NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

Advisories


Cyber-Criminals Target Their Own Kind

Vulnerabilities in crimeware kits are being exploited to steal the assets of the competition

By Lucian Constantin, Web News Editor

2nd of March 2009, 09:33 GMT

Adjust text size:


The Zeus crimeware kit is vulnerable
Enlarge picture
Cyber-crooks are not only exploiting security flaws in popular software in order to steal from vulnerable and innocent users. Independent Security Consultant Dancho Danchev describes how vulnerabilities in unpatched releases of the Zeus crimeware kit are being exploited by hackers in order to steal resources from their fellow criminals.

The security researcher has come across an interesting posting made by a botnet runner, who asks for help to secure his infrastructure after being compromised several times by other hackers. According to his own account, someone hijacked his botnet, composed of over 100,000 compromised computers, by exploiting a vulnerability in the Zeus kit, which allowed remotely injecting a high-level account into the administration panel of the crimeware.

Zeus is one of the popular commercial kits used by phishers and stands proof of the existence of an ever-evolving profitable underground industry. The crimeware (software used for criminal purposes) comes packed with a mind-boggling set of features, and allows phishers to easily create customized banking information-stealing trojans, as well as distribute and administer them.

At the time of its creation, the Zeus crimeware kit cost around $700, but, just as any application, it is susceptible to vulnerabilities, bugs and misconfiguration. In a post dating back to June 2008, Dancho Danchev announces that  a vulnerability "allows the injection of logins and passwords within any misconfigured web interface, due to the way in which Zeus is processing php scripts (web shells and backdoors) from the directory in which it stores the stolen data."

Zeus crimware kit administration panel
Enlarge picture
The recent discussion that the researcher has intercepted is particularly describing a real situation where a cyber-criminal has been plundered as a result of this vulnerability. "Dear colleagues, I'd like to hear all sorts of ideas regarding to [sic] security of Zeus. I've been using Zeus for over an year now, and while I managed to create a botnet of 100k infected hosts, someone hijacked it from me by adding a new user and changing my default layout to orange just to tip once he did it," the "victim" reports, according to a translation by Mr. Danchev.

After securing the directory permissions and applying all the available security patches for the Zeus command and control server, the phisher successfully regained control over a third of his former botnet, only to be hit again. The second attack has led him to conclude that there has been a more serious, underlying flaw in the crimeware kit. "In my opinion, a request was made to the database, either through an sql injection in s.php file or a request from within a user with higher privileges," the botnet runner writes.

The cyber-criminal goes on to offer what he calls his own "clever tips" to secure the tool. "Surreal? Not at all, given the existing monoculture on the crimeware market," Dancho Danchev adds. The security researcher also points out that a similar serious vulnerability has recently been identified in another crimeware kit known as Firepack.

These incidents raise a bunch of interesting ethical questions. Should vulnerabilities in crimware be reported and treated with the same objectivity as the ones affecting other software? Should hacked hackers be considered victims and felt sorry for, or are such stories just examples of ironic twists of fate?

I guess that "What goes around, comes around" would be an appropriate conclusion for some, yours truly included.

TAGS:

Zeus | crimware kit | malware development | botnet hijacking | vulnerability
Read by 4,890 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (4.8/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


ISP Hosting Rogue DNS Servers Shut Down

Spam Distribution Reaches Almost pre-McColo Levels

Zlob Trojan Writer Packs Up Shop and Greets Microsoft

Storm Botnet Cleaning Method Revealed

Botnet Tool to Support Israel's Offensive

Three Year Old Trojan Compromised Half Million Banking Details

Malware Spreading Tool for the Masses

Phishers Update Their Infrastructure

User opinions:


Comment #1 by: Michael on 03 Apr 2009, 17:03 GMT reply to this comment

Perhaps Law Enforcement could exploit these flaws to reclaim stolen information, etc.


Comment #2 by: Val on 06 Apr 2009, 17:12 GMT reply to this comment

After reading this article, I feel more vulnerable than ever about using the internet to do any of my information transactions. Since there are different levels of tech nerds doing there crime games leaving the rest of the "normal" population frustrated and angry.
Can't We Just Get Along, for once!!!

Comment #2.1 by: Lucian Constantin on 07 Apr 2009, 07:12 GMT

Hello Val,

Thank you for commenting on this article.

These "nerds" are no different than the thieves we face in real life. Granted, they are using the electronic equivalent of "lockpicks," but what drives them are the same easy monetary gains obtained through illegal means.

Now, thieves have existed since forever and most likely they will be around forever, as long as people have assets. Unfortunately, it's in the human nature. Therefore, we can't expect us to "just get along," because we will never do.

The real issue is to try and limit our losses. At the moment, stealing the financial data and implicitly the money of someone else online is much easier and hard to trace than breaking into someone's home and plundering their jewelry box for example.

The anonymous and global nature of the Internet makes it more likely for you to be "robbed" online than in real life. That's the problem we need to tackle.

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM