Feeds

Credit-card hackers stung with bogus IIS 'sploit

Dumb and lazy

  • alert
  • submit to reddit

5 things you didn’t know about cloud backup

What happens when you float a counterfeit IIS hole in a carder chatroom on IRC, tantalizing its young denizens with a quick, easy score? Do they proxy up, patiently enumerate the site, grab banners, analyze what they're up against and carefully plot an attack? Or do they rush into the trap like so many elite lemmings?

That's what CardCops' Dan Clements and Penetrationtest.com's Karsten Johansson wanted to know. So they set up a fake IIS directory .../InetPub/scripts/_private on an Apache server (yes, Apache), with a fake security hole, seeded a couple of IRC carder channels with the news, and watched.

Within 24 hours approximately 200 cyber warriors had bitten the hook, and not one figured out that they were stuffing around on a Linux box. A quick banner check, or even a quick check with Netcraft, was all they'd have needed to see what they were onto. No one tried to own the machine; and a surprising number didn't even bother to go through a proxy.

Scanners were employed but not by many; a handful appear to have used Nmap and/or Nessus, and two appear to have used an older version of Gaa Moa's HTTP Exploiter (GME) which contained a number of recommended directory paths until GM decided to release it without them in later versions to discourage the utterly clueless.

A few visitors showed initiative and attempted a couple of known exploits with Front Page Extensions, continuing to trust that they were on an IIS server. Also "a few people recognized the apparent directory traversal attack that we emulated, and attempted to read other directories using our 'exploit,'" Johansson said.

In the bogus IIS directory were a couple of .exe files and an .xls spreadsheet with fake CC numbers. "Roughly half of the of the people who connected actually downloaded the xls file with the fake credit card numbers in it. There were a lot of 'look but don't touch' connections, and some people who focused on the .exe files instead," he added.

"Most of them simply downloaded the files in the exploited directory. A few then tried to look at the primary Web page but did not return once they received the fake 404 error. A fair number of them did manage to find the fake login screen, though, but nowhere near as many as I expected."

A couple also requested favicon.ico -- the little custom icon added to a Web browser's favorites list. Since servers log the requests, an attacker can often learn where the logfiles are located, which can in turn lead to additional exploitation. Again, immediate failure was not followed up with curiosity.

A number looking for /.htpasswd ended up looking for /.htpasswrd , /~passwrd , /~.passwrd /htpasswrd /htpasswd, etc. (The circumflex character merely refers to the home directory, so it's clearly useless unless there's a user named 'htpasswrd' on the system.)

It was interesting that the carders exhibited so little imagination, curiosity and patience. If they couldn't get what they wanted easily, either by trying some stock exploit or running some automated progie, they gave up without a struggle. Those who attempted additional exploits and failed seemed not to ask themselves why they failed.

Of course, by selecting IRC for a venue one is necessarily selecting less sophisticated IP warriors. But there's a reason for this. CardCops' Clements reckons that the vast majority of CC fraud can be attributed to the cumulative effects from vast batallions of unskilled opportunists, which the carder channels represent. It makes sense to expect competent blackhats to have better things to do than whack minor pr0n pay-sites and Mom & Pop e-commerce sites for easy pickings.

CardCops, a CC fraud-prevention Web site, "believes in engaging hackers and carders on their own turf...where we can define the location of the virtual battlefield," Clements says.

"It's a warning to kiddies: 'it's not as easy as you think.' We're letting them know that we'll be in their virtual world; and they'll always have to wonder if someone's playing with them."

He's hoping that by publicizing the results of the joint sting with Penetrationtest.com, the teeming millions of would-be cyber fraudsters will get a sense of how easily they can be jerked around, deceived, even trapped -- and perhaps be deterred.

At least until they figure out what a banner check is. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
JLaw, Kate Upton exposed in celeb nude pics hack
100 women victimised as Apple iCloud accounts reportedly popped
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.