Showing posts with label DNS. Show all posts
Showing posts with label DNS. Show all posts

June 18, 2008

New Home Router Hacking Program

A newly discovered Trojan in the wild hacks into home wireless routers and changes their DNS settings to point to the attacker’s rogue DNS server. The malware is a new variant of the DNSChanger Trojan that has been circulating around the Internet, according to researchers at Secure Computing who have been studying it.

Home routers make easy prey because many users don’t lock them down, and even use their default passwords for authentication. There’s been plenty of research in this space over the past year, everything from drive-by hacks to botnet infections to DNS rebinding. (See Attackers Use New 'Call-Home' Method to Infiltrate Home Networks and RSA Session Features Live Linksys Router Hack and The Hack Your Home Router Challenge.)

Sven Krasser, director of data mining research for Secure Computing, says the new DNSChanger Trojan attack also indirectly infects any machine that connects to the router. “This is the first time we’ve seen on [a] wide basis that the computing resources of the wireless router are part of the attack,” he says. “It also [affects] machines that are not directly exploited -- ones that are connecting to the router.”

The Trojan executes brute-force attacks on the Web interface of a router that only uses basic authentication -- and it’s mostly going after D-Link and Linksys routers so far, according to Krasser.

Secure Computing says the attackers behind the malware are the infamous Zlob malware authors.

Krasser says the attackers can send a victim to any Website, and most times return the correct site back to the user to evade detection. Other times they redirect a user to their own spoofed pages, he says. He says phishing is a likely goal of the attackers.

He says it’s possible that attackers could kick the attack up a notch and add put their malcode onto the routers, such as zombie code. Secure Computing researchers have posted some screen shots and an analysis of the Trojan in their blog.

Never use default passwords in home routers, Krasser says, and keep it updated.

June 8, 2008

Students Hack Windows Cardspace

Students at the Ruhr University of Bochum, Germany, say they have found a way to steal security tokens in Microsoft's new CardSpace authentication framework. Attackers can apparently get access to protected, encrypted user data – such as passwords, credit card numbers, and delivery addresses – when they are transmitted. CardSpace (formerly InfoCard) is the successor to Passport. In both architectures, users' personal data are stored locally on the user's system. Depending on the web site, users can decide which data they want to transmit. CardSpace is designed to make classic passwords a thing of the past, by replacing them with digital certificates that may be self-signed or signed by an authoritative CA such as Verisign.


According to the report, anti-DNS pinning, DNS rebinding, DNS spoofing, and drive-by pharming are apparently all successful ways to steal transmitted tokens. Attackers basically need to manipulate the user system's name resolution so that the token for the browser-based CardSpace is sent to the attacker. To this end, attackers manipulate the DNS entries on a router, for instance by means of cross-site request forgery, and send the attacked user to a malicious name server. If the attacker manages to switch name resolution during an authentication process so that the victim lands both on a shop's genuine CardSpace website and on a malicious forgery, the attacker then gets the token. During the token's validity, attackers can then pretend to be the user in question when they go shopping.

The students have created a demo server that they claim demonstrates the problem. To reproduce the demonstration, you should change your own DNS settings and install an untrusted certificate. In our test at heise Security, we could not get the demonstration to run, however. Microsoft has apparently already been informed of the problem and is working on a solution. In their report, the students propose improving Same Origin Policy as a security function for browsers.

May 19, 2008

Dear God

Recently, I was browsing government websites to see if there were any new articles to read. However when I came to www.NSA.gov (National Security Agency), their website was offline. Baffled by this National Security Issue,  seeing as how the NSA is supposed to be the pinnacle of Intelligence and Technology, I decided to do some digging.

So who was the "Super hacker" that executed such a technologically advanced, planning intensive attack upon the US government? Well, as it turns out the super hacker was a incompetent mole. No, not a double agent. Someone who was hired,  because there was extra room in the Budget.  DNS misconfiguration in my NSA? Its more likely than you think.

              First, a web server was running on the same computer or the same IP address as one of the so-called authoritative name servers for nsa.gov. The authoritative name servers are the primary and secondary servers that translate the web addresses humans understand (i.e., NSA.gov) to machine-readable IP addresses (in the NSA.gov case, 189.182.93.126).

             Moreover, the primary and secondary authoritative name servers were both downstream from the Qwest edge access router in Washington, D.C. They should have been separated topologically within the network infrastructure, according to McPherson.

Come On Guys, thats basic network design. If the Top Security Agency can't design a network properly- what does that say about our national network infrastructure.

April 28, 2008

Sweet Tools Suite

Recently I came across a very versatile tool developed by the Crazy Germans over at http://www.gaijin.at/. The Name of the suite is E-Toolz. Basically, It is a web-developers dream.
Ping,Tracert,DNS,HTTP-Header, Domain Dossier, Mail-Checker, And Time Server Check.
Forget the days of spending 30-45 minutes jumping between sites, with E-Toolz- Its all at your fingertips.

Also- As a sidenote: Google Translate has some issues with German Emails.

The programme eToolz are the main Internet and network programs such as Nazi lookup, Ping, Traceroute and Whois united.

Wow! German Emails Are Now Nazis?!