Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • Myth crushed as hacker shows Mac break-in | InfoWorld
  • The State Secrets Privilege [US Senate Judiciary Comm.]
  • Maryland Court Weighs Internet Anonymity
  • Hunton & Williams LLP Voted Top Privacy Advisors for Second Year in Computerworld Poll
  • Could Too Much Transparency Lead to Sunburn?
  • Piracy More Serious Than Bank Robbery?
  • AT&T effort to stem Internet piracy raises privacy concerns

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Security Expert Gives Computer Intruders a Taste of Their Own Medicine

Submitted by MacRonin on April 11, 2008 - 4:24pm
  • Activists
  • Bot- Nets
  • Editorial
  • Exploits
  • Hmmm
  • How-To
  • Infrastructure
  • Privacy
  • Remember
  • Rights
  • Security
  • Seminar
  • Software

Security Expert Gives Computer Intruders a Taste of Their Own Medicine - Via Threat Level:

SAN FRANCISCO -- Malicious hackers beware: computer security expert Joel Eriksson might already own your box.

Eirksson, a researcher at the Swedish security firm Bitsec, uses reverse engineering tools to find remotely-exploitable security holes in hacking software. In particular, he targets the client-side applications intruders use to control Trojan horses from afar, finding vulnerabilities that would let him upload his own rogue software to intruders' machines.

He demoed the technique publicly for the first time at the RSA conference Friday.

"Most malware authors are not the most careful programmers," Eriksson said. "They may be good, but they are not the most careful about security."

Eriksson's research on cyber counter-attack comes as the government and security firms are raising alarms about targeted intrusions by hackers in China, who are evidently using Trojan horse software to spy on political groups, defense contractors and government agencies around the globe.

The researcher suggests that the best defense might be a good offense, more effective than installing a better intrusion detection system. Hacking the hacker may be legally dubious, but it is hard to imagine any intruder-turned-victim picking up the phone to report that he had been hacked.

Eriksson first attempted the technique in 2006 with Bifrost 1.1, a piece of free hackware released publicly in 2005. Like many so-called remote administration tools, or RATs, the package includes a server component that turns a compromised machine into a marionette, and a convenient GUI client that the hacker runs on his own computer to pull the hacked PC's strings.

Using traditional software attack tools, Eriksson first figured out how to make the GUI software crash by sending it random commands, and then found a heap overflow bug that allowed him to install his own software on the hacker's machine.

The Bifrost hack was particularly simple since the client software trusted that any communication to it from a host was a response to a request the client had made. When version 1.2 came out in 2007, the hole seemed to be patched, but Eriksson soon discovered it was just slightly hidden.

Eriksson later turned the same techniques on a Chinese RAT known as PCShare (or PCClient), which hackers can buy for about 200 yuan.

PCClient is slightly better engineered than Bifrost, since it won't accept a file uploaded to it, unless the hacker is using the file explorer tool.

But, Eriksson found, the software's authors left a bug in the file explorer tool in the module that checks how long a download will take. That hole allowed him to upload an attack file the hacker hadn't asked for, and even write it into the server's autostart directory.

The software's design also inadvertently included a way for the reverse attacker to find the hacker's real IP address, Eriksson said. He said its unlikely that the malware authors know of these vulnerabilities, though its unlikely that PCClient is still in use.

But he says his techniques should also work for botnets as well, even as malware authors start using better encryption, and learn to obfuscate their communication paths using peer to peer software.

"If there is a vulnerability, it is still game over for the hacker," Eriksson said.

See Also:

  • Zombie Computers Decried As Imminent National Threat
  • US Has Launched a Cyber Security 'Manhattan Project,' Homeland ...
  • Industrial Control Systems Killed Once And Will Again, Experts Warn
  • FBI Cracks Down (Again) on Zombie Computer Armies
  • Even the hackers are nervous

Screenshot of PCShare courtesy of Joel Eriksson.


(Read Original Article - Via Threat Level.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • In Bid to Sway Sales, Cameras Track Shoppers
  • Unprecedented 25-Year Sentence Sought for TJX Hacker
  • EFF Appeals Dismissal of Warrantless Wiretapping Case
  • Viacom Makes Its Case Against Yesterday's YouTube
  • Obama supports Senators draft plan to rework U.S. immigration policy - Includes National Biometric ID card for all.
  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.