Darknet - The Darkside

Don`t Learn to HACK - Hack to LEARN. That`s our motto and we stick to it, we are all about Ethical Hacking, Penetration Testing & Computer Security. We share and comment on interesting infosec related news, tools and more. Follow us on Twitter, Facebook or RSS for the latest updates.

07 May 2006 | 4,817 views

New Trojan Targets World Cup Fans – Troj/Haxdoor-IN

Prevent Network Security Leaks with Acunetix

Ah, first we had the ransomeware, yesterday the trojan targetting WoW users, now we have the World Cup trojan..

It really must be Trojan season.

A Trojan horse that poses as a World Cup wallchart has begun circulating on the net. The Haxdoor-IN Trojan horse is been spamvertised in messages, written in German, that purport a program that will allow fans to keep tab on football teams participating in next month’s eagerly anticipated tournament.

Windows users who follow links in these messages and download the software will wind up with infected PCs. Net security firm Sophos says all the spam emails promoting downloads of the malware it has seen so far have been written in German. “There is no reason to believe that hackers will not switch to using other languages to increase their pool of potential victims,” it warns.

It has happened in similar ways before.

Virus writers have regularly taken advantage of World Cup competitions to promote their wares. A year ago, the Sober-N worm offered tickets to the tournament in an attempt to trap gullible users into opening an infectious email attachment. In 2002, the Chick-F virus tried to exploit fans’ desires to learn the latest scores from games in South Korea and Japan.

At the end of the day it all comes down to Social Engineering, hacking the wetware, always the weakest link..They may have firewalls, antivirus and anti-spyware software up the chute, but if you can make them run an executable their PC is yours. Especially on Windows where the concept of privelege segregation is extremely vague..

Theres a bit more info about the trojan over at Sophos: Haxdoor-IN.

Its aliases are:

  • Backdoor.Win32.Haxdoor.in
  • BKDR_HAXDOOR.GM
  • Backdoor.Haxdoor.J

Source: The Register



06 May 2006 | 13,701 views

New Password Stealing Trojan Targets WoW Players

It really does seem like the Malware/Spyware folks are really into making money nowdays, what with $15 spyware kits and Viruses that place your machine under lockdown until you pay the ransom..

What happened to people just doing stuff for learning, for enhancement of knowledge, deep understanding..not a quick few hundred dollars.

I have to say though targetting WoW users is a pretty smart and unique vector, as quite a lot of money does come from Virtual sources, selling level 60 characters, selling certain items, selling information and so on.

A new password-stealing Trojan targeting players of the popular online game “World of Warcraft” hopes to make money off secondary sales of gamer goods, a security company warned Tuesday.

MicroWorld, an Indian-based anti-virus and security software maker with offices in the U.S., Germany, and Malaysia, said that the PWS.Win32.WOW.x Trojan horse was spreading fast, and attacking World of Warcraft players.

The trojan spreads through the normal VB virus of the week vectors (email, network etc), but specifically targets WoW accounts.

The Trojan spreads via traditional vectors, such as e-mail and peer-to-peer file sharing, added Rammurthy, but it has also been watched while it installs in a drive-by download from gaming sites’ pop-up ads. The surreptitious installation is accomplished by exploiting various vulnerabilities in Microsoft’s Internet Explorer Web browser.

Interesting to see what comes next..

Source: Information Week


05 May 2006 | 17,111 views

The MIT IP Packet Spoofing Project – Can We Spoof IP Packets?

Now this is a VERY interesting project, as I’ve always said the majority of DoS attacks and DDoS attacks (90%+) could be stopped if all the ISP’s null routed packets which DO NOT originate from IP blocks they own, e.g. spoofed packets.

Basically the project has been established to see if you can spoof IP packets or not, and what percentage of ISPs already drop the packets.

It seems in general about 20-25% of systems are able to spoof packets.

Packet Pie Charts

The classic design tenets of Internet architecture produced a network capable of remarkable scalability while relegating security to the end hosts. As a result, the public Internet includes no explicit notion of authenticity and will forward packets with forged headers. Malicious users capitalize on the ability to spoof” source IP addresses for anonymity, indirection, targeted attacks and security circumvention. Compromised hosts on networks that permit IP spoofing enable a wide variety of attacks. Despite being first exploited over two-decades ago, IP spoofing is a persistent problem and a continued threat. In addition to mounting spoofed-source bandwidth-based denial-of-service (DoS) attacks, new exploits utilizing IP spoofing surface regularly.

You can read more of the intro to the ANA spoofing project here.

Some may suspect the project and the software involved is somewhat nefarious, but oh well, if you are going to get r00ted by someone, let it be MIT ok? Anyway you can always run it in a sandbox or in a fresh VMware machine.

If you don’t care either way, you can download the spoofer software here.

Please note though, it won’t run under Windows XP SP2, due to the whole raw sockets issue I would imagine.

The majority of systems tested so far have been Windows systems though (64%).

A summary of the results:

Total Completely Failed Spoof Attemps: 1823
Failed as a result of Windows XP SP2: 528
Failed as a result of (non-Windows) Operating System block: 111
Failed as a result of being Behind a NAT: 702

The various types of tests show which restrictions are in place.

Packet Summary Results

A full summary of the results are here.

Digg This Article


04 May 2006 | 4,529 views

AV Firms Say Windows Vista Security Claims are Bullsh*t

It seems the faith in Microsoft from the security industry is at an all time low, not surprising really with the amount of flaws that have been coming out in both the OS and the crapware forced upon its users like Internet Explorer Exploder.

Anti-virus firms at Infosec say they expect Vista and IE7 to change nothing for the industry. Microsoft used its presence at the show to laud the security features they’ve been busy building in the the upcoming software.

In particular, Microsoft was eager to talk about how Vista will finally jettison the need to run Windows as an administrator most of the time.

Basically what they are saying is, your mom, your gran and anyone else technically unsavvy is still going to be subjected to huge risks, even if they upgrade to Vista. Nothing is going to change in essence.

Eugene Kaspersky, founder of the eponymous Russian AV outfit said he expects the new privilege regime to have little effect. He said: “Of course they [virus writers] will find a way round it. Within a year there will be something like a rootkit for Vista.”

John Kay, Chief Technical Officer at Blackspider reckons on a “bug per line of code”. With the traditionally Heath-Robinsonian construction of MS browsers he’s not hopeful for IE7. He said: “I dread to think how many lines of code there are in there.”

1 bug per line of code? Amazingly bad, but I don’t think it would be quite so terrible. Even so, the people in the know say Windows is the worst hodge podge of spaghetti coding they’ve ever seen. It was pretty much confirmed when the Win2k & NT4 source code leaked out.

Let’s all stick to *nix & Open Source hey, but then that’s not perfect either. At least it’s improving at a rate of knots…I’m just waiting for Firefox to have a decent Bookmark manager ;)

Source: The Register


04 May 2006 | 12,803 views

Homeland Security Uncovers Critical Flaw in X11

An open-source security audit program funded by the U.S. Department of Homeland Security has flagged a critical vulnerability in the X Window System (X11) which is used in Unix and Linux systems. A missing parentheses in a bit of code is to blame. The error can grant a user root access, and was discovered using an automated code-scanning tool.

The flaw has been fixed.

It was a change from this:

if (getuid() == 0 || geteuid != 0)

to this:

if (getuid() == 0 || geteuid() != 0)

The best part was the CVS comment:

Fri Mar 10 17:29:51 2006 UTC (7 weeks, 4 days ago) by deraadt:
proper geteuid calls because suse hires people who mistype things

From the article:

Coverity, the San Franciso-based company managing the project under a $1.25 million grant, described the flaw as the “biggest security vulnerability” found in the X Window System code since 2000.

The X Window System, also called X11 or X, provides the toolkit and protocol to build GUIs for Unix and Unix-like operating systems. It is used to provide windowing for bit-map displays.

Source: Yahoo News

Apparently OpenBSD already fixed this during a code-cleanup.


03 May 2006 | 71,330 views

Medusa Password Cracker Version 1.1 Now Available For Download

Medusa is a speedy, massively parallel, modular, login brute-forcer for network services created by the geeks at Foofus.net. It currently has modules for the following services: CVS, FTP, HTTP, IMAP, MS-SQL, MySQL, NCP (NetWare), PcAnywhere, POP3, PostgreSQL, rexec, rlogin, rsh, SMB, SMTP (VRFY), SNMP, SSHv2, SVN, Telnet, VmAuthd, VNC, and a generic wrapper module.

While Medusa was designed to serve the same purpose as THC-Hydra, there are several significant differences. There is a Comparison between Medusa and THC-Hydra Here.

This release adds several new modules, additional OS support, and fixes numerous bugs. A somewhat detailed report is available here:

http://www.foofus.net/jmk/medusa/ChangeLog

You can download Medusa Here:

Medusa 1.1 Download

Author Note:

Medusa was developed on Gentoo Linux and FreeBSD. Some limited testing has been done on other platforms. If people wish to contribute patches to fix portability issues, I’d be happy to accept them. There are probably lots of bugs which have yet to surface. Please let me know if you encounter issues, fix a bug or just find the application useful.

More information on Medusa Here.


03 May 2006 | 5,021 views

Who is Gouki?

Well the original Gouki (also known as Akuma) is a character from the Street Fighter game series. I started using this handle approximately 10 years ago, when I was a big fan of the game.

My name is Tiago, and I’m a 20-something geek living in Portugal (all over the place).

I am interested in Information Security and everything related to GNU/Linux. I consider myself a free culture activist and free software supporter. I’m involved in the FSF, the GNU project, I do a lot of tracing and editing on the Open Street Map project and I do all sorts of contributions to the Ubuntu GNU/Linux distribution.

I also use a fair part of my free time working on the Tor Project, where I’m the core translator off all projects under Tor to Portuguese, run several relay nodes and one bridge node. I also keep a server with hidden services up and running for people on the .onion land.

During the day, I maintain my own small business dealing mostly with disaster recovery, teach LPI (I’m LPIC-3 and UCP-1 certified) and CompTia (A+, Network+, Security+ and Linux+ certified) courses and maintain a few Drupal/Wordpress websites for clients. Basically doing what I can to pay the bills.

My posts on Darknet will, obviously, be related to Information Security with special interest on Wireless, Linux kernel and general news.

My homepage is available at http://xroot.org/. Feel free to contact me if I can help you in any way.

Tiago


02 May 2006 | 4,415 views

Microsoft Shelves Support for RSA SecurID in Vista

Switchback? For the worst? Aww Microsoft would never compromise our security for the sake of convenience or their profit line right?

Microsoft has shelved plans to include native support for RSA’s SecurID tokens in Windows Vista, even though the company has been trialling the technology for almost two years.

In February 2004, Microsoft chairman Bill Gates announced that Windows would be able to support easy integration with RSA Security’s ubiquitous SecurID tokens, which meant that enterprises would find it far easier to deploy a two-factor authentication system for logging on to networks and applications.

However, almost two years after the SecurID beta programme kicked off, the chief executive of RSA Security Art Coviello has revealed that Windows Vista will not natively support the technology.

Yeah, you read it right, Vista will not support SecurID. Shame really it opened up a whole load of new capabilities.

Microsoft had said they would include the ability to support all kinds of One Time Password (OTP) and challenge response type authentication in Vista but they were unable to get it in with all the other issues they have had — so it is going to take longer

Seems like they may retrofit it some time in the future.

Source: Zdnet


02 May 2006 | 6,710 views

Proof of Concept for Internet Explorer Modal Dialog Exploit

Pretty interesting and imaginative way to exploit the flaw in IE…yeah I know linked to ActiveX again, all the more reason to use Firefox right?

It just shows that the browser really is a point of entry, this could be useful for a penetration test, another way to show how easy it is to get in via internet explorer, the frequency with which IE exploits have been coming out recently is scarier than normal.

A particular scenario was identified that involved the exploitation of the modal ActiveX prompt delivered by some systems. The user is asked to type a certain string of characters (ala captcha). A prompt will be displayed (hopefully during the time the user is typing the string) to install the Microsoft Surround Video Control.

If you’re still typing the “captcha” when the prompt appears, you’ll install the control. This works as advertised against all systems EXCEPT Windows XP SP2 and Windows Server 2003 SP1. If the software you install hoses your box, just remember that it’s signed by Microsoft. In
other words… don’t look at me.

You can check the PoC here:

Proof of Concept for IE Modal Dialog Issue

It just crashes IE for me, I’m not sure if it’s a null pointer or what, but I’m sure there’s some way to exploit it to take over the machine, it’s a another vulnerability, which usually can be mashed together with a couple of others to get complete control.

By Matthew Murphy spotted on Vulnwatch


30 April 2006 | 8,772 views

Gary McKinnon Busted Because he Forgot the Time Difference

It turns out Gary McKinnon got sloppy, that’s why he got busted. He forgot the computers he was comprimising were in a completely different time zone, and as he was using remote control software, the person in the office saw their mouse moving around. We have reported about this guy before, when he was fearing being exported and chucked in Guantanamo.

A British computer hacker facing extradition for breaking into United States military computers said today that computer administrators fail to take easy steps that deter unwanted intrusions.

Gary McKinnon, who spoke on a panel at Infosec Europe 2006 here, made a critical miscalculation when poking around one of his targets that started an international investigation.

“I got caught because I was using a graphical remote control tool, and I forgot what time zone I was in,” McKinnon said. “Somebody was in the office when I was moving the mouse around.”

McKinnon’s probes occurred when computers were left on but employees were gone. Simply shutting down computers at night reduces the risk, he said.

Sloppy mistake though.

He makes some good points in the interview too, weak passwords generally are the weakest link, it’s quite common to find blank admin passwords and the C$ still enabled giving you full access to a Windows machine. Users really are the weakest link.

Passwords are a consistent weak point. McKinnon was able to hack a few unguarded passwords that gave him access; stronger passwords are recommended, he said. Misconfiguration by administrators made it easier, as some password protection was simply not enabled, he said.

Source: Yahoo News