Chinese security team becomes malware victim

Even security groups are not immune to malware writers: the Chinese Internet Security Response Team (CISRT) has apologised for occasionally serving up malicious code to visitors to its Web site.

"We are very sorry that when sometimes visiting our … pages, malicious codes are inserted," CISRT posted on its English-language Web site.

A short line of malicious code placed at the top of some of its Web pages can result in browsers being directed to sites housing malware. Should users visit an infected page, a 37 KB size file "sms.exe" will be downloaded to the sites, which antivirus company Kaspersky has identified as Trojan-Downloader.Win32.Baser.w.

The attack exploits buffer overflow vulnerabilities in the Chinese-developed browser-based media player, BaoFeng Storm. Symantec's antivirus centre warned that BaoFeng Storm's ActiveX control is "prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data."

CISRT believes its Web site is not necessarily compromised, but has rather come under an "ARP" attack, sometimes referred to as ARP poisoning or spoofing.

Patrik Runald from Finnish security firm, F-Secure, said that it is unusual for a security response team's Web site to be hacked like this, but that if it is indeed an ARP attack, it uses a very complicated method.

"It's not really easy to make happen. When a computer makes a request somewhere [on the network], they use the ARP number which is sometimes called a MAC ID. The bottom line is if you can spoof an ARP you can insert yourself between a client and server -- for example at the gateway.

"If you're on an internal network, you can spoof an ARP packet so that any machine wanting to connect to a Web site will be routed to a malicious machine. From here you can insert an iFrame line and it would only affect people going through that gateway."

Australian-based security firm, Sunnet Beskerming, which first reported the attack, wrote that by intermittently serving the malicious iFrame, the attacker can extend the life of a hack by making it harder to isolate and investigate.

"With intermittent attacks on visitors it also means that investigators need to look at all of the intermediate connections between site visitors and the Web site," Sunnet Beskerming reported.

Advertisement

Talkback 0 comments


ZDNet's CIO Vision Series

Customs | Murray Harrison, CIO

Australian Customs CIO Murray Harrison dislikes SLAs and runs away if a vendor talks to him about innovation. In this interview, he also explains why getting excited about gadgets can be dangerous and talks about how Customs' outsourcing strategy has evolved.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Munir Kotadia iPhone suckers test our patience
    So how many of you have bought a 3G iPhone? Do you feel like a sucker? If you don't, maybe you will once your first bill arrives.
  • Array Westpac bank: AVG's toughest competitor
    The next time you're buying antivirus software, don't go direct to Symantec or McAfee. Don't download free antivirus. And definitely don't see Harvey Norman. Ask your bank — they're quite literally giving the stuff away.
  • Array Will you manage in the exabyte era?
    Mammoth growth in storage volumes is a fact of life, but even so it's helpful to pause occasionally and try and work out whether our information strategies have fallen hopelessly out of step with the pace of technological growth and changes in costs.
  • More blogs »

Tags

Back to top

Featured