PSA #2 Malware

Feds Are Suspects in New Malware That Attacks Tor Anonymity

Security researchers tonight are poring over a piece of malicious software that takes advantage of a Firefox security vulnerability to identify some users of the privacy-protecting Tor anonymity network.

The malware showed up Sunday morning on multiple websites hosted by the anonymous hosting company Freedom Hosting. That would normally be considered a blatantly criminal “drive-by” hack attack, but nobody’s calling in the FBI this time. The FBI is the prime suspect.

“It just sends identifying information to some IP in Reston, Virginia,” says reverse-engineer Vlad Tsyrklevich. “It’s pretty clear that it’s FBI or it’s some other law enforcement agency that’s U.S.-based.”

When does “do what you have to do“, clash with “obey the law“.  You see this is a apparently a hack to identify the people who sent up child porn servers.

The heart of the malicious Javascript is a tiny Windows executable hidden in a variable named “Magneto.” A traditional virus would use that executable to download and install a full-featured backdoor, so the hacker could come in later and steal passwords, enlist the computer in a DDoS botnet, and generally do all the other nasty things that happen to a hacked Windows box.

But the Magneto code doesn’t download anything. It looks up the victim’s MAC address — a unique hardware identifier for the computer’s network or Wi-Fi card — and the victim’s Windows hostname. Then it sends it to the Virginia server, outside of Tor, to expose the user’s real IP address, and coded as a standard HTTP web request.

Problem is, this program is out there now. And anyone can use it.

HOW BAD IS THE AMMO SHORTAGE?

 

Unknown's avatar

About On the North River

Forty years toiled in the Tel-com industry, married for 36 years widowed at sixty-one. Ten years in a relationship with a woman until her death. Was a Tea Party supporter. Today a follower of the Last American President to be honestly elected, Donald J. Trump. Recently had Ancestry.com tell me I'm Swedish, not Danish. I may need to change my avatar.
This entry was posted in News and opinion. Bookmark the permalink.

Leave a Reply but please keep it Legal.