5 ms·
I've seen reports of the attack vector being IE and Acrobat, Flash player and (IIRC) Windows XP. It doesn't matter what the actual product was, it only matters
by achew22 17y ago
I've seen reports of the attack vector being IE and Acrobat, Flash player and (IIRC) Windows XP. It doesn't matter what the actual product was, it only matters that people aren't patching well known vulnerabilities. The vector is not a particular program it is a lack of attention to detail when it comes to patches.
- tptacek 17y agoIt doesn't matter if you patch well-known vulnerabilities if the Chinese are using undocumented flaws in browsers to attack you. HN doesn't want to hear this, but in the worst case IE is probably tied with Firefox as the most secure browser.
- BrandonM 17y agobut in the worst case IE is probably tied with Firefox as the most secure browser. The difference being that Once the malware is downloaded and installed, it opens a back door that allows the attacker to perform reconnaissance and gain complete control over the compromised system. is less feasible in Firefox than it is in IE. Firefox forces you to download an executable and then manually run it, so a user would be conscious that he or she is installing a program. It is still possible (last I knew) in IE to install a program practically in the background, or to get broader OS control through a browser vulnerability.
- sriramk 17y agoHow is this possible in IE?
- julio_the_squid 17y agoWhat I wonder about IE is how sites or access points set cookie without there even being a browser window open. When I go to certain coffee shops, I'll see the 'this and this site is trying to set a cookie' popup (since I have IE set not to accept cookies) and I don't even have IE open!
- bd 17y ago"Firefox forces you to download an executable and then manually run it, so a user would be conscious that he or she is installing a program." Unfortunately not. I already encountered malware specifically targeted to Firefox that was fully automatic. It used some Mozilla specific JS hooks to launch Acrobat plugin. This in turn loaded tiny infected PDF that exploited some Acrobat security hole which allowed to directly execute code on your machine. It was enough to visit a compromised website, no further user action required. All was happening automatically, practically invisible to the user. I only noticed it because Acrobat plugin is a massive resource hog, so I managed to kill it in time before it could execute a payload.
- ars 17y agoWhat you wrote is not a firefox attack, it's acrobat attack. You don't need Mozilla specific JS hooks to launch an Acrobat plugin - I don't even think there is such a thing. Acrobat plugin opens automatically if you embed a pdf.
- bd 17y agoI don't remember details, it happened already some time ago. It was actually quite sophisticated malware - heavily obfuscated, assembling itself from pieces spread all around the world, jumping through several hoops of compromised servers. When I finally managed to reverse engineer to JS code that carried the infection, it was full of functions I didn't even know existed. Not usual JS, more like API hooks to the underlying platform, with special prefixed names. These names indicated it was about plugins. BTW it was multiplatform, attacking not just Firefox, there was a browser detection and browser specific code paths for several popular browser. I remember there was also something trying to use Silverlight. Oh, and it was multipurpose. Besides trying to infect your PC with a malware, it was also earning money. Some parts of JS were loading ads in invisible frames, presumably to be part of some distributed click farm.
- tptacek 17y agoThis comment demonstrates a misunderstanding of the problem. The problem probably isn't that the Chinese can trick people into running programs they download. The problem is that your browser has secret, subtle, horrible security vulnerabilities that allow attackers to embed executable code on web pages that will get run without even creating a new process.
- mixmax 17y agoThis is very interesting coming from someone with a strong background in security and definitely not what I would expect to hear. Has IE ramped up security in later versions, has it always been like this or what?
- tptacek 17y agoNot that I'm vouching for the project, but IE may be among the 5 products that receive more security attention, internally and externally, than any other product.
- ZeroGravitas 17y agoDoes receive security attention externally mean targeted by an entire industry of malware writers, trained and funded by many lucrative years of previous insecurity and ubiquity?
- tptacek 17y agoThat and the hundreds of thousands of dollars Microsoft spends to have it continually re-assessed by external consultants.
- nishantmodak 17y agow.r.t Firefox I use a plugin these days called NoScript.[https://addons.mozilla.org/en-US/firefox/addon/722 https://addons.mozilla.org/en-US/firefox/addon/722] - Allows active content to run only from sites you trust Finding it very useful!
- tptacek 17y agoNoScript is great, and it may reduce the attack surface of your browser, but it's not a panacea. If you look at the history of browser attacks, they're not overwhelmingly Javascript-based.
- invisible 17y agoBut it does reduce popups to 0, which reduces those fake "you have 5 viruses! Scan now" programs that fill up the whole screen (and probably cause a portion of malware).
- tptacek 17y agoAgain, just to be perfectly clear: assume that any time you browse with any mainstream browser to any malicious website, your browser could probably be popped. Especially if your adversary can bankroll $100,000-$200,000 of security research. That's the number I'd put on this attack. Maybe a reliable IE clientside bumps the number up north of $200,000, because folk wisdom puts the actual value of a reliable IE in the six figures. I don't know. I know what a year of time from someone who can find these bugs costs.
- julio_the_squid 17y agoThe equivalent salary for a top-notch engineer in China is about 12-25% of the US rate, however.
- tptacek 17y agoThat does not necessarily imply that Chinese vulnerability researchers are proportionally cheaper... yet.
- andreyf 17y agoIE is probably tied with Firefox as the most secure browser Meaning both are more secure than Chrome? What about the process sandboxing Chrome does?
- tptacek 17y agoIt's a good idea, but Chrome is very new code.