Monday, July 24, 2006

cutting through the mobile malware mess

techdirt, renowned for it's technical acumen (in other words it's signal to noise ratio is just slightly better than the garbage heap of the internet known as slashdot), has a post today that basically roasts f-secure for spreading mobile malware FUD... small problem - i couldn't find the FUD even after following all their links to supposed examples...

let's take a closer look, shall we?

from silicon.com:
Sal Viveros, wireless security evangelist at McAfee, said F-Secure's figures are largely in line with industry figures in terms of the total number of mobile viruses but added such viruses have largely been "proof of concept" to date and pose little threat to users.
ok, so we've got independant verification of f-secure's figures on the total number of mobile malware instances - score 1 for f-secure...

from a different article on silicon.com:
"The number of proof of concept viruses is increasing but that's not to say there has been an increase in the risk of infestation or that there is any need for panic or worry."
the person making this statement (david wood of symbian, the company holding the largest stake in the mobile phone market - aka the microsoft of the mobile phone market) clearly doesn't understand the nature of risk... the more instances of malware out there the greater the chance of a particular user encountering one of them, and therefore the greater the risk...

from the same article:
He added that these viruses will only spread with user permission and conceded that in very rare instances a user could contrive to infect their phone.
which shows that he clearly doesn't understand what's really going on in a mobile infection scenario... the no option doesn't work - you choose no and the prompt just comes back... press no again and the same thing happens... cabir and similar worms will just keep trying and effectively DoS the phone until the user chooses yes... user interaction is a non-issue if the user isn't given a real choice...

(see the video evidence here, it starts about 26 minutes in)

[edit - there's a better view of the video evidence here, starting at about 1 hour and 26 minutes]

from an article at vnunet.com:
"Phone viruses so far have been spreading over Bluetooth, so they only affect phones that are within a few metres. A MMS virus can potentially go global in minutes, just like an email worm," warned F-Secure's antivirus laboratory.
now that is a little troubling that it says minutes - because mikko hypponen, in the video referenced above, says 24 hours (both for mobile phone viruses and for email viruses) and he explains why... it's correct that it has the same potential speed as email worms but minutes seems like an error, either on the f-secure rep's side or (more likely, since they're known for botching these sorts of things) the reporter's side...

at any rate, saying a type of virus has the potential to do X is quite a bit different than saying a particular virus will do X or is likely to do X (which is the implication techdirt makes here)...

and from the a zdnet.co.uk article that triggered the current threat at techdirt:
"F-Secure is saying there's a huge risk of malcode spreading, but they've built this up," said Simon Perry, European vice president of security for CA. "If you look at their behaviour, they've consistently pushed this message. But it's a theoretical, not a real threat," he added.
i don't know where mr. perry is getting this - mikko hypponen (again in the video referenced above) made it seem pretty clear to me that mobile viruses are not anywhere near as problematic as their pc counterparts... susceptible phones are comparatively quite rare, and most of the malware can only spread to other phones that are physically nearby... that doesn't sound like a huge risk to me... he does mention some big total numbers (in the tens of thousands) but considering the law of large numbers as it applies to this situation that doesn't really raise eyebrows...

furthermore, in the same zdnet article an f-secure representative is quoted:
"I have difficulty understanding how this can be bad for [the antivirus] business. This is not a mass problem for all consumers, but our solution is available to those who need it, and there are people who need it today," Impivaara added.
it seems hard to imagine how f-secure could be making mobile malware out to be a huge risk when they're quoted in the media as saying the opposite...

still, techdirt has persisted in laying the FUD spreader charge against f-secure for some time now, not unlike many other community sources (slashdot and digg are the 2 glaring examples) have done to many other vendors... it bears a striking similarity to the reaction you get whenever you suggest there are genuine security risks in mac osx or linux... i thought at first it might just be one site or 2 sites, but the pattern that is emerging seems more widespread - it seems to have something to do with the wisdom of mobs where the wisdom of crowds fails due to the signal to noise ratio being too low... the reality is is that he who yells loudest has the most individual impact on the whole and without sufficient real wisdom to counteract that impact the whole becomes an ignorant mob...

Sunday, July 23, 2006

the REAL reason anti-virus programs don't work

by now a lot of people have seen one or both of the pair of zdnet articles on anti-virus apps not being worth a damn... i've already argued that the logic of their argument is bogus but then along comes a different article with an entirely different observation...

readers of this blog probably know by now that i tend to be a little on the critical side - i tend not to say anything when i agree with someone, usually only when i disagree, so brace yourselves for a departure from the norm because martin overton has done an excellent job of capturing the REAL reason why anti-virus programs aren't working and i just thought it was so good i had to try and draw more attention to it...

he's done a much better job than i probably would have done because i wouldn't have tip-toed around the thorny issue of blaming the victims and just come out and said that the anti-virus programs are failing because they're being used by morons who move their lips when they click and click on everything except the update button...

why? why are people so dense? ok, i get that the average person isn't going to be a technical marvel, but the simple behaviour we've been trying to teach them for a decade or 2 now is to use anti-virus software AND keep it up to date... is that second part really so much harder than the first?

come on folks, buying a new computer in order to solve a malware problem is not the answer - there comes a time when you have to look with a critical eye at the sequence of events that lead to the malware contamination and ask yourself "what could i have done differently that would have helped to avoid this problem?"... if you don't get a better handle on this then you're new computer will soon be infested by malware as well and then what will you do? unfortunately musical chairs does not represent an effective anti-malware strategy...

if you're going to use anti-virus (and you should) you're going to also have to keep it up to date... why? because there are about 60-70 new pieces of malware created each day... malware scanners mostly only detect what they know so each day that your scanner goes without being updated represents an additional 60-70 pieces of malware it doesn't know about and therefore won't be able to help you avoid... if it's been months (or years) since you last updated, do the math and figure out how many potential threats your security software isn't helping to protect you from... pretty scary, huh?

if that just woke you up out of your stupor and you've started to ask yourself "but what if i am completely up to date and i still encounter malware my anti-virus app doesn't know about?" then congratulations, you've just ascended to a new level of malware awareness... to you i say that your anti-virus is just one layer of defense and nobody ever said you were limited to only using one...

Wednesday, July 19, 2006

80% of new malware does what to antivirus?

here's the backstory - apparently graham ingram, general manager of the australian computer emergency response team (AusCERT) has revealed that 80% of new malware defeats antivirus software...

now, i haven't seen enough of the full text of his talk to know for sure what he was on about (the media are notorious for twisting perfectly valid statements into horrendously misleading sound-bytes) but saying that the anti-virus products aren't working does not inspire confidence...

in fact, framing it the way he does, talking about new malware and an 80% miss rate is rather misleading too...

let's put things into proper perspective, shall we? when malware is new it is unknown to the anti-malware vendors - that's the nature of things... when it's been around for a while it will no longer be new and no longer be unknown... further, the mainstream anti-virus products are essentially known malware scanners...

now ask yourself, are you at all surprised that known malware scanners don't do a very good job of detecting unknown malware? of course not... now ask yourself, is it really a problem or all that big a deal? no again, known malware scanners aren't supposed to be good at dealing with unknown malware, they aren't meant to deal with that part of the malware problem... unknown malware doesn't stay unknown for long so it will be caught by the anti-virus products eventually, but during that initial window of opportunity you need to employ other techniques and technologies to protect yourself... anti-virus products aren't a panacea, they aren't a cure-all, don't depend on them exclusively but rather practice defense-in-depth - use a multi-layered approach to protection...

the only people who should be seeing a problem here are those naive enough to think that anti-virus products should be all they really need... and doesn't that make you wonder what graham ingram, general manager of AusCERT, was thinking giving quotes that made it sound like the sky was falling?

Friday, July 14, 2006

symantec, viruses, and the mac

i've written about viruses and the mac before but of course people don't read what i write or don't listen to what i say or maybe just don't think i'm right and so continue to make silly gaffes... sometimes those people are even in a position where you'd expect them to know what they're talking about...

take for example the recent pronouncement from symantec that there are no file infecting viruses for the mac osx platform... todd woodward is a symantec employee so of course people are going to assume what he says about viruses and the mac must be true... he makes a pretty convincing argument too, except for one tiny problem - in trying to convince us that osx/leap.a wasn't a file infecting virus he points to a symantec virus analyst's write-up that actually says osx/leap.a does infect files...

ooops...

but lets not be too hard on poor todd, after all he's not a virus analyst himself, rather he's a product support analyst for symantec... still, that embarrassing gaffe could have been avoided if he'd simply read the page he was linking to...

so just to clear up the confusion (and to repeat something i've said a bunch of times already) osx/leap.a is an overwriting file infector (that would have been a companion infector if not for a bug in the code) and an instant messaging worm at the same time... that's right, is a worm/virus hybrid and therefore there IS a virus for the mac osx platform... i get the feeling that perhaps todd is not aware that something can be both a virus and worm at the same time but it can and there are plenty of examples in the windows world so that part of his post about the differences between worms and viruses is poorly conceived..

what is an overwriting virus?

an overwriting virus is a virus that infects it's host program by replacing the host with itself...

overwriting infectors are probably the most unsophisticated of all viruses as it requires no complex programming skills whatsoever, they are needlessly destructive and incapable of hiding their presence because the host program is lost...

back to index

Wednesday, July 12, 2006

what is a virus writer?

a virus writer is a person who writes/programs viruses, nothing more, nothing less...

while many virus writers do more than just write viruses, those other things are not technically part of being a virus writer - being a virus writer does not imply sharing viruses, spreading viruses, publishing viruses, or letting viruses escape... the act of writing a virus does not require or imply the communication of the virus with the rest of the world, and if the virus isn't communicated to the rest of the world it cannot be a problem - thus we shouldn't try to solve the supposed problem with totalitarian laws about what we can or cannot write on our own computers as it addresses the wrong problem...

people often forget/ignore/gloss over the distinction between virus writing and the related activities but i think martin overton said it best when he said "I don't give a flying fig that you write viruses (as long as you keep them to yourself)"...

back to index

what is a virus spreader?

a virus spreader is a person who tries to cause other people's computers to become infected by viruses either directly by executing infected programs on those computers or indirectly by sending infected programs to users of those computers with an appropriate social engineering attack to trick those users into executing the infected programs themselves...

intentionally spreading viruses is perhaps the most malicious of all pro-virus behaviours as it is an explicit attempt to inflict viral infection on others... some try to justify it with excuses like 'scientific curiosity' (ie. wanting to know if it will really spread in the wild) even though history has shown that viral success in the wild has more to do with luck than it does any technical quality of the virus (ie. technically impressive viruses can be complete failures while unsophisticated and often buggy viruses become widespread)...

there are other less benign justifications as well, such as revenge for some perceived wrong-doing, spreading social or political messages that may be contained within the viruses, financial gain, or even plain old ordinary malice...

back to index

Saturday, July 08, 2006

the flip side of sophos' mac advice

as many have reported already, sophos is suggesting that home computer users purchase mac computers in the future in order to avoid the huge amount of windows malware out there...

while that's all well and fine, there's a bit of context that is conspicuously absent from the various news accounts - sophos doesn't really deal with the home user market... they're focused on the enterprise market and don't really have a product geared for the home user market... they aren't giving this advice to corporations or anyone they actually do business with...

now, don't get me wrong, i'm not a sophos basher, i think there's plenty of good things to be said about them, but their advice seems a little like patting the home users on the head and saying "there, there"... 'buy a mac' is just about the most hands-off answer you could give to the home computer users looking for a helping hand with their malware problems... at the very least switching to linux or freebsd would be cheaper and more expedient than waiting until one has enough money to go out and buy a whole new computer...

also, if everyone switched to macs, that would include the malware writers... after all, the new generation of malware writers are profit oriented, and if everyone is using a mac then the mac platform is where the malware-related profits will be found...

at best, jumping ship would just be a temporary solution to a persistent problem... it would probably help in the interim, but only for a while and then what happens when it stops working?

i can't help but see their advice, not as the professional endorsement of the mac platform that some consider it, but rather as a glib response to a problem they don't really want any part of...

Friday, July 07, 2006

"mine's bigger"

yeah, i know it's a pretty provocative statement, but that's pretty much what authentium are saying in this blog post...

mcafee lets everyone know their product is about to reach the 200,000 threats detected milestone and authentium pipes and and says 'well we're about to reach 300,000'... classic - no really, i'm surprised there are anti-virus companies still playing this particular numbers game... i thought it went out of style years ago...

now let me ask you something, do you really think there are 100,000 pieces of malware being missed by mcafee's product? you can't trust the raw numbers reported by vendors, unfortunately, and not just because some of them have apparent inferiority complexes...

this is old news for some of us but for those who don't know yet, here's how it works... say you have 2 malware samples that are related to each other (they belong to the same malware family) - scanner-A detects both pieces of malware using 2 separate signatures and scanner-B detects both pieces of malware using only 1 signature... now both detect the same number of real world threats, but the way they count is by counting the number of distinct malware definitions in the scanner's database so scanner-A will say it detects 2 pieces of malware where scanner-B will only say it detects 1 piece of malware because they're similar enough that they look the same to scanner-B...

now whether a scanner needs 1 or 2 signatures in the scenario above doesn't really have any bearing on which scanner is better, there are benefits and drawbacks for on both sides and it's not always scanner-A that requires more signatures... that said, you should be able to easily see how one scanner's numbers can be very different from those of another... now a 50% difference is considerable and i find that very suspicious, especially when f-secure pegged the number at 185,000 earlier this year which is much more in line with mcafee's 200,000 figure...

regardless, the numbers that vendors report just do not mean what they otherwise seem to mean... comparing the number of signatures between different products is a pointless exercise and it ultimately misleads the reader into thinking that one product is better than another when it may not be true... and if you're detecting the scent of snake oil in that practise, well me too...

what is a logic bomb?

a logic bomb is a piece of malware that waits for some logical condition to be met on the affected computer before carrying out it's malicious behaviour...

the condition a logic bomb waits for could be anything measurable/detectable within the computer - a specific key or combination of keys being pressed, the existence of a file, the free space on the drive being equal to some predetermined value...

the most well known condition used in logic bombs, however, is the system time being equal to (or greater than, sometimes) a specific date/time... logic bombs that trigger on system time are a subcategory known as time bombs and are the most well known because time-based triggers are quite reliable (more so than waiting for a key combination that may never be typed) and relatively easy to implement so they have historically gotten used the most by malware writers when implementing logic bomb functionality (or payloads as they're often called when attached to some other class of malware)...

back to index

Thursday, July 06, 2006

about me

ugg - what a boring topic... well if you're like me and the question of who writes this stuff is uninteresting to you then you can stop reading this right now because that's basically what this entry is going to be about...

my name is at the end of each post, you're free to google it or click on it and send me email... i'm a computer scientist - i got my bsc in computer science from university of toronto in 2000... computer science was a natural path to take as i was already quite familiar with computers before i started - i'd been a coder since the age of 10 and had taught myself a variety of programming languages by the time i entered university (c was probably the most helpful)... i'd also developed an almost instant interest in computer security back when i was still puttering around on my vic20 when i was 10-11 (though obviously not out of any actual necessity as all my data was just games and coding experiments)...

in late 1989, the 2nd hand compaq luggable i had been using for about a year developed a very strange problem where characters would appear on the screen without ever having been typed... around the same time i had heard through the media about these things called computer viruses and i got to wondering if maybe my computer had one and set out to learn more about the subject because the problem was quite annoying and i wanted it solved...

of course in retrospect that all seems silly - it was clearly a problem with the keyboard, which i did deduce after a while and did manage to repair but not before having developed an interest in computer viruses...

so there ther i was, 14, with a couple of years of programming under my belt, and i'd just developed an interest in computer viruses - i think we all know where that leads....... hah! don't trust stereotypes, that's not where it lead - not because my moral compass was anymore more developed than other teenagers, it definitely wasn't... when i did finally find forums for talking about viruses (which i find are generally much more useful than books) in the early 90's ('91 or '92 i think - if anyone can remember when edwin cleton stepped down as moderator of the VIRUS echo in fidonet, let me know) i found the analytical approach used by the anti-virus community to be more appealing than the less rigorous approach used by the vx at the time...

so there you have it - i've been learning about computer viruses (and by extension, malware and related security problems) since 1989, trying to discern the underlying principles, trying to put it into a nice, neat, easily understood package, and for much of that time sharing what i've learned with others... i'm not an expert, at least i don't consider myself one - i've interacted with those i consider experts (like frisk or dr. solly) in various forums and they're far more knowledgable than i... i'm also not a member of the anti-virus industry, basically because there aren't any av shops in my area and i don't want to move, but i also gather prior knowledge of/interest in viruses can actually be a barrier to getting hired (av companies don't want to risk hiring someone who might have a virus writing past they aren't disclosing) so it's not something i've really investigated too much... i'm just a long time member of the anti-virus community...

if you really must know more, well, i can only suggest visiting my other blog to see a different side of me...

what is the VX?

the vx is a community of people involved in the creation and distribution of viruses and viral materials... the term 'vx' is an acronym that stands for Virus eXchange - it was originally the name of a virus trading BBS (bulletin board system) back in the 90's...

members of the vx community (also known as the virus underground), are known as vx'ers... many in this group of people create, share, publish and in some cases even spread computer viruses...

while some people outside the community like to claim that it's members are anti-social, the fact that they formed a social group suggests otherwise... just because one social group does things that the rest of us don't like doesn't make them anti-social, it makes them a counter-culture... furthermore, studying the group reveals that they are motivated by the desire for many of the same social rewards that motivate everyone else - respect, social status, notoriety, influence, friendship, collaboration, etc. all within their social group... that's not to say that those are the only reasons people create/distribute/release viruses, but those that participate in the vx community do so because they are motivated at least in part by the same things that make any set of people form a social group...

back to index

Thursday, June 29, 2006

the blue pill is NOT 100% undetectable

that's right, the blue pill is not 100% undetectable...

i was amazed at the number of writers swallowing the "100% undetectable" bit hook, line, and sinker... clearly people aren't really thinking things through...

and i'm not even referring to my previous post on the blue pill, that was really just conjecture... i don't know it will work, nobody knows what will work against the blue pill because nobody's seen the blue pill yet except the researchers involved... i suspect that a pre-emptive tactical move to secure privileged virtualization resources can be used to foil next-gen vm-based stealth but it's all just guesses right now...

no, now i'm going to go back to first principles... let's start with some background - there is no perfect protection... this is a truism, an axiom, and something that the bad guys will tell you ad nauseam* in trying to show you that your security mechanisms, no matter how good, are flawed... and you know what they're absolutely right, there is no perfect protection - but watch out if you try to turn that attitude around on them 'cause you will get flamed... you see there are true believers out there, pro-malware zealots who in one breath will gleefully expound on how your security efforts are vulnerable to this or that in an attempt to feel superior for being on the supposed winning side in the malware/anti-malware battle and then in the next breath go ballistic when you suggest that the same principle applies to the tricks and techniques that malware writers use to protect their malware from security apps...

yes, that's right, stealth is nothing more than a protection mechanism (one of many as a matter of fact) that facilitate malware persistence and if there can be no perfect protection then there can be no perfect stealth, no 100% undetectability... nada, zilch... if the blue pill were to turn out to be the exception then we would study it and learn from it and build more perfect protection techniques - the same fundamental principles that apply to good software must apply to bad software too and vice versa, it's all just software after all...

what's more, i can't believe nobody is catching the scent of snake oil... i mean come on, 100% undetectable should sound as impossible as 100% detection...

no, the blue pill is not 100% undetectable, it cannot be, it would violate one of the most fundamental principles in security... it may very well be undetectable by current products but that's just not the same thing... by that logic new viruses are 100% undetectable --- until they're not...

[edit * thanks for the spelling correction, edgewalker]

Wednesday, June 28, 2006

the blue pill is hard to swallow

i've blogged before about virtual machine based stealthkits and i was pretty dismissive of the idea so you might think there was nothing more for me to say about the subject now that another one has been proposed (except maybe to say "not another one!")...

well here's my mea culpa... while the method of booting clean to get a baseline snapshot of the system to compare to when trying to generically detect the presence of active stealth techniques (outside-the-box cross-view difference detection) is still quite effective against conventional stealth malware, joanna rutkowska presents an idea for stealth where that just won't work... in memory only malware won't be found on the disk after a clean boot so the outside-the-box method won't work... also, stealth born out of moving the entire operating system into a virtualization layer (vm-based stealth) has the potential to make the malware invisible in memory - so it would seem like it's the perfect stealth...

and indeed it's getting called completely undetectable, but for me that's a little hard to swallow so i got to thinking - how would you attack something like this?.. the best way to attack malware is to find some scenario where it's not in control... clean booting doesn't get us there in this case because the malware will be entirely gone so there won't be anything to find... in-situ cross-view analysis won't work either because everything's within the malware's virtualization layer...

but what if something wasn't inside the malware's virtualization layer? in fact, what if the malware itself got executed inside of a virtualized system? a sandbox using virualization technology as advanced as that which the malware uses, designed not to do bad things but rather to look for the tell-tale signs of active stealth (especially vm-based stealth)...

if undetectable virtualization technology can be used to hide the presence of malware, then equally undetectable virtualization technology pre-emptively deployed on the system should be able to detect the undetectable vm-based stealth malware if/when it is encountered...

Tuesday, June 13, 2006

surprised by malicious software removal tool statistics

if you follow such things, i'm sure you've seen quite a few posts about microsoft's new malicious software removal tool study...

of course some folks can't manage to properly interpret the stats in it, prompting microsoft to issue a clarification (they did not find bots on ~60% of all computers scanned, only on ~60% of computers they cleaned), but i can sort of see where those people are coming from... we've sort of become accustomed to the idea that malware really is that prevalent - that's certainly the message the media has been pushing for a long time... microsoft's study is saying something very different, however:
As of the writing of this report, Microsoft has shipped 15 additional enhanced versions of the tool and continues to ship a new version on the second Tuesday of each month, each adding new prevalent malware to detect and remove. Since the initial release of the MSRT, the tool has been executed approximately 2.7 billion times by at least 270 million unique computers.
...

The MSRT has removed 16 million instances of malicious software from 5.7 million unique Windows-based computers over the past 15 months. On average, the tool removes at least one instance of malware from every 311 computers it runs on.
in 15 months of operation they've scanned ~270 million unique computers and removed malware from only 5.7 million?... that's just 2.1%... that seems surprisingly low to me...

now, i imagine if microsoft agreed to add detection/removal for their own spyware the percentage would be much higher so there might arguably be an issue of malware prevalence being under reported in order to allow practices that would result in most other supposed security vendors being labelled rogue...

another reason to suspect under reporting is that microsoft is complaining about the difficulty of dealing with tens of thousands of peices of malware when the anti-virus industry has been dealing with hundreds of thousands of peices of malware for some time now:
A significant challenge we have today is the large number of active malware samples, totaling in the order of tens of thousands, and increasing rapidly.


i don't know, maybe microsoft's numbers are right... there's not a lot to compare them to - i haven't really seen similar types of metrics coming out of other vendors for the most part (probably because most vendors' products don't report their results back to their creator(s) ... and why does microsoft's do that again?)...

if the numbers are right, it certain adds a new perspective on things... but as with all statistics it needs to be taken with a grain of salt...

Friday, June 09, 2006

can joe barr's opinion of the malware industry be trusted?

well, joe barr is at it again... i've blogged about joe once before and where the previous article i wrote about seemed to just be a case of false authority syndrome, this new one about whether the anti-malware industry can be trusted seems to be a more deliberate smear campaign...

when he's not throwing out non-sequiturs like what happened to dan greer formerly of @stake (which isn't really part of the anti-malware industry), he's redressing other non-sequiturs to look like they're actually relevant... for example:
US-Cert knows about the problem of the super-inflated malware numbers in their summary,
except that cert doesn't count malware, they count vulnerabilities - ergo what cert is or isn't doing, what they do or don't know has no bearing on whether the anti-malware industry can be trusted...

then there's innuendo about timing things specifically to make OSX look bad:
The SANS Institute, -- a name which sounds all officious and possibly not profit oriented, but which is owned by the mysterious but definitely for-profit Escal Institute of Technology -- recently did an unusual update to its Top 20 list of vulnerabilities.

They issued their "update" in order to trumpet the assertion that Apple OS X is now just as exposed and vulnerable to malware as Windows. The timing of the release of this unusual "update" is suspicious, coming as it did on the eve of the new advertising campaign by Apple which plays up the fact that Apple is pretty much immune to the types of malware infestations that plague Windows. Previous updates to this list have usually come in the fall: November, 2005; October, 2004; October, 2003; and October, 2002.
what mr.barr fails to acknowledge, however, is that there's a 3rd event in this coincidence - that being the dramatic change in the security landscape of OSX around the same time... 2 viruses and a spate serious vulnerabilities - issuing a report to inform people of the new state of things was a responsible thing for SANS to do...

there's some crazy re-interpreting of that same report, too:
The SANS Institute announcement seemed to be designed to destroy -- or at least bring into question -- the idea that Apple OS X is more secure than Windows. In a document sent to members of the press prior to the teleconference, the SANS Institute wrote:

During the past few months, Apple Safari browser users faced their first zero-day attack. A zero-day attack is one that causes damage to users even before the vendor makes a patch available. In this case, Safari users who just browsed a malicious web site found their computers automatically downloading and executing a malicious file. The user made no error other than to visit the web site. Apple patched Safari to fix this flaw, but almost immediately had to issue a second patch to stop another attack involving email attachments. The experts involved in the 2006 Top 20 Spring update agree that OS/X still remains safer than Windows; but its reputation for offering a bullet-proof alternative to Windows is in tatters. As attackers are increasingly turning their attention to the platform, OS/X vulnerabilities are being discovered at a rapid pace, which could erode this safety in the future.
now, how exactly can the report destroy or bring into question the idea that OSX is more secure than windows when his own quote of the report explicitly says that OSX is still safer than windows? and his later jab (by way of quoting a 3rd party) at the supposed claim that OSX's security reputation is in tatters? the quote clearly shows that the report said OSX's reputation for being bullet-proof was in tatters - which it is... it can't be considered bullet-proof anymore, it's been proven that it's not totally immune to threats...

the real meat of the article doesn't come until the section entitled "From Russia with malice", however... joe barr clearly has a venomous contempt for kaspersky labs, he goes on and on about supposed wrong-doings, such as:
Kaspersky Lab, a Russian Internet security company which operates around the globe, including here in the USA, has been spreading FUD about malware targeting Linux for years. I've cited this example from 2001 before, but here it is again, and it still appears on their Web site. Hey, maybe the SANS Institute used it as a template for their anti-Apple effort. I quote:

Predictions regarding a world epidemic of Linux-viruses have come true in the first quarter of 2001. The latest incidents caused by the Ramen Internet-worm and its numerous modifications, as well as the multi-platform virus Pelf (Lindose) and other Linux-targeted malicious code, have proved that this operating system, (previously considered as the most protected software), has fallen victim to computer viruses.
while one would probably not consider ramen going into the wild to be comparable with the windows worm epidemics like blaster or sasser, compared with other linux malware it was a very big deal... as for pelf, cross-platform infectors have long been considered the means by which self-replicating linux malware would become really widespread and pelf was an indication that such infectors were coming...

of course, since he was chronicling all the perceived misdeeds of kaspersky he had to include 'the case of the non-viral virus' that i de-debunked previously, but then he goes on to describe his disbelief over their linux malware report that showed there were 91 viruses for the linux platform:
I asked Kaspersky Lab if they had any documentation to back up that claim. Jennifer Jewett, a public relations person representing Kaspersky, told me "the documentation sighting the viruses is included in the Encyclopedia on Kaspersky's Viruslist site: http://www.viruslist.com/en/viruses/encyclopedia."

I searched the encyclopedia for Linux viruses and came up with an astounding 972 hits. But just the barest hint of an analysis of those hits reveal that the number would break an industrial-strength bogusity-meter.
strangely, when i did a search for linux viruses on that site, i got 92 hits not 972... just one more than was indicated in the report - most without actual descriptions but at least they include the aliases that other products use so that one can corroborate their existence... is he incapable of using a search engine or just so biased against kaspersky that he can't manage due dilligence? he knew the result set shouldn't have been anywhere near that big, he should have refined his search to narrow it down to just viruses (972 would have been the list of all linux malware, not just viruses, though the number now stands at 976 and will probably change again as time wears on)...

his final bit of evidence against kaspersky came from the recently noted intended macro virus which caused the confusion i wrote about earlier:
After this story was submitted, and the week following another black-eye for Microsoft security in the form of malevolent macros in MS Word, Kaspersky Lab issued another headline-grabbing but bogus alert for a proof-of-concept of the same type of attack on MS Word's largest competitor, OpenOffice.org. Was the timing once more just a coincidence? I don't think so.
since the existence of the malware was independently confirmed and since kaspersky labs didn't create it themselves, the timing was entirely out of their hands... it gets discovered when it gets discovered... should they have kept the first openoffice malware a secret? would it have really served the public to sit on the fact that openoffice is now being targeted by at least one malware writer? somehow that doesn't seem likely...

joe barr concludes that the anti-malware industry cannot be trusted and he attributes all these misdeeds to a desire for more money - so what should we attribute joe barr's misdeeds (ie. his FUD) to?

Thursday, June 08, 2006

mcafee on the possibility of cell phone stealthkits

the mcafee avert blog has a post on it expressing concerns that the recent release of symbian ROM images and research may lead to the development of stealthkits (what mcafee and most of the rest of the industry are currently referring to as rootkits) for cell phones...

after their stealthkit report of a couple of months ago it would be easy to interpret their newly expressed concern as meaning they feel that the ROMs and research should not have been released...

i don't know if that was actually the intention of the mcafee blogger in question, but just in case: you cannot use the threat that security research could be used for nefarious purposes as a means to justify stifling the public dissemination of any arbitrary type of security research...

while it is a risk in all public disclosure of security research, only some types of research documents (generally actual malware) fail to give the security benefits when shared publicly that justify public disclosure... i may have agreed with the sentiment from mcafee that stealthkit disclosure shouldn't be afforded the same respect that normal full disclosure enjoys, but i think this case (that doesn't disclose actual malware but just research that malware creators might be able to use) legitimately falls under full disclosure... there are plenty of security benefits that can be had by examining the symbian OS...

Wednesday, June 07, 2006

the stardust dustup

i've been seeing a number of posts like this lately, talking about how the new staroffice/openoffice macro virus is just hype...

statements like this are really telling:
In a statement prominently displayed on the OpenOffice.org home page, the group also disputes applying the label “virus” to Stardust, the proof-of-concept exploit discovered last week by Kaspersky Labs.
you see, stardust is an intended virus as mentioned by both mcafee and kaspersky... unfortunately, kaspersky labs didn't mention it was broken in their first blog post on it, only in the actual encyclopedia description which the media (mainstream and blogosphere alike) didn't bother to read and/or understand, thus necessitating the second blog post to clarify the issue...

there's lots of talk about how kaspersky labs is misleading the public and hyping up a non-existent threat... about how nothing in stardust is really new and how it's not really a vulnerability but rather a misuse of legitimate functionality... well, here's the thing:
  1. while it's true kasperky labs could have made a more informative blog post the first time 'round, the place where they said further details would be clearly stated the virus was broken...
  2. what's new here is that someone is trying to write viruses for the staroffice/openoffice platform and they may eventually succeed or someone else may fix the bugs in the current attempts and thereby succeed in making a virus for that platform... stardust is the first attempt, and the fact that someone is making that attempt is new and newsworthy... there might not be an actual virus yet, but one (or more) is coming...
  3. of course it's just a misuse of legitimate functionality - that's true for viruses in general... they aren't made possible only because of security defects, they're inherent to the general purpose computing platform and if you're going to provide a reasonably powerful macro programming facility in your office suite you're going to invariably wind up supporting macro viruses...

what is a macro virus?

a macro virus is a virus written in a macro programming language (a programming language for embedding simple programs within documents)...

most (but not all) macro viruses are written to operate in microsoft applications such as word or excel or powerpoint... these macro viruses contain one or more macros with the same name as a macro that is built into the microsoft application they're running under... then, when the ms application tries to execute it's own macro it finds the one in the document first and executes it (which makes it kind of like a companion infection technique)... since the applications in question have macros for all kinds of standard functions (like file->save or file->open) macro viruses don't have any trouble getting executed...

although it is often said that macro viruses infect documents this does not mean it's a type of virus that infects data... for one thing word/excel/powerpoint (OLE2) documents are not pure data - they're more like little file systems that contain both data and (macro) programs, not unlike your C: drive... so when someone says "my document is infected with a virus" it's comparable to the colloquialism "my computer is infected with a virus"... also, technically what a macro virus is infecting is another macro...

additionally, the operating system that uses those little file systems is the ms application that opens the document - that's why macro viruses can often operate on both windows and macs without being classified cross-platform... whether it's a windows machine or a mac machine a word macro virus runs on the ms word platform...

back to index

Tuesday, June 06, 2006

what is a companion virus?

a companion virus is a virus that exists as a separate (companion) program to the host program...

it may not be obvious how something like this would be able to meet the definine criteria of a virus and may sound more like a worm, however a companion virus is able to infect host programs without modifying their contents (that is how they can be separate programs)... it does this by taking advantage of operating system features that allow it to be executed instead of it's host program...

for example - in DOS if you type a program name without specifying the path and that program happens to not be in the current directory, DOS will search each directory in your PATH sequentially until it finds a program with that name or it reaches the end of your PATH... a path companion virus need only assume the same name as an existing program on your computer but place itself in a directory closer to the beginning of your PATH so that DOS finds the viral program first and executes it instead of the program the user intended...

another type of companion infection utilizes the fact that if a program name is specified without a file extension, DOS will look for *.com files before it looks for *.exe files so the virus need only copy itself as ProgramName.com in the same directory as the original ProgramName.exe in order to get executed...

some flavours of *nix (as well as some alternative DOS shells) have a command alias facility that can also be used for companion infection...

additionally, a virus could rename or make a backup copy of the host program and then replace the original with itself and be yet another kind of companion virus...

the original program is generally retained so that the companion virus can execute it after the virus itself gets executed - this makes the system appear to behave properly since the program you intended to execute does get executed....

back to index