::Trend Micro Threat Resource Center::

28 August 2009

Video: Social Zombies presentation from DEFCON

Presented on August 2, 2009 at DEFCON 17 in Las Vegas, Tom Eston and Kevin Johnson explore the various concerns related to malware delivery through social network sites. Ignoring the FUD and confusion being sowed today, this presentation will examine the risks and then present tools that can be used to exploit these issues.

This presentation begins by discussing how social networks work and the various privacy and security concerns that are caused by the trust mass that is social networks. We use this privacy confusion to exploit members and their companies during our penetration tests.

The presentation then discusses typical botnets and bot programs. Both the delivery of this malware through social networks and the use of these social networks as command and control channels will be examined.

Tom and Kevin next explore the use of browser-based bots and their delivery through custom social network applications and content. This research expands upon previous work by researchers such as Wade Alcorn and GNUCitizen and takes it into new C&C directions.

Finally, the information available through the social network APIs is explored using the bot delivery applications. This allows for complete coverage of the targets and their information.

Social Zombies: Your Friends Want To Eat Your Brains from Tom on Vimeo.

Attack Of The Tweets: Major Twitter Flaw Exposed

A newly exposed cross-site scripting (XSS) vulnerability in Twitter lets an attacker wrest control of a victim's account merely by sending him or her a tweet.

The embedded code can perform any tasks the Twitter Website can perform, including redirecting a user to another page, sending tweets, changing account information, or adding or deleting followers, he said.

"Simply by seeing one of these tweets, code can be run inside your browser impersonating you and doing anything that your browser can do. Perhaps it may simply redirect you to a pornographic website? Or maybe delete all of your tweets? Send a message to all of your friends? Maybe it would delete all of your followers, or worse still, just send the details needed to log in to your account off to another website for someone to use at their leisure," Slater said

Detailed article here.

24 August 2009

More Employers Blocking Social Networks

Employers are gradually putting more restrictions on what websites their employees can view and are increasingly choosing to block access to popular social networking sites, according to a new report from security firm ScanSafe.

"When Web filtering first became an option for companies we generally saw them block access to typical categories such as pornography, illegal activities and hate and discrimination," said Spencer Parker, director of product management at ScanSafe.

"In recent months, employers are obviously wising up to the dangers and negative impact on productivity linked to certain sites and more and more of our customers have chosen to block social networking, online banking and Webmail."

The report found a 20 percent increase in the number of companies blocking social networking sites in the last six months. Currently, 76 percent of companies are blocking social networks and it is now a more popular category to block than online shopping (52%), weapons (75%), alcohol (64%), sports (51%) and Webmail (58%).

ScanSafe specifically found an increase in the number of customers choosing to block the below categories in the last 6 months.

28% increase in travel
27% increase in restaurants and bars
26% increase in sports
26% increase in online shopping
19% increase in Job Searches
16% increase in Webmail

"Social networking sites can expose businesses to malware and if not used for business purposes can be a drain on productivity and bandwidth," says Parker.

"Given the option, companies are increasingly taking a sterner approach to the sites that their employees are allowed to access. I imagine before long, social networking will be up there with pornography in terms of categories blocked."

16 August 2009

Twitter Used As Botnet Command Center

As if being deluged under DDoS attacks isn't bad enough, this week Twitter found itself the target of another sort of threat. The Register recently reported that the wildly popular social networking service is also being used to direct part of a botnet's activities.

According to the report, a security analyst accidentally stumbled across a Twitter account being used by botherders as a cheap and effective way of directing infected computers to websites where they can get further instructions.

This appears to be the first time Twitter has been used as part of a botnet's command and control structure. At time of writing, the malicious account has already been taken offline.

For more details, you can also check the original post from Arbor Sert.

Credits

14 August 2009

Nearly 80% Of Users Vulnerable To Adobe Flash Attack

Most users haven't fixed their Acrobat Reader apps two weeks after Adobe issued critical patch, Trusteer says.

Adobe may have sped up its process of releasing security patches to its software, but most users apparently aren't applying them immediately or at all, according to new data released today.

Trusteer found that close to 80 percent of users are running older and vulnerable versions of Flash, and 84 percent, older and vulnerable versions of Acrobat Reader. The data (PDF) was gathered from Trusteer's 2.5 million users of its Rapport browser security service, 98.8 percent of whom have Flash active in their browsers.

More details here.

So please be a good boy/girl and patch up your Adobe products:

13 August 2009

WordPress Password Problem Crops Up

People who use version 2.8.3 of the WordPress blogging software may want to download an update posthaste. A vulnerability's been discovered that, while it won't let other folks take over accounts, will allow troublemakers to lock out administrators.

Laurent GaffiƩ gets credit for uncovering the problem, and according to a warning published on Full Disclosure, this hack isn't the domain of shadowy professionals and government agents. About all that's needed in order to pull it off is a Web browser and one special URL.

Then, it's possible to mess with the WordPress password reset function, resetting passwords without the admin ever getting any notice of the action.

You can imagine how this would prove problematic if an administrator couldn't figure out what was going on. And even if an admin did catch on, a prankster could probably manage to repeat the performance over and over, creating a real headache or even permanent roadblock.

Luckily, version 2.8.4 of WordPress has been made available in response, and it addresses the issue. So get to downloading the update as soon as seems convenient for the sake of not getting locked out of your blog.