Are we secure here?

General discussion about the NoScript extension for Firefox
Post Reply
luntrus
Senior Member
Posts: 237
Joined: Sat Mar 21, 2009 6:29 pm

Are we secure here?

Post by luntrus »

Hi malware fighters,

It is an advanced attack: http://isc.sans.org/diary.html?storyid=7867
Hackers are using it on the popular BitTorrent site IsoHunt.com at the mo , so block these from your OS:
193.104.22.0/24 and 89.149.236.46 this was already blocked 193.104.22.0/24

PDF-files have become the hacker-tool of sorts and this is proven by new advanced attack. The shellcode used in this attack was only 38 bytes large. While the same heap spraying technique has been used inside other exploits, the second part of the shellcode has been added as another object to the PDF document. At first the code seems to be corrupted, but then Adobe Reader will open the whole of the document into memory, as well as the corrupted code. According to Bojan Zdrnja the benefits for the attacker are crystal clear. He easily may change what the exploit is to perform, without the first part of the shellcode needs any change to it.

This will make automatic analysis with a Javascript Interpreting Tool for added malcoded JavaScript impossible. Research has found up two hidden binairies and also that the PDF doc has all aboard to take over a machine completely. No "extra's" are to be downloaded. "Not only is this an example of a malicious PDF-document with an advanced payload, but also to show to what trouble malcreants will go to circumvent detection from av vendors and victims alike", according to the ISC-handler.
Are we NS-users secure against this?

luntrus

P.S. Anyway Adobe is now going for silent uploads a la GoogleChrome, hoping some added obscurity will also add some added security. At the moment I hope they will patch this one real soon. For a while I will use an alternative reader...

Damian
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.3 (KHTML, like Gecko) Iron/4.0.227.0 Chrome/4.0.227.0 Safari/532.3
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Are we secure here?

Post by Giorgio Maone »

NoScript protect you against silent attacks from websites you don't know/trust, since all plugins included Acrobat are disabled by default on unknown/untrusted sites.
You can further harden this protection by checking NoScript Options|Embedded|Apply these restrictions to trusted sites as well, which will disable all the plugin content unless you specifically enable it by clicking on placeholders.

However nothing can protect you against social engineering attack, i.e. making you voluntarily open a certain PDF file either from a web page or from an email message.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6 (.NET CLR 3.5.30729)
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Are we secure here?

Post by therube »

Disable JavaScript in Adobe.
Update when they release the update.
(Keep on your toes for the next exploit against Adobe.)

Adobe.com CVE-2009-4324: Security Advisory for Adobe Reader and Acrobat
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.6) Gecko/20091206 SeaMonkey/2.0.1
Alan Baxter
Ambassador
Posts: 1586
Joined: Fri Mar 20, 2009 4:47 am
Location: Colorado, USA

Re: Are we secure here?

Post by Alan Baxter »

therube wrote:(Keep on your toes for the next exploit against Adobe.)
RSS feed: http://blogs.adobe.com/psirt/atom.xml
Foxit Software - Foxit Reader 3.0 for Windows
Disable JavaScript in Foxit Reader
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.7) Gecko/20091221 Firefox/3.5.7
User avatar
computerfreaker
Senior Member
Posts: 220
Joined: Wed Sep 16, 2009 10:03 pm
Location: USA

Re: Are we secure here?

Post by computerfreaker »

Alan Baxter wrote:Foxit Software - Foxit Reader 3.0 for Windows
Disable JavaScript in Foxit Reader
Worse.
http://security-labs.org/fred/docs/pacs ... d-full.pdf (ironically a PDF talking about PDF vulns), page 105:
A word about the Readers
* Adobe Reader: each version has new (useful?) features...
* Obvious security is well handled
* Blacklist security
* Foxit Reader: many features are supported... with no security at all
* Preview, poppler: minimalist viewers with few supported features
I, for one, have dumped Foxit in favor of Sumatra PDF Reader, another minimalist viewer.
IMHO, fewer features means a smaller attack surface, which translates into fewer vulns.
With great power comes great responsibility.
Learn something new every day, and the rest will take care of itself.
Life is a journey, not a destination. Enjoy the trip!
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6
Post Reply