Chinese security team becomes malware victim

By Liam Tung, ZDNet Australia
Friday, October 05, 2007 09:15 AM

Even security groups are not immune to malware writers: the Chinese Internet Security Response Team (CISRT) has apologized for occasionally serving up malicious code to visitors to its Web site.

"We are very sorry that when sometimes visiting our...pages, malicious codes are inserted," CISRT posted on its English-language Web site.

A short line of malicious code placed at the top of some of its Web pages can result in browsers being directed to sites housing malware. Should users visit an infected page, a 37 KB size file "sms.exe" will be downloaded to the sites, which antivirus company Kaspersky has identified as Trojan-Downloader.Win32.Baser.w.

The attack exploits buffer overflow vulnerabilities in the Chinese-developed browser-based media player, BaoFeng Storm. Symantec's antivirus center warned that BaoFeng Storm's ActiveX control is "prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data."

CISRT believes its Web site is not necessarily compromised, but has rather come under an "ARP" attack, sometimes referred to as ARP poisoning or spoofing.

Patrik Runald from Finnish security firm, F-Secure, said that it is unusual for a security response team's Web site to be hacked like this, but that if it is indeed an ARP attack, it uses a very complicated method.

"It's not really easy to make happen. When a computer makes a request somewhere [on the network], they use the ARP number which is sometimes called a MAC ID. The bottom line is if you can spoof an ARP you can insert yourself between a client and server--for example at the gateway.

"If you're on an internal network, you can spoof an ARP packet so that any machine wanting to connect to a Web site will be routed to a malicious machine. From here you can insert an iFrame line and it would only affect people going through that gateway."

Australian-based security firm, Sunnet Beskerming, which first reported the attack, wrote that by intermittently serving the malicious iFrame, the attacker can extend the life of a hack by making it harder to isolate and investigate.

"With intermittent attacks on visitors it also means that investigators need to look at all of the intermediate connections between site visitors and the Web site," Sunnet Beskerming reported.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

It's just a group of 5 hobbists named themselves as "Chinese Internet Security Response Team"..... News worthy?
Posted by Sherman on Friday, October 05 2007 03:41 PM


Tech Jobs Now!

Search for your ideal tech job:

Common ways IT wastes money on development

Web Development

Examples include using developers as support staff and failing to calculate a project's ROI before giving it the go-ahead.


Read more »



  • Enterprise 2.0

    Vince Casarez, vice president of product management at Oracle, explains how Web 2.0 technologies, such as tags, wikis, and mash-ups, can be applied within an organization.
    Play video


  • Nehalem Architecture

    What makes next-generation Intel® Microarchitecture (Nehalem) such a superior successor?
    Play video

 
On demand CRM goes strategic
CRM technology has come of age, and is now able to align with your customer strategy and grow in step with your business.

» Learn more about Oracle’s CRM Solutions



Free the untapped potential of your IT infrastructure
Reduce bottlenecks to drive the efficiency and productivity of Business IT.
» Ultimate virtualization blade
» Scalable SAN solution
» Accelerate service delivery

Could this be the most critical budget for India?

Blog thumbnail

For business journalists in India, budget time is excitement time. It's like sports journos covering the Olympics. As a newspaper correspondent, I too had my fill of budget-time excitement. But..... by Swati Prasad

Read more »

Tags

  1. attack
  2. bank
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. u.s.
  19. viruses and worms
  20. web