Slashdot Mirror


Blackhole Exploit Kit Gets an Upgrade

wiredmikey writes "The popular Blackhole exploit kit, assumed to be created and maintained by an individual going by the online moniker of 'Paunch,' who continuously updates the browser exploit software, looks like it has just received another upgrade. The exploit works by infecting a user when they visit a Blackhole-infected site, and their browser runs the JavaScript code, usually via a hidden iframe. If the location or URL for the malicious iframe changes or is taken down, all of the compromised sites will have to be updated to point to this new location, making it hard for the attackers. To deal with this, the Blackhole JavaScript code on compromised sites now dynamically generates pseudo-random domains, based on the date and other information, and then creates an iframe pointing to the generated domain. Moreover, the kit's recent upgrade also added a new attack. According to Sophos, sometime in early June Blackhole was updated to include an attack that targets a flaw in Microsoft's XML Core Services, which remains unpatched. Unfortunately, the changes prove once again that the criminal economy online is alive and well."

13 of 43 comments (clear)

  1. Firefox + NoScript by Anonymous Coward · · Score: 4, Insightful

    Problem fecking solved. Nobody should be running without a script blocker in this day and age.

    1. Re:Firefox + NoScript by lostsoulz · · Score: 5, Interesting

      Broadly agreed, but t'Internet is a woeful mess of script upon script upon script. I use NoScript, Ghostery, AdBlock Plus and HTTPS Everywhere...but sometimes find well-known sites that still b0rk until I reconfigure an addon.

    2. Re:Firefox + NoScript by JDG1980 · · Score: 4, Insightful

      If you run NoScript, essentially every web site in existence is broken by default and has to be whitelisted. If you get into the habit of auto-allowing everything, you're no safer than you would be without it installed, and if you don't, then you have to manually spend 5 minutes picking and choosing which scripts you have to enable for the page to work.

    3. Re:Firefox + NoScript by Trilkin · · Score: 2

      More like 10 seconds. It's a compromise worth the time.

      --
      Nobody cares what the CAPTCHA for your post was.
  2. Before a knee jerk posts... by trifish · · Score: 5, Insightful

    Before a knee jerk posts "I use NoScript -- I'm safe!"...

    This doesn't mean that JavaScript is insecure. It just means there's an exploitable unpatched vulnerability in JS in some browser. The fact that this malware uses JavaScript + iframe doesn't mean JavaScript is inherently insecure or less secure than bare HTML.

    And now the worst news of all for you: the HTML engine (or any other portion) of the browser can and often does contain exploitable unpatched vulnerabilities. So even if you disable JavaScript you can get infected.

    The bottom, line the best way to protect yourself is honor the following three golder rules:

    1. Keep your browser and OS updated with security fixes.

    2. Don't visit suspicious websites and don't open suspicious email attachments.

    3. Use a good antivirus that monitors your internet traffic.

    Profit?

    1. Re:Before a knee jerk posts... by f3rret · · Score: 4, Insightful

      You don't know how plugins work with modern browsers. Please stop pretending that you do.

      Without the JS redirect, there is no avenue for infection. Period. NoScript will stop this, properly configured. Period. Because of the nature of the kit, most antivirus products WILL NOT protect you from the threat. Period.

      Yes this particular exploit (and any other JS based exploits, probably). Guy you are replying to said that while NoScript might protect you from JS based exploits, it does not protect you from exploits that targets elements not affected by NoScript or exploits aimed at NoScript itself.

      The internet is a dangerous place, sometimes bad stuff slips through the cracks. There isn't a silver bullet solution that will keep you 100% safe 100% of the time.

      --
      Admit nothing. Deny Everything. Make Counter-accusations.
    2. Re:Before a knee jerk posts... by plover · · Score: 2

      You're a couple posts behind staving off the knee jerks. However, the safety of NoScript isn't the primary reason I run it. It's the crap that third party scripts "add to browsing experience" that I find useless at best; distracting in most cases of advertising; and tracking sites that are actively harmful to my privacy as well as to the accuracy of the web in general because their results are used by marketers to manipulate search engine results via their SEO activities.

      And I would argue against your assertion that JavaScript is secure. The problem is that it's so complex, and that it interacts in so many different ways with browsers, that the many implementers have unintentionally created a seemingly limitless supply of security holes.

      --
      John
    3. Re:Before a knee jerk posts... by Viol8 · · Score: 2

      "The internet is a dangerous place"

      Not that you're overegging it at all. The internet may be many things but dangerous it isn't. Not until someone plugs a browser into an industrial robot.

      "There isn't a silver bullet solution that will keep you 100% safe 100% of the time."

      I've been using the internet for 20 years and the web since about 1995. I've never once had a machine become infected with malware or a virus despite never using a virus scanner though I will admit someone once hacked an ftp server I hadn't upgraded. Want to know my secret? Its called unix/linux.

    4. Re:Before a knee jerk posts... by Inda · · Score: 2

      NoScript. How can you view the WWW with that installed?

      I installed it. Visited a dozen of my favourite sites. Whitelisted half of them, because I trust them. OK so far.

      It's the new sites where the problems start. Google says, on the top result, I can convert XYZ online, using forms. Excellent. Only that functionality no longer exists. Maybe the site is broken. Maybe Google is mistaken. Maybe I'll look at the source. Maybe I'll try the next site.

      I'm struggling to think of the exact reason I uninstalled it; it all happened so fast. It was missing content; probably forms.

      I was writing JS back when it was nasty. I'm fine with the reasons people on Slashdot use NoScript. It does not pass the "Dad check" though. It makes for a crap browing experience. Sites should degrade nicely without JS, but they don't - why would they when 99.9% of people don't know their iFrame object from their multidimensional array?

      --
      This post contains benzene, nitrosamines, formaldehyde and hydrogen cyanide.
    5. Re:Before a knee jerk posts... by Anonymous Coward · · Score: 3, Insightful

      How do you know you have never had an infection if you don't occasionally scan? Exploits for Linux-based systems have been found in the wild before -- Red Hat releases patches on an almost daily basis. You are certainly /more/ secure than a Windows user, but the only truly secure system is the one without both power and network connectivity. You are advocating a poor security posture by suggesting that Linux users need not worry about infection.

    6. Re:Before a knee jerk posts... by plover · · Score: 3, Insightful

      Funny, I often wonder how so many people can view with the WWW without NoScript installed! Zooming up fake windows, continually scrolling sidebars, attack ads, "do you want to chat with a representative online" boxes, it seems like there are usually about three things to dismiss before even uncovering most content.

      However, I'd certainly agree that NoScript is not for the uninitiated. It doesn't pass the mom test, or even the wife test. Most people just want things to work, and are willing to put up with whatever crap they're served in order to get it. I'm willing to view the static content, and if there's something deeper to explore, I understand up front that I might have to whitelist a few things to get it to work. Note that you can configure NoScript to automatically permit scripts originating from "base 2nd level domains" (i.e. allow everything from *.foobar.com when you're on www.foobar.com), which generally enables local content to work just fine, while still preventing XSS nonsense. The only place where I commonly run into trouble is with video content, as it's generally hosted somewhere else like Vimeo or YouTube, and with third party SSO providers like Yahoo. In all, over many years of browsing I've added some margin of trust for about a hundred sites which seem to have taken care of most of those issues.

      --
      John
    7. Re:Before a knee jerk posts... by firewrought · · Score: 2

      This doesn't mean that JavaScript is insecure. It just means there's an exploitable unpatched vulnerability in JS in some browser. The fact that this malware uses JavaScript + iframe doesn't mean JavaScript is inherently insecure or less secure than bare HTML.

      This is the wrong way to see this. A markup language that generates a static DOM (from which a GUI is rendered) is inherently more secure than a programming language that has access to a large set of supposedly sandboxed API's in that, while both can have vulnerabilities, the latter has considerably more "surface" to attack. Exploits may leverage one-off, soon-to-be-patched bugs to do their nasty work, but--statistically speaking--these bugs are going to arise more often in the more complex piece of software, and it's going to keep happening so long as new browser code is being written. NoScript nets a huge surface reduction and big security win here.

      And now the worst news of all for you: the HTML engine (or any other portion) of the browser can and often does contain exploitable unpatched vulnerabilities. So even if you disable JavaScript you can get infected.

      This is a good reminder. An example would be the 2004 exploit in Microsoft's JPEG code. But it would be interesting to see stats about how often the rendering engine is a vector of attack. I'm thinking it's relatively rare (although part of that would be that JS gets more attention from black hats because it's more fertile ground to begin with).

      --
      -1, Too Many Layers Of Abstraction
  3. Re:Core XML Services by rbrausse · · Score: 2

    afaik Mozilla includes the expat parser