New Hacker Toolkit Cloaks Browser Exploits - InformationWeek
IoT
IoT
News
News
10/17/2006
12:55 PM
50%
50%

New Hacker Toolkit Cloaks Browser Exploits

"VoMM," when applied to any browser exploit code, hides the exploit from static signature-based detection systems.

Metasploit, which regularly publishes exploit code for its flagship open-source attack testing platform, has released a new module designed to disguise any browser exploit from detection by signature-based defenses, Symantec warned Tuesday.

HD Moore, Aviv Raff, and someone identified only as "LMH" have created VoMM (for eVade-o-Matic Module), which when applied to any browser exploit code, hides the exploit from static signature-based detection systems.

Static detection -- where a specific signature is created to identify each exploit -- is used by many anti-virus products; the alternative, a generic signature that can spot an entire class of Web-based vulnerabilities, is harder to design and develop, said Symantec.

According to a post by LMH on his blog, VoMM uses multiple techniques to hide an exploit, including string obfuscation, block randomization, random comments, and variables obfuscation.

HD Moore applied most of the techniques to create an exploit of the now-patched VML vulnerability in Internet Explorer. Moore's exploit was undetected by all 26 virus scanning engines supported by VirusTotal, which include Grisoft's, McAfee's, Microsoft's, Symantec's, Kaspersky's, and others.

"This new module will make the detection of such attacks much more difficult," Symantec warned in an alert to customers of its DeepSight threat system.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
Digital Transformation Myths & Truths
Transformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.
Video
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll