Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

March 9th, 2011, 16:35 GMT · By

New 'Open Source' Exploit Toolkit Identified

SHARE:

Adjust text size:


k0desploit exploit toolkit distributed for free
Enlarge picture
Researchers from security vendor M86 Security have identified a new exploit toolkit being distributed on the underground market for free and being worked on as a community effort.

Called k0desploit, the new toolkit is actually based on the notorious Eleonore exploit pack which is commonly used in drive-by download attacks.

The k0desploit admin panel login page displays the text "K0de.org Open Source Exploits," which sent M86 researchers searching for more information about it.

This lead them to a few forum posts made by the original author explaining the toolkit is an improved version of the Eleonore mod posted by Blackdevil.

He mentions that preliminary tests done on 1,000 computers revealed an infection rate of 9.6%, significantly more than the original 3.5% the Eleonore mod had.

The developer also notes that most of the successful attacks were for the MDAC and IE vulnerabilities, not Java as previous research suggested.

He also claims he got the exploits to partially work via Firefox and Chrome, which they didn't before, and he appeals to the community to help with the exploit development.

"In addition to the 'open-source' exploit kit, the page contains a long list of anonymous proxy servers near the bottom as well as stolen credit card numbers along with the login credentials of dozens of individuals," the M86 experts say about the forum post they found.

Drive-by download attacks launched from compromised legit websites are one of the primary malware distribution vectors used today.

They are widely preferred over other propagation channels because they result in a much higher infection rate and can last for longer if done properly.

Most attack toolkits are commercial in nature and cost significant sums of money, however, free alternatives like k0desploit do exist for people who are just starting their cyber criminal activity.

Users are advised to keep all of their software, including the operating system, up to date and to run an antivirus capable of scanning Web traffic at all times.

TELL US WHAT YOU THINK:

1,851 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Blackhole-Powered Drive-By Download Attacks on the Rise

New Phoenix Exploit Kit Version Employs Anti-Analysis Techniques

New Drive-By Download Attack Exploits Recently Patched IE Flaw

Siberia Exploits Kit Features AV Scanner Module

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM