Link
Embed
Share
Beginning
This slide
Copy link URL
Copy link URL
Copy iframe embed code
Copy iframe embed code
Copy javascript embed code
Copy javascript embed code
Share
Tweet
Share
Tweet
Slide 1
Slide 1 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 1 Scareware From Ireland Mark Hillick IrissCert Incident Handler http://www.iriss.ie
[email protected]
Slide 2
Slide 2 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 2 What is Scareware?
Slide 3
Slide 3 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 3 Irish Scareware Exploit q Browse to Irish website & collect your fake anti- virus
Slide 4
Slide 4 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 4 Dialog-box fun…..
Slide 5
Slide 5 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 5 Dialog-box fun cont…..
Slide 6
Slide 6 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 6 System Scan
Slide 7
Slide 7 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 7 Trojan Log file
Slide 8
Slide 8 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 8 Money, please!
Slide 9
Slide 9 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 9 Are you sure?
Slide 10
Slide 10 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 10 Are you mad????
Slide 11
Slide 11 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 11 BSOD
Slide 12
Slide 12 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 12 Effect on the end-user….
Slide 13
Slide 13 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 13 Exploit q Exploited Sites hosted on one server § Microsoft FTPd & IIS 6.0 q Two most popular web site attacks – § Gumblar q PHP Sites § Asprox q SQL Injection
Slide 14
Slide 14 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 14 Pass the Parcel q http://compromisedsite.ie § http://jobstopfil.biz q http://poppka.net q http://sujetline.ru q http://grownclubfest.ru q PDF & SWF files served back
Slide 15
Slide 15 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 15 Obfuscation q Engaged SANS ISC Malware Team § Heavily obfuscated javascript § Used techniques not seen before
Slide 16
Slide 16 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 16 Complex Design….
Slide 17
Slide 17 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 17 q Tamper Data, Live HTTP Headers – Firefox q Burp Suite q Tcpdump, Wireshark & Netwitness q Dig/nslookup Tools Used
Slide 18
Slide 18 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 18 Incident Handling - Containment Source: http://www.tazworld.co.uk/gallery/pictures/www.tazworld.co.uk_taz_035.gif © Warner Bros. Entertainment Inc.
Slide 19
Slide 19 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 19 Incident Handling - Eradication Source -> http://www.alexross.com/CJ011.jpg © Warner Bros. Entertainment Inc
Slide 20
Slide 20 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 20 Incident Handling - Recovery Dilbert ©2009, United Feature Syndicate, Inc.
Slide 21
Slide 21 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 21 Incident Handling - Lessons Learned q Patch web-server & application § Input validation q Close unnecessary open ports (e.g. FTP) q Password Policy q Regular back-ups q Web-app security testing
Slide 22
Slide 22 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 22 Securing the Desktop q End-User Defence q Rescue CDs § Google -> “rescue site:raymond.cc” q Free Tools § http://zeltser.com/fighting-malicious-software/
Slide 23
Slide 23 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 23 Next Steps & Extra Info q Sans GCIH Gold Paper - Scareware & its evolution - Incident Handling Process q Full Incident Report - http://www.iriss.ie – in shared documents - http://www.hillick.net/things/scareware.doc
Slide 24
Slide 24 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 24 References q Sunbelt Blog q Dancho Danchev Blog q SANS ISC (Thanks to @bojanz) q VRT-Sourcefire Blog q Symantec White Papers q Sans Forensics Blog
Slide 25
Slide 25 text
Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 25 That's it..... Hat Tip for image - Jesse M. Heines - http://teaching.cs.uml.edu/~heines/images/ questions.gif