Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Opening the email that was used to hack RSA

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
41,351
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Aug 26, 2011

In this video you can see us opening the very email that was used to break into RSA / EMC in March 2011. The email is opened to Outlook and the attachment is launched. The attachment is an XLS file which has no content except an embedded flash object. The object shows up as a [X] symbol in the spreadsheet. Flash is executed by Excel and it uses the CVE-2011-0609 vulnerability to execute code and to drop a Poison Ivy backdoor to the system. After this, the exploit code closes Excel and the infection is over. After this, the attacker has full remote access to the infected workstation and full access to network drives that the user can access. Video done by F-Secure Labs

Link to this comment:

Share to:

Top Comments

  • Man, RSA are such noobs.

  • LOL, RSA fell for a scam that even my grandmother wouldn't be suckered in to. Poor practice indeed.

see all

All Comments (14)

Sign In or Sign Up now to post a comment!
  • @newlookmedia You've lost your mind bro ._.

  • @AndreasHassing

    That's what I've just sad !

    This video is just reconstruction of behavior of email and user.

    So! What does this user (F-secure worker) done ? NOTHING!

    He or she must IGNORE this suspicious behavior and let this thing work in their internal network for next few days. Until someone discovered security break.

    So !?

    Is it possible? In fully secured company which workers live from building security software or ..

    .. someone trying to feed us some shit to cover real circumstances of

  • @newlookmedia What are you talking about? They're opening the mail in a sandboxed instance of windows, to show what happens when you open the file (which is nothing).

  • Ten film to lipa!

    Gdzie w firmie zajmującej się ochroną antywirusową ten kto odebrał takiego maila zignorował by takie zachowanie arkusza !

    Lepiej æeby poszukali sobie pracy na farmie na nie robili oprogramowanie do ochrony danych.

    This video is FAKE !

    If not then they must fire all F-secure workers and close company.

    People who call themselfs security specialist and ignore that kind behavior ???!!!

    They better look for jobs in farm! Not to sell security software.

  • @stupidjunk978 Ur grandma would get a computer virus from the ATM at the Mall

  • FS Labs sucks. XP Suck at security.

  • security is a dream?! no wonder we got all our RSA token replaced.

    It is really funny, our IT shipped my colleague's token to me. Well, he got a token that was undocumented!!! The final solution was that we exchanged the token and our IT reassigned the undocumented token to me. LOL.

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more