Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 11-29-2007, 10:20 PM
Symantec's Avatar
Symantec Symantec is offline
Senior Member
 
Join Date: Oct 2006
Posts: 295
New Exploit for Xunlei Thunder in the Wild

New Exploit for Xunlei Thunder in the Wild
<p>Symantec Security Response has observed web based exploit attacks using a <a href="http://www.securityfocus.com/bid/26536">previously unknown vulnerability</a> in the Xunlei Thunder PPlayer ActiveX control. This is a component of the Chinese download accelerator and file-sharing application, Xunlei Thunder 5.7.4 401.</p>

<p>The attack originates from a server on the 522love.cn domain. If a user navigates to the site, a Web page hosted on the site employs a client detection technique to determine the appropriate exploit code that should be sent back to the requesting client in order to successfully exploit it. This technique is similar to the techniques used by the <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/06/mpack_the_movie.html">MPack</a> attack kit that is already widely used. We have seen a whole range of vulnerabilities both new and old used by this site, including the following:</p>

<p>• <a href="http://www.securityfocus.com/bid/26536">Xunlei Thunder PPLAYER.DLL_1_WORK ActiveX Control Buffer Overflow Vulnerability </a><br />
• <a href="http://www.securityfocus.com/bid/17462">Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution Vulnerability</a><br />
• <a href="http://www.securityfocus.com/bid/26247">SSReader Ultra Star Reader ActiveX Control Register Method Buffer Overflow Vulnerability</a><br />
• <a href="http://www.securityfocus.com/bid/25601">BaoFeng Storm MPS.DLL ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities</a><br />
• <a href="http://www.securityfocus.com/bid/25601">PPStream PowerPlayer.DLL ActiveX Control Buffer Overflow Vulnerability</a><br />
• <a href="http://www.securityfocus.com/bid/25751">Xunlei Web Thunder ActiveX Control DownURL2 Method Remote Buffer Overflow Vulnerability</a><br />
• <a href="http://www.securityfocus.com/bid/21930">Microsoft Windows Vector Markup Language Buffer Overrun Vulnerability</a><br />
• <a href="http://www.securityfocus.com/bid/23194">Microsoft Windows Cursor And Icon ANI Format Handling Remote Buffer Overflow Vulnerability</a></p>

<p>Successful exploitation of the client results in code execution that may result in the download and installation of additional malicious files. These files are currently detected by Symantec as <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-101518-4323-99">Downloader</a> and <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-071010-4808-99">Trojan.Maliframe!html</a>. </p>

<p>Until a vendor patch is available, users can minimize their risk of exposure by avoiding unknown or untrusted URLs, such as those sent in spam emails and unsolicited instant messages, disabling JavaScript and ActiveX in their Web browser and ensuring that their antivirus software is up-to-date.</p>

<p><strong>Update:</strong><br />
Upon further analysis we have discovered that the following vulnerabilities are also used on this Web server:<br />
• <a href="http://www.securityfocus.com/bid/8634">Yahoo! Webcam ActiveX Control Buffer Overrun Vulnerability</a><br />
• <a href="http://www.securityfocus.com/bid/25121/exploit">Baidu Soba Search Bar BaiduBar.DLL ActiveX Control Remote Code Execution Vulnerability</a></p>

<p>Clearly this piece of malware attempts to cover its bases pretty well in terms of market coverage. However, on closer inspection we have also found that the server appears to be misconfigured, as a result the client detection and exploit selection code is appended to everything that the server serves up–HTML, data, and binary files included. As a result, clients receiving the content may behave unpredictably in many cases, causing browser crashes. Perhaps the quality control department must have had a bad day at the office in this operation.</p>
http://www.symantec.com/enterprise/security_response/weblog/2007/11/new_exploit_for_xunlei_thunder.html
http://www.symantec.com/enterprise/security_response/weblog/2007/11/new_exploit_for_xunlei_thunder.html
Fri, 23 Nov 2007 05:11:27 -0800
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump



    All times are GMT -5. The time now is 02:51 PM.


    Firefox 2