Saturday, 9 August 2014

Millions of WordPress & Drupal websites are vulnerable to DoS Attack

Users running the website on a self-hosted WordPress or on Drupal are strongly recommended to update their websites to the latest version immediately.

A moderately critical vulnerability was discovered in the way Drupal and WordPress implement XMLRPC, which can lead an attacker to disable your website via a method known as Denial of Service (DoS).

VULNERABILITY RESULTS IN DoS ATTACK
The latest update of WordPress 3.9.2 mainly addresses an issue in the PHP’s XML processor that could be exploited to trigger a DoS (denial of service) attack. The vulnerability affects all previous versions of WordPress.

The XML vulnerability was first reported by Nir Goldshlager, a security researcher from Salesforce.com's product security team that impacts both the popular website platforms. The issue was later fixed by Michael Adams and Andrew Nacin of the WordPress security team and David Rothstein of the Drupal security team.

ATTACK MAKES YOUR WEBSITE COMPLETELY INACCESSIBLE
The vulnerability makes use of a well-known cyber-attack, XML Quadratic Blowup Attack. When executed, it has the capability to take down the whole website or server almost instantly, with the use of only a single machine.

The XML vulnerability can cause complete CPU and memory exhaustion and the site’s database to reach the maximum number of open connections, and as a result, the vulnerable site and server become unavailable for a period of time, hence affecting Availability of your website.

In short, when the vulnerability is exploited, your website and web server can become totally inaccessible.

WORDPRESS AND DRUPAL USED BY MILLIONS OF WEBSITES
The issue is actually serious because WordPress and Drupal is being used by millions of websites. The recent statistics from the World Wide Web Consortium (WC3) says that WordPress alone powers nearly 23% of the web, and over one million websites used by Drupal.

WordPress is a free and open source blogging tool and a content management system (CMS) with more than 30,000 plugins, each of which offers custom functions and features enabling users to tailor their sites to their specific needs, therefore it is easy to setup and use, that’s why tens of millions of websites across the world opt it.

HOW EXPLOIT WORKS

As explained earlier, the XML vulnerability makes use of an XML Quadratic Blowup Attack, which is almost similar to a ‘Billion Laughs Attacks’ that allows a very small XML document to completely disrupt the services on machine in a matter of seconds.

The XML Quadratic Blowup Attack exploits the use of entity expansion, instead of using nested entities inside an XML document, it replicates one large entity with tens of thousands of characters over and over again.

In this type of attack, a medium-sized XML document of nearly two hundred kilobytes in size could require within the range of hundreds of megabytes to several gigabytes of memory. That if exploited by an attacker, could easily bring down an entire website or web server.


Friday, 1 August 2014

Introducing Operation Emmental: A new banking malware causing havoc around the world


A new piece of banking malware called "Operation Emmental" is targeting banks around the world, particularly in countries like Switzerland and Austria.
Operation Emmental, apparently so-named due to the full-of-holes security systems of many major banks, is designed to bypass the generic two-factor authentication mechanism that banks employ to ensure that their customers' money remains safe.
The Operation Emmental attacks are spread using phishing emails, which masquerade as legitimate mail in order to coax a user into clicking a booby-trapped link.
The attacks bypass session tokens sent by a bank's remote server to users' mobile devices via text messaging. Customers preferring to bank online are required to mandatorily enter these session tokens, to start new sessions and verify/authenticate the login credentials.
The infrastructure required to pull the attack off is not inconsequential, however. The attackers need a Windows malware binary, a malicious Android app sporting various banks' logos, a rogue DNS resolver server, a phishing Web server with several fake bank site pages, and a compromised C&C server to successfully pull off an Operation Emmental strike.
"Emmental is an attack that has very likely evolved over time," according to Trend Micro. "The fact that the most salient part of the attack—the PC malware—is not persistent likely helped the attackers keep a low profile."
"We believe this allowed them to use different infection strategies, not just through emails".

Banking malware Zeus caused chaos over the years it was active, infecting 3.6 million PCs in the United States alone, and stealing millions of pounds from banks around the world, including in the UK. It is most often used to steal banking information through man-in-the-browser keystroke logging and form grabbing. It is also used to install the CryptoLocker ransomware
More recently, a new premium piece of malware called Kronos has begun to be advertised on a Russian cybercriminal forum, it's capable of stealing credentials from browsing sessions in Internet Explorer, Mozilla Firefox and Google Chrome by using form-grabbing and HTML content injection techniques.