You are here: silicon.com > Software > Malware

Malware

Malicious code getting harder to spot

Cyber crooks becoming more sophisticated, says expert

Tags: trojan, malicious, cyber crook

By Joris Evers

Published: 19 April 2007 10:21 BST

Cyber crooks who rig websites to break into PCs are getting better at hiding their malicious code, a security expert has said.

Increasingly the actual code, often JavaScript, used to attack PCs is hidden in Flash animations or scrambled so anyone who examines the source of a page can't easily identify it, said Jose Nazario, a senior software engineer at Arbor Networks, in a presentation at the CanSecWest security confab in Vancouver.

Nazario said: "Their obfuscation tools are primitive but effective." Referring to security techniques based on signatures to detect malicious websites, he said: "They use obfuscation to avoid simple signatures." Signatures are fingerprints of known attacks.

Tens of thousands of websites attempt to install malicious code, according to StopBadware.org. The websites, the bulk of which are compromised sites, often drop a Trojan horse or other pest onto a PC through a security hole in the web browser.

Many attacks use JavaScript. Initially miscreants used plain JavaScript in their attacks but that has changed, Nazario said. He has spotted an encoded script function called "makemelaugh" that downloads a Trojan horse that captures bank information and a Paris Hilton Flash animation that installs a tool that makes a PC part of a botnet.

Attackers are also trying to outsmart security pros by programming malicious sites to load their malicious code only once on the same PC, Nazario said. Furthermore, a new toolkit called NeoSploit identifies the browser and is packed with security exploits to launch the proper attack, he said.

There are things security professionals can do to investigate attacks, Nazario added. "Bad guys are limited by the fact that JavaScript has to be decoded to be used by the browser. As long as you can analyse it outside the browser, you can figure out what it is going to do," he said.

The scrambled code can be made legible since it typically uses simple Base64 encoding for obfuscation and not actual encryption, according to Nazario. He suggested NJS, Rhino and SpiderMonkey as tools to investigate script code. Flash files can be analysed using a program called Flasm, he added.

Malicious JavaScript can be embedded in a web page and will typically run without warning when the page is viewed in any ordinary browser. Attackers could try to lure you to their own, rigged website. But an attack could also lurk on a trusted site by exploiting a common flaw known as cross-site scripting.

To shield against malicious JavaScript, web surfers can disable JavaScript but that can impact the functionality of many websites. An alternative is to use security tools that have blacklists of known bad sites such as McAfee's SiteAdvisor or Google's Toolbar or Desktop software.

Another alternative is Exploit Prevention Labs' LinkScanner, which monitors traffic going into a PC and blocks known exploits.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
PHP, ASP, Javascript, Photoshop, Flash, Fireworks Lancashire 6 mth

PHP, ASP, Javascript, Photoshop, Flash, Fireworks Lancashire 6 mth My design agency client in central Lancashire is seeking a web designer to work ...

Senior PHP Developer - Nottingham - PHP, MySQL,Flash - circa 30,000

Flash, AJAX and .NET. Desirable skills include Flash, AJAX, .NET and SEO. You will also require experience in both developing websites and web ...

FLASH DEVELOPER - ActionScript - Berkshire - 30-33k + Benefits

Key Words: Flash ActionScript Flash Action Script Flash ActionScript To perform this role you will require a thorough understanding of Action Script ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: