Showing posts with label CVE-2010-2883. Show all posts
Showing posts with label CVE-2010-2883. Show all posts
Wednesday, October 26, 2011
Thursday, July 14, 2011
Jul 13 CVE-2010-2883 PDF Meeting Agenda with more Poison Ivy www.adv138mail.com | 112.121.171.94
Other PI domains noted are:
web.adv138mail.com; -2011
dns.adv138mail.com - 2011 (thank you, John)
web.adv138mail.com; -2011
dns.adv138mail.com - 2011 (thank you, John)
www.adv138mail.com - 2011 - 112.121.171.94
pu.flower-show.org - 2011 - 112.121.171.94
pu.flower-show.org - 2011 - 112.121.171.94
cecon.flower-show.org - 2010
posere.flower-show.org - 2009
posere.flower-show.org - 2009
112.121.171.94 Nov.adv138mail.com, ftp.adv138mail.com and asm.adv138mail.com point to 112.121.171.94.
- Contagio | Jul 5 CVE-2010-2883 PDF invitation.pdf with Poison Ivy from 112.121.171.94 | pu.flower-show.org
- Contagio | More flowers with some poison ivy - Feb. 10, 2010
- F-secure | Watch Out for flower-show.org - Feb.10, 2010
- ISC | Sophisticated, targeted malicious PDF documents exploiting CVE-2009-4324 - Jan 4, 2010
Jul 5 CVE-2010-2883 PDF invitation.pdf with Poison Ivy from 112.121.171.94 | pu.flower-show.org
Update Jul 13. Considering that this pdf is very low detection, I decided to post some of the target domains here in case it helps them to prevent or identify infections.
The non-gmail domains included:
usjapancouncil.org, spfusa.org, vanderbilt.edu, comdt.uscg.mil, miis.edu
If you work at one of those places and must know the actual recipient, you can contact me. ~ Mila
Contagio | More flowers with some poison ivy - Feb. 10, 2010
F-secure | Watch Out for flower-show.org - Feb.10, 2010
ISC | Sophisticated, targeted malicious PDF documents exploiting CVE-2009-4324 - Jan 4, 2010
Tuesday, May 31, 2011
May 17 CVE-2010-2883 PDF Bin Laden's successor from spoofed Nationalpost.com
Common Vulnerabilities and Exposures
CVE-2010-2883 Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010.
General File Information
MD5 8E633588B3EE59DE09FE126D99869D2D
SIZE 103981 bytes
EXPLOIT TYPE CVE-2010-2883
FILE NAME Bin Ladens successor.pdf
The file uses Fonts/SING CVE_2010-2883 exploit, which does not seem to be metasploit generated.
* Jan 12 CVE-2010-3654 + CVE-2009-4324 + CVE-2009-0927 + CVE-2008-0655 PDF JANUARY 2011 from a compromised Thai Police account
EXPLOIT TYPE CVE-2010-2883
FILE NAME Bin Ladens successor.pdf
Post Updates
The sender is often uses compromised servers of different organizations
* Jan 6 CVE-2010-3333 DOC with info theft trojan from the American Chamber of Commerce* Jan 12 CVE-2010-3654 + CVE-2009-4324 + CVE-2009-0927 + CVE-2008-0655 PDF JANUARY 2011 from a compromised Thai Police account
It is unclear whether this time it is a compromised server or the attacker uses the services of this internet provider as a customer
Beyond the Network America, Inc. (BTNaccess) is a wholly owned subsidiary of PCCW, and is headquartered in Reston, Virginia and Hong Kong with offices in Los Angeles, New York City, Philadelphia, Houston, London, Moscow, Prague, Kuala Lumpur, Singapore, Shenzhen, Tokyo, Mumbai and New Delhi.
PCCW, a global leader in next generation broadband solutions, is the largest telecommunications provider in Hong Kong. PCCW is the operator of one of the world’s most advanced broadband networks and has over 700,000 broadband customers and 12,500 employees worldwide. As a global player, PCCW has portrayed innovation within the industry and demonstrated financial stability with 2003 revenues reaching US$2.89 billion.
Friday, December 3, 2010
Nov 19 CVE-2010-2883 with Flash JIT Spray (PDF in PDF) Event Invitation from The Heritage Foundation from spoofed Heritage address
Common Vulnerabilities and Exposures (CVE)number
CVE-2010-2883 Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
General File Information
File Event Invitation from Heritage.pdf
MD5 529AE8C6AC75E555402AA05F7960EB0D
SHA1 d793f0c3e051bc03b0cd5e2c2f87f3be33612d49
File size : 358996
Type: PDF
Distribution: Email attachment
Wednesday, November 10, 2010
CVE-2010-3654 Adobe Reader 0 day + CVE-2010-2883 Flash 10.1.102.64 + Reader 9.4.0.195 PDF Federal Benefits
Common Vulnerabilities and Exposures (CVE)number
CVE-2010-3654 Adobe Flash Player 10.1.85.3 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.95.2 and earlier on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.
CVE-2010-2883 Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
Update 6, Nov 16 2010-------------------------------------------------------------------------------------------
After yesterday tweets (snowfl0w and sempersecurus), GoDaddy took notice and suspended mysundayparty.com domain
here is the email
Registrant:
debby ryan
411 N. 6th Street, Emery, SD
Emery, SD
sd, shen zhen 90002
China
Registered through: GoDaddy.com, Inc. (http://www.godaddy.com)
Domain Name: MYSUNDAYPARTY.COM
Created on: 15-Sep-10
Expires on: 15-Sep-11
Last Updated on: 15-Sep-10
Administrative Contact:
ryan, debby g.debbei_@yahoo.com
411 N. 6th Street, Emery, SD
Emery, SD
sd, shen zhen 90002
China
+86.9801455 Fax --
Technical Contact:
ryan, debby g.debbei_@yahoo.com
411 N. 6th Street, Emery, SD
Emery, SD
sd, shen zhen 90002
China
+86.9801455 Fax --
Domain servers in listed order:
NS1.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
NS2.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
Update 5, Nov 15 2010-------------------------------------------------------------------------------------------
mysundayparty.com domain is still active. resent the message below to abuse@godaddy.com
Update 4, Nov 13 2010-------------------------------------------------------------------------------------------
mysundayparty.com domain is still active
The message that was sent to GoDaddy abuse department on Nov 10, 2010 read
After yesterday tweets (snowfl0w and sempersecurus), GoDaddy took notice and suspended mysundayparty.com domain
here is the email
---------- Forwarded message ----------Here is current Whois
From: GoDaddy Abuse Department
Date: Tue, Nov 16, 2010 at 11:16 AM
Subject: RE: reminder - mysundayparty.com complaint
To: Mila
Dear Mila Parkour,
Thank you for bringing this situation to our attention. We have gone
ahead and suspended the domain name in question.
Please let us know if you find any other domain names connected to C&C
servers or other malware distribution.
Regards,
Joe
GoDaddy.com
Spam and Abuse Department
24/7 Abuse Department Hotline: 480-624-2505
ARID1003
Registrant:
debby ryan
411 N. 6th Street, Emery, SD
Emery, SD
sd, shen zhen 90002
China
Registered through: GoDaddy.com, Inc. (http://www.godaddy.com)
Domain Name: MYSUNDAYPARTY.COM
Created on: 15-Sep-10
Expires on: 15-Sep-11
Last Updated on: 15-Sep-10
Administrative Contact:
ryan, debby g.debbei_@yahoo.com
411 N. 6th Street, Emery, SD
Emery, SD
sd, shen zhen 90002
China
+86.9801455 Fax --
Technical Contact:
ryan, debby g.debbei_@yahoo.com
411 N. 6th Street, Emery, SD
Emery, SD
sd, shen zhen 90002
China
+86.9801455 Fax --
Domain servers in listed order:
NS1.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
NS2.SUSPENDED-FOR.SPAM-AND-ABUSE.COM
Update 5, Nov 15 2010-------------------------------------------------------------------------------------------
mysundayparty.com domain is still active. resent the message below to abuse@godaddy.com
24.248.182.214
Hostname: wsip-24-248-182-214.ph.ph.cox.net - Is it C&C or someone's sinkhole? Anybody?Update 4, Nov 13 2010-------------------------------------------------------------------------------------------
mysundayparty.com domain is still active
The message that was sent to GoDaddy abuse department on Nov 10, 2010 read
Dear GoDaddy Abuse Department,
mysundayparty.com has been C&C for 0-days malware
and used in targeted attacks described above.
Please take action asap
Thanks
Monday, November 8, 2010
CVE-2010-2883 PDF An invitation to the Nobel Prize ceremony of Liu Xiaobo
Common Vulnerabilities and Exposures (CVE)number
CVE-2010-2883 Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information
General File Information
File invitation.pdf
MD5 : 29db2fba7975a16dbc4f3c9606432ab2
SHA1 : 5d65e6984e521936707b32219b39388efb4296fa
File size :344218 bytes
Type: PDF
Distribution: Email attachment
Post Updates
Nov 8, 2010 Post by Mikko H. Hyppönen on F-Secure blog - Case Nobel
- Nov 10, 2010 CPJ. Committee to Protect Journalists. That Nobel invite? Mr. Malware sent it -- By Danny O'Brien/CPJ Internet Advocacy Coordinator
- Nov 10, 2010 Computerworld (Norway) New attack against Nobel Prize by Ole Petter Baugerød Stokke (Google Translated)
- Nov 10, 2010 Le Figaro*fr Nobel: new computer attack (Google translated)
- Nov 10, 2010 APF Google New cyber attack linked to Nobel Peace Prize
- Nov. 13 Infowar Monitor Nobel Peace Prize, Amnesty HK and Malware by Nart Villeneuve
More about similar attacks
- Oct 22, 2010 Infowar Monitor Command and Control in the Cloud
- Aug 19, 2010 Infowar Monitor Human Rights and Malware Attacks
Thursday, October 14, 2010
Oct 08 CVE-2010-2883 PDF Nuclear Challenges and Responses in the Century from JUN.Bong-Geun@ifans.go.kr
CVE-2010-2883 Stack-based buffer overflow in CoolType.dll in Adobe Reader and
Acrobat 9.3.4 and earlier allows remote attackers to execute arbitrary
code or cause a denial of service (application crash) via a PDF
document with a long field in a Smart INdependent Glyphlets (SING)
table in a TTF font, as exploited in the wild in September 2010.
NOTE: some of these details are obtained from third party information.
From: JUN.Bong-Geun@ifans.go.kr [mailto:JUN.Bong-Geun@ifans.go.kr]
Sent: Friday, October 08, 2010 1:43 PM
Subject: Nuclear Challenges and Responses in the Century
Dear all
We inform you of an event and expect your kindly opinions.
On October 4th-5th 2010, the IFANS Conference on Global Affairs in 2010, "Nuclear Challenges and Responses in the Century" is hosted by the Institute of Foreign Affairs and National Security (IFANS) and the Presidential Council for Future and Vision (PCFV), and is organized by the Institute of Foreign Affairs and National Security (IFANS),ROK.
At the conference,in-depth discussion is expected among international and Korean experts and turn-out policy recommendations in terms of three subjects.
The sessions and programs were attached to a file "Conference Information.pdf".
Headers
Received: (qmail 13720 invoked from network); 8 Oct 2010 01:43:34 -0000Received: from mail.tekkan.com (HELO mail.tekkan.com) (164.46.125.50)
by XXXXXXXXXXXXXXXXX; 8 Oct 2010 01:43:34 -0000
Received: from mofat-p6463dmel ([221.9.247.17])
by mail.tekkan.com (8.12.11.20060829/8.11.3) with SMTP id o981guo7022508;
Fri, 8 Oct 2010 10:42:59 +0900
Message-ID: <201010080142.o981guo7022508@mail.tekkan.com>
From: JUN.Bong-Geun@ifans.go.kr
To:
Subject: Nuclear Challenges and Responses in the Century
Date: Fri, 8 Oct 2010 10:43:08 -0700
X-Mailer: CSMTPConnection v2.17
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="ad7e60eb-fca5-415b-9c56-9d74439519e2"
Content-Transfer-Encoding: quoted-printable
Hostname: 221.9.247.17
ISP: China Unicom Jilin province network
Organization: China Unicom Jilin province network
Assignment: Static IP
Country: China
State/Region: Jilin
City: Changchun
Virustotal
http://www.virustotal.com/file-scan/report.html?id=0c8f17b2130addebcb2ca75bd7a982e37ddcc49d49e79fe60e3fda767f2ec972-1287057726
File name:Conference Information_2010 IFANS Conference on Global Af[...].pdf
Submission date:2010-10-14 12:02:06 (UTC)
Current status:
14/ 43 (32.6%)
Avast 4.8.1351.0 2010.10.14 PDF:CVE-2010-2883
Avast5 5.0.594.0 2010.10.14 PDF:CVE-2010-2883
AVG 9.0.0.851 2010.10.14 Exploit_c.LMW
BitDefender 7.2 2010.10.14 Exploit.PDF-TTF.Gen
Comodo 6388 2010.10.14 UnclassifiedMalware
F-Secure 9.0.16160.0 2010.10.14 Exploit.PDF-TTF.Gen
GData 21 2010.10.14 Exploit.PDF-TTF.Gen
Kaspersky 7.0.0.125 2010.10.14 Exploit.Win32.CVE-2010-2883.a
NOD32 5530 2010.10.14 JS/Exploit.Shellcode.A.gen
Norman 6.06.07 2010.10.14 HTML/Shellcode.Q
nProtect 2010-10-14.01 2010.10.14 Exploit.PDF-JS.Gen
PCTools 7.0.3.5 2010.10.14 Trojan.Pidief
Sophos 4.58.0 2010.10.14 Mal/JSShell-B
Symantec 20101.2.0.161 2010.10.14 Trojan.Pidief
Additional information
Show all
MD5 : 3abfe5fd78ffddebf23bd46edf4e4eb7
Created files
C:\windows\system32\syschk.ocx
File name: syschk.ocx
MD5 : 16ba21c1eac48eb20c04ac91ef9c2bd1
Submission date: 2010-10-16 04:33:16 (UTC)
Result: 0/ 43 (0.0%)
Strings (yes, C:\Documents and Settings\Mila\Desktop\Conference Information_2010 IFANS Conference on Global Affairs (1001).pdf" is not a accidental paste, it is in the file = inserted path from the original location of the pdf.
C:\windows\system32\form.ocx = same string as it tried to download = see the pcap screenshot below
File: form.ocx
MD5: 279b3b44fa1ac9e72d030ff42b1b77c6
Size: 15
Ascii Strings:
---------------------------------------------------------------------------
02510c
Unicode Strings:
---------------------------------------------------------------------------
MD5: 279b3b44fa1ac9e72d030ff42b1b77c6
Size: 15
Ascii Strings:
---------------------------------------------------------------------------
02510c
Unicode Strings:
---------------------------------------------------------------------------
66.220.9.57
Hostname: www.mbizgroup.bizISP: Hurricane Electric
Organization: LaFrance Internet Services
Proxy: None detected
Type: Corporate
Assignment: Static IP
Country: United States
State/Region: California
City: Fremont
Tuesday, September 21, 2010
Sep 21 CVE-2010-2883 PDF Agenda of the United Nations Criminal Justice Events in October 2010
CVE-2010-2883 Stack-based buffer overflow in CoolType.dll in Adobe Reader and
Acrobat 9.3.4 and earlier allows remote attackers to execute arbitrary
code or cause a denial of service (application crash) via a PDF
document with a long field in a Smart INdependent Glyphlets (SING)
table in a TTF font, as exploited in the wild in September 2010.
NOTE: some of these details are obtained from third party information.
Download ac4a484bb27e08433f822d4120291be4 UNICRI-Agenda-2010.pdf as a password protected archive (contact me if you need the password)From: Cook Henry [mailto:henry.b.cook@gmail.com]
Sent: Tuesday, September 21, 2010 2:46 PM
To: XXXXXXXXXX
Subject: Agenda of the United Nations Criminal Justice Events in October 2010
sir,
In case this is useful for you.
UNICRI-Agenda-2010.pdf
http://www.virustotal.com/file-scan/report.html?id=b058fcc16446464c0aa94edabbc98cfd87d5d2ac2f9e3009b11a3aff96ed53b7-1286451255
13/ 43 (30.2%)
AntiVir 7.10.12.146 2010.10.07 HTML/Malicious.PDF.Gen
Avast 4.8.1351.0 2010.10.07 PDF:CVE-2010-2883
Avast5 5.0.594.0 2010.10.07 PDF:CVE-2010-2883
AVG 9.0.0.851 2010.10.07 Exploit_c.KLX
BitDefender 7.2 2010.10.07 Exploit.PDF-TTF.Gen
Emsisoft 5.0.0.50 2010.10.07 Exploit.Win32.CVE-2010-2883.a!A2
F-Secure 9.0.15370.0 2010.10.07 Exploit.PDF-TTF.Gen
Fortinet 4.2.249.0 2010.10.07 PDF/CoolType!exploit.CVE20102883
GData 21 2010.10.07 Exploit.PDF-TTF.Gen
Kaspersky 7.0.0.125 2010.10.07 Exploit.Win32.CVE-2010-2883.a
Microsoft 1.6201 2010.10.07 Exploit:Win32/CVE-2010-2883.A
PCTools 7.0.3.5 2010.10.07 HeurEngine.MaliciousExploit
Symantec 20101.2.0.161 2010.10.07 Bloodhound.Exploit.357
Additional information
MD5 : ac4a484bb27e08433f822d4120291be4
Friday, September 17, 2010
CVE-2010-2883 Adobe 0-Day David Leadbetter's One Point Lesson from 193.106.85.61 thomasbennett34@yahoo.com
CVE-2010-2883 Security Advisory for Adobe Reader and Acrobat
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.
A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.
Technical Analysis and Research links (just a few, in no particular order, send more if you want me to add)
- Brief Analysis On Adobe Reader SING Table Parsing Vulnerability (CVE-2010-2883) Matt Oh
- Return of the Unpublished Adobe Vulnerability http://blog.metasploit.com/ Joshua J. Drake
- New Adobe 0day Demonstration - Attack Vector Matt
- Adobe advises on new Reader and Acrobat vulnerability Chester Wisniewski’s Blog
- VUPEN Vulnerability Research Team (VRT) Blog- Criminals Are Getting Smarter: Analysis of the Adobe Acrobat / Reader 0-Day Exploit << very detailed analysis
-
- =================================================================
Download files
- golf clinic.pdf - (\Application Data) - 6AF93ED231AEA3B00769FC8283943E75
- iso88591 - (same location as the original) F7A341ACBB05F6A597EC33ACCB7AD04E
- wincrng.exe + winhelp32.exe (downloaded from academyhouse.us) 687B8D2112F25E330820143EDE7FEDCE
- igfxver.exe (%tmp%) E8CE9CB98C71405F0FB3888235302568 - dropped by the original
Download hlp.cpl signed with the stolen Verisign certificate issued to secure2.ccuu.com
Update 10
Lead Adobe 0-day CVE-2010-2883 Made in Korea - by villy
Update9
[Unofficial] 0-Day Acrobat SING Table Vulnerability Patch (sent by INT3 CC, thank you)
https://www.rafzar.com/node/22
I did not test but heard it works well. Try it, test it
Update 8
Cédric Gilbert, from SkyRecon Systems sent a short and later (per my request, because I wanted to understand it ) , a more detailed explanation for the DEP bypass - in clear terms, for people who don't already know everything :)DEP Bypass in Golf Clinic PDF by Cédric Gilbert, SkyRecon Systems
Please comment and correct, if you find mistakes, we will add the corrections. Many thanks!
---------------------------------------------
There are 4 settings for DEP :- AlwaysOff- Opt-in- Opt-out- Always On
‘Opt-in’ is the one used by default on every Desktop Edition of Windows, while ‘opt-out’ is the default for Server Editions.‘Opt-in’ only protects software that is fully compatible with DEP (those software programs are marked at compilation with the flag ‘/NXCOMPAT’).‘Opt-out’ protects every software program (even the ones without /NXCOMPAT) except the ones explicitly added by the administrator to a white list.
“AcroRd32.exe” is not /NXCOMPAT, thus if an execution occurs in a page in memory marked as ‘not executable’ (the heap for instance), DEP in ‘opt-in’ mode will ignore the fault and silently change the rights of the page to ‘EXECUTE’. On the other hand, if DEP is set to ‘opt-out’, it will immediately kill the faulting process. This is why most exploits using heap spraying actually do work. Because even though execution occurs on the heap (NO EXEC) when the execution flow is redirected into the ‘nop’ slide, DEP in opt-in mode will not block the attack.
Now the writers of the exploit used in this case obviously wanted to go a step further by bypassing DEP even in its ‘opt-out’ or ‘always-on’ mode.
Which means that they had to find a way to execute their payload without triggering any ‘page fault’ in NO EXECUTE memory.
The best way to do so is to use some kind of ‘ret into libc’ technique (in this case a ROP technique). Instead of redirecting the execution flow into the heap, they redirect it to a CODE section in a DLL (which got EXECUTE rights) by overwriting saved eip on the stack. Of course no DLL exactly have the code that the attacker would like to execute, so the idea is to chain calls into this DLL on small code portions using return addresses smartly placed on the stack before the vulnerability is triggered. The problem with this technique is that it requires the attacker to use ‘hardcoded’ addresses pointing at each code portion that he wishes to execute.
Starting with Windows Vista, Microsoft introduced a new protection called ‘ASLR’ for Address Space Layout Randomization. This protection, among other things, randomize the base address of each DLL when they get loaded into a process address space (the random base address changes at each boot). This protection was meant to defeat attacks, which used hardcoded addresses, since a randomized DLL place in memory is changing at each boot.
So to defeat both DEP and ASLR, the attacker got AcroRd32.exe to load a DLL not compatible with ASLR into its address space (I do not know how they managed to do so at the moment).The DLL used is “icucnv34.dll”, the fact that it is not compatible with ASLR means that it will always get loaded at the same address in memory, thus allowing the attacker to use ‘hardcoded’ addresses pointing to this DLL.
The thing is, it’s very complicated to build a whole shellcode using this kind chained call into a DLL. So the attacker used it only to get a place in memory allocated with exec rights, copy his shellcode on it and, eventually, jump on it and do whatever he wants without caring about DEP anymore.
In this exploit, the attacker manages to do so by chaining 4 API call in “icucnv34.dll”.
1) CreateFileA:IN LPCTSTR lpFileName = 4a8254e0 = « iso88591 »
IN DWORD dwDesiredAccess = 0x 10000000 = GENERIC_ALL
IN DWORD dwShareMode = 0 = not shared
IN lpSecurityAttributes (OPTIONAL) = 0
IN DWORD dwCreationDisposition = 2 = CREATE_ALWAYS
IN DWORD dwFlagsAndAttributes = 0x102 = FILE_ATTRIBUTE_TEMPORARY | FILE_ATTRIBUTE_HIDDENHere the attacker creates an empty file called “iso88591” at the location where the pdf was opened.
2) CreateFileMappingAIN HANDLE hFile = 0x1c4 = handle on « iso88591 »IN OPT lpAttributes = NULLIN DWORD flProtect = 0x40 = PAGE_EXECUTE_READWRITEIN DWORD dwMaximumSizeHigh = 0IN DWORD dwMaximumSizeLow = 0x10000IN OPT LPCTSTR lpName = NULLSince the file is empty, the attacker has to specify an arbitrary size for the file mapping.At this point the attacker is ready to map the file into memory.
3) MapViewOfFileIN HANDLE hFileMappingObject = 0x2dc = Handle from CreateFileMappingAIN DWORD dwDesiredAccess = 0x22 = FILE_MAP_EXECUTE | FILE_MAP_WRITEIN DWORD dwFileOffsetHigh = 0IN DWORD dwFileOffsetLow = 0IN SIZE_T dwNumberOfBytesToMap = 0x10000Now the attacker’s got a 0x10000 bytes space with EXECUTE rights allocated into memory. All that he has to do to complete his ‘DEP-evading-technique’ is to copy the shellcode that he wishes to execute in this newly allocated exec space and jump on it.Which he does by calling :4) MSVCR80!memcpyDst = 0x05bc0000 // Base Address returned from the MapViewOfFile aboveSrc = 0885f118 // Not sure whether it is an address from the mapping of the pdf itself or something that he sprayed on the heap beforeLen = 0x1000
And here we are, after this call the real payload (at 0x0885f118) is mapped into an ‘EXEC’ memory space (at 0x05bc0000). The jump to the the payload is actually made by the memcpy call itself since the return address set on the stack by the attacker for this call is the destination of the copy (0x05bc0000) ! BAM! Both ASLR and DEP are defeated!
Now one may ask : ”Ok nice, icucnv34.dll is not ASLR-compatible, but kernel32.dll is, so how did the attacker get the required API addresses?”. Well, it is pretty simple actually, he just had to use API imported by icucnv34.dll ! When this DLL got loaded, its import table got fixed by the loader with the addresses of all API required by the DLL.Since the base address of icucnv34.dll is known by the attacker, he just had to retrieve the needed addresses from icucnv34.dll import table :)
Cédric Gilbert, SkyRecon Systems
Update7 - Aurora?
Here here an interesting observation by Itzhak Avraham (Zuk) @ihackbanme about the fact that this pdf is using a technique similar to one found in Aurora.DMS.bat mentioned in Update 6, has been observed during analysis of ad_1_.jpg file, which was one of the files recovered during the Aurora investigation (see Aurora US-CERT advisory here)
ad_1_.jpg unpacking/analysis - Aurora by Itzhak Avraham (Zuk)
DFS.bat from ad_1_.jpg (Aurora)
The DMS.bat from CVE-2010-2883 Adobe 0-Day
:Repeat
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl"
if exist "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl" goto Repeat
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\DMS.bat"
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl"
if exist "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl" goto Repeat
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\DMS.bat"
Update6
Exploit in action:(see a video demo in the end of this post)According to Sophos researchers (many thanks to Chester Wisniewski) -
- the shellcode drops hlp.cpl DLL to user %tmp% folder and then manually parses to its StartUp export and runs from there.
- wincrng .exe gets downloaded using the DLLs's "DownloadFile" export from hxxp://academyhouse .us/from/wincrng exe to user Application Data folder, renames it to winhelp32.exe and runs it. The domain is currently under the control of Shadow Server (http:/internal/tools/whois/?domain=academyhouse.us)
- The DLL then calls its "MakeAndShowEgg" export, which reads a filename from the original PDF ("Golf Clinic.pdf") and then drops a clean PDF file (golf clinic.pdf 6AF93ED231AEA3B00769FC8283943E75) and launches it in Acrobat Reader so as not to arouse suspicion. The text of the PDF, however, still arouses a lot of suspicion - see below :)
- Finally the DLL calls the imaginatively-titled "DeleteMyself" export to drop the file DMS.bat which deletes the DLL and then itself.
:Repeat
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl"
if exist "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl" goto Repeat
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\DMS.bat"
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl"
if exist "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl" goto Repeat
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\DMS.bat"
Update5
A few more variants of this message
Variant 2
from 119.247.163.249 MD5 2802c47b48cced7f1f027f3b278d6bb3
From: Thomas Bennett [mailto:Thomas.Bennett@gmx.com]
Sent: Tuesday, September 07, 2010 5:41 AM
To: xxx
Subject: Golf Clinic, David Leadbetter's One Point Lesson
Importance: High
Hi
Want to improve your score?
In these golf tips David Leadbetter shows you some important principles Cause & Effect, which have been helpful to thousands of amateur golfers around world.
Whatever your handicap, Whatever your age or ability, the tips will improve your game!
bye
Posted by
Mila
at
3:39 PM
3
comments
Tags:
- ADOBE READER + ACROBAT 9.3.4,
certificate,
CVE-2010-2883
Subscribe to:
Posts (Atom)




