![]() |
|
#1
|
||||
|
||||
|
I just fouind an interesting malicious doc file. Just seeing it in explorer causes the explorer to crash.
I know of ani exploit but never heard of such an explot via a doc file. CFP and GW were not able to intercept this exploit. Quote:
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#2
|
|||
|
|||
|
From the file name, this seems to be a PoC, demo from several years ago. These kinds of PoC files that crash applications are plentiful, and demonstrate that a particular vulnerability can execute code. An old one where a ZIP file crashes Win Explorer:
Quote:
While interesting to play with, not until a PoC becomes an exploit with a payload can we know what we need to protect against. For MSWord: Responding to a file-parsing application attack http://isc.sans.org/diary.html?storyid=3757 Quote:
Quote:
Until the vulnerability is patched to prevent the code from executing, the payloads of these exploits, of course, are easy to block with many solutions: ---- rich |
|
#3
|
||||
|
||||
|
Thanks a lot for the nice analysis.
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#4
|
||||
|
||||
|
Have you tried aigle to view the file with sanboxed Windows Explorer using Sandboxie?
It should be very interesting, because there is a minor issue concerning Sandboxie + Windows Explorer, which you can see here.
__________________
TuX Factory |
|
#5
|
||||
|
||||
|
I doubt that any HIPS/ Sandbox will prevent explorer crash due to any exploit. But if there is a pay load sure it will be stopped and that is all what we need.
I am not using SBIE. If u like, PM me. Thanks
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|