IGEL extends UK distribution with Arrow appointme... » Reading, UK: IGEL Technology has appointed Arrow Electronics Inc. as a distributor in the UK. The ap... Parliament receives troop rotation details for fi... » The troop rotation arrangements outlining the tour lengths for deployed UK personnel between now and... Lancope joins Cloud Security Alliance to help prot... » LONDON (UK): Lancope, Inc., a leader in network visibility and security intelligence, has joined the... Why Hosters Should Care About Web Security » Last week, the “Moroccan Ghosts” published a list of 52 defaced Israeli sites, replacing site conten... AhnLab sets aggressive business growth targets in... » LONDON, UK: AhnLab, a leader in advanced internet security protection for businesses, today announce... Unified Security Management provider included i... » San Mateo, Calif.: AlienVault, the leading Unified Security Management provider committed to making ... Prolexic issues recommendations for validating DDo... » HOLLYWOOD, FL: Prolexic, the global leader in Distributed Denial of Service (DDoS) protection servi... Hitachi TrueNorth Partners have a complete solutio... » LONDON (UK): Varonis Systems Inc., the leading provider of comprehensive data governance software, t... Barracuda web application firewall enhances protec... » Basingstoke: Barracuda Networks Inc, a leading provider of security and storage solutions, has annou... ProRail chooses NICE Situator for security, safety... » NICE is partnering with Geodan to deploy an integrated security solution for improved incident respo...

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

Information Security Header

AlienVault’s research team has discovered a large human rights Web portal that has been compromised and is serving up malware to site visitors.

The ASEAN site compromise is notable as the portal is both high profile and may be linked to Google’s warnings on state-sponsored attacks, says Jaime Blasco - a researcher with the Security Information and Event Management (SIEM) solutions specialist – who adds the crack appears to centre around a Windows XML Core zero-day vulnerability (http://bit.ly/N2xxU2)

“Whilst this high-profile portal crack and consequent drive-by malware-fest is notable for being a possible hostile act by another government and/or its supporters, the fact that Windows flaw has been exploited so quickly and comprehensively proves the need for vigilance and understanding of zero-day flaws,” he said.

“It also, of course, underlines the need to patch your operating system as well as the applications software on a very regular basis, regardless of how large – or small – your computer systems estate is,” he added.

The AlienVault researcher went on to say that the CVE-2012-1889-linked vulnerability exploit on the ASEAN human rights portal appears to involve the same group as the site hacks reported by colleagues at Sophos.

Every time a page is displayed to the visitor, the content is modified and additional html code – in this case actual exploit code – is inserted dynamically to the user’s Web browser:

The malicious code, he says, checks the operating system version - as well as the Java Run Time Environment code – presented on the visitor’s computer, loading a payload delivery Flash file – Geoffrey.swf – if the visitor’s system is WinXP or Win7-powered.

The infection is also notable, he adds, because another file – icon.js – loads externally and interrogates the visitor’s computer for a wide variety of information – including details of which IT security/AntiVirus software that is running – which is then relayed to an remote Internet server.

Thanks to its research, AlienVault has extracted a variety of this interrogative information, including the following revealing screenshots:

AV

Blasco concludes that the number of state-sponsored incidents involving Southeast Asian Nations have been increasing in recent last months, especially when it comes to private sector (non-governmental) organisations.

“We have described a technique used by attackers to perform reconnaissance that gives them information about potential targets including software and Antivirus versions,” he says in his latest security posting.

This information can be used to perform future attacks on the victims. Being able to detect the Antivirus used by the victim within the browser opens new options when exploiting the system. The attacker can drop different payloads based on the detected Antivirus to evade detection,” he adds

Add comment


Security code
Refresh