邪恶八进制信息安全团队技术讨论组's Archiver

pub!1c 2006-6-11 22:26

[转载]Hackers and 0day Exploits:Prelude to attack?

<p>信息来源: Zone-H</p><p>The Department of Defense has stated in the past they are worried about China and the <a href="http://www.time.com/time/nation/article/0,8599,1098371,00.html" target="_blank">dedicated intrusions</a> into thousands of computer systems throughout national infrastructure and private sector networks. Again in 2006 they have released a <a href="http://www.defenselink.mil/pubs/pdfs/China%20Report%202006.pdf" target="_blank">report</a> that tries to assess the PLA's mechanism and game plan. The Chinese People's Liberation Army, DOD officials suggest, is the group responsible for this sustained assault and continued attacks.</p><p>These are not the typical attacks in a few different ways than traditional techniques, in that they differed in both the method of attack and the type of information that was gathered...</p><p>Let us put aside the method of attack for a moment and let us look at the goal. Just like a bank robbery, the goal is not only to get the money, but to get the money and yourself out safely. Obviously seeing a robber carrying sacks of money out of the vault is easy to spot, and so is electronic transactions by traditional means, in that both require the thief to transport something.</p><p><br />The PLA took a different approach to traditional means of targeting systems and capturing and transferring data it found. Also by targeting government subcontractors and smaller niche companies to gather information from much less monitored and secured systems, the success of these attacks was unprecedented.<br /><br />Here we hypothesize two of the mechanisms that allowed them to do so with impunity:<br /><br />Method of Attack: The 0day factor<br /><br />0day exploits seem to be the favored choice for the majority of these successful attacks. Going back to May 2004, news was announced that the Cisco IOS source code has been <a href="http://news.com.com/Cisco+investigates+source+code+leak/2100-7349_3-5213724.html?tag=nl" target="_blank">purloined</a> as well as August 2004, a new Malware called MyFip.a virus discovered.November 2004 USDOD reports mass hacking from Chinese based <a href="http://www.time.com/time/nation/article/0,8599,1098371,00.html" target="_blank">systems</a>. Coincidentaly Cisco's PIX source code was being <a href="http://www.eweek.com/article2/0,1895,1710415,00.asp" target="_blank">offered by hackers</a> in the same month.Forward to July 2005, Michael Lynn of ISS discloses security flaws in Cisco routers. Claiming to have stumbled upon a Chinese forum discussing and using a flaw attributed to Cisco routers (and for which he was promptly prevented from speaking about). Now in 2006 researchers discover a 0day Microsoft Word exploit being used in very targeted attacks, again the info gathered by these attacks is being sent to the far east.Info Gathering: The new malware</p><p>They designed a new type of <a href="http://www.lurhq.com/myfip.html" target="_blank">malware</a> that searched for documents and files for software applications that are most likely to be used in the design of things, such as:Adobe PDF, Microsoft Word, AutoCAD, CirCAD circut design files and Microsoft Database files to name a few. Both of these techniques allowed the PLA to compromise systems and peruse data at will, as detection of these methods was not known at the time of the attacks.</p>

页: [1]
© 1999-2008 EvilOctal Security Team