What's Breaking News Tonight?
A GOP professional laments the "slime and dirt and muck attached not only to the two candidates but also to the party itself."
What's New?
The new black hole exploit kit has been out and we've had a chance to deconstruct it. Before we get super geeky, some general observations about the innovation in this kit:
- Malware developers continue to use the latest tools to encrypt their malware to evade anti-virus (AV) software. As usual, the encryption signature is new, avoiding AV--our analysis showed that 70 percent of AV software would miss this altogether. This serves as a not-so-gentle reminder the fundamental problem with signature based AV--it changes every week with the use of a new encryption algorithm.
- Hackers are deploying resiliency. In the past, we've seen hackers deploy a single exploit server. In this case, there were four that could be redirected if any of the URLs was taken down.
What are BEPs?
An exploit kit, a browser exploit pack (BEP) is a toolkit that automates the exploitation of client side vulnerabilities.
The toolkit is a bundle of PHP and HTML files with a list of exploit files (including JAVA, PDF, Browsers, Adobe Flash Player ...etc) designed to target the operating system, browser or other client side application. Toolkits are usually heavily obfuscated using some known or unknown obfuscation and crypto algorithms tools to avoid detection by anti-virus vendors.
Black hole is yet another web exploit kit developed by Russian hackers. Blackhole is a very powerful kit with a number of recent exploits including Java and Adobe PDF exploits. One blog published (with updates) a great overview of the most known exploit packs.










