|
![]() |
|
| Author |
|
|||||||
|
pARODY
Posts: 339
Location: Brisbane, Queensland
|
Had a great email thread today at work about keyloggers and the last 24hours has had a massive surge in new delivery methods. I've personally seen and captured old Gumblar infectors now delivering keyloggers for games instead of just their usual botnet drops.
The most fun delivery method we've seen is a vulnerability in QuickTime's MS DirectShow implementation (CVE-2009-1537). Bundle that with Xvid having a bug that could be used against users (http://www.xvid.org/) Basic version, update your PDF reader, all of them I've seen have various ways of being exploited. Update xvid and update your Windows for the DirectShow bug. Not much AV coverage for the keylogger though. :( Update your stuff and watch out for .PDF files and .SWF files from suspect sites. |
|||||||
| #0 07:07pm 15/06/09 |
|
|||||||
|
system
|
--
|
|||||||
| #0 |
|
|||||||
|
infi
Posts: 12551
Location: Brisbane, Queensland
|
hmm interesting info.
|
|||||||
| #1 07:09pm 15/06/09 |
|
|||||||
|
Spook
Posts: 25335
Location: Brisbane, Queensland
|
i thought keyloggers all came from wow forums
|
|||||||
| #2 07:22pm 15/06/09 |
|
|||||||
|
reload!
Posts: 4638
Location: Brisbane, Queensland
|
and guitars
|
|||||||
| #3 07:23pm 15/06/09 |
|
|||||||
|
Obes
Posts: 7686
Location: Brisbane, Queensland
|
i thought keyloggers all came from wow forums You'd be wrong. Usually cross site scripting exploits inside adverts on totally legit sites. |
|||||||
| #4 07:48pm 15/06/09 |
|
|||||||
|
reload!
Posts: 4639
Location: Brisbane, Queensland
|
whoa whoa whoa WHOA
stop the f***ing presses. did obes just get trolled? |
|||||||
| #5 07:51pm 15/06/09 |
|
|||||||
|
JakeG
Posts: 624
Location: Brisbane, Queensland
|
Back in the day my gunbound account got keylogged.. :< (used to play at infernolan).
|
|||||||
| #6 07:57pm 15/06/09 |
|
|||||||
|
pARODY
Posts: 346
Location: Brisbane, Queensland
|
Bumping this. Avertlabs did some research on some of the new keyloggers out there and its packed with comedy gold. 2 different keyloggers seen in the wild at present have changed their return delivery method from email to SQL directly to a DB in brazil/china. Stupid malware coders left the credentials to post into the DB in the code. http://www.avertlabs.com/research/blog/index.php/2009/06/22/more-password-theft-shenanigans/ |
|||||||
| #7 07:26pm 23/06/09 |
|
|||||||
|
euphoria
Posts: 1247
Location: Gold Coast, Queensland
|
lol
|
|||||||
| #8 07:31pm 23/06/09 |
|
|||||||
|
Hashy
Posts: 269
Location:
|
You'd be wrong.Nice straight-faced, pretentious reply to a joke bro. |
|||||||
| #9 08:06pm 23/06/09 |
|
|||||||
|
paveway
Posts: 9939
Location: Brisbane, Queensland
|
haha reload
|
|||||||
| #10 08:08pm 23/06/09 |
|
|||||||
|
system
|
--
|
|||||||
| #10 |
|
|||||||
|
| ||||||||