Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le avril 24, 2012, 23:00:22

Titre: [SecListe]OS X Mass Exploitation - Why Now?
Posté par: igor51 le avril 24, 2012, 23:00:22
OS X Mass Exploitation - Why Now?

<P> Market share! It’s an easy answer, but not the only one. </P> <P> In 2011, Apple was estimated to account for over 5% of worldwide desktop/laptop market share. This barrier was a significant one to break - Linux maintains under 2% market share and Google ChromeOS even less. This 15 year peak coincided with the first exploration by the aggressive FakeAv/Rogueware market targeting Apple computers, which we discovered and posted <a href=http://www.securelist.com/en/blog/6178/Odd_FakeAv_Marketing target=_blank>in April 2011</a> and later <a href=https://www.securelist.com/en/blog/6211/Rogueware_campaign_targeting_Mac_users target=_blank>in May 2011</a>, which no longer seem to be such an odd coincidence. Also, the delay in Apple malware until now most likely was not because Apple exploits were unavailable, or because the Mac OS X system is especially hardened. The 2007 "Month of Apple Bugs" demonstrated that the Mac OS X and supporting code is full of exploitable flaws. Safari, Quicktime, and other software on Apple devices is regularly exploited during pwnage contests, but widespread cybercrime attention hadn’t caught on until this past year. </P>  <P> At this point, we still don't know who is behind Flashfake, so we don’t know for sure that they were the same Mac OS X FakeAv/Rogueware group. Speculating that eastern euro-cybercrime is behind the botnet would be a pretty confident way to go right now. There are known groups from the region that have succeeded at wringing ad revenues from traffic hijacking. We don't believe that other sensitive data has been targeted. And the exploit distribution URLs that we are aware of have only targeted mac users. These factors limit the operational and technical needs of a financially motivated cybercrime gang. </P> <P> In a sense, it would appear that their activity was somewhat similar to the Koobface or Tdss gangs. They haven't commited large unique financial crimes to attract the attention of law enforcement, and their malware contains hooks and other code to perform more sophisticated banking crime than search traffic hijacking, but they most likely were looking to make a multitude of small financial gains. On the other hand, thankfully, Apple hasn't given these guys ample notice to make their run. There can be plenty of money in that business - it is estimated that the Koobface guys ran off with millions after Facebook "outted" their operation under investigation. But based on the domain registrations we have examined, the individuals are not quite so public and they are hiding their identities while they hijack search engine traffic. The malware itself injects a number of hooks into running applications, much like the Zeus, SpyEye, and other spyware. If these were used for financial crimes, the group operating this botnet would need to organize money mules and accomplices to launder their stolen money, which would grow the group and attract the attention of other authorities. </P> <P> On the technology side, Java is a big part of the puzzle. Although the Trojan is called Flashfake because users were being convinced to install the malware as an Adobe Flash update, more recent versions of the malware were being installed via client-side Java exploitation.  </P> <P> Three vulnerabilities were targeted with client-side exploits, none of them were 0day, which seem to have become much more difficult to come by. Besides, this set worked just as well for these operators. It is interesting to note the duration of time from the original Oracle Java security update to the Apple Java security update, and when in that timeframe the release offensive security research publicly appeared. And, when were Metasploit open source exploit modules were released targeting the related Java vulnerabilities? The windows of time may be alarming - these are not 0day exploits, but Apple simply hasn’t released patches, leaving their customers exposed to the equivalent of known 0day exploits. </P> <P>  <a href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0507 target=_blank>CVE-2012-0507</a> </P> <P>  2012-02-15 Oracle patches <a href=http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html target=_blank>Atomic Reference Array vulnerability</a>  </P> <P> 2012-03-10 First Itw exploits targeting the vuln  </P> <P> 2012-03-30 Metasploit developers  <a href=https://community.rapid7.com/community/metasploit/blog/2012/03/29/cve-2012-0507--java-strikes-again https://github.com/rapid7/metasploit-framework/commit/f069a3222359908afec6c6366c0c27244cc18cb6 target=_blank>add Java atomicreferencearray exploit module</a>  </P> <P> 2012-04-03 Apple <a href=http://support.apple.com/kb/HT5228  target=_blank>patches their code</a>  </P> <P><a href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544  target=_blank>CVE-2011-3544</a> </P> <P> 2011-05-12 <a href=http://www.zerodayinitiative.com/advisories/ZDI-11-305/ target=_blank>Reported to vendor</a>  </P> <P> 2011-11-18 Oracle <a href=http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html target=_blank>patched their Java SE</a>  </P> <P> 2011-11-30 Metasploit developers <a href=https://community.rapid7.com/community/metasploit/blog/2011/11/30/test-results-for-javarhino http://schierlm.users.sourceforge.net/CVE-2011-3544.html target=_blank>add "Rhino exploit" module</a>  </P> <P> 2011-11-30 Krebs reports operational Blackhole site with the    <a href=http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/ target=_blank>new Java exploit</a> </P> <P> 2012-3-29 <a href=http://support.apple.com/kb/HT5045 target=_blank>Patched by Apple</a>  </P> <P> <a href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5353 target=_blank>CVE-2008-5353</a>  </P> <P> "Deserializing Calendar objects" </P> <P> 2008-08-01  Reported to Sun with <a href=http://slightlyrandombrokenthoughts.blogspot.com/2008/12/calendar-bug.html target=_blank>first instance of the vulnerability</a> </P> <P> 2008-12-03 Sun patches their code  (Sun link down) </P> <P>  2009-05-15 Apple <a href=http://support.apple.com/kb/HT3632  target=_blank>patches MacOSX code</a>  </P> <P> 2009-06-16 Metasploit developers <a href=http://dev.metasploit.com/redmine/projects/framework/repository/changes/modules/exploits/multi/browser/java_calendar_deserialize.rb target=_blank>add Java deserialization exploit</a>  </P> <P> Also on this list <a href=http://dev.metasploit.com/redmine/projects/framework/repository/entry/modules/exploits/multi/browser/java_signed_applet.rb target=_blank>is a lame exploit</a> described as a signed applet social engineering trick.  </P> <P> I'd prefer to call it the "the terribly confused user presented with the Java 'do you want to trust this applet?' dialog and will run anything you present them" gamble. It first became a part of the Metasploit exploit module list on 2010-01-27. Basically, these guys present the user with a file that the user thinks is a JavaUpdate provided by Apple Inc themselves, which they grant trust to perform any action on their machine. The downloader will then communicate with a couple of sites to register and download new Flashfake components. These components in turn, collect the system UUID and timestamp, then auto-generate with a crypto algorithm a set of C2 domains, along with maintaining a list of hard coded domains. A couple of the newer components inject into running processes on the system hooking software functionality and hijacking traffic, much like past TDS malware. </P>
Source: OS X Mass Exploitation - Why Now? (http://www.securelist.com/en/blog/208193490/OS_X_Mass_Exploitation_Why_Now)