks access to those domains so that it will appear that the network request timed out. This means infected users may not be able to update their security software from those websites. This can be problematic as worm authors generally dish out new variants constantly.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Symantec researchers are seeing considerable detections of both variants of W32.Downadup and W32.Downadup.B. As illustrated by the following infection maps based on data from the past 60 days, the infections are geographically quite widespread. The highest infection rates typically correspond to countries with high rates of computer/Internet usage.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;strong&gt;Infections of W32.Downadup &lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/w32.downadup-full.jpg&#034; target=&#034;_blank&#034;&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/w32.downadup-thumb.jpg&#034; border=&#034;0&#034; width=&#034;512&#034; height=&#034;384&#034; /&gt;&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;strong&gt;Infections of W32.Downadup.B&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/w32.downadup.b-full.jpg&#034; target=&#034;_blank&#034;&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/w32.downadup.b-thumb.jpg&#034; border=&#034;0&#034; width=&#034;512&#034; height=&#034;384&#034; /&gt;&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Symantec strongly encourages users to patch their system against the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability, take steps to control the execution of applications referenced in the autorun.inf files that may be located on removable and network drives, and enforce a strong password policy on all computers within their networks.&amp;nbsp; Particularly during holiday periods patch updates can be missed and is an opportune time for malware to spread.&amp;nbsp; Consider implementing an automated patch management solution to help mitigate risk.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Click &lt;a href=&#034;http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008032111570648&#034; target=&#034;_blank&#034;&gt;here&lt;/a&gt; to obtain more information about how to prevent a threat from spreading using the &amp;quot;AutoRun&amp;quot; feature.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;For more detail on the evolution and infection statistics of this threat, check out the earlier Security Response blog posting - &lt;a href=&#034;https://forums.symantec.com/t5/blogs/blogarticlepage/blog-id/malicious_code/article-id/224&#034; target=&#034;_blank&#034;&gt;W32.Downadup Infection Statistics&lt;/a&gt; - posted on January 6th.&lt;/p&gt;&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by Trevor Mack on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 01-09-2009&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 09:07 AM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>Symantec Security Response</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;thread.id=225</guid>
				<dc:date>2009-01-09T15:11:30+00:00</dc:date>
				<category>Malicious Code</category>
			</item>
		<item>
				<title>New Year Brings New Spam Attacks</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=135</link>
				<description>Happy New Year! At this time of year, personal and professional resolutions are often made. These resolutions are often broken within a few days, but it is clear that one resolution will not be broken in 2009. Spam levels are slowly creeping back up to their pre-McColo shutdown levels and spammers have come back fighting.</description>
				<content:encoded>Happy New Year! At this time of year, personal and professional resolutions are often made. These resolutions are often broken within a few days, but it is clear that one resolution will not be broken in 2009. Spam levels are slowly creeping back up to their pre-McColo shutdown levels and spammers have come back fighting. You may remember that on November 11, 2008, McColo-hosted systems were shut down based on abuse complaints. As a result, spam volumes dropped dramatically across the world. However, recent statistics indicate that spam volumes have slowly crept back up to 80 percent of their pre-McColo shutdown levels.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;In recent days, Symantec has also observed that spammers are continuing to piggyback on legitimate newsletters and using the reputation of major social networking sites to try and deliver spam messages into recipients&amp;rsquo; inboxes. The social networking spam messages were carefully crafted to closely mimic the legitimate notification emails often distributed from social networking sites.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;The recent holiday season was also used as a vehicle by spammers to distribute a wide host of spam messages including adult, leisure, finance, and meds spam messages. These spam attacks were not limited to the English language but included non-English language spam too. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;To read about these or other trends in the Symantec Monthly State of Spam Report, such as spammers using the recession to get into your inbox, new year brings new fraud attacks, and Obama-related spam messages, please visit the &lt;a href=&#034;http://www.symantec.com/spam&#034; target=&#034;_blank&#034;&gt;State of Spam website&lt;/a&gt; and the &lt;a href=&#034;http://eval.symantec.com/mktginfo/enterprise/other_resources/b-state_of_spam_report_01-2009.en-us.pdf&#034; target=&#034;_blank&#034;&gt;January State of Spam Report&lt;/a&gt;.&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by Trevor Mack on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 01-08-2009&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 09:30 AM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>Dermot Harnett</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=135</guid>
				<dc:date>2009-01-08T13:41:28+00:00</dc:date>
				<category>Spam</category>
			</item>
		<item>
				<title>A Spammer Has Sent You a Message</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=134</link>
				<description>Symantec has observed at least two major social networking sites being spoofed in spam attacks this week. The spam is likely hitching a ride on the back of a recent phishing scam, as discussed on our Norton Protection Blog. The spam emails appear to be official notifications from the social networking sites, with identical subject line formats.</description>
				<content:encoded>&lt;p&gt;Symantec has observed at least two major social networking sites being spoofed in spam attacks this week. The spam is likely hitching a ride on the back of a recent phishing scam, as &lt;a href=&#034;http://community.norton.com/t5/Norton-Protection-Blog/Twitter-Users-Attacked-by-Phishing-Efforts/ba-p/55091;jsessionid=BAF5F99922006E5D198CDD1048491731#A258&#034; target=&#034;_blank&#034;&gt;discussed on our Norton Protection Blog&lt;/a&gt;. The spam emails appear to be official notifications from the social networking sites, with identical subject line formats. The headers of the messages, such as message ID, received lines, and even the custom X-headers have been carefully crafted to closely mimic a legitimate email as closely as possible. &lt;br /&gt;&lt;br /&gt;The lure of the emails is the promise of a free mobile phone. There are two different attack vectors being used. In the first variation the user is invited to click directly on a link in the email. In some cases, a free blogging site is used as an intermediary to redirect end users to the ultimate destination URL in order to avoid spam filters. In other cases, as in the example shown below, the spammer has linked directly to a suspicious site.&lt;br /&gt;&lt;br /&gt;The domain being utilized was recently registered anonymously via a third party on December 19, 2008, and the site has already been taken down.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/twitter1_sml.jpg&#034; border=&#034;0&#034; width=&#034;384&#034; height=&#034;304&#034; /&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&amp;nbsp;&lt;br /&gt;In the second variation the user is invited to join a group on the social networking site. In this case the link in the email actually goes to a real group that was created on the social networking site by the spammers. The group then links to a free blogging site as an intermediary to redirect end users to the ultimate destination URL. So far, many of the messages observed are using the same single social networking group. It may be because this was an experiment by the spammers or because the creation of multiple groups associated to multiple accounts could be too time-consuming.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/twitter2_sml.jpg&#034; border=&#034;0&#034; width=&#034;373&#034; height=&#034;259&#034; /&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&amp;nbsp;&lt;br /&gt;Once the user arrives at the destination URL they are requested to fill out a form collecting personal information. This information can be sold on to marketing companies and/or used in future spam campaigns. Symantec recommends that you do not accept any social networking invitations from names that are unfamiliar to you.&lt;/p&gt;&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by Trevor Mack on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 01-07-2009&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 11:37 AM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>Amanda Grady</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=134</guid>
				<dc:date>2009-01-07T19:20:24+00:00</dc:date>
				<category>Spam</category>
			</item>
		<item>
				<title>Not-For-Profit Phishing</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=online_fraud&amp;thread.id=101</link>
				<description>A recent phishing scheme that targets users of Twitter (http://blog.twitter.com/2009/01/gone-phishing.html) may be related to a string of Web attacks against several high-profile celebrities and no doubt many other users.</description>
				<content:encoded>&lt;p&gt;A recent phishing scheme that targets users of Twitter (&lt;a href=&#034;http://blog.twitter.com/2009/01/gone-phishing.html&#034; target=&#034;_blank&#034;&gt;http://blog.twitter.com/2009/01/gone-phishing.html&lt;/a&gt;) may be related to a string of Web attacks against several high-profile celebrities and no doubt many other users. The most recent attacks apparently began when stolen credentials were distributed by a user on the &lt;a href=&#034;http://www.digitalgangster.com&#034; target=&#034;_blank&#034;&gt;Digital Gangster&lt;/a&gt; website. The noticeable result was a spontaneous defamation free-for-all, whereby the credentials were used to post humorous and sometimes vulgar messages on the compromised accounts. Some of the posts also redirected users to advertising websites.&lt;br /&gt;&lt;br /&gt;This sort of activity is nothing new; however, it is interesting that the user gave out the credentials for free instead of selling them for a profit. As discussed in the recent Symantec &lt;em&gt;&lt;a href=&#034;http://www.symantec.com/business/theme.jsp?themeid=threatreport&#034; target=&#034;_blank&#034;&gt;Report on the Underground Economy&lt;/a&gt;&lt;/em&gt;, user credentials can be sold for a profit and the fact that some of the credentials were for high-profile celebrities would likely add to the value of such information. It could be that the person was only after credibility and enjoys the act of phishing but has no interest in keeping the catch. Sport-phishing, anyone?&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style=&#034;font-weight: bold&#034;&gt;Update&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;According to the (overlooked) Monday post on the &lt;a href=&#034;http://blog.twitter.com/&#034; target=&#034;_blank&#034;&gt;Twitter Blog&lt;/a&gt;, the attacks on the celebrity accounts were not related to the phishing scam as was first speculated. A hacker gained unauthorized access to some of Twitter&amp;rsquo;s administrative support tools and subsequently used them to take control of 33 accounts. According to other sources, the hacker used a brute-force dictionary attack to determine the administrative password.a brute-force dictionary attack to determine the administrative password. &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Twitter has addressed the issue, having restored the hacked accounts, and is currently undergoing a full security review to mitigate future attacks. As quoted from Twitter&#039;s Monday post, &amp;quot;We immediately locked down the accounts and investigated the issue.
Rick, Barack, and others are now back in control of their accounts.&amp;quot; &lt;/p&gt;&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by Trevor Mack on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 01-08-2009&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 08:22 AM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>Téo Adams</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=online_fraud&amp;thread.id=101</guid>
				<dc:date>2009-01-07T11:16:20+00:00</dc:date>
				<category>Online Fraud</category>
			</item>
		<item>
				<title>W32.Downadup Infection Statistics</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;thread.id=224</link>
				<description>The W32.Downadup.A worm was the first worm discovered in the wild that was successfully leveraging MS08-067 in a widespread fashion. Symantec carried out an in-depth analysis of this threat and discovered that infected hosts will generate 250 pseudo-random domain addresses each day, in preparation of attempting to contact them later on to download and execute an update binary.</description>
				<content:encoded>The &lt;a href=&#034;http://www.symantec.com/security_response/writeup.jsp?docid=2008-112203-2408-99&amp;amp;tabid=2&#034; target=&#034;_blank&#034;&gt;W32.Downadup.A&lt;/a&gt; worm was the first worm discovered in the wild that was successfully leveraging &lt;a href=&#034;http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx&#034; target=&#034;_blank&#034;&gt;MS08-067&lt;/a&gt; in a widespread fashion. Symantec carried out an in-depth analysis of this threat and discovered that infected hosts will generate 250 pseudo-random domain addresses each day, in preparation of attempting to contact them later on to download and execute an update binary.&lt;br /&gt;&lt;br /&gt;This is an interesting and increasingly popular technique that malicious code authors have been deploying. It allows them to more easily evade domain and server takedowns, because until they choose to register a domain associated with a given day, the security industry is unable to know for sure which domain will be used and therefore has little to target. Fortunately, by reverse engineering the domain-generation algorithms, we are able to proactively identify and blacklist the domains.&lt;br /&gt;&lt;br /&gt;What&amp;rsquo;s also interesting about this method of obtaining binary updates is that it does allow for the number of infections to be approximated by monitoring contact attempts against generated domains. By pre-calculating and registering future domains, the Symantec Intelligence Analysis Team was able to observe contact attempts made by numerous infections. Over the course of a week, we observed over three million unique IP addresses attempting to obtain a download file from our server. However, we believe that the number of infections is higher than this estimate due to multiple internal infections that may be using network address translation (NAT) behind a single external IP address. Also, it&amp;rsquo;s possible that an infected computer does not contact all 250 generated domains each day. If this latter possibility is the case, then we may only be seeing a subset of the actual total number of infected computers in this bot network.&lt;br /&gt;&lt;br /&gt;For instance, we have been able to show that multiple infections are coming from a single IP address by identifying unique user-agent strings coming from the same IP. The following graph shows the statistics, over a 72-hour period, of unique IP addresses versus unique IP address and user-agent pairs:&lt;br /&gt;&lt;br /&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/down1_sml.jpg&#034; border=&#034;0&#034; width=&#034;348&#034; height=&#034;314&#034; /&gt;&lt;br /&gt;&lt;br /&gt;While on the topic of user-agents, when contacting one of the generated domains to obtain a binary, an infected computer sends a specific user-agent string as part of the HTTP request. User-agent strings contain version information about the associated operating system (OS) and Web browser, and can be used to collect interesting statistics. For example, Windows XP SP1 can be identified by a user-agent containing Windows NT 5.1. Systems running Windows XP SP2 and later can be identified by Windows NT 5.1; SV1. By analyzing the user-agent strings associated with each unique request, we are able to approximate the distribution of infected operating system types. The following graphic shows the OS distribution observed over a 72-hour period:&lt;br /&gt;&lt;br /&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/down2_sml.jpg&#034; border=&#034;0&#034; width=&#034;330&#034; height=&#034;351&#034; /&gt;&lt;br /&gt;&lt;br /&gt;As can be seen, the most commonly infected systems appear to be Windows XP SP1 and earlier. Over 500,000 of the infected computers that contacted our server were running these operating system versions. Close behind was Windows XP SP2 and later systems. Windows 2000 and Windows 2003 had smaller shares.&lt;br /&gt;&lt;br /&gt;We believe that the W32.Downadup.A propagation routine has been very aggressive. It will continue to infect computers in the near future and receive updates via the aforementioned mechanism. Symantec discovered a new variant of this worm on December 30, 2008, dubbed &lt;a href=&#034;http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-123015-3826-99&amp;amp;tabid=2&#034; target=&#034;_blank&#034;&gt;W32.Downadup.B&lt;/a&gt;. This updated version contains additional propagation routines and what appears to be an altered domain generation routine. It&amp;rsquo;s not currently known if this new version was seeded to W32.Downadup.A infections or has independently spread through its own propagation routines. &lt;br /&gt;&lt;br /&gt;We strongly encourage all users to ensure that the patches available in MS08-067 have been applied and that antivirus products are fully up-to-date to ensure that this threat does not find its way onto computers.</content:encoded>
				<dc:creator>Security Intel Analysis Team</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;thread.id=224</guid>
				<dc:date>2009-01-06T20:39:43+00:00</dc:date>
				<category>Malicious Code</category>
			</item>
		<item>
				<title>2008—Ending With a Bang</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&amp;thread.id=183</link>
				<description>This has been an interesting year for high-profile vulnerabilities and security research. In 2008, awareness has been raised about a number of high impact, remote code-execution vulnerabilities affecting both server- and client-side applications. Published attacks targeted important protocols used by critical Internet infrastructure.</description>
				<content:encoded>&lt;p&gt;This has been an interesting year for high-profile vulnerabilities and security research. In 2008, awareness has been raised about a number of high impact, remote code-execution vulnerabilities affecting both server- and client-side applications. Published attacks targeted important protocols used by critical Internet infrastructure. A number of flaws in the implementation of a number of cryptographic implementations have also been made public. In addition to the aforementioned issues, new exploitation techniques were demonstrated that emphasized the growing trend toward application-specific attacks targeting Web technologies.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Let&#039;s begin with a few high-profile memory corruption flaws on the Microsoft Windows front. The year started with a bang, MS08-001, which is a remotely exploitable memory-corruption vulnerability affecting the Microsoft Windows kernel. Then, in October we saw in-the-wild exploitation of a previously undisclosed RPC vulnerability affecting Microsoft Windows (MS08-067). In December we saw in-the-wild exploitation of a previously unknown and unpatched vulnerability affecting Internet Explorer (MS08-078).&lt;br /&gt;&lt;br /&gt;On the critical infrastructure front, research was published regarding the targeting of two protocols that are critical to supporting Internet infrastructure. The first was Dan Kaminsky&#039;s much talked about DNS vulnerability that allowed attackers to easily insert arbitrary DNS records into an affected DNS server. The second piece of research demonstrated a man-in-the-middle attack abusing BGP.&lt;br /&gt;&lt;br /&gt;On the cryptographic front, June marked the disclosure of a high-profile vulnerability affecting SNMPv3. Due to an implementation flaw, attackers were able to perform brute-force attacks against the HMAC authentication routine used in some SNMPv3 implementations. In May, a flaw in Debian&#039;s OpenSSL package was publicized. Due to a mistake made during testing, the entropy pool for the generation of cryptographic keys was limited to using Process IDs (PIDs), making brute-force attacks trivial.&lt;br /&gt;&lt;br /&gt;The aforementioned cryptographic vulnerabilities make for an interesting segue into some research that was disclosed today. It looks like 2008 is going to end on an exceptionally high note (or a low one, depending on how you look at it). Today (December 30, 2008), three security researchers added to the list of cryptographic-implementation flaws when they gave a talk at the 23rd Chaos Communication Congress in Berlin. Their talk disclosed a vulnerability affecting certificate authority (CA) signing. A CA &amp;ldquo;signs&amp;rdquo; digital certificates, operating as a trusted third party to help ensure the validity of a certificate. The ability to create a rogue, signed certificate for an arbitrary site has extremely dangerous implications. This is what the attack presented today does.&lt;br /&gt;&lt;br /&gt;First, a little bit of background information is required. In the past couple of years, researchers have identified a few attacks that leverage hash collisions computed using the MD5 algorithm. A hash collision means that computing a collision for a particular hash algorithm means finding two different messages, such that the hashes of those messages are the same, effectively proving the hash algorithm is technically not cryptographically secure. Computing hash collisions is not particularly easy and often requires large amounts of time and computational resources. The researchers who published this research overcame that limitation by using a cluster of PlayStation 3 video game consoles to brute-force hash collisions in MD5.&lt;br /&gt;&lt;br /&gt;The attack targets CAs that specifically use the MD5 hash algorithm to issue certificates. According to the summary, in a nutshell, the attack breaks down like this:&lt;/p&gt;&lt;p&gt;&lt;br /&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp; Identify a CA that is accepted by most/all common Web browsers and uses MD5 to issue certificates.&lt;br /&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp; Use a crafted request to obtain a certificate from the CA, which will collide with a specially crafted intermediary CA certificate (already in the attackers&amp;rsquo; possession).&lt;br /&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp; Copy the digital signature from the certificate issued by the CA into the attacker-generated intermediary certificate, effectively creating a trusted and signed CA under the attackers&amp;rsquo; control.&lt;br /&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp; Use the attacker-controlled certificate to sign arbitrary certificates, making them appear to come from a legitimate CA and thereby be trusted by third parties. &lt;br /&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp; Use arbitrarily signed certificate for nefarious purposes.&lt;br /&gt;&lt;br /&gt;Step two, listed above, is of course the non-trivial portion of this attack and a detailed explanation is certainly out of scope for this blog entry. For a detailed explanation of all the caveats and complexities involved, please refer to the link included at the end of this article.&lt;br /&gt;&lt;br /&gt;The effects of this attack are important for several reasons and a particularly interesting use (a case noted by the authors of this research) is in creating convincing phishing scams. Used in conjunction with something like the DNS vulnerability published by Dan Kaminsky earlier this year, attackers would be able to create highly convincing websites to steal user credentials and all sorts of confidential information.&lt;br /&gt;&lt;br /&gt;For example, say an attacker wanted to obtain legitimate authentication credentials to a specific financial institute&amp;rsquo;s online banking site. The attacker would set up a fake site designed to appear identical to the legitimate site. The attacker would then direct unsuspecting victims to this site in the hopes of luring them to attempt to log in and thus exposing their authentication credentials. This may be carried out via cross-site-scripting, distributing fake emails, or as previously mentioned leveraging a localized DNS poisoning attack. This is a common phishing scenario and is an easy way for an attacker to drain money from the accounts of victim users.&lt;br /&gt;&lt;br /&gt;Previously, under most attack scenarios, the malicious and fake banking site would not contain a legitimate and/or trusted certificate and a users browser would flag it as untrusted. However, an attacker with a maliciously crafted CA certificate created using the aforementioned vulnerability would be able to sign a certificate for the malicious site, and due to the implied trust of the root CA that was manipulated to sign the malicious intermediary CA, the browser would trust the site and unknowingly flag it as safe. &lt;br /&gt;&lt;br /&gt;When all of these conditions are fulfilled and carried out successfully, an attacker would be left with an extremely convincing and seemingly legitimate banking site that most users would never know to be malicious. By supplying a trusted certificate an attacker could greatly improve the chances of obtaining credentials.&lt;br /&gt;&lt;br /&gt;The Internet threat landscape for 2009 is going to be interesting. So-called esoteric or &amp;ldquo;difficult&amp;rdquo; attacks are beginning to become reality. Time and time again new research has proven that seemingly &amp;ldquo;un-exploitable&amp;rdquo; scenarios are indeed exploitable given a sufficient period of time. &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;For further reading:&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;&lt;strong&gt;&lt;br /&gt;MD5 considered harmful today - &lt;/strong&gt;&lt;/em&gt;&lt;a href=&#034;http://www.win.tue.nl/hashclash/rogue-ca/&#034; target=&#034;_blank&#034;&gt;Creating a rogue CA certificate&lt;/a&gt;&lt;/p&gt;</content:encoded>
				<dc:creator>Security Intel Analysis Team</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&amp;thread.id=183</guid>
				<dc:date>2008-12-31T00:07:48+00:00</dc:date>
				<category>Vulnerabilities &amp; Exploits</category>
			</item>
		<item>
				<title>Merry Christmas from Arnold Schwarzenegger! (?)</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;thread.id=223</link>
				<description>W32.Waledac is a worm that sends emails containing a link to an apparent Christmas e-card that you have received. However, when the link for the e-card in the email is visited, you receive a copy of the worm instead of a greeting card. The file name used by the worm is ecard.exe and the links are all Christmas related</description>
				<content:encoded>&lt;p&gt;While investigating the worm W32.Waledac recently, we got a shock (and a few laughs) from what popped up on ours screens (yes, unfortunately this is what passes for kicks in the virus lab during the holiday season):&lt;br /&gt;&lt;br /&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/arnold1.jpg&#034; border=&#034;0&#034; width=&#034;400&#034; height=&#034;401&#034; /&gt;&lt;br /&gt;&lt;br /&gt;(to see how we received this &amp;ndash; skip to &amp;ldquo;Arnold Surprise&amp;rdquo; below)&lt;br /&gt;&lt;br /&gt;First, I&amp;rsquo;ll tell you a little bit about the worm. &lt;a href=&#034;http://www.symantec.com/en/th/enterprise/security_response/writeup.jsp?docid=2008-122308-1429-99&#034; target=&#034;_blank&#034;&gt;W32.Waledac&lt;/a&gt; is a worm that sends emails containing a link to an apparent Christmas e-card that you have received. However, when the link for the e-card in the email is visited, you receive a copy of the worm instead of a greeting card. The file name used by the worm is ecard.exe and the links are all Christmas related, such as:&lt;br /&gt;&lt;br /&gt;hxxp://[removed]fatherchristmas.com&lt;br /&gt;hxxp://b[removed]christmascard.com&lt;br /&gt;hxxp://white[removed]christmas.com&lt;br /&gt;hxxp://christmas[removed]snow.com&lt;br /&gt;hxxp://[removed]christmasworld.com&lt;br /&gt;&lt;br /&gt;The emails look something like the following (although the template changes slightly all the time):&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;blockquote&gt;&lt;em&gt;From: &amp;quot;[FirstName]&amp;quot; &amp;lt;random@random&amp;gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;To:victim&lt;/em&gt;&lt;br /&gt;&lt;em&gt;&amp;nbsp;Subject: Merry Christmas wishes just for you&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Date: Tue, 23 Dec 2008 20:14:17 -0000&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;[FirstName] has just posted Merry Christmas Wishes.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;To pick up your greeting card, click on the following link:&lt;/em&gt;&lt;br /&gt;&lt;em&gt;http://white[removed]christmas.com?8d02cdcc97&lt;/em&gt;&lt;br /&gt;&lt;em&gt;The greeting card will be stored for you for 14 days.&lt;/em&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;br /&gt;And, when the link is visited, you will get a message like this:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/arnold2_lrg.jpg&#034; target=&#034;_blank&#034;&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/arnold2_sml.jpg&#034; border=&#034;0&#034; width=&#034;500&#034; height=&#034;399&#034; /&gt;&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;(&lt;strong&gt;Please don&amp;rsquo;t&lt;/strong&gt; run the .exe!)&lt;br /&gt;&lt;br /&gt;Even if you don&amp;rsquo;t accept the download of the ecard.exe &amp;ldquo;greeting card,&amp;rdquo; the attackers are already hard at work trying to exploit vulnerabilities in your browser. The page currently attempts to exploit many different vulnerabilities, including the zero-day vulnerability in Microsoft Internet Explorer discovered last week (patches from MS available here &lt;a href=&#034;http://www.microsoft.com/technet/security/Bulletin/MS08-078.mspx&#034; target=&#034;_blank&#034;&gt;http://www.microsoft.com/technet/security/Bulletin/MS08-078.mspx&lt;/a&gt;).&lt;/p&gt;&lt;p&gt;&lt;br /&gt;The list of exploits includes:&lt;br /&gt;&lt;br /&gt;MDAC Exploit (of course) &lt;br /&gt;Adobe PDF Exploit&lt;br /&gt;MS IE7 Exploit MS08-078&lt;br /&gt;Qiucktime RSTP exploit&lt;br /&gt;Snapshot Viewer exploit&lt;br /&gt;WebfolderIcon exploit&lt;br /&gt;NCTAudioFile2 ActiveX exploit&lt;br /&gt;KingSoft UpdateOcx2.dll SetUninstallName() Heap Overflow Exploit&lt;br /&gt;Yahoo! Webcam image upload ActiveX Exploit&lt;br /&gt;Yahoo! Webcam view utilities ActiveX Exploit&lt;br /&gt;Aurigma ImageUploader ActiveX Exploit&lt;br /&gt;RealNetworks RealPlayer ActiveX Exploit&lt;br /&gt;Creative Software AutoUpdate Engine ActiveX stack buffer overflow Exploit&lt;br /&gt;CA BrightStor ARCserve Backup r11.5 AddColumn() Exploit&lt;br /&gt;WebEx Meeting Manager ActiveX Control Exploit&lt;br /&gt;&lt;br /&gt;(Patches for all of the exploits mentioned above have been released by the respective vendor previously, i.e., there are no new exploits here.)&lt;br /&gt;&lt;br /&gt;The worm contains a long list of IP addresses that appear to be the control servers [see the writeup here for details]. The worm communicates with the control servers via a series of post requests to randomly named pages at these IP addresses and the data sent appears to be encrypted. The worm also appears to communicate with other infected hosts via a peer-to-peer channel. We are still analyzing the communication channels used by the worm. We will update this blog at a later stage with more info.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Arnold Surprise&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;While monitoring activity on the botnet we mostly saw encrypted info being sent via post requests to the control servers. Then we noticed a large image being sent down. Curious as to what the image might be we grabbed the image from the wire and hesitantly opened it. I&amp;rsquo;m not sure what we were expecting exactly, but this old picture of Arnold certainly wasn&amp;rsquo;t it! That caught us off guard completely and gave us a good laugh (thanks?). It seems that the speed of our connection was being tested, because shortly after this the worm tried to start sending spam.&lt;br /&gt;&lt;br /&gt;The spam that the worm was trying to send was mostly Christmas e-card emails that the worm uses to try and spread itself as mentioned above. However, we also saw the following emails being sent (we also enjoyed the poor English that is usually employed in these types of emails&amp;mdash;it keeps us laughing too):&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;blockquote&gt;&lt;em&gt;From: &amp;quot;Random Name&amp;quot; &amp;lt;random@email.address&amp;gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;To: &amp;lt;victim &amp;gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Subject: Flexible Hours career_ promotion possibilities for you&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Date: Tue, 23 Dec 2008 20:14:11 -0000&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Hello &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;We found your ad of work search. First of all let me introduce. We are&lt;/em&gt;&lt;br /&gt;&lt;em&gt;the large financial company. The main types of activity:&lt;/em&gt;&lt;br /&gt;&lt;em&gt;securities,exchange services,trading services,broker intermediary.&lt;/em&gt;&lt;br /&gt;&lt;em&gt;During the global crisis we have obtain a lot of customers who are&lt;/em&gt;&lt;br /&gt;&lt;em&gt;waiting for jump of the basic stock quotes. Most of the newly acquired&lt;/em&gt;&lt;br /&gt;&lt;em&gt;customers is in the Canada. Due to features of the legislation we&lt;/em&gt;&lt;br /&gt;&lt;em&gt;cannot work directly with physical persons. To do this we need an&lt;/em&gt;&lt;br /&gt;&lt;em&gt;authorized representative or official representation. As we did not&lt;/em&gt;&lt;br /&gt;&lt;em&gt;expect huge interest from the Canada - the opening of representation&lt;/em&gt;&lt;br /&gt;&lt;em&gt;is not included in our plans. In connection with the aforesaid, we are&lt;/em&gt;&lt;br /&gt;&lt;em&gt;looking for responsible person for mediation services which will be&lt;/em&gt;&lt;br /&gt;&lt;em&gt;the official representative in your region. In more details we will&lt;/em&gt;&lt;br /&gt;&lt;em&gt;tell to you in case of your interest. Send your interest note ONLY to:&lt;/em&gt;&lt;br /&gt;&lt;em&gt;[removed]@gmail.com&lt;/em&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Symantec originally detected this threat as a downloader and it has now been renamed to &lt;a href=&#034;http://www.symantec.com/en/th/enterprise/security_response/writeup.jsp?docid=2008-122308-1429-99&#034; target=&#034;_blank&#034;&gt;W32.Waledac&lt;/a&gt;, so be sure to update your definitions. Our IPS signatures also detect exploit-related traffic from the URLs listed above and our browser protection also triggered when we visited the sites listed above.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;A tip of the hat goes out to my colleague, Vikram Thakur, who shared in the research on this threat and also helped compile the info for this article. Also, over at Arbor Networks, Jose Nazario also posted a blog about this threat that you can find &lt;a href=&#034;http://asert.arbornetworks.com/2008/12/another-holiday-another-e-card-run-waledec/&#034; target=&#034;_blank&#034;&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;That&amp;rsquo;s all for now, but we&amp;rsquo;ll keep you posted on any new info. So, from everyone here in the virus lab, Happy Holidays!&lt;/p&gt;&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by Trevor Mack on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 12-29-2008&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 04:29 AM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>Liam O Murchu</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;thread.id=223</guid>
				<dc:date>2008-12-29T12:06:47+00:00</dc:date>
				<category>Malicious Code</category>
			</item>
		<item>
				<title>Phishing Attacks Utilizing Port Numbers</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=online_fraud&amp;thread.id=100</link>
				<description>There are varying types of technologies used by online attackers these days. There are old tricks and of course new ones, but it is the newer ones that make it even more difficult to handle the dilemmas faced in the world of Internet security. One of the trends of attack that was noticed a little while ago was an attack based on a website’s “port number.”</description>
				<content:encoded>&lt;p&gt;There are varying types of technologies used by online attackers these days. There are old tricks and of course new ones, but it is the newer ones that make it even more difficult to handle the dilemmas faced in the world of Internet security. One of the trends of attack that was noticed a little while ago was an attack based on a website&amp;rsquo;s &amp;ldquo;port number.&amp;rdquo; A port number is a way to identify a specific process to which an Internet or other network message is to be forwarded when it arrives at a server. We can identify a port number after a colon (&amp;ldquo;:&amp;rdquo;) following the host name. For example, consider &lt;a href=&#034;http://1.1.1.1/&#034; target=&#034;_blank&#034;&gt;http://1.1.1.1&lt;/a&gt;:8080/, in which the port number in the URL is 8080. &lt;br /&gt;&lt;br /&gt;According to the IANA (Internet Assigned Numbers Authority), the port numbers are divided into three ranges: well known ports, registered ports and the dynamic and/or private ports.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;blockquote&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp; The &amp;ldquo;well known&amp;rdquo; ports are those ranging from 0 through 1023. &lt;br /&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp; The &amp;ldquo;registered&amp;rdquo; ports are those from 1024 through 49151 &lt;br /&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp; The &amp;ldquo;dynamic&amp;rdquo; and/or &amp;ldquo;private&amp;rdquo; ports are those from 49152 through 65535. &lt;/blockquote&gt;&lt;p&gt;Statistics were taken for the phishing websites and it was seen that the maximum utilized port number was 82. It also came to light that the maximum amount of fraud against different port numbers came from the United States and Korea. The question then arises, why is there such a higher rate of attacks on port 82?&lt;br /&gt;&lt;br /&gt;With further research we see that port 82 is used for the &amp;ldquo;Xfer Utility.&amp;rdquo; The Xfer utility is a utility used for DNS zone transfers. This means that if data has to be transferred or replicated from the database of one DNS server of a particular zone to another, then the Xfer utility would be used. Only the administrator of that particular server, however, can perform this transfer. The cause of such a higher number of frauds in this protocol may be due to the vulnerabilities faced by the zone transfers.&lt;br /&gt;&lt;br /&gt;There are typically two security risks with regard to zone transfers:&lt;br /&gt;&lt;br /&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Exposure of data&lt;/strong&gt;: A zone transfer means an entire DNS record being exposed. If a hacker catches a hold on this transfer with some malicious code, he or she can view the entire set of listings of hosts in that domain. This gives the hacker a lot more control on the servers, which could allow a larger range of malicious practices to be attempted. &lt;br /&gt;&lt;br /&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;strong&gt;Denial of Service (DoS)&lt;/strong&gt;: If malicious code captures a DNS zone transfer, then the attacker could launch a DoS attack by overloading the servers with multiple requests. This would make the servers slow and unresponsive. In a more serious case it would block legitimate requests as well. &lt;br /&gt;&lt;br /&gt;There are possibilities that port 82 is used simply as an alternate to the regular ports of 80 and 81. However, it is difficult to prove the exact reason for witnessing this trend of port 82 frauds and the above two vulnerabilities are only a possible explanation. In the below images there are some interesting statistics that were collected earlier this year over a three-week period. They show the coverage of fraud attacks against certain port numbers, as shown: &lt;br /&gt;&lt;br /&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/sai_port1.jpg&#034; border=&#034;0&#034; width=&#034;530&#034; height=&#034;352&#034; /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/sai_port2.jpg&#034; border=&#034;0&#034; width=&#034;530&#034; height=&#034;349&#034; /&gt; &lt;br /&gt;&lt;br /&gt;Another reason for the attacks based on port numbers might be to escape anti-phishing technologies. Attackers continue to randomize the ports they use, which may possibly help in evading anti-phishing toolbars and at the same time try to target specific customers. For example, there were fraud sites coming from an IP that was phishing a specific brand, but was reported with several ports:&lt;br /&gt;&lt;br /&gt;http://IP number:722/update/secure/&lt;br /&gt;http://IP number:306/update/secure/&lt;br /&gt;http://IP number:9306/sharethisfolder/refunds.php&amp;nbsp;&amp;nbsp; &lt;br /&gt;http://IP number:9277/EBSec/index.html&amp;nbsp;&amp;nbsp; &lt;br /&gt;http://IP number:9777/xxx.NET/login.php&amp;nbsp;&amp;nbsp; &lt;br /&gt;http://IP number:8444/logon/index.html&amp;nbsp;&amp;nbsp; &lt;br /&gt;http://IP number:8444/haide/refunds.php&amp;nbsp;&amp;nbsp; &lt;br /&gt;http://IP number:844/recycler/refunds.php&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Here we can see that the IP remains the same but the ports randomize as 722, 306, 9306, 9277, and so on. The attack is also phishing only on a specific brand. This gives us an idea that the port randomization isn&amp;rsquo;t a coincidence in this case; rather, it looks like an intentional attempt by the attacker. Certain antifraud measures today might perform a check on a website for a certain port, but may not look into whether the site is active on any other port, which gives the attacker a chance to escape. Some of these ports, however, might also be accessible to the customer. This way, the attacker might escape anti-phish toolbars and succeed in targeting the customers.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;A method to detect and fight this form of attack would be to monitor the websites that seems to be dead by viewing them irrespective of the port number. We have to view the website, which may be alive on a different port. Best practices include being wary of sites that both ask for confidential information and that contain a port number in their URL. Please take the time to verify that the website is run by the original brand/company and only then provide information to the site.&lt;/p&gt;&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by Trevor Mack on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 12-23-2008&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 01:07 PM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>Sai Nayaran Nambiar</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=online_fraud&amp;thread.id=100</guid>
				<dc:date>2008-12-23T21:00:55+00:00</dc:date>
				<category>Online Fraud</category>
			</item>
		<item>
				<title>An Early Holiday Gift—The Return of Spam</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=133</link>
				<description>After the shutdown of McColo, which was aiding the distribution of about half of all spam on the internet globally, spam volumes dropped. However, since mid-November, spam volumes have been slowly inching their way back up as old botnets are being brought back online and potential new botnets are being created.</description>
				<content:encoded>&lt;p&gt;After the shutdown of McColo, which was aiding the distribution of about half of all spam on the internet globally, spam volumes dropped. However, since mid-November, spam volumes have been slowly inching their way back up as old botnets are being brought back online and potential new botnets are being created.&lt;br /&gt;&lt;br /&gt;At this point, spam volumes have slowly crept back up to 80 percent of their pre-McColo shutdown levels (when reviewing daily averages):&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/dm_colo_gph1.jpg&#034; border=&#034;0&#034; width=&#034;519&#034; height=&#034;339&#034; /&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The types of spam being seen in new attacks are similar to what was being sent around the Internet prior to the shutdown. The spam messages can be categorized into the following groups:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Replica watches&lt;/li&gt;&lt;li&gt;Generic pharmacy&lt;/li&gt;&lt;li&gt;Erectile dysfunction drugs&lt;/li&gt;&lt;li&gt;Weight loss&lt;/li&gt;&lt;li&gt;Software&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;The spam is being sent from various countries around the world and is associated with botnets. The top three senders of spam reviewed for this post were Brazil, the United States, and Russia.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Geographic origins of this spam:&lt;/p&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/dm_colo_gph2.jpg&#034; border=&#034;0&#034; /&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The makeup of the spam is varied. Some of the messages are very short, containing only a single URL, while others are slightly longer with some basic HTML that links to images. The longer spam messages contain both text and HTML parts. When looking at the URLs contained in spam, URLs containing the .cn top level domain (TLD) make up almost 10% of the URLs in spam, holding the second spot in the top eight TLDs appearing in spam, behind the .com TLD only.&lt;br /&gt;&lt;br /&gt;TLD breakdown for URLs appearing in spam:&lt;/p&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/dm_colo_gph3.jpg&#034; border=&#034;0&#034; width=&#034;520&#034; height=&#034;400&#034; /&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Some sample spam messages:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/dm_colo_img1.jpg&#034; border=&#034;0&#034; width=&#034;520&#034; height=&#034;523&#034; /&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/dm_colo_img2.jpg&#034; border=&#034;0&#034; width=&#034;520&#034; height=&#034;523&#034; /&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/dm_colo_img3.jpg&#034; border=&#034;0&#034; /&gt; &lt;/p&gt;</content:encoded>
				<dc:creator>Dylan Morss</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=133</guid>
				<dc:date>2008-12-20T00:26:04+00:00</dc:date>
				<category>Spam</category>
			</item>
		<item>
				<title>Missing Email Headers? Find Them in the Body.</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=131</link>
				<description>Spammers always try to come up with new tricks to bypass antispam filters. This time, they have shown an ability to partly (or sometimes completely) hide essential headers, ruling filters on headers out of picture. Except for the &#034;Received&#034; lines, we do not find any headers in the message.</description>
				<content:encoded>&lt;p&gt;Spammers always try to come up with new tricks to bypass antispam filters. This time, they have shown an ability to partly (or sometimes completely) hide essential headers, ruling filters on headers out of picture. Except for the &amp;quot;Received&amp;quot; lines, we do not find any headers in the message.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Analyzing the samples, we see very few SMTP commands before the actual message. We think that spammers may be using a slamming technique where all of the SMTP commands necessary to transmit an email message to another mail server are fired without waiting for the normal SMTP responses from the remote machine. Most of the time the remote server will end up accepting the message, although this clearly disobeys SMTP behavior as per various Internet standards. Slamming is primarily done to send unsolicited emails as rapidly as possible or, in this case possibly to hide all of the headers.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/mk_head1.jpg&#034; border=&#034;0&#034; width=&#034;520&#034; height=&#034;464&#034; /&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Symantec is keeping a close watch on this trend and ensuring that your inbox is free of such spam. Users are advised to use caution opening messages without subject lines, especially from unknown senders.&lt;/p&gt;</content:encoded>
				<dc:creator>Mayur Kulkarni</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=131</guid>
				<dc:date>2008-12-18T15:37:59+00:00</dc:date>
				<category>Spam</category>
			</item>
		<item>
				<title>A Caution During the Season of Giving</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=132</link>
				<description>Like so many forms of donations today, contributions to cancer research and treatment can be made online. Unfortunately, any online business or charity can be prone to phishing attacks against unsuspecting users.</description>
				<content:encoded>Like so many forms of donations today, contributions to cancer research and treatment can be made online. Unfortunately, any online business or charity can be prone to phishing attacks against unsuspecting users. We have come across messages posing as though they have been sent from a legitimate cancer institute, but with spoofed URLs inside. These spoofed URLs redirect users to fake websites where online donations can be made. When a user enters their email address and password for making payments, an error is shown and they are redirected to the legitimate site. This is common behavior seen with such attacks. The actual intention of these phishing websites is to harvest email addresses and steal confidential information.&lt;br /&gt;&lt;br /&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/mk_caution1.jpg&#034; border=&#034;0&#034; width=&#034;520&#034; height=&#034;371&#034; /&gt;&lt;br /&gt;&lt;br /&gt;Simple preventive measures such as manually typing legitimate URLs directly in the browser can be employed to make your contributions. It is the season of giving, but please make your online contributions with caution.</content:encoded>
				<dc:creator>Mayur Kulkarni</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=132</guid>
				<dc:date>2008-12-18T15:31:21+00:00</dc:date>
				<category>Spam</category>
			</item>
		<item>
				<title>Rise of IE Zero-Day Through SQL Injection</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&amp;thread.id=182</link>
				<description>Since our blog Yes, There’s a Zero-Day Exploit for Internet Explorer Out There that was posted in relation to the now known Microsoft Security Advisory (961051) for IE, we have been closely monitoring the uptake of this vulnerability. </description>
				<content:encoded>&lt;p&gt;Since our blog &lt;a href=&#034;../../../blogs/blogarticlepage/blog-id/vulnerabilities_exploits/article-id/180#M180&#034; target=&#034;_blank&#034;&gt;Yes, There&amp;rsquo;s a Zero-Day Exploit for Internet Explorer Out There&lt;/a&gt; was posted in relation to the now known &lt;a href=&#034;http://www.microsoft.com/technet/security/advisory/961051.mspx&#034; target=&#034;_blank&#034;&gt;Microsoft Security Advisory (961051)&lt;/a&gt; for IE, we have been closely monitoring the &lt;br /&gt;uptake of this vulnerability. Symantec provides the antivirus signature &lt;a href=&#034;http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-121012-3605-99&#034; target=&#034;_blank&#034;&gt;Bloodhound.Exploit.219&lt;/a&gt; and IPS signature &lt;a href=&#034;http://www.symantec.com/business/security_response/attacksignatures/detail.jsp?asid=23241&#034; target=&#034;_blank&#034;&gt;23241 - HTTP MSIE Malformed XML BO&lt;/a&gt; to protect users againstthis exploit. To date, since the release of our antivirus signature for this vulnerability, we have observed over 33,000 hits on Symantec customers. Abreakdown of the top 10 countries or regions reporting detections can be seen below:&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;a href=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/pc_zero1_lrg.JPG&#034; target=&#034;_blank&#034;&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/pc_zero1_sml.JPG&#034; border=&#034;0&#034; width=&#034;520&#034; height=&#034;370&#034; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;At present, Asia is clearly leading the way for potential infections through exploitation of this&lt;br /&gt;vulnerability. This is not surprising because we have also observed SQL injection attacks that&lt;br /&gt;specifically target Asian websites and use this Internet Explorer vulnerability. The following iframe examples below have been seen to be injected into over 100,000 compromised&lt;br /&gt;websites, mainly South Korean in origin.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;hxxp://s.a[removed]shanghai.com/s.js &lt;/p&gt;&lt;br /&gt;&lt;p&gt;hxxp://s.caw[removed].com/s.js &lt;/p&gt;&lt;br /&gt;&lt;p&gt;Once a compromised site containing one of these iframes is visited, the &lt;a href=&#034;http://www.microsoft.com/technet/security/advisory/961051.mspx&#034; target=&#034;_blank&#034;&gt;IE Exploit (961051)&lt;/a&gt; is one of several vulnerabilities run against the visiting computer user&#039;s system. Symantec currently has protection against the exploits served. If the system is exploited, it drops various malicious code onto the exploited system such as &lt;a href=&#034;http://www.symantec.com/security_response/writeup.jsp?docid=2002-101518-4323-99&#034; target=&#034;_blank&#034;&gt;Downloader&lt;/a&gt; and &lt;a href=&#034;http://www.symantec.com/security_response/writeup.jsp?docid=2008-042615-4654-99&#034; target=&#034;_blank&#034;&gt;Infostealer.Gamler&lt;/a&gt;. At present, Symantec has detection for this malicious code, but recommends that you keep your definitions up-to-date because the malicious code being served is changing on a regular basis.&lt;/p&gt;&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by Turlas on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 12-16-2008&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 12:53 PM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>Peter Coogan</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&amp;thread.id=182</guid>
				<dc:date>2008-12-15T19:08:45+00:00</dc:date>
				<category>Vulnerabilities &amp; Exploits</category>
			</item>
		<item>
				<title>Just a Reminder</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=evolution_of_security&amp;thread.id=26</link>
				<description>You may have seen an article in the New York Times on December 6, 2008, by John Markoff, entitled &#034;Thieves Winning Online War, Maybe Even in Your Computer.&#034; As we&#039;ve previously discussed here, we&#039;re exploring an exciting new reputation-based security approach to protect against the continuing proliferation of the types of threats described in the article.</description>
				<content:encoded>&lt;p&gt;You may have seen an article in the New York Times on December 6, 2008, by John Markoff, entitled &amp;quot;&lt;a href=&#034;http://www.nytimes.com/2008/12/06/technology/internet/06security.html?ref=technology&#034; target=&#034;_blank&#034;&gt;Thieves Winning Online War, Maybe Even in Your Computer&lt;/a&gt;.&amp;quot; As we&#039;ve previously discussed here, we&#039;re exploring an exciting new reputation-based security approach to protect against the continuing proliferation of the types of threats described in the article.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;For more detail, please take a look at these two previous blog articles by Carey Nachenberg:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt; &lt;a href=&#034;https://forums.symantec.com/t5/blogs/blogarticlepage/blog-id/emerging/article-id/113&#034; target=&#034;_blank&#034;&gt;It&#039;s All About Reputation&lt;/a&gt;, and &lt;a href=&#034;https://forums.symantec.com/t5/blogs/blogarticlepage/blog-id/emerging/article-id/112&#034; target=&#034;_blank&#034;&gt;Losing Touch with Fingerprinting&lt;/a&gt; &lt;/p&gt;&lt;/blockquote&gt;</content:encoded>
				<dc:creator>Steve Trilling</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=evolution_of_security&amp;thread.id=26</guid>
				<dc:date>2008-12-13T00:47:53+00:00</dc:date>
				<category>Evolution Of Security</category>
			</item>
		<item>
				<title>Protecting Zero-Day</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&amp;thread.id=181</link>
				<description>Earlier this week we had the opportunity to analyze an interesting shellcode that is associated with the initial malicious exploit attempts against the Microsoft Internet Explorer XML Handling Remote Code Execution Vulnerability (BID 32721).</description>
				<content:encoded>Hello, this is Anthony from the Symantec Intelligence Analysis Team. Earlier this week we had the opportunity to analyze an interesting shellcode that is associated with the initial malicious exploit attempts against the &lt;a href=&#034;http//www.securityfocus.com/bid/32721&#034; target=&#034;_blank&#034;&gt;Microsoft Internet Explorer XML Handling Remote Code Execution Vulnerability&lt;/a&gt; (BID 32721). Currently this vulnerability is not patched and there are several public exploits available to leverage the issue. The vulnerability exists due to a flaw in how Internet Explorer handles XML data bindings. Specially crafted XML can lead to object corruption and code execution. I am not going to go into describing the vulnerability in detail because this &lt;a href=&#034;https://forums.symantec.com/t5/blogs/blogarticlepage/blog-id/vulnerabilities_exploits/article-id/180&#034; target=&#034;_blank&#034;&gt;has already been done well elsewhere&lt;/a&gt;. However, I think that the shellcode is unique enough to warrant some discussion.&lt;br /&gt;&lt;br /&gt;When the shellcode executes, it uses GlobalAlloc() to relocate itself into memory that is safe. This is to make sure that the shellcode is not corrupted by the Internet Explorer process before it can finish executing. This is a common technique in modern shellcode payloads. However, after this relocation, the shellcode begins installing hooks into several key functions:&lt;br /&gt;&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; UnhandledExceptionFilter&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; MessageBeep&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; LdrShutdownThread&lt;br /&gt;&lt;br /&gt;The hook is fairly straightforward. The shellcode gets the address of the target function and then uses VirtualProtect() to change the memory permissions for it. It then writes &amp;ldquo;&lt;font face=&#034;times new roman,times&#034; size=&#034;1&#034;&gt;mov eax, addr_of_new_code; jmp eax&lt;/font&gt;&amp;rdquo; into the function prelude. This has the affect of hijacking execution flow from the hooked function so that it executes code that the attacker supplies. This can be seen in the following disassembly of the hook for UnhandledExceptionFilter():&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:00000043&amp;nbsp;&amp;nbsp;&amp;nbsp; call&amp;nbsp;&amp;nbsp;&amp;nbsp; get_addr_Kernel32_UnhandledExceptionFilter&lt;/font&gt;&lt;br /&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:00000048&amp;nbsp;&amp;nbsp;&amp;nbsp; mov&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; edi, eax&amp;nbsp; &lt;/font&gt;&lt;br /&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:0000004A&amp;nbsp;&amp;nbsp;&amp;nbsp; call&amp;nbsp;&amp;nbsp;&amp;nbsp; VirtualProtect_EDI_Mem_PAGE_EXECUTE_READWRITE&lt;/font&gt;&lt;br /&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:0000004F&amp;nbsp;&amp;nbsp;&amp;nbsp; call&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;HOOK_UnhandledExceptionFilter&lt;/font&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;EDI now points to target function and the target function memory is marked EXCUTE_READWRITE. This means that the shellcode can now overwrite parts of the target function prelude:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;font face=&#034;times new roman,times&#034;&gt;Hook_UnhandledExceptionFilter:&lt;/font&gt;&lt;br /&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:000001A1&amp;nbsp;&amp;nbsp;&amp;nbsp; call&amp;nbsp;&amp;nbsp;&amp;nbsp; hook_function&lt;/font&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The function below &amp;ldquo;&lt;font face=&#034;times new roman,times&#034;&gt;hook_function&lt;/font&gt;&amp;rdquo; writes &amp;ldquo;&lt;font face=&#034;times new roman,times&#034;&gt;mov eax, addr_of_new_code; jmp eax&lt;/font&gt;&amp;rdquo; into the target function prelude:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;font face=&#034;times new roman,times&#034;&gt;hook_function:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/font&gt;&lt;br /&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:000000CE&amp;nbsp;&amp;nbsp;&amp;nbsp; pop&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ebx&amp;nbsp;&amp;nbsp;&amp;nbsp; ;ebx = addr_of_new_code&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/font&gt;&lt;br /&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:000000CF&amp;nbsp;&amp;nbsp;&amp;nbsp; mov&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; byte ptr [edi], 0B8h &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;; mov eax, addr_of_new_code seg000:000000D3&amp;nbsp;&amp;nbsp;&amp;nbsp; mov&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [edi&#43;1], ebx&lt;/font&gt;&lt;br /&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:000000D7&amp;nbsp;&amp;nbsp;&amp;nbsp; mov&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; word ptr [edi&#43;5], 0E0FFh ; jmp eax&lt;/font&gt;&lt;br /&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:000000DE&amp;nbsp;&amp;nbsp;&amp;nbsp; retn&lt;/font&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;In this case the hook makes the UnhandledExceptionFilter() function return a generic Windows error. This can be seen below:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;font face=&#034;times new roman,times&#034;&gt;addr_of_new_code: &lt;/font&gt;&lt;br /&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:000001A6&amp;nbsp;&amp;nbsp;&amp;nbsp; mov&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eax, 80040111h ; Make function return a &amp;lsquo;normal&amp;rsquo; error.&lt;/font&gt;&lt;br /&gt;&lt;font face=&#034;times new roman,times&#034;&gt;seg000:000001AB&amp;nbsp;&amp;nbsp;&amp;nbsp; retn&amp;nbsp;&amp;nbsp;&amp;nbsp; 0Ch&lt;/font&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Separate hooks are installed for the MessageBeep() and LdrShutdownThread() functions. These functions are redirected to a routine that uses EnumWindows() and GetClassName() to find the Internet Explorer window. After it finds the window it uses DestroyWindow() to kill the Internet Explorer window, and ExitProcess() to exit the process cleanly.&lt;br /&gt;&lt;br /&gt;After all of these hooks are installed, the shellcode is very ordinary; it simply downloads a tertiary executable payload that acts as a vehicle to deliver a number of malicious binaries to install on the compromised system. So, I guess the question now is, why are these function hooks installed? I have not seen this type of behavior in shellcode before, and consequently I don&amp;rsquo;t think hooking these functions is a common technique. Though, I could be mistaken.&lt;br /&gt;&lt;br /&gt;My best guess is that these hooks are designed to hide the malicious nature of the browser crash. A zero-day vulnerability loses its value in relation to the number of people that know about the vulnerability. It is most valuable when the vulnerability is not known by a large number of people. So, it makes sense that an attack using a zero-day would be as covert as possible. I am not intimately familiar with how this particular vulnerability affects the process memory of Internet Explorer yet, but perhaps it leaves the process in an unstable state. If this is the case, hooking functions that are likely to be triggered during a browser crash such as UnhandledExceptionFilter(), MessageBeep(), and LdrShutdownThread(), could be a covertness tactic. If the shellcode payload causes the process to exit cleanly with generic errors, the victim of an attack may not be suspicious of a crash and therefore less likely to investigate and discover the vulnerability.&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by Trevor Mack on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 12-12-2008&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 04:55 PM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>Security Intel Analysis Team</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&amp;thread.id=181</guid>
				<dc:date>2008-12-13T00:02:41+00:00</dc:date>
				<category>Vulnerabilities &amp; Exploits</category>
			</item>
		<item>
				<title>IDNs in Phishing</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=online_fraud&amp;thread.id=99</link>
				<description>What is an IDN? IDN stands for “internationalized domain name.” These are the domain names that contain one or more characters that do not belong to a Latin-based western language (or characters that are not available in the ASCII character set).</description>
				<content:encoded>&lt;p&gt;What is an IDN? IDN stands for &amp;ldquo;internationalized domain name.&amp;rdquo; These are the domain names that contain one or more characters that do not belong to a Latin-based western language (or characters that are not available in the ASCII character set). &lt;br /&gt;&lt;br /&gt;Domain Name System or DNS (a naming system that links domain names to IP addresses) has the technical support for these IDNs, but many applications such as Web browsers, email services, etc. are not yet able to support them. Such compatibility issues arising from IDNs necessitated a conversion from an international character to a suitable ASCII character. The conversion is achieved by the use of certain algorithms that converts these characters into a code called Punycode. A Punycode contains ASCII characters prefixed with the string &amp;ldquo;xn&amp;mdash;.&amp;rdquo; &lt;br /&gt;&lt;br /&gt;The following is an example for a Chinese domain converted to its Punycode:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Domain name&lt;/strong&gt; -&amp;nbsp; 例如.com&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Punycode&lt;/strong&gt; -&amp;nbsp; xn--fsqu6v.com&lt;br /&gt;&lt;br /&gt;The Punycode can be converted back to its original form. Many online conversion tools are available to do the conversion to Punycode and back. So, the next time you see the four character string &amp;ldquo;xn&amp;mdash;&amp;rdquo; in the domain of a website, you may be looking at an IDN in its Punycode form.&lt;br /&gt;&lt;br /&gt;Unfortunately there is a danger involving IDNs, where the similarity of certain non-ASCII characters with western, Latin-based alphabets is being taken advantage of in phishing attacks. Typosquatters take advantage of such similarities. For example, the character &amp;ldquo;&amp;auml;,&amp;rdquo; which is German, resembles the letter &amp;ldquo;a&amp;rdquo; in English. A typosquatter can create a phishing site with the string &amp;ldquo;b&amp;auml;nk,&amp;rdquo; which resembles &amp;ldquo;bank.&amp;rdquo; Internet users can then be tricked into entering their confidential information into the phishing site for the purpose of identity theft.&lt;br /&gt;&lt;br /&gt;In the month of October, Symantec observed 10 phishing websites that contained IDNs that were in German, Korean, and Vietnamese. One of these phishing Web sites was leveraging international characters resembling ASCII characters to spoof a western brand&amp;rsquo;s domain name.&lt;br /&gt;&lt;br /&gt;Stay on your toes when visiting domains with names based on Punycode and/or non-ASCII characters. Take a look around and use some of the online conversion tools to check on any unfamiliar domain names, and please don&#039;t click on any unfamiliar links and be wary of any links received in emails that have come from an untrustred or unexpected source.&lt;/p&gt;</content:encoded>
				<dc:creator>Mathew Maniyara</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=online_fraud&amp;thread.id=99</guid>
				<dc:date>2008-12-12T17:47:58+00:00</dc:date>
				<category>Online Fraud</category>
			</item>
		<item>
				<title>Phishing Messages Evolve as Webmail Phishing Comes Along</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=130</link>
				<description>Webmail phishing was first reported earlier this year, but it has gained a higher profile in recent times. The call to action or general purpose of this attack is to obtain webmail credentials such as passwords and contact list email addresses.</description>
				<content:encoded>Webmail phishing was first reported earlier this year, but it has gained a higher profile in recent times. The call to action or general purpose of this attack is to obtain webmail credentials such as passwords and contact list email addresses. A number of different scenarios have been employed by webmail phishers to try and secure this information and have included:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Scenario 1&lt;/strong&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;&amp;ldquo;We write to bring to your notice that we will be caring out some temporary maintenance on our service due to congestion in all email accounts and we are afraid that during this process email accounts of our customers will be deactivated; but just to avoid your email account from been deactivated and to enable your records remain in our database we advice you provide us with the below information or your email account will be suspended within 48 hours for security reasons.&amp;rdquo;&lt;/em&gt; (sic)&lt;/blockquote&gt;&lt;strong&gt;Scenario 2&lt;br /&gt;&lt;/strong&gt;&lt;blockquote&gt;&lt;em&gt;&amp;ldquo;Due to spam complaints of email users in our [Name Removed] webmail system, our investigation shows that your email address is&amp;nbsp; compromised and is used to send out spam message in our [Name Removed] webmail&amp;nbsp; system. As a result, your Username will be disabled if you do not send us the required information within 24hrs.&amp;rdquo;&lt;/em&gt; (sic)&lt;/blockquote&gt;As with other phishing messages, these are adapted to look like they are coming from a specific organization and are then targeted towards members of that organization. One of the common features of webmail phishing is that the message is only in text. Unlike traditional phishing messages, the message does not contain a fraudulent URL link. The recipient is asked to use the address in the &amp;quot;Reply To&amp;quot; header or an email address in the message body to respond to the webmail phishing message.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;It is clear that as long as the profit motive exists, the purveyors of phishing messages will continue to evolve and adapt their techniques to try and scam individuals and organizations.</content:encoded>
				<dc:creator>Dermot Harnett</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=130</guid>
				<dc:date>2008-12-11T15:13:13+00:00</dc:date>
				<category>Spam</category>
			</item>
		<item>
				<title>Yes, There’s a Zero-Day Exploit for Internet Explorer Out There</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&amp;thread.id=180</link>
				<description>A new and previously unknown vulnerability affecting the Microsoft Internet Explorer 7 browser has been reported, just at the start of the Microsoft “Patch Tuesday” cycle for the month of December. Bad luck, or an intentional strategy by the attackers?</description>
				<content:encoded>A new and previously unknown vulnerability affecting the Microsoft Internet Explorer 7 browser has been reported, just at the start of the Microsoft &amp;ldquo;Patch Tuesday&amp;rdquo; cycle for the month of December. Bad luck, or an intentional strategy by the attackers? It&amp;rsquo;s not clear at the moment, but the reality is that users around the world started to download and patch their systems just yesterday, while at the same time a new and dangerous exploit surfaced on the Web, trying to infect computers in China and other parts of Asia.&lt;br /&gt;&lt;br /&gt;We ran some tests and confirmed that the new vulnerability is, unfortunately, not fixed by the current set of patches released yesterday. The attack is indeed new and it works successfully against a fully patched Windows XP SP3 with Internet Explorer 7, including all recent Microsoft Tuesday patches. Also, Internet Explorer 6 could potentially be affected by the same problem and is therefore only temporarily immune to this initial exploit, which seems to target Internet Explorer 7 on Windows XP and 2003 systems.&lt;br /&gt;&lt;br /&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ef_ie7zero_1.jpg&#034; border=&#034;0&#034; /&gt;&lt;br /&gt;&lt;br /&gt;Initial reports by other security vendors mentioned a malformed XML tag as the possible cause of the vulnerability; however, from a deeper analysis it seems that the problem affects the XML parsing engine of IE7 and the library MSHTML.DLL. The vulnerability depends on how certain elements of HTML pages are terminated and therefore could potentially affect not only XML, but also other objects handled by the browser. This means that attackers may start using different attack vectors in the future to exploit this vulnerability, but at the moment it seems that this recent exploit, which has been publicly released on several Chinese forums, only uses the XML elements and tags.&lt;br /&gt;&lt;br /&gt;&lt;a href=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ef_ie7zero_2_lrg.jpg&#034; target=&#034;_blank&#034;&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ef_ie7zero_2_sml.jpg&#034; border=&#034;0&#034; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The vulnerability is caused by a function that incorrectly frees a certain region of heap memory so that an attacker is able to control the EAX register with a specially crafted Unicode URL, which includes the magic &amp;ldquo;0x0A0A&amp;rdquo; value in it. The image below shows an example of the execution crash in the MSHTML module; EAX is loaded with the value controlled by the attacker and is used later as a function pointer to control execution.&lt;br /&gt;&lt;br /&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ef_ie7zero_3.jpg&#034; border=&#034;0&#034; /&gt;&lt;br /&gt;&lt;br /&gt;Because of the nature of this attack, it does not depend by any specific ActiveX control, so this time we can&amp;rsquo;t tell you to disable or set the KillBit for a specific CLSID. However, the attack still requires some JavaScript in order to use heap-spray techniques to achieve a reliable code execution; so, blocking JavaScript for un-trusted websites could help to somewhat mitigate the risk. &lt;br /&gt;&lt;br /&gt;Our advice for Windows users is as follows:&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; Update your AV and IPS software with the latest signatures&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; Run Internet Explorer with limited privileges&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enable DEP protection for browsers&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; Disable JavaScript in Internet Explorer &lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; Avoid following links to un-trusted sites&lt;br /&gt;&lt;br /&gt;At the moment, we can trace many attacks back to Chinese domains and websites, which are used by the exploit to install and download additional malicious code components. The downloaded malicious code is a variety of &lt;a href=&#034;http://www.symantec.com/security_response/writeup.jsp?docid=2002-101518-4323-99&#034; target=&#034;_blank&#034;&gt;Downloader&lt;/a&gt;, &lt;a href=&#034;http://www.symantec.com/security_response/writeup.jsp?docid=2000-122016-0558-99&#034; target=&#034;_blank&#034;&gt;Infostealer&lt;/a&gt;, and &lt;a href=&#034;http://www.symantec.com/security_response/writeup.jsp?docid=2007-011714-4020-99&#034; target=&#034;_blank&#034;&gt;W32.SillyDC&lt;/a&gt; variants. We also recommend blocking the following hosts at network boundaries:&lt;br /&gt;&lt;blockquote&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; wwwwyyyyy.cn&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; sllwrnm5.cn&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; baikec.cn&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; oiuytr.net&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; laoyang4.cn&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; cc4y7.cn&lt;br /&gt;&lt;/blockquote&gt;Symantec released the antivirus signature &lt;a href=&#034;http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-121012-3605-99&#034; target=&#034;_blank&#034;&gt;Bloodhound.Exploit.219&lt;/a&gt; and IPS signature &lt;a href=&#034;http://www.symantec.com/business/security_response/attacksignatures/detail.jsp?asid=23241&#034; target=&#034;_blank&#034;&gt;23241 - HTTP MSIE Malformed XML BO&lt;/a&gt; to protect users against this exploit.&lt;br /&gt;&lt;br /&gt;* Big thanks go out to Nishant A Doshi and Chintan Trivedi for their valuable help in the analysis of this vulnerability.</content:encoded>
				<dc:creator>Elia Florio</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&amp;thread.id=180</guid>
				<dc:date>2008-12-10T17:47:52+00:00</dc:date>
				<category>Vulnerabilities &amp; Exploits</category>
			</item>
		<item>
				<title>November 2008 – A Historic Month in the Political and Spam Landscape</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=129</link>
				<description>November 2008—what a month! A new U.S. president is elected and spam volumes drop significantly as a hosting company called McColo is shutdown. While both these events were generally welcomed, the new President and the antispam community continue to face tough obstacles in the year ahead.</description>
				<content:encoded>&lt;p&gt;November 2008&amp;mdash;what a month! A new U.S. president is elected and spam volumes drop significantly as a hosting company called McColo is shutdown. While both these events were generally welcomed, the new President and the antispam community continue to face tough obstacles in the year ahead.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;On November 11, 2008, McColo-hosted systems were shut down based on abuse complaints. As a result, spam volumes dropped dramatically across the world. The Symantec probe network saw a 65 percent drop in traffic when compared to the 24 hours before the McColo.com shutdown. As November drew to a close, Symantec saw that spam volumes have had various upward spikes and are again creeping upwards. These spikes indicate that a return to normal spam activity is in the works. While the profit motive behind spam continues to exist, spammers will regroup to drive new spam campaigns.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;While the McColo shutdown may have brought some cheer to email users during this holiday season, spammers have, in 2008, just as in previous years, adjusted their spam campaigns to include a holiday element. It seems that no holiday season would be complete without spam messages offering a fake brand name watch.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To read about these or other trends in the Symantec Monthly State of Spam Report, such as Italian-, casino-, and IRS-related spam messages, please visit the &lt;a href=&#034;http://www.symantec.com/spam&#034; target=&#034;_blank&#034;&gt;State of Spam website&lt;/a&gt; and the &lt;a href=&#034;http://eval.symantec.com/mktginfo/enterprise/other_resources/b-state_of_spam_report_12-2008.en-us.pdf&#034; target=&#034;_blank&#034;&gt;December State of Spam Report&lt;/a&gt;.&lt;/p&gt;</content:encoded>
				<dc:creator>Dermot Harnett</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=129</guid>
				<dc:date>2008-12-09T21:56:57+00:00</dc:date>
				<category>Spam</category>
			</item>
		<item>
				<title>Microsoft Patch Tuesday, December 2008</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&amp;thread.id=179</link>
				<description>Hello and welcome to this month&#039;s blog on the Microsoft patch releases. As far as vulnerability counts go, this is the largest patch release since Microsoft started the &#034;Patch Tuesday&#034; program back in late 2003. The release contains eight bulletins covering 28 vulnerabilities.</description>
				<content:encoded>&lt;p&gt;Hello and welcome to this month&#039;s blog on the Microsoft patch releases. As far as vulnerability counts go, this is the largest patch release since Microsoft started the &amp;quot;Patch Tuesday&amp;quot; program back in late 2003. The release contains eight bulletins covering 28 vulnerabilities.&lt;br /&gt;&lt;br /&gt;Of those issues, 23 are rated &amp;quot;Critical&amp;quot; and affect Word, Outlook, Internet Explorer, Visual Basic ActiveX controls, GDI, Windows Search, and Excel. All of the &amp;quot;Critical&amp;quot; issues this month require some sort of user interaction, whether visiting a Web page that contains malicious content or viewing a malicious file. The remaining issues affect GDI, Windows Search, SharePoint, and Windows Explorer; they range in importance from &amp;quot;Important&amp;quot; to &amp;quot;Moderate.&amp;quot;&lt;br /&gt; &lt;br /&gt;As always, customers are advised to follow security best practices, including:&lt;br /&gt;&lt;br /&gt;-	Install vendor patches as soon as they are available&lt;br /&gt;-	Block external access at the network perimeter to specific sites and computers only&lt;br /&gt;-	Avoid sites of questionable or unknown integrity&lt;br /&gt;-	Never open files from unknown or questionable sources&lt;br /&gt;-	Run all software with the least privileges required while still maintaining functionality&lt;br /&gt;&lt;br /&gt;Microsoft&#039;s summary of the December releases can be found here: &lt;br /&gt;&lt;a href=&#034;http://www.microsoft.com/technet/security/bulletin/ms08-dec.mspx&#034; target=&#034;_blank&#034;&gt;http://www.microsoft.com/technet/security/bulletin/ms08-dec.mspx&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The &amp;quot;Critical&amp;quot; issues this month are:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1. &lt;a href=&#034;http://www.microsoft.com/technet/security/Bulletin/MS08-070.mspx&#034; target=&#034;_blank&#034;&gt;MS08-070&lt;/a&gt; Vulnerabilities in Visual Basic ActiveX Controls Could Allow Remote Code Execution (932349)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Multiple remote code execution vulnerabilities affect various ActiveX controls for Visual Basic 6. An attacker can exploit these issues by tricking an unsuspecting victim into viewing a malicious Web page. A successful exploit will result in the execution of arbitrary attacker-supplied code in the context of the currently logged-in user. The issues include:&lt;br /&gt;&lt;br /&gt;CVE-2008-4252 (&lt;a href=&#034;http://www.securityfocus.com/bid/32591&#034; target=&#034;_blank&#034;&gt;BID 32591&lt;/a&gt;) Microsoft DataGrid ActiveX Control Memory Corruption Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4253 (&lt;a href=&#034;http://www.securityfocus.com/bid/32592&#034; target=&#034;_blank&#034;&gt;BID 32592&lt;/a&gt;) Microsoft FlexGrid ActiveX Control Memory Corruption Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4254 (&lt;a href=&#034;http://www.securityfocus.com/bid/32612&#034; target=&#034;_blank&#034;&gt;BID 32612&lt;/a&gt;) Microsoft Hierarchical FlexGrid ActiveX Control Memory Corruption Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4255 (&lt;a href=&#034;http://www.securityfocus.com/bid/32613&#034; target=&#034;_blank&#034;&gt;BID 32613&lt;/a&gt;) Microsoft Windows Common AVI ActiveX Control File Parsing Memory Corruption Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4256 (&lt;a href=&#034;http://www.securityfocus.com/bid/32614&#034; target=&#034;_blank&#034;&gt;BID 32614&lt;/a&gt;) Microsoft Charts ActiveX Control Memory Corruption Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-3704 (&lt;a href=&#034;http://www.securityfocus.com/bid/30674&#034; target=&#034;_blank&#034;&gt;BID 30674&lt;/a&gt;) Microsoft Visual Studio &#039;Msmask32.ocx&#039; ActiveX Control Remote Buffer Overflow Vulnerability (MS Rating: Critical/Symantec Urgency Rating 8.9/10)&lt;br /&gt;&lt;br /&gt;This is a previously public vulnerability in the MaskedEdit ActiveX control detected by Symantec on August 13, 2008, and is documented in BID 30674. A stack-based buffer overflow occurs when the control handles overly large arguments to the &amp;quot;Mask&amp;quot; parameter. An attacker can exploit this issue by tricking an unsuspecting victim into viewing a malicious Web page. A successful exploit will result in the execution of arbitrary attacker-supplied code in the context of the currently logged in user.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. &lt;a href=&#034;http://www.microsoft.com/technet/security/Bulletin/MS08-071.mspx&#034; target=&#034;_blank&#034;&gt;MS08-071&lt;/a&gt; Vulnerabilities in GDI Could Allow Remote Code Execution (956802)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;CVE-2008-2249 (&lt;a href=&#034;http://www.securityfocus.com/bid/32634&#034; target=&#034;_blank&#034;&gt;BID 32634&lt;/a&gt;) Microsoft Windows GDI WMF Integer Overflow Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;A remote code-execution vulnerability affects GDI when processing a specially malformed header in a WMF file. An attacker can exploit this issue by tricking an unsuspecting victim into opening a malicious WMF file. A successful exploit will result in the execution of arbitrary code in the context of the currently logged in user.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;3. &lt;a href=&#034;http://www.microsoft.com/technet/security/Bulletin/MS08-072.mspx&#034; target=&#034;_blank&#034;&gt;MS08-072&lt;/a&gt; Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (957173)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Multiple remote code execution vulnerabilities affect Word when handling malicious Office and Rich Text Format (RTF) files. An attacker can exploit these issues by tricking an unsuspecting victim into opening a malicious file. A successful exploit will result in the execution of arbitrary code in the context of the currently logged-in user. The issues include:&lt;br /&gt;&lt;br /&gt;CVE-2008-4024 (&lt;a href=&#034;http://www.securityfocus.com/bid/32580&#034; target=&#034;_blank&#034;&gt;BID 32580&lt;/a&gt;) Microsoft Word Malformed Record Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4026 (&lt;a href=&#034;http://www.securityfocus.com/bid/32583&#034; target=&#034;_blank&#034;&gt;BID 32583&lt;/a&gt;) Microsoft Word Malformed Value Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4837 (&lt;a href=&#034;http://www.securityfocus.com/bid/32584&#034; target=&#034;_blank&#034;&gt;BID 32584&lt;/a&gt;) Microsoft Word Malformed Record Value Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4025 (&lt;a href=&#034;http://www.securityfocus.com/bid/32579&#034; target=&#034;_blank&#034;&gt;BID 32579&lt;/a&gt;) Microsoft Word RTF Malformed Control Word Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4027 (&lt;a href=&#034;http://www.securityfocus.com/bid/32581&#034; target=&#034;_blank&#034;&gt;BID 32581&lt;/a&gt;) Microsoft Word RTF Malformed Control Word Variant 1 Remote Code Execution Vulnerabillity (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4030 (&lt;a href=&#034;http://www.securityfocus.com/bid/32642&#034; target=&#034;_blank&#034;&gt;BID 32642&lt;/a&gt;) Microsoft Word RTF Malformed Control Word Variant 2 Remote Code Execution Vulnerabillity (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4028 (&lt;a href=&#034;http://www.securityfocus.com/bid/32585&#034; target=&#034;_blank&#034;&gt;BID 32585&lt;/a&gt;) Microsoft Word RTF Malformed Control Word Variant 3 Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4031 (&lt;a href=&#034;http://www.securityfocus.com/bid/32594&#034; target=&#034;_blank&#034;&gt;BID 32594&lt;/a&gt;) Microsoft Word RTF Malformed String Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;4. &lt;a href=&#034;http://www.microsoft.com/technet/security/Bulletin/MS08-073.mspx&#034; target=&#034;_blank&#034;&gt;MS08-073&lt;/a&gt; Cumulative Security Update for Internet Explorer (958215)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Multiple remote code execution vulnerabilities affect Internet Explorer. An attacker can exploit these issues by tricking an unsuspecting victim into viewing a Web page containing malicious content. A successful exploit will result in the execution of arbitrary code in the context of the currently logged-in user. The issues include:&lt;br /&gt;&lt;br /&gt;CVE-2008-4258 (&lt;a href=&#034;http://www.securityfocus.com/bid/32596&#034; target=&#034;_blank&#034;&gt;BID 32596&lt;/a&gt;) Microsoft Internet Explorer Navigation Method Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4259 (&lt;a href=&#034;http://www.securityfocus.com/bid/32586&#034; target=&#034;_blank&#034;&gt;BID 32586&lt;/a&gt;) Microsoft Internet Explorer HTML Objects Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4260 (&lt;a href=&#034;http://www.securityfocus.com/bid/32593&#034; target=&#034;_blank&#034;&gt;BID 32593&lt;/a&gt;) Microsoft Internet Explorer Deleted Object Access Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4261 (&lt;a href=&#034;http://www.securityfocus.com/bid/32595&#034; target=&#034;_blank&#034;&gt;BID 32595&lt;/a&gt;) Microsoft Internet Explorer Embedded Object Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;5. &lt;a href=&#034;http://www.microsoft.com/technet/security/Bulletin/MS08-074.mspx&#034; target=&#034;_blank&#034;&gt;MS08-074&lt;/a&gt; Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Multiple remote code execution vulnerabilities affect Excel when handling malicious Excel files. An attacker can exploit these issues by tricking an unsuspecting victim into opening a malicious Excel file. A successful exploit will result in the execution of arbitrary code in the context of the currently logged-in user. The issues include:&lt;br /&gt;&lt;br /&gt;CVE-2008-4265 (&lt;a href=&#034;http://www.securityfocus.com/bid/32618&#034; target=&#034;_blank&#034;&gt;BID 32618&lt;/a&gt;) Microsoft Excel Malformed Object Handling Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4264 (&lt;a href=&#034;http://www.securityfocus.com/bid/32621&#034; target=&#034;_blank&#034;&gt;BID 32621&lt;/a&gt;) Microsoft Excel Formula Handling Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;CVE-2008-4266 (&lt;a href=&#034;http://www.securityfocus.com/bid/32622&#034; target=&#034;_blank&#034;&gt;BID 32622&lt;/a&gt;) Microsoft Excel Global Array Memory Corruption Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;6. &lt;a href=&#034;http://www.microsoft.com/technet/security/Bulletin/MS08-075.mspx&#034; target=&#034;_blank&#034;&gt;MS08-075&lt;/a&gt; Vulnerabilities in Windows Search Could Allow Remote Code Execution (959349)&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;CVE-2008-4269 (&lt;a href=&#034;http://www.securityfocus.com/bid/32652&#034; target=&#034;_blank&#034;&gt;BID 32652&lt;/a&gt;) Microsoft Windows Search &#039;search-ms&#039; Protocol Parsing Remote Code Execution Vulnerability (MS Rating: Critical/Symantec Urgency Rating 7.1/10)&lt;br /&gt;&lt;br /&gt;A remote code execution vulnerability affects Windows Explorer in the &amp;quot;search-ms&amp;quot; protocol handler. An attacker can exploit this issue by tricking a victim into viewing a Web page with a malicious &amp;quot;search-ms://&amp;quot; URI. A successful exploit will result in the execution of arbitrary attacker-supplied code in the context of the currently logged-in user.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;hr /&gt;&lt;p&gt;&lt;br /&gt;More information on these and the other vulnerabilities being addressed this month is available at Symantec&#039;s free &lt;a href=&#034;http://www.securityfocus.com/&#034; target=&#034;_blank&#034;&gt;SecurityFocus&lt;/a&gt; portal and to our customers through the DeepSight Threat Management System.&lt;/p&gt;</content:encoded>
				<dc:creator>Robert Keith</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&amp;thread.id=179</guid>
				<dc:date>2008-12-09T21:44:25+00:00</dc:date>
				<category>Vulnerabilities &amp; Exploits</category>
			</item>
		<item>
				<title>DNS Pharming Attacks Using Rogue DHCP</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=emerging&amp;thread.id=118</link>
				<description>Following Dan Kaminsky’s research on DNS insecurities, we saw attackers racing with their DNS servers to hijack network connections. It was only a matter of time before the bad guys decided that racing against DNS was not enough.</description>
				<content:encoded>&lt;p&gt;Following Dan Kaminsky&amp;rsquo;s research on DNS insecurities, we saw attackers racing with their DNS servers to hijack network connections. It was only a matter of time before the bad guys decided that racing against DNS was not enough.&lt;br /&gt;&lt;br /&gt;DHCP is a widely used network protocol that has been around for a while&amp;mdash;it&amp;rsquo;s used to automatically assign IP addresses on a local network. When you connect your laptop on the wireless router at your home or to your office network, it is most likely that a DHCP server assigns an IP address to your machine and will provide all of the important parameters such as a gateway IP and DNS servers. The DHCP protocol is simple, transparent, and efficient for end users, but it is also non-secure. There&amp;rsquo;s nothing new and sensational in that statement, because it&amp;rsquo;s something well known and is really just a lack of authentication. Wikipedia has a &lt;a href=&#034;http://en.wikipedia.org/wiki/Dhcp&#034; target=&#034;_blank&#034;&gt;pretty good description&lt;/a&gt; of common DHCP attacks.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;blockquote&gt;&amp;ldquo;Having been standardized before network security became a significant issue, the basic DHCP protocol includes no security features, and is potentially vulnerable to two types of attacks&amp;hellip; (1) Unauthorized DHCP Servers&amp;hellip; (2) Unauthorized DHCP Clients&amp;hellip;&amp;rdquo;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The &amp;ldquo;Unauthorized DHCP Servers&amp;rdquo; attack is the main topic of this blog, and the real (bad) news is that today we found malicious code in the wild that actively uses this attack, with the aim of hijacking the DNS configurations of other machines on the same local network. The malicious code is named &lt;a href=&#034;http://www.symantec.com/security_response/writeup.jsp?docid=2008-120318-5914-99&amp;amp;tabid=2&#034; target=&#034;_blank&#034;&gt;Trojan.Flush.M&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The idea is simple and evil at the same time: a Trojan installed on an infected machine runs a rogue DHCP server on the local network and serves bogus DHCP packets to other machines when they request a new IP configuration. If the Trojan is fast enough in sending out these DHCP packets, with some luck it can modify the network configuration of other computers. The basic principle of this attack is also described in &lt;a href=&#034;http://en.wikipedia.org/wiki/Rogue_DHCP&#034; target=&#034;_blank&#034;&gt;this Wikipedia article&lt;/a&gt;. &lt;br /&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;a href=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ef_dhcp1_lrg.jpg&#034; target=&#034;_blank&#034;&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ef_dhcp1.jpg&#034; border=&#034;0&#034; width=&#034;432&#034; height=&#034;163&#034; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The above network capture shows in detail what&amp;rsquo;s happening on a network with only a single machine (address 192.168.91.129) infected with Trojan.Flush.M. When a second, clean, machine (address 192.168.91.132) is renewing its IP address (e.g., ipconfig /release and ipconfig /renew on a Windows system) it sends a DHCP RELEASE packet and then tries to discover the DHCP server to get the new IP configuration. The configuration requested will have all the vital information that any device (PC, Mac, Smartphone, etc.) needs to access Internet, including the address of DNS servers.&lt;br /&gt;&lt;br /&gt;On a clean network we should only see one DHCP OFFER packet sent from the legitimate DHCP Server (192.168.91.254) to the clean machine. This packet is showed in the above capture at entry number 7. However, as shown in the capture, there&amp;rsquo;s another DHCP OFFER packet (at number 3) that has been sent by the infected machine only a moment earlier. The following diagram provides a clearer picture of what&amp;rsquo;s happening on this network:&lt;br /&gt;&lt;br /&gt;&lt;a href=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ef_dhcp2_lrg.jpg&#034; target=&#034;_blank&#034;&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ef_dhcp2.jpg&#034; border=&#034;0&#034; width=&#034;432&#034; height=&#034;324&#034; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The packet sent by the infected machine arrives first; therefore, it wins the race against the real DHCP server and the clean machine ends up getting the following IP configuration:&lt;br /&gt;&lt;br /&gt;&lt;a href=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ef_dhcp3_lrg.jpg&#034; target=&#034;_blank&#034;&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ef_dhcp3.jpg&#034; border=&#034;0&#034; width=&#034;432&#034; height=&#034;151&#034; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Clearly, the IP configuration of the clean machine 192.168.91.132 (which is still clean and is not infected by any kind of threat) has been assigned remotely by the infected machine and now includes some well-known rogue DNS servers: 85.255.112.36 and 85.255.112.41.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Performing an Internet search for these DNS servers leads only to bad comments and results, mostly related to a known family of DNS &amp;ldquo;changer Trojans,&amp;rdquo; which include Zlob and the recent Mac OS X threat &lt;a href=&#034;http://www.symantec.com/security_response/writeup.jsp?docid=2007-110101-2320-99&amp;amp;tabid=2&#034; target=&#034;_blank&#034;&gt;OSX.RSPlug.A&lt;/a&gt;. Once the DNS servers are modified, the attacker can redirect a machine to any malicious or phishing website (for example, you type &amp;ldquo;&lt;a href=&#034;http://www.google.xn--com-9o0a/&#034; target=&#034;_blank&#034;&gt;www.symantec.com&amp;rdquo;&lt;/a&gt; and your computer brings you to the &amp;ldquo;6.6.6.6&amp;rdquo; host).&lt;br /&gt;&lt;br /&gt;Some interesting facts of this curious DNS pharming attack include:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; A single infected machine with this Trojan can virtually compromise the DNS configuration of all other machines in the same network without infecting them.&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; It is difficult for the clean machine to identify if DNS servers in use are legitimate or not (the DHCP server shown in the example is still valid and the machine is not infected).&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; There&amp;rsquo;s no registry setting or configuration file that is modified on the machine&amp;mdash;the attack relies on network protocols.&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; These malicious DHCP packets could affect any device connected to the compromised network, so even a smartphone or Mac could accept the bogus configuration and start using rogue DNS servers.&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Since this is a race between the legit DHCP Server and an infected machine running a rogue DHCP Server, it all depends on luck and speed. We noticed that the attack is not always successful; sometimes the DHCP Server packet arrives first and so everything goes fine.&lt;br /&gt;&lt;br /&gt;To detect this attack, administrators should scan their traffic for bogus DHCP offer packets coming from a machine that is not the DHCP server. As final note, the attack has been reported in the wild and as suggested by a friend at &lt;a href=&#034;http://isc.sans.org/diary.html?storyid=5434&#034; target=&#034;_blank&#034;&gt;ISC SANS&lt;/a&gt;, network administrators should monitor and/or block traffic on: 85.255.112.0 &amp;ndash; 85.255.127.255.&lt;br /&gt;&lt;br /&gt;Thanks to my colleague Marian Borucki for help during the investigation of this threat.&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by SR Blog Moderator on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 12-04-2008&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 05:49 PM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>Elia Florio</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=emerging&amp;thread.id=118</guid>
				<dc:date>2008-12-05T01:25:16+00:00</dc:date>
				<category>Emerging</category>
			</item>
		<item>
				<title>AutoPlay Worms</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;thread.id=222</link>
				<description>Banning the use of removable drives may sound like a strict IT policy. But when faced with a worm introduced to your network by such devices, it is the sensible thing to do. Recently, the US Department of Defense has done just that in order to protect their networks from such threats.</description>
				<content:encoded>&lt;p&gt;Banning the use of removable drives may sound like a strict IT policy. But when faced with a worm introduced to your network by such devices, it is the sensible thing to do. Recently, the &lt;a href=&#034;http://blog.wired.com/defense/2008/11/army-bans-usb-d.html&#034; target=&#034;_blank&#034;&gt;US Department of Defense has done just that&lt;/a&gt; in order to protect their networks from such threats.&lt;br /&gt;&lt;br /&gt;As the use of removable drives has increased, they have become a successful vehicle to enter a network and compromise computers. The ease of infection is facilitated by a feature within Windows called AutoPlay. Meant as a feature of convenience, AutoPlay allows programs to automatically launch when CDs, DVDs, removable drives, or any other form of storage is inserted into a computer. However, this convenience comes at a serious security cost, as described in the following video:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div&gt;&lt;object classid=&#034;clsid:d27cdb6e-ae6d-11cf-96b8-444553540000&#034; codebase=&#034;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0&#034; width=&#034;480&#034; height=&#034;385&#034;&gt;&lt;param name=&#034;width&#034; value=&#034;480&#034; /&gt;&lt;param name=&#034;height&#034; value=&#034;385&#034; /&gt;&lt;param name=&#034;allowfullscreen&#034; value=&#034;true&#034; /&gt;&lt;param name=&#034;allowscriptaccess&#034; value=&#034;always&#034; /&gt;&lt;param name=&#034;src&#034; value=&#034;http://www.youtube.com/v/xgVecDefOMg&amp;amp;hl=en&amp;amp;fs=1&amp;amp;ap=%2526fmt%3D18&#034; /&gt;&lt;embed type=&#034;application/x-shockwave-flash&#034; width=&#034;480&#034; height=&#034;385&#034; allowfullscreen=&#034;true&#034; allowscriptaccess=&#034;always&#034; src=&#034;http://www.youtube.com/v/xgVecDefOMg&amp;amp;hl=en&amp;amp;fs=1&amp;amp;ap=%2526fmt%3D18&#034;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;So how do you protect yourself from such rapidly spreading threats? Banning the use of removable media does reduce the risk. On many computers you can also disable the USB ports from within the computer&amp;rsquo;s BIOS, rendering the ports inert. At the very least, Symantec recommends disabling AutoPlay.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&amp;bull; If you are running Windows XP, you can download and install a Microsoft &amp;ldquo;Powertoy&amp;rdquo; called &lt;a href=&#034;http://www.microsoft.com/windowsxp/downloads/powertoys/xppowertoys.mspx&#034; target=&#034;_blank&#034;&gt;TweakUI&lt;/a&gt;. There are a number of options within TweakUI for customizing AutoPlay under &lt;strong&gt;My Computer &amp;gt; AutoPlay&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;bull; If you are running Windows Vista, there is now a &lt;a href=&#034;http://windowshelp.microsoft.com/Windows/en-us/help/7e1fe788-0747-4e00-895b-c3461b1ddd971033.mspx&#034; target=&#034;_blank&#034;&gt;Control Panel applet&lt;/a&gt; dedicated to AutoPlay customization. To reach it, open the Control Panel and then go to &lt;strong&gt;Hardware and Sound &amp;gt; AutoPlay&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;bull; If you are managing a network of computers, you can use the &lt;a href=&#034;http://technet.microsoft.com/en-us/windowsserver/grouppolicy/default.aspx&#034; target=&#034;_blank&#034;&gt;Group Policy editor&lt;/a&gt; to create Group Policy Objects to assign to your clients. In Windows 2000/XP/2003&amp;rsquo;s Group Policy editor, AutoPlay options are under &lt;strong&gt;Computer Configuration &amp;gt; Administrative Templates &amp;gt; System &amp;gt; Turn off AutoPlay&lt;/strong&gt;. For Windows Vista/2008, go to &lt;strong&gt;Computer Configuration &amp;gt; Administrative Templates &amp;gt; Windows Components &amp;gt; AutoPlay Policies&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;bull; Administrators using Symantec Endpoint Protection Manager have the option to disable programs from running from removable drives entirely. In the management console, go to &lt;strong&gt;Policies &amp;gt; Application and Device Control &amp;gt; Add an Application and Device Control Policy &amp;gt; Application Control&lt;/strong&gt;, select &lt;strong&gt;Block Programs from running from removable devices&lt;/strong&gt; and then push the changes out to your clients. Alternatively, you can prevent autorun.inf files from running entirely by following the instructions in &lt;a href=&#034;http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008050910464348&#034; target=&#034;_blank&#034;&gt;this support document&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;bull; Norton users- no need to do anything. By default, all Norton products that contain antivirus will scan removable drives when they are plugged into the computer.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;bull; Sometimes AutoPlay doesn&amp;rsquo;t behave as expected after making changes. Microsoft has a knowledge base article that covers these situations and &lt;a href=&#034;http://support.microsoft.com/kb/953252&#034; target=&#034;_blank&#034;&gt;how to get AutoPlay working as you&amp;rsquo;d like it to&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;bull; Finally, &lt;a href=&#034;http://www.derkeiler.com/Mailing-Lists/securityfocus/security-basics/2007-07/msg00201.html&#034; target=&#034;_blank&#034;&gt;disable AutoPlay on network drives&lt;/a&gt; as well. While these worms are often introduced to the network via a removable device, many copy themselves to all drive letters on a compromised computer, regardless of the device type. When a compromised network drive is accessed, AutoPlay will launch the malicious code.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Completing any of these tasks should significantly reduce the risk posed by removable drives and help prevent you or your users from being an unwitting agent for spreading malicious code.&lt;/p&gt;&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by Trevor Mack on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 12-03-2008&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 01:11 PM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>Ben Nahorney</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;thread.id=222</guid>
				<dc:date>2008-12-03T17:02:51+00:00</dc:date>
				<category>Malicious Code</category>
			</item>
		<item>
				<title>Spammers Attempting to Cash in on Mumbai Terror</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=128</link>
				<description>India recently suffered a shocking terrorist attack, with hostage situations in Mumbai involving Indian nationals as well as tourists and travelers from all over the world. Updates on the terrorists’ activity are still being followed closely. Sadly, spammers would never want to miss the chance</description>
				<content:encoded>&lt;p&gt;India recently suffered a shocking terrorist attack, with hostage situations in Mumbai involving Indian nationals as well as tourists and travelers from all over the world. Updates on the terrorists&amp;rsquo; activity are still being followed closely. Sadly, spammers would never want to miss the chance to capitalize on the fast-spreading news of this tragic incident, using the headlines for their fraudulent emails with product advertisements or malicious links/attachments. Symantec has come across spam messages showing news headlines regarding the Mumbai terror, but the content inside is completely unrelated and is advertising pills.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/mk_mbai1.jpg&#034; border=&#034;0&#034; /&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;In the past, we have seen similar methods being used, where topical news headlines are used to lure recipients into opening unsolicited emails. Users are advised not to click on links found in such spam emails. Be wary of emails that have been delivered to you from an unknown sender or source, or if the email is unexpected and/or out of the ordinary, even if it appears to have been sent to you from a known contact. If you are looking for updates on recent news, please search for them on trusted news websites.&lt;/p&gt;</content:encoded>
				<dc:creator>Mayur Kulkarni</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=128</guid>
				<dc:date>2008-12-02T17:20:03+00:00</dc:date>
				<category>Spam</category>
			</item>
		<item>
				<title>Casino Spam Rolling Higher</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=127</link>
				<description>In recent weeks, Symantec has observed an increase in messages promoting online casinos, typically offering a cash bonus or VIP treatment. Leisure spam (defined as e-mail attacks offering or advertising prizes, awards, or discounted leisure activities) has accounted for up to 10% of spam globally during early November. </description>
				<content:encoded>&lt;p&gt;In recent weeks, Symantec has observed an increase in messages promoting online casinos, typically offering a cash bonus or VIP treatment. Leisure spam (defined as email attacks offering or advertising prizes, awards, or discounted leisure activities) has accounted for up to 10% of spam globally during early November.&amp;nbsp; &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ag_casino1.jpg&#034; border=&#034;0&#034; width=&#034;363&#034; height=&#034;219&#034; /&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;As we reported in the March 2007 State of Spam report, these attacks are often translated into many different European languages in order to maximize the reach of the attack. The URLs are quickly changed from message to message, with a simple directory change for each European language&amp;ndash;a French example is shown below. Spammers change the URLs frequently in order to try and stay ahead of URL-based anti-spam filters. Symantec uses more than 20 different filtering technologies in order to ensure comprehensive blocking of spam attacks no matter what techniques spammers employ.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ag_casino2.jpg&#034; border=&#034;0&#034; width=&#034;422&#034; height=&#034;227&#034; /&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Despite the fact that online gambling in the U.S. has many legal restrictions, most notably the Unlawful Internet Gambling Enforcement Act of 2006, which made transactions from banks or similar institutions to online gambling sites illegal, this hasn&amp;rsquo;t stopped spammers from targeting Americans, because clearly the potential size of the market is too large to ignore.&lt;br /&gt;&lt;br /&gt;Free webhosting URL redirects have been notably used in the spam attacks targeting the U.S. market, presumably not only in an effort to evade spam filters, but also to make it more difficult to track down the hosts of the ultimate destination website.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src=&#034;https://www-secure.symantec.com/content/en/us/enterprise/images/security_response/blogs/ag_casino3.jpg&#034; border=&#034;0&#034; /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In both examples shown, the objective of the email is to get the end user to download software running the various games. The software may attempt to steal sensitive information such as login credentials. But don&amp;rsquo;t be tempted by the offer of seemingly free money. In addition to the fact that a deposit is required in order to play, the terms and conditions state that 25 times the deposit and bonus must be wagered before cashing out, and it&amp;rsquo;s likely the house will have long won by then.&lt;/p&gt;</content:encoded>
				<dc:creator>Amanda Grady</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=127</guid>
				<dc:date>2008-11-28T18:17:57+00:00</dc:date>
				<category>Spam</category>
			</item>
		<item>
				<title>Symantec Report on the Underground Economy – Malicious Tools</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=istr&amp;thread.id=12</link>
				<description>The newly released Symantec Report on the Underground Economy discusses a number of topics, including the supply and demand of goods and services that were advertised for sale in the underground economy. This information was gathered by monitoring various IRC channels devoted to the commerce of these good and services.</description>
				<content:encoded>&lt;p&gt;The newly released Symantec &lt;em&gt;&lt;a href=&#034;http://www.symantec.com/business/theme.jsp?themeid=threatreport&#034; target=&#034;_blank&#034;&gt;Report on the Underground Economy&lt;/a&gt;&lt;/em&gt; discusses a number of topics, including the supply and demand of goods and services that were advertised for sale in the underground economy. This information was gathered by monitoring various IRC channels devoted to the commerce of these good and services. In particular, I&amp;rsquo;d like to highlight some of the things we observed in analyzing the trade in malicious tools.&lt;br /&gt;&lt;br /&gt;One of the things we observed is that the underground economy is self-sufficient. What this means is that the tools necessary to produce goods and services are also available for sale in the underground economy. This indicates that the market has matured enough that productivity gains can occur through the division of labor; i.e., the economy makes it viable for individuals to increasingly specialize in the tasks they excel at. This is where malicious tools come into play. &lt;br /&gt;&lt;br /&gt;Malicious tools of many different varieties are offered for sale in the underground. This includes exploits, vulnerability scanners, botnets, autorooters, spam/phishing kits, and tools for obfuscating malicious code. These tools play a part in generating many of the other goods and services marketed in the underground economy, such as credit card numbers, personal information, shells, banking credentials, etc. Therefore, the demand for these goods and services creates an opportunity for individuals with the skills required to develop malicious tools, and this helps to foster increasing specialization.&lt;br /&gt;&lt;br /&gt;While the market for malicious tools is relatively small in comparison other goods and services such as stolen credit card numbers, the market appears to be productive enough to support the demand for these goods and services. One of our findings is that tools for discovering and exploiting Web application vulnerabilities were popular. This is because compromised websites can generate many different types of goods and services such as personal information, email addresses, shells, spam mailers, credit card numbers, etc. &lt;br /&gt;&lt;br /&gt;Here are a few examples (all prices in USD):&lt;/p&gt;&lt;blockquote&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; A scanner for remote file include vulnerabilities sold for an average price of $26, and ranged from $5 to $100.&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; A scanner for cross-site scripting vulnerabilities was advertised for an average price of $20, and prices ranged from $10 to $30.&lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exploit links to websites that are affected by remote file include vulnerabilities were sold in bulk&amp;mdash;100 links could be obtained for an average price of $34 and 200 links could be obtained for an average price of $70. &lt;br /&gt;&amp;bull;&amp;nbsp;&amp;nbsp;&amp;nbsp; SQL injection tools were sold for an average price of $63, and ranged from $15 through $150.&lt;br /&gt;&lt;/blockquote&gt;The trade in attack tools and exploits for Web-based vulnerabilities is one more example of how attackers are increasingly motivated by profiting from their malicious activities. Our report helps to show how the underground economy is maturing and becoming a viable source of alternative income for hackers, exploit developers, and authors of malicious code.&lt;br /&gt;&lt;br /&gt;I should also note there is one small correction to the report based on recent events. In the report, we discuss the news that development of the Neosploit toolkit had ceased due to competitive from cheaper, less advanced toolkits. It appears that this no longer the case. A new version&amp;mdash;Neosploit 3.1&amp;mdash;has been spotted in the wild, sporting new exploits and features. Like legitimate software vendors, the developers of Neosploit are also concerned about the effect of piracy on their bottom line. To counter piracy, they have included new anti-piracy measures into this version. It is not known whether the news of its demise was merely a red herring or whether the developers decided to start developing a new version that incorporated features that could recoup some of the losses experienced from piracy or the prevalence of cheaper toolkits.&lt;br /&gt;&lt;br /&gt;More information about malicious toolkits and other trends in the underground economy can be found in the Symantec &lt;em&gt;&lt;a href=&#034;http://www.symantec.com/business/theme.jsp?themeid=threatreport&#034; target=&#034;_blank&#034;&gt;Report on the Underground Economy&lt;/a&gt;&lt;/em&gt;.&lt;div class=&#039;message-edit-history&#039;&gt;&lt;span class=&#039;edit-author&#039;&gt;Message Edited by SR Blog Moderator on &lt;/span&gt;&lt;span class=&#039;local-date&#039;&gt; 11-27-2008&lt;/span&gt;&lt;span class=&#039;local-time&#039;&gt; 05:19 AM&lt;/span&gt;&lt;/div&gt;</content:encoded>
				<dc:creator>David McKinney</dc:creator>
				<guid>https://forums.symantec.com/syment/blog/article?blog.id=istr&amp;thread.id=12</guid>
				<dc:date>2008-11-27T13:16:30+00:00</dc:date>
				<category>ISTR</category>
			</item>
		<item>
				<title>Can’t Read English? Ecco lo Spam Italiano!</title>
				<link>https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=126</link>
				<description>You may have come across multilingual translations of your favorite book or a popular movie. It’s a surefire way to extend one’s work to a wider audience. The desire for an extra buck has driven spammers to adapt to similar tactics for their campaigns.
</description>
				<content:encoded>&lt;p&gt;You may have come across multilingual translations of your favorite book or a popular movie. It&amp;rsquo;s a surefire way to extend one&amp;rsquo;s work to a wider audience. The desire for an extra buck has driven spammers to adapt to similar tactics for their campaigns. Recent messages observed offered a job that included relaying payments betwee