View previous topic :: View next topic |
Author |
Message |
BeerCheeze *hick*
Joined: 14 Jun 2003 Posts: 9285 Location: At the Bar
|
Posted: Wed, 09 Aug 2006 16:49:23 Post Subject: It's time for the tin-foil hats |
|
|
I hate computers....
Quote: | Websense® Security Labs™ has received a sample of a new phishing Trojan that delivers stolen information back to the attacker via ICMP packets. Upon infection of a victim's computer, the Trojan will install itself as an Internet Explorer Browser Helper Object (BHO). The BHO then waits for the user to post personal information to a monitored website. As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
The method of network transport used by the attacker makes this Trojan unique. Typically, keyloggers of this type will send the stolen information back to the attacker via email or HTTP POST, which can appear suspicious. Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into the data section of an ICMP ping packet.
To network administrators and egress filters, this ICMP packet looks like legitimate traffic leaving the network. However, the ICMP packet actually contains encoded personal information entered by a user. The attackers presumably capture this packet at their remote server, where the packet is easily decoded to reveal the information entered by the user.
In our example, we infected a workstation and entered account information into the SSL website of Deutsche Bank. The Trojan BHO captured the information and sent a ping to a malicious remote server. Below you can view the encoded contents of the ICMP data section as well as the actual contents after they were manually decoded. |
http://www.websense.com/securitylabs/alerts/alert.php?AlertID=570 |
|
Back to top |
|
|
Little Bruin
Boo Boo
Joined: 07 Apr 2003
Posts: 667
Location: Pic-A-Nic Basket |
|
|
Kilamon Rated XXX
Joined: 22 Mar 2005 Posts: 811
|
|
Back to top |
|
|
knight0334 Rated XXX
Joined: 22 Aug 2003 Posts: 2234 Location: Neither Here, Nor There
|
|
Back to top |
|
|
LaTech Ruthless TechTator
Joined: 15 Mar 2005 Posts: 532 Location: Missoula, MT
|
|
Back to top |
|
|
|