Feeds

Worms 2.0!

The Metasploit menace inside your firewall

High performance access to file storage

Examples of browser communication with a bindshell (behind a firewall) have been done by encapsulating and sending commands in HTTP. These commands echo valid JavaScript and HTML script tags. It literally uses the 'echo' command. The echoed instructions tell the browser to encode the bindshell response and use the response in a new request back to the attacker's web server. This allows the attacker to see the results of the shell commands.

Using the browser as a middleman, the attacker has two way communication. Also, because HTTP is used to send and receive data from the browser it is likely that a Firewall/DMZ will permit the traffic.

Could it work against search engines spiders?

It would depend on the extent to which the spider logic constructs the requests using JavaScript. If it is a fully functioning JavaScript implementation, there is a likelihood that the spider will be capable of Inter-protocol Exploitation just like web browsers.

We talked about web browsers loading the exploit from a website, but could this work with different file formats and software? For example Acrobat Reader comes to my mind for this advisory.

This is a new area of research and there are potentially more inter-protocol issues with web technologies. For one, AJAX can allow more flexibility than the methods discussed in the research. Also, different character sets have the potential to yield more tightly controllable Inter-protocol Exploits.

The recently published acrobat cross-site scripting vulnerability could potentially be used to launch Inter-protocol Exploits. Any issue that has the potential to force an application to make a request with controllable content could be used for attacks, provided it meets the requirements of encapsulation and error tolerance.

The advisory states that the vulnerability does 'allow remote attackers to inject arbitrary JavaScript into a browser session.' Provided there are no other restrictions it will be very similar to using a normal cross-site scripting vulnerability for Inter-protocol Exploitation.

I think it was Nimda that exploited both web servers and browsers to spread... does this approach could be used to install a worm on a webserver, then the browser of every visitor will load some Javascript to exploit a random website that will spread the worm to its visitors, and so on? And this time there is no need to exploit a bug in browsers

It is even simpler. If the attacker used an advanced cross-site scripting virus, the payload would be enough to launch the attack on Internal networks. For example the MySpace virus payload was executed one million times in 20 hours. Inter-protocol Exploitation and advanced cross-site scripting viruses are a dangerous combination.

How do you search for new bugs? How do you develop new attacks?

My work brings me into contact with a wide range of platforms and technologies. In recent times, developing BeEF has supported an interest in the dynamics of component interaction in complex, often eclectic, environments.

Interception proxies are a must when developing web attacks. The Odysseus and Burp proxies allow a lot of control over HTTP communication. Increasingly, I am finding the need for generic network proxies like Echo Mirage that hook into network function calls.

Another tool which I couldn't do without is netcat. It is simple and powerful - a great combination. ®

Wade Alcorn is a security researcher/consultant living in Brisbane, Australia. His permanent role at NGS Consulting is Principal Security Consultant. Further to consultancy engagements he has contributed various security tools and published vulnerabilities and white papers.

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.