Friday, May 9, 2008

Back to the roots

I'm back at the UNAM-CERT after spending 3 months at NextiraOne. And it's a good returning for me because I've been told I'll be teaching at the engineering school at UNAM, a course of selected topics on network security.

Tuesday, February 5, 2008

Security patch for the "2wire authentication vulnerability"

Today the UNAM-CERT has released an update to the security note published back in December 2007 that warned about an authentication vulnerability in the 2wire modems.

Last week the UNAM-CERT tested the new firmware that is scheduled to be released to the TELMEX users (prodigy Infinitum) later this month. The new firmware version is 5.29.135.5 and will be deployed in the next weeks. It is important to say that the update is automatic.

The complete information is here: http://www.cert.org.mx/nota/?vulne=5534

Sunday, January 27, 2008

2wire authentication vulnerability reaches the mainstream

It's been 50 days since the UNAM-CERT first warned about the 2wire authentication vulnerability we found through an 0-day exploit.

Many people and security-related companies have claimed that "that was old news" referring to the "cross site request forgery (XSRF)" vulnerability reported by a mexican hacker group back in August 2007, BUT our security note announced a brand-new-authentication-vulnerability that put in high risk more than 1 million users (at least) in Mexico.

Back in December 2007 we got in touch with 2wire and Telmex before releasing the security note, we were the first team to discover and to report the issue while some companies were buying their gifts for christmas day and cooking the turkey.

For those companies, the issue remained unnoticed for some weeks (even when we made public the vulnerability and when some blogs had been discussing the topic for a while). But two weeks ago a company (one of those cooking the turkey for the christmas back in 2007, TrendMicro) made a statement about the issue, 1 month after our security note was released (just in time) . It's funny TrendMicro is warning about a "massive attack to hit the mexican users" when this issue has been exploited for a long time.

It seems that TrendMicro Labs are only able to "predict attacks" when they have enough newspapers to "read the future".

Then appeared Symantec, some days ago, with the article "first case of drive-by-pharming in the wild", based on the Trendmicro statement (I guess).

But aside the flames, the important thing here is: antivirus and security-related companies based in the USA or other countries doesn't put enough efforts to detect the current threats in LatinAmerica or at least not in Mexico. And that's odd, because they sell a lot of licenses here, I think they should start working instead of warning of "(already) upcoming threats".

Shame on them!

Tuesday, December 11, 2007

Vulnerability in 2Wire routers

We've just released a security advisory for a vulnerability in 2Wire routers that is being actively exploited through phishing.

The advisory is located here.

Monday, December 3, 2007

Win a car!, just click here

I don't know if this scam really qualifies as "phishing" because it seems odd at first sight.

I don't know even if it really represents a threat to anyone. Let me explain, the e-mail asks the user to click on the attachment and answer a trivia to win a car, so what's this all about?

The picture of the "prize" is of a Volkswagen Golf (by the way, the name of the file is misspelled as "Wolsvagen") but not the brand new model, not even the previous one, the car is something around Mark 3 or Mark 4 (newest is Mark 5), I'm not sure because I'm not a VW fan nor expert, but certainly it isn't a Mark 5 VW Golf, you can take a look at the VW Mexico website.


So, my first thought was "this e-mail must be a joke", but when I analized the binary I realized that the threat was very real, the .exe file modifies the hosts file in Windows and, guess what, add some entries to replace the BANAMEX domain name.

I don't know if this is intentional, but in any case the phishers put little effort to deceive the user, finally, there's always a user who will try to "win the car" even if the car was dropped from production in Mexico many years ago.

Md5sum: 70d0a93d0001288ad057f41c7fd8a397
Filename: Wolsvagen-Sorteo.exe
IP: 65.23.158.58

Ps. I did some research and found that the car is indeed offered as a prize in Spain, so my guess is that this phishing scam originates in the Motherland.

Tuesday, October 23, 2007

iPhone targeted for hacking

HDMoore has announced very good stuff to hack the iPhone (like adding an openssh to the phone and getting a rootshell). The entry has been added to the Metasploit blog.

I know it will be a long time before the iPhone make its debut in Mexico, but it seems like the delay will be worth it.

Friday, October 12, 2007

Malware speech

Next monday I'm giving a speech at Facultad de Ingeniería, UNAM. Here is the complete information.