When you look at security from just the last few years you only get a small picture of how things are. And based on that picture you may believe that your systems are secure – you’ve tested them against malware in the wild, you haven’t been infected yet, you’ve stayed ahead of the pack. But, depending on your particular security policies, this may not be the case – it may in fact be the case that there’s already research about bypassing those policies, and attackers will follow.

It’s not hard to see this in more recent days. ROP was a long time ago (at least for me) but what about the first MD5 hash collision ever used for in-the-wild attacks? That’s s something researched as early as the 90’s, but we’ve now seen it adopted for a real attack. Flamer used that collision to bypass Windows Update authentication (or trick it, whatever you want to call it) and install malware onto regular users systems. Those were regular people infected, and that was a very advanced attack. Will we start seeing commonplace MD5 collisions? Absolutely not, but first came the research, and then came the attack.

I think it’s critical to remember that the victims of Flamer were largely your average user. They weren’t the main target, but they were used to propagate the malware. Those people weren’t all government officials and the like, some were just regular people, and they were subjected to a very advanced attack.

Don’t ever think that your computer, or your information, is not highly valuable to an attacker. Maybe you’re just a relay to get to the next person, maybe your credit card info is of value, maybe just compromising the system and hooking it up to a botnot will be enough – the point is that hackers always find a way to make lots of money.

If you think that attacks haven’t evolved in the last few years you’re wrong. One simple example is that attackers aren’t just using the same ROP they always have. As ASLR implementations have improved attackers have had to rely more on information leakage, something that had been talked about for years, but there hadn’t been a need for it as ASLR didn’t even exist on Windows until a few years ago, and it was terribly flawed until Windows 8.

I could list a thousand things, like local kernel exploitation, sandbox escapes, etc, but it would be fruitless. The point is that you can’t look at a system now and judge it by the current threats. Always consider research, because attackers do.



blog comments powered by Disqus

Published

17 April 2013

Category

security