Wednesday, January 21, 2009

A New MSN Phishing ( Identity Theft ) Worm - ENG

[ A Rewrite of this post in english , due to the importance ]

 

A few days back , I received a nice gift via my Msn IM account, i got the following link :

http://myparties.piclooks.com/?<user> ( where <user> is the infected sender ). in that case i got it through MSN , so i dont tknow if any other IM is compromised.

when clicking on that link you would get the following web window -

SNAG-0044

That screen immediately raised my suspicion that there is something wrong here. an unknown site is asking for my MSN / Hotmail credentials in order to provide me a service which natively could be provided via a normal API... so i started checking.

Viewing the client side source code was very nice , cause it shows a very simple - almost child-like html code that is generated via simple tools.

An IP address (  64.34.154.82 ) was embedded in, which is not something that you would expect from a service, very unusual.

When disecting the URL to its basics and just going to piclooks.com , you would get the following output ( meaning , there is no actual homepage behind this application )

piclooks-com

The summary is very simple , this is most probably a phising site , and not a very sophisticated one , which its whole purpose is to steal the online identities of those who are naive enough to play along.

be careful of this hoax.

Labels: , , , , , , , ,

Thursday, September 27, 2007

Cisco.com XSS Vulnerability Found

A few days back , I have read about a Cross-Site-Scripting vulnerability in cisco's search engine. this vulnerability enables a hacker to use the cisco.com website for phishing purposes and for "man-in-the-browser" attacks.

With the code ( posted as a link ) following , one could send a user to cisco's website and bounce off to his own bogus machine. i did not check for any further enrichments of this exploit , but it seems strange that this kind of thing could come out on a website that is as secure as cisco.com. I really believe that there are Application Layer Firewalls defending cisco's website, and if there are any - are they misconfigured ?

I have reported this vulnerability to a friend of mine at cisco's security proffesional services team in EMEA , and i hope this will soon be fixed.

Here is the POC code :

http://cisco.com/pcgi-bin/search/search.pl?searchPhrase=%27+onmouseover%3D%22location.href%3D%28%27http%3A%2F%2Fwww.cnn.com%27%29%22+value%3D%27&x=20&y=15&accessLevel=Guest&language=en&country=US&Search+All+Cisco.com=cisco.com

Notice that the code bounces you to www.cnn.com website , but anything can be put here. which makes you wonder ...

Anyway, I cannot give credit to this code to any specific Hacker\Hacking Group because i have seen a similar code at more than one of my resources , each from a different country . strangely enough - they all came out in the same 24 hours. script kiddies ?

As i was promised by my cisco friend - this is not a light weighted issue for a company of that size , and i believe that the fix will come very soon.

 

Labels: , , , ,

Monday, September 17, 2007

MSN Messenger - Ad Block - Revisited


Following some email requests ( too many for that specific question ) that ive got to help various FORTIGATE ( by fortinet ) owners - to set their firewall security policy to block MSN Advertisment within the client ( as a Proof Of Concept ONLY ) ... and following an old post ( that i have posted here on march 13th 2007 - Link ) i am posting the requested configuration for the machines.

I have devided to re-post this , with better technical explenation - and in english this time , as a gesture to the "Security Bloggers Network" ( which i only post english feeds to , and this is one worth mentioning ).

the main concept is to block 3 reg-ex uri links that the messenger client gets its advertisment ads from. ( as you may or may not know , this IM uses HTTP to get things done , well - lets break its path...

[ note : configuration is made for the FortiOS mr5 patch 2 and tested on FGT60 ]

As i previsously posted , this is a good way of handeling messenger usage within organizations that do not approve end-user advertisment on its computer environment.

There are two ways of doing it ... one through the url filter engine , and the other one is through the IPS ( which i find much more exotic way of getting things done through deep packet inspection ).

Method 1 - URL Filter :

1. goto the CLI on the machine and paste the following configuration -

  • config webfilter urlfilter
        edit 1
                config entries
                    edit "ad.msn.co.il/js.ng"
                        set action block
                    next
                    edit "rad.msn.com/ADSAdClient31.dll"
                        set action block
                        set type regex
                    next
                    edit "config.messenger.msn.com/Config/MsgrConfig.asmx"
                        set action block
                        set type regex
                    next
                end
            set name "block-msn-ad-engine"
        next
    end

2. choose the "block-msn-ad-engine" within your protection-profile of choice.

Method 2 - IPS :

1. go to the Intrusion Protection >> Signature >> Custom menu and add the following signatures -

  • F-SBID( --name "bs_MSN-AD-Stop.A"; --protocol tcp; --flow established ; --regex "ADSAdClient31.dll"; --no_case)
  • F-SBID( --name "bs_MSN-AD-Stop.B"; --protocol tcp; --flow established ; --content "ad.msn.co.il"; --no_case)
  • F-SBID( --name "bs_MSN-AD-Stop.C"; --protocol tcp; --flow established ; --regex "MsgrConfig.asmx"; --no_case)

2. choose appropriate severity and include the severity in the desired protection-profile.

 

Disclaimer : this is a POC only , this kind of usage may conflict with the MSN Messenger usage aggreement , and i am not to take any responsibility for and unethical or illegal usage of this article and the information it provides. and although i tink using this information to violate any EULA or other agreement is wrong - if you use it - you are taking for responsability for it.


i am not sure that there is any violation , since all this solution does is changing the availability of web data to an application - so basically treating the application as a user in the network and denying it from getting to some internet content . legitimate isnt it ?

Labels: , , , ,

Friday, September 14, 2007

Security Bloggers Network

לבקשת מר אלן שימל - VP פיתוח אסטרטגי בחברה האמריקאית - StillSecure , ומחבר אחד הבלוגים האמינים והאיכותיים יותר בתעשיה ( קישור כאן ) , הצטרפתי לרשת הבלוגרים העולמית לאבטחת מידע בשם SBN . רשת זו נחשבת אמינה באופן יחסי מבחינת סוג האנשים אשר מקושרים אליה , ולכן שמחתי לקבל הצעה זו ממר אלן ולהצטרף.

קישור לרשת הSecurity Bloggers Network נמצא כאן

כמחווה , אני רואה לנכון להוסיף לתפריט הבלוג ( צד ימין למטה ) את הבאנר הרלוונטי לרשת זו. ואני מקווה שקו הבלוגר שלי יפעל להרחיב אופקים גם כלפי חו"ל. אגב - זה אומר שיהיו כאן מידי פעם פוסטים באנגלית. לפחות יותר מהרגיל.


Following Alan Shimel's proposal to join the SBN ( "Security Bloggers Network" ) a few months back , after getting some feedback from Richard Stiennon to my article about UTM , and the followup by Alan Shimel , And because of some path changes that i have decided to take recently . i am proud to say that i am a shiny new member of the SBN , and i hope to bring the voice of israeli information security expertise to the more borad public of security/networking and system professionals .

I have Added the SBN widget to my sidebar in order to let israeli crowd. this means that although i usually write in Hebrew, i will most definetly write in english more often . thank you alan.

Labels: , , ,


About

    My Name is Barry Shteiman, im a devoted tech junkie, and this is my blog.
    E: barry.shteiman -at- gmail.com
    Twitter : bshteiman

Tags & Categories

Mailing List & RSS

Stay Updated  
Add to Technorati Favorites