Code Used To Attack Google Now Public
itwbennett writes "The IE attack code used in last month's attack on Google and 33 other companies was submitted for analysis Thursday on the Wepawet malware analysis Web site. One day after being made publicly available, it had been included in at least one hacking tool and could be seen in online attacks, according to Dave Marcus, director of security research and communications at McAfee. Marcus noted that the attack is very reliable on IE 6 running on Windows XP, and could possibly be modified to work on newer versions of IE."
The attack is very reliable on Internet Explorer 6 running on Windows XP ...
That's apparently what happened at Google late last year, when hackers were able to get into the company's internal systems
Google has employees running XP/IE6???
The only way I run IE6 nowadays is in a VM and basically just to test websites we're developing on local/trusted hosts. I wouldn't dare accessing anything with IE6 (especially with reputable sites being hacked and all).
All the legacy IE6 users I've met tend to be government, non-technical corporates or extremely pro-Microsoft shops that bet the farm on IE6 and wrote everything in IE6/ActiveX fashion.
This is a shocker!
If you can't mod them join them.
Seems like running IE4 on windows 95 has paid off....finally! Now if only active desktop worked properly...
That admin has a hot rack.
Help stamp out iliturcy.
http://praetorianprefect.com/archives/2010/01/the-aurora-ie-exploit-in-action/
Yawn, another unpatched MS browser exploit.
I hear there are several more for sale...
I'm not a network engineer or very astute when it comes to security, but I have to wonder why we (America) have our electrical grid online (accessible from say Hainan China) or really any sensitive area online and accessible from the internet, the benefits versus the liabilities seem way out of proportion.
The fact that a bit of code can compromise governments is a strong indicator that no one really knows what they are doing in said government, and also begs the question why isn't Microsoft held liable for these issues? Why do we even use Windows for Government systems?
Hackers are cutting edge people, the government seems to be dwelling in 1990's tatics and security.
"If any question why we died, Tell them because our fathers lied."
Who else suspects that Google is stepping up internal use of Chrome?
Next time somebody tells you that their organisation can't switch from Internet Explorer 6 because of legacy intranet applications, point out that virtually all of Europe switched from their own centuries-old currency to the Euro in less time than it's taking to get rid of Internet Explorer 6.
The following links to an example of using this vulnerability in Metasploit to compromise a user's PC, in essence what happened to users at Google and some 30 other companies via bad actors assumed to be Chinese Nationals: http://praetorianprefect.com/archives/2010/01/the-aurora-ie-exploit-in-action/
While it is writen to say could possibly be modified to work with newer versions of IE, I find that a little unlikely considering the more recent track record of IE's beefing of security. Unfortunately the people writing these articles tend to have bias towards IE as a whole and not just against the mess that IE6 was.
For those who seek perfection there can be no rest on this side of the grave.
or 5.5, because it is easier to find in a downloadable form
Can you give us some of those "good reasons"?
Try it... about 3 of the web pages in the world will actually display... Two of them are probably in Ugandan.
~/ssh slashdot.org ssh: connect to host slashdot.org port 22: too many beers
See how to mitigate the IE6 vulnerability using Group Policy here http://www.grouppolicy.biz/2010/01/how-to-mitigate-kb979352-a-k-a-google-china-security-vulnerability-using-group-policy/
Anyone else find it amusing that Google has its very own web browser yet IE6 is apparently still widely deployed on their desktops?
Hopefully now that there's been this wide scale attack on major corporations, all IT departments can finally force dropping the browser for security reasons.
I can not believe that Google, with all of its vast resources and years online, that a few email accounts getting hacked all of sudden set them off to pull out of China. They are pretending to the press as if this is something special or new on the internet that China is doing, or that these couple of "attacks" from China are too much. Google has got to be just hammered by Chinese attackers, and they make it sound like no other gmail account has ever been hacked. I bet they get thousands of illegally hacked email accounts a day for all kinds of people, from all over the World, by all kinds of means. Hell, I blocked Chinese ISP blocks and cut down on my little server being attacked and spam by about half.
So, what in particular is suddenly special about this one in relation to China?
Living in Chile
It doesn't matter which browser you're using ...
If you're logged in as Administrator or a user with administrative user rights/access, while surfing the web, checking your email, etc. --> you're vulnerable.
Until users change their behavior and start using least-privilege accounts while surfing the web, it's wrong to blame the browser.
Microsoft even says it in their security advisory kb 979352: An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
And this applies to any OS: Linux, Windows, Mac OS, etc.
Rootkit - contrary to what its name may imply, a rootkit does not grant a user administrator privileges, as it requires prior admin access to execute and tamper with system files and processes.
As long as after work you keep your skills up on modern tech, taking the customer's money to do the stupid thing is a wise course. Advising them, giving the chance, telling them that it's stupid is the moral choice but if not asked there's no shame in doing what you can with what you've got.
Actually there's an opportunity here - but I'm not going to enumerate it because then you'll be competing with me.
Help stamp out iliturcy.
YES. Finally.
Kill IE6. Kill it with fire.
every time i shoot at funny, all i hear is whoosh
Comment removed based on user account deletion
This is such a dumb American attitude, I hope your Company can work without its intellectual property and computer systems. I assume you dont have insurance as well!
Everyone knows girls need longer.
MMO Quests are like orgasms:
You may solo them, I prefer them in a group.
So you are the one that has sales demanding we support old browsers.
Right men, we got its location, capture is imminent.
Anyone want to set up a poll what do with him?
It better have a cowboyNeal option.
MMO Quests are like orgasms:
You may solo them, I prefer them in a group.
Making a country secure is easy.
Everyone mandatory implanted ID that can't be removed or altered without dying, say a chip implanted in the brain that extends barbs.
Tracking posts everywhere. All travel recorded and logged.
1 computer system, can only be activated with ID. No 3rd party software let alone your own stuff, every access is recorded and logged for 10 years minimum.
Should I go on? It is easy to implement and will eliminate all security problems. Feel free to take these ideas for when you run for election.
Security is easy, freedom and security ain't. To be honest, I prefer my government to be a bit slow and inefficient. The alternative is far more scarier.
People are so upset about that illegal immigrant who got shot on the tube when he tried to run. I would be far more worried if that guy had NEVER been able to make it into the country or if they had shot the right guy with a sniper efficiently. The whole mess shows there is still freedom. Freedom to get shot for sure, but also the freedom for journalists to still find leaks.
MMO Quests are like orgasms:
You may solo them, I prefer them in a group.
"Microsoft held liable for these issues? Why do we even use Windows for Government systems?" - by koan (80826) on Friday January 15, @11:07PM (#30787586)
I feel that MS ought to ship a system TOTALLY "closed off", personally (or, @ least, security hardened, per the guidelines I set below)
I do show guidelines for security that DO actually work no less there!
Simply due to the usage of "layered security", conscientious patching, & knowing when and when NOT to use things like JAVASCRIPT + FAR MORE!
(E.G.-> AND, even a "return to antiquities teachings" (per Ozymandias of "The Watchmen" in that quote) by using things like HOSTS files for example, which is 1970's thinking (but, it works like no tomorrow for BOTH added speed, but more importantly, for ADDED LAYERED SECURITY, especially nowadays...)).
Then, when the END-USER elects to "turn those features" on again (or rather, the protection vs. them, off)? He/She, as said end-user, assumes the responsibility for what happens... NOT MS!
(MS ships these OS' nowhere NEAR where they can be 'security-hardened' to, & probably so "everything just works" + so it's easier to "mass deploy" quickly, imo @ least, as to the "WHY" of why MS' OS are so damned 'wide open' outta the box/oem stock!)
----
"Hackers are cutting edge people, the government seems to be dwelling in 1990's tatics and security" - by koan (80826) on Friday January 15, @11:07PM (#30787586)
Ah, ACTUALLY in my experience (more than a year professionally dealing with their junk, disassembling & tracing it, & removing it etc. et al as part of my job duties when level 1 folks failed vs. them)?
They're MOSTLY "script kiddies" actually...
I.E.-> Using & REUSING the stuff the TRULY "cutting edge" people's (hacker/cracker) designs & work + tactics, over & over again, prefab style. Sometimes with only SLIGHT variations...
HOWEVER, for security THAT ACTUALLY WORKS (with a testimonial I'll supply, just one of MANY like it, from those that applied my guide's techniques/methods/suggestions)?
YOU DO THIS:
====
HOW TO SECURE Windows 2000/XP/Server 2003/VISTA/Server 2008/Windows 7, & make it "fun-to-do", via CIS Tool Guidance (& beyond):
http://www.tcmagazine.com/forums/index.php?s=fc2d534ea11b15071b6ffc04ad948f00&showtopic=2662
====
A testimonial to its effectiveness, for a year straight no less of uptime (& beyond, this reply is quite old actually):
----
PERTINENT QUOTE(s)/EXCERPT(s):
http://www.xtremepccentral.com/forums/showthread.php?t=28430
"...recently, months ago when you finally got this guide done, had authorization to try this on simple work station for kids. My client, who paid me an ungodly amount of money to do this, has been PROBLEM FREE FOR MONTHS! I haven't even had a follow up call which is unusual. Now I don't recommend this for the average joe, but it if can work for a kids PC it can work for anything!"
and
http://www.xtremepccentral.com/forums/showthread.php?s=10f9ba9ad5ff990aaae1e7ec91f593a2&t=28430&page=3
"Its 2009 - still trouble free! I was told last week by a co worker who does active directory administration, and he said I was doing overkill. I told him yes, but I just eliminated the half life in windows that you usually get. He said good point. So from 2008 till 2009. No speed decreases, its been to a lan party, moved around in a move, and it still NEVER has had the OS reinstalled besides the fact I imaged the drive over in 2008. Great stuff! My client STILL Hasn't called me back in regards to that one machi
...to code.google.com.
Under capitalism man exploits man. Under communism it's the other way around.
Yawn, another unpatched MS browser exploit.
For two-versions-ago of a browser on two-versions-ago of the operating system (that MS has tried to end-of-life repeatedly). In other news, Roman centurions' helmets have been found to provide woefully inadequate protection from rocket-propelled grenades...
Odd, innit. When it comes to 10% Linux and 10% Mac making 20% of a market, they can be ignored.
But when it comes to 20% using IE6, it can't.
How's that happen?
Another odd one. People keep bitching that GIMP will never be used because it's name is silly and OOo will never work because it doesn't do what Office does. Yet here we have someone relating the story that businesses don't care about it doing the wrong thing, they've worked around it.
Seems like they shouldn't care about GIMPs name, or OOo's lack of the dirty corners of Office.
Much as I appreciate a +2 Funny for an A.C., I have to confess I didn't even realize the endeavor shouldn't take all day.
Perhaps I failed to emphasize correctly. Let me try again.
If it was up to me to do things I enjoy , I would probably play WOW, eat pizza and masturbate all day long. Happy now?
You're doing it wrong.
Everyone knows girls need longer.
Everyone knows girls need longer.
You underestimate the power of the Slash Dot, General.
Development is programmable; Discovery is not programmable. (Fuller)
Microsofts greatest innovation is to steal it. Haaaaaaaaaaaaaaa Haaaaaaaaaaaa Haaaaa And their totally SHIT browseR/s.... I have more security if I pull down my pants and hang my bare arse out of a tree at night in the park. LOSERS. I hate microsoft - I hate microsoft - I hate microsoft.... Traaaa Laaaaaa Laaa Laaaaaaaaaa
.
Voting up, Voting down - If I really gave a fuck about your approval or not, I'd come and ask you.