Home > Ask the Security Experts > Expert Archive: Information Security Threats Questions & Answers > What security measures can be taken to stop crimeware kits?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What security measures can be taken to stop crimeware kits?

Ed Skoudis EXPERT RESPONSE FROM: Ed Skoudis

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 November 2007
What defensive measures have been put in place to stop the sale of crimeware kits like MPack? How big of a threat are they to the enterprise?

>
EXPERT RESPONSE
MPack is a nasty piece of work. Written by a group of Russian developers, MPack is modular PHP code that bad guys place on compromised Web servers. When users surf to an MPack'ed server, their browsers are pummeled with a barrage of client-side exploits that try to install bots, keystroke loggers, rootkits and other malware on the unsuspecting victims' machines.

The MPack developers sell their creation, which they keep up to date with the latest exploits, to a series of organized crime groups, and they do so for about $1,000 per toolkit. In July 2007, SecurityFocus posted a pretty spooky interview with the MPack developers, known as the "Dream Coders Team," in which they describe their business model and practices. In August 2007, MPack developers were implicated in an attack against the Bank of India's Web site, which compromised and served up 22 different exploits to unsuspecting surfers.

These types of crimeware tools are a significant threat to the enterprise, because they represent a major vector by which malware propagates today. Enterprises that don't have thoroughly patched browsers, PDF readers, media players and other client-side software are very likely to get compromised by MPack and similar tools. Once the bad guys have control of an internal enterprise network's machines, they can steal sensitive information, resulting in significant damages to an organization's profits and reputation.

From a defensive measure, there's not a lot that law enforcement can do to prevent the sale of this code. First off, most of the code is developed overseas, in countries where law enforcement lacks the resources to stop, or even track, such transactions. Furthermore, in many countries, the sale of such code isn't a crime in and of itself.

Thus, our best defense against these exploit-distributing attacks is to keep our Web servers hardened. The Center for Internet Security features downloadable hardening guides, many specific types of Web servers. Furthermore, clients must be patched thoroughly – especially browsers and third-party client software -- to minimize the chance of exploitation. Check out my recent tip that describes methods for patching third-party applications on Windows systems.

More information:

  • Yuval Ben Itzak talks about the growing use of crimeware kits.
  • The sale of crimeware kits is skyrocketing, according to a report issued by security vendor Symantec Corp.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Emerging Information Security Threats
    Critical infrastructure security grim, study finds
    New malware exploits Microsoft RPC flaw
    Smartphone security: The growing threat of mobile malware
    Microsoft sees OS flaws drop, application breaches rise
    Security Squad: Security pros face troubles
    Trojan exploiting Microsoft RPC flaw
    Malicious program poses as Windows Security Center
    Adobe addresses clickjacking in latest Flash Player
    Clickjacking details released after attack proof-of-concept emerges
    Billy Hoffman on AJAX security and browser attacks

    Organized Cybercrime
    McColo shutdown won't stop spam, malware, warn security experts
    Express Scripts offers reward in hacker extortion case
    Programmer charged for sniffer used in TJX breach
    Anti-cybercrime legislation sent to president
    Web security threats gaining attention at many companies
    EV SSL certificates won't stop phishers, researchers say
    Stolen data ending up in Google cache, say researchers
    Built-in Windows commands to determine if a system has been hacked
    Exploit research: Keeping tabs on the hacker underground
    Enterprise security in 2008: Malware trends suggest new twists on old tricks

    Expert Archive: Information Security Threats
    Are there antivirus suites that pick up more than just run-of-the-mill viruses?
    What tools can a hacker use to crack a laptop password?
    Are social networking sites an easy target for malicious hackers?
    What are the dangers of cross-site request forgery attacks (CSRF)?
    Should social engineering tests be included in penetration testing?
    What kind of data is compromised during a Google hack?
    Best practices for using restriction policy whitelists
    Defining mobile device security concerns
    What are the risks associated with RIM's line of PDAs?
    What software development best practices can prevent input validation attacks?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    DNS rebinding attack  (SearchSecurity.com)
    drive-by pharming  (SearchSecurity.com)
    JavaScript hijacking  (SearchSecurity.com)
    man in the browser  (SearchSecurity.com)
    phlashing  (SearchSecurity.com)
    polymorphic malware  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts