Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft

April 5th, 2007, 09:38 GMT · By

Chinese Hackers Make Available Microsoft Exploit Building Tool

SHARE:

Adjust text size:



Enlarge picture
Not a hacker? No problem! Not even technically skilled? Again no problem. "2007 Doc Binder" will do all the work for you! Exploiting vulnerabilities across Microsoft products has never been easier! According
to Symantec, the number of samples for Trojan.Mdropper.X is through the roof. Usually, the case is that a malware family numbers something in the vicinity of five different samples. Trojan.Mdropper.X has in excess of 30. All the samples of Trojan.Mdropper.X are designed to target a Word Malformed Data Structures Vulnerability - CVE-2006-6456 that has been patched by Microsoft as of February 13, 2007.

At the basis of the Trojan.Mdropper.X expansion is none other than the "2007 Doc Binder," a Chinese toolkit that enables users to build Microsoft Word samples that exploit the CVE-2006-6456 flaw.

"The attacker has only to bind an executable such as Backdoor or an Infostealer trojan, and the tool will do the rest. It will create a malicious MS Word file that can drop and run the chosen .exe file. No need to analyze buffer overflows, find return addresses, or program complicated shellcode. Zero knowledge, maximum result, and minimal effort. Using this tool, an attacker could potentially generate several variants of malicious documents in a few minutes and spam them out immediately," revealed Elia Florio, Symantec Security Response Engineer.

Symantec has issued an additional warning revealing that while these exploits are indeed generated automatically, some recent samples in the wild had suffered manual patching and alterations in order to avoid detection by security software. Symantec has concluded in this regard that an evolved version of the "2007 Doc Binder" tool has become available.

"We observed that the samples generated by this tool have the shellcode located usually around offset 0x16730. The shellcode starts with the magic value of "C!29" (0x43213239), which is a kind of static marker used by the exploit. The executable is encrypted with a trivial XOR and is appended at the end of the .doc file. The generic detection for the Trojan.Mdropper.X family is currently detecting all the files generated by this tool," Florio added.

TELL US WHAT YOU THINK:

2,799 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft Office 2007 Basic, Standard, Small Business, Professional and Ultimate - Comparison

The $100,000 Microsoft Poetry Has New York Store-Front

Windows PowerShell Will Be Included into Windows Server Longhorn

Windows Vista - Cool, Natural and Refreshing

Microsoft Tahiti Pre-Beta

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM