Showing posts with label code. Show all posts
Showing posts with label code. Show all posts

Tuesday, December 15, 2009

Hackers Brew Self-Destruct Code to Counter Police Forensics

Hackers have released an application designed to thwart a Microsoft-packaged forensic toolkit used by law enforcement agencies to examine a suspect’s hard drive during a raid.

The hacker tool, dubbed DECAF, is designed to counteract the Computer Online Forensic Evidence Extractor, aka COFEE. The latter is a suite of 150 bundled, off-the-shelf forensic tools that run from a script. Microsoft combined the programs into a portable tool that can be used by law enforcement agents in the field before they bring a computer back to their forensic lab. The script runs on a USB stick that agents plug into the machine.

The tools scan files and gather information about activities performed on the machine, such as where the user surfed on the internet or what files were downloaded.

Someone submitted the COFEE suite to the whistleblower site Cryptome last month, prompting Microsoft lawyers to issue a take-down notice to the site. The tool was also being distributed through the Bit Torrent file sharing network.

This week two unnamed hackers released DECAF, an application that monitors a computer for any signs that COFEE is operating on the machine.

According to the Register, the program deletes temporary files or processes associated with COFEE, erases all COFEE logs, disables USB drives, and contaminates or spoofs a variety of MAC addresses to muddy forensic tracks.

The hackers say that later releases of the program will allow computer owners to remotely lock down their machine once they detect that it has fallen into law enforcement hands. The hackers, however, have not released source code for the program, which would make it easy for anyone to see if the program contains malware that might also harm a computer or allow the attackers to take control of it.

Update: The developers of DECAF have taken issue with Threat Level referring to them as hackers. “We’re just two developers who support the free flow of information and privacy,” one of them wrote Threat Level in an anonymous e-mail. “You could say we’re just average joes.”

Tuesday, August 4, 2009

Nine very scarey things about Botnets

In a shrinking universe, the Botnet world is expanding.

Let me warn you that this article will paint a scarey picture of botnets taking over all PCs, both the ones on corporate networks as well as the ones at home.


I am sure you have long wondered just how widespread the botnet problem is. What you will learn is enough to make you want to return to the days of stand-alone computing. The reality is worse than most people suspect.

Here is a list of nine known things about botnets that will scare you but perhaps this article will help you to increase your effort to keep your PCs off the illicit botnets.


1. The process of developing software that creates and controls botnets has reached a professional level. Forget the amateur script kiddies that are out for kicks; developers are in it to make a lot of money. The techniques they use to create malware or command and control software are as sophisticated as those used by any commercial software company.

What's more, this underground development community is very cooperative, like a quasi-legitimate open source community. Software is shrink-wrapped, packaged and sold or passed around. The developers add their "personal touches" to create many variants of the malware. Finjan reports that the Golden Cash network operated by cybercriminals provides an exploit toolkit as well as an attack toolkit to distribute malware.

2. Once a PC is captured by a botnet, the use of that PC can be bought and sold many times e.g. the Golden Cash network is a vast botnet exchange. Cyberthieves purchase malware-infected PCs from anyone in the underground market, and then like bond traders, they bundle them and resell them to criminals who want to rent the use of a botnet. This provides a great incentive for criminals to create even larger botnets.

3. Botnets use multiple automated propagation vectors to spread, including spam, worms, viruses and drive-by download attacks e.g. legitimate Web sites are often compromised with HTML tags that force a victim's browser to download JavaScript code from a server that's controlled by the attacker.

That code can launch a number of exploits against the unsuspecting PC. If any of the exploits is successful, the PC can become the next zombie on the botnet, making it easier than ever for the attacker to collect new nodes on his illicit network.

4. The malware that turns the PC into a bot can hide as a rootkit, making it exceptionally hard to detect and eradicate the malware. The Torpig botnet, as an example, implants Mebroot on the victim PC. Mebroot is a rootkit that replaces the system's Master Boot Record. Therefore, the PC is under the attacker's control even before the operating system loads.

5. Once installed, the malware can attack and nullify the very software that is supposed to prevent or at least detect the malware infection. Intel researchers report that botnet developers have begun to target the antivirus, local firewall and intrusion prevention/detection software and services.

The researchers identified at least two ways that a botnet blocked the security software from getting updates:
  • A botnet changed the local DNS settings of the affected system to disable the antivirus software from reaching its update site.
  • A botnet was actively detecting connection attempts to the update site and blocking them.
6. Botnet malware code is often polymorphic; that is, it changes with every new infection. This means that signature-based antivirus software is useless against it. What's more, the Intel researchers have discovered the use of techniques such as code obfuscation, encryption and encoding that further hide the true nature of the code, making it hard for antivirus software to detect it.

7. Botnets can be reprogrammed, allowing their missions to change. One day the botnet can be sending out spam, and the next day it can be told to collect credit card information from the infected PCs.

8. It used to be that bots generated a lot of "noise," making it easier to spot a compromised PC on a network. These days, some bots transmit little traffic, helping them to fly under the radar of log management systems. What's more, botnet traffic can masquerade as legitimate network traffic, making it hard to detect.

9. Legitimate applications such as Web browsers or office productivity tools can be compromised as part of the botnet's malware infection. For instance, the Torpig botnet injects malevolent DLLs into browsers, popular applications, e-mail clients, instant messengers and system programs. After the injection, Torpig can peruse and steal any data that is handled by these applications, including logon IDs and passwords.

If you were under the impression that botnets are no big deal, it's time to realise that they are a big threat and that they are to legitimate businesses and organisations. Now all you have to do is find ways to detect botnet infestations on your network.

Monday, May 11, 2009

Strictly Confidential: The Cloud of Silence

The Cloud of Silence! No it has nothing to do with the Triads and it's not a criminal organisation, it's a privacy concept that has been considered for many years by sci-fi writers, film makers and Machiavellian managers.

The problem: how can you hold a confidential conversation in an open office without everyone overhearing? The answer that is being considered here is a device that will create an intimate 'cloud of silence' around the selected participants.

The proposed modern cloud of silence, we are assured, will work as it says on the box. It is being patented by engineers Joe Paradiso and Yasuhiro Ono of the Massachusetts Institute of Technology.

Patented solution
Their idea, revealed in US patent application 2009/0097671 on 16 April, is to make confidential conversations possible in open-plan offices and canteens, the two places most regularly occupied by US employees. It will even let a conversing group move around a room and still remain in a secure sound bubble, like a 'cloud of silence'.

"In open-plan offices, the violation of employees' privacy can often become an issue, as third parties overhear their conversations intentionally or unintentionally," the inventors say in their patent. Their aim is to relieve people of that concern. Presumably the intentional eavesdropper is going to have to make other arrangements or choose a new hobby.

The Plastic Dome scenario

Initially people considered using plastic domes, this was temporarily attempted but quickly fell out of favour, partly due to the obvious suffocation risk and the unbearable humidity. So, the idea of the plastic dome was scrapped but the name and the concept clung on, regardless. The need was still strong in them.

The Modern Solution
In the modern 'cloud of silence' they use a sensor network to work out where potential eavesdroppers are, and mini speakers to generate subtle masking sounds, at just the correct audible level.

It sounds simple, but it needs quite a bit of smart infrastructure. The walls of the room must be peppered with light-switch-sized units that include a microphone, a speaker, an infrared location sensor and networking circuitry connected to a server. When somebody wants to activate what the MIT researchers call the "sound shield", they do so on their desktop computer.

By responding to the position of the computer, the sensors identifies the person's location and maps out the locations of the other people around them. Smart software assesses who is so close that they must be participants in the conversation and who might be a potential eavesdropper.

The array of speakers then aims a mix of white noise and randomised office hubbub at the eavesdroppers. The subtle, confusing sound makes the conversation unintelligible or more unintelligible, depending on which of your colleagues is talking. Good luck! with this new system guys and success in replacing the older low-tech ways.

Low-tech solutions
Clearly, as a human, you will be able to see which of your colleagues around you is wearing their headphones, staring closely at their screen, whilst pounding the keyboard and is completely unaware that they are in the office at all. For convenience, we will call this colleague Troy.

From his behaviour you can quickly determine that he is not listening in on your chat. To further disguise your conversation and to drown out your voice completely, you should encourage Troy to sing along to whatever Country & Western album he is listening to. This is what is called 'white trash noise.'