This Month in the Threat Webscape – June 2010
Jul 30
Month of June
Security conferences are a great way to learn about what's on the cutting-edge, germinate and cross-pollinate ideas, and establish real-world relationships within the tight-knit community of white hat hackers. This past month, we presented at both EUSecWest in Amsterdam and SyScan in Singapore.
If you missed us there, not to worry, in just a few weeks we are presenting at Black Hat and DEF CON, both in Las Vegas. Come say hi to us!
Major hits
Every major event and news item is followed very closely by exploiters looking to achieve some profit. It may be the death of a celebrity or a major event such as FIFA World Cup; the bad guys are always there. With the World Cup still ongoing, we continue to see targeted attacks of known zero-day pdf vulnerabilities, the infamous 419 scam letters, phishing attempts, and of course the more popular than ever Blackhat SEO scareware campaigns.
More than 100k popular Web sites were compromised last month with a mass injection targeting IIS using ASP.net platform. The attack came from Chinese IP addresses and the injected iFrame led to a Chinese-hosted domain http://www.ro[REMOVED]nt.us serving juicy Mal/Behav-290 malware. The majority of Web sites were cleaned up in matter of hours.
Apple, Inc. was accused of a data breach resulting in the loss of 100k email addresses and ICC-ID numbers. A few hours later the finger was pointed to the real miscreant. An AT&T designed and secured Web application allowed the Goatse hacker group to match ICC-IDs with email addresses used by iPad users to access their iTunes accounts. Observations? If you are a developer, carefully design and review for security and secure coding practices. If you are a hacker, do not irritate a giant without very good armor.
Web 2 dot uh oh
It seems like everyone on the Web today is trying to figure out how to leverage social networking tools (Facebook, Twitter) for "viral" marketing. Even the bad guys. This month, the baddies used a clever combination of social and technical tricks to increase their own reputation and get over 15,000 people to 'like' them on Facebook. The social-engineering trick started off with a lure (as they all do) to see the "best passport application rejection in history". Behind the scenes, an invisible Facebook 'like' button follows your mouse cursor, guaranteeing that you'll click on the Facebook 'like' button regardless of where you click on the malicious web site. The consequence of clicking the hidden 'like' button is that a link to this web site is posted on your Facebook profile for all your friends to see – and if they too click on it, the cycle repeats itself.
In a separate Facebook scam involving the lure 'Teacher nearly killed this boy', a rogue Facebook app requested permission to access the viewer's profile information, and permission to post content on the viewer's Facebook wall. Users who don't pay attention and simply click through to get to the video risk the safety of their Facebook friends should they click on something malicious that could be posted by the rogue app from the viewer's wall.
A persistent cross-site scripting (XSS) vulnerability was discovered on Twitter. You may recall a similar incident some time ago, but whereas the previous case involved the application URL, this time around it involves the application name.
A study by ISACA, an international organization that researches IT governance and control just published a research paper that listed viruses and malware, brand hijacking, and lack of control over corporate content as some of the top risks faced by companies using Web 2.0 social media tools.
Is that any surprise?
Browser & friends
Adobe made a big splash in the security market this month. New zero-day vulnerability (CVE-2010-1297) was discovered early in the month. A few days later PDF samples embedded with a SWF file exploiting the vulnerability were found in the wild. The samples spread as an email attachment. And then html pages with exploited SWF files arrived. The more convenient method has been used to attack customers. Details about the zero-day vulnerability can be found here.
In the middle of the month Adobe released a security update for Flash Player that fixes 31 vulnerabilities, including the zero-day vulnerability. At the end of the month Adobe released a security update for Adobe Reader and Acrobat to fix the zero-day vulnerability. You should update your Flash Player and Adobe Reader as soon as possible.
Mozilla released 8 security advisories this month, several critical vulnerabilities were fixed in the recent Firefox update. A new feature called Crash Protection, also known as OOPP(Out Of Process Plug-ins) has been added to Firefox 3.6.4. With this feature, the plug-in process is isolated from the browser process. This makes the browser more stable because a plug-in crash should not affect the browser.
Apple has patched 48 vulnerabilities for Safari and WebKit.
Microsoft
The two big events this month were Microsoft's busy Patch Tuesday, addressing 34 vulnerabilities, and a zero-day POC released by a Google security researcher.
Among the many fixes this month, Microsoft fixed the SharePoint XSS bug from April and a publicly disclosed data leakage vulnerability in Internet Explorer. Other vulnerabilities affect Windows, Office, Internet Explorer, and the IIS Web server.
Tavis Ormandy, a security researcher at Google, released a zero-day exploit in the Windows Help and Support Center that allows remote code execution. Tavis posted exploitation details to the Full Disclosure list just a few days after notifying Microsoft of the vulnerability. Microsoft released and discussed an advisory on the issue, including a workaround to disable the HCP protocol being exploited until a patch is released.
Hello ThreatSeeker. You've got mail!
Delivering Web sites as an attachment via email is a bit like snail-mailing someone a newspaper clipping when you can just send them the URL. As silly and inefficient as that may be, if the method delivers, then it's well worth it. And that's exactly what the malicious hackers did: deliver malicious Web sites as an attachment via email. In this incident, victims were told their computers were infected and that they needed to open the attachment "Virus Scan.html". This resulted in the computer downloading a malicious PDF and Java .jar file.
The bad guys also capitalized on the official launch of the much anticipated iPhone 4 by delivering scams via email and also posting them on Facebook. The lure enticed users with the chance of receiving a free iPhone 4 (yes, some offers on the Internet are just too good to be true. Always proceed with caution!)
Other assorted unhealthy snacks served up via email this month included the following themes:
- Reset your Twitter password - malicious link to fake AV
- FIFA World Cup South Africa… bad news - malware attachment in a "news.html" file
- Account verification (yeah, this one's subject line is boring in comparison) – malicious link to malware and exploits
- Notice of Underreported Income (masquerading as from the IRS) – malicious link to fake site and malware
Security Trends
Joanna Rutkowska, who is known for her work on virtualization security and low-level rootkits, is building a project named Qubes, which is an open-source OS meant to provide isolation of the OS components for better security.
At the Syscan'10 Singapore conference, security researchers from TEHTRI-Security published twelve zero-day flaws targeting five of the most common Web malware exploitation kits, such as Neon, Eleonore, Liberty, Lucky, and the Yes exploitation kits.
It was observed in a specific malicious spam campaign, that the malicious HTML file attachment used the same obfuscation algorithm as a known mass injection attack on the web.
This month's contributors:
- Lei Li
- Ulysses Wang
- Erik Buchanan
- Ivan Sabo
- Jay Liew







I’d be inclined to settle with you one this subject. Which is not something I usually do! I enjoy reading a post that will make people think. Also, thanks for allowing me to comment!
I’ve really found out a lot studying this page. Plainly pretty great product right here. Content material similar to this assist make this weblog internet site really worth coming back again to for even a lot more details
I found your entry interesting do I’ve added a Trackback to it on my weblog
……
Rakeback is an Great Way to get very much more Money only for Playing Poker.
i�ve ideas relating to this i�ll distribute the situation
I liked seeing this i�ve been wondering about this for a while.
Don�t consider every nice comment as spam its not � but here my two cents. It�s all about fitness mates! Or what do you think? I like this info and it has given me some sort of commitment to succeed for some reason so thank you. Moreover I�m definitely thinking about blogging these figures in my own blog!
solid law firm web marketing services
Yeah! Thank you! I constantly needed to write on my site something like that. Can I implement a portion of your post to my blog?
Great website, where did you obtain the theme?
I definitely appreciate this post. We need far more people today like you bringing value towards the community. Can I put this post on my blog? I’d give you credit and link back of course.
Yeah! Thank you! I constantly needed to write on my site something like that. Can I implement a portion of your post to my blog?
I really find this a eyeopener. Never looked at it in this way. If you are going to write some more articles about this subject, I definitely will be back in the near future! Btw your layout is truly briliant. I will be using something similar for my own website if it’s ok with you.
Rakeback is an Great Way to get lots more Money but for Playing Poker.
Amazing website & writing skills. You my friend have TALENT!
There is evidently a bundle to know about this. I feel you made various good points in features also.
Its consistently great to learn guidelines such as you part targeted blog posting. As I only began posting remarks targeted blog and dealing with trouble as in lots of rejections. I think the suggestion would be useful for me. i’ll let you know if its function for me too.
I also wish to signal to your RSS feeds. Thank you as soon as once again and maintain up the excellent function!
I’ve bookmarked this, you should receive a pingback shortly:) the free SEO directory
I foud your blog while googleing heart attack, but your post looks very interesting for me too.
yesss very thanks man i love this site
Superb blog post, I accept book apparent this internet website so alluringly I’ll see abundant added on this accountable in the accountable future!
Interesting layout on your blog. I really enjoyed reading it and also I will be back to read more in the future.
I have to be the alone accurate being who never heard of this diet plan above-mentioned to a ages ago. I still accept the actual best access to lose weight is just to absolute calories and clutter aliment and sweets and not chase any specific diet plan. Just eat abundant less, just a little of everything. Atkins diet sounds acute to me accurately accustomed that it causes poor animation and being like that. No acknowledge you, but for those who like it that’s accomplished but it’s just not? for me.
Dressing well can help in looking taller. Try wearing solid, dark colors. Pinstripes also produce a slimming effect while making you seem taller. Make sure to wear clothing that fits your frame well and is comfortable as well. This will help with your posture, which can also help you look taller if you sit up straight and keep your head held high. You can read more on these tips here
Hi. I just noticed that your site looks like it has a few code errors at the very top of your website’s page. I’m not sure if everybody is getting this same problem when browsing your site? I am employing a totally different browser than most people, referred to as Opera, so that is what might be causing it? I just wanted to make sure you know. Thanks for posting some great postings and I’ll try to return back with a completely different browser to check things out!
Your place is valueble for me. Thanks!…
Was actually doing some research and came across this site. I must say that this info is on point! Keep up the good info. Will be following your posts
I was doing some research and came across this blog site. I must admit that this information is great! Keep up the good info. Will be reading your sites
asojqimpilbdnnlapbdmgcrrcdspe
wow this is cool!
My friend suggest me to search your website This Month in the Threat Webscape – June 2010 | HackerSafe Security Related Blog for all, i think, it’s very best! I will absorb it my favorites. Usually, I think you can put your own wonderful articles to digg.com, it wil improve your blogs rate.
Hi I like your comment and it is so good and I am gonna save it. I Have to say the Indepth analysis this article has is greatly remarkable.Who goes that extra mile these days? Bravo. Just one more suggestion you shouldinstall a Translator for your Global Readers !!!
I was been looking the Internet for this info and i wanted to thank u for this post. Also, just off topic, where can i get a version of this theme? – 10x
We are a group of volunteers and starting a new initiative in a community. Your blog provided us valuable information to work on. You have done a marvellous job!
i was starting to presume i would probably be the only student which cared about this, at the least currently i discover i’m not extreme
i am going to make it a point to go and visit a couple of additional blogposts just after i get some caffeine in me, adios for now
Howdy I really considered the post , good information, Can we fix the RSS feeder. . .? I can’t get it from the browser. Anyway thanks,.
http://www.gpstrackerforvehicle.com – GPS Vehicle Tracker
You completed some fine points there. I did a search on the subject and found the majority of persons will go along with with your blog.
You got a really useful blog I have been here reading for about an hour. I am a newbie and your success is very much an inspiration for me.
http://www.senseofashion.com/blog/258/alie-is-great
Hey, Would it be possible to utilize this brilliant post on my site? I would of course backlink back to you. Let me find out what you decide to perform.
I found your blog via Google while searching for the related topic, your blog came up. Thank you for the fantastic blog. Amazingg skills! Continue man, you rock!
My wife and i got very relieved John could carry out his inquiry with the precious recommendations he received through your blog. It’s not at all simplistic just to continually be offering guidance which some people have been selling. Therefore we do know we’ve got you to be grateful to for this. The specific illustrations you made, the easy blog menu, the relationships you will make it easier to promote – it’s mostly amazing, and it’s leading our son and us reckon that that topic is enjoyable, and that is particularly essential. Thank you for the whole thing!
I noticed your weblog on bing and browsed a few of your other blogposts. I just added you to my personal Google News Reader. Carry on the great work. Will enjoy reading more from you later on.
foremost! I think it’s worth to leave a piece of words here!
Apple now has Rhapsody as an app, which is a great start, but it is currently hampered by the inability to store locally on your iPod, and has a dismal 64kbps bit rate. If this changes, then it will somewhat negate this advantage for the Zune, but the 10 songs per month will still be a big plus in Zune Pass’ favor.
My brother suggested I might like this blog. He was totally right. This post truly made my day. You cann’t imagine just how much time I had spent for this Game info! Thanks!
My spouse and I absolutely love your blog and find the majority of your post’s to be what precisely I’m looking for. Do you offer guest writers to write content in your case? I wouldn’t mind writing a post or elaborating on some of the subjects you write concerning here. Again, awesome blog!
Although I consider myself great in this topic, I was able to learn few new things about cars from here. Good work.
This valuable specific internet online site usually really are travelling in the future to become sweet!