Techtree is reporting that Cabir is in the wild in Mumbai, India's most populous city.
The article mentions a "Nokia Priority Dealer" offering to clean an infected phone for 850 rupees. The exchange rate is approximately 1 US dollar to 45 Indian rupees. About $18-$19 a phone. Adjusting for cost of living ($ * 5) gives an effective rate of US$90-$95. It's never cheap to live in the big city.
Speaking of viruses written by 29a members , The Register is reporting that Benny of the same group has turned over a new leaf and has joined the ranks of the AV community. An interesting situation.
Info on mobile phone antivirus, anti-malware software and commentary on mobile security.
Monday, November 08, 2004
Monday, October 25, 2004
J2ME, interesting stuff
I've just seen Adam's post on the Full-Disclosure list. Apparently Sun has been informed but no Sun Alert is forthcoming. Considering that unlike the recent JRE XSLT issue the KVM is a harder to update. Most phones would require their ROMs reflashed, meaning a trip to the nearest cell technician or return to factory.
UPDATE: Acoording to a tecchannel interview , licensees(Nokia,Siemens, others) have been provided with a fixed reference implementation. So it is now up to the licensees to update their various products.
The presentation pdf was quite large so I've converted it to .chm format for ease of reading. From 53MB to a bit more than 8. Most of the work was automated with pdf2html and pngcrush and the Html Help compiler.
For those looking for the original pdf, it's currently available through Packetstorm and mirrors.
UPDATE: Acoording to a tecchannel interview , licensees(Nokia,Siemens, others) have been provided with a fixed reference implementation. So it is now up to the licensees to update their various products.
The presentation pdf was quite large so I've converted it to .chm format for ease of reading. From 53MB to a bit more than 8. Most of the work was automated with pdf2html and pngcrush and the Html Help compiler.
For those looking for the original pdf, it's currently available through Packetstorm and mirrors.
Friday, October 22, 2004
Adam Gowdiak's Research on J2ME Vulnerabliites
I never really looked at the Hack in the Box conferences;this year it was in Kuala Lumpur. The Register has an article mentioning Adam Gowdiak's presentation at the latest conference.
The PDF of his presentation comes in at about 53 MB(91 pages).
There was a also presentation on .net self compiling viruses .
I haven't gone through the whole thing yet, but here are some interesting quotes from the J2ME presentation:
on future threats -
on the rest of his research -
J2Me might be the "in" malware needed that bluetooth wasn't . I'm not sure how worried I'd be that "closed" mobile devices are at risk, as they usually lack in memory and additional networking capabilities compared to "open" systems. Still, anywhere from 3-6 months to find out. :)
* Hack in the Box is putting out videos of the conference via BitTorrent within the next 4 weeks.
The PDF of his presentation comes in at about 53 MB(91 pages).
There was a also presentation on .net self compiling viruses .
I haven't gone through the whole thing yet, but here are some interesting quotes from the J2ME presentation:
on future threats -
- The fact that there are more users of mobile devices than
PC’s makes it very attractive target for attackers and worm writers- It should be expected that remote vulnerabilities for
mobile devices will be published within next 6 months- Vendors and antivirus industry are not prepared for this kind
of threats (there are no means to protect users of the so called „closed” mobile devices against malicious code)- Open platforms (PalmOS, Symbian OS, Windows CE)
seem to be easier to protect, but they are also at the most risk.
on the rest of his research -
- Research paper with all the details including some
additional material that didn’t fit into this 90min talk will be
published in a couple of months
J2Me might be the "in" malware needed that bluetooth wasn't . I'm not sure how worried I'd be that "closed" mobile devices are at risk, as they usually lack in memory and additional networking capabilities compared to "open" systems. Still, anywhere from 3-6 months to find out. :)
* Hack in the Box is putting out videos of the conference via BitTorrent within the next 4 weeks.
Wednesday, October 06, 2004
On emulation
I've been looking into fx!32. Due to the nature of the Symbian emulator and the cost of actual hardware, this might be the most feasible/lazy way to analyze most malware. Sort of a phone-bochs. Of course, it's a different story for scanning.
The GBA emu scene is also useful .
The GBA emu scene is also useful .
F-Secure Releases Cabir Fixtool
F-Secure has finally released a fixtool for Cabir. It weighs in at about 11KB. Kapsersky still wins on size. :) The purpose of Thumb encoding is to reduce size with a tradeoff in speed.
Considering this is a fixtool speed is not that important. The tool does make it clear that it just removes Cabir from your system and it is not a general AV scanner.
Other fixtools are also available, as mentioned previously.
F-Secure's tool is available in two packages, with instructions or separately.
F-Secure blog
Considering this is a fixtool speed is not that important. The tool does make it clear that it just removes Cabir from your system and it is not a general AV scanner.
Other fixtools are also available, as mentioned previously.
F-Secure's tool is available in two packages, with instructions or separately.
F-Secure blog
Monday, October 04, 2004
Cabir in Singapore
F-Secure's blog is reporting news of Cabir in Singapore.
On a related note, I've just noticed that Trend Micro has an updated pattern file for their Pc-cillin for EPOC scanner. The scanner will only run on EPOC/Symbian devices. I have it installed on my Mako. Due to the EIKON dependency and perhaps STDLIB, the scanner will not run on the Series 60 phones.
The recent "outbreak" of Cabir in the Philippines is notable. Not so much for any infections but mainly for the rise of the Cabir disinfection business. Considering that people were willing to spend the cost of living equivalent of US$26+ to get rid of real and suspected infections. The scams were large enough to get press coverage outside of the Philippines. Looks like there is a business case for producing a Series 60 scanner. Especially if it's in your own backyard.
PC-cillin for Epoc sis (EPOC/Symbian ver 5 devices only)
Pattern file 349 (Cabir Detection added, file date July 26,2004)
Porting Psion Revo/5MX Applications to Series 60.pdf :)
On a related note, I've just noticed that Trend Micro has an updated pattern file for their Pc-cillin for EPOC scanner. The scanner will only run on EPOC/Symbian devices. I have it installed on my Mako. Due to the EIKON dependency and perhaps STDLIB, the scanner will not run on the Series 60 phones.
The recent "outbreak" of Cabir in the Philippines is notable. Not so much for any infections but mainly for the rise of the Cabir disinfection business. Considering that people were willing to spend the cost of living equivalent of US$26+ to get rid of real and suspected infections. The scams were large enough to get press coverage outside of the Philippines. Looks like there is a business case for producing a Series 60 scanner. Especially if it's in your own backyard.
PC-cillin for Epoc sis (EPOC/Symbian ver 5 devices only)
Pattern file 349 (Cabir Detection added, file date July 26,2004)
Porting Psion Revo/5MX Applications to Series 60.pdf :)
Tuesday, September 21, 2004
Trusecure Betrusted Merger
The information security space seems to be consolidating fast these days. Reminiscent of the many US defense industry mergers. Not to mention the various cellular industry mergers.
I'm not very familiar with Betrusted but they are similar in both products and market with Trusecure. Trusecure covering North America and Betrusted holding Europe and Asia.
ICSA labs, a subsidiary of Trusecure, is looking for a Malicious Code Security Analyst. They're very friendly at ICSA labs. I believe that notwithstanding what it says in the job description they will be willing to offer relocation for the well qualified cadidate. Good opportunity at what is now a larger company.
I'm not very familiar with Betrusted but they are similar in both products and market with Trusecure. Trusecure covering North America and Betrusted holding Europe and Asia.
ICSA labs, a subsidiary of Trusecure, is looking for a Malicious Code Security Analyst. They're very friendly at ICSA labs. I believe that notwithstanding what it says in the job description they will be willing to offer relocation for the well qualified cadidate. Good opportunity at what is now a larger company.
Friday, September 17, 2004
AV buying Network Security firms
I might have gotten the situation backwards previously. Symantec has just bought @stake. With McAfee buying Foundstone last month, the situation actually becomes AV firms moving into Network Security and Security consulting.
The moves into the AV market by the various network security companies may have been lures to encourage acquisition by the larger AV firms. This is not to say that these firms were not actually looking for virus analysts.
In the case of Foundstone , pre-acquisition, they were looking for one person to bring them up to speed on virus analysis. Given the nature of newer malware threats , one expert is not sufficient for the task. Gaps in knowledge would reduce response time behind that of your competitors. Actively interviewing candidates from a small pool, such as AV people, does bring your firm to the attention of larger firms . An expert working for you is not working for them; even if you are not a large competitor you do reduce their effectiveness. This may have been the case with McAfee.
I don't believe @stake was entering the AV market. They do have experience with investigating cell phones and other embedded devices. MobilePenTester, PDAZap and RedFang come to mind.
Regarding virus analysts Symantec seems to be looking for a virus analyst with phone experience:
"Experience with operating systems for handheld devices such as Palm OS, Pocket PC, Symbian OS and/or Windows Mobile software for Smart phones a distinct advantage."
Perhaps Airscanner might be receiving an offer in the near future.
The moves into the AV market by the various network security companies may have been lures to encourage acquisition by the larger AV firms. This is not to say that these firms were not actually looking for virus analysts.
In the case of Foundstone , pre-acquisition, they were looking for one person to bring them up to speed on virus analysis. Given the nature of newer malware threats , one expert is not sufficient for the task. Gaps in knowledge would reduce response time behind that of your competitors. Actively interviewing candidates from a small pool, such as AV people, does bring your firm to the attention of larger firms . An expert working for you is not working for them; even if you are not a large competitor you do reduce their effectiveness. This may have been the case with McAfee.
I don't believe @stake was entering the AV market. They do have experience with investigating cell phones and other embedded devices. MobilePenTester, PDAZap and RedFang come to mind.
Regarding virus analysts Symantec seems to be looking for a virus analyst with phone experience:
"Experience with operating systems for handheld devices such as Palm OS, Pocket PC, Symbian OS and/or Windows Mobile software for Smart phones a distinct advantage."
Perhaps Airscanner might be receiving an offer in the near future.
Thursday, September 09, 2004
On FPs and behavior blocking; another Malware Analysis opening
False positives (FP) are a troublesome problem in the AV industry. Sometimes innocent products share enough behavioral characteristics with malware that we initially classify them as malware.
Mistakes like this affect your credibility and the credibility of your product, so fixing FPs is usually a very high priority. Therefore it was interesting to see that earlier this week one of the top 3 AV vendors was having some trouble with a good sized FP. It was something to do with ISP connection software. The detections were of course fixed quickly but the good will lost with customers may not easily be repaired.
The rate of FPs is also the reason why behavior blocking (or as it's known in the Homeland Security business , "profiling" ) has been so late in entering the market. Blocking someone's ISP software because it uses your modem to dial your ISP is forgivable if done by a human. After all, we all have deadlines and other pressures. If you are unable to connect to your ISP once every 2 weeks due to your computer security software, you are unlikely to be as forgiving.
Handling false positives usually requires human intervention. Speaking of which, There is an opening at McAfee :
Research Scientist
"Knowledge of various file formats and operating systems a plus, namely PE and ELF formats and Linux and MacOS operating systems."
ELF? ELF knowledge as a requirement for malware analysis seems to be getting more popular.
I'd think after PE, Mach-O knowledge would be more important given market share. Or even Symbian PE.
Mistakes like this affect your credibility and the credibility of your product, so fixing FPs is usually a very high priority. Therefore it was interesting to see that earlier this week one of the top 3 AV vendors was having some trouble with a good sized FP. It was something to do with ISP connection software. The detections were of course fixed quickly but the good will lost with customers may not easily be repaired.
The rate of FPs is also the reason why behavior blocking (or as it's known in the Homeland Security business , "profiling" ) has been so late in entering the market. Blocking someone's ISP software because it uses your modem to dial your ISP is forgivable if done by a human. After all, we all have deadlines and other pressures. If you are unable to connect to your ISP once every 2 weeks due to your computer security software, you are unlikely to be as forgiving.
Handling false positives usually requires human intervention. Speaking of which, There is an opening at McAfee :
Research Scientist
"Knowledge of various file formats and operating systems a plus, namely PE and ELF formats and Linux and MacOS operating systems."
ELF? ELF knowledge as a requirement for malware analysis seems to be getting more popular.
I'd think after PE, Mach-O knowledge would be more important given market share. Or even Symbian PE.
Monday, September 06, 2004
Looking into buffer overflows
CAN-2004-0143 initially looked promising when I read the heading at pentest.co.uk. Unfortunately after reading the full advisory it becomes obvious that the vulnerability type has been mis-stated. It is actually a denial of service instead of a buffer overflow. Other references listed at the CVE list correctly list it as a denial of service.
This is not quite the automatic security-bypassing download vulnerability of which whe have been warned. The main use would be in "finishing " the job after getting the malicious code past security in some yet unknown fashion. Essentially an automatic reboot to enable a boot loading component to gain control. Similar, recently to Sasser or much earlier to one or two older multipartite viruses. Regardless, an unwieldy attack.
Perhaps some of the StrongARM shellcode techniques may be more appropriate.
This is not quite the automatic security-bypassing download vulnerability of which whe have been warned. The main use would be in "finishing " the job after getting the malicious code past security in some yet unknown fashion. Essentially an automatic reboot to enable a boot loading component to gain control. Similar, recently to Sasser or much earlier to one or two older multipartite viruses. Regardless, an unwieldy attack.
Perhaps some of the StrongARM shellcode techniques may be more appropriate.
Thursday, September 02, 2004
Makefn tool added to DmpE32
As Symbian exe files import by ordinal it is very helpful for an exe dumper like DmpE32 to map the import ordinals to the original function names.
Previously I'd been generating the import function name files(.fn) for each version of the sdk. Unfortunatley the zip of the latest .fn files was in the range of 300-400 KB. Offering these for download would require more bandwidth than I pay for (>0). Additionally, in the case of the series 60 specific files the mappings were inaccurate.
I had been using nm to dump the function names and post processing the output. Unfortunately nm sorts by object module and not ordinal. In some cases the numeric portion of the object module name matches the ordinal. A lucky coincidence but definitely not reliable.
Matt Pietrek's article on COFF libraries and source code proved very helpful. GNU's dlltool source provided insight on the various idata components.
I've added a tool for generating imported function to ordinal mapping to the DmpE32 package.
COFF Lib references:
Pietrek, Matt. "Under The Hood." Microsoft System Journal
Apr. 1998 <http://www.microsoft.com/msj/0498/hood0498.aspx>.
GNU Dlltool.c , GNU Binutils package.
Previously I'd been generating the import function name files(.fn) for each version of the sdk. Unfortunatley the zip of the latest .fn files was in the range of 300-400 KB. Offering these for download would require more bandwidth than I pay for (>0). Additionally, in the case of the series 60 specific files the mappings were inaccurate.
I had been using nm to dump the function names and post processing the output. Unfortunately nm sorts by object module and not ordinal. In some cases the numeric portion of the object module name matches the ordinal. A lucky coincidence but definitely not reliable.
Matt Pietrek's article on COFF libraries and source code proved very helpful. GNU's dlltool source provided insight on the various idata components.
I've added a tool for generating imported function to ordinal mapping to the DmpE32 package.
COFF Lib references:
Pietrek, Matt. "Under The Hood." Microsoft System Journal
Apr. 1998 <http://www.microsoft.com/msj/0498/hood0498.aspx>.
GNU Dlltool.c , GNU Binutils package.
Subscribe to:
Posts (Atom)
Protecting the ‘Metaverse ecosystem’…: Openness is healthy
Meta’s Reality Labs has an opening for “Malware Reverse Engineer” . Not an uncommon role, but this particular one is a bit more specific whe...
-
Dick Tracy, the great comic strip detective , is known for having great gadgets like his 2-way radio/computer wristwatch. Though a wrist mo...
-
The Internet of Things is not as complex as one would think. Smart Objects(e.g. Power meters, Fridge computers, etc.) or "Things" ...