Hacker
The 'Tornado' malware offers attackers a full set of traffic statistics
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Experts warn of 'Tornado' hacker tool

New web attack conducts multiple exploits

Shaun Nichols in California, vnunet.com 23 Apr 2008
ADVERTISEMENT

Security researchers have discovered a new web-based attack tool which exploits up to 14 browser vulnerabilities and installs malware on the user's system.

Symantec researcher Liam O'Murchu said that 'Tornado' is commonly installed on a server by a single 'administrator', who then offers accounts on the server to other attackers.

The attackers then inject code into other web pages to redirect users to the Tornado server, where the exploit and malware installation is conducted.

"Perhaps this is why the code for this pack has stayed private for so long," said O'Murchu.

"Using this model, the creators of the pack can sell it to a few trusted customers at a higher price, rather than selling it to many untrustworthy customers and risking the code being released in the underground."

Tornado also offers attackers a full set of traffic statistics and options for selecting which exploits can be conducted.

The malware features an option to redirect repeat visitors to a phoney 'account suspended' page.

This helps the tool to evade security researchers who will make repeated visits to infected pages in order to study the exploits and malware in use.

Programs such as Neosploit and MPack offer similar capabilities to set up servers that can conduct multiple exploits against users.

See also:

Infosec Europe 2008Hacking fades in favour of theft  22 Apr 2008
Infosec Europe 2008Employee web filtering gets weird  22 Apr 2008
Infosec 2008 Preview: Ed Gibson, Chief Security Advisor at Microsoft UK, talks to vnunet.com about the security focus for the coming year.  21 Apr 2008
Infosec Europe 2008The latest news and views from Europe's number one information security event  01 May 2008

All Hacking
Tags: Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | The Moving Picture Company
Web Developer - London   MPC's continued success is dependent on a continued investment in technology so that its clients continue to enjoy the highest possible quality of work and service. Key to MPC's offering is ... more >
London, United Kingdom | Deloitte
Technology and Systems Consulting Event - LondonWith the right balance, you'll achieve great things. Join our Consulting practice and have the opportunity to balance your technical and business consulting skills to bring out the best ... more >
Oxford, Oxfordshire, United Kingdom | University of Oxford
Senior Business Analyst - Oxford University - £34,793 - £45,397   Business Services & Projects (BSP) Are you an experienced Business Analyst with the skills to improve the efficiency of Oxford University's business systems? The ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
More job opportunities