Sunday, September 18, 2011

BitTorrent serves malware directly from website - no need for P2P!



Back in 2001, when BitTorrent was first announced, it seemed inevitable - and, at the same time, implausible - that a commercial company based around its social approach to file sharing would emerge and succeed, despite its novelty.
Inevitable, because the sheer popularity of peer-to-peer file sharing means that the potential return for any company successfully commercialising a popular P2P client is enormous.
Implausible, because the indelible association between P2P and piracy means that potential risk of burning out in lawsuits from copyright holders is vast.
But the creator of BitTorrent, Bram Cohen, did create a company out of his codebase, and BitTorrent, Inc. is effectively today's Torrent mothership.
The company is also the custodian of two popular Torrent clients: the so-called Mainline version, and its extremely popular compact cousin, uTorrent.
(The character u is commonly, if confusingly, used in Latin alphabets to represent the Greek letter μ. Short for micro, it's pronounced in English as mew, as in cat. So much for internationalisation.)
In its ten-year history, BitTorrent - the protocol, not the company - has become well known for facilitating the unregulated sharing of arbitrary material. Indeed, it's become quite the way to find all the ripped-off software, films, TV shows and porn you might need. Unsuprisingly, the cybercrooks love that sort of neo-anarchic mix, because it makes it easy for them to expose you to your fair share of malware.
Unfortunately, however, even if you are one of the several many entirely law-abiding users of BitTorrent, the folks at BitTorrent, Inc. may recently have put you in harm's way.
According to a really-ought-to-be-more-visible warning on the download pages of www.bittorrent.com and www.utorrent.com, a breach of the two servers resulted in a two-hour window in which downloading BitTorrent's software would have given you a fake anti-virus program instead.
This morning [13 Sep 2011 on the US West Coast] at approximately 4:20 a.m. PT, the uTorrent.com and BitTorrent.com Web servers were compromised. Our standard software download was replaced with a type of fake antivirus "scareware" program.
Just after 6:00 a.m. PT, we took the affected servers offline to neutralize the threat. Our servers are now back online and functioning normally
BitTorrent, Inc. identifies the malware as belonging to the Security Shieldscareware family. Program files under this "brand" of fake anti-virus should be mopped up by Sophos Anti-Virus as CXmal/FakeAV-A.
Confusingly, the BitTorrent blog has recently been updated to claim that the software available from the www.bittorrent.com URI was not affected, implying that only those who downloaded utorrent during the infection window would be at risk.
Since the two sites share the same network infrastructure - both resolve to the same IP number in Limelight Networks' cloud - you might want to ignore that blog update and assume that any recent downloads from Bittorrent, Inc. were dodgy and give yourself a thorough anti-malware checkover.
I'd also ignore the time window, since BitTorrent used the annoyingly ambiguous abbreviation "PT" to denote the timezone. I'm guessing they meant to say UTC-7, but they didn't.
Update. Allison at BitTorrent got in touch to say she's updated the official report to make it clear: Pacific Daylight Time, UTC-7. Thanks for listening, Allison!

Hackers steal credit card details at Wisconsin and Tennessee Wilderness resorts



Credit card loss at vacation resortsBad news if you have been on vacation at one of the Wilderness resorts in Tennessee and Wisconsin in the last couple of years - hackers may now have your credit card details.
VacationLand Vendors Inc, a firm which provides arcade and vending machines to businesses, has revealed that a hacker broke into its credit card processing systems and stolen up to 40,000 credit card details.
The credit cards were used in arcades at the Wilderness Hotel & Golf Resort in Wisconsin, and the Wilderness at the Smokies Waterpark Resort in Tennessee.
Precise details of how the data breach occurred have not been made public, but the company has published a warning on its website, and advised customers to keep their eyes peeled for unusual transactions on their credit cards.
Statement from VacationLand Vendors
Vacationland Vendors says that it "deeply regrets" the security breach and shut down its systems at the affected arcades as soon as it discovered the problem on March 25, 2011 - but that patrons may be impacted as far back as December 12, 2008.
The FTC has produced a website all about how consumers can protect themselves against identity theft.

SSCC 72 - DigiNotar, DNS hijacking and Firesheep v2



Sophos Security Chet Chat logoThis week my guest for the podcast was Mike Wood, a Senior Threat Researcher at SophosLabs in Vancouver, Canada.
Mike is our expert on digital certificates and how malware authors try to use andabuse digital certificates for their own purposes.
I talked briefly about this month's Patch Tuesday, which fortunately is a small one compared to others this year.
I also briefly mentioned the compromise at DNS registrar NetNames. The attacker pointed the DNS for The Register, UPS and others to a Turkish hacker web site.
We discussed the latest version of Firesheep and how it is now able to steal your Google search history due to a flaw in how some Google sites handle cookies.
The meat of this Chet Chat was spent discussing the recent breach and impact of the hacker(s) who compromised certificate authority DigiNotar.
Mike went into some detail of how certificates have been abused and what these attackers might accomplish if they were to use bogus certificates they purloined from DigiNotar.

(8 September 2011, duration 27:22 minutes, size 12.5 MBytes)
You can also download this podcast directly in MP3 format: Sophos Security Chet Chat 72 or subscribe to our RSS.

Windows 8 to have built-in anti-virus - there's good and bad news



Microsoft will ship Windows 8 with built-in anti-virus software.
That's the big news that is no doubt being discussed furtively at the watercoolers of computer security companies around the world today.
What will it mean to them? A quick glance at Twitter reveals that some people already have pretty good ideas about how the news might have been received..

Jason Hughey
Microsoft announces Windows 8 has anti-virus/anti-malware built in. Loud screams are heard from Symantec/Norton and McAfee headquarters!
But seriously, is this good news for the existing anti-virus companies and - more importantly - consumers?
Microsoft Security EssentialsMicrosoft has been making a free anti-virus software available for a couple of years, in the form of Microsoft Security Essentials. But you had to download it from the internet - it wasn't bundled with Windows itself.
Microsoft has been bundling a program called Windows Defender with Windows 7, Windows XP and Vista, but it doesn't really compare to a proper anti-virus product.
With Windows 8, it sounds as if Windows Defender will be beefed up to incorporate the functionality of Microsoft Security Essentials. Effectively, Windows 8 users will be getting out-of-the-box protection against malware, as well as a firewall and parental controls.
So, it's a case of good news and bad news.

Good news for..

Consumers. Anything which encourages Joe User to run up-to-date anti-virus software has to be a positive thing. There are too many poorly protected home computers out there, which have been commandeered into botnets.
Windows Defender running on Windows 8
But at the same time it's also good news for..
Malware authors. You don't think they're going to ignore this development, do you? If most budget-conscious home users stick with Microsoft's built-in offering, then surely the first thing the bad guys will do is make sure their latest creation can slip past Microsoft's scanner.
No doubt they'll have a new template for their fake anti-virus alerts too.

Bad news for..

Security vendors. It's bad news for those security vendors who rely heavily on consumer sales of their software. It's questionable as to whether many home users will want to reach into their pockets and pay for security from them if there's already one built into Windows 8.
Frankly, it's their own fault. The two big security hippopotamuses have had years of opportunity to gobble up the end-user market, and yet still millions of home users were infected by malware, spyware and pop-ups each year.
It's understandable that Microsoft want to clean up the image of Windows - and if commercial anti-virus vendors haven't managed to do the job, then why shouldn't they do it themselves?
Microsoft's plans for Windows 8 might mean knee jerk reactions from some vendors, and even perhaps more price-cuts and giveaways in an already aggressive market.
I wouldn't be surprised if the legal eagles at rival security firms accused Microsoft of anti-competitive practices, and forced the software giant to offer users security products from a selection of different vendors, just
just as happened in the case of Internet Explorer.
Browser choice screen
But it's not just some security vendors who may struggle, with Microsoft's decision. There's another group who may find life isn't too rosey in the Windows 8 world..
Consumers. Yes, it could be bad news for users too. At least some of them. The thought of running the same anti-virus product as every other home user on the planet, gives me shivers. A security monoculture is not a good thing.
Clued-up folks may well choose to use a non-Microsoft anti-virus (either free or commercial) just to not go with the crowd.
We certainly live in interesting times.
Me? I welcome Microsoft doing more to protect home users from the huge problem of malware, but at the same time I'm pleased to say I don't work for a company which relies on anti-virus sales to home users.