** ** Return address = SAIC****
===========================================================**** ** ** Feds are Suspects in New Malware That Attacks Tor Anonymity**** http://www.wired.com/threatlevel/2013/08/freedom-hosting/**** ** ** **** By Kevin Poulsen**** 08.05.13**** **** ** ** Security researchers tonight are poring over a piece of malicious software** ** that takes advantage of a Firefox security vulnerability to identify some*** * users of the privacy-protecting Tor anonymity network.**** ** ** The malware showed up Sunday morning on multiple websites hosted by the**** anonymous hosting company Freedom Hosting. That would normally be considered **** a blatantly criminal "drive-by" hack attack, but nobody's calling in the FBI **** this time. The FBI is the prime suspect.**** ** ** "It just sends identifying information to some IP in Reston, Virginia," says **** reverse-engineer Vlad Tsrklevich. "It's pretty clear that it's FBI or it's** ** some other law enforcement agency that's U.S.-based."**** ** ** If Tsrklevich and other researchers are right, the code is likely the first* *** sample captured in the wild of the FBI's "computer and internet protocol**** address verifier," or CIPAV, the law enforcement spyware first reported by** ** WIRED in 2007.**** ** ** Court documents and FBI files released under the FOIA have described the**** CIPAV as software the FBI can deliver through a browser exploit to gathers** ** information from the target's machine and send it to an FBI server in**** Virginia. The FBI has been using the CIPAV since 2002 against hackers,**** online sexual predator, extortionists and others, primarily to identify**** suspects who are disguising their location using proxy servers or anonymity* *** services, like Tor.**** ** ** The code has been used sparingly in the past, which kept it from leaking out **** and being analyzed or added to anti-virus databases.**** ** ** The broad Freedom Hosting deployment of the malware coincides with the**** arrest of Eric Eoin Marques in Ireland on Thursday on an U.S. extradition*** * request. The Irish Independent reports that Marques is wanted for**** distributing child pornography in a federal case filed in Maryland, and**** quotes an FBI special agent describing Marques as "the largest facilitator** ** of child porn on the planet."**** ** ** Freedom Hosting has long been notorious for allowing child porn to live on** ** its servers. In 2011, the hactivist collective Anonymous singled out Freedom **** Hosting for denial-of-service attacks after allegedly finding the firm**** hosted 95 percent of the child porn hidden services on the Tor network.**** ** ** Freedom Hosting is a provider of turnkey "Tor hidden service" sites -**** special sites, with addresses ending in .onion, that hide their geographic** ** location behind layers of routing, and can be reached only over the Tor**** anonymity network.**** ** ** Tor hidden services are ideal for websites that need to evade surveillance** ** or protect user's privacy to an extraordinary degree - which can include**** human rights groups and journalists. But it also naturally appeals to**** serious criminal elements.**** ** ** Shortly after Marques' arrest last week, all of the hidden service sites**** hosted by Freedom Hosting began displaying a "Down for Maintenance" message. **** That included websites that had nothing to do with child pornography, such** ** as the secure email provider TorMail.**** ** ** Some visitors looking at the source code of the maintenance page realized*** * that it included a hidden iframe tag that loaded a mysterious clump of**** Javascript code from a Verizon Business internet address located in eastern* *** Virginia.**** ** ** By midday Sunday, the code was being circulated and dissected all over the** ** net. Mozilla confirmed the code exploits a critical memory management**** vulnerability in Firefox that was publicly reported on June 25, and is fixed **** in the latest version of the browser.**** ** ** Though many older revisions of Firefox are vulnerable to that bug, the**** malware only targets Firefox 17 ESR, the version of Firefox that forms the** ** basis of the Tor Browser Bundle - the easiest, most user friendly package*** * for using the Tor anonymity network.**** ** ** "The malware payload could be trying to exploit potential bugs in Firefox 17 **** ESR, on which our Tor Browser is based," the non-profit Tor Project wrote in **** a blog post Sunday. "We're investigating these bugs and will fix them if we* *** can."**** ** ** The inevitable conclusion is that the malware is designed specifically to*** * attack the Tor browser. The strongest clue that the culprit is the FBI,**** beyond the circumstantial timing of Marques's arrest, is that the malware*** * does nothing but identify the target.**** ** ** The heart of the malicious Javascript is a tiny Windows executable hidden in **** a variable named "Magneto". A traditional virus would use that executable to **** download and install a full-featured backdoor, so the hacker could come in** ** later and steal passwords, enlist the computer in a DDoS botnet, and**** generally do all the other nasty things that happen to a hacked Windows box. **** ** ** But the Magneto code doesn't download anything. It looks up the victim's MAC **** address - a unique hardware identifier for the computer's network or Wi-Fi** ** card - and the victim's Windows hostname. Then it sends it to the Virginia** ** server, outside of Tor, to expose the user's real IP address, and coded as a **** standard HTTP web request.**** ** ** "The attackers spent a reasonable amount of time writing a reliable exploit, **** and a fairly customized payload, and it doesn't allow them to download a**** backdoor or conduct any secondary activity," says Tsrklevich, who**** reverse-engineered the Magneto code.**** ** ** The malware also sends, at the same time, a serial number that likely ties** ** the target to his or her visit to the hacked Freedom Hosting-hosted website. **** ** ** In short, Magneto reads like the x86 machine code embodiment of a carefully* *** crafted court order authorizing an agency to blindly trespass into the**** personal computers of a large number of people, but for the limited purpose* *** of identifying them.**** ** ** But plenty of questions remain. For one, now that there's a sample of the*** * code, will anti-virus companies start detecting it?**** ** ** Update: 8.5.13 12:50 According to Domaintools, the malware's**** command-and-control IP address in Virginia is allocated to Science**** Applications International Corporation. SAIC is a major technology**** contractor for defense and intelligence agencies, including the FBI.**** __._,_.___ __,_._,___ -- -- Thanks for being part of "PoliticalForum" at Google Groups. For options & help see http://groups.google.com/group/PoliticalForum * Visit our other community at http://www.PoliticalForum.com/ * It's active and moderated. Register and vote in our polls. * Read the latest breaking news, and more. --- You received this message because you are subscribed to the Google Groups "PoliticalForum" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/groups/opt_out.
