::Trend Micro Threat Resource Center::

04 January 2011

Adobe PDF format riddled with exploitable features

Adobe's PDF format and standard has been known for a while now to be easily exploitable and, thus, rather insecure. In the past, attackers have taken advantage not only of its vulnerabilities, but of its features as well. And as Adobe has recently announced a sandbox for Adobe Reader, some experts wonder if it's enough.

As Julia Wolf, a researcher with security company FireEye, pointed out at the 27th Chaos Communication Congress in Berlin - the current PDF standard is riddled with functions that can be misused in various ways.

According to her, a PDF file can have a database scanner embedded in it which is rigged to start scanning as soon as the file is printed on a network printer. It can also be made to display completely different content depending on the OS, browser, PDF reader software or language settings used on the computer.

What's more, some of its functions can be used to set off arbitrary code execution. The fact that the standard supports many insecure formats (XML), technologies (RFID tags) and script languages (JavaScript) only adds to its weak security.

According to The H Security she also mentioned that, interestingly enough, Adobe calls the the PDF format a "container format". And, indeed, it can contain many things - from audio and video to Flash files, which can, in their turn, be exploited by the attackers.

But, one of the biggest problems regarding the exploitation of this feature is that most anti-malware solutions fail to detect this embedded malicious software, and the detection rate is poorer still if the malicious code is compressed.

All in all, the sandboxing feature will be a welcome addition to the new version of Adobe Reader. Whether it will solve the problems she described, it remains to be seen.

01 January 2011

Android Trojan with botnet capabilities found in the wild

A new, more sophisticated Trojan for Android devices has been spotting lurking on third-party Chinese Android app markets - the first ever piece of Android malware that has the capability to receive instructions from a remote server and thus become part of a botnet.

Dubbed "Geinimi", the Trojan is attached to (obviously compromised) versions of legitimate applications - mostly games such as Monkey Jump 2, Sex Positions, President vs. Aliens, City Defense and Baseball Superstars 2010.

So far, it has only been spotted being distributed through third-party Chinese app stores. Versions of these applications on the official Google Android Market have not been compromised.

When the affected application is installed on the device, it requires the user to give more permissions that it would usually need. Geinimi them kicks into action, harvests the device's location coordinates, the IMEI and IMSI (unique identifiers for the device and the SIM card), and transmits that information to a remote server via a number of hard-coded domain names.

Until now, the server hasn't been spotted sending instructions to the Trojan, so its final purpose is not yet clear.

It is known, though, that it can download and prompt the user to install an app, prompt him to uninstall an app, and transmit a list of all the installed apps on the device to the aforementioned server.

Lookout's researchers say that Geinimi also uses obfuscation techniques to hide its activities, so it will be more difficult to spot.

But users in general should suspect their devices of being infected by mobile malware if the phone presents unusual behavior such as automatic SMS sending to unknown recipients, automatic phone calls, stealthy installation of unknown applications, etc.

An occasional check of outbound calls and SMSs and of installed applications should become a habit for users.

31 December 2010

WordPress 3.0.4 critical security update

Version 3.0.4 of WordPress is a very important update to apply to your sites as soon as possible because it fixes a core security bug in our HTML sanitation library, called KSES.


Certain unspecified input is not properly sanitized in the KSES library before being displayed to the user, according to Secunia.

This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in the context of an affected site when the malicious data is being viewed.

This is a critical release, available immediately through the update page in your dashboard or for download here.

29 December 2010

Older Facebook apps threaten your and your friends' privacy

Facebook users that are concerned with keeping their privacy have probably become more careful with the years about adding applications to their account, since many ask access to more information they are willing to provide.

But two, three years back - before Facebook was forced to give users more privacy control over each application used - applications asked for a lot more information in order to function than they do now. And all the users that use older versions of various applications are still giving it access to all that information that was agreed on before, reports Vanessa Dennis.

Take the YouTube App as an example, and see what information it asked access to before and what it asks now:


As you can see, before it could access practically all your information, post to your Wall and even access your friends' information. Unfortunately, that means that all the "Facebook" friends that are using any of these "older" applications are giving it access to your information - and vice versa.

If you are at all concerned about this, it's best to review every application you have on your account. Go to Privacy Settings/Apps and Websites, then click on the "Edit Settings" button and on each application individually to review their specific privacy settings. If you are not satisfied with them, delete the application and think twice about adding it again. Then send this article to your friends and ask them to do the same.

24 December 2010

Fake iTunes e-mail leads to drive-by download

E-mails purportedly coming from iTunes and bearing "iTunes account may be suspended" in the subject line have been hitting inboxes in the last few days.

"Dear iTunes Customer, it is possible that your account password has been stolen. 4 different IP addresses have been used to login to your account within the last 24 hours. Please visit the bellow link and read what to do and how to contact support department," says in the message.

At first glance, this seems a typical phishing e-mail. But no - "iTunes will never ask you for your password or any confidential information," claims the e-mail, and perhaps gains the trust of some users who then proceed to click on the link.

They land on a fake Apple support page, and it doesn't ask them to share any confidential information:

But, unbeknownst to them, the site silently serves a malicious script that tries to exploit vulnerabilities in older versions of Java and Windows Help to gain access to the system and download and install malware. Users that patch their OS and software regularly are safe from this attack.

23 December 2010

Worm blocks access to Facebook

A relatively new worm that Symantec named W32.Yimfoca presents a very interesting and never before seen modus operandi.

A variant of the worm spreads via Yahoo! Messenger and, once installed, downloads and installs W32.Yimfoca on the target system. Lately, it has been noticed that it specifically targets Facebook users by denying them access to their accounts if they don't complete a survey.

Every time the user lands on the Facebook homepage, a window offering the surveys pops up:


Also, while the victim fills out the survey, a progress bar is shown accompanied by a "threat" - "You have only 3 minutes to fill out the selected survey or you will not have access to your account."

Once you have completed a survey - which, by the way, earn the scammers up to $1 per survey - you can access your account. If you don't do it within 3 minutes, the worm will not allow you to access the account while it's running - and it resets even after a reboot of the infected computer.

It is also interesting to note that the worm blocks access to Facebook only if you use Internet Explorer. Using any other browser fails to trigger the worm and you can access your Facebook account without being sidetracked by annoying pop-ups.