<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>M32 Security &#187; Chymine</title> <atom:link href="http://m32consulting.com/tag/chymine/feed/" rel="self" type="application/rss+xml" /><link>http://m32consulting.com</link> <description>Network Security Info, News, and Resources</description> <lastBuildDate>Sun, 22 Jan 2012 23:37:02 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>Microsoft LNK vulnerability exploit spreading quickly</title><link>http://m32consulting.com/2010/07/microsoft-lnk-vulnerability-exploit-spreading-quickly/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=microsoft-lnk-vulnerability-exploit-spreading-quickly</link> <comments>http://m32consulting.com/2010/07/microsoft-lnk-vulnerability-exploit-spreading-quickly/#comments</comments> <pubDate>Thu, 29 Jul 2010 05:14:41 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Exploits]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Chymine]]></category> <category><![CDATA[LNK]]></category> <category><![CDATA[LNK-O]]></category> <category><![CDATA[malware]]></category> <category><![CDATA[microsoft lnk]]></category> <category><![CDATA[SALITY]]></category> <category><![CDATA[SCADA]]></category> <category><![CDATA[Stuxnet]]></category> <category><![CDATA[TrojanDownloader]]></category> <category><![CDATA[Vobfus]]></category> <category><![CDATA[ZBot]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=119</guid> <description><![CDATA[At last writing, the Microsoft LNK vulnerability that was originally used to target SCADA systems by the Stuxnet worm in Iran, India, and Indonesia was slowly gaining speed and the exploit had a proof-of-concept in the open. Now it is accelerating. It is now being picked up by old virus/worm/malware families and incorporated into their [...]]]></description> <content:encoded><![CDATA[<p>At last writing, the Microsoft LNK vulnerability that was originally used to target SCADA systems by the Stuxnet worm in Iran, India, and Indonesia was slowly gaining speed and the exploit had a proof-of-concept in the open. Now it is accelerating. It is now being picked up by old virus/worm/malware families and incorporated into their arsenals to take new victims; some using social engineering, some using their own unique tactics. While the exploit method itself hasn&#8217;t changed, the exploiters using it are vigorously churning out new versions of their software. <a
title="SHUT.DOWN.EVERYTHING." href="http://www.newgrounds.com/portal/view/448950" target="_blank">I think it&#8217;s safe to say Madagascar will be closing its ports soon</a>. (Warning: addictive)</p><p>New detected malwares are <a
title="Win32/TrojanDownloader.Chymine.A" href="http://blog.eset.com/category/win32trojandownloader-chymine-a" target="_blank">Chymine</a>, <a
title="Worm:W32/Vobfus.BK" href="http://www.f-secure.com/v-descs/worm_w32_vobfus_bk.shtml" target="_blank">Vobfus</a>, <a
title="PE_SALITY.LNK-O" href="http://about-threats.trendmicro.com/ArchiveMalware.aspx?language=us&amp;name=PE_SALITY.LNK-O" target="_blank">Sality</a>, <a
title="ZBot" href="http://blog.trendmicro.com/zeuszbot-and-sality-jump-on-the-lnk-exploit-bandwagon/" target="_blank">Zeus</a>, and most recently, <a
title="Downloader-CJX" href="http://blogs.mcafee.com/mcafee-labs/downloader-cjx-cashing-in-on-microsoft-lnk-flaw" target="_blank">Downloader-CJX</a></p><p><a
href="http://blogs.technet.com/b/mmpc/archive/2010/07/23/protection-for-new-malware-families-using-lnk-vulnerability.aspx" target="_blank">Technet article on Vobfus</a></p><p><a
href="http://www.theregister.co.uk/2010/07/27/zeus_exploit_shortcut_hole/" target="_blank">The Register on LNK exploit activity</a></p><p><a
href="http://www.f-secure.com/weblog/archives/00001996.html" target="_blank">F-Secure blog entry</a></p>Tags: <a
href="http://m32consulting.com/tag/chymine/" title="Chymine" rel="tag">Chymine</a>, <a
href="http://m32consulting.com/tag/lnk/" title="LNK" rel="tag">LNK</a>, <a
href="http://m32consulting.com/tag/lnk-o/" title="LNK-O" rel="tag">LNK-O</a>, <a
href="http://m32consulting.com/tag/malware/" title="malware" rel="tag">malware</a>, <a
href="http://m32consulting.com/tag/microsoft-lnk/" title="microsoft lnk" rel="tag">microsoft lnk</a>, <a
href="http://m32consulting.com/tag/sality/" title="SALITY" rel="tag">SALITY</a>, <a
href="http://m32consulting.com/tag/scada/" title="SCADA" rel="tag">SCADA</a>, <a
href="http://m32consulting.com/tag/stuxnet/" title="Stuxnet" rel="tag">Stuxnet</a>, <a
href="http://m32consulting.com/tag/trojandownloader/" title="TrojanDownloader" rel="tag">TrojanDownloader</a>, <a
href="http://m32consulting.com/tag/vobfus/" title="Vobfus" rel="tag">Vobfus</a>, <a
href="http://m32consulting.com/tag/zbot/" title="ZBot" rel="tag">ZBot</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2010/07/microsoft-lnk-vulnerability-exploit-spreading-quickly/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>LNK Zero-Day Exploit: Siemens WinCC SCADA systems targeted</title><link>http://m32consulting.com/2010/07/ln-zero-day-exploit-siemens-wincc-scada-systems-targeted/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ln-zero-day-exploit-siemens-wincc-scada-systems-targeted</link> <comments>http://m32consulting.com/2010/07/ln-zero-day-exploit-siemens-wincc-scada-systems-targeted/#comments</comments> <pubDate>Mon, 26 Jul 2010 05:20:59 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Corporate]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Hacking]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[2WSXcder]]></category> <category><![CDATA[Chymine]]></category> <category><![CDATA[Ivanlef]]></category> <category><![CDATA[july 14]]></category> <category><![CDATA[LNK]]></category> <category><![CDATA[SCADA]]></category> <category><![CDATA[Siemens]]></category> <category><![CDATA[siemens wincc]]></category> <category><![CDATA[WinCC]]></category> <category><![CDATA[zero day]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=104</guid> <description><![CDATA[It turns out that the original targets for the highly-dangerous Windows Shell LNK Zero-Day Exploit were Siemens WinCC SCADA systems with hard-coded credentials used in large infrastructure systems like factories and power grids. Once the attacker had successfully executed the LNK exploit, they accessed the Siemens WinCC program and extracted sensitive data from the database [...]]]></description> <content:encoded><![CDATA[<p>It turns out that the original targets for the highly-dangerous Windows Shell LNK Zero-Day Exploit were Siemens WinCC SCADA systems with hard-coded credentials used in large infrastructure systems like factories and power grids. Once the attacker had successfully executed the LNK exploit, they accessed the Siemens WinCC program and extracted sensitive data from the database the software uses. It is highly suspected that the exploit was explicitly used for espionage toward Iran and Indonesia at the very least, but by whom or what exact purpose is not clear. What is clear is that the Siemens WinCC software was targeted. The Siemens WinCC software has what is considered one of the top vulnerabilities in software according to CWE/SANS, which is the use of fixed-credentials. This type of vulnerability has been publicly disclosed for over two years and the password to this specific software (2WSXcder) has been publicly known since <a
href="http://www.automation.siemens.com/forum/guests/PostShow.aspx?PostID=16127&amp;16127&amp;Language=en&amp;PageIndex=3" target="_blank">at least</a> <a
href="http://iadt.siemens.ru/forum/viewtopic.php?p=2974&amp;sid=58cedcf3a0fc7a0b6c61c7bc46530928" target="_blank">2008</a>. Siemens was made aware of the issue on July 14 and shortly started to asses the problem and notify customers.</p><p>In the meantime, a security researcher known as Ivanlef0u has <a
href="http://www.ivanlef0u.tuxfamily.org/?p=411" target="_blank">posted a proof-of-concept of the exploit</a> (site is in French), while Win32/TrojanDownloader.Chymine.A and Win32/Autorun.VB.RP are in the wild already actively actively using this exploit according to ESET. Expect to see this exploit to be a bit prolific due to its new and unique nature combined with the relative ineffectiveness of detection/removal systems thus far.</p><p><a
href="http://www.wired.com/threatlevel/2010/07/siemens-scada/" target="_blank">Wired Article on password&#8217;s public exposure</a></p><p><a
href="http://blog.eset.com/2010/07/22/new-malicious-lnks-here-we-go" target="_blank">ESET Blog on new Zero-day exploit in the wild</a></p>Tags: <a
href="http://m32consulting.com/tag/2wsxcder/" title="2WSXcder" rel="tag">2WSXcder</a>, <a
href="http://m32consulting.com/tag/chymine/" title="Chymine" rel="tag">Chymine</a>, <a
href="http://m32consulting.com/tag/ivanlef/" title="Ivanlef" rel="tag">Ivanlef</a>, <a
href="http://m32consulting.com/tag/july-14/" title="july 14" rel="tag">july 14</a>, <a
href="http://m32consulting.com/tag/lnk/" title="LNK" rel="tag">LNK</a>, <a
href="http://m32consulting.com/tag/scada/" title="SCADA" rel="tag">SCADA</a>, <a
href="http://m32consulting.com/tag/siemens/" title="Siemens" rel="tag">Siemens</a>, <a
href="http://m32consulting.com/tag/siemens-wincc/" title="siemens wincc" rel="tag">siemens wincc</a>, <a
href="http://m32consulting.com/tag/wincc/" title="WinCC" rel="tag">WinCC</a>, <a
href="http://m32consulting.com/tag/zero-day/" title="zero day" rel="tag">zero day</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2010/07/ln-zero-day-exploit-siemens-wincc-scada-systems-targeted/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 7/26 queries in 0.051 seconds using disk: basic
Object Caching 1167/1211 objects using disk: basic

Served from: m32consulting.com @ 2012-02-11 16:25:19 -->
