** **

Return address = SAIC****

===========================================================****

** **

Feds are Suspects in New Malware That Attacks Tor Anonymity****

http://www.wired.com/threatlevel/2013/08/freedom-hosting/****

** **

****

    By Kevin Poulsen****

    08.05.13****

    ****

** **

Security researchers tonight are poring over a piece of malicious software**
**

that takes advantage of a Firefox security vulnerability to identify some***
*

users of the privacy-protecting Tor anonymity network.****

** **

The malware showed up Sunday morning on multiple websites hosted by the****

anonymous hosting company Freedom Hosting. That would normally be considered
****

a blatantly criminal "drive-by" hack attack, but nobody's calling in the FBI
****

this time. The FBI is the prime suspect.****

** **

"It just sends identifying information to some IP in Reston, Virginia," says
****

reverse-engineer Vlad Tsrklevich. "It's pretty clear that it's FBI or it's**
**

some other law enforcement agency that's U.S.-based."****

** **

If Tsrklevich and other researchers are right, the code is likely the first*
***

sample captured in the wild of the FBI's "computer and internet protocol****

address verifier," or CIPAV, the law enforcement spyware first reported by**
**

WIRED in 2007.****

** **

Court documents and FBI files released under the FOIA have described the****

CIPAV as software the FBI can deliver through a browser exploit to gathers**
**

information from the target's machine and send it to an FBI server in****

Virginia. The FBI has been using the CIPAV since 2002 against hackers,****

online sexual predator, extortionists and others, primarily to identify****

suspects who are disguising their location using proxy servers or anonymity*
***

services, like Tor.****

** **

The code has been used sparingly in the past, which kept it from leaking out
****

and being analyzed or added to anti-virus databases.****

** **

The broad Freedom Hosting deployment of the malware coincides with the****

arrest of Eric Eoin Marques in Ireland on Thursday on an U.S. extradition***
*

request. The Irish Independent reports that Marques is wanted for****

distributing child pornography in a federal case filed in Maryland, and****

quotes an FBI special agent describing Marques as "the largest facilitator**
**

of child porn on the planet."****

** **

Freedom Hosting has long been notorious for allowing child porn to live on**
**

its servers. In 2011, the hactivist collective Anonymous singled out Freedom
****

Hosting for denial-of-service attacks after allegedly finding the firm****

hosted 95 percent of the child porn hidden services on the Tor network.****

** **

Freedom Hosting is a provider of turnkey "Tor hidden service" sites -****

special sites, with addresses ending in .onion, that hide their geographic**
**

location behind layers of routing, and can be reached only over the Tor****

anonymity network.****

** **

Tor hidden services are ideal for websites that need to evade surveillance**
**

or protect user's privacy to an extraordinary degree - which can include****

human rights groups and journalists. But it also naturally appeals to****

serious criminal elements.****

** **

Shortly after Marques' arrest last week, all of the hidden service sites****

hosted by Freedom Hosting began displaying a "Down for Maintenance" message.
****

That included websites that had nothing to do with child pornography, such**
**

as the secure email provider TorMail.****

** **

Some visitors looking at the source code of the maintenance page realized***
*

that it included a hidden iframe tag that loaded a mysterious clump of****

Javascript code from a Verizon Business internet address located in eastern*
***

Virginia.****

** **

By midday Sunday, the code was being circulated and dissected all over the**
**

net. Mozilla confirmed the code exploits a critical memory management****

vulnerability in Firefox that was publicly reported on June 25, and is fixed
****

in the latest version of the browser.****

** **

Though many older revisions of Firefox are vulnerable to that bug, the****

malware only targets Firefox 17 ESR, the version of Firefox that forms the**
**

basis of the Tor Browser Bundle - the easiest, most user friendly package***
*

for using the Tor anonymity network.****

** **

"The malware payload could be trying to exploit potential bugs in Firefox 17
****

ESR, on which our Tor Browser is based," the non-profit Tor Project wrote in
****

a blog post Sunday. "We're investigating these bugs and will fix them if we*
***

can."****

** **

The inevitable conclusion is that the malware is designed specifically to***
*

attack the Tor browser. The strongest clue that the culprit is the FBI,****

beyond the circumstantial timing of Marques's arrest, is that the malware***
*

does nothing but identify the target.****

** **

The heart of the malicious Javascript is a tiny Windows executable hidden in
****

a variable named "Magneto". A traditional virus would use that executable to
****

download and install a full-featured backdoor, so the hacker could come in**
**

later and steal passwords, enlist the computer in a DDoS botnet, and****

generally do all the other nasty things that happen to a hacked Windows box.
****

** **

But the Magneto code doesn't download anything. It looks up the victim's MAC
****

address - a unique hardware identifier for the computer's network or Wi-Fi**
**

card - and the victim's Windows hostname. Then it sends it to the Virginia**
**

server, outside of Tor, to expose the user's real IP address, and coded as a
****

standard HTTP web request.****

** **

"The attackers spent a reasonable amount of time writing a reliable exploit,
****

and a fairly customized payload, and it doesn't allow them to download a****

backdoor or conduct any secondary activity," says Tsrklevich, who****

reverse-engineered the Magneto code.****

** **

The malware also sends, at the same time, a serial number that likely ties**
**

the target to his or her visit to the hacked Freedom Hosting-hosted website.
****

** **

In short, Magneto reads like the x86 machine code embodiment of a carefully*
***

crafted court order authorizing an agency to blindly trespass into the****

personal computers of a large number of people, but for the limited purpose*
***

of identifying them.****

** **

But plenty of questions remain. For one, now that there's a sample of the***
*

code, will anti-virus companies start detecting it?****

** **

Update: 8.5.13 12:50 According to Domaintools, the malware's****

command-and-control IP address in Virginia is allocated to Science****

Applications International Corporation. SAIC is a major technology****

contractor for defense and intelligence agencies, including the FBI.****


__._,_.___






__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.


Reply via email to