Sanctum Zone

Keyword
A+ A A-
Welcome, Guest
Username: Password: Remember me
  • Page:
  • 1

TOPIC: FBI Suspects in Malware Case

FBI Suspects in Malware Case 06 Aug 2013 12:52 #1

  • wake_up_bomb
  • wake_up_bomb's Avatar
  • ZONED OUT
  • Gold Boarder
  • Rank5
  • Posts: 5063
  • Thank you received: 4418
  • Karma: 56
www.wired.com/threatlevel/2013/08/freedom-hosting/
Feds Are Suspects in New Malware That Attacks Tor Anonymity

Security researchers tonight are poring over a piece of malicious software that takes advantage of a Firefox security vulnerability to identify some users of the privacy-protecting Tor anonymity network.

The malware showed up Sunday morning on multiple websites hosted by the anonymous hosting company Freedom Hosting. That would normally be considered a blatantly criminal “drive-by” hack attack, but nobody’s calling in the FBI this time. The FBI is the prime suspect.

“It just sends identifying information to some IP in Reston, Virginia,” says reverse-engineer Vlad Tsyrklevich. “It’s pretty clear that it’s FBI or it’s some other law enforcement agency that’s U.S.-based.”

If Tsrklevich and other researchers are right, the code is likely the first sample captured in the wild of the FBI’s “computer and internet protocol address verifier,” or CIPAV, the law enforcement spyware first reported by WIRED in 2007.

Court documents and FBI files released under the FOIA have described the CIPAV as software the FBI can deliver through a browser exploit to gather information from the target’s machine and send it to an FBI server in Virginia. The FBI has been using the CIPAV since 2002 against hackers, online sexual predators, extortionists, and others, primarily to identify suspects who are disguising their location using proxy servers or anonymity services, like Tor.

The code has been used sparingly in the past, which kept it from leaking out and being analyzed or added to anti-virus databases.

The broad Freedom Hosting deployment of the malware coincides with the arrest of Eric Eoin Marques in Ireland on Thursday on an U.S. extradition request. The Irish Independent reports that Marques is wanted for distributing child pornography in a federal case filed in Maryland, and quotes an FBI special agent describing Marques as “the largest facilitator of child porn on the planet.”

Freedom Hosting has long been notorious for allowing child porn to live on its servers. In 2011, the hactivist collective Anonymous singled out Freedom Hosting for denial-of-service attacks after allegedly finding the firm hosted 95 percent of the child porn hidden services on the Tor network.

Freedom Hosting is a provider of turnkey “Tor hidden service” sites — special sites, with addresses ending in .onion — that hide their geographic location behind layers of routing, and can be reached only over the Tor anonymity network.

Tor hidden services are ideal for websites that need to evade surveillance or protect users’ privacy to an extraordinary degree – which can include human rights groups and journalists. But it also naturally appeals to serious criminal elements.

Shortly after Marques’ arrest last week, all of the hidden service sites hosted by Freedom Hosting began displaying a “Down for Maintenance” message. That included websites that had nothing to do with child pornography, such as the secure email provider TorMail.

Some visitors looking at the source code of the maintenance page realized that it included a hidden iframe tag that loaded a mysterious clump of Javascript code from a Verizon Business internet address located in Virginia.

By midday Sunday, the code was being circulated and dissected all over the net. Mozilla confirmed the code exploits a critical memory management vulnerability in Firefox that was publicly reported on June 25, and is fixed in the latest version of the browser.

Though many older revisions of Firefox are vulnerable to that bug, the malware only targets Firefox 17 ESR, the version of Firefox that forms the basis of the Tor Browser Bundle – the easiest, most user-friendly package for using the Tor anonymity network.

“The malware payload could be trying to exploit potential bugs in Firefox 17 ESR, on which our Tor Browser is based,” the non-profit Tor Project wrote in a blog post Sunday. “We’re investigating these bugs and will fix them if we can.”

The inevitable conclusion is that the malware is designed specifically to attack the Tor browser. The strongest clue that the culprit is the FBI, beyond the circumstantial timing of Marques’ arrest, is that the malware does nothing but identify the target.

The heart of the malicious Javascript is a tiny Windows executable hidden in a variable named “Magneto.” A traditional virus would use that executable to download and install a full-featured backdoor, so the hacker could come in later and steal passwords, enlist the computer in a DDoS botnet, and generally do all the other nasty things that happen to a hacked Windows box.

But the Magneto code doesn’t download anything. It looks up the victim’s MAC address — a unique hardware identifier for the computer’s network or Wi-Fi card — and the victim’s Windows hostname. Then it sends it to the Virginia server, outside of Tor, to expose the user’s real IP address, and coded as a standard HTTP web request.

“The attackers spent a reasonable amount of time writing a reliable exploit, and a fairly customized payload, and it doesn’t allow them to download a backdoor or conduct any secondary activity,” says Tsyrklevich, who reverse-engineered the Magneto code.

The malware also sends, at the same time, a serial number that likely ties the target to his or her visit to the hacked Freedom Hosting-hosted website.

In short, Magneto reads like the x86 machine code embodiment of a carefully crafted court order authorizing an agency to blindly trespass into the personal computers of a large number of people, but for the limited purpose of identifying them.

But plenty of questions remain. For one, now that there’s a sample of the code, will anti-virus companies start detecting it?
The true measure of a man is not his intelligence or how high he rises in this freak establishment. The true measure of a man is this: how quickly he can respond to the needs of others and how much of himself he can give - Philip K. Dick.
You must register to post here.

FBI Suspects in Malware Case 06 Aug 2013 13:54 #2

  • psketti
  • psketti's Avatar
  • ZONED OUT
  • Hired help
  • Rankadmin
  • we cant stop here, this is dog country
  • Posts: 15528
  • Thank you received: 5668
  • Karma: 100
The FBI has been using the CIPAV since 2002 against hackers, online sexual predators, extortionists, and others, primarily to identify suspects who are disguising their location using proxy servers or anonymity services, like Tor.


So someone who isn't a hacker, sexual predator, extortionist or other, is actually bringing more attention to themselves because they value their privacy.
the anorak hides the fact that sean is composed of 95% vaginas
You must register to post here.
  • Page:
  • 1
Moderators: psketti, oioioi, batou
Time to create page: 0.110 seconds

Latest Members Blogs

  • 1
  • 2
  • 3
Prev Next

What is going on when it comes to 9-11 I…

The EPA (environmental protection agency) and OSHA took air samples in the days following September 11th, they reported that they found no excessive levels of asbestos contrary to other findings....

Read more

9-11 Eleven Years Later

9-11 Eleven Years Later

With the anniversary of September 11th literally just around the corner, unanswered questions still remain for families who lost loved ones during the tragic event, as well as from families...

Read more

Strange Noises, Possible Link to Mass An…

Strange Noises, Possible Link to Mass Animal Deaths

In 2008 the U.S. Supreme Court agreed to review a series of lower court rulings that restrict the United States Navy's use of sonar in submarine detection training exercises off...

Read more

Annual Server Target

Whether its 50 cents or five dollars, your donations are appreciated and help keep this community site running so we can all continue to enjoy using it.
This target is to meet our server cost for one year, June 2020 - May 2021, in USD.
$ 340 - Target
( £ 250 GBP )
donation thermometer
donation thermometer
$ 192 - Raised
( £ 140 GBP )
donation thermometer
56%
Most Recent Donation:
$122 USD on 4th Jan 2021
Bitcoin Address: bc1q0kazqya0nurfxtunxv807vm0m8852nnrrk8mj8
 
Ethereum Address: 0xe69915c80dd75df19f438d556267e04f932f057d
 
More Info: Donation options for TZ

No one is obliged to donate, please only donate what you can afford. Even the smallest amount helps. Being an active member is a positive contribution. Thank You.

TradeZone Latest

Visitors

Today235
Yesterday1477
Week1712
Month235
Total1162238

Your IP Address: 216.73.216.143 Your Browser and OS: Unknown - Unknown Tuesday, 01 September 2026 04:38

Who Is Online

Guests : 688 guests online Members : No members online
© 2012 – 2021 Sanctum Zone | All rights reserved. This website is a place for people to express and discuss their views on the news and world events. DISCLAIMER: Please Note: Views expressed and submitted by contributors are their own personal opinions and do not necessarily reflect the views, opinions and beliefs of the Sanctum Zone website and its founder(s) , administrators , moderators , and any other website maintenance technicians, personnel and volunteers. Articles and messages posted on this website and forum are solely the opinion of their authors.

Login or Register

LOG IN

Register

User Registration
or Cancel