tfh
Volume 16, Number 25 -- June 25, 2007

MPack Hacker Tool Claims 10,000 Compromised Web Sites

Published: June 25, 2007

by Alex Woodie

A Russian-developed hacker tool called MPack was being utilized last week in a Web attack that has compromised an estimated 10,000 Web sites, primarily in Italy but also in other parts of Europe, security researchers reported. As the largest such attack in recent memory, MPack shows how sophisticated hackers and malicious software developers are getting at compromising network security, and ups the ante in the ongoing battle against cyber crime.

Late Friday (June 15), computer security researchers started tracking the Web site hacks and resulting spread of malware, which some have dubbed the "Italian Job" because most of the infected Web sites are based in Italy and designed for Italian audiences. By Monday, the number of Web sites infected had reached 10,000, reported WebSense, a security software company based in San Diego, California.

MPack is a professionally written suite of hacker tools that was introduced to the black market by a Russian gang last December, according to security researcher Panda Labs, which is credited with discovering MPack and which last month published a timely report titled "MPack Uncovered." You can download the report, which was written by Vicente Martínez and is in PDF format, here

According to Martínez, MPack was written in PHP and is designed to be hosted and run from a PHP server with a MySQL database. MPack includes a collection of functional modules (exploit modules, in MPack's case), a graphical management console, and--like so many legitimate software products today--is designed to be ready to use "out of the box." It costs about $700, according to Martínez' report.

All that cyber criminals need to get started with their MPack ventures is to attract some Internet traffic to their MPack Web server. They do this in several ways, including hacking into Web sites and inserting a piece of malicious JavaScript and IFRAME code that redirects Web site visitors to their malicious MPack server, or to an intermediate server that then redirects the visitor to the MPack server. (This appears to be the way that the bulk of the Italian Job traffic was generated.) Alternative tactics include setting up so-called "typo-squatting" Web sites on popular domains to trap accidental visitors, sending out spam e-mails with malicious, embedded code, or even buying Google sponsored links.

Once the victim has been delivered to the MPack server, the MPack product analyzes the HTTP request header to figure out which OS and Web browser they're using. Based on this information, the MPack product creates a tailor-made exploit cocktail that has the best chance of infecting the victim's computer, starting with the most recent zero-day exploits first. (To be infected at this point, the user must have an unpatched vulnerability on his computer.) MPack's developers also provide customers with regular updates that load exploit code for the most recently discovered vulnerabilities. The updates cost between $50 and $150. This intelligence and responsiveness is what makes the MPack code--and other hacker tools like it--so dangerous to the Web-browsing community.

Another interesting aspect of the MPack kit is the graphical control console that the product's developers built into the software. Using this password-protected console, cyber criminals operating MPack in the wild can view statistics about how many victims they have drawn in, what country they're from, and what operating systems and Web browsers they're using. MPack developers created another tool called DreamDownloader that's usually sold with MPack. It is a tool script kiddies may be attracted to. In many ways, MPack mirrors the latest in user interface design and tech support that many legitimate software companies create to attract and keep their business customers.

In a May 27 blog posting on MPack, a researcher with Symantec, Hon Lau, describes the danger of MPack. "The ongoing development of this MPack kit (currently at version 0.86) serves to underline the fact that the criminals are taking full advantage of the online world to generate their ill-gotten gains," Lau writes. "There's low risk of detection and capture, and even lower risk of physical danger in carrying out cyber crime. As one of the members of the Fujacks gang once boasted, 'This is a better money-making industry than real estate.' No wonder new attack kits and updates to existing ones keep cropping up."

While MPack was making the biggest headlines last week, especially in Italy, it isn't the only exploit tool popular with hackers and cyber criminals. Other products that make it easy for hackers to exploit vulnerabilities include the group behind the Metasploit and Webattacker products. Like MPack, Metasploit and Webattacker provide hackers and cybercriminals with easy-to-use and up-to-date automated hacking tools. In Metasploit's case, interested parties can download the product from the Metasploit Web site at www.metasploit.com. The Webattacker product, which was created by a group of Russian developers at www.inet-lux.com, according to Wikipedia, is available on several hacker Web sites.

According to security software researcher Trend Micro, MPack was used to infect legitimate Italian Web sites that are related to tourism, the automotive industry, movies, music, tax, employment services, Italian city councils, and hotels sites. The attack appears to be timed to coincide with an upcoming Italian holiday, when Italians will be more likely to visit non business-related Web sites, Trend Micro says.

Most of the compromised Web sites appear to be hosted by the same Internet Service Provider (ISP), according to Trend Micro. Symantec says the compromise was "most likely some vulnerability or configuration issue at the ISP/hosting level." It appears that somebody, or a group of people, made a mistake that has resulted in the infection of tens of thousands of PCs around the world.

The most important step that users can take to protect themselves from MPack is to apply security patches as soon as possible. As hackers get better and faster at devising exploit code for newly discovered or reported vulnerabilities, it shrinks the window of protection that users enjoy following the disclosure of a vulnerability. In many cases, it takes just days for hackers to develop and distribute exploit code for vulnerabilities announced and patched by Microsoft on the second Tuesday of every month--the so-called "Patch Tuesday" events. In recent years, it would take a week or more for the first exploits to come out, a sign of the escalating nature of the Web hacking game. In some cases, hackers discover the vulnerabilities first and release exploit code before the owner of the compromised product has a chance to patch it, which are so-called "zero-day" exploits.

While consumers are encouraged to apply security patches immediately, most large businesses and organizations must first test these patches before deploying them, lest they create conflicts with existing programs. These businesses and organizations must deploy and maintain more sophisticated security tools to provide protection from vulnerabilities during the critical days or weeks following the disclosure of security vulnerabilities.



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
WORKSRIGHT SOFTWARE

Do you need area code information?
Do you need ZIP Code information?
Do you need ZIP+4 information?
Do you need city name information?
Do you need county information?
Do you need a nearest dealer locator system?

We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

Just call us and we'll arrange for 30 days FREE use of either
ZIP/CITY or PER/ZIP4.

WorksRight Software, Inc.
Phone: 601-856-8337
Fax: 601-856-9432
E-mail: software@worksright.com
Web site: www.worksright.com


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

COMMON:  Join us at the Annual 2008 conference, March 30 - April 3, in Nashville, Tennessee
Seagull Software:  Web-enable your System i apps with LegaSuite GUI
VAULT400:  Securely archive data with Instant Back-Up & 24x7 Recovery

 

IT Jungle Store Top Book Picks

The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95

 

The Linux Beacon
Linspire Hooks Up with Microsoft, Too

Intel Bangs the Itanium Drum, Draws Out Roadmap

Novell Ships Service Pack 1 for SUSE Linux 10

Torvalds Says Linux May Follow Solaris with GPL v3

Four Hundred Stuff
IBM Taps Nortel for Entry-Level System i VoIP Solution

North Carolina Schools Laud SafeData for Online DR Solution

NGS Hooks Into Query/400 to Protect BI Investments

S4i Expands File Support in Document Management Software

Big Iron
Mainsoft Updates .NET-Java Tool with 2.0 Release

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Parameter Passing and Performance

Conditional Counting with Open Query File

What Is SMIOSTCPGT and Why Is It Eating My System?

System i PTF Guide
June 16, 2007: Volume 9, Number 24

June 9, 2007: Volume 9, Number 23

June 2, 2007: Volume 9, Number 22

May 26, 2007: Volume 9, Number 21

May 19, 2007: Volume 9, Number 20

May 12, 2007: Volume 9, Number 19

The Windows Observer
MPack Hacker Tool Claims 10,000 Compromised Web Sites

Microsoft Ships Updated Dynamics ERP Products

Intel Bangs the Itanium Drum, Draws Out Roadmap

Linspire Hooks Up with Microsoft, Too

The Unix Guardian
Intel Bangs the Itanium Drum, Draws Out Roadmap

Sun Revs Solaris Express Developer Edition, Adds Non-Sun Iron Support

Disk Array Sales Still Humming Along, Says IDC

Vision Solutions Acquires HA Rival Lakeview Technology

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

Profound Logic Software
MKS
Maximum Availability
VAULT400
WorksRight Software



TABLE OF CONTENTS
The AS/400 at 19: Predicting the Future--Or Not

IBM Kills Off System i ServerProven, Standard Edition Rebates

VoIP and the Search for Single Points of Failure

As I See It: Dare to Be Rich

But Wait, There's More:

The CIO Is the Hammer, and Everything IT Vendors See Are Nails . . . IBM Offers Virtualization-Friendly Pricing for RHEL 5 on Power . . . IBM Previews Virtualization Management Tool for Power-Based Boxes . . . Database Sales Grew By 14.2 Percent in 2006, Says Gartner . . . Lawson Expects Better Results for Fiscal Q4 Than Anticipated . . . MPack Hacker Tool Claims 10,000 Compromised Web Sites . . .

The Four Hundred

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement