Jump to content
thehat

Have a Taste of Communism with a Mouthful of APT

Recommended Posts

Have a Taste of Communism with a Mouthful of APT

Posted by sinn3r in Metasploit on Jun 7, 2013 6:05:02 AM

Screen Shot 2013-06-05 at 3.26.46 PM.pngEveryone loves a good cyber-espionage story, and we love to put China under the spotlight. Why? Because their methods work. China has some well known hacking groups that have conducted cyber-espionage-oriented attacks, such as the Elderwood Group, Unit 61398, the Nitro gang, etc. As far as we know, most of these groups tend to use some kind of 0day exploit to gain acces of the targeted organization, and then steal terabytes of data for years. However, by studying these hacking groups, we also learned that a successful APT doesn't always require an 0day, whatever gets the job done is more than enough, and NetTravler demonstrates just that.

According to a recent research paper by Kaspersky, the Chinese-based hacking group NetTraveler tends to get their victims infected through spear-fishing attacks using exploits that are already publicly known, specifically CVE-2010-3333 and CVE-2012-0158. Although already patched, these vulnerabilities still remain effective, and are among the most exploited in recent attacks, for example: Tibetan/Uyghur activists, oil industry companies, scientific research centers, universities, private companies, governments and military contractors, etc. And of course, they've stolen more than 22+ gigabytes of data because they 1337.

This is all kind of depressing (or amusing?) to hear especially when our memory is still fresh about HD Moore's talk about how many percent of the Internet still remain insecure, and NetTraveler kind of verifies that claim by shoving old exploits in the US government's faces. Hey guess what? As a high profile target, you can prevent that. If you run a system update, your vulnerable software will tell you your stuff is outdated. If you run a vulnerability scanner, the scanner will tell you you're waiting to be exploited. If you run a penetration testing framework like Metasploit, shells will be popped, and that should be a red flag for you.

CVE-2012-0158 is a vulnerability in Microsoft Office. There is a Metasploit module (ms12_027_mscomctl_bof.rb) that specifically targets Office 2007 and Office 2010, written by Wei Chen and Juan Vazquez. Demo (note: target specific):

Screen+Shot+2013-06-05+at+5.43.51+PM.png

CVE-2010-3333 is a vulnerability in Microsoft Word. There is also a Metasploit module (ms10_087_rtf_pfragments_bof.rb) for it targeting Office 2003, 2010, and 2010. Written by ex-Metasploit Exploit Developer Joshua J. Drake. Demo:

Screen+Shot+2013-06-05+at+5.41.58+PM.png

Sursa: https://community.rapid7.com/community/metasploit/blog/2013/06/07/have-a-taste-of-communism-with-a-mouthful-of-apt

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...