2012年5月27日 星期日

[ 特別通報 ] APT 惡意文件新攻擊手法 ! 擊敗所有自動化分析沙盒與掃毒軟體 !

最近這半個月來我們持續收到一些特別惡意文件,這些惡意文件有一個特色都是沙盒與掃毒軟體偵測全都是 0 !而且是完美的免殺。 上傳到VirusTotal, ThreatExpert 與 CWSandbox 全都無法分析 ! 看來駭客已經找到躲過目前所有 Anti-APT 完美方案。

9plus的 Brandon 在他的Blog(http://blog.9bplus.com)也有發現最近這些樣本

就是這麼神奇 ! XecScan在不需要更新下就可以全部捕獲,沒有誤判漏報 !
http://scan.xecure-lab.com

2012年5月25日 星期五

韓國資安業者報導: 台灣政府單位遭到 APT 攻擊 (關韓國人甚麼事? 奇怪ㄟ你)

雖然這不是新聞了, 但是在國外資安業者網站看到對我們的報導,還是關注了一下,結果我國政府機關的資安事件在韓國資安業者的網站被當 APT 宣傳材料,這...



在國外資安公司通報中看到繁體中文的個案並不多見,此例是國外業者透過 VirusTotal 比較不為人知的樣本交換加值服務方式取得,韓國資安業者刻意貼出台灣政府機關被 APT,來凸顯此問題的嚴重性,但說真的,關他們甚麼事...

從這報告的諸多信件畫面,一般社會大眾可以略窺台灣如何惡意文件滿天飛(這邊不是指言語文字上的惡意,而是開啟那個文件就會發生駭客木馬歡迎光臨的慘事),全民都應該要小心,政治人物更是要提高警覺...

工商時間: 這些 APT 不用外國人,台灣就有自主能量可以分析搞定,XecScan (http://scan.xecure-lab.com) 把 APT 通通揪出來 ;-)

2012年5月21日 星期一

Malicious PDF used in APT attacks exploiting new variants of CVE-2012-0754

Xecure Lab has discovered a new CVE-2012-0754 Flash player exploit variant being used in recent APT activities. The earliest version came from a Word document named "Iran's Oil and Nuclear Situation.doc" (see Mila's blog), where the embedded Flash codes would download an MP4 file from a remote server that contains the actual exploit codes for triggering the Flash bug. Today, the new variant we found is a malicious PDF and the MP4 is self-contained in the PDF!

2012年5月10日 星期四

Hacker's Paradise and Miserable Infosecurity (駭客天堂和資安慘業)

Though Taiwan is a tiny country with very limited natural resources, "fortunately" we have lots of cyber warfare resources to be explored. Most Taiwanese are very familiar with all sorts of scam, ranging from phone call informing your kids had been kidnapped, got a car accident, your bank account had been suspended, to your online transaction was mis-processed, or you're involved with money laundry. Yet, not many people are aware how advanced threats are endangering our daily life, business operations, critical infrastructures. Only few see it as a matter of national security.

This year, we had accepted talk invitation from a few local universities and media to share our security viewpoints with young people. Hopefully it would inspire some of them in devoting themselves to explore the information security domain.

Recording of APT attack demo (conducted in Chinese): APT Attack Demo (APT攻擊實戰)
Slides of our talk at school campus (also in Chinese though): Hacker's Paradise and Miserable Infosecurity

2012年4月17日 星期二

[廣告] 國際資安展之 HIT2012 宣傳小活動 (4/18~20)

這禮拜三開始 (4/18~20) 在台北南港展覽館舉辦了國際安全展
http://www.secutechinfosecurity.com/12/tw/about_is.aspx

"「駭客教你的事」Demo秀"
http://www.secutechinfosecurity.com/12/tw/newsdetail.aspx?nid=61
我們 HIT2012 與資安人雜誌合做, 在每天 13:00 展場中,有舉辦
小型的Talk與宣傳活動,希望大家多多捧場 ! (不是在會議室中喔)
也來多聊聊天.


我們在 4F的資訊安全-新產品發表區
http://www.secutechinfosecurity.com/12/tw/floorplan.aspx

Info Security 2012第11屆台北國際資安展暨亞太資安論壇,即將於4月18至20日熱烈展開,今年也特地邀請到台灣最大的駭客與資安技術研討會(HIT, Hacks In Taiwan) 講師群,到現場的「數位鑑識主題區暨新產品發表區」攤位(N227-N232),為您示範精彩的展中展「駭客教你的事」!(13:00開始,座位有限,請盡早入場)

4/18(三) Day1:APT攻擊模擬實戰!
APT(Advanced persistent threat)攻擊-近年來令企業最聞之色變的一種攻擊,常聽資安廠商賣產品,但是你看過攻擊的過程嗎?第一天,我們邀請到APT防禦專家,告訴你攻擊方是怎麼實作的?

4/19(四) Day2:我的密碼沒加密,你的呢? 
這些年來,不少電子商務網站遭到入侵,使用者的帳號、密碼也遭竊,如果網站沒有將使用者的密碼加密,駭客就可能在入侵過程中,直接就會取得全站所存的密碼。最令人擔心的是,如果你在這個網站的密碼,跟另外一個網站是一樣的呢?現場講師將為大家展示密碼未加密的網站,遭到入侵時可能遭遇怎樣的風險。

4/20(五) Day3:無線網路,駭客天堂
你是否常在辦公室外,用iPhone、iPad或是筆電工作呢?那你一定得來看看這場精采的Demo,講師將會示範在公眾的無線網路環境下,使用行動裝置上網可能會遭遇什麼樣的風險?行動裝置的資料如何被竊取?但是怎樣又會比較難被竊取?





2012年4月16日 星期一

New RTF Exploit CVE-2012-0158 has been discovered in real-world APT attacks!

We have discovered new exploit (CVE-2012-0158) in APT emails!

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0158










This RTF vulnerability was just patched in Apr. 10 as MS12-027.
Microsoft Security Bulletin MS12-027 -
Critical Vulnerability in Windows Common Controls
Could Allow Remote Code Execution (2664258)
http://technet.microsoft.com/en-us/security/bulletin/ms12-027

RTF File:











At this moment, the new exploit enjoys a very low AV detection rate
on VirusTotal, with only 2 out of the 42 antivirus engines flagging it as malicious.

2012年4月15日 星期日

第八屆台灣駭客年會 HITCON 2012 Call For Papers


http://www.hitcon.org/hit2012/en/

第八屆台灣駭客年會將於 2012 年 7 月 20~21 日(週五、六)舉行。 歡迎各界人士踴躍投稿。論文內容以探討實作技術並能演講 50 分鐘為佳。 


This is the 8th year of Hacks in Taiwan security conference. The exciting event will be held on 20th and 21st of July in Taipei. We are very pleased to announce the Call For Papers for HIT2012.
Location: International Conference Hall, Humanities & Social Sciences Building, Academia Sinica, Taipei, Taiwan (No.128, Sec. 2, Academia Rd., Nangang Dist., Taipei City 115, Taiwan)


Dates: Jul 20, 2012 (Fri) - Jul 21, 2012 (Sat)
HITCON 2012 Call For Papers