Blog for hpHosts, and whatever else I feel like writing about ....

Thursday, 29 September 2011

hpHosts: Updated 29-09-2011

Sorry for the delay folks.

The hpHOSTS Hosts file has been updated. There is now a total of 222,922 listed hostsnames.

If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)
  1. Latest Updated: 29/09/2011 18:00
  2. Last Verified: 29/09/2011 01:00
Download hpHosts now!
http://hosts-file.net/?s=Download

Wednesday, 28 September 2011

Dear internet.bs ....

Q. How do you tell when a registrar is generating alot of abuse reports?

A. When you receive failure messages such as;

This is the mail system at host us.internet.bs.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

The mail system

<rinaudo@gmail.com> (expanded from <abuse@internetbs.net%gt;): host
alt1.gmail-smtp-in.l.google.com[209.85.143.26] said: 450-4.2.1 The user you
are trying to contact is receiving mail at a rate that 450-4.2.1 prevents
additional messages from being delivered. Please resend your 450-4.2.1
message at a later time. If the user is able to receive mail at that
450-4.2.1 time, your message will be delivered. For more information,
please 450 4.2.1 visit
http://mail.google.com/support/bin/answer.py?answer=6592 fk9si120242wbb.116
(in reply to RCPT TO command)


This was received a few minutes ago, in response to a report to Internet.BS.

Dear Internet.BS, please fix this.

Tuesday, 27 September 2011

Microsoft Security Advisory: Vulnerability in SSL/TLS Could Allow Information Disclosure

Executive Summary

Microsoft is aware of detailed information that has been published describing a new method to exploit a vulnerability in SSL 3.0 and TLS 1.0, affecting the Windows operating system. This vulnerability affects the protocol itself and is not specific to the Windows operating system. This is an information disclosure vulnerability that allows the decryption of encrypted SSL/TLS traffic. This vulnerability primarily impacts HTTPS traffic, since the browser is the primary attack vector, and all web traffic served via HTTPS or mixed content HTTP/HTTPS is affected. We are not aware of a way to exploit this vulnerability in other protocols or components and we are not aware of attacks that try to use the reported vulnerability at this time. Considering the attack scenario, this vulnerability is not considered high risk to customers.

We are actively working with partners in our Microsoft Active Protections Program (MAPP) to provide information that they can use to provide broader protections to customers.

Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.

Mitigating Factors:

The attack must make several hundred HTTPS requests before the attack could be successful.
TLS 1.1, TLS 1.2, and all cipher suites that do not use CBC mode are not affected.


Read more;
http://technet.microsoft.com/en-us/security/advisory/2588513

Wednesday, 21 September 2011

Microsoft dumps partner over telephone scam claims

About bleedin time too.

One of Microsoft's Gold Partners has had its relationship with the software giant unceremoniously terminated, after being revealed to be orchestrating a telephone support scam.

Comantra, based in India, are said to have cold-called computer users in the UK, Australia, Canada and elsewhere, claiming to offer assistance in cleaning up virus infections.

The bogus support calls came from Comantra employees who claimed to be representing Microsoft, and used scare tactics to talk users into opening the Event Viewer on Windows, where a seemingly dangerous list of errors would be seen.

Once terrified by what appears to be a worrying collection of warning messages, and believing this was evidence of a malware infection, users would be tricked into allowing Comantra technicians to gain remote access to their computer, and hand over their credit card details to fix any "problems".


Read more ...
http://nakedsecurity.sophos.com/2011/09/21/microsoft-dumps-partner-telephone-support-scam/

References

Microsoft Support Scam (again)
http://isc.sans.org/diary.html?storyid=10912

Info: Telephone scammers still coming to a phone near you!
http://hphosts.blogspot.com/2011/03/info-telephone-scammers-still-coming-to.html

Support Scams: Even More Personal
http://blog.eset.com/2010/12/16/support-scams-even-more-personal

Fake Support: the War Drags On
http://blog.eset.com/2010/11/18/fake-support-the-war-drags-on

Marketing Misusing ESET’s Name
http://blog.eset.com/2010/06/23/marketing-misusing-esets-name

techonsupport.com, click4rescue.com, pcrescueworld.com: SupportOnClick revisited
http://hphosts.blogspot.com/2009/12/techonsupportcom-click4rescuecom.html

SupportOnClick: Phoned by Malwarebytes? BigPond? Anyone else?

http://hphosts.blogspot.com/2009/07/supportonclick-phoned-by-malwarebytes.html

SupportOnClick Update
http://hphosts.blogspot.com/2009/04/supportonclick-update.html

supportonclick.com scamming you by telephone!
http://hphosts.blogspot.com/2009/03/supportonclickcom-scamming-you-by.html

Fake tech support call scam - prefetch virus logmein123.com
http://www.digitaltoast.co.uk/fake-tech-support-call-scam-prefetch-virus-logmein123com

New scam - They call you by phone!
http://www.malwarebytes.org/forums/index.php?showtopic=11156

Staffordshire Council - Telephone computer support warning (PDF)
http://www.staffordshire.gov.uk/NR/rdonlyres/6997DBB0-E31E-4AFB-A886-C9DDEE114204/90090/TelephoneComputerSupportWarning.pdf

Cold call scam warns of virus infection
http://www.h-online.com/security/Cold-call-scam-warns-of-virus-infection--/news/112893

Scareware scammers adopt cold call tactics
http://www.theregister.co.uk/2009/04/10/supportonclick_scareware_scam

Saturday, 17 September 2011

Alert: 70.85.43.147

I was sent a URL earlier, that redirected to fake meds (surprise surprise). Checking further however, I arrived at the sites homepage to discover two scripts being loaded, one from a site that has now been cleaned, and another loaded from 70.85.43.147, that is still there;

70.85.43.147/minitools.js

Trying a quick check, Malzilla, JSUnpack etc failed to decode it, so I figured I'd wait until I had a few mins spare, to do it manually. A look over the code showed the problem - the interpreters couldn't handle the way the script worked, so it required heavy modification to get it to decode.

I can't post the scripts themselves here, as your AVs will go haywire if they've got heuristics enabled, so will post screenshots instead.

Original (before modification)



Modified



The result of this, is a lovely little iFrame;



the iFrame itself is the blackhole exploit, loaded from;

twefwf.freewww.info/showthread.php?t=15410812

This is currently residing at;

IP: 89.201.174.28
IP PTR: Resolution failed
ASN: 34594 89.201.128.0/17 OT-AS OT - Optima Telekom d.d.

inetnum: 89.201.174.0 - 89.201.174.63
netname: INFONET
descr: InfoNET d.o.o.
descr: Livanjska 23
descr: 10000 Zagreb
country: HR
admin-c: DM1283-RIPE
tech-c: DM1283-RIPE
status: ASSIGNED PA
remarks: INFRA-AW
mnt-by: OT-MNT
source: RIPE # Filtered

person: Damir Maracic
address: InfoNET d.o.o.
address: Livanjska 23
address: 10000 Zagreb
address: Croatia
phone: +385 1 3840205
nic-hdl: DM1283-RIPE
abuse-mailbox: abuse@infoit.hr
mnt-by: OT-MNT
source: RIPE # Filtered

% Information related to '89.201.128.0/17AS34594'

route: 89.201.128.0/17
descr: OT - Optima Telekom d.d.
origin: AS34594
mnt-by: OT-MNT
source: RIPE # Filtered

% Information related to '89.201.160.0/19AS34594'

route: 89.201.160.0/19
origin: AS34594
descr: OT - Optima Telekom d.d.
mnt-by: OT-MNT
source: RIPE # Filtered


Personally I'd recommend putting a block on it if you've not already. I'll leave the decision as to whether to block just the IP or the entire range, up to you.

freewww.info itself is a dynamic DNS service operated by ChangeIP, a service heavily abused by miscreants (not all together surprising, but very disappointing that like no-ip.com and the likes, they're still seemingly doing very little to put a stop to it).