Xecure Lab has discovered a new CVE-2012-0754 Flash player exploit variant being used in recent APT activities. The earliest version came from a Word document named "Iran's Oil and Nuclear Situation.doc" (see Mila's blog), where the embedded Flash codes would download an MP4 file from a remote server that contains the actual exploit codes for triggering the Flash bug. Today, the new variant we found is a malicious PDF and the MP4 is self-contained in the PDF!
2012年5月21日 星期一
2012年5月10日 星期四
Hacker's Paradise and Miserable Infosecurity (駭客天堂和資安慘業)
Though Taiwan is a tiny country with very limited natural resources, "fortunately" we have lots of cyber warfare resources to be explored. Most Taiwanese are very familiar with all sorts of scam, ranging from phone call informing your kids had been kidnapped, got a car accident, your bank account had been suspended, to your online transaction was mis-processed, or you're involved with money laundry. Yet, not many people are aware how advanced threats are endangering our daily life, business operations, critical infrastructures. Only few see it as a matter of national security.
This year, we had accepted talk invitation from a few local universities and media to share our security viewpoints with young people. Hopefully it would inspire some of them in devoting themselves to explore the information security domain.
Recording of APT attack demo (conducted in Chinese): APT Attack Demo (APT攻擊實戰)
Slides of our talk at school campus (also in Chinese though): Hacker's Paradise and Miserable Infosecurity
This year, we had accepted talk invitation from a few local universities and media to share our security viewpoints with young people. Hopefully it would inspire some of them in devoting themselves to explore the information security domain.
Recording of APT attack demo (conducted in Chinese): APT Attack Demo (APT攻擊實戰)
Slides of our talk at school campus (also in Chinese though): Hacker's Paradise and Miserable Infosecurity
2012年4月17日 星期二
[廣告] 國際資安展之 HIT2012 宣傳小活動 (4/18~20)
這禮拜三開始 (4/18~20) 在台北南港展覽館舉辦了國際安全展
http://www.secutechinfosecurity.com/12/tw/about_is.aspx
"「駭客教你的事」Demo秀"
http://www.secutechinfosecurity.com/12/tw/newsdetail.aspx?nid=61
我們 HIT2012 與資安人雜誌合做, 在每天 13:00 展場中,有舉辦
小型的Talk與宣傳活動,希望大家多多捧場 ! (不是在會議室中喔)
也來多聊聊天.
我們在 4F的資訊安全-新產品發表區
http://www.secutechinfosecurity.com/12/tw/floorplan.aspx
Info Security 2012第11屆台北國際資安展暨亞太資安論壇,即將於4月18至20日熱烈展開,今年也特地邀請到台灣最大的駭客與資安技術研討會(HIT, Hacks In Taiwan) 講師群,到現場的「數位鑑識主題區暨新產品發表區」攤位(N227-N232),為您示範精彩的展中展「駭客教你的事」!(13:00開始,座位有限,請盡早入場)
4/18(三) Day1:APT攻擊模擬實戰!
APT(Advanced persistent threat)攻擊-近年來令企業最聞之色變的一種攻擊,常聽資安廠商賣產品,但是你看過攻擊的過程嗎?第一天,我們邀請到APT防禦專家,告訴你攻擊方是怎麼實作的?
4/19(四) Day2:我的密碼沒加密,你的呢?
這些年來,不少電子商務網站遭到入侵,使用者的帳號、密碼也遭竊,如果網站沒有將使用者的密碼加密,駭客就可能在入侵過程中,直接就會取得全站所存的密碼。最令人擔心的是,如果你在這個網站的密碼,跟另外一個網站是一樣的呢?現場講師將為大家展示密碼未加密的網站,遭到入侵時可能遭遇怎樣的風險。
4/20(五) Day3:無線網路,駭客天堂
你是否常在辦公室外,用iPhone、iPad或是筆電工作呢?那你一定得來看看這場精采的Demo,講師將會示範在公眾的無線網路環境下,使用行動裝置上網可能會遭遇什麼樣的風險?行動裝置的資料如何被竊取?但是怎樣又會比較難被竊取?
http://www.secutechinfosecurity.com/12/tw/about_is.aspx
"「駭客教你的事」Demo秀"
http://www.secutechinfosecurity.com/12/tw/newsdetail.aspx?nid=61
我們 HIT2012 與資安人雜誌合做, 在每天 13:00 展場中,有舉辦
小型的Talk與宣傳活動,希望大家多多捧場 ! (不是在會議室中喔)
也來多聊聊天.
我們在 4F的資訊安全-新產品發表區
http://www.secutechinfosecurity.com/12/tw/floorplan.aspx
Info Security 2012第11屆台北國際資安展暨亞太資安論壇,即將於4月18至20日熱烈展開,今年也特地邀請到台灣最大的駭客與資安技術研討會(HIT, Hacks In Taiwan) 講師群,到現場的「數位鑑識主題區暨新產品發表區」攤位(N227-N232),為您示範精彩的展中展「駭客教你的事」!(13:00開始,座位有限,請盡早入場)
4/18(三) Day1:APT攻擊模擬實戰!
APT(Advanced persistent threat)攻擊-近年來令企業最聞之色變的一種攻擊,常聽資安廠商賣產品,但是你看過攻擊的過程嗎?第一天,我們邀請到APT防禦專家,告訴你攻擊方是怎麼實作的?
4/19(四) Day2:我的密碼沒加密,你的呢?
這些年來,不少電子商務網站遭到入侵,使用者的帳號、密碼也遭竊,如果網站沒有將使用者的密碼加密,駭客就可能在入侵過程中,直接就會取得全站所存的密碼。最令人擔心的是,如果你在這個網站的密碼,跟另外一個網站是一樣的呢?現場講師將為大家展示密碼未加密的網站,遭到入侵時可能遭遇怎樣的風險。
4/20(五) Day3:無線網路,駭客天堂
你是否常在辦公室外,用iPhone、iPad或是筆電工作呢?那你一定得來看看這場精采的Demo,講師將會示範在公眾的無線網路環境下,使用行動裝置上網可能會遭遇什麼樣的風險?行動裝置的資料如何被竊取?但是怎樣又會比較難被竊取?
2012年4月16日 星期一
New RTF Exploit CVE-2012-0158 has been discovered in real-world APT attacks!
We have discovered new exploit (CVE-2012-0158) in APT emails!
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0158
This RTF vulnerability was just patched in Apr. 10 as MS12-027.
Microsoft Security Bulletin MS12-027 -
Critical Vulnerability in Windows Common Controls
Could Allow Remote Code Execution (2664258)
http://technet.microsoft.com/en-us/security/bulletin/ms12-027
RTF File:
At this moment, the new exploit enjoys a very low AV detection rate
on VirusTotal, with only 2 out of the 42 antivirus engines flagging it as malicious.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0158
This RTF vulnerability was just patched in Apr. 10 as MS12-027.
Microsoft Security Bulletin MS12-027 -
Critical Vulnerability in Windows Common Controls
Could Allow Remote Code Execution (2664258)
http://technet.microsoft.com/en-us/security/bulletin/ms12-027
RTF File:
At this moment, the new exploit enjoys a very low AV detection rate
on VirusTotal, with only 2 out of the 42 antivirus engines flagging it as malicious.
2012年4月15日 星期日
第八屆台灣駭客年會 HITCON 2012 Call For Papers
http://www.hitcon.org/hit2012/en/
第八屆台灣駭客年會將於 2012 年 7 月 20~21 日(週五、六)舉行。 歡迎各界人士踴躍投稿。論文內容以探討實作技術並能演講 50 分鐘為佳。
This is the 8th year of Hacks in Taiwan security conference. The exciting event will be held on 20th and 21st of July in Taipei. We are very pleased to announce the Call For Papers for HIT2012.
Location: International Conference Hall, Humanities & Social Sciences Building, Academia Sinica, Taipei, Taiwan (No.128, Sec. 2, Academia Rd., Nangang Dist., Taipei City 115, Taiwan)
Dates: Jul 20, 2012 (Fri) - Jul 21, 2012 (Sat)
HITCON 2012 Call For Papers
2012年3月13日 星期二
Xecure Lab is relocating to a bigger office ;-)
After a year of operation, the team is moving to a new location this week. Apology that two free services XecScan and XecMail for Webmail are still not available, it will be back as soon as possible.
The new office is right next to the National Police Agency and Executive Yuan in Taiwan, and has a green park nearby, much better view than previous location. Visit us if you are in Taiwan. ;-)
The new office is right next to the National Police Agency and Executive Yuan in Taiwan, and has a green park nearby, much better view than previous location. Visit us if you are in Taiwan. ;-)
2012年3月2日 星期五
We launched a commcercial website to describe our solution in English
The world went APT-crazy for the past two years. Taking a glance at this year's RSA 2012 keynotes: cyber terrorists, cyber spies, cyber warriors, hacktivism, advanced persistent threats - these are the challenging issues that get people's attention.
Though Xecure Lab was founded a year ago, we never have website in English that help introduce our solution to reach more people. Recently we finally spent some spare time and have the English version launched today.
Our commercial website promotes the solution that Xecure Lab team developed to help customers counter advanced threats like APT emails and APT activities. Typically APT email comes with document in common file format, and embeds some sort of malware and exploit. Apparently it should be blocked in the first place from ever entering the corporate intranet. Then this APT attempt could also be associated with a long-history APT database to cluster into groups. It helps understand the origin of the attack as well as its intent and targets.
On the other hand, we would continue offer XecScan freely to the community, giving everyone a fast on-demand handy tool to scan any suspicious document, pretty much like VirusTotal version for APT scanning.
For more commercial offerings of our solution, please visit http://xecure-lab.com/en/index.html
Though Xecure Lab was founded a year ago, we never have website in English that help introduce our solution to reach more people. Recently we finally spent some spare time and have the English version launched today.
Our commercial website promotes the solution that Xecure Lab team developed to help customers counter advanced threats like APT emails and APT activities. Typically APT email comes with document in common file format, and embeds some sort of malware and exploit. Apparently it should be blocked in the first place from ever entering the corporate intranet. Then this APT attempt could also be associated with a long-history APT database to cluster into groups. It helps understand the origin of the attack as well as its intent and targets.
On the other hand, we would continue offer XecScan freely to the community, giving everyone a fast on-demand handy tool to scan any suspicious document, pretty much like VirusTotal version for APT scanning.
For more commercial offerings of our solution, please visit http://xecure-lab.com/en/index.html
訂閱:
文章 (Atom)


