View Full Version : dll exploit/ .lnk exploit mitigation by HIPS
aigle
October 11th, 2010, 07:29 PM
There are two interesting exploits/ vulnerabilities discovered recently.
1- .lnk exploit( involves a dll execution too).
2- dll vulnerability
HIPS and behav blockers are usually not meant to handle malicious dll execution, though many of classical HIPS can be configured to intercept dll execution/ loading but due to the insane no of pop up alerts it,s not practical at all.
I have tried the POCs for both exploits with Comodo Defence Plus v 4, EQSecure and GesWall.
CIS v 5 is great but sadly it has no control for dll execution. :'( No way to intercept both these exploits via CIS 5.
Here is .lnk exploit POC that executes a test dll named dll.dll.
222511
222512
222513
222517
aigle
October 11th, 2010, 07:32 PM
Here is second POC. This is for dll exploit. I tried with VLC Media Player.
222514
222515
222525
222516
aigle
October 11th, 2010, 08:16 PM
And here is an interesting dll issue.
http://www.greatis.com/security/explorer_redirection_dll_startup_hole.htm
I searched this malware and then tested with CISv 4 and GesWall. Besides the dll issue malware also installs a driver so any HIPS will stop it anyway. However the dll part of it is interesting. In case of XP, once a malicious linkinfo.dll is dropped into windows directory, then windows explorer will automatically load it on next boot.
222518222519
222520222521
aigle
October 11th, 2010, 08:19 PM
And with GesWall.
222522
222523
222524
moontan
October 11th, 2010, 08:19 PM
sorry to hijack your thread for an instant m8.
aigle:
-{ Quote: "I have tried the POCs" }-
POC?
i see this quite often here.
what does it mean?
i've Googled it and there's about 30-40 definitions.
from where i sit, it's either Proof of Concept or Pile of Cr*p! :o
is it something else?
aigle
October 11th, 2010, 08:20 PM
Again this dll loading part can,t be tested with CIS v 5 as it has no dll control. >:(
trjam
October 11th, 2010, 08:23 PM
Proof of Concept.:dry:
aigle
October 11th, 2010, 08:24 PM
-{ Quote: "sorry to hijack your thread for an instant m8.
aigle:
POC?
i see this quite often here.
what does it mean?
i've Googled it and there's about 30-40 definitions.
from where i sit, it's either Proof of Concept or Pile of Cr*p! :o
is it something else?" }-
Yep, Proof of Concept. :)
You may call it pile of crap until the real malware comes out, it,s upto you. By the way .lnk exploit is already more than a Proof of concept( stuxnet worm).
moontan
October 11th, 2010, 08:25 PM
tnx m8!
now back to our regular programming...
moontan
October 11th, 2010, 08:43 PM
according to the article at greatis:
-{ Quote: "Affected Systems
Windows 2000, XP(SP1,SP2,SP3), 2003, Vista(SP1), 2008 Server.
Vista UAC prevents a user from creating files in the Windows folder but it may be easily skipped." }-
m00nbl00d
October 11th, 2010, 08:59 PM
-{ Quote: "according to the article at greatis" }-
-{ Quote: "Vista UAC prevents a user from creating files in the Windows folder but it may be easily skipped." }-
What about a LUA Limited User Account (XP)/Standard User Account (Vista, 7)? By definition, a limited/standard user has no write permissions to C:\Windows.
Boost
October 12th, 2010, 04:03 AM
Geswall - :thumb:
Kyle1420
October 12th, 2010, 04:36 AM
Yep, As always ;D If there isn't a conflict... Geswall is nice layer.
blacknight
October 12th, 2010, 05:30 AM
-{ Quote: "
CIS v 5 is great but sadly it has no control for dll execution. :'( No way to intercept both these exploits via CIS 5." }-
Aigle, did you try it, or only you saw the 5v Defense+ settings ? I say it because is unknow which files are checked by default, see here (https://forums.comodo.com/news-announcements-feedback-cis/comodo-internet-security-501626361135-released-t61661.195.html) 196
aigle
October 12th, 2010, 11:14 AM
Yes i tried. Also officially egemen, the lead developer, himself wrote that dll control is no more there in this version.
moontan
October 12th, 2010, 11:19 AM
tnx for feeding my paranoia folks! :lurking:
i think i'm gonna give Ubuntu a try.;D
blacknight
October 12th, 2010, 01:23 PM
-{ Quote: "Yes i tried. Also officially egemen, the lead developer, himself wrote that dll control is no more there in this version." }-
??? ??? Another good reason for don't upgrade from 4v.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums