Saturday, November 10, 2007

Need mobile spyware? Look on eBay

InfoWorld 9/11/2007
Website: http://www.infoworld.com

San Francisco - Think your wife may be cheating on you? Wondering who your boss might be talking to? "Learn the truth. Spy today."

So reads an ad for "Bluetooth Spy Pro-Edition," one of nearly 200 mobile phone spyware products currently listed for sale on eBay.

The software, which costs as little as $3.99, can be used to view photographs, messages, and files on the phone, listen into phone conversations, and even make calls from the phone being spied upon.

Security experts are concerned because while these products aren't illegal, installing them without authorization to spy on someone else most definitely is.

And that's exactly what some of these products seem to be advertising. "You can now easily find out who your partner, business associates, friends have been in contact with," reads the Bluetooth Spy ad. "Whether you are suspicious of an affair or would just like information that will help progress your career, you can now do all of the following using your mobile phone, and the person you are targeting will not suspect a thing. Guaranteed!"

Another spellcheck-free ad claims that "You will now be able to establish who your freinds associates and husband/wife have been conversating with, you can read messages, even download them to your own phone or laptop, view their information and pictures."

This type of mobile spy software has been available for several years now, sold by companies like Flexispy and Neo-Call. Typically, however, it is much more expensive, and these companies are generally careful to promote only their legal uses such as monitoring corporate equipment, said Mikko Hyppönen, CTO with F-Secure. But the software is often used for nefarious purposes, such as industrial espionage and spying, Hyppönen said.

According to him, eBay shouldn't be selling this software; it is simply too dangerous.

Another security expert said that this type of software may even be harmful to the buyer. "You're certainly at a higher risk with the software of there being additional functionality that is not advertised and potentially malicious," said Craig Schmugar, virus research manager at McAfee's AVERT labs. "In general, when you see the advertising claims made and the types of pages represented, you should approach them with some skepticism."

This software can be installed via a Bluetooth connection and typically runs on both Windows Mobile and Symbian operating systems, McAfee said.

eBay representatives could not immediately be reached for comment on this story.


Wednesday, November 7, 2007

Apple Patches QuickTime Holes, Microsoft Warns Of Macrovision Driver Flaw

InformationWeek 6/11/2007
Website: http://www.informationweek.com

Apple on Monday released QuickTime 7.3 for Mac OS X and Windows XP SP2 to patch seven vulnerabilities in its multimedia software.

All seven of the vulnerabilities have the potential to allow arbitrary code execution by an attacker if the user visited a site with certain maliciously crafted movie or image files, or a maliciously crafted Java applet.

Apple updated QuickTime to version 7.2 in July, when it fixed eight security problems with the software.

Microsoft meanwhile warned Monday that a flaw it the Macrovision secdrv.sys driver in Windows Server 2003 and Windows XP is actively being exploited. An attacker making use of the vulnerability potentially could gain elevated privileges to the affected system.

"This vulnerability does not affect Windows Vista," Microsoft said. "We are aware of limited attacks that try to use the reported vulnerability. Microsoft is actively monitoring this situation to keep customers informed and to provide customer guidance as necessary."

Macrovision, which provides Microsoft with digital rights management (DRM) technology, is offering a driver update to address the vulnerability.

Microsoft expressed concern that the vulnerability had been made public rather than first disclosed to the company in private.

"We continue to encourage responsible disclosure of vulnerabilities," Microsoft said. "We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed."

Microsoft said that it plans to address the issue as part of its regularly scheduled patch plan.

Microsoft to patch software driver vulnerability

InfoWorld 6/11/2007
Website: http://www.infoworld.com

San Francisco (IDGNS) - Microsoft has warned that a faulty driver used for copy protection could allow a hacker to gain high-level access to a PC.

The problem lies with a driver called secdrv.sys, which is part Macrovision's SafeDisc software included with Windows Server 2003 and Windows XP. The software, which can block unauthorized copying of some media, also ships with Windows Vista, but that OS is not affected.

Microsoft said it knows of "limited attacks" that try to use the vulnerability, in an attack known as an elevation of privilege. The vulnerability could allow a hacker with local access to a machine to elevate his access rights and gain administrator rights, for example, allowing him to install software.

Microsoft said it was concerned that the vulnerability had been disclosed before it had a chance to fix it, which puts people at greater risk. "We continue to encourage responsible disclosure of vulnerabilities," it said.

Macrovision has issued an update for the driver. Microsoft said it also plans to issue a fix as part of its monthly patch cycle.

Danish security vendor Secunia said the vulnerability was first reported as a zero-day about two weeks ago, meaning the problem was being exploited by hackers as it became known.The company rated the vulnerability as "less critical," it's second lowest risk ranking for a vulnerability.

Friday, November 2, 2007

Mac Users Targeted with Nasty Malware

News Factor Network 1/11/2007
Website: http://www.newsfactor.com

So much for Mac users avoiding bugs, worms, and other security nuisances. A Trojan targeting Macs is on the loose, and it's hanging out on porn sites, according to security researchers.

The incident was first reported by Intego, a Mac security software vendor. Sunbelt Software, the SANS Institute's Internet Storm Center (ISC), Sophos, and McAfee have confirmed the Trojan. Dubbed "OSX.RSPlug.a," the Trojan changes the Mac's Domain Name System (DNS) settings to redirect unsuspecting users to different sites.

"The whole Trojan is relatively simple and works almost exactly the same as its brother for Windows," said ISC analyst Bojan Zdrnja in a warning the center posted on Thursday. "The bad guys are taking Mac seriously now. This is a professional attempt at attacking Mac systems, and they could have been much more damaging."

Porn Opens the Door

The family of malware that is targeting Macs is called "Puper." It's been plaguing Windows users since 2005. One of the most notable cases of Puper attacks was exploits on infected MySpace pages.

In the Mac attack, people who are searching for porn on the Internet may find it. But they may also find a nasty payload when they encounter a popup window instructing them that QuickTime needs to install new software so they can view the videos. If the user tries to install the codec, a script then creates a scheduled task to change the Mac's DNS to point to a malicious server.

"In effect, instead of getting valid entries for Web sites like you would expect, you're now getting whatever this malicious site decides to point you to. That could be a phishing site, that could be more malicious files, you can no longer trust that the URL you expected to get will be what is delivered to you," Allysa Myers, part of the computer search research team at McAfee Avert Labs, wrote on the company's blog.

Mac Malware Short List

The OSX/RSPlug.a Trojan is on a very short list of malware that's been specifically designed to target Mac OS X, according to Graham Cluley, senior technology consultant for Sophos. The motive of this particular Trojan could be for the purposes of phishing, identity theft, or simply to drive traffic to alternative Web sites, he said.

The good news is the Trojan doesn't exploit a vulnerability in Leopard, Tiger, or any Apple code. This Trojan exploit depends on a user to take actions to open the door to the nasty payload.

"This is not a red alert, but it is a wake-up call to Mac users that they can be vulnerable to the same kind of social engineering tricks as their Windows cousins," Cluley said. "The truth is that there is very little Macintosh malware compared to Windows, but clearly criminal hacker gangs are no longer shy of targeting the platform."

Keeping It in Perspective

In February 2006, in the wake of the discovery of the first Mac OS X worm, Sophos released research that showed 79 percent of computer users believed Macs would be targeted more in the future. However, over half of those polled said they did not believe the problem would be as great as for Windows. Still, Sophos experts are urging Macintosh users to keep the threat in perspective.

Cluley said the latest version of Mac malware is making headlines because it is so rare. A Trojan like this for Windows would be unlikely to generate as many column inches because such Trojans are encountered every day. Nevertheless, he said, it obviously makes sense for Mac users to ensure that they are protected.

"People have been predicting that as soon as financially motivated malware came to the Mac neighborhood, its denizens could no longer be so smug about security issues," McAfee Avert Labs' Myers wrote. "This is a very simple piece of malware, and yet it works. Time will tell if this family will wreak as much havoc as it has on Windows."

Fortress Mac Is Gone

eWeek 1/11/2007
Website: http://www.eweek.com

Several pornography sites are loading a Trojan disguised as a video codec required to view content on Macs—the first Mac-targeted malware exploit to be spotted in the wild and validation of security researchers' long-maintained prediction that, sooner or later, the rationale for Mac security smugness would rub off.

"[Users infected by visiting questionable Web sites] began using Macs as most malware target the Windows operating system. Well, soon enough, it may not matter which OS you are using," said Symantec's Joji Hamada in a Nov. 1 posting.

Sunbelt Software and Intego, a maker of Mac security software, are warning that a mother lode of spam has been posted to many Mac forums in an attempt to trick users into visiting sites with rigged porn photos. The photos are from reputed porn videos. If Mac users click on the stills to view the videos, they're taken to a site that informs them that the QuickTime Player is unable to play the movie file. They're then instructed to click to download a new codec.

Sunbelt reports that the fake codec is a variant of Trojan.DNSChanger, malware that's been plaguing Windows users for some time. Symantec Security Response has confirmed the finding and has added detection for the threat as OSX.RSPlug.A.

Intego says that after the page loads, a disk image (.dmg) file downloads to users' Macs. If users have checked "Open 'Safe' Files After Downloading' in the General preferences of their Safari browser—or similar settings in other browsers—the disk image mounts. The .dmg file contains an installer package that then launches.

Otherwise, if users wish to install the codec, they double-click the .dmg file, then double-click the package file, which is named install.pkg.

If users continue with the installation, a Trojan program installs. Installation requires an administrator's password, which grants the Trojan full root privileges. No video codec is actually installed. If users return to the purported porn site, they just receive the download anew.

The Trojan uses a sophisticated method, via the scutil command, to change the Mac's DNS server. When the new, malicious DNS server is active, it hijacks some Web requests, leading users to phishing Web sites that are after account information for sites such as eBay, PayPal and some banks, or simply to pages displaying ads for other porn sites. "In the first case, users may think they are on legitimate sites and enter a user name and password, a credit card, or an account number, which will then be hijacked. In the latter case, it seems that this is being done solely to generate ad revenue," Intego said in its release.

Running Mac OS X 10.4, the GUI has no way to display the changed DNS server. Running Mac OS X 10.5, it can be seen in the Advanced Network preferences, Intego officials said. However, Trojan-installed DNS servers are dimmed and can't be removed manually. Intego said it's now testing previous versions of Mac OS X and that they're likely vulnerable as well, given that they all have the scutil command.

The malware also installs a root crontab that checks every minute to ensure that its DNS server is still active. Since changing a network location could change the DNS server, this added touch ensures that, in such a case, the malicious DNS server remains the active server, Intego officials said.

Heise Security's Juergen Schmidt told eWEEK that this malware is related to the security company's recent findings on holes in Leopard's firewall. If a user were to install the fake video codec, it could install a backdoor on a Leopard system that can let in remote attackers, even if the Leopard firewall has been configured to block all incoming connections, if there isn't a hardware firewall in front of the Leopard system.

Schmidt noted that this Trojan also provides different versions of itself, perhaps according to the country in which the user is located to provide country-specific spoofing. "Repeated downloads of the disk image show that there are several different versions," he said.

To see an eWEEK Labs' walk-through of Leopard, click here.

Tom Ptacek, founder of Matasano Security, told eWEEK that the threat to Macs is real, although it's not a huge one—just the same old scenario Windows users face every day.

It is an interesting story, however, given that it's the first OS X malware to be "weaponized." Unlike prior OS X malware, which was all about ego, this one's out to make money, Ptacek said—again, same old, same old in the world of Windows.

Unsurprisingly, there are more than a few I-told-you-sos ensuing in security circles. "For years, we've heard snorts of derision from Mac users about the poor security of PCs. Yet that supercilious attitude (as we know from our history books) is patently dangerous, because it creates a false sense of security. Now, Mac users will need to be a bit more careful out there ('cause when Joey wants his pr0n, he wants it now!). On the heels of the poorly-secured release of Leopard, we now find that there is no perfect protection against human stupidity social engineering, even for a Mac user," said Alex Eckelberry, Sunbelt president, in an Oct. 31 eWEEK.com's Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK's Security Watch blog.


Researchers dig for hidden links in spam

InfoWorld 1/11/2007
Website: http://www.infoworld.com

San Francisco (IDGNS) - Filtering spam messages is a thankless job for software. For every 100 spam e-mails, one message usually gets through, an irritating pitch with links to Web sites selling questionable drugs or sketchy Rolexes.

The links contained within spam are one indicator in determining whether it should be blocked. Often after a large spam run, the addresses of spammy Web sites will be added to blocklists that are used by antispam software to cull future messages with those links.

To get around it, spammers construct e-mails with links that can't be identified by filters but still are valid in the messages, said Christopher Fuhrman, a professor of software engineering in the Department of Software and IT Engineering at the University of Quebec.

Spammers do this by "munging" the HTML -- adding backslashes, taking out tags -- so that the message and its links are still readable by the rendering engines of browsers or e-mail clients but appear as a garble of nonsense to filters. The technique is also known as obfuscation.

It's a trial-and-error process because spammers don't read HTML Web standards. "Spammers just want to get the cash," Fuhrman said.

Tamper with the HTML too much, and the message won't render at all. Too little, and filters snare the message.

So spammers aim for a narrow gap: Most browsers and e-mail clients can render a certain amount of munged HTML, although the tolerances vary depending on the application.

Fuhrman theorizes that spammers test their messages using Microsoft's widely used Outlook program, which uses the same HTML rendering engine as its IE (Internet Explorer) browser.

So Fuhrman and one of his graduate students, Hicham El Alami, are writing a program to use that IE's rendering engine as a way to "parse" messages, or extract the links.

Services such as SpamCop already do this. SpamCop -- part of IronPort Systems, a subsidiary of Cisco -- has a Web-based service that uses algorithms to parse links out of spam messages submitted by users.

Those algorithms are hard to write, although SpamCop's is pretty good, Fuhrman said. Fuhrman and El Alami are interested in creating an alternate way to do that same parsing without needing to consistently tweak an algorithm to keep up with new tricks used by spammers.

It's hard to write a parser that will read links the same way IE's rendering engine does since Microsoft's source code is secret, Fuhrman said. So a better idea would be just to use that engine as part of a program to parse messages. A variety of tools exist to manipulate IE's rendering engine through APIs, Fuhrman said.

The links that IE's engine renders would be reported to a blocklist service. Fuhrman wrote a model version of his idea that works in Java, but El Alami is now working on one for .NET, Microsoft's application development framework.

"I want to ultimately get it as a Web-based engine so that users can paste spam, and when it comes out, it will reveal the links," Fuhrman said.