Malvertising (malicious advertising) is a reasonably fresh take on an online criminal methodology that appears focused on the installation of unwanted or outright malicious software through the use of internet advertising media networks, exchanges and other user supplied content publishing services common to the Social Networking space. The most popular Malvertising vector active "in the wild" is a result of the client rendering of Adobe Flash SWF files that contain maliciously coded Flash ActionScript. In my own limited (but growing) experience, Malicious SWF files may share one or more of the following features:
In light of a growing problem that has the potential to effectively place every internet user at risk, even when only visiting sites they would otherwise fully trust, there is at least a new tool available to assist the security researcher community with a means to better identify malicious SWF files. The timing for this is excellent, as I have personally only learned of this tool just this morning. This particular tool is the OWASP hosted project named 'SWFIntruder'. I will be doing my own deep dive into the details of it's use for inclusion into my own SWF analysis tool bag. The personal SWF analysis tool bag happens to include two other freely available (also cross platform) SWF file decompilers:
SWFIntruder : https://www.owasp.org/index.php/Category:SWFIntruder
swfdump : http://www.swftools.org/ (source available)
and 'flare' : http://www.nowrap.de/flare.html (binary only) :(
We may expand on how you might consider applying security mitigations for this threat type as a protection for the average user which may include your spouse, parents, children, corporate network users, etc... in a future diary. Please do write in with your own insights into the malvertising problem space.
William Salusky
Handler on Duty :)
Login here to post a comment. Diary Archive
If you still have the test used to check the status of ISP static IP addresses I will search for it. If not please restore it if possible.
Louis.