ABE blocked a potential malware

Discussions about the Application Boundaries Enforcer (ABE) module
Salvy
Posts: 1
Joined: Fri Sep 11, 2009 4:51 pm

ABE blocked a potential malware

Post by Salvy »

Hi today I was visiting this site http**://www**.chilenosencalifornia**.c*om/ and got a warning from ABE regarding it filtered a request from :

Code: Select all

ht**tp://***double.boubleba**relled.ws**/FrMal
After a bit of research I found out that piece of code is being used on exploited websites to distribute malware.

I'm curious how ABE determined it was a malicious code?

PS: Thanks for your great work Giorgio !
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3365
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

Re: ABE blocked a potential malware

Post by GµårÐïåñ »

Because it attempts to make a local access to save the malware to be executed later. Since your standard ABE system ruleset denies such access to local system, it was thwarted.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3
Post Reply