Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics

11/21/2006
07:45 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Video: The New Attack Frontier

Attackers are starting to send their payload by video

Careful playing that video file: It could be infected. Researchers say video files are becoming the new mode of transportation for malware.

There's been a recent increase in proof-of-concept code for embedding malware in Windows Media and RealMedia files, for instance. The first known exploit using such a technique was spotted last week by McAfee; it was a worm aimed at Real Networks' RealPlayer and RealMedia files. Although the so-called W32/Realor.worm is considered a low-risk exploit, it opened the door for similar attacks via video players, security experts say.

Video is the new frontier for attackers. "This is one of the top attack vectors you should be concerned about. The potential [damage] is pretty massive," says Mark Zielinski, security engineer for Arbor Networks' Security Engineering and Response Team.

The Realor worm basically uses an infected hyperlink in a video file, and to do its dirty work it requires that a user click the poison link.

Attackers used to stick malware executables in an email attachment, but those typically get stopped at the email gateway, so attackers have resorted to using known applications as a way to deliver their malicious code.

These types of attacks aren't limited to video files. Zielinski says there's been an increasing number of vulnerabilities being published in Word, PowerPoint, and Real Networks' RealPlayer. "This kind of attack exists in any format where an application is willing to render an image."

If one of these attacks makes it successfully into the corporate network, it typically sets up a backdoor, so the victimized computer sends a connection back to the attacker, and the hacker doesn't have to initiate the connection, Zielenski says, and it can get by the firewall. It would be a popular method for a targeted attack, he says.

At the heart of the problem is the fact that video and audio formats -- as well as "workshare" apps like Word and PowerPoint -- contain multiple, complex features that leave them prone to attack, says Dimitri Alperovitch, principal research scientist with Secure Computing. "Those are files piquing the interest of virus writers... At the beginning of this year, we saw an increase in worms targeting Microsoft Office."

"As these applications become more and more bloated with features, this threat will continue to rise," he says, as well as with those video players that automatically load an embedded link in a video file when you open a video file.

"Old video files were just sets of frames you could view and create video applications [with]," he says. "Now you can insert all kinds of things into a video file: information about it, external links, etc. That presents more possibilities for exploitation."

YouTube is a prime candidate for attack, as well as other multimedia sites. Arbor's Zielinski says all it would take is an attacker downloading a video from YouTube, injecting his exploit, and re-uploading it, and then anyone who viewed it would get infected. "If there were 20,000 people viewing a popular video, they would get [infected]."

How do you protect yourself from a video attack? Aside from running the usual antivirus and host-based IPS tools, you should trust no outside sources.

"Be careful which documents you open," says Secure Computing's Alperovitch. "Nowadays, you can't trust any sort of data file you get from someone you don't know."

— Kelly Jackson Higgins, Senior Editor, Dark Reading

  • Arbor Networks Inc.
  • Secure Computing Corp. (Nasdaq: SCUR)
  • McAfee Inc. (NYSE: MFE) Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio
     

    Recommended Reading:

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Oldest First  |  Newest First  |  Threaded View
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 7/2/2020
    Ripple20 Threatens Increasingly Connected Medical Devices
    Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
    DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
    Dark Reading Staff 6/30/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    How Cybersecurity Incident Response Programs Work (and Why Some Don't)
    This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
    Flash Poll
    The Threat from the Internetand What Your Organization Can Do About It
    The Threat from the Internetand What Your Organization Can Do About It
    This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-9498
    PUBLISHED: 2020-07-02
    Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
    CVE-2020-3282
    PUBLISHED: 2020-07-02
    A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
    CVE-2020-5909
    PUBLISHED: 2020-07-02
    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
    CVE-2020-5910
    PUBLISHED: 2020-07-02
    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
    CVE-2020-5911
    PUBLISHED: 2020-07-02
    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.