Showing posts with label Threat. Show all posts
Showing posts with label Threat. Show all posts

Wednesday, October 30, 2013

HTTP Referer Spoofing, don't get confused, don't worry, Block or Avoid

HTTP Referer?
It's an optional HTTP Request Header which can be set to URI to inform the WebServer the source URI which led the client to current URI.

Analytics Benefit:
It's useful for Web content publishers for analysis sake as per which are the web portals that are attractive more visitors to that URI.

Security Benefit:
It has also been seen to be used as an extra layer of check by WebApps to confirm if the requested URI has been accessed via proper channels and respond accordingly.

HTTP Referer Spoofing ?

As other popular spoofing attack this doesn't involve attacker trying to hide their identity.

Here attacker will actually retain and embed their identity into the HTTP Request made to your WebServer. The spoofing in this case happens of is forging a custom HTTP Request with a fake HTTP Referer header added to make the WebServer believe some user is visiting their service by getting the link from attacker's injected referrer URI.

For past sometime I've been viewing a flood of spoofed HTTP referers on the user statistics page.
Here is a screenshot of web statistics page from one of my other blog for span of a month on one of the date-ranges. These are top-chart statistics for reported traffic referrals.

As you can notice... among top 10 referring URLs 5 are spammers, namely

  1. http://r-e-f-e-r-e-r.com/(target-specific-uri)
  2. http://adfoc.us/(some-numeric-id)
  3. http://www.googlecorrection.com/
  4. http://justforlaughsgags.tv
  5. http://smarts-loans.com/

Threat ?

There are potential 2 types of threats which arise from it:
  1. Opening an Infected Website
    Most of these referer spoofing happens to trick the website admin/publisher into thinking a new/dis-respected portal is referring to their content. In some of those cases, out of curosity the site admin/publisher tend to visit the URI mentioned as referer.
    Now if the URI leads to an infected portal, the visit is as safe as the attempt to click on an untrusted link. It might be just an advertisement portal or a generously malware spreading service.
  2. Indirectly triggering WebApp Vulnerability
    This is more of an indirect attack where the site-admin/publisher doesn't need to visit the referer URI but just view it on a weak web-application responsible to show the analytics.
    Now, since anything can be injected into the HTTP Referer Header. Any web-view dealing with the rendering of it or any backend application/database dealing with processing it can fall pray to a cleverly designed referer entry. The attacks possible here have a wide range and depend on the components involved at site-admin/publisher end to analyze it.

Solution ?

Don't be curious of unknown referers.

If building something yourself to analyze these, make sure your own code is safe enough.

Monday, October 3, 2011

Social Engineering [from Eden Guide to Hacking >> Active Recon]

Eden Guide To Hacking : https://github.com/abhishekkr/eden_guide_to_hacking
 
Social Engineering
direct link :  https://github.com/abhishekkr/eden_.....  ineering.txt


Most creative non-technical hacker practice known to mankind.
 
a.) It's Art of Communication with People for 'Information Leakage'.

  • You have a 'Victim' identified by now and wanna collect more and more available information related to them.
  • Not just any relevant information, but sensitive details, that Victim or related people handover to you in confidence.
  • You think like a con-artist, assess weakness of your victim & the possibilities of make-believe for them.
  • Then you come up with an entire scenario to pose yourself a reliable savior for your Victim to be saved; a benefactor.
  • And you will find them revealing such discreet and sensitive information so that they can encash the situation to its max. And let you gather all sensitive information that you can.



b.) Example: "The pretend employee loosing access at critical time"

  • You are a management personnel on client location in middle of a very life-changing deal.
  • You need to get some files from your organization's machine or file-share; but can't access them due to firewall policies on either side.
  • If you can't seal the deal, the failure will take away your job and the person refusing you such crucial-moment help.
  • And there are many chances that you'll get the data fetched from your pretended 'Employee', mailed to you.


 
c.) Example: "I'm here to check your Network from Agency"

  • You are at home of your Victim when some family member, hopefully not much security aware is in-charge and pose as the Network Guy from the Telecom Agency they use.
  • Offering new organization customer satisfaction mumble-jumble, you try to get access to check health status of network devices installed there, and more computing devices if possible.
  • Now, if the devices are tweakable without any credential request from the family member there... try that first.
  • If it doesn't work and even they don't have access, then pose as attempting the 'Master Password' so they don't inform the Victim.


d.) For ultimate case studies, read "Art of Deception" by "Kevin Mitnick", the most famous Social Engineering Hacker 'known'.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Friday, July 3, 2009

First Firefox Malware : Trojans Stealing Passwords Typed in Firefox using Firefox Add-on Disguise

First Firefox Malware : Trojans using Firefox Add-on Disguise
Roll your mouse over topics to expand them... :)
Information On Malware

Symptoms of Infection

List of Accounts mainly under attack

What To Do If Infected
__________________________________________________
Bitdefender released information on this threat naming it as Trojan.PWS.ChromeInject.A, which spawns with the execution of Firefox and poses as a Plug-in to it, mainly works on Key Banking... can get access to all your passwords entered in the Password boxes opened in Firefox Browser.

The ChromeInject suffix refers to the Chrome component Firefox has. This malware infects your machine via drive-by download or download duping.
Once installed on the machine it registers itself as a fake 'GreaseMonkey' (a great firefox add-on for website customization using javascripts), and using javascript checks your machine for mainly banking passwords of more than 100 sites (like PayPal, etc.).
All this sensitive data collected by it is then transferred online to a server supposed to be located in Russia.

So, don't stop using Greasemonkey... but make sure you download it from Mozilla.com, so that you don't fall pray to malware.
__________________________________________________

Saturday, June 13, 2009

ATMs under Trojan Attack in Eastern Europe

ATMs under Trojan Attack in Eastern Europe

security experts revealed a family of data-stealing trojans is infecting automatic teller machines in Eastern Europe over the past 18 months

It monitors transaction message queue for track 2 data stored on inserted cards. If it contains data belonging to a banking customer, it logs it, along with the PIN code that was entered.

The software works with Controller Cards... in its Primary Menu the main features it provide are
1. Print Collected Data
2. Restore logged files before malware infected the machine
3. Uninstallling the malware

there is a secomdary menu with main features as
1. Dispensing all Cash in ATM
2. Upload data to a chip on cotroller card