ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Cybercrooks get better at concealing code

Joris Evers CNET News.com

Published: 19 Apr 2007 10:53 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cybercrooks who rig websites to break into PCs are getting better at hiding their malicious code, a security expert said on Wednesday.

Increasingly the actual code, often JavaScript, used to attack PCs is hidden in Flash animations or scrambled, so that anyone who examines the source of a page can't easily identify it, said Jose Nazario, a senior software engineer at Arbor Networks, in a presentation at the CanSecWest security confab.

"Their obfuscation tools are primitive but effective," Nazario said. "They use obfuscation to avoid simple signatures," he said, referring to security techniques based on signatures to detect malicious websites. Signatures are fingerprints of known attacks.

Read this

Fishing for Deepfish

"Are any ZDNet UK readers beta-testing Deepfish? If you are, we'd love to hear what you think of it so far..."

Read more +

Web attacks have become commonplace. Tens of thousands of websites attempt to install malicious code, according to StopBadware.org. The sites, the bulk of which are compromised sites, often drop a Trojan horse or other pest onto a PC through a security hole in the web browser.

Many attacks use JavaScript. Initially miscreants used plain JavaScript in their attacks, but that has changed, Nazario said. He has spotted an encoded script function called "makemelaugh" that downloads a Trojan horse that captures bank information, and a Paris Hilton Flash animation that installs a tool that makes a PC part of a botnet.

Attackers also are trying to outsmart security pros by programming malicious sites to load their malicious code only once on the same PC, Nazario said. Furthermore, a new toolkit called NeoSploit identifies the browser and is packed with security exploits to launch the proper attack, he said.

There are things security professionals can do to investigate attacks, Nazario said. "Bad guys are limited by the fact that JavaScript has to be decoded to be used by the browser. As long as you can analyse it outside the browser, you can figure out what it is going to do," he said.

The scrambled code can be made legible since it typically uses simple Base64 encoding for obfuscation and not actual encryption, Nazario said. He suggested NJS, SpiderMonkey and Rhino as tools to investigate script code. Flash files can be analysed using a program called Flasm, he said.

Malicious JavaScript can be embedded in a web page and will typically run without warning when the page is viewed in any ordinary browser. Attackers could try to lure you to their own rigged website. But an attack could also lurk on a trusted website by exploiting a common flaw known as cross-site scripting.

To shield against malicious JavaScript, web surfers can disable JavaScript, but that can affect the functionality of many websites. An alternative is to use security tools that have blacklists of known bad sites, such as McAfee's SiteAdvisor or Google's Toolbar or Desktop software.

Another alternative is Exploit Prevention Labs' LinkScanner, which monitors traffic going into a PC and blocks known exploits.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
17 out of 21 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Flash Developer- Digital Agency

Essential skills: * Flash CS2/3 + Action Script 2/3 * Knowledge of Group Design Patterns (OOP) * Experience of server-side integration with ...

Web Front End Developer / Designer

Web Front End Developer / Designer Salary: 30,217 33,828 per annum Location: ICH, London, Waterloo The Web front end developer / designer is a key ...

ACTIONSCRIPT AS2-AS3 FLASH DEVELOPER - DIGITAL - LONDON - 45K+

Computer Futures Solutions are seeking a Flash Actionscript Script Developer to join a very prestigious digital agency based in London. To meet the ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment