03:27 PM
Connect Directly

Hacker's Toolkit Attacks Unpatched Computers

The "smartbomb" toolkit sniffs for seven unpatched vulnerabilities in Internet Explorer and Firefox, then attacks the easiest-to-exploit weakness.

A dirt-cheap, do-it-yourself hacking kit sold by a Russian Web site is being used by more than 1,000 malicious Web sites, a security company said Monday.

Those sites have confiscated hundreds of thousands of computers using the "smartbomb" kit, which sniffs for seven unpatched vulnerabilities in Internet Explorer and Firefox, then attacks the easiest-to-exploit weakness.

For $15 to $20, hackers can buy the "Web Attacker Toolkit," said San Diego-based Websense in an online alert. The tool, which uses a point-and-click interface, can be planted on malicious sites -- or on previously-compromised computers -- to ambush unsuspecting users.

"It puts a bunch of code on a site that not only detects what browser the victim is running, but then selects one of seven different vulnerabilities to exploit, depending on how well patched the browser is," said Dan Hubbard, senior director of security and research at Websense.

Both Firefox and Internet Explorer vulnerabilities are among the seven.

Websense has detected the kit being used about 1,000 sites, which then plant a Trojan horse on vulnerable computers. The Trojan is installed in a silent "drive-by download" that doesn't require any user intervention; in fact, it installs in the background, so the user has no idea her computer has been hacked.

The Trojan can log keystrokes, download additional code, or open backdoors, said Websense.

"What's interesting is that these sites all have an administration console on them with statistics. We've managed to capture a couple of screenshots."

Those screens, posted with Websense's advisory, detail the browsers running on the compromised computers and keep a running tally of the most successful vulnerabilities.

According to the screenshots, the single site that Websense illustrated had attracted 51,896 computers, the bulk of them -- 76 percent, in fact -- running Microsoft Internet Explorer. (About 12 percent ran Firefox; the remainder were unspecified.)

This site, however, only used 4 of the 7 vulnerabilities, all of them directed at IE. The most successful of the quartet as one tagged as MS03-11 to match the security bulletin MS03-011, which published a patch for a bug in Microsoft Virtual Machine in April 2003. The malicious site managed to compromise 1,773 PCs using that three-year-old flaw, a 3.42 percent infection rate.

"And this is just one site," Hubbard said. "Together, these sites have compromised tens if not hundreds of thousands of systems."

The next-most useful vulnerability was dubbed "0-day" (zero-day), but was actually the "createTextRange" bug that was discovered last month and patched April 11 by Microsoft, said Hubbard. That vulnerability was used to compromise 1,507 PCs (2.9 percent success rate).

"Everyone knows they should patch their browsers," said Hubbard, "but this is further evidence that that's not happening as much as it should be."

The trend toward hackers sharing attack code, even selling simpleton software "kits," has been well-documented. Just last week, in fact, McAfee's research labs reported a major increase in the use of rootkits to cloak worms, Trojans, and spyware; the boost is largely due to cut-and-paste-style tools that automatically add rootkit components to other malicious code, Stuart McClure, chief of McAfee's research lab, said in an interview last week.

"The use of multiple vulnerabilities isn't commonplace," added Websense's Hubbard. "But this [toolkit] shows how hackers are becoming more and more organized."

Comment  | 
Print  | 
More Insights
The Business of Going Digital
The Business of Going Digital
Digital business isn't about changing code; it's about changing what legacy sales, distribution, customer service, and product groups do in the new digital age. It's about bringing big data analytics, mobile, social, marketing automation, cloud computing, and the app economy together to launch new products and services. We're seeing new titles in this digital revolution, new responsibilities, new business models, and major shifts in technology spending.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest - August 27, 2014
Who wins in cloud price wars? Short answer: not IT. Enterprises don't want bare-bones IaaS. Providers must focus on support, not undercutting rivals.
Flash Poll
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Howard Marks talks about steps to take in choosing the right cloud storage solutions for your IT problems
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.