Trick or Treat: Storm's Halloween

Wednesday, October 31. 2007
Tonight is Halloween. The Storm Worm has changed - as usually - the social engineering scheme according to the upcoming holiday.
The mails used for propagation now point to a website with a Halloween theme. The website shows a Skeleton and exploits several browser vulnerabilities when the user-agent indicates an exploitable browser. The text "Click here for a spooky good time" gets an interesting meaning in this context :-)

URI Handling Vulnerability and RBN

Thursday, October 25. 2007
The URL handling vulnerability in Windows XP and Windows Server 2003 is being actively exploited in the wild according to a posting to full-disclosure. The PDF file attached to that mail contains an exploit for this vulnerability, which contains shellcode to download a binary via FTP from 81.95.146.130. A whois lookup of this IP shows that it belongs to RBN, the Russian Business Network. RBN was quite often in the press recently.

The downloaded binary injects itself into several Windows processes and collects various information from the infected machine. This data is then sent to http://81.95.147.107/cgi-bin/pstore.cgi, another IP address within the RBN network. A complete CWSandbox analysis of the binary is also available.

Continue reading "URI Handling Vulnerability and RBN"

Honeynet Project's Status Report for 2007

Thursday, October 18. 2007
The status report of the Honeynet Project for the fiscal year 2007 is online since a couple of days. It contains an overview of what the Honeynet Project has done in the past year, together with links to the status report of each chapter. If you want to know what was done during the last couple of months, this is a good starting point.