Re: On classifying attacks

From: Steven M. Christey (coley_at_mitre.org)
Date: 07/18/05

  • Next message: Mihai Amarandei-Stavila: "Re: On classifying attacks"
    Date: Mon, 18 Jul 2005 16:07:51 -0400 (EDT)
    To: bugtraq@securityfocus.com
    
    

    Derek Martin said:

    >The vulnerability is neither truly remote nor local, in the normal
    >senses as we have defined them here. It is a different kind of
    >vulnerability altogether. The vulnerability is one to automatically
    >triggering trojan horses....

    I agree with you on the need for a third category.

    Another term could be "user-complicit," which reflects the core role
    that the user has in activating the vulnerability, versus the
    traditional "automatic" exploitation (no human user interaction) and
    "opportunistic" exploitation (attacker has no control over when the
    vulnerable state occurs, as can happen in some types of information
    leaks for example).

    Depending on the normal channels by which the "trojan" is delivered,
    the attack could be "local user-complicit" or "remote user-complicit."
    For example, images are usually shared in some remote fashion, thus a
    vulnerability in an image renderer could be remote user-complicit,
    whereas a vulnerability that requires a local user to trick another
    local user into changing into a directory with a large name would be
    local user-complicit.

    One small difficulty I have with associating this too closely with the
    "trojan horse" terminology is that many Trojans are inserted after a
    vulnerability has been exploited and access is gained, so this further
    muddies the waters of an already vague term.

    - Steve


  • Next message: Mihai Amarandei-Stavila: "Re: On classifying attacks"

    Relevant Pages

    • Re: spyware
      ... | Even before downloaded,Panda is detectiong it as a PUP/Hack Tool/ ... Such software is installed via a vulnerability exploitation or through an already ... The problem with V software is that it may find a Trojan or some Trojanized files ... that sets my tool apart is not only is it hard coded for the known threats bu it ...
      (microsoft.public.security.virus)
    • [Full-disclosure] New PowerPoint 0-day Trojan in the wild
      ... New zero-day vulnerability in Microsoft PowerPoint has been disclosed. ... This vulnerability is being exploited by Trojan horse Trojan.PPDropper.E. ... Possibly attackers/targets are located in China area or bad guys just tested the Trojan with Chinese version. ...
      (Full-Disclosure)
    • New PowerPoint 0-day Trojan in the wild
      ... New zero-day vulnerability in Microsoft PowerPoint has been disclosed. ... This vulnerability is being exploited by Trojan horse Trojan.PPDropper.E. ... Possibly attackers/targets are located in China area or bad guys just tested the Trojan with Chinese version. ...
      (Bugtraq)
    • [sb] RE: [Full-Disclosure] Internet explorer 6 execution of arbitrary code (An analysis of the 180 S
      ... >>Finally I also attached the source files to this message ... The vulnerability allows for the writing, and overwriting, of local ... There are several variants of this trojan. ...
      (Full-Disclosure)
    • [NT] Ipswitch IMail IMAP Vulnerabilities (Multiple Buffer Overflow, Multiple DoS, Directory Traversa
      ... A directory Traversal vulnerability also was found, ... attackers to remotely view files on the server. ... Remote exploitation of a denial of service vulnerability in Ipswitch ...
      (Securiteam)