19 Jan 2010

Operation Aurora

Author: Abhijeet | Filed under: Information Security, Web Security

Update:

I simulated the exploit in my virtual pentest lab against different target systems including Windows XP, Windows 2003 R2 and Windows 7. I have written a separate post on EvilFinger blog on steps to reproduce the attack and basic analysis of exploit code.

Last week, Google Inc publicly disclosed about being attacked by Chinese and reported Theft of intellectual property. This attack was also carried against 30 other companies under the name “Operation Aurora”. After this attack, Google has decided to take new approach to China. Now the question arises, Why name Aurora?”

According to McAfee,

“Aurora” was part of the filepath on the attacker’s machine that was included in two of the malware binaries that we have confirmed are associated with the attack. That filepath is typically inserted by code compilers to indicate where debug symbols and source code are located on the machine of the developer. We believe the name was the internal name the attacker(s) gave to this operation.

Attackers have used zero day vulnerability in Microsoft Internet Explorer (DOM Operation Memory Corruption) and used social engineering tricks to gain access to victim systems. Microsoft has published a security advisory confirming the deadly and not so publicly known vulnerability on Thursday.

As of now there is no patch available for the mitigation of vulnerability. The recent public disclosure of exploit code has already increased the frequent attack possibilities. Latest svn checkout of metasploit contains an exploit module for Operation Aurora which targets IE 6.

Protected Mode in IE 7 on Windows Vista, later significantly reduces the ability of an attacker to impact data on a user’s machine. Microsoft is advising to enable Data Execution Prevention (DEP) which helps to mitigate such online attacks.

Metasploit has published a blog post on Reproducing “Aurora” IE Exploit. When major the antivirus failed to detect exploit code, my Avast Antivirus free home edition is able to block the attack against vulnerable IE 6. Following is the screenshot showing Avast blocking malicious URL.

Avast blocking attack

Download ie_aurora exploit attack traffic. Download the packet captures of ie_aurora exploit module.

References:

Tags: , , , , ,

2 Responses to “Operation Aurora”

  1. Operation Aurora - Evil Fingers – The Blog Says:

    [...] being atta"; VN:F [1.7.7_1013]Rating: 0 (from 0 votes)The following has been copied and pasted from[Chackra Blog]: Last week, Google Inc publicly disclosed about being attacked by Chinese and reported Theft of [...]

  2. chackraview.net » Blog Archive » Yet another information disclosure vulnerability in Internet explorer. Says:

    [...] IE Aurora’s dust was not even settled in our minds and yet another critical vulnerability in IE has emerged with a bang !! [...]

Leave a Reply

Get Adobe Flash playerPlugin by wpburn.com wordpress themes